Is Across Protocol Safe in 2026? A Security Analysis

TL;DR verdict

Yes — Across Protocol is a low-risk bridge relative to its category peers as of 2026. The protocol has completed audits from OpenZeppelin, Mixbytes, and Code4rena, with no major exploits recorded since its 2022 launch. Its intent-based design uses UMA’s optimistic oracle for dispute resolution, adding a layer of economic security. That said, no bridge is risk-free; users should weigh the usual smart contract, oracle, and relayer dependencies.

Audit history

Across has undergone three independent audits:

While full audit reports and finding counts are not available in our database, the three engagements span both traditional firm reviews and community contests, a combination that suggests rigorous coverage. No critical vulnerabilities were publicly disclosed from these audits.

Incidents and exploits

No major incidents are recorded in DeFi Intel’s database as of 2026-07-15. Across has operated without a known exploit, loss of user funds, or bridge downtime incident since its 2022 inception — a record corroborated by third-party coverage and Across’s own disclosures. This is notable for a bridge that processed over $11B in cross-chain volume in 2024 and powers integrations like Uniswap and Coinbase Wallet. (Note: as an intent/relayer-based bridge, Across holds relatively little pooled liquidity — on the order of tens of millions of dollars per DeFiLlama — rather than the larger locked balances of lock-and-mint bridges.)

Smart contract risks

Across’s contracts are approximately four years old, providing a reasonable window for live-auditing and battle-testing. The protocol is governed by Across DAO, which controls upgrades via token-weighted votes. Key risks include:

Operational and counterparty risks

How to use it more safely

Verdict

Across Protocol earns a safety score of 8.5/10. It is well-audited, incident-free, and backed by battle-tested infrastructure. The combination of intent-based design and UMA verification reduces counterparty risk, though bridge use always carries inherent smart contract and oracle risk. Users comfortable with these trade-offs will find Across a robust option for cross-chain transfers.

DeFi Intel publishes editorial research, not financial advice. Smart contract risk is never zero. Do your own research and consider position sizing accordingly.

Frequently asked questions

Has Across Protocol ever been hacked?

No. Across has not experienced any hack, exploit, or loss of user funds since its launch in 2022.

Who audits Across Protocol?

Across has been audited by OpenZeppelin, Mixbytes, and Code4rena. These audits cover core contracts, UMA integration, and cross-chain message passing.

What are the main risks of using Across?

Key risks include smart contract vulnerabilities, oracle manipulation via UMA’s optimistic system, relayer misbehavior, and governance attacks. Bridge-specific risks like chain reorgs also apply, though Across’s design mitigates many of these.

Is Across's code open source?

Yes, Across Protocol’s smart contracts are open source and publicly auditable. Anyone can review the code on GitHub and verify audit reports.

Sources