A decentralized finance bridge called Across Protocol has disclosed a sophisticated attack in which hackers fabricated nearly 42 million USD worth of fake Solana deposits to drain funds from the system. But in a rare piece of good news for the DeFi sector, the protocol’s risk controls limited the actual damage to under four million USD, and recovery efforts are already underway. The incident highlights both the creativity of attackers and the growing maturity of DeFi security infrastructure.
By David Chen | July 25, 2026
The Hook: A Digital Heist With a Twist
Bridge protocols are the connective tissue of decentralized finance. They allow users to move assets between different blockchains, like sending tokens from Solana to Ethereum or vice versa. Because these bridges often hold large amounts of pooled capital, they have become one of the most attractive targets for hackers in the crypto ecosystem. The history of DeFi is littered with bridge exploits that cost users hundreds of millions.
That is what makes the Across Protocol incident so interesting. According to the protocol’s own disclosure, attackers managed to forge approximately 41.7 million USD in fake Solana deposits. In simple terms, they tricked the system into believing that large sums of cryptocurrency had been deposited on the Solana side of the bridge, when in reality no such deposits existed. The goal was to use those fake deposit records to withdraw real funds from the Ethereum side.
Think of it like depositing a fake check at an ATM. The machine reads the check, credits your account, and you withdraw cash before anyone realizes the check was worthless. The difference is that in traditional finance, this scam usually fails because the check clears in a day or two. In DeFi, transactions happen in seconds, which means the window for catching the fraud is much smaller.
On-Chain Evidence: What Actually Happened
The attack targeted a component of the Across Protocol called a “relayer.” A relayer is essentially a messenger service that verifies and transmits information between blockchains. When you send tokens through a bridge, the relayer on the source chain (in this case, Solana) confirms the deposit and tells the destination chain (Ethereum) to release the corresponding funds.
The attackers found a way to make the relayer report fake deposits. They fabricated approximately 41.7 million USD worth of fraudulent Solana deposit records, which the system initially accepted as legitimate. Under normal circumstances, this kind of exploit could have resulted in losses equal to the full amount of the fake deposits. But Across Protocol had additional layers of protection.
- Fake deposits forged — approximately 41.7 million USD in fraudulent Solana deposit records
- Actual net loss — under 4 million USD, thanks to the protocol’s risk controls
- Recovery status — funds are actively being recovered, according to the protocol
- User impact — no user funds were directly compromised, as the loss was absorbed by the protocol’s insurance pool
The Core Conflict: Innovation Speed vs. Security Depth
The Across Protocol exploit exposes the fundamental tension at the heart of decentralized finance. DeFi protocols move fast. They ship new features, support new chains, and add new functionality at a pace that traditional finance cannot match. But that speed comes with risk. Every new integration, every new blockchain connection, and every new relayer creates a potential attack surface.
The DeFi market currently holds about 63.3 billion USD in total value locked, according to CoinMarketCap data. That is a massive amount of money sitting on software that, in many cases, has been live for less than two years. The Across Protocol incident shows that even protocols with mature security infrastructure can be caught off guard by novel attack vectors.
But the incident also shows something encouraging. The fact that the actual loss was contained to under 4 million USD, despite the attackers attempting to extract nearly 42 million USD, suggests that layered security measures work. The protocol’s insurance pool and risk limits functioned as designed, absorbing the blow and protecting users. That is a far cry from the early days of DeFi, when a single exploit could drain an entire protocol dry.
Market Implications: What This Means for DeFi Investors
For anyone using DeFi protocols, the Across incident is a reminder of three important things. First, bridges remain the riskiest component of the DeFi ecosystem. If you are moving assets between chains, you are exposing yourself to bridge risk. That does not mean you should never use bridges, but it does mean you should use reputable ones with proven security track records.
