Taiko confirms compromise of chain state verification mechanism; urges immediate withdrawal of funds from all Taiko bridges.
Security & Exploits ·
On June 22, 2026, Taiko announced a compromise of its chain state verification mechanism that undermined the security of all bridges deployed on the platform. The team advised all users to withdraw funds immediately and said it was coordinating with the Security Council and ecosystem partners to contain the incident.
The exploit leveraged a flaw in Taiko's multi-prover system, where attackers registered a rogue SGX instance through the permissionless registerInstance function and submitted proofs for fabricated L2 blocks. This allowed them to craft invalid bridge messages and drain approximately 650,000 USDC plus 130 ETH—estimated at around $1.7 million—from the Taiko Bridge's ERC20 Vault. Funds have since moved toward exchanges including MEXC, with activity traced to four attacker addresses. Taiko requested all centralized exchanges suspend TAIKO deposits until further notice.
The vulnerability lay in the permissionless nature of prover registration. Taiko plans to implement stricter controls on registration, strengthen proof verification, and increase reliance on zero-knowledge proofs. A detailed post-mortem investigation remains pending, leaving the full scope of affected systems and recovery timeline still uncertain.