Vana Foundation

Statement on the 31 July L1 Deposit Contract Incident

Current status: Contained

At 02:34 UTC on 31 July 2026, 1,120,000 VANA was moved without authorisation from Vana’s L1 validator deposit contract. We are publishing this statement to set out the facts, what was and was not affected, and the actions already taken. Every on-chain claim in this statement can be independently verified.

Current status

Contained. The affected legacy key has been retired, all remaining privileged Vana mainnet access has been migrated to multisig control, and the Foundation states that this mechanism cannot be repeated.

Timeline

  • 02:34 UTC, 31 July 2026: The full 1,120,000 VANA balance was moved from the L1 validator deposit contract in one transaction.
  • Over the following approximately 80 minutes: The funds were bridged to Base and Ethereum. Roughly 905,000 VANA was sold into on-chain liquidity; the remainder entered third-party cross-chain routing services.
  • After detection: The legacy key was retired, remaining privileged mainnet access was migrated to multisig, and relevant authorities and ecosystem partners were notified.

What happened

The L1 validator deposit contract held security deposits from certain validator operators. The contract was controlled by a legacy administrative key that predated our current multisig governance structure.

As part of routine security upgrades, the Vana Foundation was auditing and migrating contracts from legacy single-key control to multisig. This contract had not been migrated. The legacy key was used to authorise a contract upgrade that transferred out the full balance in a single transaction.

Over the following ~80 minutes, the funds were bridged to Base and Ethereum, where the majority — roughly 905,000 VANA — was sold into on-chain liquidity. The remainder was moved into third-party cross-chain routing services and is being traced.

Origin transaction (Vana mainnet): 0x95e9c26e01a35ab939b3442a89048b356f887d132b7afa13550e41a61cb86eb5

Claim and evidence ledger

Claim IDCurrent claimStatusEvidence
C-01At 02:34 UTC on 31 July 2026, 1,120,000 VANA left the L1 validator deposit contract.ConfirmedOrigin transaction
C-02The transfer used a legacy administrative key rather than a smart-contract vulnerability.Foundation statementThis incident dossier
C-03The Foundation treasury, locked tokens, circulating supply, and community funds were not affected.Foundation statementThis incident dossier
C-04The affected key was retired and remaining privileged Vana mainnet access was migrated to multisig control.Foundation statementThis incident dossier

What this was and was not

This was the unauthorised use of a legacy admin key. It was not a protocol exploit. No smart-contract vulnerability was involved. The deposit contract's access controls functioned exactly as written, and the LayerZero bridge also functioned as designed and was not compromised. The Vana network itself was not attacked and continues to operate normally.

This was not a treasury breach. All Vana Foundation treasury wallets are held with a qualified custodian and were not accessed. The Foundation treasury and any locked tokens were not affected.

There was no increase in circulating supply. No new VANA was minted or created. Total supply is unchanged.

No community funds were lost. No user, data contributor, or member of the public lost funds.

Containment

Since detection, our operations, finance, and engineering teams have completed the key-hardening work that was in progress:

  • The issue was isolated to a single legacy administrative key. That key has been fully retired.
  • All remaining privileged access across Vana mainnet has been migrated to multisig control and verified on-chain.
  • The loss is capped at the 1,120,000 VANA already taken. There is no remaining path for this mechanism to be repeated.

Investigation and next steps

The Vana Foundation takes incidents of this nature extremely seriously. We are cooperating with the relevant authorities. Exchanges, market makers, and bridging partners have been notified and are monitoring for movement of the funds.

The network remains fully operational and secure, and we are always working to strengthen the security of the network.

Please direct any security issues to security@vanafoundation.org.

Corrections and revisions

No substantive corrections have been published. Future substantive changes will retain the original publication date, show a new last-updated date, and be recorded in the visible revision history.