A cross-chain attacker forged 1,627 fake Solana deposits worth $41.7 million to trick Across Protocol’s relayer into paying out, marking the first security breach in the $34 billion bridge’s five-year history, though actual losses landed under $4 million.
According to Across Protocol’s post-incident report, the incident targeted Risk Labs’ off-chain relayer rather than Across’s smart contracts or the Solana blockchain itself. The relayer ultimately paid about $4.5 million from its own capital before the protocol halted Solana operations.
However, roughly $500,000 of attacker funds remained trapped inside the system, bringing the reported net loss to less than $4 million.
The incident began at 05:07 UTC on July 17 and continued until approximately 06:14 UTC. During that period, the attacker created 1,627 single-use Solana wallets and used them to manufacture deposit events that the relayer mistakenly treated as legitimate.
How the Across Protocol exploit fooled the relayer
The scale of the attack was striking, but the real concern was where the vulnerability existed.
Rather than exploiting a smart contract, the attacker manipulated the software responsible for reading Solana events off-chain. The fabricated deposits appeared valid to the Risk Labs-operated relayer even though the corresponding transactions had not actually occurred on-chain.
The attacker directed the fraudulent requests toward a single recipient address on an EVM-compatible network, with the fake deposits spread across 18 destination chains.
Risk Labs’ relayer processed 581 of the 1,627 requests before Across suspended Solana activity. Those successful fraudulent requests accounted for approximately $4.5 million in payouts.
That represented only about 35.7% of the fraudulent requests but roughly 10.8% of the total stated value.
Across then invalidated the remaining 1,046 requests, preventing approximately $37 million in additional funds from being released.
The distinction is important. The $41.7 million figure represents the face value of fabricated deposits, not the amount actually stolen.
The Across Protocol exploit therefore resulted in a substantially smaller financial loss than the headline attack value might initially suggest.
Why users did not absorb the loss
Across’s architecture helped contain the damage because relayers, rather than users, provide the liquidity needed to complete transfers.
Relayers advance their own assets to recipients before later claiming repayment. In this case, that mechanism meant Risk Labs’ relayer absorbed the fraudulent payouts instead of legitimate Across users.
Across said genuine transactions were either completed or refunded on July 17. It also said the incident did not compromise user funds or affect the protocol’s planned ACX token buyback.
The attack nevertheless highlights the security risks that can exist outside blockchain smart contracts. While smart-contract audits remain central to DeFi security, cross-chain protocols also depend on off-chain infrastructure that interprets blockchain data and determines when funds should be released.
That infrastructure can become a critical attack surface if event verification is incomplete.
The Across Protocol exploit also differs materially from other recent crypto security incidents. The Lien Finance attack involved a smart-contract validation weakness, while the reported Drift incident involved the subsequent movement of allegedly stolen assets. Across’s case instead centered on falsified blockchain event data being accepted by off-chain software.
CCTP restores Solana transfers
Across moved quickly to restore Solana functionality, deploying a fix for the underlying issue roughly five hours after the attack and returning Solana transfers approximately 12 hours after the incident began.
The protocol shifted Solana order flow to Circle’s Cross-Chain Transfer Protocol, or CCTP.
Circle describes CCTP as an on-chain system that enables native USDC transfers between supported blockchains by burning USDC on the source network and minting the equivalent amount on the destination network. The design avoids conventional bridge liquidity pools and wrapped tokens.
That distinction matters for users moving USDC between Solana and other supported networks. Instead of depending on the compromised Risk Labs event-reading infrastructure, transfers could be routed through CCTP’s native burn-and-mint mechanism.
Across said the incident did not affect USDC reserves or Circle’s minting contracts.
The broader backdrop is also significant for U.S. crypto users. President Donald Trump signed the GENIUS Act into law on July 18, 2025, creating the first federal regulatory framework for payment stablecoins in the United States. The White House said the law requires stablecoin issuers to maintain 100% reserve backing with qualifying liquid assets and make monthly public disclosures about reserve composition.
Those requirements apply to stablecoin issuers and should not be confused with the separate relayer-software vulnerability behind the Across incident.
ACX buyback remains intact after attack
Despite the financial hit, Across said the loss would not alter its planned ACX token buyback.
The market impact on ACX has remained a separate issue from the operational loss. CoinGecko data shows ACX trading around the equivalent of roughly $0.04 in recent market data, although cryptocurrency prices can change rapidly.
The Across Protocol exploit ultimately demonstrates why cross-chain security extends beyond smart-contract code. The attacker did not need to compromise Solana, drain a bridge contract or defeat an on-chain liquidity pool. Instead, forged information was enough to convince a relayer to advance real assets.
That makes the incident a warning for protocols built around intent-based transfers and off-chain verification: the software deciding what happened on-chain can be just as important as the contracts enforcing transactions.
Across has not announced when it will restore its previous Solana routing mechanism. For now, Solana order flow remains routed through CCTP while the protocol works through the consequences of the attack and any potential recovery of funds.
The Across Protocol exploit may have cost less than $4 million in net terms, but its larger significance lies in the security lesson: a cross-chain system can remain technically intact on-chain while an off-chain data-reading failure still creates a multimillion-dollar loss.