Bridge entity

Taiko Bridge

Taiko Bridge is Taiko's first-party canonical bridge between Ethereum and Taiko. In June 2026, forged L2 proof/state data enabled fraudulent withdrawals from the canonical Bridge and ERC20Vault after an exposed SGX prover signing key and an attestation check that failed to reject debug-enabled enclaves undermined the prover trust boundary. Taiko paused the affected paths, restored the pre-attack state, recollateralized the bridge 1:1, made users whole, and reopened the bridge on July 2 under conservative quotas.

activereviewedcurrent

Bridge facts

Canonical name
Taiko Bridge
Type
Canonical Bridge
Status
Active
Confidence
High
Primary chains
Ethereum, Taiko
Primary assets
ETH, WETH, USDC, crvUSD, USDT, CRV, iZi, WBTC, weETH, TAIKO
Operator
Taiko Labs and Taiko protocol contributors
Ecosystem
Taiko
Launch date
2024-05-27
End date
Unknown
Terminal reason
Not applicable / unknown
Last reviewed
2026-08-20
Last verified
2026-08-20

Incident cases

  • Taiko Bridge June 2026 forged proof/state exploit2026-06-21

    On June 21, 2026, an attacker used an exposed SGX prover signing key together with an attestation check that failed to reject debug-enabled enclaves to produce accepted proofs over a fake Taiko L2 state. The forged finalized state enabled fraudulent withdrawals from the canonical Bridge and ERC20Vault. Taiko's first-party postmortem reports about $1.75 million of actual loss. The bridge was paused, remediated, recollateralized 1:1, and reopened on July 2; users were made whole while attacker-fund recovery remained partial.

    Exploitabout $1.75 millionUnresolved

Evidence records

Official URL status

Official URL recorded as live_verified: https://bridge.taiko.xyz/
Independent incident archive

Help maintain bridge history

Support incident linkage, lifecycle updates, evidence preservation, broken-link replacement, and corrections.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.