Across Protocol has confirmed that a relayer operated by Risk Labs has suffered a loss of just under $4m, after an attacker manufactured tens of millions of dollars’ worth of fake Solana deposit events and triggered cross-chain transfers.
The cross-chain bridge provider detailed the incident in a post-mortem, explaining that the attack took place on 17 July between 05:07 and 06:14 UTC. During that period, the attacker created 1,627 single-use Solana wallets and used each one to generate a bogus deposit event.
On paper, those fabricated deposits were worth around $41.7m and requested transfers to 18 different destination blockchains. Across said all of the resulting payouts were directed to a single recipient address on an Ethereum Virtual Machine-compatible network.
Risk Labs’ relayer – a component that fronts its own capital to complete user transfers – honoured 581 of those fake requests before Across halted all Solana-related operations. Although those 581 transactions represented about 35.7% of the fraudulent requests by number, they accounted for only 10.8% of the total claimed value.
In total, the relayer advanced roughly $4.5m of its own funds before the exploit was stopped. Across then invalidated the remaining 1,046 fraudulent requests, blocking around $37m of additional outflows.
Around $500,000 that belonged to the attacker was left stranded inside the protocol. Across said it netted that amount off the gross payout, bringing the final loss figure for Risk Labs’ relayer to below $4m.
Off-chain software flaw, not smart contract bug
Across stressed that the root cause was a weakness in Risk Labs’ off-chain event-reading software, rather than an error in Across’ on-chain smart contracts. The protocol also said there was no compromise of the Solana network itself.
Across operates using relayers that temporarily advance their own assets to fulfil cross-chain transfers, then later claim reimbursement. Because of that model, the financial damage has fallen on Risk Labs’ relayer and not on users who made genuine transfers.
The protocol said all legitimate transactions were either completed as intended or fully refunded on 17 July. Across’ website states that it has processed more than $34bn in transfers to date without reporting any loss of user funds.
Contrast with other recent crypto exploits
Across highlighted that the incident was distinct from the Lien Finance exploit reported by crypto.news on 24 July. In that case, security firm SlowMist concluded that Lien’s attacker abused a smart contract validation issue to mint unsupported bond tokens and withdraw approximately 542,144.63 USDC.
crypto.news has also reported that a wallet linked to the $285m Drift Protocol exploit moved 23,095.1 ETH – worth around $44.4m – through Tornado Cash on 23 and 24 July. Together, the cases showcase three separate strands of malicious activity: an off-chain software failure at Across, a contract validation bug at Lien, and post-exploit laundering activity attributed to the Drift incident.
Solana service restored via Circle’s CCTP
Across said it restored Solana support within about 12 hours by diverting transfers through Circle’s Cross-Chain Transfer Protocol (CCTP). Engineers deployed the underlying software fix roughly five hours after the attack was detected, according to the post-mortem.
Circle, which issues USDC and operates CCTP, says the system works by burning native USDC on the sending chain and minting an equivalent amount on the receiving chain, avoiding traditional bridge liquidity pools and third-party fillers.
For US users moving USDC into or out of Solana, this contingency route allowed transfers to resume without touching the compromised Risk Labs event-reading infrastructure. Across reported that the breach did not extend to USDC’s reserves or Circle’s minting contracts.
The shift to CCTP comes soon after the United States enacted its first federal framework for payment stablecoins under the GENIUS Act. According to a White House fact sheet, the law obliges approved issuers to hold qualifying reserves and publish regular disclosures. These obligations apply to stablecoin issuers and not to separate relayer software such as the Risk Labs system involved in the Across loss.
Token impact and unresolved questions
Following publication of the post-incident analysis, Across’ native token ACX was trading around $0.041, giving it a market capitalisation of roughly $29m, according to CoinGecko – more than 97% below its historical peak.
Across said the financial hit to the Risk Labs relayer would not derail its planned ACX token buyback programme. However, the protocol did not say whether Risk Labs intends to alter how it funds its relayers, nor did it outline any new monitoring mechanisms or changes to operating limits.
At present, all Solana order flow handled by Across continues to be routed through CCTP. The protocol has not set out a timetable for reinstating its previous routing system and has not announced the recovery of any further funds connected to the exploit.
