
The cross-chain protocol said user funds and bridge transfers remained safe, while potential losses were limited to a Risk Labs-operated relayer and investigators traced addresses tied to the attacker.
Across said an attack hit its Solana deployment around 5:30 a.m. UTC on July 17, prompting the cross-chain protocol to disable Solana deposits while it investigates. The project said no user funds were affected, all bridge transactions were completed, and the protocol is otherwise operating normally. Potential losses appear limited to funds tied to a relayer operated by Risk Labs, the foundation supporting Across, reflecting the protocol’s intent-based design in which relayers front capital for transfers and are later repaid through settlement on Ethereum verified by UMA’s optimistic oracle. Across said it is coordinating with SEAL 911 to trace one Solana and two EVM addresses linked to the attacker, warned users about phishing links, and said refunds will process automatically. The team plans to publish a full post-mortem in the coming days.