Stolen funds enter privacy blender
Nearly $6.2 million from the SagaEVM exploit was transferred to Tornado Cash, according to blockchain security firm CertiK. This is a common tactic used by hackers when they want to obscure transaction trails and make recovery of funds difficult or impossible.
The exploit occurred on January 21, targeting what Saga describes as an “L1 to launch L1s.” After confirming the attack, the team suspended the SagaEVM chain at block height 6593800. They stated that mitigation measures were underway and they were focused on finding a solution.
How the funds were moved
The CertiK report shows that the attackers first distributed the stolen assets across five separate wallets. Then they transferred everything to Tornado Cash via multiple transactions. The total stolen was almost $7 million in various assets – USDC, yUSD, ETH and tBTC – all transferred to the Ethereum mainnet.
The exploiter’s wallet was identified and shared with exchanges and bridges for blacklisting. But with $6.2 million now dedicated to privacy protection, recovery efforts face serious challenges. Tornado Cash does exactly what it was designed to do: help funds disappear.
What happened during the feat
According to a post-mortem shared on January 21, the incident involved coordinated contract deployments, cross-chain activity, and subsequent liquidity withdrawals. The team suspended the channel out of an abundance of caution during the investigation.
Their goal was to stop any further impact by keeping SagaEVM paused, validating the entire scope using archive data and execution traces, and hardening affected components before restarting. The main components affected were the SagaEVM chain, Colt and Mustang. Other parts such as the Saga SSC mainnet, protocol consensus, validator security, and other chains were not affected.
“There were no consensus failures, validator compromises, or signer key leaks,” the document states. “The wider Saga network remains structurally sound.”
Root Cause and Next Steps
With support from Cosmos Labs engineers, the team traced the issue back to the original Ethermint codebase. So this was a legacy vulnerability, not something new introduced.
Cosmos Labs acknowledged the incident, saying it was working closely with Saga and external security partners to investigate and remediate the confirmed vulnerability. They contacted the EVM chains they considered affected and proposed short-term mitigation measures.
“As always, we recommend that all projects continue to implement basic security practices such as rate limiting and security monitoring to enhance early detection and mitigation,” they wrote on X.
The Saga team says its next steps include validating root causes, applying patches and hardening affected cross-chain and deployment components, coordinating with ecosystem partners, and publishing a more comprehensive technical postmortem.
Meanwhile, the latest filing adds to the complicated history of Tornado Cash, a tool with legitimate privacy uses that has also become a favorite of hackers trying to launder stolen funds after exploits.
![]()



