Trust bridge crossed. The attacker returned 331.8 ETH to Across Protocol's Hub Pool Owner multisig address yesterday. On the surface, a win. Dig deeper: this is a Band-Aid on a severed artery.

Data checked. Community warned. The funds—worth approximately $620,000 at current prices—represent only 17% of the $3.6 million stolen from the protocol's Solana side on July 28. The attacker still holds the rest. The vulnerability that enabled the exploit remains undisclosed.
Context: A bridge broken before it was built. Across Protocol is a cross-chain bridge that moves assets between Ethereum and Solana. It relies on a relayer network and multisig governance—a design I've audited a dozen times over the past three years. In my experience, these systems often contain hidden assumptions about message verification and slippage tolerance. The July 28 attack triggered a flash loan–assisted drain of $3.6 million, with the attacker moving funds through multiple wallets before landing on Ethereum. Now, a partial return. But why?
Core: The numbers tell a story, not a solution.
Let's break down what we know—and don't.
First, the return itself is real. The 331.8 ETH was sent to a known multisig address controlled by the Across team. On-chain verificiation by PeckShield confirms the transaction. But here's the rub: the attacker didn't return the full loot. They kept roughly 83% of the stolen value, currently sitting in an address that shows no signs of further movement.
Second, the technical root cause is still unknown. Was it a signature replay attack? A relayer collusion? A manipulation of the Solana→Ethereum message passing layer? Without a public post-mortem, every user who funds this bridge is betting on an untested patch. I've witnessed similar partial returns in past hacks—Polynetwork, Multichain—and in every case, the protocol later suffered either a second exploit or an exodus of liquidity. The market hasn't learned. Yet.
Third, the immediate impact is muted. Across Protocol's TVL hovered around $45 million before the attack; it has since dropped by roughly 12%, according to DefiLlama. The partial return briefly stabilized the price of the native ACX token, but volume remains thin. The real loss isn't the $3.6 million—it's the erosion of trust. Liquidity gone. Run. Not yet, but the signal is flashing yellow.

Contrarian: The return is a trap for optimists.
The mainstream narrative will spin this as a victory: “Hacker gives back $620k, protocol avoids full disaster.” That's dangerous. Here's what I see from the code trenches.
- Partial returns are often a negotiation tactic. Experienced attackers know that returning a fraction buys time, reduces attention, and can even lead to reduced legal pressure. The remaining funds can still be laundered through mixers or cross-chain bridges. The attacker is playing chess while the market is playing checkers.
- The vulnerability remains unpatched. Across Protocol has not released a detailed security report. If the attack vector is something like a flawed Merkle proof in the Solana message relay, it could take weeks to fully redesign. Meanwhile, the protocol still processes transactions. Running on a broken bridge is like driving a car with a cracked axle—eventually, it fails again.
- The community is being misled by the return. Retail users see “attacker returns funds” and think “safe now.” But the underlying weakness? Still there. I've seen this pattern in 2022 with the Wormhole attack: partial recovery created a false sense of security, and the project later faced a governance crisis. Across Protocol's multisig itself is a single point of control—an ironic weakness for a bridge that promises decentralization. From my audit experience, any bridge with a power-concentrated governance key is only as safe as the weakest signer.
Takeaway: Watch the silence, not the ETH.
The attacker's return is a headline, not a resolution. The real story is what comes next.
- If Across Protocol publishes a full breakdown of the vulnerability within two weeks, and offers full compensation to all affected users, trust may slowly rebuild.
- If they stay quiet, or issue a vague “security update,” treat the 331.8 ETH as an expensive distraction.
My advice? Don't bridge funds through Across until you see a peer-reviewed audit and a clear explanatory report. The attacker still holds the keys to the kingdom—and they've shown they know how to use them.
The bridge is cracked. A $620k patch won't hold forever. Data checked. Community warned.
