Attacker exploits abandoned Edgeless Network L2 bridge with fake rollup assertion to drain ~$23K in leftover ewETH.
Security & Exploits ยท
An attacker has exploited dormant infrastructure on the Edgeless Network, an abandoned Arbitrum Orbit L2, by submitting a fraudulent rollup assertion to drain approximately $23K in leftover ewETH from the project's bridge. The team stopped sequencer activity around September 2025, leaving roughly 9.2 ewETH unprotected in the L1 bridge contract.
The exploit works because Edgeless left validation permissionless with no active validators remaining. A Railgun-funded address deployed a contract that posted a fake state assertion (node 228), which cannot be disputed since no validator exists to challenge it. The attacker need only wait through the challenge window before confirming the fraudulent state and withdrawing funds via the Outbox mechanism.
The assault was detected during the contract deployment phase, before the assertion was even proposed. A window remains to halt the drain: node 228 cannot be confirmed until approximately block 25,999,225 around September 17โ18. Any actor can stop it by posting the correct assertion and submitting a fraud proof backed by 0.1 ETH, though no intervention has yet been reported.