Cross-chain bridge protocol Across suffered an attack and lost US$4.5 million. User Funds Security
Cross-chain bridge protocol Across (ACX) disclosed on July 17 that its attack resulted in losses of approximately US$4.5 million. The team confirmed that user funds were not affected and were still safe. The incident was attributed to a vulnerability in the relay software responsible for reading events under the Solana (SOL) network chain.
How the attack occurred
According to an official statement issued by Across on the X platform, the attacker exploited a vulnerability in relay software that resolves offline deposit events on Solana. The attacker faked a deposit event that never actually occurred and tricked the repeater into treating it as a legal transaction, causing the repeater to pay its own funds and steal approximately $4.5 million from its successor reserves. Across emphasized that its core smart contracts and Solana programs have not been hacked or compromised in any way.
Immediate response and fix
The Across team quickly discovered the problem and deployed the patch within five hours of discovery. The fix targets specific vulnerabilities in the relay software and prevents further attacks. The team also confirmed that the original ACX repurchase plan will proceed as planned and will not be affected by this incident. Throughout the attack, user funds were never at risk.
Broader impact on cross-chain security
The incident highlights the increasing complexity of cross-chain bridge security, especially when integrating with networks such as Solana, which rely on off-chain event processing. Although core smart contracts remain secure, vulnerabilities in off-chain relay software suggest that auditing all levels of the bridge infrastructure, not just on-chain components, is critical. The attack did not affect Across's Solana Bridge contract itself, but rather external software used to relay data between chains.
Conclusion
The attack on Across Protocol reminds us that the security of decentralized finance is not limited to smart contracts, but also includes off-chain infrastructure. The team's rapid response and transparent disclosure help control losses and maintain user trust. With user funds fully protected and the repurchase plan continuing, Across seems to have successfully weathered the incident without causing continued operational disruption.
FAQs
Q1: Were there any user funds lost in the Across attack?
Answer: No. Across confirmed that user funds were not affected and that the losses were limited to the repeater's own funds.
Question 2: Was Across's smart contract or Solana program hacked?
Answer: No. The attack targeted vulnerabilities in relay software that read off-chain events, rather than core smart contracts or Solana programs.
Q3: Will the ACX repurchase program continue as planned?
Answer: Yes. Across said the repurchase plan will proceed as planned and will not be affected by this incident.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ACX
SOL