Across Protocol Exploit Results in $4.5M Loss, User Funds Safe

Across Protocol Exploit Results in $4.5M Loss, User Funds Safe

First seen 26 Jul 2026, 16:04 UTC KucoinBitget 82% similarity 51.1

Article Content

Browse articles
ThreatCluster

On July 17, 2026, Across Protocol experienced an exploit that led to a loss of approximately $4.5 million due to a bug in the relay software interpreting off-chain events on the Solana network. The attacker fabricated 1,627 fraudulent deposit transactions, tricking the relayer into advancing funds for 581 of these transactions. Despite the significant face value of the fraudulent deposits, user funds remained unaffected, and the core smart contracts were not compromised. The Across team quickly patched the vulnerability within five hours of discovery and confirmed that their scheduled ACX buyback plan would proceed as planned. The incident highlights the importance of auditing all layers of cross-chain bridge infrastructure, especially off-chain components. The remaining fraudulent deposits have been invalidated, and approximately $500,000 of the attacker’s funds are still trapped within the protocol.

Key Points: • Across Protocol lost approximately $4.5 million due to an exploit on July 17, 2026. • User funds were not affected, and the core smart contracts remained secure. • The exploit involved fabricating fraudulent deposit transactions using a bug in relay software.

ThreatCluster AI

Timeline

2026-07-17
Across Protocol exploit occurred
Attackers exploited a vulnerability in the relay software, resulting in a loss of $4.5 million.
Bitget
2026-07-17
Fraudulent transactions fabricated
The attacker created 1,627 fake deposit transactions, tricking the relayer into advancing funds.
Kucoin
2026-07-17
Quick patch deployed
Across team patched the vulnerability within five hours of discovering the exploit.
Bitget
2026-07-25
Post-incident report released
Across Protocol confirmed the net loss was under $4 million after invalidating fraudulent deposits.
Kucoin

Community

Browse all →