NewsCryptoAcross Protocol Reports Relayer Attack with Under $4M in Net Losses; User Funds Unaffected

Across Protocol Reports Relayer Attack with Under $4M in Net Losses; User Funds Unaffected

Author: CoinCuΒ·

Key Takeaways

  • β€’Across Protocol reported net losses of under $4 million from a relayer attack, with no user funds compromised at any point.
  • β€’The protocol's architecture requires relayers to advance their own capital for transfers, creating a structural separation that shielded depositor balances from the incident.
  • β€’The event was disclosed through Across Protocol's official X account, with losses explicitly confined to relayer-layer infrastructure.
  • β€’This incident is categorically distinct from major cross-chain bridge exploits like the 2022 Ronin Network and Wormhole attacks, where smart-contract vulnerabilities directly drained user deposits.
  • β€’Across Protocol competes in a bridging market that includes LayerZero, Stargate, and Synapse, and uses UMA's Optimistic Oracle to verify cross-chain transactions.
Across Protocol Reports Relayer Attack with Under $4M in Net Losses; User Funds Unaffected

Across Protocol, a cross-chain bridging solution, disclosed that a relayer attack resulted in net losses of less than $4 million, while user funds remained entirely unaffected by the incident.

The protocol described the event as a relayer attack in a statement posted to its official account on X, attributing the impact to relayer-related activity rather than to end-user wallets. A follow-up statement was also issued via X.

The Role of Relayers in Across Protocol

Relayers are actors within the Across Protocol ecosystem that front their own capital to fulfill user transfer requests on a destination chain before being reimbursed from the source chain. This architectural design means that relayer capital, rather than depositor balances, is the component of the system exposed when an operational failure occurs.

Across framed the incident as affecting protocol infrastructure tied specifically to the relaying process, drawing a clear separation between that layer and end-user balances. The protocol confirmed that the losses were confined within this infrastructure and did not reach funds held or moved by users.

Why User Funds Remained Secure

The central reassurance provided in the protocol's follow-up statement is that deposits and transfers routed through the bridge were not compromised at any point. Because relayers advance their own capital to settle transfers, a shortfall at the relaying layer can produce a loss for the protocol or its relayers without touching the deposits that users bridge across chains.

This structural separation between relayer capital and user deposits is what shielded end-user balances from the incident. The outcome stands in contrast to numerous prior cross-chain bridge incidents across the broader DeFi ecosystem, where smart-contract exploits have directly drained user deposits. Bridge protocols have historically accounted for some of the largest losses in crypto history, including the Ronin Network incident in 2022 (approximately $625 million) and the Wormhole bridge exploit the same year (approximately $326 million), making the distinction between relayer-layer losses and depositor losses a material one for users evaluating bridge risk.

Quantifying the Impact

Across quantified the impact at less than $4 million in net losses. The protocol's use of the term "net" rather than "gross" indicates that the figure reflects the final exposure after any applicable offsets or contained damage, not the total gross value that passed through the affected path.

The protocol did not publish a line-by-line breakdown of gross exposure versus recoveries in the material made available. The disclosed statement supports only the net loss ceiling of under $4 million and the assertion that users were shielded from any losses.

Relayer Risk vs. Smart-Contract Risk

Relayer risk is fundamentally distinct from smart-contract risk. A smart-contract exploit typically drains funds directly from a protocol's contracts, while a relayer-layer loss falls on the capital that those operators post to service transfers. Across' description of the event places it firmly in the latter category.

Even when user funds remain safe, infrastructure-level incidents can affect confidence in cross-chain bridges, a segment of the crypto ecosystem that has repeatedly drawn scrutiny over security concerns. Across, which uses UMA's Optimistic Oracle to help verify cross-chain transactions, competes in a bridging market that includes protocols such as LayerZero, Stargate, and Synapse. The narrow, quantified disclosure from Across represents the protocol's effort to define the boundaries of the incident and contain potential concerns in a sector where transparency and rapid post-incident communication have become critical trust signals for users.

Disclosure and Sources

Across disclosed the incident and the loss figure directly through its official account on X. The protocol's official website is available at across.to.

Key details at a glance:

  • Incident type: Relayer attack
  • Net losses: Less than $4 million
  • User funds affected: No
  • Disclosure platform: Official Across Protocol account on X

Source: CoinCu