0G Foundation: Contract Attacked, Resulting in the Theft of 520,000 $0G
According to ChainCatcher, 0G Foundation posted on X that a targeted attack compromised its rewards contract. The attacker exploited the emergency withdrawal function of the 0G rewards contract, which is used to distribute alliance rewards, and stole 520,010 $0G tokens. These tokens were subsequently bridged and dispersed via Tornado Cash.
The attacker obtained a leaked private key from an Alibaba Cloud instance responsible for managing NFT status and rewards updates, with the private key stored locally. Due to a critical vulnerability in Next.js (CVE-2025-66478) that was exploited on December 5, multiple Alibaba Cloud instances were breached. The attacker moved laterally through internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, computing, Aiverse, Perpdex, Ascend, and others. The confirmed total losses are: 520,010 $0G, 9.93 ETH, and 4,200 USDT. Aside from the rewards distribution contract, neither the core chain infrastructure nor user funds were affected.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Citibank says US midterm elections have limited overall impact on the S&P 500 Index
Meta is expected to launch two camera-free smart glasses to address privacy concerns
Wells Fargo lowers Micron Technology's target price to $1,400.
Citi raises Micron Technology's target price to 1,300 USD.
