πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
Blockchain

Taiko Halts Its Ethereum Layer-2 After a $1.7M Bridge Exploit

22 Jun 2026by CryptoJazz Admin1 min read5 views
Taiko Halts Its Ethereum Layer-2 After a $1.7M Bridge Exploit

Taiko halted its Ethereum layer-2 network on June 22 after an attacker drained roughly $1.7 million from the network's bridge and token vault. The withdrawals were authorized by forged proofs submitted on Ethereum, claims of Taiko-side deposits that had never been made. The security firm BlockSec traced the attack to an exposed signing key belonging to Raiko, Taiko's proving component, which had been committed to a public GitHub repository. Within hours Taiko stopped producing blocks, froze bridge withdrawals, urged users to move funds out of the bridge and asked exchanges to suspend TAIKO deposits. The token fell about 10% on the day, according to CoinDesk.

The Mechanics: A Signing Key That Vouches for Work It Never Saw

Taiko's proving setup relied on SGX, a processor feature that runs code inside an enclave, an isolated region of memory that other software on the same machine cannot read or alter. The enclave holds a private signing key and uses it to sign a statement that a particular computation ran inside genuine, unmodified hardware and produced a particular result. Contracts on Ethereum do not repeat that computation; they check the signature and accept the result as attested. That is what makes hardware-based proving cheap to verify, and also its single point of failure: an attestation is worth exactly as much as the secrecy of the key behind it.

A bridge withdrawal runs on the same logic. The contract on Ethereum releases assets only when it is shown evidence that a corresponding deposit or burn was recorded on the layer-2. An attacker holding the enclave key can sign that evidence for a transaction that never happened, and the contract has no independent way to tell the difference, because it was built to trust the key rather than to re-derive the facts. That is how roughly $1.7 million left the bridge and token vault with nothing on the Taiko side to match it. Nothing was broken in the usual sense of a contract bug; the system did what it was written to do, for the wrong signer.

The Trail: An Enclave Key in a Public Repository

BlockSec attributed the incident to a Raiko SGX enclave signing key that had been committed to GitHub, where it was readable by anyone who went looking for it. That reduces the exploit from a cryptographic problem to a housekeeping one: the attacker never had to defeat the enclave, only to find the secret the enclave was supposed to be the sole holder of. Committed secrets are among the oldest failure modes in software, and unusually costly in proving systems, where one key stands in for the correctness of an entire chain. Rotating it closes the door on future forgeries but does nothing about withdrawals already settled on Ethereum.

The Response: Block Production Stopped and Withdrawals Frozen

Taiko reached for the bluntest control available to it. Halting block production on a layer-2 stops an attacker and every honest user in the same motion, since no new transactions are confirmed until the operator resumes. Bridge withdrawals were frozen within hours, and users still holding assets in the bridge were urged to exit. Taiko also asked exchanges to suspend TAIKO deposits, the standard request when a team wants to slow a token's movement through trading venues while an incident is still being scoped. TAIKO fell around 10%, and the network remained stopped as the day ended.

What Is Unresolved: The Trust Placed in Attested Hardware

The immediate questions were whether the bridge would reopen on rotated keys or on a rebuilt proving path, and whether users whose assets backed the forged withdrawals would be made whole. The larger one is what an SGX attestation is worth in production. Layer-2 networks that settle on cryptographic proofs rather than trusted hardware carry a different assumption, one resting on mathematics anyone can check rather than on a manufacturer's silicon and a team's key hygiene. Hardware proving is fast and inexpensive, and June 22 showed what that trade costs when key handling fails. The halt carried a second lesson: a network that can be stopped in an afternoon by its operators is one whose users depend on those operators being attentive as well as honest.

Read also: Secret Network's Axelar Bridge Hit by a $4.67M Infinite Mint

← All news