Is Across Protocol Safe?
Risk Grade: C (46/100)
Across Protocol is rated as elevated risk — multiple novel mechanisms and notable interaction risks.
Elevated risk — first security incident confirmed July 2026 (off-chain relayer exploit, ~$4M net loss); governance centralized under AcrossCo after DAO dissolution; user funds were unaffected but off-chain attack surface is now a confirmed risk class
A cross-chain bridge with a 4+ year operating history and $34B+ in total volume that experienced its first security incident in July 2026 — a $4.5M loss from off-chain relayer software manipulation on Solana. User funds and LP pools were never at risk; Risk Labs' proprietary relayer absorbed the full loss. The protocol transitioned from a DAO to a US C-corporation (AcrossCo) in April 2026 via a 91.51% governance vote. TVL has declined from a $249M peak to roughly $19M, and Solana routing now runs through Circle's CCTP rather than Across's intent-based architecture.
TVL
$19M
Mechanisms
7
Interactions
6
Value Grade
C
Key Risks for Across Protocol Users
A July 2026 attack exploited a missing validation check in Across's Solana relayer software, draining $4.5M from Risk Labs' own funds. This proved that off-chain code — which doesn't appear in standard smart contract audits — is a real and confirmed attack surface.
Protocol governance is now controlled by AcrossCo, a private US company, after the DAO was dissolved in April 2026. There are no on-chain voting rights on protocol changes for ACX holders.
The system that verifies bridge transfers still uses UMA token voting, and a $7M attack on Polymarket (March 2025) proved that a single wealthy actor can accumulate enough votes to approve fake transactions using the same oracle mechanism.
Top Risk Factors
- •Off-chain relayer software proved exploitable in July 2026 ($4.5M net loss): an attacker used counterfeit Solana program events to trigger fraudulent relayer fills across 18 chains. Smart contract audits do not cover off-chain event parsing code, which is a confirmed attack surface.
- •UMA optimistic oracle has a demonstrated manipulation vector (Polymarket attack, March 2025, $7M loss): a single entity controlling 25% of voting power can approve fraudulent bridge fills. UMA OO V2 narrowed the proposer set to 37 addresses but on-chain DVM vote manipulation risk remains.
- •DAO dissolved April 2026 (91.51% governance vote); AcrossCo, a US C-corporation, now controls all protocol development and IP with no decentralized governance checks.
How Across Protocol Compares to Peers
Across Protocol ranks #19 of 28 Bridge protocols (below-median — riskier than average). At a risk score of 46/100, it's 3 points riskier than the sector average of 43/100.
Adjacent peers: USDT0 (C, 45/100) is ranked just safer, and WBTC (Wrapped Bitcoin) (C, 50/100) is ranked just riskier.
See the full Bridge sector leaderboard or the Across Protocol vs Hyperlane comparison.
Common Questions about Across Protocol
Plain-English answers based on Across Protocol's scores across Hindenrank's 8 risk dimensions. The highest-scoring (riskiest) dimension is Oracle Surface (7/10).
Has Across Protocol ever been hacked or exploited?
Across Protocol has had some operational issues or moderate incidents in its history. The track record dimension scored 8/15 — not catastrophic, but enough to flag. Look at the specific events and whether they were addressed by the team before drawing conclusions.
How much money is at stake in Across Protocol?
Across Protocol currently holds roughly $19M in user deposits. Smaller TVL means individual depositors carry a larger share of any loss event, and it can be harder to exit a position quickly during stress.
What's the worst-case scenario for Across Protocol?
Hindenrank has identified specific collapse scenarios for Across Protocol. The most prominent: "UMA Oracle Governance Capture". The trigger condition is A single entity accumulates 25%+ of UMA voting power and submits fraudulent bridge fill proposals during a period of low disputer activity. Reading through the full scenario list on the protocol page is the single best way to understand the actual failure modes — generic "smart contract risk" is rarely the thing that takes a protocol down.
Is Across Protocol regulated or insured?
Across Protocol has low regulatory exposure on Hindenrank's framework (3/10). The protocol is structured in a way that minimizes counterparty and jurisdiction concentration, though regulatory risk in crypto can change rapidly. No DeFi protocol carries FDIC-style insurance — even with low regulatory risk, depositors are not protected in the way bank customers are.
What are the biggest red flags for Across Protocol?
Hindenrank's retail-focused risk audit flagged: A July 2026 attack exploited a missing validation check in Across's Solana relayer software, draining $4.5M from Risk Labs' own funds. This proved that off-chain code — which doesn't appear in standard smart contract audits — is a real and confirmed attack surface. Protocol governance is now controlled by AcrossCo, a private US company, after the DAO was dissolved in April 2026. There are no on-chain voting rights on protocol changes for ACX holders. The system that verifies bridge transfers still uses UMA token voting, and a $7M attack on Polymarket (March 2025) proved that a single wealthy actor can accumulate enough votes to approve fake transactions using the same oracle mechanism.
Should beginners deposit into Across Protocol?
Across Protocol's C grade puts it in the elevated-risk band. This is not a beginner-friendly protocol. Anyone depositing here should treat the position as speculative and avoid concentrating significant savings in it.
How does Across Protocol compare to safer Bridge alternatives?
Across Protocol is one protocol in Hindenrank's Bridge coverage. The safest Bridge protocols on the leaderboard tend to share three traits: a long incident-free track record, conservative mechanism design, and high-quality public documentation. Compare Across Protocol against the full Bridge ranking before committing capital.
For the full 8-dimension score breakdown, the radar chart, and dependency graph, see the Across Protocol risk report.
Read the Full Across Protocol Risk Report
This protocol has 3 collapse scenarios. 2 high-severity interaction risks identified. See the full mechanism classification, interaction matrix, and deep-dive recommendations.
View Full Report →Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.