On June 22, Taiko.eth announced the latest developments regarding the security incident on platform X, stating that the risk of vulnerability attacks has been controlled. We have suspended the Ethereum Layer 1 cross-chain bridge and the ERC20 token vault, and all withdrawal functions through these two channels have been completely closed. The attacker exploited a vulnerability in the cross-chain bridge's message proof verification mechanism to launch the attack. In the absence of any real transaction events on the source chain, the Ethereum Layer 1 mainnet still recognized the forged message credentials, allowing the attacker to initiate fraudulent withdrawals and steal assets from the cross-chain bridge and token vault. Based on current estimates, the total losses from the theft could be as high as $1.7 million before we shut down the relevant contracts.
All Comments