Security Incident Update
Following the initial blog post regarding the security incident affecting the SKALE IMA Bridge, the SKALE team has continued its investigation into the incident, worked with affected infrastructure providers and ecosystem partners, and conducted a comprehensive review of the affected systems.
This update provides the current high-level findings and remediation actions. The investigation and recovery efforts remain ongoing, and additional technical details will be shared once they have been sufficiently verified.
On August 27 at approximately 9:00 PM UTC, infrastructure providers running validator nodes in the SKALE Network were compromised and the SKALE IMA Bridge was exploited. The attacker was able to drain ERC-20 assets held within the affected bridge infrastructure.
The SKALE team immediately began investigating the incident and working with affected parties to assess the full impact and trace the movement of assets. The affected bridge functionality remains paused.
The incident was contained to the IMA Bridge infrastructure associated with SKALE on Ethereum. SKALE on Base was not affected. SKALE on Base operates as a separate deployment with its own infrastructure and architecture, and applications and functionality running on SKALE on Base continue to operate normally.
The SKL token on Ethereum and staked SKL were also not affected. The impact was limited to assets held within the affected bridge infrastructure.
The team continues to work with authorities and relevant ecosystem partners in major jurisdictions to support efforts to freeze and potentially recover affected funds and pursue appropriate action.
Our investigation has identified the initial entry point as externally accessible infrastructure ports on a subset of affected validator nodes that were intended to remain restricted.
Certain internal services on these nodes were reachable from outside the validator environment due to insufficient network restrictions. This exposed internal functionality that should not have been accessible from the public internet and allowed the attacker to interact with privileged node services.
On the affected nodes with externally accessible ports, the investigation also identified unauthorized activity involving node wallets, resulting in the transfer of funds from certain validator node wallets. This appears to have been used as a parallel attack path in addition to the exploitation of internal services.
Based on the evidence reviewed to date, the incident was primarily enabled by insufficient network isolation of internal node services and the resulting exposure of privileged functionality.
The investigation remains ongoing, and we are continuing to review infrastructure configurations, service interactions, logs, and on-chain activity to establish the full scope and sequence of events.
The affected functionality was limited to the infrastructure associated with the IMA Bridge and the validator nodes involved in the incident.
The investigation has identified multiple affected ERC-20 assets and unauthorized transfers associated with the incident. The exact impact continues to be reconciled against on-chain activity and infrastructure evidence.
The complete list of affected assets, wallets, transactions, and any final loss figures remains subject to the ongoing investigation by the relevant authorities and applicable jurisdictional requirements.
At this stage, we are not publishing preliminary or partially reconciled figures, as the investigation and reconciliation process remains ongoing and the information may be subject to further verification, revision, or restrictions on disclosure.
Following identification of the attack path, the SKALE core team initiated a number of immediate and long-term security measures.
The SKALE core team communicated with validators to ensure that internal service ports are properly restricted and not exposed to the public internet.
This included:
- Verifying firewall configurations across relevant validator infrastructure.
- Performing checks of relevant network ports to identify unauthorized external access.
- Reinforcing the requirement that internal service interfaces remain accessible only from trusted network contexts.
- Reviewing validator networking configurations for unintended external exposure.
For validator nodes that may have been exposed, operators were instructed to preserve relevant logs and other forensic evidence before performing cleanup, restarting services, or making configuration changes.
This is supporting the ongoing investigation and helping ensure that the attack path and scope can be reconstructed accurately.
The SKALE core team has rolled out a new skale-node version across the validator network that includes additional security enhancements and changes addressing the conditions identified during the investigation.
The updated components are being reviewed as part of the broader security assessment before the affected bridge functionality is restored.
The SKALE team has conducted several comprehensive internal security reviews covering the affected infrastructure and all system components.
These reviews are part of a broader assessment of the security posture of the SKALE network and are not limited to the specific entry point identified in this incident. The audits examine system architecture, component configurations, network exposure, access controls, authentication and authorization mechanisms, inter-service communication, and other areas that could present security risks.
The objective is to identify and address potential vulnerabilities and areas for security improvement across all components, with particular attention to protecting privileged system functionality and reducing the potential impact of unauthorized access or compromise.
The SKALE core team is strengthening monitoring and detection capabilities across the relevant infrastructure as part of the broader security improvements.
The goal is to improve the ability to identify potential security events, anomalous activity, and other indicators of compromise at an earlier stage, enabling faster investigation and response.
Additional monitoring and detection controls are being developed, including the use of AI-based monitoring agents to support continuous analysis and assist with the identification of potential security issues. These capabilities are being introduced as part of the ongoing security improvement efforts.
The affected bridge remains paused while the investigation, remediation, and security review continue.
The SKALE team continues to work with affected parties, exchanges, security partners, and authorities to trace affected assets and support recovery efforts.
If you were affected and have not yet filled out the submission form, please do so here.
We will provide additional updates as material developments are confirmed.
Security remains a fundamental priority for SKALE.
This incident has reinforced the importance of strict network isolation, defense-in-depth controls, least-privilege access, and continuous monitoring across validator and bridge infrastructure.
We are using the findings from this incident to strengthen the affected infrastructure and review security controls across the broader system.
We will continue to share additional findings as they are verified and will provide further updates on the recovery process, security improvements, and the status of the IMA Bridge.



