Cross-chain bridge protocol Across (ACX) disclosed on July 17 that it suffered an exploit resulting in the loss of approximately $4.5 million. The team confirmed that user funds were not compromised and remain safe. The incident was attributed to a bug in the relay software responsible for reading off-chain events on the Solana (SOL) network.
How the Exploit Occurred
According to an official statement posted on Across’s X account, the attacker exploited a vulnerability in the relay software that interprets off-chain deposit events on Solana. By forging deposit events that never actually occurred, the attacker tricked the relayer into treating them as legitimate transactions. This caused the relayer to pay out its own funds, draining approximately $4.5 million from the relayer’s reserves. Across emphasized that its core smart contracts and Solana programs were not hacked or compromised in any way.
Immediate Response and Patch
The Across team detected the issue quickly and deployed a patch within five hours of discovery. The fix addressed the specific vulnerability in the relay software, preventing further exploitation. The team also confirmed that the scheduled ACX buyback plan will proceed as planned, unaffected by the incident. No user funds were at risk at any point during the exploit.
Broader Implications for Cross-Chain Security
This incident highlights the growing complexity of cross-chain bridge security, particularly when integrating with networks like Solana that rely on off-chain event processing. While the core smart contracts remained secure, the vulnerability in the off-chain relay software underscores the importance of auditing all layers of a bridge’s infrastructure, not just on-chain components. The exploit did not affect Across’s Solana bridge contracts themselves, but rather the external software used to relay data between chains.
Conclusion
The Across Protocol exploit serves as a reminder that security in decentralized finance extends beyond smart contracts to include off-chain infrastructure. The team’s rapid response and transparent disclosure helped contain the damage and maintain user trust. With user funds fully protected and the buyback plan continuing, Across appears to have weathered the incident without lasting operational disruption.
FAQs
Q1: Were any user funds lost in the Across exploit?
A1: No. Across confirmed that no user funds were affected. The loss was limited to the relayer’s own funds.
Q2: Was the Across smart contract or Solana program hacked?
A2: No. The exploit targeted a bug in the relay software that reads off-chain events, not the core smart contracts or Solana programs.
Q3: Will the ACX buyback plan continue as scheduled?
A3: Yes. Across stated that the buyback plan will proceed as planned, unaffected by the incident.
Related Reading
- Kinetic Group Plans $11.7M Open Market Purchase of FLUID Tokens to Boost Institutional DeFi
- Uniswap Launches Permissioned Pools for v4, Enabling Compliant Asset Trading on AMMs
- Token Holder Payouts Hold Steady Despite 33% Drop in Onchain Fee Revenue
- Whale or Institution? $88.2M in HYPE Staked Across Eight Wallets
- AFX Trade on Arbitrum Exploited for $24.15 Million in USDC
coinfomania.com
en.cryptonomist.ch