How Does Across Protocol Work?
A cross-chain bridge with a 4+ year operating history and $34B+ in total volume that experienced its first security incident in July 2026 — a $4.5M loss from off-chain relayer software manipulation on Solana. User funds and LP pools were never at risk; Risk Labs' proprietary relayer absorbed the full loss. The protocol transitioned from a DAO to a US C-corporation (AcrossCo) in April 2026 via a 91.51% governance vote. TVL has declined from a $249M peak to roughly $19M, and Solana routing now runs through Circle's CCTP rather than Across's intent-based architecture.
TVL
$19M
Sector
Bridge
Risk Grade
C
Value Grade
C
Core Mechanisms
Bridge/Intent-Based
NovelIntent-based cross-chain bridging where users declare desired outcome
Users submit transfer intents specifying source chain, destination chain, and amount. Relayers compete to fulfill intents. While intent models are spreading, Across's relayer-fronted capital model remains differentiated.
Oracle/Optimistic
NovelUMA optimistic oracle for cross-chain transfer verification
Relayer fills are verified through UMA's optimistic oracle: proposer submits a claim with a bond, 1-hour challenge window opens, and unchallenged claims are accepted. Disputes escalate to UMA's DVM. UMA OO V2 (November 2025) narrowed proposers to 37 pre-approved addresses.
Bridge/Relayer
Competitive relayer network fronting capital for instant bridging
Relayers front their own capital to fulfill user intents immediately, then are reimbursed from liquidity pools after optimistic verification. Relayer models are now standard in bridge designs.
Liquidity/Single-Sided
Single-sided liquidity pools on Ethereum mainnet for relayer reimbursement
LPs deposit assets into single-sided pools on Ethereum. Pools reimburse relayers after verified fills.
Governance/ACX
ACX token governance with staking for protocol security
ACX token governance was dissolved April 2026 via on-chain vote (91.51% approval). AcrossCo, a US C-corporation, now controls protocol development and IP. Token holders could exchange for equity or redeem at $0.04375 USDC.
Fee/Dynamic
Dynamic bridge fees based on route liquidity and relayer competition
Standard dynamic fee model based on available liquidity and gas costs.
Security/Escalation
Multi-step dispute escalation from optimistic to full DVM resolution
Standard dispute escalation pattern from optimistic oracle to full DVM token holder vote.
How the Pieces Interact
The Polymarket governance attack (March 2025) demonstrated that UMA's oracle can be manipulated by accumulating 25% of voting power. If applied to Across, fraudulent bridge fills could be validated.
Relayer network concentration among few well-capitalized actors introduces censorship risk and reduces decentralization guarantees, though it does not directly endanger user funds.
The short 1-hour challenge window prioritizes speed over security; if disputers are offline or economically disincentivized, fraudulent fills could be finalized without challenge.
During high bridge volume, LP pool utilization could spike, creating temporary shortfalls where relayers cannot be reimbursed promptly.
Chain reorganizations after intent fulfillment could create double-spend scenarios or orphaned relayer fills.
What Could Go Wrong
- Off-chain relayer software proved exploitable in July 2026 ($4.5M net loss): an attacker used counterfeit Solana program events to trigger fraudulent relayer fills across 18 chains. Smart contract audits do not cover off-chain event parsing code, which is a confirmed attack surface.
- UMA optimistic oracle has a demonstrated manipulation vector (Polymarket attack, March 2025, $7M loss): a single entity controlling 25% of voting power can approve fraudulent bridge fills. UMA OO V2 narrowed the proposer set to 37 addresses but on-chain DVM vote manipulation risk remains.
- DAO dissolved April 2026 (91.51% governance vote); AcrossCo, a US C-corporation, now controls all protocol development and IP with no decentralized governance checks.
UMA Oracle Governance Capture
TailTrigger: A single entity accumulates 25%+ of UMA voting power and submits fraudulent bridge fill proposals during a period of low disputer activity
- 1.Attacker accumulates sufficient UMA tokens to control 25% of Data Verification Mechanism votes — Attacker can propose and validate fraudulent bridge fills through the optimistic oracle
- 2.Fraudulent fill proposals pass the 1-hour optimistic challenge window unchallenged — LP pools reimburse attacker for fills that never occurred on destination chains
- 3.LP pool balances drain as fraudulent reimbursements accumulate — Legitimate relayers cannot be reimbursed, halting bridge operations
- 4.Bridge users with in-flight transfers face failed or delayed completions — Trust in Across collapses; users migrate to competing bridges
- 5.ACX token crashes as protocol's core security assumption is invalidated — Remaining LP capital exits, making recovery economically unviable
Risk Profile at a Glance
Overall: C (46/100)
Lower score = safer