Taiko Bridge June 2026 forged proof/state exploit
On June 21, 2026, an attacker used an exposed SGX prover signing key together with an attestation check that failed to reject debug-enabled enclaves to produce accepted proofs over a fake Taiko L2 state. The forged finalized state enabled fraudulent withdrawals from the canonical Bridge and ERC20Vault. Taiko's first-party postmortem reports about $1.75 million of actual loss. The bridge was paused, remediated, recollateralized 1:1, and reopened on July 2; users were made whole while attacker-fund recovery remained partial.
Incident facts
- Incident title
- Taiko Bridge June 2026 forged proof/state exploit
- Bridge
- Taiko Bridge
- Incident date
- 2026-06-21
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, Taiko
- Affected assets
- ETH, WETH, USDC, crvUSD, USDT, CRV, iZi, WBTC, weETH, TAIKO
- Attack category
- Message Verification Failure
- Reported loss
- about $1.75 million
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- Partial Recovery
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-20
- Last verified
- 2026-08-20
Amount and valuation
Taiko's first-party postmortem reports about $1.75 million of tokens actually withdrawn from the canonical Bridge and ERC20Vault. Larger fraudulent claims that never paid are excluded from the loss total.
The canonical figure is Taiko's approximate first-party aggregate. BIR does not derive a more precise USD value from historical token prices and does not count unpaid fraudulent claims as loss.
actual successful withdrawals across ETH, stablecoins, TAIKO and other ERC-20 assetsabout $1.75 million
Excludes larger fraudulent claims that never paid and were later force-resolved.
Why this remains unresolved
- Attacker-fund recovery remains incomplete: Taiko reported 17 ETH returned to treasury, additional TAIKO frozen at MEXC pending law-enforcement process, and other stolen ETH moved through Tornado Cash or remained in known attacker wallets.
- The approximate $1.75 million first-party loss total is not converted into an invented exact recovered-USD figure.
Timeline events
Taiko recollateralized bridge and reviewed fixes2026-06
Taiko closed the attack path, restored the pre-attack state, recollateralized the bridge 1:1 in kind, and reviewed fixes with independent specialists before reopening. This restoration is separate from attacker-fund recovery.
Recollateralization and Foundation backfill are not classified as attacker-fund recovery.
Forged Taiko proof/state enables bridge withdrawals2026-06-21
An exposed SGX prover signing key and an attestation check that failed to reject debug-enabled enclaves allowed accepted proofs over a fake L2 state. The resulting forged finalized state enabled fraudulent withdrawals through the canonical Bridge and ERC20Vault. Taiko reports about $1.75 million of actual loss.
Public description is intentionally non-operational. Taiko states that the ZK proving math and Bridge contracts themselves were not the exploited bug.
Taiko halted network and bridge operations2026-06-22
Taiko's Security Council paused the canonical Bridge and ERC20Vault during containment, preventing further withdrawals while additional permissionless proving/proposing paths were disabled and remediation proceeded.
Pause is first-party documented and distinct from the later July 2 reopening.
Bridge withdrawals suspended2026-06-22
Taiko warned that bridge withdrawals were not secure during containment and suspended the affected first-party paths.
Taiko reports about $1.75 million of actual withdrawals2026-06-22
Taiko's postmortem reports about $1.75 million of actual successful withdrawals before containment. Larger fraudulent claims that never paid are excluded.
Taiko Bridge reopened2026-07-02
After remediation, state restoration and 1:1 recollateralization, Taiko reopened the Bridge and ERC20Vault on July 2 under deliberately conservative withdrawal quotas.
Taiko stated all affected users were made whole2026-07-02
Taiko states that the Foundation and Taiko Labs covered the complete shortfall, restored 1:1 backing, and made every affected user whole without waiting for attacker-fund recovery.
Completed user backfill is distinct from still-partial attacker-fund recovery.
Conservative withdrawal quotas retained2026-07-02
Taiko retained temporary withdrawal quotas as a post-reopening safeguard.
The safeguard does not by itself establish current limited status after later active verification.
Evidence records
- Taiko incident and containment statementTaiko · Tier 1 · High reliability · primary · 2026-06-22Claim scope: Incident Case
Primary source for verification compromise, bridge withdrawals, halt, and approximate USD 1.7 million estimate.
- Taiko bridge reopening and make-whole statementTaiko · Tier 1 · High reliability · primary · 2026-07-02Claim scope: Reimbursement
Primary source for restored backing, reopening, all users made whole, and temporary quotas.
- Taiko confirms exploit and halts block productionThe Block · Tier 2 · High reliability · secondary · 2026-06-22Claim scope: Incident Case
Independent contemporaneous incident context.
- Taiko reopens bridge after USD 1.7M exploitCrypto Economy · Tier 3 · Medium reliability · secondary · 2026-07-02Claim scope: Restart
Secondary reopening and make-whole context.
- Taiko incident and containment statementTaiko · Tier 1 · High reliability · primary · 2026-06-22Claim scope: Shutdown
Event-scoped duplicate supporting suspension of Taiko bridge withdrawals during containment.
- Taiko incident and containment statementTaiko · Tier 1 · High reliability · primary · 2026-06-22Claim scope: Amount
Event-scoped duplicate supporting Taiko's approximate USD 1.7 million loss estimate before containment.
- Taiko bridge reopening and make-whole statementTaiko · Tier 1 · High reliability · primary · 2026-07-02Claim scope: Restart
Event-scoped duplicate supporting restored backing, reviewed fixes, and the reopening boundary.
- Taiko bridge reopening and make-whole statementTaiko · Tier 1 · High reliability · primary · 2026-07-02Claim scope: Status
Event-scoped duplicate supporting temporary conservative withdrawal quotas after reopening.
- Taiko incident and containment statementTaiko · Tier 1 · High reliability · primary · 2026-06-22Claim scope: Incident Case
Event-scoped primary copy supporting fraudulent Taiko bridge-message acceptance, affected assets, and immediate containment.
- Taiko bridge reopening and make-whole statementTaiko · Tier 1 · High reliability · primary · 2026-07-02Claim scope: Reimbursement
Event-scoped primary copy supporting restoration of the Taiko network and bridge, reopening with conservative withdrawal quotas, and the make-whole commitment.
- Taiko Security Incident: A Postmortem and Next StepsTaiko Labs · Tier 1 · High reliability · primary · 2026-07Claim scope: Incident Case
Core first-party incident authority for the forged proof/state mechanism, approximate $1.75M actual loss, itemized successful withdrawals, partial attacker-fund recovery, complete user backfill, remediation and July 2 reopening. The reviewed page does not expose a reliable day-level publication date, so BIR preserves only month precision.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The first-party postmortem does not establish completed recovery of all attacker-controlled assets.
- Frozen TAIKO at MEXC is not treated as recovered until returned through the law-enforcement process.
- BIR intentionally keeps the public mechanism at a non-operational forged-proof/state-acceptance boundary and does not reproduce exploit payload construction.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.