Taiko Ethereum Layer-2 Network Investigates $1.7 Million Bridge Exploit, Urges User Withdrawals

Taiko’s statement (via a referenced “Security Council”) said the incident is being contained while the project warned that “all bridges on Taiko can no longer be trusted” and urged users to withdraw immediately.
One technical account of the failure says the bridge proof verification system did not confirm that a legitimate “MessageSent” event occurred on the Taiko chain before authorizing withdrawals from the ERC-20 vault—allowing forged proofs to be accepted.
Security firm Blockaid reported preliminary findings that the exploit leveraged a weakness in the ERC-20 vault’s logic (even though the exact method was still under investigation at the time).
On-chain reporting specified that the attacker routed 1.99M TKO/TAIKO (about $189K) to MEXC and was still controlling 870.8 ETH (about $1.52M), indicating the attacker had not fully liquidated holdings.
Taiko, an Ethereum layer-2 network, suffered a critical bridge exploit on June 22, 2026, draining roughly $1.7 million from its ERC-20 vault. The attack forged withdrawal proofs to trick the system into releasing funds that were never actually authorized. Hokanews reported the revised loss figure after earlier estimates put the damage at around $1 million.
Taiko's team issued an urgent warning: "all bridges deployed on Taiko can no longer be trusted." They urged all users to pull funds immediately and asked centralized exchanges to freeze TAIKO token deposits while the investigation continues.
The exploit targeted a specific flaw in Taiko's bridge proof-verification system. A bridge works by checking that a "MessageSent" event actually happened on the Taiko chain before releasing funds on Ethereum. According to Crypto News, the attacker bypassed this check entirely — submitting crafted proofs that the Ethereum-side vault accepted as valid, even though no real withdrawal request existed on the Taiko side.
Security firm Blockaid flagged the attack first. MEXC reported that Blockaid traced the breach to a logic error in the ERC-20 vault's proof-validation code. The flaw let the attacker register a rogue "prover" — the entity responsible for confirming chain activity — and then use it to generate fake authorization signals.
On-chain trackers identified four attacker wallets. The attacker sent 1.99 million TAIKO tokens — worth roughly $189,000 — directly to MEXC exchange, according to Crypto.news. At the same time, the attacker's wallets still held 870.8 ETH, valued at approximately $1.52 million, meaning most of the stolen funds had not yet been liquidated.
MEXC confirmed it suspended TAIKO deposits and froze accounts linked to the attacker's identified wallet addresses. Because MEXC requires identity verification (KYC), analysts believe there is a realistic chance of identifying the individuals behind the attack through legal channels.
Taiko's Security Council ordered a full halt to block production shortly after 1:00 AM EDT on June 22. Proposers — the network participants who build new blocks — were told to stop immediately. The halt was controversial. It protected remaining user funds, but it also confirmed that a small group can shut down the entire network at will, raising questions about how decentralized Taiko truly is.
The TAIKO token swung sharply on the news. It briefly surged 11.5% as some traders misread early reports, then fell nearly 4% once the full picture emerged. The token traded around $0.081 in the aftermath, down from a daily high of $0.097, according to Hokanews.
This attack fits a well-known pattern. Bridges are high-value targets because they hold large pools of assets on both sides of a transaction. The Ronin and Horizon bridge hacks cost hundreds of millions of dollars in earlier years. What makes the Taiko exploit distinct is that it manipulated proof logic rather than stealing private keys — a more sophisticated approach, according to Crypto.news.
Blockaid argued that static code audits are not enough to catch this type of flaw. Experts suggest Taiko must now redesign its prover-registration system — possibly moving to a "multi-prover" setup or a restricted whitelist for approved provers. Taiko has not yet released a public post-mortem or a recovery plan for affected users, according to Kryptonews.
Publishers
45
Articles
14
Reach
59