An RSA-3072 private signing key left in a public GitHub repository enabled an attacker to drain $1.7 million from Taiko's Ethereum bridge on June 22, 2026. The breach forced a full network halt, collapsed the TAIKO token by more than 20%, and left the bridge undercollateralized four days later. T...
"The root cause appears to be a flaw in Taiko bridge source-signal proof validation." — Blockaid, Blockchain Security Firm
An RSA-3072 private signing key left in a public GitHub repository enabled an attacker to drain $1.7 million from Taiko's Ethereum bridge on June 22, 2026. The breach forced a full network halt, collapsed the TAIKO token by more than 20%, and left the bridge undercollateralized four days later. The exploit adds to a pattern that has now cost the industry $340.7 million across 14 bridge incidents in 2026 alone, according to PeckShield.
Taiko, an Ethereum Layer-2 rollup co-founded by former Loopring CEO Daniel Wang with $13.71 million in total value secured per L2Beat, relied on Intel SGX hardware enclaves to attest the validity of cross-chain state transitions. The trust model assumed that the signing key would remain sealed inside secure hardware. It did not. The key was committed as a plaintext file to the project's open-source taikoxyz/raiko repository, where it sat accessible to anyone with an internet connection.
The incident raises a question that extends beyond Taiko's $14.5 million market-cap token: how many other L2 and bridge systems depend on operational security assumptions — key custody, server access, signing thresholds — that their code audits never examine.
The attack exploited a single file: enclave-key.pem, an RSA-3072 private key stored in the public taikoxyz/raiko GitHub repository. Raiko is Taiko's multi-prover stack, combining Intel SGX attestation with zero-knowledge backends including SP1 and RISC0. The architecture was designed to require simultaneous defeat of independent proof systems. The leaked key bypassed that layered design entirely.
The exploit unfolded in two steps, according to analysis by BlockSec and Blockaid:
Step 1 — Prover Registration. The attacker used the leaked key to register a rogue SGX prover. Taiko's L1 contracts validated provers against a stored MrSigner value derived from the corresponding public key. Because the attacker possessed the genuine private key, their forged prover matched the trusted MrSigner and was accepted as legitimate by the on-chain verifier.
Step 2 — Fraudulent Attestations. With prover status established, the attacker signed fake L2 state attestations and withdrawal proofs. These forged proofs triggered processMessage() calls on Ethereum, setting withdrawal statuses to RETRIABLE. The attacker then called retryMessage(), which executed with minimal additional checks, releasing funds from the ERC20 Vault on Ethereum mainnet. No corresponding MessageSent events existed on Taiko's source chain — the withdrawals were fabricated end-to-end.
Four attacker wallets have been identified on-chain:
0x7506DeA0c38ca0B55364B22424374c5A1ae1B76a0x5fbc60a12bc6635e7d587d8dac52e4b1388b49900x3cc936b795a188f0e246cbb2d74c5bd190aecf180x9108828e30f2de407aadb0af677b4a9228e4acd4Intel Software Guard Extensions (SGX) create isolated execution environments called enclaves. Code and data inside an enclave are protected from the host operating system, hypervisors, and other software. In Taiko's architecture, SGX enclaves generated cryptographic attestations that L2 state transitions were valid. The L1 bridge contracts accepted these attestations as proof, enabling cross-chain asset transfers.
The security model rests on a critical assumption: the enclave signing key never leaves the secure hardware. Taiko's multi-prover design — SGX plus ZK backends — theoretically required an attacker to compromise multiple independent systems. In practice, the SGX layer was the only one actively verifying bridge messages. The ZK provers were not yet enforced as mandatory co-signers on bridge withdrawals.
When the signing key was committed to a public repository, the entire trust chain collapsed. The attacker did not need to break SGX hardware, find a cryptographic weakness, or compromise a server. They needed only to read a file on GitHub.
BlockSec's Phalcon team described it as "the same cross-chain proof-forgery pattern" observed in bridge exploits throughout 2026.
| Time (UTC) | Event | |---|---| | June 22, 00:44–00:49 | Blockaid's automated exploit detection system flags suspicious activity on Taiko ERC20 Vault | | June 22, ~06:00 | Taiko Security Council activates emergency response | | June 22, ~06:08 | Block proposers halt production; L1 Bridge and ERC20 Vault withdrawals paused | | June 22, ~09:00 | Taiko confirms compromise via public statement: "We have confirmed a compromise of Taiko's chain state verification mechanism" | | June 22, 17:09 | Recovery PR #21820 opened on GitHub | | June 25 | Taiko confirms bridge remains undercollateralized; pledges full 1:1 recollateralization before reopening |
Detection-to-containment took approximately five to six hours. During that window, the attacker extracted approximately 870 ETH and nearly 2 million TAIKO tokens from the ERC20 Vault. Roughly 2 million TAIKO tokens (~$170,000 at pre-exploit prices) were transferred to the MEXC exchange before Taiko coordinated a deposit freeze.
