Saga paused the SagaEVM chain after identifying a security incident involving a coordinated sequence of contract deployments, cross-chain activity, and liquidity withdrawals that resulted in nearly $7 million in assets being moved to Ethereum mainnet. Saga reported the impact was limited to the SagaEVM chainlets Colt and Mustang, while the Saga SSC mainnet and other chainlets remained operational; the company also stated there was no validator compromise, no consensus failure, and no signer key leakage, indicating the broader network remained structurally sound.
Saga said it paused SagaEVM at block height 6593800 to prevent further impact while engineering and security teams validate blast radius using archive data and execution traces, harden affected components, and complete remediation before restart. Saga identified an exploiter wallet 0x2044697623afa31459642708c83f04ecef8c6ecb and is coordinating with exchanges and bridges to blacklist the address and attempt recovery of funds (including USDC, yUSD, ETH, and tBTC); additional protections to deter similar attack patterns were reported as already implemented, with a fuller technical post-mortem planned after remediation.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
In a separate incident noted in reporting on the SagaEVM exploit, Makina disclosed an approximately 11-minute attack that resulted in losses of nearly $4 million. Makina said it was developing and auditing a fix for deployment through a protocol upgrade.
Saga published a security incident investigation update stating that recovery efforts were underway and that additional protections had been implemented. The update also reiterated that the incident did not appear to affect core validator or consensus integrity.
Following the exploit, SagaEVM halted blockchain operations while recovery efforts began. Saga said there was no evidence of validator compromise, consensus failure, or leaked signer keys, and that the broader network remained structurally sound.
SagaEVM suffered a security incident in which an attacker used contract deployments, cross-chain activity, and liquidity withdrawals to steal nearly $7 million in cryptocurrency assets. Saga later said it had identified the attacker’s wallet.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.