Skip to main content
Sign in

Audit log

Every state-changing event for Taiko Bridge SGX Key Exploit (June 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-29 12:27:20Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    JBYJiodPP2g8…QxT7CzBfsha256 → base58
    verifying row…
    canonical bytes (17696 B) ▸
    {"actor":"system:backfill","investigation_id":"906525a5-b86d-4d1f-bfd6-a3c27a894f5d","kind":"publish","page_slug":"taiko-bridge-sgx-key-exploit-june-2026","published_at":"2026-07-29T12:27:20.626Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Taiko Bridge SGX Key Exploit (June 2026)","sections":[{"content":"On June 22, 2026, Taiko — an Ethereum-equivalent ZK rollup operating under the name Taiko Alethia — confirmed that its L1 bridge and ERC20Vault contracts had been exploited for approximately $1.7 million. The attack was made possible by an operational security failure: an RSA-3072 private key file named enclave-key.pem, used to authenticate Intel SGX enclave computations for Taiko's Raiko multi-prover stack, had been publicly committed to the open-source taikoxyz/raiko GitHub repository. With this key, the attacker was able to register their own hardware as a trusted SGX prover and generate fraudulent withdrawal proofs that Taiko's on-chain verifier accepted as legitimate, allowing assets to be released from L1 custody without any corresponding deposits on the Taiko chain.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":1,"name":"Taiko halts its Ethereum layer-2 network after a bridge exploit, token dives — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"credibility":2,"name":"$1.7M Gone: Taiko Bridge Exploited After SGX Signing Key Leak — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/22/1-7m-gone-taiko-bridge-exploited-after-sgx-signing-key-leak/"},{"credibility":2,"name":"Taiko Bridge Source-Signal Proof Forgery — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"}]},{"content":"Taiko's Raiko proving stack relies on Intel SGX (Software Guard Extensions) enclaves to generate cryptographic attestations of L2 state transitions. The MrSigner value embedded in Taiko's on-chain verifier contracts is derived from the RSA-3072 public key corresponding to the enclave signing key. An enclave signed with the matching private key is treated by the contracts as a trusted prover. The file enclave-key.pem, containing this RSA-3072 private key, was allegedly committed to the public taikoxyz/raiko GitHub repository and left publicly readable. Security firm BlockSec identified the exposed key as the likely root cause following a preliminary investigation. Quill Audits also disclosed and analyzed the exploit publicly. Because the on-chain verifier contracts derive trust solely from the MrSigner attestation and do not apply additional controls, possession of the private key was sufficient to register an attacker-controlled enclave as a fully trusted prover.","heading":"Root Cause: Exposed SGX Signing Key on GitHub","severity":"critical","sources":[{"credibility":2,"name":"Taiko Bridge Exploit: How a Leaked Key Drained $1.7M from an Ethereum L2 — thirdweb Blog","type":"research","url":"https://blog.thirdweb.com/taiko-bridge-exploit-explained-how-a-leaked-key-led-to-1-7m-in-forged-withdrawals/"},{"credibility":2,"name":"Taiko Bridge Drained $1.7M After SGX Signing Key Left Exposed on GitHub — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/taiko-bridge-exploit-sgx-signing-key-github-1-7m"},{"credibility":2,"name":"Taiko Bridge Source-Signal Proof Forgery — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"}]},{"content":"Technical analysis by DARKNAVY identified a four-phase attack sequence beginning on June 21, 2026. In the first phase, the attacker (primary wallet: 0x7506DeA0c38ca0B55364B22424374c5A1ae1B76a) registered two malicious SGX verifier instances (IDs 5 and 6) in a single transaction (0x2f44dc1b883522a88f9b0cbbdfabf9ec33884b69dd4326600c3fab7fb2277260). A compounding configuration flaw, INSTANCE_VALIDITY_DELAY set to zero, meant that freshly registered SGX instances could immediately authorize high-value withdrawals in the same transaction, eliminating any finality window that might have detected