0G Foundation: Contract attacked, 520,000 0G stolen The 0G Foundation announced on X that on December 11, a targeted attack compromised their rewards contract. The attacker exploited the emergency withdrawal function of the 0G rewards contract used for distributing alliance rewards, stealing 520,010 0G tokens, which were subsequently bridged and dispersed via Tornado Cash. The attacker obtained a private key leaked from an Alibaba Cloud instance responsible for managing NFT status and reward updates, storing the private key locally. Due to a serious vulnerability in Next.js (CVE-2025-66478) being exploited on December 5, multiple Alibaba Cloud instances were compromised. The attacker moved laterally through internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, computing, Aiverse, Perpdex, Ascend, and others. Confirmed total losses: 520,010 0G, 9.93 ETH, and $4,200 USDT. Aside from the reward distribution contract, core chain infrastructure and user funds remain unaffected. $0G
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
What a tumultuous autumn.
0G Foundation: Contract attacked, 520,000 0G stolen
The 0G Foundation announced on X that on December 11, a targeted attack compromised their rewards contract.
The attacker exploited the emergency withdrawal function of the 0G rewards contract used for distributing alliance rewards, stealing 520,010 0G tokens, which were subsequently bridged and dispersed via Tornado Cash.
The attacker obtained a private key leaked from an Alibaba Cloud instance responsible for managing NFT status and reward updates, storing the private key locally.
Due to a serious vulnerability in Next.js (CVE-2025-66478) being exploited on December 5, multiple Alibaba Cloud instances were compromised. The attacker moved laterally through internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, computing, Aiverse, Perpdex, Ascend, and others.
Confirmed total losses: 520,010 0G, 9.93 ETH, and $4,200 USDT. Aside from the reward distribution contract, core chain infrastructure and user funds remain unaffected. $0G