Direct losses: ~$1.7 million in ETH and TAIKO tokens drained from the ERC20 Vault on Ethereum.
Token impact: TAIKO fell more than 20% following disclosure, dropping from ~$0.097 to ~$0.077. The token's market capitalization contracted from approximately $14.5 million. The $1.7 million loss represented roughly 11.7% of TAIKO's pre-exploit market cap — a severe ratio by any standard.
Bridge status: As of June 25, the Taiko bridge remains undercollateralized. The team has committed to restoring 1:1 backing before reopening but has not specified a timeline or funding source.
TVS context: Taiko held $13.71 million in total value secured on L2Beat prior to the incident, classifying it as a Stage 0 rollup. The loss of $1.7 million represents approximately 12.4% of the total value secured on the network.
Taiko's CEO has filed a formal report with Singapore authorities. The team stated: "We took careful, deliberate steps from the start: containing the incident, identifying how it happened, and working with our board on the right way to protect users."
Recovery PR #21820, titled "port hack recovery hooks to v3," proposes four structural fixes:
As of publication, the PR had been opened but specific merge and deployment timelines have not been publicly confirmed. The Taiko team stated that testing is underway but provided no target date for bridge reopening.
The team has also warned users against phishing attempts: "We'll never DM you first, and there's no claim or refund site."
The Taiko incident is the latest in a year that has made bridge security the dominant theme in crypto losses. PeckShield data as of June 1, 2026 shows:
The two largest incidents of 2026:
| Date | Protocol | Loss | Vector | |---|---|---|---| | April 19 | Kelp DAO | $292M | LayerZero message spoofing via poisoned RPC node | | April 1 | Drift Protocol | $285M | Social engineering + fake collateral |
Chainalysis found that Kelp DAO's exploit succeeded because LayerZero had set a 1-of-1 RPC quorum default, meaning a single compromised node could authorize fraudulent cross-chain messages. The structural similarity to Taiko's failure is notable: in both cases, the theoretical multi-party security model was undermined by a single-point-of-failure in operational deployment.
Additional 2026 bridge exploits include IoTeX ioTube ($4.4M, private key compromise), CrossCurve ($3M, missing bridge validation), Hyperbridge ($2.5M, bridge exploit), and Verus-Ethereum ($11.4M, May). April 2026 recorded 30 separate hack incidents — approximately one per day — making it the most-hacked month on record for the crypto industry.
Bridge TVL stood at $21.94 billion as of March 2026, according to DefiLlama. At the current annualized loss rate, roughly $680 million per year is being extracted from bridge infrastructure, implying a loss rate of approximately 3.1% of bridge TVL annually.
The Taiko exploit exposes a gap in the industry's security review process. Smart contract audits examine on-chain code for logical vulnerabilities, reentrancy bugs, and access control failures. They rarely assess operational infrastructure: key management, CI/CD pipeline security, repository access controls, or hardware enclave deployment procedures.
Taiko's smart contracts may have passed audit. The enclave-key.pem file sitting in a public repository would not have been flagged by a Solidity audit because it is not a Solidity problem. It is an operational security failure — one that rendered the entire cryptographic trust model irrelevant.
This gap is not unique to Taiko. IoTeX's ioTube bridge lost $4.4 million in February 2026 through a private key compromise. The pattern repeats: the weakest link in bridge security is not the code verified by auditors but the infrastructure operated by teams.
L2Beat classifies Taiko as Stage 0, noting explicit flags for the absence of a user exit window alongside SGX-related proof assumptions. The classification system, while useful, does not capture operational security practices — the exact category of risk that materialized in this exploit.
enclave-key.pem — committed to a public GitHub repository enabled a $1.7 million bridge drain, representing 12.4% of Taiko's total value secured.The Taiko exploit is small by 2026 standards — $1.7 million against $292 million at Kelp DAO or $285 million at Drift. Its significance lies in the mechanism. A private key posted to GitHub is not a sophisticated attack. It does not require zero-day exploits, social engineering campaigns, or nation-state resources. It requires a git clone and the ability to read a PEM file.
The incident demonstrates that the weakest point in cross-chain infrastructure is not typically the cryptography, the consensus mechanism, or the smart contract logic. It is the operational layer: how keys are stored, how access is controlled, how deployment pipelines are secured. These are mundane concerns — the kind that do not generate conference talks or audit reports — but they are the ones that keep producing nine-figure losses.
Until the industry subjects operational infrastructure to the same rigor applied to on-chain code, bridge exploits will remain the dominant source of value extraction from Web3 systems.