
Risk Labs said a flaw in Solana event parsing let an attacker submit 1,627 fabricated deposits across 18 chains, leading a relayer to pay out about $4.5 million of its own capital.
Across said a July 17 exploit drained about $4.5 million from a Risk Labs-operated relayer after an attacker exploited a flaw in offchain software that reads Solana events and fabricated deposits with a face value of about $41.7 million. Between 05:07 and 06:14 UTC, the attacker submitted 1,627 forged deposits from 1,627 single-use wallets across 18 destination chains, all pointing to a single EVM recipient address. Risk Labs said its relayer filled 581 of those requests before Solana was disabled as an origin chain, while the remaining roughly $37 million in forged deposits expired unfilled. The company said the root cause was a missing check for Anchor’s 8-byte event discriminator in the relayer’s event-parsing code, not a flaw in Solana programs or in the get_unsafe_deposit_id helper function the attacker used as a carrier. Because Across uses an intents-based design in which relayers advance their own capital and are reimbursed only after settlement verifies deposits, no user funds were lost or put at risk, and all genuine transfers were completed or fully refunded the same day. Risk Labs said gross losses were about $4.5 million, with roughly $500,000 in attacker funds trapped in the protocol, putting the net loss below $4 million and still falling as recovery efforts continue. The company said it deployed a root-cause fix within about five hours of detection, restored full Solana service in roughly 12 hours using fallback CCTP routing, and is keeping intents routing to and from Solana disabled while it re-audits offchain event parsing logic. SEAL 911 and U.S. law enforcement are involved in recovery efforts, attacker addresses have been flagged across exchanges and off-ramps, and the ACX token buyout process remains on track.