Image default
News

Across Protocol relayer loses under $4M in Solana attack

Across Protocol relayer loses under $4M in Solana attack插图

Across Protocol’s Risk Labs-operated relayer lost less than $4 million after an attacker fabricated $41.7 million in Solana deposit events, according to a post-incident report released by the cross-chain protocol.

Summary

  • 1,627 fake deposits worth $41.7 million targeted 18 chains during the Solana attack.
  • Risk Labs’ relayer paid $4.5 million across 581 fraudulent requests before suspending service.
  • Around $500,000 in attacker funds remained trapped, reducing the net loss below $4 million.
  • Across restored Solana transfers through CCTP, while user funds and the ACX buyback remained unaffected.

Across attacker forged 1,627 Solana deposits

The attack occurred between 05:07 and 06:14 UTC on July 17, according to the Across Protocol post-mortem. The attacker used 1,627 single-use Solana wallets to create the same number of fake deposit events.

Those deposits carried a combined face value of approximately $41.7 million and requested payments across 18 destination chains. Across reported that the funds were directed toward one recipient address on an Ethereum Virtual Machine-compatible network.

Risk Labs’ relayer filled 581 requests before Across stopped Solana operations. Those payments represented about 35.7% of the fraudulent requests but only 10.8% of their stated value.

The relayer advanced approximately $4.5 million of its own capital. Across invalidated the remaining 1,046 requests, preventing about $37 million in additional payouts.

Approximately $500,000 belonging to the attacker remained trapped within the protocol. Across deducted that amount from the gross payout to place its net loss below $4 million.

Why Across users avoided the relayer loss

Across attributed the breach to a flaw in Risk Labs’ off-chain event-reading software rather than a vulnerability in its smart contracts. The protocol also reported that the attacker did not compromise the Solana network.

Across uses relayers that advance their own assets to complete cross-chain transfers before claiming repayment. That structure left Risk Labs’ relayer responsible for the loss instead of users who had submitted legitimate transactions.

All valid transfers were completed or fully refunded on July 17, according to Across. The protocol’s website shows that it has processed more than $34 billion in transfers without reporting a loss of user funds.

The incident differed from the Lien Finance exploit reported by crypto.news on July 24. SlowMist found that Lien’s attacker exploited a smart contract validation flaw to mint unsupported bond tokens and withdraw approximately 542,144.63 USDC.

crypto.news also reported that a wallet linked to the $285 million Drift Protocol exploit moved 23,095.1 ETH, worth about $44.4 million, through Tornado Cash on July 23 and July 24. Together, the incidents involved separate attack methods: off-chain software failure at Across, faulty contract logic at Lien, and post-exploit laundering tied to Drift.

What the CCTP shift means for US users

Across restored Solana service in approximately 12 hours by routing transfers through Circle’s Cross-Chain Transfer Protocol. The protocol reported that its engineers deployed the root-cause fix about five hours after the attack.

The change has a direct U.S. connection because Circle issues USDC and operates CCTP. Circle states that CCTP burns native USDC on the source network and mints the same amount on the destination network without using traditional bridge liquidity pools or third-party fillers.

For U.S. users moving USDC to or from Solana, the fallback allowed transfers to resume without relying on the affected Risk Labs event reader. The Across breach did not involve USDC’s reserves or Circle’s minting contracts, according to the protocol’s findings.

The shift also comes after the United States established its first federal payment-stablecoin framework through the GENIUS Act. The law requires permitted issuers to maintain qualifying reserves and publish regular disclosures, according to a White House fact sheet. Those rules govern stablecoin issuers rather than the separate relayer software that caused the Across loss.

ACX buyback remains unchanged

ACX traded near $0.041 after the post-mortem, with a market capitalization of about $29 million, according to CoinGecko. The token remained more than 97% below its all-time high.

Across stated that the loss would not affect its planned ACX token buyback. However, the protocol did not disclose whether Risk Labs would change its relayer funding, monitoring systems or operating limits.

Solana order flow remains routed through CCTP. Across has not provided a timeline for returning to its earlier routing system or announced the recovery of any additional funds.

News,Cyber Attack,DeFi Exploit,Solana#Protocol #relayer #loses #Solana #attack1784981334

Related posts

Bitcoin ETFs Post 8 Straight Days of Inflows Worth $2.1 Billion as BlackRock Absorbs 75% of All Flows

admin

What is Lighter? Robinhood’s perps DEX

admin

Inveniam to acquire MANTRA, combining tokenized asset infrastructure with AI-ready private market data

admin

Leave a Comment