Solana Relayer Bug Exposes Vulnerability in Offchain Software
An attacker exploited a bug in Risk Labs' offchain Solana relayer on July 17, 2026, but no user funds were lost or at risk. The vulnerability was due to a missing eight-byte check in an offchain code file that allowed the attacker to drain roughly $4.5 million from the relayer's capital.
The attack unfolded inside a narrow technical seam between Solana's onchain programs and the offchain software Risk Labs used to read them. The attacker submitted 1,627 forged deposits across 18 destination chains totaling roughly $41.7 million in face value. However, the relayer only filled 581 of those fraudulent requests, paying out approximately $4.5 million of its own capital before being disabled.
Risk Labs absorbed the financial damage directly and has since deployed a root-cause fix to prevent similar attacks in the future. The incident highlighted the importance of secure offchain event parsing logic and led to more advanced anomaly detection techniques being implemented. Law enforcement is also involved in recovery efforts, with attacker addresses flagged across exchanges and off-ramps.