Taiko: Offchain Signature Key Leak and Missing Check Enabled Proof Forgery in Bridge Attack
AI Market Summary
Taiko disclosed a bridge/Vault exploit caused by an offchain signing key leak and a missing verification step that enabled forged proofs and whitelist bypasses, while ZK cryptography and smart contracts remained intact. About $1.75M was stolen, but most assets were protected and no user funds were lost. The vulnerability is patched, OpenZeppelin's audit found no remaining issues, and an Aug 6 upgrade will require per-block ZK proofs.
Impact level
● Medium
Affected assets
TAIKO/USDT-0.49%
AI Insight · TAIKO/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Taiko, an Ethereum Layer 2 network, published a June 21 post-incident report detailing a security breach traced to a leaked offchain signing key and a missing verification step. The combination allowed attackers to forge proofs and bypass the Prover whitelist. Taiko said neither its ZK cryptography nor its smart contracts were compromised.
The attackers extracted about $1.75 million from the cross-chain bridge and Vault. Taiko added that more than $11 million in assets remained safeguarded and no user funds were lost.
The team has patched the flaw, reverted the network to its pre-attack state, and resumed operations on July 2. An OpenZeppelin review found no remaining high-, medium-, or low-severity issues.
Taiko also said its Unzen upgrade, scheduled for August 6, will require a ZK proof for every block, a change intended to further strengthen network security.