◇ Theory
Thresholds and key custody
Many bridges release funds when a threshold of validators sign. The security of the whole bridge is then the security of that many keys — if too few independent parties hold them, compromising one organisation can be enough.
Diversify key holders, raise thresholds relative to the value secured, monitor for unusual withdrawals, and never leave temporary signing permissions in place.
What does the signature cover?
A signature only proves that someone signed a particular message. If that message does not include a nonce, an expiry, the chain id and the verifying contract, the same signature can be accepted again — or on another chain.
EIP-712 typed data with a domain separator, plus a per-signer nonce, binds each signature to one use in one place.
Verify the verifier
Signature checks are often delegated to a helper, a precompile or an account passed in by the caller. If the contract does not confirm that the thing doing the verification is the genuine one, an attacker can supply their own.
Every lab pairs the vulnerable contract with its patched twin in the Post-Mortem stage — the exact lines that fail, and the exact lines that fix them.