SagaEVM Exploit Drains Nearly $7 Million as Network Is Paused

SagaEVM Exploit Drains Nearly $7 Million as Network Is Paused

N
News Editor 01
2026-07-24 00:50:17
Saga said its SagaEVM chain lost nearly $7 million in an exploit. The stolen assets were moved out quickly, converted into ETH, and bridged away. The team paused the network at block 6593800 and is working with exchanges and bridge operators to blacklist the attacker address.
SagaEVMsecurity breachbridgeETHon-chain exploit

Saga said its SagaEVM chain lost nearly $7 million in a security breach. The network has been paused while the team investigates the incident and works on fixes.

According to the project, the stolen funds were moved out of the SagaEVM network shortly after the suspicious activity was detected, converted into ETH, and then bridged away. Saga said it temporarily halted the network at block height 6593800 on January 21 to contain the situation and review the attack path.

The exploit involved contracts, liquidity flows, and cross-chain activity

Saga said the attack used a coordinated sequence of contract deployments, liquidity movements, and cross-chain interactions. That combination allowed the exploiter to withdraw funds rapidly. The pace of the transfers appears to have limited the response window once the activity was spotted.

The team also said it has not found signs of a broader infrastructure failure. Saga stated that the core consensus layer and the SSC mainnet were not affected, and that there is no evidence of validator compromise, consensus failure, or leaked signer keys.

Attacker wallet identified as Saga seeks blacklisting support

Saga identified wallet “0x2044…c6ecb” as the address tied to the attacker. The team said it is working with exchange platforms and bridge operators to blacklist the wallet in an effort to limit additional movement of funds and reduce further damage.

The project said its immediate focus is to complete the investigation and address the vulnerabilities that made the exploit possible. After that process ends, Saga plans to publish a detailed post-mortem covering the scope of the attack, how it unfolded, and what security changes will follow.

Attention now turns to the post-mortem and fund tracing

Based on the current disclosure, the damage is centered on SagaEVM rather than the protocol’s broader consensus layer or SSC mainnet. With the chain paused, the next questions are when Saga will confirm the root cause and whether the stolen assets, after being swapped into ETH and bridged out, can still be tracked or intercepted.

So far, Saga has not released a fuller breakdown of the fund flows or a technical incident report. The team said more details will be shared after the investigation is complete.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.