A missing eight-byte check in an offchain code file handed an attacker a window to drain roughly $4.5 million from a Risk Labs-operated relayer on July 17, 2026 — yet every user of the Across protocol walked away without losing a cent. The Across Solana relayer attack exposed a narrow but consequential gap between what a blockchain sees and what offchain software chooses to trust.
The incident became a live test of a deliberate architectural bet. When Across was designed as an intents protocol, the decision to have relayers advance their own capital — rather than draw from shared user escrow — was a risk-management choice that many users may never have noticed. On July 17, that choice proved its worth. The attack’s financial impact was real, but it was contained entirely within Risk Labs’ own operational capital.
That said, the incident also illustrates a structural tension that any protocol relying on offchain event parsing must reckon with. Onchain contracts can be formally verified and audited with high confidence. Offchain relayer software operates in a grayer space — it interprets chain activity and acts on it, but the interpretation logic sits outside the trust guarantees of the blockchain itself. A single missing discriminator check in that layer was enough to generate $4.5 million in fraudulent payouts.
Risk Labs has committed to re-auditing its Solana offchain event parsing logic even while Solana order flow runs exclusively through CCTP — meaning the vulnerable path is already inactive. The goal is to ensure the vulnerability class is completely closed before intents routing to and from Solana is re-enabled, and to standardize how event security is handled across the broader infrastructure.
The deeper question the incident raises is how the industry treats offchain components of onchain protocols. Smart contract audits are now standard practice. Offchain relayer logic, event listeners, and parsing libraries have historically received less scrutiny — partly because they sit outside the formal security perimeter most auditors focus on. If the Across incident reshapes how protocols approach that gap, the $4 million loss may end up funding a broader security upgrade across the cross-chain settlement space.
Risk Labs disabled Solana as an origin chain, paused the Solana SpokePool on-chain, deployed a root-cause fix within approximately five hours of detection, and fully restored Solana service within roughly 12 hours using fallback CCTP routing.
No. No smart contracts were exploited. All Solana programs and EVM contracts behaved exactly as designed throughout the incident. The vulnerability existed entirely within the offchain relayer software.
#USPausesIranStrikesSecondNight
