An exploiter returned 331.8 Ether, worth approximately $624,000, to Across Protocol following a $3.6 million exploit on the Solana blockchain. Blockchain security firm PeckShield reported the on-chain transaction. The funds were transferred back to a designated wallet controlled by the protocol team weeks after the initial attack, raising questions about the exploiter's motives.
The attack targeted Across Protocol's cross-chain bridging infrastructure, the mechanism for moving assets between Ethereum Virtual Machine-compatible chains and Solana. Attackers used a vulnerability in the protocol's smart contracts to drain $3.6 million in tokens—including USDC, USDT and Wrapped Ether—from its liquidity pools. On-chain analysis showed the stolen assets were consolidated and routed through mixers and decentralized exchanges, complicating tracing efforts.
The partial return often signals a white-hat action—where a hacker exploits a vulnerability to expose it, then returns the funds—or a negotiation attempt. The 331.8 Ether represents less than one-fifth of the total stolen. The remaining $2.976 million is unrecovered, leaving a deficit for the protocol and its affected users and creating uncertainty for liquidity providers who deposited capital into Across Protocol's pools.
Protocols managing cross-chain liquidity face scrutiny after incidents like this. Investors holding positions in bridge tokens are watching for post-mortem analyses and remediation plans as indicators of how teams manage crises and whether the protocol can hold its liquidity base.

