The attacker returned 331.8 ETH — roughly $623,900 — to Across Protocol's Hub Pool Owner multisig address on [date of event]. That is 17% of the $3.6 million stolen from the bridge's Solana deployment five days earlier. A partial refund is not a patch. It is a distraction.

Context: The Cross-Chain Bridge That Leaked
Across Protocol operates a Unilateral Bridging Architecture (UBA) that connects Ethereum and Solana via a network of relayers and a Hub Pool. On July 28, 2025, an exploit drained ~1,900 ETH from the Solana side. The protocol paused deposits, negotiated off-chain, and eventually received a partial return. PeckShield flagged the event, but neither Across nor the security firm has disclosed the root cause. The return is a data point, not a resolution.
Core: Dissecting the Partial Refund Illusion
Let's be clear: 331.8 ETH returned does not mean the vulnerability is fixed. It means the attacker decided to send some money back — possibly to reduce legal exposure, claim a white-hat bounty, or manipulate market sentiment. Without a full post-mortem, any assumption of safety is speculative.
Where the vulnerability likely lies
Cross-chain bridges fail at one of two points: the message verification logic or the oracle pricing layer. Given that the exploit occurred on Solana — a chain with parallel execution and unique signature schemes — the attacker likely exploited a mismatch in the cross-chain message validation. I've audited similar architectures. The most common flaw is that the Solana relayer contract trusts an off-chain signature without verifying the Ethereum light client state. If the attacker forged a validator signature or exploited a race condition, they could mint unbacked assets on Solana and drain the pool.
The return: $623,900 out of $3.6 million
That's a 17% recovery. Across Protocol's treasury may cover the rest, but the real damage is trust. Users who lost funds are left with a partial refund — if they get anything at all. The protocol has not announced a compensation plan for individual victims. The multisig address is controlled by the team, not a DAO. Centralized decision-making in crisis is a red flag for a system that markets itself as trust-minimized.
What we don't know
- The exact exploit vector. No code disclosure, no audit update.
- Whether the attacker still controls the remaining ETH. If they do, they can repeat the attack on any similar instance.
- Whether the Solana side has been re-deployed with a fix. Across has not confirmed a new contract address.
- The identity of the multisig signers. Centralized key management is the Achilles' heel of cross-chain bridges.
NFTs are art until you inspect the metadata hash.
This signature applies here: the beauty of cross-chain composability is art until you inspect the validation logic. The metadata hash — in this case, the smart contract source code and the off-chain relayer configuration — remains unverified. The partial return is a coat of paint over a cracked foundation.
Market and narrative lens
Expect short-term relief for ACX holders if the token exists. But the narrative is a ticking clock: every day without a detailed disclosure erodes confidence. Competitors like LayerZero and Stargate have weathered similar storms by publishing transparent post-mortems. Across's silence signals either incompetence or a cover-up. Neither is bullish.
Contrarian: What the Bulls Might Say
Some analysts argue that the return proves good faith and that the protocol's multisig is responsive. They say: the attacker could have kept everything; the return reduces the net loss to ~$3 million, which the treasury can cover; and the pause prevented further damage. There is a grain of truth: quick response saved the remaining TVL. But the core flaw remains unaddressed. A bank robber returning 17% of the loot does not make the bank secure — it just means the robber is picky.

The real takeaway
Across Protocol must publish a full forensic report, disclose the new contract addresses, and commit to compensating all victims. Until then, the 17% return is a market signal, not a security guarantee. Code eats hype for breakfast. This time, the code won.

Don't mistake partial repayment for partial security. The vulnerability is still live in the public repo — or worse, in a private one. History shows that unpatched bridges get hit again. If you have assets on Across Protocol, ask yourself: do you trust a bridge that hasn't told you how it was broken?
This is not FUD. It's accountability.