AI 摘要
Taiko, an Ethereum layer-2 network, halted block production and told users to pull their funds after an attacker exploited its bridge earlier Monday. The team estimated losses at about $1.7 million before it stopped t...
风险提示
这条新闻可能带来较大波动,建议先核对原文和后续公告。
所属事件
Taiko halts Ethereum layer-2 network after a bridge exploit, token dives
Taiko, an Ethereum layer-2 network, halted block production and told users to pull their funds after an attacker exploited its bridge earlier Monday. The team estimated losses at about $1.7 million before it stopped t...
Taiko, an Ethereum layer-2 network, halted block production and told users to pull their funds after an attacker exploited its bridge earlier Monday.
The team estimated losses at about $1.7 million before it stopped the outflows. The chain's TAIKO token, which has a market capitalization of $14.5 million, has slumped more than 20% since midnight UTC.
The attacker was able to forge the proofs a bridge uses to confirm that a withdrawal matches a real deposit. Fake withdrawal requests were accepted on Ethereum without any matching transaction on Taiko's chain, which let the attacker register fraudulent withdrawals and drain funds from the bridge and its token vault, Taiko said.
Bridges are blockchain-based tools that move assets between different chains, in this case, Taiko and Ethereum. Layer-2 blockchains process transactions off the main chain and settle them back to it, to provide faster, cheaper service than the host system.
The attacker's ability to forge valid-looking proofs indicates it may have had access to a leaked key.
Security firm BlockSec said its initial investigation traced the likely cause to a signing key for Raiko, which Taiko uses to produce proofs indicating a transaction is genuine, that was left publicly accessible on GitHub.
The key is meant to stay sealed inside secure hardware so the proofs can be trusted. If it's exposed, attackers can enroll their own provers as legitimate and sign fraudulent proofs that Taiko's verifier accepted, then fake a bridge withdrawal that releases real assets on Ethereum.
. @taikoxyz was reportedly attacked, with losses exceeding $1.7M. Our initial investigation suggests the likely root cause was an exposed Raiko SGX enclave signing key on GitHub. Raiko is Taiko’s multi-prover stack for Taiko and Ethereum blocks, so an exposed Raiko SGX enclave key… https://t.co/8BIiEeNtYJ pic.twitter.com/eAq9Xjngz8
Taiko urged all users to withdraw from every bridge on the network, asked centralized exchanges to suspend deposits of its TAIKO token, and had its block producers stop making new blocks during the investigation.
By about 2 a.m. ET Taiko said the exploit had been contained and that withdrawals through the main bridge and token vault halted. The exploiter had already moved about 2 million TAIKO, worth roughly $170,000, to an account on the MEXC exchange.
The dollar loss is small, but the flaw came from the same DeFi mechanism that has caused hundreds of millions worth of losses this year.
Forged cross-chain messages drained $292 million from Kelp DAO's bridge in April and $11.4 million from the Verus-Ethereum bridge in May. Bridges have produced more than $340 million in losses across at least 14 exploits in 2026, making it the costliest target in crypto. Taiko's damage stayed contained mainly because the team caught and froze it within hours.
Taiko, which started up on Ethereum in May 2024, said it is preparing a full breakdown of the incident.
In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high.
Disclosure & Polices : CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies . CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of Bullish (NYSE:BLSH), an institutionally focused global digital asset platform that provides market infrastructure and information services. Bullish owns and invests in digital asset businesses and digital assets and CoinDesk employees, including journalists, may receive Bullish equity-based compensation.
新闻图片





