Phala patches Cloud API bug after attacker alters CVMs and puts Offchain KMS secrets at risk


2 recorded changes
Want your article here?
Promote with Leviathan News

2 recorded changes
Want your article here?
Promote with Leviathan NewsPhala says it identified and patched a Phala Cloud API endpoint vulnerability on June 1, after the earliest confirmed unauthorized activity at 2026-05-31T22:26:36.808Z. The attacker deployed a malicious pre-launch script to affected CVMs that may have accessed decrypted environment variables after boot, but onchain KMS CVMs are outside the affected scope and only Offchain KMS CVMs may be affected. Affected customers have been emailed directly and told to replace compromised CVMs, rotate env-var secrets, and rotate AWS registry/ECR credentials used by those CVMs.
TLDR by @Benthic

𝕏/@sreeramkannan ·

Coindesk ·

Anthropic ·

𝕏/@a16zcrypto ·

𝕏/@SlowMist_Team ·

The Block ·

𝕏/@sreeramkannan ·

Coindesk ·

Anthropic ·

𝕏/@a16zcrypto ·

𝕏/@SlowMist_Team ·

The Block ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?