Across Protocol says a relayer operated by Risk Labs lost less than $4 million after an attacker forged deposit events on Solana and triggered cross-chain payouts before the protocol halted activity. According to Across’s post-incident report, user funds were not affected and valid transfers were either completed or refunded the same day.

Attack timeline and scale

The incident took place between 05:07 and 06:14 UTC on July 17. Across said the attacker used 1,627 single-use Solana wallets to generate 1,627 fake deposit events with a combined face value of about $41.7 million.

Those fabricated deposits requested payouts across 18 destination chains. Across said the requests were directed to a single recipient address on an Ethereum Virtual Machine-compatible network.

Before Solana operations were stopped, Risk Labs’ relayer fulfilled 581 of the fraudulent requests. Across said that amounted to roughly 35.7% of the requests by count, but only 10.8% of their claimed value.

How the loss was contained

The relayer advanced around $4.5 million of its own capital before the attack was interrupted. Across then invalidated the remaining 1,046 requests, preventing what it estimated was about $37 million in further payouts.

The protocol also said around $500,000 belonging to the attacker remained trapped inside the system. After offsetting that amount against the gross payout, Across put the net loss at under $4 million.

Across attributed the breach to a flaw in Risk Labs’ off-chain event-reading software, not to a vulnerability in the protocol’s smart contracts. It also said the attacker did not compromise the Solana network itself.

Why users were not hit

Across uses relayers that front their own assets to complete transfers before later seeking repayment. Under that model, the loss fell on the Risk Labs-operated relayer rather than on users carrying out legitimate transactions.

Across said all valid transfers were completed or fully refunded on July 17. The protocol’s website states that it has processed more than $34 billion in transfers without reporting a loss of user funds.

The protocol added that the incident would not affect its planned ACX token buyback. It did not say whether Risk Labs would change relayer funding, monitoring systems, or operating limits following the breach.

Solana service resumes through CCTP

Across said engineers deployed a root-cause fix about five hours after the attack and restored Solana service roughly 12 hours later by routing transfers through Circle’s Cross-Chain Transfer Protocol, or CCTP. Solana order flow remains on that route for now.

The protocol has not given a timeline for returning to its previous routing system, and it has not announced whether any additional funds have been recovered.

The report said the breach did not involve USDC reserves or Circle’s minting contracts. According to Circle, CCTP works by burning native USDC on the source chain and minting the same amount on the destination chain, rather than relying on a traditional bridge liquidity pool or third-party fillers.

The Across incident stands apart from other recent crypto attacks cited in coverage, with the protocol describing this case as an off-chain software failure rather than a smart contract exploit. For now, the main confirmed outcomes are a relayer loss kept below $4 million, uninterrupted protection of user funds, and a temporary operational shift for Solana transfers.

Source: crypto.news