Taiko: Offchain Signature Key Leak and Missing Check Enabled Proof Forgery in Bridge Attack
AI مارکیٹ کا خلاصہ
Taiko disclosed a bridge/Vault exploit caused by an offchain signing key leak and a missing verification step that enabled forged proofs and whitelist bypasses, while ZK cryptography and smart contracts remained intact. About $1.75M was stolen, but most assets were protected and no user funds were lost. The vulnerability is patched, OpenZeppelin's audit found no remaining issues, and an Aug 6 upgrade will require per-block ZK proofs.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
TAIKO/USDT+1.56%
AI تجزیاتی سمجھ · TAIKO/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Taiko, an Ethereum Layer 2 network, published a June 21 post-incident report detailing a security breach traced to a leaked offchain signing key and a missing verification step. The combination allowed attackers to forge proofs and bypass the Prover whitelist. Taiko said neither its ZK cryptography nor its smart contracts were compromised.
The attackers extracted about $1.75 million from the cross-chain bridge and Vault. Taiko added that more than $11 million in assets remained safeguarded and no user funds were lost.
The team has patched the flaw, reverted the network to its pre-attack state, and resumed operations on July 2. An OpenZeppelin review found no remaining high-, medium-, or low-severity issues.
Taiko also said its Unzen upgrade, scheduled for August 6, will require a ZK proof for every block, a change intended to further strengthen network security.