ChainCatcher reported, citing Blockaid monitoring, that Taiko’s ERC20 Vault on Ethereum was attacked, resulting in losses of more than $1 million. The incident involved the message verification process of Taiko’s cross-chain bridge. According to the monitoring information, the attacker was able to have crafted message proofs accepted as valid on Ethereum L1.
Verification flaw tied to source signal proofs
Blockaid identified the root cause as a defect in the verification of source signal proofs within the Taiko bridge. Under the expected flow, a cross-chain message should correspond to a legitimate MessageSent event on the Taiko source chain. In this case, the constructed proof was accepted on Ethereum L1 without a matching valid MessageSent event on the source chain.
That verification gap allowed the attacker to register and withdraw fraudulent cross-chain messages, which in turn released assets from the ERC20 Vault without authorization. Based on the information disclosed, the loss exceeded $1 million, and the core of the incident centered on Taiko’s Ethereum ERC20 Vault and the bridge’s message proof verification mechanism.

