#PeckShieldAlert @taikoxyz has been exploited for ~$1.7M.
The exploiter has already transferred 1.99M $TAIKO (~$189.12K) to #MEXC
https://t.co/uJhqTYrqHH https://t.co/Sl9kesSSUM
#PeckShieldAlert @taikoxyz has been exploited for ~$1.7M.
The exploiter has already transferred 1.99M $TAIKO (~$189.12K) to #MEXC
https://t.co/uJhqTYrqHH https://t.co/Sl9kesSSUM
⚠️ Security Notice
1/2: We have confirmed a compromise of Taiko’s chain state verification mechanism. As a result, the security assumptions of all bridges deployed on Taiko can no longer be relied upon.
We are actively coordinating with the Security Council and ecosystem partners to contain the incident, pause affected systems where possible, and take all necessary technical and legal actions.
We strongly advise all users to withdraw their funds from all bridges deployed on Taiko immediately.
Further updates will be provided as more information becomes available.
Wu reported that security firm Blockaid indicated it detected an attack on the ERC20 Vault on Ethereum operated by Taiko, with losses exceeding $1 million. Preliminary analysis shows the vulnerability stems from a flaw in Taiko's cross-chain bridge source-signal proof verification mechanism, where the attacker‑crafted message proof was accepted by the Ethereum mainnet without a corresponding legitimate MessageSent event on the Taiko chain, allowing registration and extraction of forged cross‑chain messages, ultimately causing assets in the ERC20 Vault to be released without authorization. https://t.co/jm6oNmb7ui
Taiko 发布安全通知称,已确认其链状态验证机制遭入侵,部署在 Taiko 上的所有跨链桥的安全假设已无法依赖。Taiko 强烈建议用户立即从相关跨链桥撤出资金,并请求中心化交易所立即暂停 TAIKO 充值,直至官方通知后再恢复。
🚨Taiko: Chain state verification mechanism has been breached!
Taiko posted that it has confirmed the chain state verification mechanism of Taiko has been breached, and the security assumptions of all cross-chain bridges deployed on Taiko are no longer reliable.
Taiko is coordinating with the Security Council and ecosystem partners to contain the situation, pause affected systems, and take technical and legal actions.
Taiko strongly recommends all users to withdraw funds from all cross-chain bridges deployed on Taiko immediately.
Taiko urgently requests all centralized exchanges to suspend TAIKO token deposits until an official notice is received. The attacker’s address has been disclosed.
⚠️ Security Notice
1/2: We have confirmed a compromise of Taiko’s chain state verification mechanism. As a result, the security assumptions of all bridges deployed on Taiko can no longer be relied upon.
We are actively coordinating with the Security Council and ecosystem partners to contain the incident, pause affected systems where possible, and take all necessary technical and legal actions.
We strongly advise all users to withdraw their funds from all bridges deployed on Taiko immediately.
Further updates will be provided as more information becomes available.