Across Solana Relayer Lost $4.5M in Forged Deposit Attack on July 17

SOL-2.86%
ACX-1.00%
Key Takeaways
  • Risk Labs' Solana relayer lost $4.5 million on July 17, 2026, after attacker forged 1,627 deposit events.
  • Attacker exploited missing eight-byte Anchor event discriminator check to create $41.7 million in fraudulent withdrawal requests.
  • Risk Labs disabled Solana routing, deployed fix within five hours, and restored full service within twelve hours.

Risk Labs' Solana relayer lost approximately $4.5 million on July 17, 2026, when an attacker exploited a missing eight-byte check in offchain event-parsing code to forge 1,627 deposit events that never occurred on-chain. The vulnerability allowed fraudulent withdrawal requests totaling roughly $41.7 million in face value, of which 581 were filled before the team disabled Solana routing and deployed a fix within five hours of detection. No user funds were lost or at risk because Across operates as an intents protocol where relayers advance their own capital rather than drawing from shared user escrow, containing the entire financial impact within Risk Labs' operational reserves.

Missing Discriminator Check Enabled Forged Deposit Events

The vulnerability existed in the SvmCpiEventsClient component of the Risk Labs relayer, which accepted any inner instruction addressed to the SpokePool contract through its event_authority PDA as a genuine event without verifying the 8-byte Anchor event discriminator. The attacker deployed a wrapper program that invoked a benign read-only SpokePool helper function—get_unsafe_deposit_id—and appended forged FundsDeposited payloads to it. From the relayer's perspective these appeared as legitimate deposit events, though no funds moved on-chain, no balances changed, and no contracts were touched. Risk Labs clarified that get_unsafe_deposit_id was not itself the vulnerability but simply a carrier the attacker used; the root cause was the missing discriminator check in the relayer's code base.

Attacker Submitted 1,627 Forged Deposits Across 18 Chains

Between 05:07 and 06:14 UTC on July 17, the attacker submitted 1,627 forged deposits from 1,627 single-use wallets, spreading them across 18 destination chains with a face value of approximately $41.7 million consolidating to a single EVM recipient address. Risk Labs' relayer filled 581 of those fraudulent requests, paying out roughly $4.5 million of its own capital before the team disabled Solana as an origin chain. The remaining approximately $37 million in forged deposits expired worthless once the relayer stopped filling them. No smart contracts were compromised; the Solana programs and all EVM contracts behaved exactly as designed throughout the incident.

Intents Protocol Design Prevented User Fund Loss

No user funds were lost at any point during the incident. Across operates as an intents protocol where users deposit assets into an escrow contract on the origin chain and independent relayers advance their own capital to fulfill transfers on the destination chain. The protocol only reimburses relayers after a separate settlement process verifies each deposit they filled, meaning the forged deposits never touched user escrow. Every real user deposit was either completed or fully refunded the same day. Risk Labs absorbed the gross payout of approximately $4.5 million directly; with roughly $500,000 in attacker funds trapped inside the protocol, the net loss sits under $4 million and continues to shrink as recovery efforts advance.

Risk Labs Deployed Fix Within Five Hours of Detection

The first forged deposit was submitted at 05:07 UTC on July 17; the forged deposit stream ended at 06:14 UTC with first attacker addresses blacklisted at 06:16 UTC. Solana was disabled as an origin and destination chain in the API at 08:23 UTC, the Solana SpokePool was paused on-chain at 08:35 UTC, and the first public statement was issued at 08:36 UTC. The root-cause fix was merged at 09:37 UTC and deployed across all Risk Labs infrastructure at 10:26 UTC—roughly five hours after detection. Solana deposits were re-enabled via CCTP routing at 17:05 UTC, restoring full Solana service in approximately 12 hours. All other protocol operations remained unaffected throughout.

Solana Event Parsing Logic Undergoing Re-Audit

Solana order flow is now routed exclusively through fallback CCTP routing, which Risk Labs states covers all major chains. Intents routing to and from Solana remains disabled while the team re-audits Solana offchain event parsing logic to confirm this vulnerability class is fully closed and the security model around event handling is standardized across the stack. Risk Labs is working with SEAL 911, which provided near-instant support after the incident was reported, and with US law enforcement; attacker addresses have been flagged across exchanges and off-ramps. The ACX token buyout process remains completely unaffected and continues as planned.

FAQ

Did any user funds get lost in the Across Solana relayer attack?

No user funds were lost or at risk at any point. All genuine transfers were completed or fully refunded on July 17, 2026.

What was the technical cause of the security vulnerability in the Risk Labs relayer?

The vulnerability was caused by missing verification of the 8-byte Anchor event discriminator in the offchain relayer code. This allowed an attacker to forge deposit events that the relayer treated as real, even though no funds moved on-chain.

How did Risk Labs respond to the forgery attack on their Solana relayer?

Risk Labs disabled Solana as an origin chain, paused the Solana SpokePool on-chain, deployed a root-cause fix within approximately five hours of detection, and fully restored Solana service within roughly 12 hours using fallback CCTP routing.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments