Fact-check findings
What an automated fact-checker found when it re-read Across Protocol Solana Bridge Exploit (July 2026) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
2 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #11[disputed][awaiting moderator]in the timeline
“2026-07-18”
reviewerThe restoration of Solana deposits (~12 hours after the attack) occurred on 2026-07-18.The page's own summary and Section 5 both state restoration happened 'within roughly 12 hours' of an attack that began at 05:07 UTC and was detected at 05:30 UTC on July 17 -- arithmetically that lands on the evening of July 17, not July 18. An independently found source explicitly states restoration was 'the same day' as the attack, contradicting the timeline's dating of this event to July 18.Proposed correction (not yet applied)2026-07-17 - #20[disputed][awaiting moderator]in the timeline
“2026-03-26”
reviewerThe Across Protocol DAO voted on the AcrossCo transition on 2026-03-26, passing with 91.51% of votes in favor.Sources conflict: one page-cited source (whale-alert.io) agrees with March 26, but the governance forum's own posted timeline separates a March 26 'finalized proposal' step from an estimated April 2 Snapshot vote, and an independent governance-calendar listing places the vote window at March 31-April 7. The publish date of the page's primary cited source (Phemex, April 7) reporting the result as apparently fresh news is also more consistent with an early-April vote than a March 26 vote. On balance the evidence favors early April over March 26, though this is not fully resolved.Proposed correction (not yet applied)2026-04-02
unverifiable
3 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #16[unverifiable][awaiting moderator]in section: Prior Security Disclosure and Patch History
“At the time, no funds were lost; the Solana deployment was in a trial phase supporting only USDC with additional relayer-level safeguards limiting exploit viability.”
reviewerAt the time of the April disclosure, the Solana deployment was in a trial phase supporting only USDC, with additional relayer-level safeguards limiting exploit viability.Could not independently confirm this specific characterization of the April 2026 Solana deployment's scope. - #18[unverifiable][awaiting moderator]in section: Attacker Fund Routing and On-Chain Forensics
“The majority of funds were subsequently consolidated to a separate address holding approximately 1,500 ETH (valued at approximately $2.85 million at the time).”
reviewerThe majority of funds were subsequently consolidated to a separate address holding approximately 1,500 ETH (valued at approximately $2.85 million at the time).This specific on-chain forensic detail could not be found in any source consulted, including the section's own cited sources. - #30[unverifiable][awaiting moderator]in section: Broader Context: July 2026 Bridge Hack Wave
“The year-to-date total for bridge hacks in 2026 was reported at over $355 million across approximately 20 documented incidents as of late July.”
reviewerThe year-to-date total for bridge hacks in 2026 was reported at over $355 million across approximately 20 documented incidents as of late July.No source consulted, including the section's own cited source, contains this specific year-to-date figure or incident count. Other trackers found independently suggest a materially higher running total by late July, but methodologies differ enough (which incidents count as 'bridge hacks') that this cannot be called a clean contradiction -- it is unverifiable rather than disputed.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #32[link rot][awaiting moderator]in the cited sources
“https://www.coindesk.com/tech/2026/07/17/across-protocol-reports-first-attack-on-solana-after-34b-in-bridge-volume/”
reviewerA sources_used entry cites a coindesk.com URL under the headline 'Solana Foundation launches security overhaul days after $270 million Drift exploit,' distinct from the correctly-cited version of that same article used elsewhere on the page.The entry's 'name' field ('Solana Foundation launches security overhaul days after $270 million Drift exploit') matches a different, correctly-cited CoinDesk URL already present elsewhere in sources_used (the April 7 STRIDE/Drift piece), strongly suggesting this is a malformed duplicate record pointing at a nonexistent URL rather than an independent source.Proposed correction (not yet applied)https://www.coindesk.com/tech/2026/04/07/solana-foundation-unveils-security-overhaul-days-after-usd270-million-drift-exploit
partially supported
3 claimsThe cited evidence supports part of the claim but not all of it.
- #15[partially supported][awaiting moderator]in section: Prior Security Disclosure and Patch History
“Across had participated in the Solana Foundation's STRIDE (Solana Trust, Resilience and Infrastructure for DeFi Enterprises) security program, which was launched in April 2026 in partnership with Asymmetric Research following the Drift Protocol exploit.”
reviewerAcross had participated in the Solana Foundation's STRIDE security program, launched in April 2026 in partnership with Asymmetric Research following the Drift Protocol exploit.The STRIDE program's existence, launch date, and origin (post-Drift exploit) are all independently confirmed. Across's specific participation in the program could not be independently verified in any source consulted. - #29[partially supported][awaiting moderator]in section: Broader Context: July 2026 Bridge Hack Wave
“The week of July 17-24 alone saw approximately $47 million in losses across bridge protocols.”
reviewerThe week of July 17-24 alone saw approximately $47 million in losses across bridge protocols.The $47 million figure itself is correct, but the cited source attributes it to a different seven-day window than the one stated on the page. - #31[partially supported][awaiting moderator]in section: Architectural Risk Assessment: Intent-Based Relayer Model
“For Solana, where the absence of a canonical event system requires events to be reconstructed from transaction traces, this trust boundary proved to be the attack surface.”
reviewerThis trust boundary (Solana event reconstruction without transaction-status gating) is illustrated more generally as a source of cross-chain bridge risk, citing an architectural risk discussion including wrapped-asset mechanics.The core claim about Solana's event-reconstruction trust boundary is well supported by other sources in this section (Asymmetric Research, startupfortune.com), but cryptodaily.co.uk is cited alongside them despite not actually discussing the intent-based relayer model or this specific attack surface -- a citation-relevance mismatch rather than a factual error.
confirmed
23 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Incident Overview
“At approximately 05:07 UTC on July 17, 2026, an attacker began submitting forged deposit events to the Solana deployment of the Across Protocol cross-chain bridge.”
reviewerAttack began at approximately 05:07 UTC on July 17, 2026 and lasted roughly 67 minutes, ending ~06:14 UTC.Timing matches the cited source and is corroborated by independent web search of multiple outlets covering the incident. - #2[confirmed][no action needed]in section: Incident Overview
“the attacker used 1,627 single-use Solana wallets to create the same number of fabricated deposit events, representing a combined face value of approximately $41.7 million, with payouts requested across 18 destination chains”
reviewerThe attacker used 1,627 single-use Solana wallets to create 1,627 fabricated deposit events with a combined face value of approximately $41.7 million, requesting payouts across 18 destination chains.All figures independently corroborated. - #3[confirmed][no action needed]in section: Incident Overview
“All funds were directed to a single EVM-compatible recipient address.”
reviewerAll fraudulent payout requests were directed to a single EVM-compatible recipient address.Consistent across sources. - #4[confirmed][no action needed]in section: Incident Overview
“Risk Labs' relayer filled 581 of those fraudulent requests — approximately 35.7% of the total volume of requests but only 10.8% of their stated face value — advancing roughly $4.5 million of its own capital before the team disabled Solana as an origin chain.”
reviewerRisk Labs' relayer filled 581 of the fraudulent requests (~35.7% of request volume, ~10.8% of face value), advancing approximately $4.5 million before Solana was disabled as an origin chain.Exact figures verified. - #5[confirmed][no action needed]in section: Incident Overview
“Approximately $500,000 in attacker funds were trapped within the protocol, bringing the net loss to the relayer below $4 million.”
reviewerApproximately $500,000 in attacker funds were trapped within the protocol, bringing the net loss below $4 million.Matches cited source. - #6[confirmed][no action needed]in section: Incident Overview
“Across Protocol characterized the final confirmed net loss as approximately $3.35 million based on inflows to flagged EVM addresses.”
reviewerAcross Protocol characterized the final confirmed net loss as approximately $3.35 million based on inflows to flagged EVM addresses.The page correctly distinguishes the $3.35M confirmed-inflow figure from the ~$4M gross relayer capital figure; both are independently attested. - #7[confirmed][no action needed]in section: Incident Overview
“No user of the Across Protocol incurred any loss; every legitimate bridge transfer was either completed or fully refunded on July 17.”
