//Across Protocol
C

Across Protocol

Risk Score 46/100·CValue
Compare
$19MTVL·$40MFDV·BridgeWebsite →

Elevated risk — first security incident confirmed July 2026 (off-chain relayer exploit, ~$4M net loss); governance centralized under AcrossCo after DAO dissolution; user funds were unaffected but off-chain attack surface is now a confirmed risk class

Risk Breakdown

Top Risks

1

Off-chain relayer software proved exploitable in July 2026 ($4.5M net loss): an attacker used counterfeit Solana program events to trigger fraudulent relayer fills across 18 chains. Smart contract audits do not cover off-chain event parsing code, which is a confirmed attack surface.

2

UMA optimistic oracle has a demonstrated manipulation vector (Polymarket attack, March 2025, $7M loss): a single entity controlling 25% of voting power can approve fraudulent bridge fills. UMA OO V2 narrowed the proposer set to 37 addresses but on-chain DVM vote manipulation risk remains.

3

DAO dissolved April 2026 (91.51% governance vote); AcrossCo, a US C-corporation, now controls all protocol development and IP with no decentralized governance checks.

Frequently Asked Questions

Is Across Protocol safe to use?
Across Protocol receives a C risk grade (46/100) from Hindenrank, where lower scores indicate lower risk. Elevated risk — first security incident confirmed July 2026 (off-chain relayer exploit, ~$4M net loss); governance centralized under AcrossCo after DAO dissolution; user funds were unaffected but off-chain attack surface is now a confirmed risk class A cross-chain bridge with a 4+ year operating history and $34B+ in total volume that experienced its first security incident in July 2026 — a $4.5M loss from off-chain relayer software manipulation on Solana. User funds and LP pools were never at risk; Risk Labs' proprietary relayer absorbed the full loss. The protocol transitioned from a DAO to a US C-corporation (AcrossCo) in April 2026 via a 91.51% governance vote. TVL has declined from a $249M peak to roughly $19M, and Solana routing now runs through Circle's CCTP rather than Across's intent-based architecture.
What are the main risks of using Across Protocol?
The key risks identified for Across Protocol are: (1) A July 2026 attack exploited a missing validation check in Across's Solana relayer software, draining $4.5M from Risk Labs' own funds. This proved that off-chain code — which doesn't appear in standard smart contract audits — is a real and confirmed attack surface. (2) Protocol governance is now controlled by AcrossCo, a private US company, after the DAO was dissolved in April 2026. There are no on-chain voting rights on protocol changes for ACX holders. (3) The system that verifies bridge transfers still uses UMA token voting, and a $7M attack on Polymarket (March 2025) proved that a single wealthy actor can accumulate enough votes to approve fake transactions using the same oracle mechanism.
What is Across Protocol's risk score breakdown?
Across Protocol scores 46/100 across eight risk dimensions: Mechanism Novelty: 6/15, Interaction Severity: 10/20, Oracle Surface: 7/10, Documentation Gaps: 2/10, Track Record: 8/15, Scale Exposure: 3/10, Regulatory Risk: 3/10, Vitality Risk: 7/10. The highest risk area is Oracle Surface at 7/10.
How does Across Protocol compare to other Bridge protocols?
Among 28 rated Bridge protocols on Hindenrank, Across Protocol ranks #19 by safety (lowest risk score = safest). Its 46/100 risk score and C grade place it in the middle tier of Bridge protocols.
Has Across Protocol ever been hacked or exploited?
Across Protocol scores 8/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.

Incident History

1incident|$4Mtotal losses
Last scanned 2026-07-30

Get risk alerts before it's too late

Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.