$6.2 million of the funds stolen during the SagaEVM exploit has been traced to deposits into Tornado Cash, a privacy mixer on Ethereum that helps obscure transaction$6.2 million of the funds stolen during the SagaEVM exploit has been traced to deposits into Tornado Cash, a privacy mixer on Ethereum that helps obscure transaction

$6.2M of the funds stolen during the SagaEVM exploit has been deposited into Tornado Cash

3 min read

$6.2 million of the funds stolen during the SagaEVM exploit has been traced to deposits into Tornado Cash, a privacy mixer on Ethereum that helps obscure transaction trails. 

The tactic is common among hackers trying to launder considerable stolen funds and make recovery almost impossible. 

The exploit that targeted SagaEVM, described as an L1 to launch L1s, occurred on January 21. After the incident, the team posted on X that the L1 had been paused at block height 6593800 in response to the confirmed exploit on the SagaEVM chainlet.

How the hackers laundered the stolen funds 

According to the report by blockchain security firm CertiK, the attackers initially distributed the funds across five separate wallets before they funneled them into the privacy mixer via multiple transactions. 

“Mitigation is underway, and the team is fully focused on a solution,” the team wrote at the time. 

The exploit saw nearly $7,000,000 in USDC, yUSD, ETH, and tBTC transferred to the Ethereum mainnet. The exploiter’s wallet had been identified and fed to exchanges and bridges to blacklist it and possibly reclaim the stolen funds. 

According to Certik’s report, $6.2 million out of those funds is what has now been split into deposits fed into the Tornado Cash mixer. This is expected to frustrate remediation and recovery efforts. 

The latest deposit adds to the notoriety of Tornado Cash, adding to a past checkered with US sanctions and legal issues still plaguing its developers. 

Attackers continue to use it to obscure their trails post-exploit, and it does exactly what it was designed to do — help them disappear. 

What happened to SagaEVM? 

According to a post-mortem the team shared on January 21, the incident involved a coordinated sequence of contract deployments, cross-chain activity, and subsequent liquidity withdrawals.

The document revealed that the team paused the chain out of an abundance of caution while they actively investigated and mitigated. It revealed the focus was stopping further impact by keeping SagaEVM paused while mitigation is implemented; validating the full blast radius using archive data and execution traces; and hardening the relevant components before a restart. 

The main components affected by the exploit include the SagaEVM chainlet, as well as Colt and Mustang. Others, like the Saga SSC mainnet, Saga protocol consensus, validator security, and other Saga chainlets, went unaffected. 

“There has been no consensus failure, validator compromise, or signer key leakage,” the document read. “The broader Saga network remains structurally sound.” 

The team claimed its next steps would be to complete root cause validation, patch and harden affected cross-chain and deployment components, coordinate with ecosystem partners where relevant, and publish a more comprehensive technical post-mortem. 

After receiving support from Cosmos Labs engineers, the team has revealed that the issue originated from the original Ethermint codebase, making it an inherited issue. 

In response to that post, Cosmos Labs shared a statement, admitting they are aware of the incident and claiming they have been working closely with Saga and external security partners to investigate and remediate the “confirmed vulnerability.” 

They revealed they had contacted a subset of EVM chains they deemed affected by the incident and provided short-term mitigations. 

“As always, we recommend all projects continue to implement baseline security practices such as rate-limiting and security monitoring to strengthen early detection and mitigation,” they wrote on X.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Optimizely Named a Leader in the 2026 Gartner® Magic Quadrant™ for Personalization Engines

Optimizely Named a Leader in the 2026 Gartner® Magic Quadrant™ for Personalization Engines

Company recognized as a Leader for the second consecutive year NEW YORK, Feb. 5, 2026 /PRNewswire/ — Optimizely, the leading digital experience platform (DXP) provider
Share
AI Journal2026/02/06 00:47
Elizabeth Warren raises ethics concerns over White House crypto czar David Sacks’ tenure

Elizabeth Warren raises ethics concerns over White House crypto czar David Sacks’ tenure

The post Elizabeth Warren raises ethics concerns over White House crypto czar David Sacks’ tenure appeared on BitcoinEthereumNews.com. Democratic lawmakers pressed David Sacks, President Donald Trump’s “crypto and AI czar,” on Sept. 17 to disclose whether he has exceeded the time limits of his temporary White House appointment, raising questions about possible ethics violations. In a letter signed by Senator Elizabeth Warren and seven other members of Congress, the lawmakers said Sacks may have surpassed the 130-day cap for Special Government Employees, a category that allows private-sector professionals to serve the government on a part-time or temporary basis. The Office of Government Ethics sets the cap to minimize conflicts of interest, as SGEs are permitted to continue receiving outside salaries while in government service. Warren has previously raised similar concerns around Sacks’ appointment. Conflict-of-interest worries Sacks, a venture capitalist and general partner at Craft Ventures, has played a high-profile role in shaping Trump administration policy on digital assets and artificial intelligence. Lawmakers argued that his private financial ties to Silicon Valley raise serious ethical questions if he is no longer within the bounds of SGE status. According to the letter: “When issuing your ethics waiver, the White House noted that the careful balance in conflict-of-interest rules for SGEs was reached with the understanding that they would only serve the public ‘on a temporary basis. For you in particular, compliance with the SGE time limit is critical, given the scale of your conflicts of interest.” The group noted that Sacks’ private salary from Craft Ventures is permissible only under the temporary provisions of his appointment. If he has worked past the legal limit, the lawmakers warned, his continued dual roles could represent a breach of ethics. Counting the days According to the letter, Sacks was appointed in December 2024 and began working around Trump’s inauguration on Jan. 20, 2025. By the lawmakers’ calculation, he reached the 130-day threshold in…
Share
BitcoinEthereumNews2025/09/18 07:37
Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Recently, PANews interviewed Smokey The Bera, co-founder of Berachain, to unravel the background of the establishment of this anonymous project, Berachain's PoL mechanism, the latest developments, and answered widely concerned topics such as airdrop expectations and new opportunities in the DeFi field.
Share
PANews2024/07/03 13:00