Svmuu News: Across Protocol has released a post-incident report on the Relayer security incident. Attackers exploited a vulnerability in Risk Labs’ Solana off-chain event reading software to fabricate 1,627 fake deposit transactions with a total face value of approximately $41.7 million.
According to the report, Relayer had covered 581 of these transactions with its own funds—totaling approximately $4.5 million—before suspending its Solana services; the remaining approximately $37 million in fraudulent deposits have since been invalidated. This incident did not involve any smart contract vulnerabilities, and all user transfers were either completed or fully refunded on the same day.
Across Protocol stated that the losses were limited to Risk Labs’ own relayer capital; after deducting approximately $500,000 in funds from the attackers, the net loss was less than $4 million. Currently, Solana order flow has been fully rerouted through CCTP, and the ACX token buyback program remains unaffected.