One Right-Click Won't Save You: Auditing Arkham's Cross-Chain Bridge Verification Feature

CryptoStack
Video

I spent four hours on Arkham's new right-click integration, reading every synchronous XMLHttpRequest the extension fires. The popup console displayed a spinner for 11.4 seconds. Then it returned three data points: origin chain transaction hash, destination chain transaction hash, and a bridge contract label.

Is that all?

One Right-Click Won't Save You: Auditing Arkham's Cross-Chain Bridge Verification Feature

That was the entire payload. No proof verification. No validation of relay state. No cryptographic check of the bridge's message commitment. Just two hashes and a label.

This matters. Bridge hacks account for over $2.8 billion in cumulative losses since 2021 — Ronin ($624M), Wormhole ($326M), Nomad ($190M), Harmony Horizon ($100M). The infrastructure that moves value between chains has become the single most exploited attack surface in crypto. When a tool adds "bridge verification" as a right-click menu item, it implies a security function. It implies due diligence. I found something different.

Here is the ledger, line by line.

One Right-Click Won't Save You: Auditing Arkham's Cross-Chain Bridge Verification Feature

What the Feature Actually Executes

I installed Arkham's browser extension (version 0.9.14) and traced its behavior. The right-click menu item appears when a user selects a text string that matches a 0x-prefixed hash pattern. Clicking it opens a popup — not an in-browser panel, a separate mini-window — that queries Arkham's backend API endpoint: /api/v1/bridge/verify.

The response schema, visible in the network tab, contains these fields:

One Right-Click Won't Save You: Auditing Arkham's Cross-Chain Bridge Verification Feature