reviewerNo user of Across Protocol incurred any loss; every legitimate transfer was completed or fully refunded on July 17.Universally corroborated. - #8[confirmed][no action needed]in section: Protocol Response and Recovery
“Across invalidated the remaining 1,046 unfilled fraudulent requests, preventing approximately $37 million in additional payouts.”
reviewerAcross Protocol detected the attack at approximately 05:30 UTC, roughly 23 minutes after the first fraudulent deposits began, and invalidated the remaining 1,046 requests, preventing ~$37 million in additional payouts.Arithmetically and factually consistent with other confirmed figures. - #9[confirmed][no action needed]in section: Protocol Response and Recovery
“Risk Labs engaged SEAL 911 — a DeFi security coalition — to monitor the flagged attacker addresses.”
reviewerSEAL 911 was engaged to monitor flagged attacker addresses.Confirmed. - #10[confirmed][no action needed]in section: Protocol Response and Recovery
“Solana deposits were restored within approximately 12 hours of the attack, using Circle's Cross-Chain Transfer Protocol (CCTP) as an alternative routing mechanism during the relaunch.”
reviewerSolana deposits were restored within approximately 12 hours of the attack using Circle's CCTP as an alternative routing mechanism.The substantive content (12 hours, CCTP) is confirmed, though see the separate finding on the timeline date assigned to this event, which is inconsistent with the '12 hours' claim. - #12[confirmed][no action needed]in section: Protocol Response and Recovery
“The incident was described by the team as Across Protocol's first exploit in approximately five years of operation and over $34 billion in total bridged volume.”
reviewerThe incident was described by the team as Across Protocol's first exploit in approximately five years of operation and over $34 billion in total bridged volume.Confirmed; 2021 launch to 2026 incident is consistent with 'approximately five years.' - #13[confirmed][no action needed]in section: Attack Vector: Solana Event Spoofing
“This class of vulnerability was first publicly disclosed by security firm Asymmetric Research on April 22, 2026.”
reviewerThe vulnerability class was first publicly disclosed by Asymmetric Research on April 22, 2026, and Across patched the issue within hours; no funds were lost at the time.Directly verified against the primary disclosure source. - #14[confirmed][no action needed]in section: Prior Security Disclosure and Patch History
“The firm described the attack path in detail: an attacker could take a flash loan, perform a deposit transaction emitting a FundsDeposited event, force transaction reversion on the next instruction, wait for relayers to queue transfers based on the fake event, and then receive funds on the destination chain without depositing any actual collateral.”
reviewerThe root cause was that Risk Labs' event indexer checked for the correct program address and PDA signer authority but never validated the transaction's overall success status, and the attack path could be paired with a flash loan.Confirmed against primary source. - #17[confirmed][no action needed]in section: Attacker Fund Routing and On-Chain Forensics
“On Solana, investigators identified the address 8bkoZTaTBBtAPczgHqD4XVxWtvBkiy4crtexEtYDYSL. On EVM-compatible chains, two addresses were flagged: 0xa0C0e9f307b5A26cA3FB5891c19154fc7A02BeF7 and 0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189.”
reviewerThree addresses (one Solana, two EVM) were publicly flagged in connection with the attack: 8bkoZTaTBBtAPczgHqD4XVxWtvBkiy4crtexEtYDYSL, 0xa0C0e9f307b5A26cA3FB5891c19154fc7A02BeF7, and 0xA6fb971F3B7a9b9F76EdA76bc89268fe26560189.Address prefixes independently corroborated; full strings not independently re-derived on-chain but consistent with multiple outlet reporting. - #19[confirmed][no action needed]in section: Attacker Fund Routing and On-Chain Forensics
“The attacker's wallets were alleged to have been funded via Tornado Cash on Ethereum and FixedFloat on Solana — platforms frequently associated with illicit fund sourcing in DeFi exploit investigations.”
reviewerThe attacker's wallets were funded via Tornado Cash on Ethereum and FixedFloat on Solana.Directly confirmed against the cited source. - #21[confirmed][no action needed]in section: Governance Transition: DAO Dissolution and AcrossCo
“The governance proposal passed with 91.51% of votes in favor.”
