Taiko’s L2 bridge was exploited for $1.7 million after a signing key for its Raiko SGX prover was left publicly accessible on GitHub, enabling forged withdrawal proofs. The protocol halted block production and urged users to exit all bridges.

Taiko's ERC20 vault was exploited for $1.7M due to a cross-chain bridge proof verification flaw, with $2M in TKO tokens deposited to MEXC by the attacker.

Onchain security firm Blockaid said the root cause of the exploit could be a flaw in Taiko bridge's source-signal proof validation.