T
iTokenly

Taiko Bridge hack — June 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 22, 2026
Target typeCross-chain bridge
Loss$1,700,000Published estimates range $1,000,000 to $1,700,000Price at time of incident
MethodSignature verification flawTaiko's Bridge delegated authentication of source-chain messages to its SignalService, which accepted a Merkle proof against any saved checkpoint without independently verifying the source chain, and applied no finality delay to newly registered SGX prover instances. The attacker registered a prover instance, wrote a checkpoint of their choosing and proved fabricated withdrawal messages against it. BlockSec attributed the ability to produce valid attestations to an SGX enclave signing key for Raiko, Taiko's multi-prover stack, left publicly accessible in the project's GitHub repository.
ChainsEthereum
OutcomeUsers reimbursed

What happened

Taiko, an Ethereum layer-2 rollup, lost roughly $1.7 million on 21 June 2026 when an attacker produced forged proofs that its Ethereum-side bridge accepted as evidence of withdrawals that had never been initiated on the layer 2. The incident became public the following day.

Taiko's Bridge contract delegated authentication of source-chain messages to its SignalService, which would accept a Merkle proof against any saved checkpoint without independently verifying the source chain. The attacker registered a fresh SGX prover instance and used it immediately. DARKNAVY's analysis notes the accepted checkpoint was produced right after registration, with no finality delay, letting the attacker write a checkpoint of their choosing and then prove fabricated messages against it, draining the L1 Bridge and ERC20Vault. BlockSec attributed the ability to sign valid attestations to an SGX enclave signing key for Raiko, Taiko's multi-prover stack, that had been left publicly accessible in the project's GitHub repository. The two accounts are complementary: the exposed key supplied a valid signer, and the missing checkpoint validation let that signer be used at once.

Assets taken included roughly 676,000 USDC, 138,000 USDT, 157,000 crvUSD, about 150 ETH and WETH combined, and 1.99 million TAIKO, alongside smaller amounts of WBTC, CRV and other tokens. Blockaid, which flagged the attack in real time, put the confirmed impact at $1 million or more, while $1.7 million is the figure Taiko and most reporting used. Around 2 million TAIKO, worth roughly $170,000, reached the MEXC exchange before containment.

Taiko halted block production and paused the bridge and vault. On 2 July 2026 it reopened the bridge after a four-stage recovery covering the patch, replenishment of bridge reserves to full 1:1 backing, restoration of layer-2 activity and an independent security review, saying every user had been made whole. Losses were covered by restoring 1:1 backing, not by recovering the stolen funds.

Sources

  1. DARKNAVYSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. thirdwebSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Taiko Bridge hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/taiko-bridge
https://itokenly.com/hacks/taiko-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.