Across Protocol relayer absorbs $4.5 million Solana exploit, no user funds lost
Security & Exploits ·
A July 17, 2026 attack exploited a bug in Risk Labs' offchain relayer software, but the intents-based architecture kept the losses confined to relayer capital rather than user deposits.
The incident began at 05:07 UTC when an attacker submitted forged deposit events on Solana, exploiting a missing discriminator check in the relayer's event-reading client. Between 05:07 and 06:14 UTC, 1,627 forged deposits were submitted from 1,627 single-use wallets, representing roughly $41.7 million in face value across 18 destination chains, all routing to a single EVM recipient. The relayer, unable to distinguish the forged events from genuine deposits, filled 581 of them before Solana was disabled, paying out approximately $4.5 million of its own capital against deposits that never existed onchain.
The exploit worked because Across's Solana SpokePool emits events through Anchor's CPI-event pattern, and the relayer's client accepted any inner instruction routed through the program's event-authority PDA as legitimate without checking the event's 8-byte discriminator. The attacker used a wrapper program that called a benign, read-only instruction and appended forged deposit payloads to it, creating the appearance of real activity while no funds moved and no contract state changed. According to the protocol's own account, no smart contract was exploited on Solana or any EVM chain; the flaw existed solely in the relayer's offchain code, as detailed in Across Protocol's post-mortem.
Because Across operates as an intents protocol, relayers front their own capital to pay users on destination chains and are reimbursed only after deposits are verified through a separate settlement process, which meant the forged events exposed relayer funds rather than the escrow holding user deposits. Every real user transfer was completed or refunded in full the same day, and the remaining roughly $37 million in forged deposits expired worthless once Solana was disabled at 08:23 UTC and the SpokePool was paused onchain at 08:35 UTC. A fix was merged by 09:37 UTC and deployed across Risk Labs infrastructure by 10:26 UTC, with Solana service restored via fallback CCTP routing by 17:05 UTC, roughly 12 hours after detection.
The episode is one of several relayer-related exploits circulating in the same period; separate incidents involving a different relayer report thefts of 13.28 and 13.28498 ETH, with attackers given deadlines of July 25 and July 26, 2026 respectively to return funds before enforcement action. It remains unclear whether Risk Labs will recover any of the roughly $4.5 million paid out, and the identity behind the consolidating recipient address tied to the forged deposits, visible on Etherscan, has not been disclosed.