ChainBleedv0.1 · open intel
← back to feed·SAGATOKEN-SUPPLY2026-01-22 · 4mo ago
Incident · COMMUNITY-ALERT

SagaEVM (Saga chainlet)

SagaEVM — Ethermint IBC message validation bypass → unlimited stablecoin mint
Estimated loss
$7.00M
VERDICT —AUDIT-CATCHABLE
Audit-catchable. The vulnerability — IBC message validation that checks message shape but not economic preconditions (e.g. is the mint backed by escrow?) — is a known cross-chain audit checklist item. Halborn's own post-mortem frames it as catchable through standard Cosmos/Ethermint review. Bytecode-catchable: yes, the unguarded-mint path is structurally visible in the deployed validator's message handler.
▰ METHOD
IBC message validation bypass + helper contract abuse → unbacked stablecoin mint
TOKEN-SUPPLYBYTECODE CATCHABLEAI SCANNABLE
Root cause

SagaEVM's underlying Ethermint stack contained an IBC-message-validation bypass: the attacker crafted custom IBC messages handled by a helper contract that abused the IBC token-creation path to mint stablecoin (the Saga Dollar 'D' token) WITHOUT posting collateral. The vulnerability lived in the validation logic for cross-IBC message handling — the bytecode validated structure but not economic preconditions on the mint operation. With unbacked D tokens in hand, the attacker bridged them to Ethereum and swapped via Uniswap V4 for ~2,000 ETH (~$6M) plus other assets, ultimately routing $6.2M into Tornado Cash. The Saga Dollar stablecoin lost its peg ($1.00 → $0.75) as the unbacked supply hit secondary markets. Saga halted the SagaEVM chainlet at block 6,593,800 to stop further drains. TVL dropped from ~$36M to ~$21M (-42%). Total realized loss ~$6.8-7M.

Forensic narrative

Method: Ethermint IBC-message-validation bypass via a helper contract abusing custom IBC messages, enabling unlimited mint of the Saga Dollar stablecoin without collateral backing. Root cause: SagaEVM's underlying Ethermint stack contained an IBC-message-validation bypass: the attacker crafted custom IBC messages handled by a helper contract that abused the IBC token-creation path to mint stablecoin (the Saga Dollar 'D' token) WITHOUT posting collateral. The vulnerability lived in the validation logic for cross-IBC message handling — the bytecode validated structure but not economic preconditions on the mint operation. With unbacked D tokens in hand, the attacker bridged them to Ethereum and swapped via Uniswap V4 for ~2,000 ETH (~$6M) plus other assets, ultimately routing $6.2M into Tornado Cash. The Saga Dollar stablecoin lost its peg ($1.00 → $0.75) as the unbacked supply hit secondary markets. Saga halted the SagaEVM chainlet at block 6,593,800 to stop further drains. TVL dropped from ~$36M to ~$21M (-42%). Total realized loss ~$6.8-7M. Narrative: Saga halted the SagaEVM chainlet on 2026-01-22 at block 6,593,800 after the unbacked-mint attack. Attacker bridged minted tokens to Ethereum, swapped via Uniswap V4 for ~2,000 ETH and other assets, deposited $6.2M into Tornado Cash. Saga Dollar lost its peg ($1.00 → $0.75) as supply expanded. TVL fell from ~$36M to ~$21M (-42%). Notes: Cosmos/Ethermint ecosystem incident. Cross-IBC validation surface is the relevant attack class; future Ethermint deployments should review IBC handler economic preconditions, not just structural validation.

Primary source
https://www.halborn.com/blog/post/explained-the-sagaevm-hack-january-2026
Sourced from
community-alert
Technical record
chain
saga
protocol
SagaEVM (Saga chainlet)
bug_class
token-supply
date_occurred
2026-01-22
loss_usd
$7,000,000
classification
Cross-Chain / IBC Logic
technique
IBC message validation bypass + helper contract abuse → unbacked stablecoin mint
source_id
ca:sagaevm-2026-01-22
Related — same bug class· token-supply
2026-04-16
1mo ago
Rhea Lend
Contract Vulnerability
token-supply
$18.40M
UNRATED
2026-02-23
3mo ago
BASE
DGLD
Infinite Mint and Dump
token-supply
UNRATED
2026-01-21
4mo ago
SAGA
Saga
Infinite Mint and Dump
token-supply
$7.00M
UNRATED
2025-11-23
6mo ago
BSC
Port3 Network
Infinite Mint and Dump
token-supply
$166.0K
UNRATED
2025-09-23
8mo ago
MULTI
Seedify
Infinite Mint and Dump
token-supply
$1.00M
UNRATED
2025-08-26
9mo ago
PULSEC
BetterBank
Infinite Mint and Dump
token-supply
$5.00M
UNRATED
ChainBleed — live web3 threat intelligence