Ethereum L2 Bridge Exploit Drains $1.7M: Leaked SGX Key Defeats Taiko Trust Model

General News

Summary

Taiko suffered a bridge exploit that drained about $1.7 million after a private signing key for its SGX-based prover system was exposed in a public GitHub repository. The attacker used the leaked key to forge enclave attestations and make the bridge accept fake withdrawal proofs. Taiko halted block production, told users to withdraw funds from all bridges, and activated its security council while it contained the incident. The attack highlights how a single leaked key can break the trust model of TEE-assisted blockchain infrastructure, even when smart contracts have been audited.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
No AI classifications detected

Linked Companies