Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap
Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.
