Taiko bridge exploit: $1M lost, withdrawals urged
Taiko's ERC20 Vault was exploited via a bridge flaw, causing $1M+ in losses. Users are urged to withdraw funds from all bridges as security is compromised.
Taiko's ERC20 Vault on Ethereum was exploited due to a vulnerability in the cross-chain bridge's source signal proof verification. This flaw enabled attackers to submit a crafted message proof, which was incorrectly accepted as valid on Ethereum Layer 1, despite no legitimate MessageSent event occurring on the Taiko source chain. As a result, unauthorized asset withdrawals took place, leading to losses exceeding $1 million. In response, Taiko issued an urgent security notice, urging users to withdraw funds from all bridges and requesting exchanges to suspend TAIKO deposits. The incident has heightened concerns about the security of cross-chain bridges and the reliability of blockchain infrastructure. Taiko is actively working with its security committee and partners to address the breach, with user asset safety as the top priority. The situation remains ongoing, and further updates on remediation efforts are expected soon.