A bug in data-parsing software nearly cost Across Protocol tens of millions of dollars within an hour. According to an official post-mortem report on July 17, 2026, the attack, which occurred between 05:07 and 06:14 UTC, attempted to deceive the system with 1,627 fake deposits from the Solana network.
The perpetrator used 1,627 disposable Solana wallets to submit fraudulent instructions. The nominal value claimed reached $41.7 million, spread across 18 different destination blockchains. All of these stealth fund flows were directed to a single recipient address on an EVM network. However, because Across operates on a relayer model, the attack did not directly drain funds from the protocol’s vault.
Relayer Capital Comes to the Rescue
Risk Labs, the relayer operator, initially fulfilled 581 requests, or about 35.7% of the total fraudulent claims. To front these transfers, they spent roughly $4.5 million of their own capital before realizing something was amiss and immediately halting Solana operations. This move cancelled the remaining 1,046 requests and prevented an additional $37 million in payouts.
The gross losses suffered by Risk Labs were further reduced because around $500,000 of the attacker’s funds became trapped within the protocol. After accounting for this, net losses were kept below $4 million, an amount absorbed without touching user funds.
Not a Smart Contract Vulnerability
Across emphasized that the issue stemmed from a vulnerability in Risk Labs’ off-chain event-reading software, not from a smart contract flaw. The Solana network itself was not compromised at all. A code patch to fix the vulnerability was deployed roughly five hours after the attack.
Within 12 hours, cross-chain services for Solana were restored using Circle CCTP as an interim route. All transfers from legitimate users were confirmed completed or fully refunded on the day of the incident. Across’s track record of processing $34 billion in transactions without any loss of user funds remains intact.
What Is the Market Impact?
The incident occurred while the protocol’s native token, ACX, was hovering near all-time lows. The token is trading around $0.041 with a market capitalization of $29 million, down more than 97% from its all-time high. Even so, the ACX token buyback program continues uninterrupted, while Solana fund flows are currently still routed through CCTP.
The multi-layered security system succeeded in protecting the core vaults this time, but the incident serves as an expensive reminder that off-chain data parsers can become critical entry points.
Reported by crypto.news.
Read also: What Is DeFi (Decentralized Finance)?
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




