Crypto World
Across Protocol relayer loses under $4M in Solana attack
Across Protocol’s Risk Labs-operated relayer lost less than $4 million after an attacker fabricated $41.7 million in Solana deposit events, according to a post-incident report released by the cross-chain protocol.
Summary
- 1,627 fake deposits worth $41.7 million targeted 18 chains during the Solana attack.
- Risk Labs’ relayer paid $4.5 million across 581 fraudulent requests before suspending service.
- Around $500,000 in attacker funds remained trapped, reducing the net loss below $4 million.
- Across restored Solana transfers through CCTP, while user funds and the ACX buyback remained unaffected.
Risk Labs’ relayer paid approximately $4.5 million against 581 fake deposits before Across suspended the affected service. Around $500,000 belonging to the attacker remained trapped inside the protocol, reducing the net loss below $4 million.
Across attributed the breach to its Solana off-chain event-reading software rather than a flaw in its smart contracts. The protocol reported that no users lost funds and that every legitimate transfer was completed or fully refunded on the day of the attack.
Across attacker created 1,627 fake Solana deposits
The attack occurred between 05:07 and 06:14 UTC on July 17, according to the Across Protocol post-mortem. During that 67-minute period, the attacker used 1,627 single-use Solana wallets to submit the same number of fabricated deposits.
Those deposits had a combined face value of approximately $41.7 million and directed payments across 18 destination chains. Across reported that the funds ultimately flowed toward one recipient on an Ethereum Virtual Machine-compatible network.
Risk Labs’ relayer filled 581 of the fraudulent requests, representing about 35.7% of the total. However, the $4.5 million paid out accounted for only about 10.8% of the attempted face value.
Across stopped Solana operations before the remaining 1,046 requests could be filled. The protocol invalidated approximately $37 million in unpaid fake deposits, preventing those requests from producing further losses.
The report identified the root cause as a bug in Risk Labs’ relayer codebase. Because the affected software operated off-chain, the attacker did not alter Across’ on-chain contracts or exploit Solana’s underlying network.
Why Across users avoided losses
Across uses relayers that advance their own capital to complete cross-chain orders before seeking reimbursement. This structure placed the immediate financial exposure on Risk Labs’ relayer rather than users transferring assets through the protocol.
The protocol reported that all legitimate transfers were completed or refunded on July 17. Across had processed more than $34 billion in bridge volume without losing user funds, according to figures published on its website.
The incident differs from the Lien Finance attack reported by crypto.news on July 24. Lien Finance lost approximately 542,144.63 USDC after an attacker exploited its bond exchange logic to mint unsupported tokens without destroying the required input bonds.
SlowMist traced the Lien Finance vulnerability to incomplete checks in the exchangeEquivalentBonds function. Unlike the Across incident, that attack involved smart contract logic and allowed the attacker to exchange unbacked bond tokens for USDC held by the affected liquidity source.
The Across disclosure also arrived as stolen assets from an earlier Solana breach began moving. As crypto.news reported, a wallet tied to the $285 million Drift Protocol exploit transferred 23,095.1 ETH, worth about $44.4 million, into Tornado Cash on July 23 and July 24.
ACX trades near $0.041 after the report
ACX was trading at approximately $0.04135 at the time of writing, down 2.8% over 24 hours and 2.3% over seven days, according to CoinGecko.
The token had a market capitalization of about $29.1 million and a 24-hour trading volume of approximately $3.3 million. ACX remained nearly 97.6% below its all-time high of $1.69.
Across stated that the relayer loss would not change its planned ACX token buyback. The protocol did not disclose whether the incident would affect Risk Labs’ other spending or relayer operations.
Solana service moves to CCTP routing
Across deployed a root-cause fix about five hours after the attack and restored Solana service in approximately 12 hours through its fallback CCTP route.
All Solana order flow now uses Circle’s Cross-Chain Transfer Protocol, which transfers native USDC between supported networks through a burn-and-mint process. Across has not provided a timeline for restoring its previous Solana routing system.
The protocol’s next steps include maintaining the CCTP route and monitoring the attacker-linked funds. Its report did not announce any recovery agreement, arrest, or confirmed identity for the attacker.
You must be logged in to post a comment Login