Elevated risk — first security incident confirmed July 2026 (off-chain relayer exploit, ~$4M net loss); governance centralized under AcrossCo after DAO dissolution; user funds were unaffected but off-chain attack surface is now a confirmed risk class
Risk Breakdown
Top Risks
Off-chain relayer software proved exploitable in July 2026 ($4.5M net loss): an attacker used counterfeit Solana program events to trigger fraudulent relayer fills across 18 chains. Smart contract audits do not cover off-chain event parsing code, which is a confirmed attack surface.
UMA optimistic oracle has a demonstrated manipulation vector (Polymarket attack, March 2025, $7M loss): a single entity controlling 25% of voting power can approve fraudulent bridge fills. UMA OO V2 narrowed the proposer set to 37 addresses but on-chain DVM vote manipulation risk remains.
DAO dissolved April 2026 (91.51% governance vote); AcrossCo, a US C-corporation, now controls all protocol development and IP with no decentralized governance checks.
Frequently Asked Questions
Is Across Protocol safe to use?
What are the main risks of using Across Protocol?
What is Across Protocol's risk score breakdown?
How does Across Protocol compare to other Bridge protocols?
Has Across Protocol ever been hacked or exploited?
Incident History
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.