the fraud. In the second phase, the attacker submitted a malicious checkpoint for Taiko block 1805600 with an attacker-controlled state root (0x5064e2a3dfde1cd6d164e07b5dae47433d20a2d2c1ba6c9bda60c1ab6765215f). In the third phase, the attacker called Bridge.processMessage() ten times with forged message hashes, marking them as RETRIABLE; no corresponding MessageSent events existed on the Taiko chain for the sampled hashes. In the fourth phase, follow-up transactions released tokens from the ERC20Vault and ETH holdings. The vulnerable contracts were the Bridge (0xd60247c6...), SignalService (0x9e0a2496...), and ERC20Vault (0x996282cA...). The bridge's SignalService.proveSignalReceived() accepted Merkle proofs against any saved checkpoint without independently verifying that a legitimate MessageSent event had been emitted on the source chain, making it structurally susceptible once a trusted prover was compromised. Three additional attacker-linked wallets were also disclosed: 0x5fbc60a12bc6635e7d587d8dac52e4b1388b4990, 0x3cc936b795a188f0e246cbb2d74c5bd190aecf18, and 0x9108828e30f2de407aadb0af677b4a9228e4acd4.","heading":"Attack Mechanism and On-Chain Execution","severity":"critical","sources":[{"credibility":2,"name":"Taiko Bridge Source-Signal Proof Forgery — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"},{"credibility":3,"name":"Taiko Bridge Exploit June 2026: $1.7M SGX Key Leak Explained — SpottedCrypto","type":"news_article","url":"https://www.spotedcrypto.com/taiko-bridge-exploit-june-2026/"}]},{"content":"The DARKNAVY technical analysis catalogued the following assets drained from the L1 Bridge and ERC20Vault contracts: 675,761.24 USDC; 138,139.56 USDT; 156,832.01 crvUSD; 150.70 ETH and WETH; plus smaller amounts of WBTC, weETH, CRV, iZi, and TAIKO tokens, bringing the total to approximately $1.7 million. On-chain tracking by Lookonchain identified that 1.99 million TAIKO tokens (approximately $189,000 at the time) were moved to the MEXC exchange, while approximately 870.8 ETH (valued at nearly $1.52 million) remained in the attacker's primary wallet as of initial reporting. The TAIKO token declined more than 20% from its midnight UTC price following the disclosure, falling to approximately $0.07294.","heading":"Assets Drained and Fund Movement","severity":"high","sources":[{"credibility":2,"name":"Taiko Bridge Source-Signal Proof Forgery — DARKNAVY Blog","type":"on_chain","url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"},{"credibility":1,"name":"Taiko halts its Ethereum layer-2 network after a bridge exploit, token dives — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"credibility":2,"name":"Taiko urges users to exit bridges after a verification flaw — MEXC News","type":"news_article","url":"https://www.mexc.com/news/1163847"}]},{"content":"Taiko's Security Council paused both the Bridge and ERC20Vault contracts on June 22, 2026, halting all withdrawals by approximately 2 a.m. ET. Block production was stopped entirely, with all proposers instructed to cease generating new blocks while the team coordinated containment with ecosystem partners. Taiko publicly urged users to withdraw remaining bridge funds and asked centralized exchanges to suspend TAIKO token deposits in order to limit attacker liquidity. The team confirmed the exploit was fully contained on the same day. Security firms BlockSec (via its Phalcon monitoring system) and Quill Audits both disclosed analysis of the incident publicly, identifying the exposed SGX key as the root cause.","heading":"Immediate Response and Bridge Pause","severity":"high","sources":[{"credibility":1,"name":"Taiko halts its Ethereum layer-2 network after a bridge exploit, token dives — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"credibility":2,"name":"Taiko Exploit Adds to June Tally of Over 20 Crypto Hacks — BeInCrypto","type":"news_article","url":"https://beincrypto.com/taiko-bridge-exploit-june-crypto-hacks/"},{"credibility":2,"name":"$1.7M Gone: Taiko Bridge Exploited After SGX Signing Key Leak — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/22/1-7m-gone-taiko-bridge-exploited-after-sgx-signing-key-leak/"}]},{"content":"Taiko outlined a four-stage