The cross-chain interoperability protocol Across reported a security incident targeting its Solana infrastructure on July 17, 2026. The attack, which occurred at approximately 05:30 UTC (13:30 UTC+8), prompted an immediate response from the development team to secure the network. Despite the breach, project officials have confirmed that all user funds are safe and that existing cross-chain transactions were successfully finalized before the protocol's preventative measures were fully implemented.
Impact Assessment and Emergency Measures
Following the detection of the exploit, the Across team moved to mitigate further risks by suspending all deposits to the Solana blockchain. However, other protocol functions across supported networks remain operational. Initial investigations suggest that the primary financial impact was localized to the relay nodes operated by Risk Labs, the foundation behind the Across protocol. Relay nodes are responsible for providing the liquidity necessary to fulfill cross-chain transfers instantly.
- The incident was localized specifically to the Solana side of the bridge.
- All liquidity provider (LP) assets and user deposits remain unaffected.
- Protocol functions on Ethereum, Arbitrum, and Optimism continue to operate as intended.
Tracking Attackers and Collaborative Defense
The project is currently working with SEAL_911, a specialized crypto-security emergency group, to trace the movement of the stolen assets. Analysts have identified three primary addresses linked to the threat actor: one located on the Solana network and two on the Ethereum mainnet. This collaborative effort aims to blacklist the associated wallets and potentially recover the diverted capital.
Across has suspended deposits to Solana, and other protocol functions are operating normally. The project team is tracking relevant attack addresses with SEAL_911 and will release more details and a full post-mortem later.
The Across team has committed to providing a comprehensive post-mortem analysis once the technical investigation concludes. This report is expected to detail the specific vulnerability exploited and the long-term security enhancements planned for the bridge’s architecture. Users are advised to remain vigilant and follow official communication channels for updates regarding the resumption of Solana deposit services, as the project emphasizes the importance of verifying all protocol links during this recovery phase.
Frequently Asked Questions
Quick answers to the most common questions about this topic.