📈 Get daily crypto insights that make you smarter about your money

Hackers Forged 41 Million USD in Fake Solana Deposits to Trick a Major DeFi Bridge, but the Protocol Says Its Safety Net Held the Line

A decentralized finance bridge called Across Protocol has disclosed a sophisticated attack in which hackers fabricated nearly 42 million USD worth of fake Solana deposits to drain funds from the system. But in a rare piece of good news for the DeFi sector, the protocol’s risk controls limited the actual damage to under four million USD, and recovery efforts are already underway. The incident highlights both the creativity of attackers and the growing maturity of DeFi security infrastructure.

By David Chen | July 25, 2026

The Hook: A Digital Heist With a Twist

Bridge protocols are the connective tissue of decentralized finance. They allow users to move assets between different blockchains, like sending tokens from Solana to Ethereum or vice versa. Because these bridges often hold large amounts of pooled capital, they have become one of the most attractive targets for hackers in the crypto ecosystem. The history of DeFi is littered with bridge exploits that cost users hundreds of millions.

That is what makes the Across Protocol incident so interesting. According to the protocol’s own disclosure, attackers managed to forge approximately 41.7 million USD in fake Solana deposits. In simple terms, they tricked the system into believing that large sums of cryptocurrency had been deposited on the Solana side of the bridge, when in reality no such deposits existed. The goal was to use those fake deposit records to withdraw real funds from the Ethereum side.

Think of it like depositing a fake check at an ATM. The machine reads the check, credits your account, and you withdraw cash before anyone realizes the check was worthless. The difference is that in traditional finance, this scam usually fails because the check clears in a day or two. In DeFi, transactions happen in seconds, which means the window for catching the fraud is much smaller.

On-Chain Evidence: What Actually Happened

The attack targeted a component of the Across Protocol called a “relayer.” A relayer is essentially a messenger service that verifies and transmits information between blockchains. When you send tokens through a bridge, the relayer on the source chain (in this case, Solana) confirms the deposit and tells the destination chain (Ethereum) to release the corresponding funds.

The attackers found a way to make the relayer report fake deposits. They fabricated approximately 41.7 million USD worth of fraudulent Solana deposit records, which the system initially accepted as legitimate. Under normal circumstances, this kind of exploit could have resulted in losses equal to the full amount of the fake deposits. But Across Protocol had additional layers of protection.

  • Fake deposits forged — approximately 41.7 million USD in fraudulent Solana deposit records
  • Actual net loss — under 4 million USD, thanks to the protocol’s risk controls
  • Recovery status — funds are actively being recovered, according to the protocol
  • User impact — no user funds were directly compromised, as the loss was absorbed by the protocol’s insurance pool

The Core Conflict: Innovation Speed vs. Security Depth

The Across Protocol exploit exposes the fundamental tension at the heart of decentralized finance. DeFi protocols move fast. They ship new features, support new chains, and add new functionality at a pace that traditional finance cannot match. But that speed comes with risk. Every new integration, every new blockchain connection, and every new relayer creates a potential attack surface.

The DeFi market currently holds about 63.3 billion USD in total value locked, according to CoinMarketCap data. That is a massive amount of money sitting on software that, in many cases, has been live for less than two years. The Across Protocol incident shows that even protocols with mature security infrastructure can be caught off guard by novel attack vectors.

But the incident also shows something encouraging. The fact that the actual loss was contained to under 4 million USD, despite the attackers attempting to extract nearly 42 million USD, suggests that layered security measures work. The protocol’s insurance pool and risk limits functioned as designed, absorbing the blow and protecting users. That is a far cry from the early days of DeFi, when a single exploit could drain an entire protocol dry.

Market Implications: What This Means for DeFi Investors

For anyone using DeFi protocols, the Across incident is a reminder of three important things. First, bridges remain the riskiest component of the DeFi ecosystem. If you are moving assets between chains, you are exposing yourself to bridge risk. That does not mean you should never use bridges, but it does mean you should use reputable ones with proven security track records.

Second, insurance pools matter. The reason Across Protocol users were not directly impacted is that the protocol maintained a reserve fund specifically designed to absorb losses from exploits. When evaluating a DeFi protocol, one of the first questions you should ask is whether it has an insurance mechanism and how well-funded it is.

Third, the DeFi industry is getting better at security, even if the attackers are also getting more sophisticated. The fact that Across was able to limit a 42 million USD attack to under 4 million USD in actual losses, and is actively recovering even that amount, represents real progress. Compare that to the bridge hacks of 2022 and 2023, where protocols lost hundreds of millions with no recovery mechanism in place.

The Verdict: A Near-Miss With Valuable Lessons

The Across Protocol exploit could have been much worse. A 41.7 million USD attack that results in under 4 million USD in net losses is a story about security working, not security failing. The protocol’s layered defenses, risk limits, and insurance pool all functioned as intended, protecting users from what could have been a devastating breach.

For the broader DeFi market, which currently sits at 63.3 billion USD in total value locked, the incident is both a warning and a reassurance. The warning is that attackers are constantly probing for new weaknesses, and even well-defended protocols can be targeted. The reassurance is that when the defenses hold, the damage can be contained. As DeFi continues to grow and mature, incidents like this one will help shape better security standards across the industry.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice.

12 thoughts on “Hackers Forged 41 Million USD in Fake Solana Deposits to Trick a Major DeFi Bridge, but the Protocol Says Its Safety Net Held the Line”

  1. bridge_rekt_veteran

    42M fake deposits and they only lost 4M? honestly thats a win in bridge terms. wormhole lost 325M, nomad 190M, this is nothing

  2. 41.7M in fake deposits and only 4M actual damage. the risk controls actually worked for once. rare W for DeFi security

  3. the fact that risk controls actually kicked in is the real story here. most bridges just yolo until the vault is empty

  4. the relayer was the weak link. same pattern as Nomad. messengers between chains are always the attack surface because they handle state verification off-chain

  5. forging deposit records to trick the relayer is basically a fake check attack but at the speed of light. the window to catch it is seconds not days

  6. fake deposits on Solana… was this related to the infinite mint bug pattern? seen something similar with wormhole validator trickery

  7. Across has a pauser role that triggered within the session. centralized safety net but it worked. better than the fully permissionless bridges that got drained for 600M

  8. 41.7M in fake deposits is wild. the fact that the relayer accepted forged proofs means the verification layer was basically decorative

  9. 4M actual loss on 42M attack attempt. across security team must have been monitoring in real time, that pause window was tight

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,603.00+0.8%ETH$1,890.52+1.4%SOL$74.90+1.5%BNB$571.53+0.9%XRP$1.10+0.6%ADA$0.1644+0.8%DOGE$0.0729+4.2%DOT$0.8230+0.5%AVAX$6.67+2.7%LINK$8.47+1.5%UNI$3.85+4.6%ATOM$1.39+0.2%LTC$46.74+2.1%ARB$0.0825-0.2%NEAR$1.79+0.2%FIL$0.7441+3.7%SUI$0.7163+1.5%BTC$64,603.00+0.8%ETH$1,890.52+1.4%SOL$74.90+1.5%BNB$571.53+0.9%XRP$1.10+0.6%ADA$0.1644+0.8%DOGE$0.0729+4.2%DOT$0.8230+0.5%AVAX$6.67+2.7%LINK$8.47+1.5%UNI$3.85+4.6%ATOM$1.39+0.2%LTC$46.74+2.1%ARB$0.0825-0.2%NEAR$1.79+0.2%FIL$0.7441+3.7%SUI$0.7163+1.5%
Scroll to Top