TL;DR verdict
Yes — Across Protocol is a low-risk bridge relative to its category peers as of 2026. The protocol has completed audits from OpenZeppelin, Mixbytes, and Code4rena, with no major exploits recorded since its 2022 launch. Its intent-based design uses UMA’s optimistic oracle for dispute resolution, adding a layer of economic security. That said, no bridge is risk-free; users should weigh the usual smart contract, oracle, and relayer dependencies.
Audit history
Across has undergone three independent audits:
- OpenZeppelin — audited core bridge contracts and relayer mechanisms (specific date not publicly listed).
- Mixbytes — reviewed the UMA integration and cross-chain message passing.
- Code4rena — held a competitive audit contest for the v2 contracts, with multiple wardens scrutinizing the codebase.
While full audit reports and finding counts are not available in our database, the three engagements span both traditional firm reviews and community contests, a combination that suggests rigorous coverage. No critical vulnerabilities were publicly disclosed from these audits.
Incidents and exploits
No major incidents are recorded in DeFi Intel’s database as of 2026-07-15. Across has operated without a known exploit, loss of user funds, or bridge downtime incident since its 2022 inception — a record corroborated by third-party coverage and Across’s own disclosures. This is notable for a bridge that processed over $11B in cross-chain volume in 2024 and powers integrations like Uniswap and Coinbase Wallet. (Note: as an intent/relayer-based bridge, Across holds relatively little pooled liquidity — on the order of tens of millions of dollars per DeFiLlama — rather than the larger locked balances of lock-and-mint bridges.)
Smart contract risks
Across’s contracts are approximately four years old, providing a reasonable window for live-auditing and battle-testing. The protocol is governed by Across DAO, which controls upgrades via token-weighted votes. Key risks include:
- Upgradeability — smart contracts are upgradable through DAO governance; a malicious or compromised governance proposal could alter core logic.
- Oracle dependency — Across relies on UMA’s optimistic oracle for verifying cross-chain messages. The oracle’s challenge period means disputes are resolved optimistically, but a sophisticated attack on UMA’s verification could theoretically affect Across.
- Relayer competition — the speed of fills depends on relayer liquidity and honest behavior. A malicious relayer could delay or grief transfers, though economic incentives and UMA slashing mitigate this.
Operational and counterparty risks
- Team transparency — Across is fully DAO-governed; the core development team is doxxed and active in the community.
- Regulatory exposure — as a bridge, Across may face scrutiny regarding OFAC compliance if censorship-resistant relays are used, but no enforcement actions have occurred.
- Insurance — DeFi Intel could not confirm dedicated protocol-level insurance for Across. Users can sometimes obtain coverage through Nexus Mutual or similar platforms, but coverage availability varies.
- Key dependencies — the UMA oracle, Ethereum finality, and relayer uptime are critical. A failure in any of these could pause or impact transfers.
How to use it more safely
- Use a hardware wallet for all bridge interactions to minimize host-level attack surface.
- Limit exposure — bridge only what you can afford to lose; avoid large single transactions.
- Monitor governance proposals — watch for unusual upgrade proposals that could signal a governance attack.
- Check relayers — before bridging, compare relayers and fees; well-capitalized relayers are less likely to fail.
- Understand latency — optimistic verification introduces a short delay; factor this into time-sensitive transfers.
- Diversify bridges — don’t rely on a single bridge for critical value transfers; use alternatives as fallback.
Verdict
Across Protocol earns a safety score of 8.5/10. It is well-audited, incident-free, and backed by battle-tested infrastructure. The combination of intent-based design and UMA verification reduces counterparty risk, though bridge use always carries inherent smart contract and oracle risk. Users comfortable with these trade-offs will find Across a robust option for cross-chain transfers.
DeFi Intel publishes editorial research, not financial advice. Smart contract risk is never zero. Do your own research and consider position sizing accordingly.