Across Protocol, one of the largest cross-chain bridge platforms in crypto, confirmed on July 17 that its Solana bridge deployment was hit by an attack. The good news: user funds appear untouched. The less good news: it’s another reminder that bridges remain crypto’s favorite punching bag for exploiters.
The incident was detected at approximately 5:30 AM UTC, and the team moved quickly to disable Solana deposits as a precautionary measure. All transactions completed before the attack were secured, and the protocol continues to function normally on other supported chains like Ethereum and Base.
What happened and who’s exposed
Here’s the thing about this attack: the potential losses appear limited to a very specific bucket. Only funds associated with the relayer operated by Risk Labs, the foundation that supports Across Protocol, are considered at risk. That’s an important distinction. In the world of bridge exploits, where users often wake up to find their deposits evaporated, this outcome is about as contained as it gets.
Across uses what’s called an intent-based architecture. Think of it like placing an order at a restaurant: you state what you want (move tokens from Chain A to Chain B), and a relayer fills that order using their own capital, getting reimbursed later. The relayer takes on the risk, not the user. In this case, Risk Labs was operating that relayer on the Solana side, which is why their funds, not users’ funds, are the ones in the crosshairs.









