What are the real risks of bridging assets to layer 2 for yield
Layer 2 networks offer higher yields than Ethereum mainnet. That yield premium is real. But you get it because you take on a specific, non-obvious risk: the bridge.
Bridging is not a single operation. It is a custody handoff with a waiting period. Understanding the mechanism matters more than trusting the name on the bridge UI.
Canonical bridges versus third-party bridges
A canonical bridge is built and maintained by the layer 2 team itself. For Arbitrum, that is the Arbitrum Bridge. For Optimism, the Standard Bridge. These bridges rely on the L2’s own security assumptions - fraud proofs, validators, settlement on Ethereum.
Third-party bridges are separate protocols. Examples include Wormhole, Synapse, and the now-defunct Nomad. These bridges hold your collateral in their own smart contracts on both chains. They do not inherit the layer 2’s security guarantees. They add an entirely new trust layer.
The distinction is critical. A canonical bridge can only fail if the layer 2 itself fails. A third-party bridge can fail while both chains remain perfectly secure. That has happened - repeatedly.
The Arbitrum withdrawal delay
Arbitrum’s canonical bridge imposes a 7-day withdrawal window. You initiate a withdrawal from layer 2. Your funds are locked for roughly 7 days before they appear on Ethereum mainnet.
That delay exists because of fraud proofs. During the 7-day window, validators can challenge a withdrawal if it claims an invalid state transition. This window is the mechanism that secures the bridge - it allows detection of fraud before funds move.
But the delay is also a real cost. If a bridge exploit happens during that 7 days, your funds are still on layer 2. You cannot react. You cannot pull them back early. The lock period is symmetrical: it protects honest users and traps them equally.
Third-party bridges sometimes advertise faster withdrawals - minutes or hours. That speed comes from a different security model, not from better engineering. They bypass fraud proofs by introducing a validator set or a multi-sig. Those validators become the new attack surface.
What the exploits cost
Wormhole was exploited in February 2022. The attacker minted 120,000 wrapped Ether on Solana without depositing corresponding collateral on Ethereum. Total loss: roughly $326 million at the time. The bridge was third-party. Solana and Ethereum both operated normally.
Nomad was exploited in August 2022. A messaging bug allowed anyone to replay a legitimate transaction and drain funds. Total loss: roughly $190 million. Again, both underlying chains were unharmed.
These were not DeFi protocol hacks. They were bridge failures. The bridge contracts became the weakest link. In both cases, the custodial smart contracts held assets that did not belong to them, and attackers found a way to claim them.
What you are underwriting
When you bridge to a layer 2 for yield, you are underwriting the bridge’s smart contract risk. The yield premium on L2 is, in part, compensation for that risk.
Consider the math in abstract terms. Mainnet yields 3%. A layer 2 yields 6%. The difference is 3%. If the bridge has a 1% chance of catastrophic failure, your expected return is actually 6% minus the expectation of loss - which could be far less than the mainnet yield, depending on the probability.
You cannot know that probability. No one can. The only data points are past failures - and none of those tell you the risk of the next failure.
A practical approach
Use canonical bridges for large positions. Accept the 7-day delay. Consider third-party bridges only for small amounts you can afford to lose entirely.
Read the bridge’s technical documentation. Look for whether it uses fraud proofs, a validator set, or a multi-sig. Each design has different failure modes. A multi-sig introduces counterparty risk. A validator set introduces conspiracy risk. Fraud proofs introduce time delay, not counterparty risk.
The safest bridge is the one you do not need. If the yield on layer 2 does not meaningfully exceed mainnet yield plus the estimated friction of the 7-day delay, the risk may not be worth the return.
Bridges are not middleware. They are custody points. Treat them accordingly.
Not financial advice. brooder.tech publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.