Across Protocol Solana attack: relayer loss capped under $4M, ACX buyback intact

Across Protocol says its Risk Labs-operated relayer lost less than $4M after an attacker fabricated $41.7M in Solana deposit events. The attack ran on July 17 between 05:07–06:14 UTC and used 1,627 single-use Solana wallets to create 1,627 fake deposits targeting 18 destination chains. Across Protocol reports that its relayer processed 581 fraudulent requests (35.7% of total). The relayer paid out $4.5M, but about $500k of the attacker’s funds remained trapped inside the protocol, bringing the net relayer loss to under $4M. The remaining 1,046 requests were not executed; Across invalidated roughly $37M of unpaid fake deposits. The protocol says no users lost funds and all legitimate transfers were completed or fully refunded on the day. Across Protocol attributes the incident to a bug in its off-chain Solana event-reading software (not smart-contract flaws). After the attack, Across restored Solana transfers in about 12 hours via a fallback route using Circle’s CCTP (burn-and-mint USDC). The fix was deployed roughly five hours after the incident. Market note: ACX was around $0.04135 at reporting time (down ~2.8% on the day) with a stated plan to keep its token buyback unchanged. Across has not disclosed whether other relayer spending or operations are affected.
Neutral
This is likely neutral-to-slightly bearish for sentiment, but the direct market impact is limited. Across Protocol reports a < $4M relayer loss, no user fund loss, and that legitimate transfers were completed/refunded. That reduces immediate contagion risk for bridge users, especially versus incidents where users or on-chain contract logic are directly drained. However, the attack highlights an ongoing category risk: cross-chain systems can be vulnerable through relayer/off-chain components, not only smart contracts. Similar past bridge/relayer failures often trigger short-term risk-off moves in related tokens and liquidity, as traders reprice “infrastructure trust.” Here, ACX did drop and the incident required routing changes (CCTP fallback), which can pressure sentiment in the short run. Longer term, the fast root-cause fix (~5 hours) and the use of CCTP routing may stabilize expectations if monitoring confirms the attacker-linked funds remain contained. Traders should watch for (1) any further movement of attacker-linked assets and (2) whether Across later restores its previous Solana routing without regressions. Until then, the headline “< $4M loss” supports a neutral view.