Wormhole eth-sol hack was 120k weWETH ($320m). Minted the wrapped eth on solana by passing a fake system address, which was falsely approved by the guardian signature check. Then swapped back to eth.
This whole chain of verification and process is managed by a large handful of smart contracts. One SC told another that the guardians had approved. How are these APIs not bulletproof.
Looked a bit through core contracts and deepdived wrapped tokens.