BlockSec monitoring shows that the Taiko network suffered an attack resulting in losses exceeding $1.7 million due to exposed Raiko SGX enclave signing keys on GitHub. The exposed keys allowed attackers to register controlled SGX instances and sign attestations, enabling fraudulent state proofs to be accepted. The attackers exploited the forged source signals to register fake bridge messages and called retryMessage to trigger the ERC20Vault to release L1 assets.
Taiko Network Suffers $1.7M Loss in Attack Linked to GitHub Key Leak
AiCoinShare
The Taiko network suffered a security breach following a GitHub key leak, resulting in a $1.7 million loss. Attackers exploited an exposed Raiko SGX enclave signing key to register malicious SGX instances and forge state proofs, enabling them to submit fraudulent bridge messages and trigger the ERC20Vault to release L1 assets. This incident underscores the urgent need for a network upgrade to enhance security protocols and prevent similar attacks in the future.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.