Skip to main content
Calcimator

Bridge Security Budget Calculator

Estimate cross-chain bridge security costs based on TVL, validator count, signature threshold, and transaction volume.

About this calculator

Cross-chain bridges are a favorite attack target precisely because they concentrate huge value behind a relatively small set of signers, and this calculator sizes the security spend and attack economics around that reality. Annual security budget is simply your Total Value Locked times a security-spend percentage you set (industry practice generally runs 0.1–2% of TVL), which then divides evenly across your validator/guardian count to get an annual cost per validator. The headline "estimated attack cost" figure is the calculator's core insight: it assumes an attacker only needs to corrupt enough validators to reach your signature threshold (the M in an M-of-N multisig), so it multiplies cost-per-validator by that threshold number as a rough proxy for what buying off (or otherwise compromising) the minimum viable set of signers would cost.

A lower signature threshold relative to validator count is cheaper to attack even if the total validator set is large — this is captured separately in the Byzantine Fault Tolerance percentage, computed as (threshold − 1) divided by validator count, representing the share of validators that can be dishonest before the system breaks. The TVL/security ratio flags a different risk dimension: how many dollars of value sit behind each dollar of annual security spend, with anything above roughly 500x flagged as thin protection for the assets at stake. Keep in mind the attack-cost figure is a simplified economic proxy, not a real threat model — it doesn't account for validator collusion resistance, slashing, or reputational costs that make bribing validators harder than the raw dollar math implies.

Inputs

%

Results

Annual Security Budget ($)

$50,000.00

Estimated Attack Cost ($)

$30,000.00

≈ 15 gaming PCs

Monthly Budget ($)$4,166.67
Annual Cost per Validator ($)$10,000.00
TVL / Security Ratio200
Security Cost per Tx ($)$1.37
Byzantine Fault Tolerance (%)40
How to Use This Calculator
  1. Enter Total Value Locked ($) — the dollar amount of assets currently secured by your bridge.
  2. Set Validator / Guardian Count and the Signature Threshold (M of N) — e.g., 3 of 5 validators must sign.
  3. Enter the Annual Security Budget as a % of TVL (industry range: 0.1–2%).
  4. Set daily Bridge Transactions to understand per-transaction security overhead.
  5. Review Annual Security Budget ($), Cost per Validator, and Byzantine Fault Tolerance % to ensure robust multisig design.

How the result changes with Total Value Locked ($)

Total Value Locked ($)Annual Security Budget ($)Estimated Attack Cost ($)
5,000,000$25,000.00$15,000.00
7,500,000$37,500.00$22,500.00
15,000,000$75,000.00$45,000.00
25,000,000$125,000.00$75,000.00

What each input means

Total Value Locked ($)
Total USD value of assets secured by the bridge.
Validator / Guardian Count
Number of independent validators or guardians securing the bridge.
Signature Threshold (M of N)
Minimum signatures required to approve a bridge transaction (e.g., 3 of 5).
Security Budget (% of TVL)
Annual security spend as a percentage of TVL. Industry range: 0.1% - 2%.
Bridge Transactions / Day
Average number of cross-chain transfers per day.

What each result means

Annual Security Budget ($)
Total yearly spend on bridge security infrastructure and validators.
Monthly Budget ($)
Monthly security budget allocation.
Annual Cost per Validator ($)
Annual compensation or operational cost per validator node.
Estimated Attack Cost ($)
Estimated cost to compromise enough validators to breach the signature threshold.
TVL / Security Ratio
Dollars of TVL per dollar of security spend. Lower is more secure; above 500x is risky.
Security Cost per Tx ($)
Security overhead per bridge transaction.
Byzantine Fault Tolerance (%)
Percentage of validators that can be compromised before the threshold is breached.

How this is calculated

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Total Value Locked ($) = 10000000, Validator / Guardian Count = 5, Signature Threshold (M of N) = 3, Security Budget (% of TVL) = 0.5 = 5 input(s) provided
  2. Calculate Annual Security Budget
    Annual Security Budget = tvlUsd * (annualSecurityBudgetPct / 100)
    50000 = $50,000
  3. Calculate Estimated Attack Cost
    Estimated Attack Cost = costPerValidator * signatureThreshold
    30000 = $30,000
  4. Calculate Monthly Budget
    Monthly Budget = annualSecurityBudget / 12
    4166.67 = $4,166.67
  5. Calculate Annual Cost per Validator
    Annual Cost per Validator = annualSecurityBudget / validatorCount
    10000 = $10,000

Engine last updated . Checked against 2 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

How is Estimated Attack Cost actually calculated?

It multiplies your annual cost per validator (annual security budget divided by validator count) by the signature threshold — the minimum number of signatures (M) needed out of the total validators (N) to approve a transaction. The logic is that an attacker only needs to compromise enough validators to reach that threshold, not the entire validator set, so this figure is a proxy for the minimum viable bribe or compromise cost.

What does the Byzantine Fault Tolerance percentage represent?

It's calculated as (signature threshold minus 1) divided by validator count, expressed as a percentage — the share of validators that can act dishonestly before the multisig's approval threshold is breached. A higher BFT percentage means more validators would need to collude before the bridge is at risk, so it's a structural resilience measure distinct from the dollar-based attack cost figure.

Why can a lower signature threshold be riskier even with many validators?

Estimated Attack Cost scales with the threshold number, not the total validator count — a 3-of-20 setup has the same attack cost estimate as a 3-of-5 setup, since only 3 validators need to be compromised either way, even though the 20-validator system sounds more decentralized. This is why the calculator treats signature threshold, not raw validator count, as the key input driving attack economics.

What does the TVL/Security Ratio flag, and when is it a red flag?

It's Total Value Locked divided by annual security budget, showing how many dollars of secured assets sit behind each dollar spent on security annually. The calculator flags a ratio above roughly 500x as thin protection relative to the assets at stake — meaning the bridge is securing a very large amount of value with comparatively little ongoing security investment.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.