
Taiko later estimated losses at roughly $2.2 million, said affected users are expected to be reimbursed from the protocol treasury, and is tightening proof and signal controls as recovery work continues.
Taiko urged users to withdraw funds from all Taiko-deployed bridges after saying its chain state verification mechanism was compromised, undermining the security assumptions behind those bridges. The project and security researchers said forged message proofs were accepted on Ethereum L1 without a legitimate source-chain event, allowing fraudulent withdrawals from bridge and token vaults. An Etherscan transaction showed 649,761.236201 USDC moving from the Taiko ERC20 Vault to an exploiter address on June 21 at 22:07:23 UTC, while early estimates put losses at about $1.7 million before later project updates indicated roughly $2.2 million. Taiko said affected users' funds are expected to be reimbursed from the protocol treasury, and its response has included coordinating with its Security Council and ecosystem partners, asking centralized exchanges to suspend TAIKO deposits, and implementing code changes including temporarily disabling permissionless inbox proving and proposing and introducing SignalService checkpoint versioning.