Taiko Halts Bridge After Verification Breach Drains About $1.7 Million

Taiko Halts Bridge After Verification Breach Drains About $1.7 Million

N
News Editor 01
2026-07-23 17:20:15
Taiko paused its Bridge and ERC20Vault after a compromised chain-state verification mechanism enabled forged bridge messages. Researchers estimate roughly $1.7 million in assets left the protocol.
Taikobridge exploitsecurity breachERC20VaultTAIKO

Taiko has paused its Bridge and ERC20Vault after confirming that its chain-state verification mechanism was compromised. Researchers estimate the exploit led to roughly $1.7 million in assets leaving the protocol, with affected tokens including ETH, USDC, USDT, and TAIKO.

The project said the breached component is a core part of how bridge activity is validated across the network. In Taiko’s account, the issue weakened the security assumptions behind all bridges deployed on the chain. After researchers connected a bridge exploit on June 21 to losses of more than $1 million, the team issued an urgent security notice, told users to withdraw funds from affected bridges, and asked centralized exchanges to assist with emergency measures.

Bridge operations stopped and pending transfers remain frozen

Taiko said it moved quickly with its Security Council and ecosystem partners to contain the incident. At one stage, the team urged users to withdraw funds and asked centralized exchanges to suspend TAIKO deposits until further notice. It later said the incident had been contained.

Both the Bridge and the ERC20Vault are now paused, which means withdrawals have stopped entirely. Taiko said users no longer need to take action. The team also stated that pending transactions are paused rather than lost. During the investigation, block proposers also temporarily stopped producing new blocks.

Researchers say forged bridge messages passed verification

While the investigation was still underway, security firms and independent researchers published early findings. Blockaid said the attacker targeted Taiko’s ERC20 Vault on Ethereum, and early estimates put losses above $1 million. Later analysis raised that figure to around $1.7 million.

Security researcher Defi Nerd said the attacker registered new SGX verifier instances and created a checkpoint. Using that state, the attacker allegedly validated forged bridge messages. Those messages appeared legitimate inside the system even though they had no matching MessageSent events on the Taiko chain. Researchers added that the weakness did not originate in the ERC20 vault itself, but in the source-signal proof verification process.

Multiple assets were withdrawn as exchange warning stays in place

Investigators tracked withdrawals across a wide set of assets, including USDC, USDT, crvUSD, ETH, WETH, WBTC, weETH, CRV, iZi, and TAIKO. According to Lookonchain, the attacker sent 1.99 million TAIKO to MEXC, worth about $189,000 at the time. The wallet still held about 870.8 ETH, valued at roughly $1.52 million.

Taiko said a full post-mortem will be released later. Its request for exchanges to keep TAIKO deposits suspended remains in effect for now.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.