Defimon detected a malicious fake rollup assertion targeting abandoned Edgeless Network L2 bridge holding ~$22.7K; attacker has until ~Sep 17–18 to confirm the fake state and drain funds, but community validators can still stop it with a fraud proof.
Security & Exploits ·
A malicious assertion has been submitted against Edgeless Network, an abandoned Arbitrum Orbit L2, targeting approximately $22.7K held in its L1 bridge. An attacker funded by Railgun deployed an exploit contract and proposed a fake rollup assertion claiming an invalid L2 state, staking it as node 228 in the protocol's sequencing mechanism.
The exploit is able to progress because Edgeless Network left validation permissionless and has no active validators remaining to dispute the false assertion. The attacker needs only to wait out the challenge window—set to expire around L1 block 25,999,225, approximately September 17–18—then confirm the fake state and drain approximately 9.2 ewETH through the bridge's Outbox mechanism.
The attack window remains open to intervention. Any community member can still post the correct assertion and file a fraud proof using 0.1 ETH to halt node 228 before its confirmation deadline. The exploit was detected at contract deployment before the propose() call was even submitted, preserving a narrow opportunity for defense through the protocol's permissionless dispute mechanism.