Attack on Across Cross-Chain Bridge Protocol
The Across protocol experienced an attack on its Solana deployment, but user funds were not lost. The incident involved spoofing deposit signals, affecting the Risk Labs-operated relayer.
On July 17, 2026, the Across cross-chain bridge protocol was attacked on its Solana deployment. The attacker exploited a vulnerability in Solana’s event system, allowing them to spoof deposit signals and deceive relayers into processing fake deposits. Despite the attack, user funds remained completely safe, with no losses reported, as all transactions were either completed or fully refunded.
The incident resulted in losses being confined to the Risk Labs-operated relayer. In response, the Across team paused Solana deposits and resumed operations the following day. A full post-mortem of the incident is planned to analyze the attack and improve security measures.
Sources
- Source reportrestates another report