On July 17, 2026, an attacker exploited Across Protocol's Risk Labs-operated relayer, forging 1,627 Solana deposits worth $41.7 million. The exploit succeeded due to a missing 8-byte Anchor event discriminator check in the off-chain software. The relayer paid out $4.5 million before suspending services, but trapped attacker funds kept the net loss under $4 million. Because of Across's intents-based design, user funds were completely unaffected, and service was restored within 12 hours via Circle's CCTP.
Story comments
Loading comments…