Why bridges are risky

A bridge is two or more jurisdictions on one ledger story: assets leave chain A, trust a relayer or proof system, and appear on chain B. Bugs in messaging, validator sets, or upgrade keys have caused nine-figure losses industry-wide. Your wallet’s job is to show what you sign; it cannot guarantee every hop in a composite route.

Non-custodial means GaurdWallet never holds your keys and never asks for your seed phrase — not in chat, not in e-mail, not in a fake “sync” popup. Support that requests a mnemonic is impersonation. Everything else in this article assumes you are using the real app at gaurdwallet.com/app/.

Interactive checklist

Work through these items before your first bridge of the day. Progress is stored only in your browser tab — not on our servers.

Pre-bridge checks

0 of 8 checked — start small, then scale.

Route verification

LI.FI aggregates multiple bridge and DEX providers. A quote is a program’s opinion, not a promise. Expand the route details in Exchange and note bridge names you recognize. If a path routes through an obscure token you must hold briefly, understand that hop — illiquid middle tokens are a classic way to lose value to MEV or failed swaps.

Compare time estimates with reality: optimistic rollups can finalize in minutes; some messaging bridges take longer under load. A slow bridge is not always a stolen bridge, but an unknown bridge name plus urgency language in a Telegram DM is.

When researching a provider, prefer primary docs and on-chain addresses published by the protocol, not screenshots in social posts. GaurdWallet does not audit every submodule LI.FI might call this week.

Bookmark the explorer pages for your usual chains. After signing, compare the “to” field on approve and bridge transactions with the addresses shown in the quote. A mismatch between UI and wallet confirm screen is a full stop — close the flow and report a bug if the wallet itself is wrong, or leave if the site is wrong.

Multi-hop routes that touch stableswap pools can still slip on stables during stress. Your checklist slippage item exists for that reason. If minimum received drops more than a few basis points versus spot without explanation, re-quote or reduce size.

Phishing and fake UIs

Bridge phishing often looks like “claim stuck funds” or “migrate before deadline.” The site connects your wallet and asks for unlimited approvals. Real bridging in GaurdWallet happens inside Exchange after you unlock locally — no external “connect to recover” step.

  • Check the domain character by character: gaurdwallet.com, not look-alikes.
  • Reject browser extensions you did not install deliberately.
  • Never paste your seed into any web form, including fake “network repair” tools.

Extension users: pin the official Chrome/Edge listing and disable other wallet extensions during sensitive operations so the wrong signer does not pop up.

Bookmark gaurdwallet.com/app/ and avoid search-engine ads for “Gaurd Wallet login.” Typosquat domains rotate weekly; the checklist bookmark item exists because muscle memory is faster than regret.

Wrong network mistakes

USDC on Ethereum is not USDC on Base in your mental model even when symbols match — contract addresses differ. Sending to an exchange deposit address on the wrong chain can be unrecoverable. In self-custody, the mistake is yours.

In Bridge mode, read both chain badges on From and To. If you imported a custom RPC, ensure it is the chain you think it is — malicious RPCs can show fake balances. GaurdWallet ships known networks; custom entries are your responsibility.

Pending status discipline

After you sign a bridge, GaurdWallet shows progress on the Dashboard until the destination leg completes or fails clearly. While status is pending:

  • Do not submit the same bridge again out of impatience.
  • Do not assume failure until the explorer or status card says so — some routes batch proofs.
  • Keep enough source-chain gas if a retry or cancel path exists for that protocol (not all routes support cancel).

If a bridge fails after source funds moved, recovery may require protocol support tickets and on-chain proofs — another reason to test with small size first.

Third-party contracts

Every bridge confirmation interacts with contracts GaurdWallet did not write. You may see:

  1. An ERC-20 approve to a router or bridge spender — GaurdWallet requests exact amounts by default.
  2. A bridge entrypoint that locks or burns tokens.
  3. A destination mint/release triggered by relayers — invisible until it succeeds or errors.

Read simulation errors. “Execution reverted” often means slippage, expired quote, or insufficient allowance — refresh the quote before raising gas blindly. Unlimited approvals from previous sessions on other dApps remain a risk until revoked; bridging does not fix old mistakes.

What GaurdWallet does not bridge

Exchange v0.2.1 focuses on EVM↔EVM bridges and same-chain EVM swaps via LI.FI, plus Solana swaps via Jupiter. Not supported: Bitcoin, Litecoin, or TRON bridges; cross-chain moves from Solana to EVM inside Exchange. Attempting those flows elsewhere with the same seed still carries all risks above — this checklist applies even outside our UI.

For operational steps, see how to swap and bridge and gas fees when swapping and bridging.

If something looks wrong

Stay calm and avoid “recovery” links posted in chat. Collect facts first:

  • Source transaction hash on the explorer — did it succeed or revert?
  • Dashboard bridge card status — still pending, completed, or failed?
  • Destination chain explorer — any incoming transfer pending indexing?

If the source succeeded and the destination never credits after the quoted window, open the bridge protocol’s status page with your transaction hash — many LI.FI routes map to identifiable backends. GaurdWallet support cannot reverse on-chain transactions; legitimate help works from hashes, not from your seed phrase.

Report phishing domains to [email protected] with screenshots and URLs. Revoke suspicious ERC-20 approvals through explorer tools if you signed on a malicious site — unlimited approvals remain the fastest way to lose a cold-storage stack in one block.

Document lessons in your own notes: which route, which size, which network pair. Repeat mistakes in bridging are expensive; checklists only help when you use them under time pressure.

Share checklists with friends you co-invest with — not seed phrases, just process. Social pressure to “send it” fast is how network mistakes happen; a shared habit of reading route tools aloud catches errors early.

Re-run the checklist after any wallet or browser update — UI regressions are rare but verifying a test bridge after upgrades takes minutes and preserves sleep.

Store completed checklist habits the same way you store seed backups: offline and private — not as a public thread, but as a personal runbook you actually open before large moves.