← Radar

Incident case file

Sign in to watch

Across Protocol — Solana Relayer Exploit (Risk Labs Capital Only, User Funds Safe)

Incident date July 17, 2026

8 views

ContainedSolana (relayer side); Ethereum and Base bridges unaffectedCross-chain bridge / relayer exploit (vector pending post-mortem)Cluster: ACR-BRG-2026-07

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: Solana attacker address: 8bkoZToaTBBtAPczgHqD4XVxWtvBkiy4crtexEtYDYSL. Ethereum attacker address 1: 0xa0C0e9f307b5A26cA3FB5891c19154fc7A02BeF7. Ethereum attacker address 2: 0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189. Presence of both Solana and EVM addresses suggests laundering pattern where proceeds are consolidated on Ethereum before further routing to mixers or exchange deposit addresses. No public attribution.

Funds moved to: Dollar figure of Risk Labs relayer loss NOT publicly disclosed as of July 17-18 — official post-mortem announced 'in the coming days.' No user funds affected — all in-flight bridge transactions completed successfully. Cash-out path from the 3 flagged addresses under active trace by SEAL 911. Consolidation from Solana to Ethereum already observed based on presence of both Solana and EVM addresses.
3 attacker addresses under SEAL 911 tracing: Solana 8bkoZToaTBBtAPczgHqD4XVxWtvBkiy4crtexEtYDYSL, Ethereum 0xa0C0e9f307b5A26cA3FB5891c19154fc7A02BeF7, Ethereum 0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189. Across SVM spoke pool (Anchor framework, deployed with Across V4 in July 2025 as the first non-EVM expansion). Risk Labs relayer wallet(s) — exact address not published. UMA oracle contract (Across uses optimistic verification: transactions assumed valid unless challenged within dispute window

Timeline: April 2026: Asymmetric Research discloses a vulnerability in the Across SVM spoke pool (event spoofing possible because Solana lacks a canonical event system and events are reconstructed from tx traces, with failed transactions still emitting data). Across patches the issue immediately — no funds lost, but the disclosure highlights that 'the trust boundary between Solana's on-chain state and the off-chain relayer software watching it is the most delicate seam in the system.' July 17, 2026 ~05:30 UTC: attack detected on Across Solana deployment. ~05:35 UTC: Solana deposits disabled as a precautionary measure. All in-flight bridge transactions were completed successfully for users. 11:36 AM UTC (July 17): Across posts official statement on X (tweet 2078036118209982566, 62.9K views): 'At ~5:30 AM UTC today, Across was attacked on Solana. User funds are safe. No users were affected, and all bridge transactions have been completed. Solana deposits have been disabled. The protocol is otherwise operating unaffected. The only funds potentially lost belong to the relayer operated by Risk Labs (the foundation supporting Across).' Follow-up ~11:05 UTC (July 17, 4:35 PM IST): 'your funds are safe and refunds will process automatically,' directing users to support.across.to, warning against phishing links. Across confirms cooperation with SEAL 911 to trace the 3 flagged addresses (1 Solana + 2 Ethereum). July 18, 2026: coverage by Crypto Times, Crypto Briefing, KuCoin, MarsBit, boerse-global.de. Crypto Times explicitly notes: 'Neither Across nor any independent investigator has published a dollar figure for the relayer's loss at the time of writing, and no attribution has been made.' Full post-mortem pending — Across states it will follow 'in the coming days.' Analysis question raised across coverage: was this the same class of issue as the April 2026 event handling bug, a flaw in the relayer bot infrastructure, or a compromised key? Only the post-mortem will confirm. Architecture context: Across V4 launched Solana support in July 2025 via SVM spoke pool on the Anchor framework. Intent-based model: relayers front their own capital on the destination chain to fill user transfers instantly, then are repaid via UMA optimistic oracle settlement. Users never hand custody to a pooled bridge contract — this design philosophy held here, users were not exposed. Track record before this incident: >$34-35B cumulative bridge volume with zero prior exploits since 2021 launch.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)