Across Protocol restores Solana deposits after relayer-only exploit
Security & Exploits ·
Across Protocol has resumed Solana deposits after an attack that hit its Risk Labs relayer, with the team saying no user funds were lost.
The protocol confirmed the restoration in a post from its own account, stating that the incident was contained to the Risk Labs relayer rather than spreading to user-held balances, according to Across Protocol. The announcement frames the event as an operational disruption on the relayer side of the system rather than a breach of user custody.
A relayer in this context is the infrastructure component responsible for facilitating deposit and transfer activity between chains; isolating an attack to that layer, rather than to the funds held on behalf of users, is the key distinction Across is drawing in its disclosure. By pausing and then restoring Solana deposits, the protocol signals that the affected pathway has been addressed sufficiently to reopen that specific chain's functionality.
A separate account of the incident in the same cluster corroborates the core claim, describing a Solana exploit that affected Risk Labs relayer funds while stating that user deposits remain safe. Two distinct sources are tracked covering this event, both converging on the same outcome: relayer-side impact, no reported loss of user assets.
The episode surfaces amid a broader wave of Solana-related activity, with the network's ecosystem tracked across a range of developments from infrastructure upgrades to token programs, as catalogued on the Solana coverage hub. That wider context does not itself bear on the Across incident, but it reflects the pace of activity across Solana-linked protocols against which this exploit and recovery occurred.
What remains unspecified is the technical root cause of the attack on the Risk Labs relayer, the scale of funds directly affected at the relayer level, and whether any compensation or remediation steps beyond restoring deposits are planned. Neither account provides a timeline for when the attack began, how long deposits were paused, or whether other chains served by Across faced similar exposure. Confirmation of these details, along with any post-incident review from Across Protocol or Risk Labs, would clarify how isolated the event truly was and whether structural changes to the relayer system are forthcoming.