Chia Blog

Community Update: Security Context on Recent Ecosystem Incidents

by Chia Team

To the Chia Community,

First and foremost, the chia layer-1 blockchain is safe. Your XCH and the underlying network were never compromised. 

Recently, three independent ecosystem projects: warp.green, TibetSwap v2, and CircuitDAO; experienced security exploits. These incidents were isolated logic flaws in higher-layer Chialisp smart coins written by third-party teams.

Here is what happened and how Chia Network, Inc (Chia) responded.

What Happened

  • warp.green: Chia has partnered with the warp.green team to make affected users whole after an attacker exploited a logic bug in the chia-side smart coin puzzle for the ERC-20 bridge, forging CATs to drain bridged USDC on Ethereum/Base. The CAT bridge securing $XCH was unaffected.
  • TibetSwap v2: All non-bridged funds have been returned to their rightful owners and Tibetswap has been sunset after a critical bug in liquidity pool puzzles put user funds at risk. Chia engineers joined the TibetSwap team in a war room, building a custom rescue tool that successfully extracted most of the pool liquidity into a safe vault, the remainder was extracted by a white hat hacker who worked with the project team to send the assets back to the rightful owners.
  • CircuitDAO: The CircuitDAO protocol will be sunset and relaunched with plans to make affected users whole including issuing CRTv2 tokens to CRTv1 holders. An exploit targeted CircuitDAO’s savings vault puzzle, draining their on-chain treasury (roughly 1,000 BYC). The CircuitDAO team has confirmed that user deposit losses were minimal (around 26 BYC), all users will be reimbursed as the protocol is sunset and relaunched over the coming months.

Chia’s Support & Developer Security Resources

Building stateful smart coins on a UTXO/coin-set model offers massive security benefits, but higher-layer logic flaws remain an operational risk for application developers. Chia’s engineering and security personnel continue to provide direct assistance to affected project teams with threat tracing, puzzle analysis, and recovery workflows.

We strongly encourage all ecosystem developers to review the official security documentation on Chialisp.com:

  • Attacks and Countermeasures: Guidance on replay protection, CLVM DoS vectors, and puzzle validation rules.
  • Common Issues: Real-world Chialisp pitfalls, solution malleability, and coin ID length-checking vulnerabilities.

Thank you to the whitehats, developers, and community members who worked around the clock to contain damage and protect funds. Your efforts are greatly appreciated.


Updated 10/6/2026 for accuracy