Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Markets

Across Protocol Just Broke Its Zero-Exploit Streak on Solana

Risk Labs' relayer absorbed Friday's loss, sparing user deposits and keeping the intent-based architecture's central promise intact after nearly five years and $34 billion of bridge volume.

By Aubrey Swanson··4 min read
Across Protocol Just Broke Its Zero-Exploit Streak on Solana

Key Points

  • Risk Labs' relayer absorbed Friday's loss, sparing user deposits and keeping the intent-based architecture's central promise intact after nearly five years and $34 billion of bridge volume.

Cross-chain bridge Across Protocol confirmed on Friday that its Solana deployment was attacked at roughly 5:30 AM UTC, ending a nearly five-year record of zero exploits across more than $34 billion in bridged volume since launch. User funds were not touched. The loss sits entirely on the Risk Labs relayer, the foundation-operated participant in Across's otherwise permissionless relayer network that fills user transfers on the destination chain.

Across runs on an intent-based model in which relayers front their own capital on the destination chain to fill user transfers instantly, then are repaid through settlement on Ethereum verified by UMA's optimistic oracle. Users never hand custody of their assets to a pooled bridge contract that can be drained. When something goes wrong on the fill side, it is the relayer's at-risk capital that absorbs the hit, not user deposits. Friday's incident is the first live stress test of that thesis under attack, and the containment held.

The team published three attacker addresses tied to the incident and said it is coordinating the trace with SEAL 911, the whitehat emergency response group that has become the industry's first call during a live security incident. One address sits on Solana; two are on Ethereum. The split suggests the attacker has already begun consolidating value across chains, a standard laundering pattern in bridge-adjacent incidents.

Advertisement

728×90

Solana deposits are paused while the team investigates, and every other function of the protocol continues to operate. Neither Across nor any independent investigator has published a dollar figure for the relayer's loss, and no attribution has been made. A full post-mortem is expected in the coming days.

The Solana leg was always the exposed edge. Solana only became a supported destination in July 2025 through the V4 upgrade, Across's first move beyond EVM chains, with the SVM spoke pool built on the Anchor framework. In April 2026, security firm Asymmetric Research disclosed a vulnerability in exactly this part of the stack: because Solana has no canonical event system and events are often reconstructed from transaction traces, with failed transactions still emitting data, a bug in Across could have allowed attackers to spoof deposit events and trick relayers into filling orders with no real deposit behind them. Across patched that issue immediately and no funds were lost at the time, but the disclosure named the trust boundary between Solana's on-chain state and the off-chain relayer software as the delicate seam in the system.

Whether Friday's attack exploited a similar class of event-handling issue, a flaw in the relayer bot infrastructure, or a compromised operator key will only be confirmed by the post-mortem. What can be said is that the profile fits relayer-side risk rather than a spoke pool drain, since user-facing bridge contracts continued to settle transactions normally throughout.

The comparison to earlier bridge failures is unavoidable. Wormhole lost $320 million from its Solana vault in 2022 through a signature-verification bug in the wrapped-Solana contract, and THORChain was drained for $8 million via a bug in its cross-chain swap logic. In both cases the loss sat on user-facing custody. Across's design, at least this time, forced the hit onto the professional operator that chose to run a relayer, not the retail users who bridged through it.

The DeFi security backdrop is unforgiving. This year's largest losses on Solana have come from operational compromises rather than smart-contract bugs, with the pattern set in dramatic form by Drift Protocol's April incident, which stripped roughly $285 million from the exchange and was traced to social engineering and admin-key abuse rather than a bytecode flaw. It is the same rough shape as the $1.4 billion Bybit theft attributed to North Korea's Lazarus Group earlier in the year: the wallet was fine, the humans and processes around it were not.

For Across, the reputational stakes are specific. The protocol has marketed itself for years on a perfect security record, and its intent-based design was repeatedly cited as the reason there was no pooled liquidity for an attacker to take. Friday's incident does not break the user-safety thesis, since no user lost funds, but it does show that the solver and relayer layer carries real capital at risk, and that the entity absorbing the loss this time is the foundation at the centre of the project. Risk Labs now has to eat the bill. Its size, and whether any of the flagged addresses can be frozen at an exchange deposit before the funds are consolidated, will decide how badly the balance sheet gets hit. The user-safety claim survived. The zero-exploit record did not.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.