Crypto & Web3·Jun 22, 2026

Taiko halts its Ethereum layer 2 network after a bridge exploit, token dives 10%

An attacker forged withdrawal proofs to drain about $1.7 million, the same flaw class behind this year's biggest bridge hacks. Fast containment kept the damage small.

CoinDesk3 min readVerified
Taiko halts its Ethereum layer 2 network after a bridge exploit, token dives 10%
Image · CoinDesk
The gist
5-point summary · 1 min

An attacker forged withdrawal proofs to drain about $1.7 million, the same flaw class behind this year's biggest bridge hacks. Fast containment kept the damage small.

  • Bridges are a blockchain-based tool that moves assets between Taiko and Ethereum.How the attacker forged valid-looking proofs points to a leaked key.
  • Our initial investigation suggests the likely root cause was an exposed Raiko SGX enclave signing key on GitHub.
  • ET it said the exploit was contained and withdrawals through the main bridge and token vault were fully stopped.
  • Bridges have produced more than $340 million in losses across at least 14 exploits in 2026, making it the costliest target in crypto.
  • Taiko's damage stayed contained mainly because the team caught and froze it within hours.Taiko, which launched on Ethereum in May 2024, said it is preparing a full breakdown of the incident in Asian morning hours Monday.12345678910
$1.7 million$340 million$1.7M$170,000,$292 million$11.4 million
In this article

Jun 22, 2026, 9:23 a.m. 2 min readSummaryTaiko, an Ethereum Layer 2 network, halted block production and urged users to withdraw funds after an attacker exploited its bridge to steal about $1.7 million.The attacker forged cross-chain proofs so that fake withdrawal requests were accepted on Ethereum without matching deposits on Taiko, draining the bridge and its token vault before the team froze activity.While the dollar loss was relatively small, the exploit used the same cross-chain messaging flaw behind more than $340 million in bridge hacks this year, and Taiko said it will release a full incident report on Monday in Asian hours.Taiko, an Ethereum Layer 2 network that processes transactions off the main chain and settles them back to it, halted block production and told users to pull their funds after an attacker exploited its bridge earlier Monday.The team estimated losses at about $1.7 million before it stopped the outflows.The attacker forged the proofs a bridge uses to confirm that a withdrawal matches a real deposit. Fake withdrawal requests were accepted on Ethereum without any matching transaction on Taiko's own chain, which let the attacker register fraudulent withdrawals and drain funds from the bridge and its token vault, Taiko said. Bridges are a blockchain-based tool that moves assets between Taiko and Ethereum.How the attacker forged valid-looking proofs points to a leaked key. Security firm BlockSec said its initial investigation traces the likely cause to a signing key for Raiko, the system Taiko uses to produce the proofs that convince Ethereum its transactions are genuine, being left publicly accessible on GitHub.That key is meant to stay sealed inside secure hardware so the proofs can be trusted. With it exposed, the attacker could enroll their own provers as legitimate and sign fraudulent proofs that Taiko's verifier accepted, then fake a bridge withdrawal that released real assets on Ethereum..@taikoxyz was reportedly attacked, with losses exceeding $1.7M. Our initial investigation suggests the likely root cause was an exposed Raiko SGX enclave signing key on GitHub. Raiko is Taiko’s multi-prover stack for Taiko and Ethereum blocks, so an exposed Raiko SGX enclave key… https://t.co/8BIiEeNtYJ pic.twitter.com/eAq9Xjngz8— BlockSec Phalcon (@ ) June 22, 2026 Taiko urged all users to withdraw from every bridge on the network, asked centralized exchanges to suspend deposits of its TAIKO token, and had its block producers stop making new blocks during the investigation. By about 2 a.m. ET it said the exploit was contained and withdrawals through the main bridge and token vault were fully stopped. The exploiter had already moved about 2 million TAIKO, worth roughly $170,000, to an account on the MEXC exchange.The dollar loss is small, but the flaw came from the same DeFi mechanism that have caused hundreds of millions worth of losses this year.Forged cross-chain messages drained $292 million from Kelp DAO's bridge in April and $11.4 million from the Verus-Ethereum bridge in May, the same failure where one chain is tricked into trusting a fake instruction from another. Bridges have produced more than $340 million in losses across at least 14 exploits in 2026, making it the costliest target in crypto. Taiko's damage stayed contained mainly because the team caught and froze it within hours.Taiko, which launched on Ethereum in May 2024, said it is preparing a full breakdown of the incident in Asian morning hours Monday.12345678910

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at CoinDesk. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.