An attacker began submitting forged proofs to the Taiko rollup on June 21, 2026, finalized a false version of its layer-two state on Ethereum and used that state to authorize withdrawals from Taiko’s canonical Bridge and ERC20Vault.

The incident began at 19:04 UTC, according to Taiko Labs’ subsequent postmortem. Funds started leaving at 22:07 UTC. Taiko later calculated that approximately $1.748 million of assets were released during the full incident window, mostly ether, dollar stablecoins and TAIKO tokens. That valuation was an after-the-fact estimate rather than a price reported publicly on June 21.

A trusted prover that was not trustworthy

Taiko’s reconstruction said the attacker registered two prover instances operating in Intel SGX debug mode. The instances passed the protocol’s checks because an enclave signing key had been committed to a public repository and the attestation process did not reject debug-enabled hardware environments.

The exposed key alone was not sufficient. Taiko checked that a prover’s code measurement and signer measurement matched approved values, but it did not verify the SGX debug flag. Debug mode removes the memory-protection guarantee that the hardware environment was supposed to provide. The attacker could therefore run Taiko’s genuine prover code, sign it with the exposed key and control the proof-signing material inside the enclave.

Taiko later emphasized that the attacker did not defeat its zero-knowledge cryptography or discover an arithmetic flaw in the bridge contracts. The compromised operational and attestation layers instead allowed correctly signed proofs to attest to a fabricated chain state.

False age opened the permissionless path

The protocol ordinarily restricted proof submission to a small whitelist. It also contained a liveness safeguard allowing anyone to prove a proposal that had remained unproven for more than five days.

Once capable of forging proofs, the attacker could falsify the timestamp used to calculate a proposal’s age. A new proposal was made to appear older than five days, activating the permissionless route and bypassing the whitelist without directly compromising it.

At 19:04 UTC, the attacker’s first transaction registered the rogue provers, submitted a fraudulent proof and filed 10 forged withdrawal claims. Those claims were accepted but initially left retriable because the batching contract supplied too little gas to complete payment. Ethereum block 25,367,938, finalized at 19:03:59 UTC, anchors this opening activity in the public ledger.

At 22:07 UTC, the attacker began retrying token claims. One verified transaction released 649,761.236201 USDC from Taiko’s ERC20Vault at 22:07:23 UTC. Taiko’s later accounting listed additional withdrawals involving crvUSD, USDT, TAIKO, WETH, WBTC, CRV, iZi and weETH, along with ether released over the wider incident window.

Detection began as a liveness investigation

Automated reorganization and finality-stall alerts fired at approximately 19:27 UTC, but the team initially investigated them as a prover or liveness problem. Taiko said an internal response call opened at 22:12 UTC. At 22:35 UTC, its chief technology officer identified a divergence between the L1 Inbox’s finalized state and the canonical chain.

By 23:02 UTC, the team had internally confirmed an exploit of the permissionless proving path and notified its Security Council. Emergency pause proposals were being circulated by 23:11 UTC. The first public security warning did not appear until 00:44 UTC on June 22, an important boundary between what Taiko knew internally on June 21 and what users had been told publicly.

Withdrawal quotas limited the damage but did not prevent it. Taiko later reported that a failed 999-ETH claim consumed nearly all of the bridge’s 1,000-ETH daily allowance, slowing subsequent ether withdrawals. A separate token limit restricted the attacker to 1.99 million TAIKO from roughly 110.5 million held in the vault. Lower-value tokens without configured limits could be drained completely.

Later context

Taiko reported the incident contained at 05:40 UTC on June 22 after its Security Council paused the Bridge and ERC20Vault. Remediation was executed on June 29, the bridge was recollateralized on June 30 and normal operations resumed under tighter quotas on July 2. Those outcomes were not known on June 21 and do not change the event-day finding: a failure in off-chain key handling and hardware-attestation validation allowed false L2 state to authorize real withdrawals on Ethereum.

Primary sourceTaiko Labs security-incident postmortem

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.