Taiko ERC20 Vault Hacked for Up to $1.7 Million as Chain Verification Flaw Exposed
On Monday, Taiko, an Ethereum Layer 2 protocol, suffered a security incident when an attacker took advantage of a vulnerability in its bridge verification system, resulting in an estimated loss between $1.5 million and $1.7 million from the ERC20 Vault. Blockaid was the first to report the breach, indicating initial losses exceeding $1 million. This vulnerability permitted the acceptance of fraudulent bridge messages on Ethereum L1. PeckShield later assessed the total losses to be around $1.7 million. The perpetrator transferred 1.99 million TAIKO tokens, valued at roughly $189,000, to MEXC, while 870.8 ETH, nearly $1.52 million, remained in the attacker’s wallets. Taiko has since suspended the Bridge and ERC20Vault, advising users of paused transactions and urging centralized exchanges to halt TAIKO deposits.
Key facts
- Taiko ERC20 Vault hacked for $1.5M–$1.7M on Monday.
- Exploit exploited a flaw in bridge verification system.
- Block production halted on Taiko network.
- Blockaid first flagged the attack.
- PeckShield estimated $1.7M total losses.
- Attacker moved 1.99M TAIKO tokens to MEXC exchange.
- Four attacker wallet addresses published.
- Taiko paused Bridge and ERC20Vault; pending transactions not lost.
Entities
Institutions
- Taiko
- Blockaid
- PeckShield
- Lookonchain
- MEXC
- DeFiLlama
- Humanity Protocol
- Syscoin Bridge
- Secret Network
- PancakeSwap
- Gravity Bridge
- Axelar-Secret Network
- Alephium TokenBridge
- Hyperbridge
- NFT Plazas
- Arkham