T
iTokenly

Saga (SagaEVM) hack — January 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 21, 2026
Target typeBlockchain or validator set
Loss$7,000,000Published estimates range $7,000,000 to $7,000,000Price at time of incident
MethodContract logic errorA helper contract fed crafted IBC messages to an EVM precompile bridge on the SagaEVM chainlet. Validation logic inherited from the Ethermint codebase treated them as legitimate cross-chain transfers, minting Saga Dollar stablecoins with no collateral behind them; the unbacked tokens were then redeemed against real deposits and bridged out.
ChainsOther, Ethereum
OutcomeUnresolved

What happened

Saga, a Cosmos-based layer-1 that hosts application-specific "chainlets", halted its SagaEVM chainlet on 21 January 2026 after an attacker minted its Saga Dollar stablecoin without collateral and bridged the proceeds out. Saga said on X that SagaEVM had been paused at block height 6,593,800 in response to a confirmed exploit, and that its main chain, consensus, validators and other chainlets were unaffected.

Security firm Decurity said the attacker deployed a helper contract that fed crafted IBC messages to an EVM precompile, causing the bridge to treat them as legitimate cross-chain transfers and mint Saga Dollars with nothing deposited behind them. Halborn traced the underlying flaw to transaction validation logic inherited from the Ethermint EVM codebase that SagaEVM had forked, bypassing collateral deposit checks and stablecoin supply accounting. The stolen balance — reported by all three accounts as roughly $7 million in USDC, yUSD, ETH and tBTC — was bridged to Ethereum and swapped into ether through KyberSwap, 1inch and CoW Swap. Protos, tracking the attacker's address, recorded about 2,089 ETH worth around $6 million plus roughly $850,000 of YieldFi tokens deposited into Uniswap pools, with over 12 million Saga Dollars still sitting in the exploiter's wallet. Halborn reported that a significant portion was subsequently routed through Tornado Cash.

Saga Dollar depegged to about $0.75. One on-chain analyst, Specter, suggested the loss came from a private key compromise rather than a contract flaw; Saga, Decurity and Halborn all describe a code-level vulnerability, and Saga stated there was no consensus failure, validator compromise or signer key leakage.

Saga said it restricted related cross-chain activity, added safeguards, worked with exchanges and bridge operators to blacklist the attacker's address, and would publish a full technical post-mortem after remediation.

Sources

  1. ProtosSecondary · retrieved 2026-08-01
  2. crypto.newsSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Saga (SagaEVM) hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/saga
https://itokenly.com/hacks/saga

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.