recovery plan on June 29, 2026. The protocol patched the proof verification flaw, revoked the compromised SGX signing key's authority, and replenished bridge reserves to full 1:1 backing. An independent security review was completed before the bridge was authorized to reopen; the reviewing firm was not publicly named in available reporting. The bridge reopened on July 2, 2026, ten days after the exploit, under conservative withdrawal quotas rather than an immediate full restoration. Taiko's Security Council oversaw the final unpause. The team confirmed that all affected users were made whole. No postmortem document was publicly named in available reporting as of the investigation date, though the team pledged to publish one. The TAIKO token recovered sharply on the reopening announcement, rising as much as 136% in the period following July 2, partially reflecting relief over the swift resolution and full user restitution.","heading":"Recovery, Patch, and Bridge Reopening","severity":"medium","sources":[{"credibility":1,"name":"Taiko fully restores cross-chain bridge just 10 days after a $1.7 million hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/02/taiko-s-bridge-is-back-online-after-usd1-7-million-hack-and-its-token-is-up-a-staggering-136"},{"credibility":2,"name":"Taiko reopens bridge after recovering from $1.7M exploit last month — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/taiko-reopens-bridge-after-exploit-recovery/"}]},{"content":"The Taiko incident occurred within a broader surge in cross-chain bridge exploits in 2026. PeckShield documented $340.7 million in losses across at least 14 bridge exploits during the year as of the time of reporting, making bridges the costliest attack surface in crypto during this period. The Taiko exploit was categorized as an operational security failure — a private key committed to a public repository — rather than a flaw in Taiko's underlying ZK proof system or consensus mechanism. Security researchers noted that the SGX trust model, which relies entirely on hardware attestation and key management discipline, collapses if signing credentials are mishandled, regardless of the sophistication of the surrounding cryptographic architecture.","heading":"Systemic Context: Bridge Exploit Epidemic in 2026","severity":"medium","sources":[{"credibility":2,"name":"Taiko Exploit Adds to June Tally of Over 20 Crypto Hacks — BeInCrypto","type":"news_article","url":"https://beincrypto.com/taiko-bridge-exploit-june-crypto-hacks/"},{"credibility":2,"name":"Ethereum L2 Bridge Exploit Drains $1.7M: Leaked SGX Key Defeats Taiko Trust Model — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/318886/20260623/ethereum-l2-bridge-exploit-drains-17m-leaked-sgx-key-defeats-taiko-trust-model.htm"}]}],"sources_used":[{"credibility":1,"name":"Taiko halts its Ethereum layer-2 network after a bridge exploit, token dives — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"credibility":1,"name":"Taiko fully restores cross-chain bridge just 10 days after a $1.7 million hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/02/taiko-s-bridge-is-back-online-after-usd1-7-million-hack-and-its-token-is-up-a-staggering-136"},{"credibility":2,"name":"Taiko Bridge Source-Signal Proof Forgery — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"},{"credibility":2,"name":"Taiko Bridge Drained $1.7M After SGX Signing Key Left Exposed on GitHub — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/taiko-bridge-exploit-sgx-signing-key-github-1-7m"},{"credibility":2,"name":"Taiko Bridge Exploit: How a Leaked Key Drained $1.7M from an Ethereum L2 — thirdweb Blog","type":"research","url":"https://blog.thirdweb.com/taiko-bridge-exploit-explained-how-a-leaked-key-led-to-1-7m-in-forged-withdrawals/"},{"credibility":2,"name":"$1.7M Gone: Taiko Bridge Exploited After SGX Signing Key Leak — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/22/1-7m-gone-taiko-bridge-exploited-after-sgx-signing-key-leak/"},{"credibility":2,"name":"Taiko reopens bridge after recovering from $1.7M exploit last month — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/taiko-reopens-bridge-after-exploit-recovery/"},{"credibility":2,"name":"Taiko