Incident case

Taiko Bridge June 2026 forged proof/state exploit

On June 21, 2026, an attacker used an exposed SGX prover signing key together with an attestation check that failed to reject debug-enabled enclaves to produce accepted proofs over a fake Taiko L2 state. The forged finalized state enabled fraudulent withdrawals from the canonical Bridge and ERC20Vault. Taiko's first-party postmortem reports about $1.75 million of actual loss. The bridge was paused, remediated, recollateralized 1:1, and reopened on July 2; users were made whole while attacker-fund recovery remained partial.

reviewedcurrent

Incident facts

Incident title
Taiko Bridge June 2026 forged proof/state exploit
Bridge
Taiko Bridge
Incident date
2026-06-21
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, Taiko
Affected assets
ETH, WETH, USDC, crvUSD, USDT, CRV, iZi, WBTC, weETH, TAIKO
Attack category
Message Verification Failure
Reported loss
about $1.75 million
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
Partial Recovery
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-20
Last verified
2026-08-20

Amount and valuation

Taiko's first-party postmortem reports about $1.75 million of tokens actually withdrawn from the canonical Bridge and ERC20Vault. Larger fraudulent claims that never paid are excluded from the loss total.

The canonical figure is Taiko's approximate first-party aggregate. BIR does not derive a more precise USD value from historical token prices and does not count unpaid fraudulent claims as loss.

Why this remains unresolved

Timeline events

  • Taiko recollateralized bridge and reviewed fixes2026-06

    Taiko closed the attack path, restored the pre-attack state, recollateralized the bridge 1:1 in kind, and reviewed fixes with independent specialists before reopening. This restoration is separate from attacker-fund recovery.

    OtherHigh

    Recollateralization and Foundation backfill are not classified as attacker-fund recovery.

  • Forged Taiko proof/state enables bridge withdrawals2026-06-21

    An exposed SGX prover signing key and an attestation check that failed to reject debug-enabled enclaves allowed accepted proofs over a fake L2 state. The resulting forged finalized state enabled fraudulent withdrawals through the canonical Bridge and ERC20Vault. Taiko reports about $1.75 million of actual loss.

    Exploit OccurredHigh

    Public description is intentionally non-operational. Taiko states that the ZK proving math and Bridge contracts themselves were not the exploited bug.

  • Taiko halted network and bridge operations2026-06-22

    Taiko's Security Council paused the canonical Bridge and ERC20Vault during containment, preventing further withdrawals while additional permissionless proving/proposing paths were disabled and remediation proceeded.

    Bridge PausedHigh

    Pause is first-party documented and distinct from the later July 2 reopening.

  • Bridge withdrawals suspended2026-06-22

    Taiko warned that bridge withdrawals were not secure during containment and suspended the affected first-party paths.

    Transfers SuspendedHigh
  • Taiko reports about $1.75 million of actual withdrawals2026-06-22

    Taiko's postmortem reports about $1.75 million of actual successful withdrawals before containment. Larger fraudulent claims that never paid are excluded.

    Funds LostHigh
  • Taiko Bridge reopened2026-07-02

    After remediation, state restoration and 1:1 recollateralization, Taiko reopened the Bridge and ERC20Vault on July 2 under deliberately conservative withdrawal quotas.

    Bridge ReopenedHigh
  • Taiko stated all affected users were made whole2026-07-02

    Taiko states that the Foundation and Taiko Labs covered the complete shortfall, restored 1:1 backing, and made every affected user whole without waiting for attacker-fund recovery.

    Reimbursement CompletedHigh

    Completed user backfill is distinct from still-partial attacker-fund recovery.

  • Conservative withdrawal quotas retained2026-07-02

    Taiko retained temporary withdrawal quotas as a post-reopening safeguard.

    OtherHigh

    The safeguard does not by itself establish current limited status after later active verification.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.