Across releases security incident report: net loss below $4 million, user funds not affected

robot
Abstract generation in progress

PANews July 25, Across Protocol, a cross-chain protocol, released a post-incident report on the Relayer Security Event. On July 17, the attacker exploited a vulnerability in the software used in Risk Labs’ Solana off-chain incident to read the data, and forged 1,627 fake top-up events with a total face value of approximately $41.7 million. Before pausing Solana services, the Relayer completed advances for 581 of those events, involving about $4.5 million in its own funds; of that, approximately $0.5 million in the attacker’s funds was trapped within the protocol, and net losses were below $4 million. The remaining approximately $37 million in fake top-ups had been invalidated.

Across emphasized that user funds were never lost or at risk at any time. All users’ transfers had been completed or fully refunded on the same day, and all losses had been reduced to the minimum extent to which Risk Labs’ relayer itself incurred losses. In addition, no smart contracts were exploited. The Solana programs and all EVM contracts were operating as expected. The vulnerability lies in the Risk Labs relayer’s code repository. At present, Solana order flow has been switched to be routed entirely via CCTP; the acquisition of ACX is unaffected and will continue as planned.

Previously, Across said it was attacked on Solana, and user funds were not impacted.

ACX-1.62%
SOL-2.75%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned