Across Solana Relayer Attack Drained $4.5M - No User Lost a Cent

A missing eight-byte check in an offchain code file handed an attacker a window to drain roughly $4.5 million from a Risk Labs-operated relayer on July 17, 2026 — yet every user of the Across protocol walked away without losing a cent. The Across Solana relayer attack exposed a narrow but consequential gap between what a blockchain sees and what offchain software chooses to trust.
Key takeaways
- On July 17, 2026, an attacker exploited a bug in Risk Labs’ offchain Solana relayer by forging deposit events that never existed on-chain.
- No user funds were lost or at risk; every genuine transfer was completed or refunded the same day.
- Risk Labs absorbed approximately $4.5 million gross in relayer capital, with a net loss under $4 million and shrinking as recovery continues.
- The attacker submitted 1,627 forged deposits across 18 destination chains totaling roughly $41.7 million in face value; the relayer filled 581 of them before Solana was disabled.
- Solana service was restored in approximately 12 hours via fallback CCTP routing; law enforcement and SEAL 911 are actively involved in recovery efforts.
Details of the Across Solana Relayer Attack
The incident unfolded inside a narrow technical seam between Solana’s onchain programs and the offchain software Risk Labs used to read them. No funds moved on-chain during the attack. No state changed. The blockchain itself behaved perfectly — but the software watching it did not.
… Continue reading the full article at the original source below.



