NewsCryptoAcross Protocol Relayer Loses Under $4M After Fake Solana Deposit Attack

Across Protocol Relayer Loses Under $4M After Fake Solana Deposit Attack

Author: crypto.news·

Key Takeaways

  • •The attacker fabricated 1,627 Solana deposit events seeking payouts across 18 destination chains.
  • •Risk Labs’ relayer advanced about $4.5 million before Across invalidated the remaining requests, preventing about $37 million in additional payouts.
  • •Across said the breach stemmed from off-chain event-reading software and did not affect smart contracts, Solana, user funds, or valid transfers.
  • •Solana transfer service was restored in about 12 hours through Circle’s Cross-Chain Transfer Protocol.
  • •Across said its planned ACX token buyback would not be affected by the relayer loss.
Across Protocol Relayer Loses Under $4M After Fake Solana Deposit Attack

Across Protocol’s Risk Labs-operated relayer lost less than $4 million after an attacker fabricated $41.7 million in Solana deposit events, according to a post-incident report released by the cross-chain protocol.

The attack involved 1,627 fake deposits with a stated value of $41.7 million and targeted payouts across 18 chains. Risk Labs’ relayer paid about $4.5 million across 581 fraudulent requests before service was suspended. Around $500,000 in attacker funds remained trapped in the protocol, reducing the net loss to below $4 million.

Across said it restored Solana transfers through Circle’s Cross-Chain Transfer Protocol, or CCTP, while user funds and the planned ACX buyback were unaffected.

Attacker forged 1,627 Solana deposit events

The incident took place between 05:07 and 06:14 UTC on July 17, according to the Across Protocol post-mortem. The attacker used 1,627 single-use Solana wallets to generate the same number of fake deposit events.

Those deposits had a combined face value of approximately $41.7 million and requested payments across 18 destination chains. Across said the funds were routed toward a single recipient address on an Ethereum Virtual Machine-compatible network.

Risk Labs’ relayer fulfilled 581 requests before Across halted Solana operations. Those payments accounted for about 35.7% of the fraudulent requests, but only 10.8% of their claimed value.

The relayer advanced approximately $4.5 million of its own capital. Across then invalidated the remaining 1,046 requests, preventing roughly $37 million in additional payouts.

About $500,000 belonging to the attacker remained trapped inside the protocol. Across deducted that amount from the gross payout, bringing the net loss to less than $4 million.

Why users were not responsible for the loss

Across attributed the breach to a flaw in Risk Labs’ off-chain event-reading software, not to a vulnerability in its smart contracts. The protocol also said the attacker did not compromise the Solana network.

Across relies on relayers that advance their own assets to complete cross-chain transfers before later claiming repayment. That design left Risk Labs’ relayer responsible for the loss, rather than users who had submitted legitimate transactions.

The distinction matters because many bridge and intent-based systems depend on off-chain components, including relayers, indexers, and event readers, in addition to on-chain contracts. In this case, Across said the failure was in the infrastructure that interpreted Solana events, while the contracts and legitimate user transfers remained unaffected.

According to Across, all valid transfers were completed or fully refunded on July 17. The protocol’s website says it has processed more than $34 billion in transfers without reporting a loss of user funds.

The Across incident differed from the Lien Finance exploit reported by crypto.news on July 24. SlowMist found that Lien’s attacker exploited a smart contract validation flaw to mint unsupported bond tokens and withdraw approximately 542,144.63 USDC.

crypto.news also reported that a wallet linked to the $285 million Drift Protocol exploit moved 23,095.1 ETH, worth about $44.4 million, through Tornado Cash on July 23 and July 24. The incidents involved different methods: an off-chain software failure at Across, faulty contract logic at Lien, and post-exploit laundering tied to Drift.

CCTP routing restored Solana transfers

Across restored Solana service in approximately 12 hours by routing transfers through Circle’s Cross-Chain Transfer Protocol. The protocol said its engineers deployed the root-cause fix about five hours after the attack.

The change has a direct U.S. connection because Circle issues USDC and operates CCTP. Circle states that CCTP burns native USDC on the source network and mints the same amount on the destination network without using traditional bridge liquidity pools or third-party fillers.

For U.S. users moving USDC to or from Solana, the fallback allowed transfers to resume without relying on the affected Risk Labs event reader. According to Across’ findings, the breach did not involve USDC reserves or Circle’s minting contracts.

The shift also came after the United States established its first federal payment-stablecoin framework through the GENIUS Act. The law requires permitted issuers to maintain qualifying reserves and publish regular disclosures, according to a White House fact sheet. Those rules apply to stablecoin issuers, rather than to the separate relayer software that caused the Across loss.

ACX buyback remains unaffected

ACX traded near $0.041 after the post-mortem, with a market capitalization of about $29 million, according to CoinGecko. The token remained more than 97% below its all-time high.

Across said the loss would not affect its planned ACX token buyback. However, the protocol did not disclose whether Risk Labs would change its relayer funding, monitoring systems, or operating limits.

Solana order flow remains routed through CCTP. Across has not provided a timeline for returning to its previous routing system and has not announced the recovery of any additional funds.