Second, insurance pools matter. The reason Across Protocol users were not directly impacted is that the protocol maintained a reserve fund specifically designed to absorb losses from exploits. When evaluating a DeFi protocol, one of the first questions you should ask is whether it has an insurance mechanism and how well-funded it is.
Third, the DeFi industry is getting better at security, even if the attackers are also getting more sophisticated. The fact that Across was able to limit a 42 million USD attack to under 4 million USD in actual losses, and is actively recovering even that amount, represents real progress. Compare that to the bridge hacks of 2022 and 2023, where protocols lost hundreds of millions with no recovery mechanism in place.
The Verdict: A Near-Miss With Valuable Lessons
The Across Protocol exploit could have been much worse. A 41.7 million USD attack that results in under 4 million USD in net losses is a story about security working, not security failing. The protocol’s layered defenses, risk limits, and insurance pool all functioned as intended, protecting users from what could have been a devastating breach.
For the broader DeFi market, which currently sits at 63.3 billion USD in total value locked, the incident is both a warning and a reassurance. The warning is that attackers are constantly probing for new weaknesses, and even well-defended protocols can be targeted. The reassurance is that when the defenses hold, the damage can be contained. As DeFi continues to grow and mature, incidents like this one will help shape better security standards across the industry.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice.
42M fake deposits and they only lost 4M? honestly thats a win in bridge terms. wormhole lost 325M, nomad 190M, this is nothing
41.7M in fake deposits and only 4M actual damage. the risk controls actually worked for once. rare W for DeFi security
the fact that risk controls actually kicked in is the real story here. most bridges just yolo until the vault is empty
the relayer was the weak link. same pattern as Nomad. messengers between chains are always the attack surface because they handle state verification off-chain
forging deposit records to trick the relayer is basically a fake check attack but at the speed of light. the window to catch it is seconds not days
fake deposits on Solana… was this related to the infinite mint bug pattern? seen something similar with wormhole validator trickery
Across has a pauser role that triggered within the session. centralized safety net but it worked. better than the fully permissionless bridges that got drained for 600M
Inara H. calling the pauser role centralized is fair but id rather have a human kill switch than watch another 600M drain in real time. permissionless sounds great until its your liquidity
41.7M in fake deposits is wild. the fact that the relayer accepted forged proofs means the verification layer was basically decorative
4M actual loss on 42M attack attempt. across security team must have been monitoring in real time, that pause window was tight
41.7M in fake deposits and the risk controls limited damage to 4M. Across actually built circuit breakers that work. name another bridge that can say that
the relayer model is fundamentally broken because state verification happens off-chain. Nomad, Wormhole, now Across. messengers between chains are always the exploit vector
the 4M loss is being framed as a win but thats still user funds gone. insurance fund will cover it this time, next time maybe not
fair, 4M gone is 4M gone. insurance fund eating it beats lp principal getting vaporized though. bad day instead of a ronin style graveyard
forging $41M in fake deposits and the safety net held. thats actually a bullish outcome for bridge security. a year ago this would have been a full drain
relayer_skeptic_ the safety net held THIS time. the forged merkle proofs got caught but the next attacker will just find a different verification gap. bridges remain the #1 exploit target
Nomad 2022 was the exact same forged proof trick and lost 190M. Across caught it mid session and ate 4M. Same bug class, wildly different outcome, thats measurable progress
progress sure but the pauser role being one multisig away from stopping every bridge transfer is its own headline waiting to happen. we traded exploit risk for guardian risk and nobody priced that in
forging deposit merkle proofs is old school. nomad got hit the same way in 2022. the fact that bridges still rely on single relayer verification in 2026 is embarrassing
merkle_break_ nomad exploit was literally the same bug class. committed root without zero-value verification. how do bridges keep shipping this in 2026
merkle_break_ the forged proofs getting caught proves merkle verification works. but trusting a single relayer to submit those proofs is the real failure point that keeps replicating
the relayer had no independent way to confirm the source chain finalized those deposits. bridges need native light clients, relayers are duct tape with a dashboard