Taiko, an Ethereum-based Layer 2 network, suspended block production and urged users to withdraw funds after a bridge exploit siphoned between $1 million and $1.7 million. Two cybersecurity firms, Blockaid and BlockSec, offered different analyses of the root cause of the attack, which occurred on a Monday in June and is the latest episode in a wave of cross-chain exploits that have already cost more than $340 million year-to-date.
🔑 Key Takeaways
- The Taiko bridge was drained of approximately $1.7M, with ~$1.5M in ETH still traceable.
- Two root causes are circulating: a source-signal proof validation flaw (Blockaid) or an SGX Raiko signing key exposed on GitHub (BlockSec).
- TAIKO dropped 10% during the incident and remains -98% below its 2024 high of $0.084.
- ~1.99M TAIKO tokens (~$189,000) were transferred to MEXC exchange.
- The hack is part of a string of 23+ protocol exploits in June, including Secret Network ($4.67M) and PancakeSwap (~$1.1M).
Bridge suspended and emergency response coordinated
Upon detecting the attack, the Taiko team said it was coordinating with partners to contain the incident and paused the affected systems. The project asked centralized exchanges to immediately suspend TAIKO deposits and warned that deposits would only resume after an official notice. All proposers temporarily stopped producing new blocks while the team investigated and addressed the issue.
Taiko later announced it had identified the cause of the incident and was working with exchanges and security firms to trace and attempt to recover the stolen funds. Several attacker addresses were published, and the team said it would take technical and legal action if necessary, though no timeline was given for the resumption of block production.

Two competing theories on the root cause
While the financial impact is broadly agreed upon, the technical origin of the flaw is debated among blockchain security specialists.
Blockaid: a flaw in source-signal proof validation
Blockaid identified the likely cause as a failure in validating the bridge’s source-signal proofs. According to the firm:
« Message proofs were accepted as valid on Ethereum without a legitimate counterpart on the Taiko blockchain. This allowed the attacker to register and later retrieve fraudulent bridge messages, triggering unauthorized releases from the ERC20 vault. »
Blockaid, press release
BlockSec: an SGX Raiko key exposed on GitHub
BlockSec, by contrast, points to a different vector: an SGX Raiko signing key (a secure enclave used to generate withdrawal proofs) was reportedly left publicly accessible on the project’s GitHub repository. That exposure allegedly allowed the attacker to forge withdrawal proofs that Ethereum accepted as legitimate, draining about $1.7 million. The Defiant corroborated this scenario on June 22.
Tracing the stolen funds
Loss estimates vary. Blockaid cited at least $1 million stolen, while Lookonchain and PeckShield put the value of the siphoned assets at up to $1.7 million. According to PeckShield, the exploiter already transferred 1.99 million TAIKO tokens, worth roughly $189,000, to the MEXC exchange. On-chain analytics platform Arkham shows the attacker’s wallets still hold approximately $1.5 million, mostly in Ether (ETH).
| Source | Loss estimate | Identified cause |
|---|---|---|
| Blockaid | ≥ $1M | Flaw in source-signal proof validation |
| BlockSec | ~$1.7M | SGX Raiko key exposed on GitHub |
| PeckShield / Lookonchain | Up to $1.7M | 1.99M TAIKO (~$189K) moved to MEXC |
| Arkham | ~$1.5M still in wallets | Mostly in ETH |
TAIKO token in free fall
Markets reacted sharply. According to CoinGecko, TAIKO was trading down roughly 10% during the incident. More structurally, the token remains down 98% from its 2024 high of $0.084 set at mainnet launch in May 2024. The combination of a battered token economy and repeated technical incidents weighs heavily on user confidence.
DeFi under pressure in June
The Taiko incident is part of a string of bad news for decentralized finance. According to crypto.news, cross-chain bridge exploits alone caused $28.6 million in losses in May, roughly 42% of the monthly total reported by CertiK. DeFiLlama notes that the Taiko exploit is the latest of at least 23 protocol exploits recorded in June, pushing total bridge-related losses past $340 million year-to-date.
Recent precedents
- Secret Network: $4.67M stolen via a smart contract exploit, days before Taiko.
- PancakeSwap (OLPC/LABUBU pool): ~$1.1M drained; LABUBU is a memecoin inspired by a popular toy line.
- Aztec Connect, RetoSwap, Raydium AMM, Humanity Protocol: also targeted in June.
Conclusion: a stress test for « based » rollups
Taiko is positioned as a type-1 ZK-EVM rollup equivalent to Ethereum, designed as a based rollup in which Ethereum L1 validators are expected to help order transactions. While the architecture looks robust on paper, the exploit is a reminder that infrastructure components — enclave keys, proof verification, code repository security — remain the classic weak links of cross-chain bridges.
Two things to watch in the coming weeks: first, the team’s ability to publish a detailed post-mortem that clarifies the root cause between the Blockaid and BlockSec theories; second, the reaction of custodians and market makers to the concentration of TAIKO on MEXC, which could weigh on residual liquidity. Longer term, the cost of insurance (coverage premiums, multiple audits, bug bounties) on L2 bridges is becoming an underestimated economic parameter, likely to penalize projects that neglect operational discipline.
Sources
- Cointelegraph – Taiko urges users to withdraw as bridge exploit drains $1.7M
- Blockaid – press release
- CB Insights – Taiko profile
- CryptoNews – bridge exploit coverage
- Ground News – Taiko halts its Ethereum L2 network
This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

