Taiko Security Incident Summary: $1.75M Stolen, No User Losses

iconPANews
Share
AI summary iconSummary
Taiko confirmed a security breach on June 21, during which attackers stole $1.75 million from the bridge and treasury. Over $11 million in funds were protected, and balances are now fully backed 1:1. On-chain details reveal the attack exploited a leaked signature key and bypassed the prover whitelist. Taiko’s defenses limited the losses through daily bridge caps and a rapid pause initiated by the Security Council. The incident did not impact any contracts or zero-knowledge encryption.

PANews, July 23: Ethereum Layer2 project Taiko has released a post-incident summary of the security event that occurred on June 21, emphasizing that no users suffered any losses. The attacker stole approximately $1.75 million from the bridge and treasury, but over $11 million in funds were protected; since network recovery, all balances on Taiko have been fully backed 1:1. The attack did not compromise Taiko—the smart contracts remain functional, and zero-knowledge proof cryptography was unaffected. The attack originated off-chain, as the attacker exploited a leaked signing key and oversight to forge proofs and bypass the prover whitelist. Taiko’s defenses proved effective: the bridge’s daily limit slowed fund outflows, and the Security Committee suspended the bridge and treasury within hours, preventing further transfers.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.