← Taiko

2026 Taiko — chain state verification compromise; bridge users urged to withdraw (~$1M+ vault loss)

2026 Unknown records affected Share on X

Data compromised

No consumer PII—unauthorized asset releases from Taiko ERC20 Vault on Ethereum; Blockaid reported losses exceeding $1 million; Taiko confirmed verification mechanism compromise affecting all bridges on the network

Technical writeup

On June 22, 2026 Taiko confirmed a compromise of its chain state verification mechanism, stating security assumptions for all bridges deployed on Taiko could no longer be relied upon and urging users to immediately withdraw funds from affected bridge systems. Blockaid’s exploit detection flagged an ongoing attack on Taiko’s ERC20 Vault on Ethereum with losses exceeding $1 million, attributing the root cause to flawed source-signal proof validation that accepted crafted proofs on Ethereum L1 without legitimate MessageSent events on the Taiko source chain—enabling fraudulent bridge message registration and unauthorized vault releases. Taiko temporarily halted proposers from producing blocks, asked centralized exchanges to suspend TAIKO deposits, published attacker wallet addresses, and said it was working with its Security Council and ecosystem partners on technical and legal response steps. This is a cross-chain infrastructure incident rather than a traditional personal-data breach; BreachHistory indexes recordsAffected 0.

Root cause

Flaw in Taiko bridge source-signal proof validation allowed crafted message proofs on Ethereum L1 without matching MessageSent events on Taiko L2

References