Across Protocol released a postmortem on a Relayer security incident involving a vulnerability in Risk Labs' off-chain event-reading software on Solana. According to Odaily, the attacker forged 1,627 fake deposit events with a total face value of about $41.7 million.
The report said Relayer completed 581 advance payments before Solana service was paused, involving about $4.5 million of its own funds. The remaining roughly $37 million in fake deposits were invalidated, and the incident did not involve a smart contract vulnerability. All user transfers were completed or fully refunded on the same day.
Across Protocol said the loss was limited to Risk Labs' own relayer capital. After deducting about $500,000 in attacker funds, the net loss was less than $4 million. Solana order flow has been moved entirely to CCTP routing, and the ACX token buyback plan remains unchanged.