Fact-check findings
What an automated fact-checker found when it re-read Taiko L2 Bridge Exploit June 2026 against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #16[unverifiable][awaiting moderator]in section: Background: Taiko Protocol
“No prior major security incidents have been reported for Taiko prior to this June 2026 event.”
reviewerNo prior major security incidents have been reported for Taiko prior to this June 2026 event.This is a negative claim (absence of prior incidents); no contradicting evidence was found, but a clean bill cannot be affirmatively confirmed from the sources cited, neither of which is a comprehensive incident registry.
stale
1 claimThe claim was accurate when written but events since have overtaken it.
- #10[stale][awaiting moderator]in section: Four-Step Restart Plan
“At the time of publication, PR #21820 remained unmerged pending Security Council sign-off.”
reviewerPR #21820 bundles checkpoint versioning, Inbox.init2(), invalidation of three attacker message hashes, and QuotaManager restoration, and at time of publication remained unmerged pending Security Council sign-off.The page presents 'unmerged, pending sign-off' as the current status without a timestamp qualifier, but this is now superseded: the bridge fully reopened on July 2, 2026. The page's own timeline/sections do not reflect the bridge's reopening at all, which is a significant omission given it is the resolution of the entire incident.Proposed correction (not yet applied)Taiko's bridge fully reopened on July 2, 2026 -- roughly ten days after the exploit -- after completing 1:1 recollateralization and an independent security audit; PR #21820 was subsequently merged as part of that recovery process.
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #9[partially supported][awaiting moderator]in section: Four-Step Restart Plan
“Step three restores transfers, swaps, and trading on L2 before the bridge fully opens, allowing the team to monitor normal chain activity under live conditions. Step four reopens the bridge for general deposits and withdrawals after the post-fix audit and Security Council multisig approval.”
reviewerTaiko published a four-step restart plan on approximately June 28, 2026, including deploying PR #21820, full 1:1 recollateralization, restoring L2 activity, then reopening the bridge under Security Council approval.Steps one through three match the cited crypto.news article closely; step four is mischaracterized -- the source emphasizes withdrawal quotas as the safety mechanism, not an audit/multisig approval gate. - #12[partially supported][awaiting moderator]in section: Broader 2026 Bridge Exploit Context
“By mid-to-late June 2026, bridge hacks had totaled over $340 million across more than 14 separate incidents.”
reviewerBy mid-to-late June 2026, bridge hacks had totaled over $340 million across more than 14 separate incidents.The $340M/14+ figure is real but is sourced to a June 1-2 PeckShield report not cited on the page; the page's actual cited source (CryptoTimes, May 18) reports a different, lower figure ($328.6M/8). Additionally, framing the total as 'mid-to-late June' is misleading since the underlying data is from early June and excludes Taiko's own $1.7M loss.
confirmed
13 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“On June 21–22, 2026, Taiko — an Ethereum-equivalent Layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million (roughly 870 ETH and 1.99 million TAIKO tokens) by forging cross-chain withdrawal proofs using an SGX enclave signing key that had been publicly committed to the taikoxyz/raiko GitHub repository.”
reviewerOn June 21-22, 2026, Taiko suffered a bridge exploit draining approximately $1.7 million (~870 ETH and 1.99 million TAIKO) using a leaked SGX enclave signing key publicly committed to taikoxyz/raiko on GitHub.Core facts — date, dollar amount, SGX key leak on GitHub — are corroborated across at least six independent outlets (CoinDesk, Decrypt, CryptoTimes, Thirdweb, The Defiant, DarkNavy technical writeup). - #2[confirmed][no action needed]in section: Attack Mechanics
“Approximately 870 ETH (roughly $1.52 million) and 1.99 million TAIKO tokens (approximately $170,000–$189,000) were extracted.”
reviewerThe 870 ETH and 1.99 million TAIKO token figures represent the amount extracted in the exploit.Initial contract-level breakdown (130 ETH + WETH + stablecoins) differs from the 870 ETH headline figure, but multiple outlets independently report 870.8 ETH held in the attacker's consolidated address, reconciling the discrepancy as post-conversion holdings rather than a contradiction. - #3[confirmed][no action needed]in section: Affected Smart Contracts
“The Bridge contract at address 0xd60247c6848B7Ca29eDdF63AA924E53dB6Ddd8EC processed and released ETH-denominated messages. The ERC20Vault at address 0x996282cA11E5DEb6B5D122CC3B9A1FcAAD4415Ab released ERC-20 token balances.”
reviewerTwo Ethereum mainnet contracts (Bridge at 0xd60247c6848B7Ca29eDdF63AA924E53dB6Ddd8EC, ERC20Vault at 0x996282cA11E5DEb6B5D122CC3B9A1FcAAD4415Ab) were the ones directly drained.Both addresses independently verified on Etherscan as Taiko-labeled contracts. - #4[confirmed][no action needed]in section: Root Cause: Exposed SGX Signing Key
“an RSA-3072 private key used for Intel SGX enclave signing — stored in a file named enclave-key.pem — had been committed to the public taikoxyz/raiko GitHub repository”
reviewerAn RSA-3072 SGX enclave signing key stored in enclave-key.pem was committed to the public taikoxyz/raiko repo, letting the attacker register a rogue prover whose MrSigner matched the on-chain verifier.Root cause language matches BlockSec's own reported findings and independent technical analysis. - #5[confirmed][no action needed]in section: Root Cause: Exposed SGX Signing Key
“Security firm BlockSec confirmed the root cause via its Phalcon monitoring platform.”
reviewerSecurity firm BlockSec confirmed the root cause via its Phalcon monitoring platform.Confirmed via independent search of press coverage referencing BlockSec/Phalcon's investigation. - #6[confirmed][no action needed]in section: Attack Mechanics
“the forged attestations enabled processMessage() calls that set withdrawal message statuses to RETRIABLE. Subsequent retryMessage() calls then executed with minimal additional checks, releasing ETH and ERC-20 tokens from bridge and vault contracts on Ethereum mainnet.”
reviewerThe attack proceeded via processMessage() setting withdrawal statuses to RETRIABLE, followed by retryMessage() calls executing with minimal additional checks, without corresponding MessageSent events on Taiko's source chain.Corroborated by an independent technical writeup (DarkNavy) not cited on the page, strengthening confidence beyond the page's own sources. - #7[confirmed][no action needed]in section: Incident Overview
“Taiko contained the exploit by approximately 2:08 a.m. ET on June 22. The team activated its Security Council multisig, paused the bridge and token vault, halted block production, and requested centralized exchanges suspend TAIKO deposits.”
reviewerTaiko activated its Security Council multisig, froze the Bridge and ERC20Vault contracts, halted block production, and contained the exploit by approximately 2:08 a.m. ET on June 22.The official taikoxyz X post text located via search corroborates the containment and pause claims. - #8[confirmed][no action needed]in section: Team Response and Containment
“South Korean exchanges Upbit and Bithumb suspended TAIKO deposits and withdrawals citing a network issue.”
reviewerUpbit and Bithumb suspended TAIKO deposits and withdrawals citing a network issue.Both cited sources' headlines directly support this claim. - #11[confirmed][no action needed]in section: Incident Overview
“The TAIKO token fell approximately 10–20% following the disclosure, touching an all-time low near $0.07, with a market capitalization of roughly $14.5 million.”
reviewerThe TAIKO token fell approximately 10-20% following the disclosure, touching an all-time low near $0.07, with a market capitalization of roughly $14.5 million.The 10-20% range reasonably spans the different percentages reported by CoinDesk (20%+), CoinCodex (11%), and AMBCrypto (10%). - #13[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
“Gravity Bridge lost $5.4 million on May 30, 2026, in what was attributed to signing key compromise rather than a code flaw.”
reviewerGravity Bridge lost $5.4 million on May 30, 2026, attributed to signing key compromise rather than a code flaw.Minor date imprecision possible (attack described as spanning the night of May 30-31) but not a material discrepancy. - #14[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
“The largest single incident was the Kelp DAO exploit in April 2026, in which approximately $292 million was drained via a compromised LayerZero DVN setup using a 1-of-1 node quorum, allegedly by North Korea's Lazarus Group.”
reviewerThe largest single 2026 bridge incident was the Kelp DAO exploit in April 2026, draining approximately $292 million via a compromised LayerZero DVN 1-of-1 node quorum, allegedly by North Korea's Lazarus Group.Well corroborated by tier-1 reporting. - #15[confirmed][no action needed]in section: Background: Taiko Protocol
“It was co-founded by Daniel Wang, former CEO of Loopring, and launched its mainnet in May 2024.”
reviewerTaiko was co-founded by Daniel Wang, former CEO of Loopring, and launched its mainnet in May 2024.Confirmed via independent biographical source. - #17[confirmed][no action needed]in section: Attack Mechanics
“The attacker moved the TAIKO portion to an address associated with MEXC exchange.”
reviewerThe attacker moved the TAIKO portion of stolen funds to an address associated with MEXC exchange.Consistently reported across multiple outlets, though it is worth noting this detail traces to on-chain/press analysis rather than an official Taiko statement.