MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: $6.2M stolen from Saga exploit land on Tornado Cash – Cryptopolitan
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$76,255.001.91%
  • ethereumEthereum(ETH)$2,330.411.45%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.431.11%
  • binancecoinBNB(BNB)$631.361.71%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.091.06%
  • tronTRON(TRX)$0.328422-1.56%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.01%
  • dogecoinDogecoin(DOGE)$0.0954361.27%
Blockchain Security

$6.2M stolen from Saga exploit land on Tornado Cash – Cryptopolitan

Last updated: January 25, 2026 4:20 am
Published: 3 months ago
Share

The team has the vulnerability that led to the exploit and is expected to publish a comprehensive technical post-mortem once remediation is complete.

$6.2 million of the funds stolen during the SagaEVM exploit has been traced to deposits into Tornado Cash, a privacy mixer on Ethereum that helps obscure transaction trails.

The tactic is common among hackers trying to launder considerable stolen funds and make recovery almost impossible.

The exploit that targeted SagaEVM, described as an L1 to launch L1s, occurred on January 21. After the incident, the team posted on X that the L1 had been paused at block height 6593800 in response to the confirmed exploit on the SagaEVM chainlet.

How the hackers laundered the stolen funds

According to the report by blockchain security firm CertiK, the attackers initially distributed the funds across five separate wallets before they funneled them into the privacy mixer via multiple transactions.

“Mitigation is underway, and the team is fully focused on a solution,” the team wrote at the time.

The exploit saw nearly $7,000,000 in USDC, yUSD, ETH, and tBTC transferred to the Ethereum mainnet. The exploiter’s wallet had been identified and fed to exchanges and bridges to blacklist it and possibly reclaim the stolen funds.

According to Certik’s report, $6.2 million out of those funds is what has now been split into deposits fed into the Tornado Cash mixer. This is expected to frustrate remediation and recovery efforts.

The latest deposit adds to the notoriety of Tornado Cash, adding to a past checkered with US sanctions and legal issues still plaguing its developers.

Attackers continue to use it to obscure their trails post-exploit, and it does exactly what it was designed to do — help them disappear.

What happened to SagaEVM?

According to a post-mortem the team shared on January 21, the incident involved a coordinated sequence of contract deployments, cross-chain activity, and subsequent liquidity withdrawals.

The document revealed that the team paused the chain out of an abundance of caution while they actively investigated and mitigated. It revealed the focus was stopping further impact by keeping SagaEVM paused while mitigation is implemented; validating the full blast radius using archive data and execution traces; and hardening the relevant components before a restart.

The main components affected by the exploit include the SagaEVM chainlet, as well as Colt and Mustang. Others, like the Saga SSC mainnet, Saga protocol consensus, validator security, and other Saga chainlets, went unaffected.

“There has been no consensus failure, validator compromise, or signer key leakage,” the document read. “The broader Saga network remains structurally sound.”

The team claimed its next steps would be to complete root cause validation, patch and harden affected cross-chain and deployment components, coordinate with ecosystem partners where relevant, and publish a more comprehensive technical post-mortem.

Vulnerability links back to Cosmos

After receiving support from Cosmos Labs engineers, the team has revealed that the issue originated from the original Ethermint codebase, making it an inherited issue.

In response to that post, Cosmos Labs shared a statement, admitting they are aware of the incident and claiming they have been working closely with Saga and external security partners to investigate and remediate the “confirmed vulnerability.”

They revealed they had contacted a subset of EVM chains they deemed affected by the incident and provided short-term mitigations.

“As always, we recommend all projects continue to implement baseline security practices such as rate-limiting and security monitoring to strengthen early detection and mitigation,” they wrote on X.

Join a premium crypto trading community free for 30 days – normally $100/mo.

Read more on Cryptopolitan

This news is powered by Cryptopolitan Cryptopolitan

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Nearly $3 Billion Lost In 200 Crypto Security Incidents In 2025 – With Bybit Alone Losing $1.5 Billion
BTC Becomes the New Favorite of Capital, SunnyMining Seizes the Entrance to Stable Income for Institutions
CoinShares publishes the Scheme Circular in relation to joint merger plan
Crypto news: Why institutional investors are adding Remittix to watchlists over Dogecoin at the start of Q4
Best Crypto Presale Projects to Buy Now Before TGE and Exchange Listings

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Ethereum Foundation Forms Post-Quantum Team as Security Concerns Mount
Next Article ETHA vs. BITQ: How Does This Ethereum Compare to a Fund Full of Crypto Companies
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d