K

KeyAudit

· ·bridge-hack·infrastructure·private-key-leak

Taiko L2 Bridge Security Breach: Over $1.7M Lost, Users Urged to Withdraw

Taiko, an Ethereum layer-2 network using zero-knowledge rollups, confirmed on Sunday that its chain state verification mechanism was compromised, urging users to immediately withdraw funds from all bridges on the network. While Taiko did not disclose the cause or loss amount, BlockSec Phalcon estimated losses exceeding $1.7 million and attributed the attack to a publicly exposed Raiko SGX enclave signing key on GitHub. This key allegedly allowed attackers to register malicious SGX instances and generate fraudulent proofs accepted by Taiko's verification contracts. The attackers then forged a signal to trigger asset releases from the protocol's ERC20Vault. The incident follows a series of major crypto exploits, including a $292 million bridge hack on KelpDAO in April and a $77 million unauthorized minting on Echo Protocol in May. In total, DeFi protocols lost over $840 million in the first five months of the year.

Key facts

  • Taiko confirms chain state verification compromise, urges immediate withdrawal from all bridges.
  • BlockSec Phalcon estimates losses over $1.7M; links attack to exposed Raiko SGX signing key on GitHub.
  • Attackers used fraudulent proofs to release assets from Taiko's ERC20Vault.
  • Incident follows major exploits: $292M KelpDAO bridge hack (April) and $77M Echo Protocol minting (May).
  • DeFi losses exceed $840M in first five months of the year.

KeyAudit data perspective

📊 KeyAudit data: Ethereum historical leak records: 1752013

← Back to list