Ethereum L2 Bridge Exploit Drains $1.7M: Leaked SGX Key Defeats Taiko Trust Model
Summary
Taiko suffered a bridge exploit that drained about $1.7 million after a private signing key for its SGX-based prover system was exposed in a public GitHub repository. The attacker used the leaked key to forge enclave attestations and make the bridge accept fake withdrawal proofs. Taiko halted block production, told users to withdraw funds from all bridges, and activated its security council while it contained the incident. The attack highlights how a single leaked key can break the trust model of TEE-assisted blockchain infrastructure, even when smart contracts have been audited.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected