Across Hack

Reported loss $400K
Solana (origin); destination chains via relayer payouts
Forged Deposit Event

What happened

On July 17, 2026, Across's Solana spoke was abused with forged deposit events. Risk Labs' relayer filled 581 fake requests and advanced approximately $4.5M of its own capital; Across's on-chain contracts and user funds were not directly compromised. The attacker later returned the remaining funds, leaving a final Risk Labs loss roughly equal to the 10% bounty, about $400K by the cited estimate.

Technical root cause

Risk Labs' Solana relayer accepted event-shaped payloads without validating the 8-byte Anchor event discriminator or confirming a corresponding source-chain state change. That off-chain validation gap let fabricated deposits trigger real relayer payouts.

How it happened

The attacker submitted 1,627 forged FundsDeposited payloads from single-use Solana wallets. The relayer's off-chain event reader treated them as genuine and paid 581 requests on destination chains before the origin was disabled. The response blacklisted addresses, paused the spoke, deployed the fix, and restored the relayer route.

Protocol details

Classification Bridge / Off-Chain Relayer Validation
Protocol Type Cross Chain Bridge
Implementation language Rust
Protocol links Website @AcrossProtocol

Security review history

Funds Recovery

100.0%

Recovered

$3.7M

Net Loss

$0

Post-Incident Timeline

  • 2026-07-31

    Amount Lost: ~$4.5 million initial relayer payout ($0 user funds lost; ~$3.7 million recovered after 10% bounty) Status: Off-chain event parsing code patched; Solana order flow temporarily routed through CCTP fallback; relayer funds recovered less the white-hat bounty.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.