Cross-chain protocol Across Protocol released an incident report: Relayer lost less than US$4 million when the attacker forged a Solana deposit.
According to a post-mortem analysis report released by Cross-chain protocol, its repeater operated by Risk Labs actually lost less than US$4 million after the attacker forged a US$41.7 million Solana deposit. The attack involved a total of 1627 fake deposits with a total face value of approximately US$41.7 million, and the targets covered 18 chains. Risk Labs 'forwarders suspended service after processing 581 fraud requests, during which they paid approximately $4.5 million. About $500,000 of attacker funds remained trapped in the agreement, bringing the net loss to less than $4 million. Across Protocol restored Solana transfers through CCTP (Cross-Chain Transfer Protocol), and user funds and the ACX repurchase program were not affected.
Attack details: Fake 1627 Solana deposits
According to post-mortem analysis by Across Protocol, the attack occurred between 05:07 and 06:14 UTC on July 17. During those 67 minutes, the attacker used 1627 one-time Solana wallets to submit the same amount of counterfeit deposits. These deposits have a total face value of approximately US$41.7 million and direct funds to 18 target chains. Across Protocol reported that funds were eventually remitted to a single receiving address on a compatible Ethereum-virtual machine (EVM) chain.
Risk Labs 'forwarders processed 581 of these fraudulent requests, accounting for approximately 35.7%. However, the US$4.5 million actually paid accounted for only approximately 10.8% of the attempted counterfeit face value. Before the remaining 1046 requests were processed, Across Protocol stopped Solana-related operations and voided approximately $37 million in unpaid fake deposits, avoiding further losses. The report points out that the root cause is a vulnerability in the Risk Labs transponder code base. Since the affected software was running offline, the attacker did not tamper with Across Protocol's on-chain contracts or exploit Solana's underlying network.
Why users have not suffered losses
Across Protocol adopts the transponder model: the transponder first advances its own funds to complete the cross-chain order, and then applies for reimbursement. This structure places direct financial risk on Risk Labs 'forwarders rather than users who transfer assets through protocols. The agreement reported that all legal transfers were completed or fully refunded on July 17. According to its official website, Across Protocol has processed more than US$34 billion in bridging transactions and has never lost user funds.
This incident is different from the Lien Finance attack reported by crypto.news on July 24. Lien Finance lost approximately 542,144.63 USDC because the attacker used a loophole in its bond redemption logic to minted unsecured tokens without destroying the required input bonds. Slowfog Technology traces the Lien Finance vulnerability to incomplete checks in the exchangeEquivalentBonds function. Unlike the Across incident, that attack involved smart contract logic that allowed the attacker to exchange unsecured bond tokens for USDC in the affected liquidity pool.
The disclosure by Across Protocol comes as stolen assets from previously Solana vulnerabilities also begin to be transferred. According to crypto.news, a wallet related to the $285 million Drift Protocol vulnerability transferred 23,095.1 ETH (approximately $44.4 million) to Tornado Cash on July 23 and 24.
ACX Token Price and Repurchase Program
As of press time, the ACX token trading price was approximately US$0.04135, down 2.8% in 24 hours and 2.3% in 7 days. The token has a market value of approximately US$29.1 million and a 24-hour transaction volume of approximately US$3.3 million. ACX is still down about 97.6% from its all-time high of $1.69. Across Protocol said the transponder loss will not change its planned ACX token repurchase. The agreement did not disclose whether the incident would affect Risk Labs 'other expenses or transponder operations.
Solana services migrated to CCTP routing
Across Protocol deployed a root cause fix approximately 5 hours after the attack and restored Solana services through alternate CCTP routing in approximately 12 hours. All Solana order flows now use Circle's cross-chain transport protocol, which transfers native USDC between supported networks through a destruction-casting process. Across Protocol has not provided a timetable for restoring the previous Solana routing system. The next steps in the protocol include maintaining CCTP routes and monitoring funds associated with attackers. The report did not announce any recovery agreements, arrests or identification of the attacker.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ACX
ETH