A relayer operated by Protocol’s Risk Labs suffered a loss of under $4 million when someone manipulated data to falsely report $41.7 million in Solana deposits, according to a report released by the cross-chain protocol.
Summary
- 1,627 fake deposits worth $41.7 million targeted 18 chains during the Solana attack.
- Risk Labs’ relayer paid $4.5 million across 581 fraudulent requests before suspending service.
- Around $500,000 in attacker funds remained trapped, reducing the net loss below $4 million.
- Across restored Solana transfers through CCTP, while user funds and the ACX buyback remained unaffected.
Before the service was halted, Risk Labs’ relayer processed 581 fraudulent deposits, costing around $4.5 million. Fortunately, about $500,000 of the attacker’s funds were locked within the system, bringing the total loss down to under $4 million.
Across stated the issue stemmed from its software that processes events happening outside of the blockchain (specifically related to Solana), not from a problem with its core smart contracts. They confirmed that no users lost money, and all valid transactions were either completed successfully or fully reimbursed on the day of the incident.
Across attacker created 1,627 fake Solana deposits
According to an analysis following the incident, the attack happened between 5:07 AM and 6:14 AM UTC on July 17th. Over 67 minutes, the attacker created and used 1,627 different Solana wallets to send an equal number of fake deposits.
The identified deposits totaled around $41.7 million and were sent to 18 different receiving addresses. Investigations revealed these funds eventually ended up with a single entity on a network compatible with the Ethereum Virtual Machine.
Risk Labs’ relayer processed 581 of the fake requests, which was around 35.7% of them all. But the $4.5 million actually paid out was only about 10.8% of the total value the attackers tried to steal.
Solana halted processing transactions before it could complete over a thousand pending orders. This action canceled roughly $37 million worth of fraudulent deposits, stopping them from causing additional financial harm.
The investigation determined that a flaw in the code of Risk Labs’ relayer was the source of the problem. Since this software functioned outside of the main blockchain, the attacker didn’t need to change any of Across’ core contracts or compromise Solana’s network itself.
Why Across users avoided losses
As a researcher studying this system, I’ve found that it utilizes relayers who front the capital needed to execute cross-chain orders and then request repayment afterward. This design is significant because it means Risk Labs’ relayer bears the initial financial risk of these transactions, protecting users from immediate exposure when transferring their assets.
The system confirmed that all valid transactions were either successfully completed or refunded by July 17th. Additionally, Across reports having processed over $34 billion in transfers without any loss of user funds, as detailed on their website.
This attack is different from the one that affected Lien Finance on July 24, as reported by crypto.news. In that previous incident, Lien Finance lost around $542,144.63 in USDC when someone took advantage of a flaw in how its bond exchange worked to create unauthorized tokens without properly destroying the original bonds.
SlowMist discovered the Lien Finance vulnerability stemmed from insufficient verification within the ‘exchangeEquivalentBonds’ function. This attack differed from the one on Across; it exploited a flaw in the smart contract code, enabling the attacker to swap unsupported bond tokens for USDC from the platform’s funds.
News of the Across issue came around the same time that stolen cryptocurrency from a previous hack on Solana started being moved. As crypto.news detailed, a wallet connected to the $285 million Drift Protocol theft sent 23,095.1 ETH – approximately $44.4 million worth – to Tornado Cash on July 23rd and 24th.
ACX trades near $0.041 after the report
At the time of this report, ACX was trading around $0.04135. CoinGecko data shows it had decreased by 2.8% in the last 24 hours and 2.3% over the past week.
The token was valued at around $29.1 million, with $3.3 million worth traded in the last 24 hours. However, its current price was still about 97.6% lower than its highest price ever recorded, which was $1.69.
Despite losing funds through a relayer, Across confirmed it will still proceed with its previously announced plan to buy back ACX tokens. The company didn’t say if this event would impact funding for other projects or how it would affect future relayer services.
Solana service moves to CCTP routing
After the incident, Across quickly identified and fixed the underlying problem within five hours. Full Solana service was then recovered in around twelve hours by using an alternative path called the CCTP route.
Solana transactions involving USDC are now processed using Circle’s new system that moves the currency between different blockchains by temporarily destroying (burning) it on one chain and creating (minting) a new equivalent amount on another. Currently, there’s no estimate of when the original method for handling these transactions on Solana will be available again.
Moving forward, the plan involves keeping the current communication pathway open and watching the funds connected to the hacker. The latest update didn’t mention anyone being caught, identified, or any agreements reached to get stolen money back.
2026-07-25 11:06