Taiko Bridge Exploited for $1.7M via Forged Cross-Chain Proofs, Exposed Key Suspected
Taiko, an Ethereum layer-2 network, halted block production and urged users to withdraw funds after an attacker exploited its bridge to steal about $1.7 million. The attacker forged cross-chain proofs to make fake withdrawal requests on Ethereum without matching deposits on Taiko, draining the bridge and token vault. Security firm BlockSec traced the likely cause to an exposed Raiko SGX enclave signing key on GitHub, which allowed the attacker to sign fraudulent proofs. The breach used the same cross-chain messaging flaw behind over $340 million in bridge hacks this year, including the $292 million Kelp DAO incident. Taiko's quick containment minimized losses, and the team plans to release a full incident report. The TAIKO token dropped over 20%.
Key facts
- Attacker forged cross-chain proofs to drain ~$1.7M from Taiko's bridge and token vault.
- Security firm BlockSec suspects cause is an exposed Raiko SGX signing key on GitHub.
- Exploit used same cross-chain messaging flaw behind over $340M in bridge hacks in 2026.
- Taiko halted block production, urged withdrawals, and contained the exploit within hours.
- TAIKO token price dropped over 20% since the attack.