Forged IBC Messages Let Attacker Mint $7M in Fake Saga Dollar on SagaEVM
Saga's cross-chain messaging system is built to trust what it's told. On January 21st, an attacker exploited that trust, convincing SagaEVM's bridge that fabricated deposits were real and minting $7 million worth of Saga Dollar ($D) out of nothing.
How the exploit worked

The attack targeted the Inter-Blockchain Communication (IBC) precompile that lets SagaEVM's chainlet talk to the Cosmos side of the network. Researcher Vladimir S. traced the mechanism: a helper contract generated custom IBC messages designed to mimic legitimate collateral deposits. The precompile's bridge logic never confirmed that the underlying assets actually existed on the source chain, so the forged messages were accepted without question. Colt, the Saga protocol responsible for minting $D against posted collateral, processed the fake deposits exactly as it was built to — it simply had no way to know the collateral wasn't real.
Helper contract: 0x7D69E4376535cf8c1E367418919209f70358581E
Turning fake tokens into real assets
With newly minted $D in hand, the attacker redeemed the tokens through Colt and Mustang for yETH, yUSD, and tBTC — real, yield-bearing assets that only moments earlier had been backing genuine user positions. The proceeds moved over LayerZero to Ethereum, where the attacker converted more than 2,000 ETH (roughly $6 million at the time) through a series of swaps on 1inch and KyberSwap and CowSwap, paying between 0.00007 and 0.0023 ETH in fees per transaction. Roughly $800,000 of the haul was instead deposited into Uniswap v4 liquidity positions rather than cashed out immediately.
Attacker address: 0x2044697623afa31459642708c83f04ecef8c6ecb
By the time Saga paused the SagaEVM chainlet at block height 6593800, the $7 million had already crossed the bridge to Ethereum and moved through the DEX swaps described above.
Three days later, on January 24th, the attacker created a new wallet, approved the Uniswap V4 Position Manager, and moved two UNI-V4-POSM NFTs representing the LP position into it, leaving the original, now-flagged address empty. As of January 26th, the receiving wallet held LP positions worth about $847,000 according to Debank.
Wallet holding the LP NFTs: 0xf891de97fa96839329381743f0d6180fcefe3f64
By the following weekend, CertiK reported tracing $6.2 million of the stolen funds through Tornado Cash, split across five wallets before entering the mixer.
Attack transactions: 0x0c038d70c684b5797ed5b8ac578cf7151ec95f5a1a135cd9d48028f72d0f7a2b, 0x2651c022e2ebba23032b3f0f82a4d9e7caa0be701620e51851e232aa8e35e054, 0x1fc886dcacbc3e186941236be0e6a1605348d724c0368e21fbf485cb6157ba8f
How it came to light
DefimonAlerts was first to flag the incident, reporting that "Saga was reportedly attacked, with a large amount of Saga Dollar (D token) minted. The attacker bridged the stolen assets to Ethereum, swapping part into ETH (2,000+ ETH, worth $6M+) and deploying the rest into Uniswap v4 LP positions (worth $800K+)." Blocksec Phalcon confirmed the incident shortly after, while the root cause was still unclear and the chain sat frozen. Saga then confirmed directly: "SagaEVM has been paused at block height 6593800 in response to a confirmed exploit on the SagaEVM chainlet. Mitigation is underway." CertiK and GoPlusSecurity subsequently published the attacker's address and the exploit contracts, warning users away from them.
Saga's follow-up investigation update described "a coordinated sequence of contract deployments, cross-chain activity, and subsequent liquidity withdrawals." Cosmos Labs then added a significant detail: "The issue has been identified as originating from the original Ethermint codebase." That finding widens the scope well beyond a single chain — the underlying flaw potentially affects any EVM chain built on Ethermint. Cosmos Labs has reportedly been contacting affected projects and distributing short-term mitigations.

Market impact
$D dropped roughly 25%, depegging to $0.75; other reporting on the same event put the price at $0.73 amid the disruption. Total value locked on the Saga chain fell from $37 million to $13.6 million within 24 hours, according to DefiLlama.
Saga's own marketing had described the chain's infrastructure as "automated," promising "no need for manual bridges" and validators handling settlement seamlessly, with its Liquidity Integration Layer billed as liquidity without borders. The automation functioned exactly as designed — it just had no way to distinguish a genuine deposit from a convincingly forged one.
According to Saga's update, several things did not fail: the Saga SSC mainnet kept running normally, validators remained honest, there was no consensus failure, validator compromise, or signer-key leak, and other chainlets were untouched. Saga said it is coordinating with exchanges and bridges to get the attacker's address blacklisted, and that the chain will stay paused until its engineering and security teams finish investigating, with a full post-mortem to follow once findings are confirmed.
With Cosmos Labs pointing to Ethermint's original codebase as the source of the flaw, Saga appears to be the first casualty of a defect that could reach well beyond its own chain, leaving other EVM chains built on the same base code racing to assess their exposure.
Get new scam files the moment we publish them — usually 2–3 emails a week.