Exploit Adds to June Tally of Over 20 Crypto Hacks — BeInCrypto","type":"news_article","url":"https://beincrypto.com/taiko-bridge-exploit-june-crypto-hacks/"},{"credibility":2,"name":"Ethereum L2 Bridge Exploit Drains $1.7M: Leaked SGX Key Defeats Taiko Trust Model — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/318886/20260623/ethereum-l2-bridge-exploit-drains-17m-leaked-sgx-key-defeats-taiko-trust-model.htm"},{"credibility":2,"name":"Taiko Bridge Exploit: Why L2 Withdrawal UX Is Becoming a DeFi Safety Test — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/06/taiko-bridge-exploit-l2-withdrawal-ux-defi-safety-test"},{"credibility":2,"name":"Taiko urges users to exit bridges after a verification flaw — MEXC News","type":"news_article","url":"https://www.mexc.com/news/1163847"},{"credibility":3,"name":"Taiko Bridge Exploit June 2026: $1.7M SGX Key Leak Explained — SpottedCrypto","type":"news_article","url":"https://www.spotedcrypto.com/taiko-bridge-exploit-june-2026/"}],"summary":"On June 22, 2026, Taiko's Ethereum L1 bridge was exploited for approximately $1.7 million after an RSA-3072 SGX enclave signing key for the Raiko prover stack was accidentally committed to a public GitHub repository. The attacker used the exposed key to register fraudulent SGX prover instances and forge cross-chain withdrawal proofs, draining USDC, USDT, ETH, and other tokens from the bridge and ERC20Vault contracts. Taiko paused bridge operations within hours, made all affected users whole within ten days, and reopened the bridge on July 2, 2026 following an independent security review.","timeline":[{"date":"2026-06-21","event":"Attacker begins exploit sequence: registers two malicious SGX verifier instances (IDs 5 and 6) on Ethereum mainnet using the exposed RSA-3072 signing key from the taikoxyz/raiko GitHub repository.","source":"DARKNAVY Blog — Taiko Bridge Source-Signal Proof Forgery","source_url":"https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"},{"date":"2026-06-22","event":"Attacker submits malicious checkpoint, calls Bridge.processMessage() ten times with forged message hashes, and releases approximately $1.7 million in USDC, USDT, crvUSD, ETH/WETH, and other tokens from the L1 Bridge and ERC20Vault contracts.","source":"DARKNAVY Blog; CoinDesk","source_url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"date":"2026-06-22","event":"Taiko's Security Council pauses Bridge and ERC20Vault contracts by approximately 2 a.m. ET. Block production is halted. Team publicly urges users to withdraw remaining bridge funds and asks exchanges to suspend TAIKO deposits.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"},{"date":"2026-06-22","event":"TAIKO token declines more than 20% from midnight UTC price. Approximately 1.99 million TAIKO (roughly $189,000) moved by attacker to MEXC exchange.","source":"CoinDesk; CryptoTimes","source_url":"https://www.cryptotimes.io/2026/06/22/1-7m-gone-taiko-bridge-exploited-after-sgx-signing-key-leak/"},{"date":"2026-06-22","event":"BlockSec (Phalcon) issues preliminary analysis identifying the exposed Raiko SGX enclave signing key on GitHub as the likely root cause. Quill Audits also publicly discloses analysis.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/06/22/1-7m-gone-taiko-bridge-exploited-after-sgx-signing-key-leak/"},{"date":"2026-06-29","event":"Taiko team outlines a four-stage recovery plan covering patching, reserve replenishment, independent security review, and controlled bridge reopening.","source":"CryptoBriefing","source_url":"https://cryptobriefing.com/taiko-reopens-bridge-after-exploit-recovery/"},{"date":"2026-07-02","event":"Taiko bridge reopens under conservative withdrawal quotas after completing an independent security review. Security Council authorizes the final unpause. All affected users confirmed made whole. TAIKO token rises as much as 136% on the announcement.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/07/02/taiko-s-bridge-is-back-online-after-usd1-7-million-hack-and-its-token-is-up-a-staggering-136"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 1a850a33-6d5a-4dcc-a63a-52a980a987df
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.