Across Protocol hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 17, 2026 |
| Target type | Cross-chain bridge |
| Loss | $4,500,000Published estimates range $3,600,000 to $4,500,000Price at time of incident |
| Method | Contract logic errorForged Solana deposit events. A validation gap in Risk Labs' off-chain event-reading software let the attacker fabricate deposit logs with no corresponding on-chain deposit, which the relayer accepted as genuine and filled with its own capital. Across's on-chain contracts and Solana programs were not compromised. |
| Chains | Solana |
| Outcome | Users reimbursed |
What happened
At about 05:30 UTC on 17 July 2026 an attacker exploited Across Protocol's Solana deployment. Across is an intents-based bridge: relayers front their own capital to fill a user's request on the destination chain and are repaid afterwards once the deposit is verified. The attacker did not break the on-chain contracts. Instead they exploited a validation gap in the off-chain software the Risk Labs relayer used to read Solana deposit events, letting them forge deposit logs that corresponded to no real deposit.
Across's post-mortem, published the following week, says the attacker generated 1,627 fraudulent deposit events with a combined face value of about $41.7m. Only 581 of those were actually filled, paying out roughly $4.5m of relayer capital before the activity was caught. Around $500,000 of the attacker's own capital was left trapped in the protocol, and about $37m of the fake deposits were invalidated before they could settle, so Risk Labs put its net loss at under $4m.
Published figures vary. The post-mortem gives about $4.5m of gross fills and a net position of under $4m once the trapped capital and invalidated deposits are counted; DefiLlama's hacks dataset records the loss as $3.6m, which is consistent with that net figure. The Crypto Times, reporting on the day, noted that no dollar figure had been published at that point.
Because relayers front capital rather than pooling depositor funds, the loss fell entirely on the relayer operated by Risk Labs. Across said all user transfers made during the window either completed or were refunded automatically, that its smart contracts and Solana programs were not hacked, and that it disabled Solana deposits while it patched the event reader, deploying a fix within hours. It published one Solana and two EVM addresses for tracking. No attacker has been identified.
Sources
- Across Protocol / Risk LabsPrimary · retrieved 2026-08-01
- CryptoNewsSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- CryptovkaSecondary · retrieved 2026-08-01
Official post-mortem: https://x.com/AcrossProtocol/article/2080722320814121237
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Across Protocol hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/across-protocolhttps://itokenly.com/hacks/across-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.