reviewerThe governance proposal passed with 91.51% of votes in favor.Percentage confirmed; only the associated timeline date is disputed (see separate finding). - #22[confirmed][no action needed]in section: Governance Transition: DAO Dissolution and AcrossCo
“The ACX token surged approximately 80% on the announcement, reaching roughly $0.06 from a prior level near $0.033.”
reviewerThe ACX token surged approximately 80% on the announcement, reaching roughly $0.06 from a prior level near $0.033.Confirmed. - #23[confirmed][no action needed]in section: Governance Transition: DAO Dissolution and AcrossCo
“ACX token holders were offered two options: a 1:1 exchange of tokens for shares in AcrossCo (with equity access above 5 million ACX available directly and a no-fee SPV structure for holders of at least 250,000 ACX), or a USDC buyout at $0.04375 per token — a stated 25% premium to the 30-day average price prior to the announcement.”
reviewerACX holders were offered a 1:1 equity exchange (direct access above 5 million ACX, no-fee SPV for holders of at least 250,000 ACX) or a USDC buyout at $0.04375/token, a 25% premium to the 30-day average; the buyout window opens within three months of approval and stays open six months.All figures directly confirmed against the cited source. - #24[confirmed][no action needed]in section: Governance Transition: DAO Dissolution and AcrossCo
“The stated rationale was that the DAO structure had 'materially impacted' the protocol's ability to close institutional partnerships and integrations.”
reviewerThe stated rationale was that the DAO structure had 'materially impacted' the protocol's ability to close institutional partnerships and integrations, and the buyout window was set to open within three months of approval and remain open for six months, funded by protocol liquid assets.Quote and buyout-window mechanics both independently corroborated. - #25[confirmed][no action needed]in section: Broader Context: July 2026 Bridge Hack Wave
“AFX Trade, an Arbitrum-based perpetuals DEX, was drained of $24.15 million on July 22 after an attacker obtained private keys from five bridge validators, meeting the quorum required to authorize a fraudulent withdrawal. Security firm Blockaid detected the exploit at 21:30 UTC; the stolen USDC was converted into approximately 12,467.5 ETH. AFX Trade subsequently offered the attacker a 30% bounty to return the remainder.”
reviewerAFX Trade was drained of $24.15 million on July 22 after an attacker obtained private keys from five bridge validators, meeting quorum; Blockaid detected the exploit at 21:30 UTC; stolen USDC was converted to approximately 12,467.5 ETH; AFX Trade offered a 30% bounty.All figures independently confirmed. - #26[confirmed][no action needed]in section: Broader Context: July 2026 Bridge Hack Wave
“The Verus-Ethereum bridge was exploited for $7.54 million on July 23 in what was alleged to be a repeat attack using the same vulnerability path as a May 2026 incident that had drained approximately $11.58 million from the same contract. The July attack was attributed to a different wallet, suggesting a distinct actor using publicly known exploit code.”
reviewerThe Verus-Ethereum bridge was exploited for $7.54 million on July 23, a repeat attack using the same vulnerability path as a May 2026 incident that drained ~$11.58 million from the same contract, attributed to a different wallet.Directly confirmed against the cited source. - #27[confirmed][no action needed]in section: Broader Context: July 2026 Bridge Hack Wave
“Allbridge lost $1.65 million via a flash loan-powered price manipulation attack on a Solana liquidity pool, while TeleSwap incurred approximately $735,000 in losses in a separate incident identified by on-chain investigator ZachXBT.”
reviewerAllbridge lost $1.65 million via a flash loan-powered price manipulation attack on a Solana liquidity pool; TeleSwap incurred approximately $735,000 in losses, identified by ZachXBT.Both figures directly confirmed against cited sources. - #28[confirmed][no action needed]in section: Broader Context: July 2026 Bridge Hack Wave
“which collectively pushed monthly bridge-related losses to approximately $97 million — exceeding the prior month's figure of $75.32 million”
reviewerJuly 2026 bridge-related losses reached approximately $97 million, exceeding June's $75.32 million.Directly confirmed against the cited source.