Incident case file
Sign in to watchTaiko Bridge — Leaked SGX Signing Key Forged-Proof Drain
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatT-X (undisclosed, prior to June 21): SGX enclave signing key (enclave-key.pem, RSA-3072) is exposed in the public taikoxyz/raiko GitHub repository. T0 (June 21, 2026, setup tx at block 25367938, ~19:03:59 UTC): Attacker registers a rogue prover using the leaked key. T+~3h (22:07:23 UTC, June 21): First forged-proof release transaction executes (release tx 1). T+~3h11m (22:18:23 UTC, June 21): Second release transaction executes (release tx 2). T+overnight: Blockaid detects the ongoing attack; Taiko's official X account (@taikoxyz) confirms a compromise of the chain-state verification mechanism in the early hours of June 22, 2026 (~00:44-00:49 UTC), urging all users to withdraw from every bridge on the network. T+June 22, ~02:00-02:08 ET: Block production halted; BlockSec Phalcon publishes technical analysis confirming the SGX key leak as root cause; Upbit, Bithumb and KuCoin suspend TAIKO deposits/withdrawals. T+June 23-24: Four 'respond-to-hack' PRs merged on GitHub; Taiko Security Council activated; CEO files report with Singapore authorities. T+June 25, 2026: Taiko announces plan to fully restore/recollateralize the bridge 1:1 from treasury before reopening (last documented activity for this incident).
Sources and coverage
- Articlethedefiant.iohttps://thedefiant.io/news/hacks/taiko-bridge-exploit-sgx-signing-key-github-1-7m
- Articlecryptonews.nethttps://cryptonews.net/news/security/33043483/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/25/taiko-to-fully-restore-bridge-backing-after-1-7m-hack/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlex.comhttps://x.com/taikoxyz
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)