Bitget
Across Protocol Exploit Results in $4.5M Loss, User Funds Safe
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 17, 2026, Across Protocol experienced an exploit that led to a loss of approximately $4.5 million due to a bug in the relay software interpreting off-chain events on the Solana network. The attacker fabricated 1,627 fraudulent deposit transactions, tricking the relayer into advancing funds for 581 of these transactions. Despite the significant face value of the fraudulent deposits, user funds remained unaffected, and the core smart contracts were not compromised. The Across team quickly patched the vulnerability within five hours of discovery and confirmed that their scheduled ACX buyback plan would proceed as planned. The incident highlights the importance of auditing all layers of cross-chain bridge infrastructure, especially off-chain components. The remaining fraudulent deposits have been invalidated, and approximately $500,000 of the attacker’s funds are still trapped within the protocol.
Key Points: • Across Protocol lost approximately $4.5 million due to an exploit on July 17, 2026. • User funds were not affected, and the core smart contracts remained secure. • The exploit involved fabricating fraudulent deposit transactions using a bug in relay software.