According to Across Protocol's post-incident report issued July 25, attackers exploited a vulnerability in Risk Labs' Solana off-chain software on July 17, forging 1,627 fake deposits totaling $41.7 million. Relayer completed 581 advance payments worth $4.5 million before halting Solana services; approximately $500,000 of attacker funds remained trapped in the protocol, resulting in a net loss below $4 million.
Across emphasized that user funds were never at risk. All user transfers were completed or fully refunded on the same day, and all losses were limited to Risk Labs' relay operations. No smart contracts were exploited. The vulnerability existed solely in the Risk Labs relay codebase, not in Solana or EVM contracts.