Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Inside the High-Stakes Corporate War Over the GENIUS Act
    Inside the High-Stakes Corporate War Over the GENIUS Act
    From Demonetization to Digital Rupee India's Decade-Long Blockchain Journey
    From Demonetization to Digital Rupee: India’s Decade-Long Blockchain Journey
    The 7% Premium Trap Exposed How India Makes Crypto More Expensive Than Dollars
    The 7% Premium Trap Exposed: How India Makes Crypto More Expensive Than Dollars
    GENIUS Act Scorecard What US Regulators Have Done So Far
    GENIUS Act Scorecard: What US Regulators Have Actually Delivered
    The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
    The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?
  • Opinion
    OpinionShow More
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

$1.7M Gone: Taiko Bridge Exploited After SGX Signing Key Leak

Attackers forged bridge proofs after an SGX signing key was exposed on GitHub, draining Taiko’s L1 bridge and ERC20Vault contracts.

Written By Sharmistha Suman Sharmistha Suman
Fact Checked by Shubham Soni Shubham Soni
Published 1 hour ago
Make The Crypto Times preferred on GoogleGoogle
Last updated: 1 hour ago
Published 1 hour ago
Share
Last updated: 1 hour ago
Published 1 hour ago
$1.7M Gone: Taiko Bridge Exploited After SGX Signing Key Leak

Key Highlights

  • Taiko lost around $1.7 million in a bridge exploit on June 22, 2026.
  • Fake L2 attestations allowed malicious bridge withdrawals to pass verification.
  • Taiko paused bridge operations and ERC20Vault contracts to contain the breach.

Taiko, an Ethereum Layer-2 network, suffered a security breach today, resulting in approximately $1.7 million being drained from its L1 Bridge and ERC20Vault contracts. 

According to an analysis shared by cybersecurity firm Quill Audits via X, the exploit stemmed from a critical operational error: an RSA-3072 private key used for Intel SGX enclave signing was publicly committed to the project’s open-source GitHub repository (taikoxyz/raiko).

🚨 @taikoxyz Bridge Hacked | ~$1.7M Drained

An RSA private key committed to a public GitHub repo just became a $1.7M exploit.

The attacker forged SGX prover registrations, generated fake L2 state attestations, and drained Taiko's L1 Bridge and ERC20Vault across two phases.

No… pic.twitter.com/dXYhtDPwZM

— QuillAudits 🥷 (@QuillAudits_AI) June 22, 2026

How did the attack unfold

The attacker leveraged the leaked enclave-key.pem file to forge SGX prover registrations and create fake L2 state attestations. Because Taiko’s L1 contracts trusted any enclave matching the stored MrSigner value (derived from the public key), the maliciously signed enclave was accepted as legitimate. This allowed the attacker to submit forged bridge messages that passed verification.

The attack unfolded in two phases. First, forged attestations enabled processMessage() calls to set withdrawal statuses to RETRIABLE. Then, retryMessage() executed with minimal additional checks, releasing funds from the bridge and token vault on the Ethereum mainnet. 

Security researchers noted that no private keys were stolen in real-time and no social engineering was involved; the vulnerability originated purely from the exposed signing key.

Affected contracts include the Bridge at 0xd60247c6848B7Ca29eDdF63AA924E53dB6Ddd8EC and the ERC20Vault at 0x996282cA11E5DEb6B5D122CC3B9A1FcAAD4415Ab. Major drain transactions were quickly identified, with attacker addresses linked to the transfers.

The Crypto Times team tried to reach out to Taiko for comment on the Quill Audits analysis, but the team hasn’t responded yet. 

Taiko team urges bridge withdrawals

Taiko responded swiftly through its Security Council by pausing both the Bridge and ERC20Vault and urged users to withdraw their funds. Block production was also temporarily stopped by proposers to contain the incident. 

The team confirmed the exploit is fully contained, pending transactions are paused (not lost), and users should avoid attempting to bridge assets until further notice.

This incident highlights persistent risks in bridge security, particularly around proof verification systems and key management practices in complex multi-prover setups. While SGX provides hardware-based attestation, improper handling of signing keys can undermine the entire trust model. Taiko said it is preparing a detailed post-mortem and coordinating with partners, including potential legal actions.

$TAIKO token falls after exploit

The $TAIKO token reacted negatively to the news, dropping around 10% to $0.07294 in the hours following the disclosure, according to CoinMarketCap. Some stolen funds, including roughly 2 million TAIKO tokens, were reportedly sent to the MEXC exchange, prompting requests to suspend deposits.

Despite the loss, the project’s quick containment limited damage compared to larger bridge hacks seen this year, including Kelp DAO ($292M), Gravity ($5.4M), Alephium ($815,000), and others.

The incident serves as a reminder for projects relying on trusted execution environments and open-source infrastructure to implement rigorous secret management, such as proper .gitignore rules and secret scanning tools. Taiko users are advised to monitor official channels for updates on bridge resumption and any compensation or recovery plans. 

The project’s reputation for innovation in ZK technology may help it recover, but rebuilding full confidence in its bridge infrastructure will require transparent communication and demonstrated security improvements in the coming weeks.

Also Read: Baillie Gifford Debuts Native On-Chain Yield Fund on Solana

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Sharmistha Suman - Crypto Journalist
By Sharmistha Suman
A crypto writer with a strong foundation in storytelling and digital media, Sharmistha holds a Bachelor’s degree in Creative Writing and a Master’s in Digital Journalism. Since entering the crypto industry in 2022, she has been actively covering developments across blockchain, digital assets, and emerging financial technologies. Her work focuses on breaking down complex topics into clear, engaging narratives, helping readers stay informed in a fast-evolving space.
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
Vitalik Buterin Challenges AI to Identify His Anonymous Ethereum Post
Vitalik Buterin Challenges AI to Identify His Anonymous Ethereum Post
BitGo Eyes Institutional DeFi Growth Through Morpho Partnership
BitGo Eyes Institutional DeFi Growth Through Morpho Partnership
Bittensor Isn't Fully Decentralized Yet, Co-Founder Explains Why
Bittensor Isn’t Fully Decentralized Yet, Co-Founder Explains Why
625K Users Later, Fomo Lands $75M to Expand Onchain Trading
625K Users Later, Fomo Lands $75M to Expand Onchain Trading

Find Us on Socials

You may also like

Baillie Gifford Debuts Native On-Chain Yield Fund on Solana

Baillie Gifford Debuts Native On-Chain Yield Fund on Solana

Coinbase Brings OpenAI, Anthropic Pre-IPO Futures to Traders

Coinbase Brings OpenAI, Anthropic Pre-IPO Futures to Traders

MoneyGram Goes Beyond Payments With Solana Validator Role

MoneyGram Goes Beyond Payments With Solana Validator Role

$950K Drained ATM Token Suffers Second Major Exploitation on BNB Chain

$950K Drained: ATM Token Suffers Second Major Exploitation on BNB Chain

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information