Wednesday, July 29, 2026

Across Protocol Solana Exploit Results in $3.6M Drain, Partial Refund Issued

Neon cyber-art depicting a Solana bridge breach with a glowing lock and cascading coins in cyan and purple hues.

The attacker behind the recent exploit affecting Across Protocol’s Solana operations has returned 331.8 ETH to the protocol’s Hub Pool Owner Multisig. The transfer was valued at approximately $623,900 when PeckShield identified it on July 28, representing a partial recovery from the incident earlier in the month.

Across has not disclosed a final unrecovered balance following the refund. Its incident accounting showed that the Risk Labs-operated relayer advanced approximately $4.5 million across fraudulent requests, while about $500,000 belonging to the attacker remained trapped within the protocol. The official net loss was therefore below $4 million even before the latest ETH return, rather than a fixed $3.6 million final figure.

Forged Events Targeted the Offchain Relayer

The July 17 attack generated 1,627 fabricated deposit events from the same number of single-use Solana wallets between 05:07 and 06:14 UTC. The requests carried a combined face value of approximately $41.7 million and sought payouts across 18 destination chains. Risk Labs’ relayer fulfilled 581 of the fraudulent requests before Across disabled Solana routing, preventing roughly $37 million in additional attempted payouts.

The vulnerability was located in software used to interpret Solana events, not in Across’s onchain contracts. The relayer’s SvmCpiEventsClient accepted inner instructions directed through the Solana SpokePool’s event-authority address as genuine events without verifying the required eight-byte Anchor event discriminator. That missing validation allowed the attacker to construct instructions that appeared legitimate to the offchain reader even though no corresponding deposits occurred onchain.

Across said neither its smart contracts nor the Solana network itself was compromised. The attacker exploited the difference between the state recorded by the blockchain and the information accepted by the relayer’s monitoring software. The incident demonstrates that offchain parsing and automation can become critical security boundaries even when the underlying contracts behave as intended.

Users were protected by Across’s intent-based architecture, in which relayers advance their own assets on the destination chain before seeking reimbursement through the protocol’s settlement process. The fraudulent requests depleted capital controlled by Risk Labs’ relayer rather than assets deposited by bridge users. Across said every legitimate transfer affected by the interruption was completed or fully refunded on July 17.

Partial Recovery Leaves Final Loss Unresolved

The return of 331.8 ETH reduces the amount remaining under the attacker’s control, but it does not establish the final financial impact. Asset-price changes, funds already trapped within the system and any additional recoveries can all affect the eventual calculation. Across has not confirmed that the transfer represents a negotiated settlement, voluntary refund or complete end to the recovery process.

Across responded to the attack by disabling Solana as an origin and destination chain through its API and pausing the Solana SpokePool. Engineers merged the root-cause fix and deployed it across Risk Labs infrastructure within several hours. Solana deposits resumed at 17:05 UTC through fallback routing based on Circle’s Cross-Chain Transfer Protocol, approximately 12 hours after the first fraudulent request.

The restoration did not immediately return every Solana route to its previous configuration. Across routed Solana order flow exclusively through CCTP while keeping its intent-based Solana routing disabled for further review. The protocol resumed supported USDC transfers through a different settlement pathway rather than simply reactivating the affected relayer system unchanged.

Circle’s CCTP transfers native USDC by burning tokens on the source blockchain and minting the corresponding amount on the destination network. The mechanism does not depend on traditional wrapped-token liquidity pools, giving Across an alternative route while its Solana event-processing architecture undergoes additional inspection.

Across has been working with the SEAL 911 emergency-response network and other parties to monitor attacker-linked addresses and pursue additional recovery. The technical post-mortem has already identified the event-validation failure and documented the containment timeline, although further disclosures may clarify the disposition of the remaining assets. The central unresolved issue is now recovery rather than the basic cause of the exploit.

The incident ultimately exposed a narrow but consequential weakness in the software connecting Solana events to Across’s relayer operations. The partial ETH refund improves the financial outcome without removing the need for stronger validation across offchain infrastructure. Final recovery figures will depend on whether additional attacker-controlled funds can be returned, frozen or otherwise secured.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.