Taiko says leaked key caused June 21 bridge exploit, $1.75 million stolen

Taiko's post-mortem said an offchain attack involving leaked signing keys and missed checks hit the bridge and vault, while balances remained fully backed after the network's recovery.

Summary

Taiko said its June 21 security incident was caused by leaked signing keys and missed checks in an offchain attack, according to the project's post-mortem. The attacker stole about $1.75 million from the bridge and vault, while more than $11 million was protected. Taiko said no users suffered losses and that all balances have been backed 1:1 since the network recovered. The project had previously said the breach let the attacker forge proofs and bypass the Prover whitelist through a leaked offchain signing key and a validation gap, adding that the issue did not stem from failed ZK cryptography or flaws in smart contracts. Taiko resumed network operations on July 2 after implementing fixes and has said its Unzen upgrade on August 6 will require a ZK proof for every block to tighten verification.

Terms & Concepts
  • ZK proof: Cryptographic proof that verifies data without revealing the underlying data.
  • smart contracts: Self-executing code that runs on a blockchain.
  • Prover whitelist: An approved list of entities permitted to submit proofs.