Taiko releases a security incident review for June, confirming that the attack originated from key leakage
Taiko released a security incident review on June 21st, confirming that the attack originated from off chain signature key leakage and verification process omission. The attacker forged proof and bypassed the Prover whitelist. The attacker stole approximately $1.75 million from the cross chain bridge and vault, with over $11 million in assets protected and no user funds lost. Taiko has fixed the vulnerability and re launched on July 2nd. OpenZeppelin audit confirmed that no vulnerabilities were found during the fix. The Unzen upgrade, which will be launched on August 6th, will require each block to submit a ZK proof.