Taiko issued a security notice stating that its chain certification mechanism had been destroyed and that the bridge contracts deployed on the network no longer had the original security prerequisites. The projecter indicated that it was being processed in coordination with the Security Committee and the ecological partners and advised the user to withdraw the bridge funding as soon as possible.
Project requested immediate withdrawal
Taiko stated that the incident had affected the credible basis of the bridging system and that the team was suspending the affected system to the extent possible while advancing technical disposal and legal response. The project party then again reminded on X that the user should immediately withdraw funds from the entire bridge contract on the Taiko network.
Taiko is a second-tier network compatible with the Taifung, using zero knowledge Rollup to handle transactions. The network was created with the participation of Loopring, former CEO Daniel Wang, and was launched in May 2024.
Preliminary analysis points to key exposure
Taiko did not disclose the cause of the gap, nor did it provide official loss figures. Preliminary estimates by BlockSec Phalcon indicate that the damage caused by the attack exceeded $1.7 million.
BlackSec Phalcon believes that the problem is likely to come from the SGX enclave signing key of Raiko. It states that this key was publicly accessible on GitHub, leading to the breakdown of the trust model based on the SGX certificate.
According to its analysis, the assailant may use this to register a self-controlled SGX test example to produce a forged certificate acceptable to Taiko ' s certification contract. Subsequently, the attackers used false signals to register false bridges to receive information and to release ETA assets from the ERC20Vault agreement.
The bridge is safe and secure.
This incident raised renewed market concerns about Rollup ' s certification infrastructure and cross-chain bridge security. Unlike common contractual loopholes, the issue focused on the certification and credible implementation of environmental-related components, and the security of bridge-connected assets would also be directly under pressure if the trust on the ground was damaged.
The report mentions that security incidents in DeFi have continued since this year. KelpDAO cross-chain bridge was attacked in April, with a loss of $292 million; Echo Protocol disclosed an unauthorized foundry of $770 million eBTC in May; and earlier this month, Solana Eco-Trade Platform Raydium was also lost $13.34 million from the use of the old liquidity pool.
Additional information:The report cites data that the cumulative losses of the DeFi agreement exceeded $840 million in the first five months of the year.
