Attempted Theft on Energy Web X, Blocked
Published: September 2, 2026 (UTC)
Incident awareness date: August 17, 2026
On 17 August an attacker exploited a vulnerability in an upstream dependency to credit
tokens to their own account on Energy Web X, then tried to withdraw them. The withdrawal
was blocked before it could execute. Nothing left the network.
What happened
A signature validation flaw in a runtime module allowed ten forged validator attestations to be accepted. The runtime credited 70,080,500 EWT to an account the attacker controlled, against a deposit that had never occurred.
To realise anything, the attacker had to move the tokens to Ethereum, where EWT trades as an ERC-20 and where the only market for it exists. Energy Web X is not connected to any exchange, so a balance credited there cannot be sold. They queued a withdrawal across the bridge, which carries a mandatory delay. That route was closed before the withdrawal could have executed. It is recorded on chain as never claimed and never finalised.
What was not affected
No tokens left Energy Web X. No holder lost their own funds. The ERC-20 supply on Ethereum was not touched and no EWT was released from the bridge reserve. All credited balances were reversed the same evening and total supply on Energy Web X is back to its pre-incident level. Block production continued throughout and no enterprise deployment was disrupted.
Service
Public RPC access, transfers and bridge operations were suspended as precautionary measures, then restored in stages with verification at each step.
All services are now operational: RPC, transfers, bridging and cross-chain messaging.
Cause
The flaw was in the module that validates bridge attestations, one component that Energy Web X inherits from the Aventus parachain implementation. It predates our adoption of that component and is confined to it. The fix was verified two independent ways before release.
One platform constraint is worth noting for others building on Polkadot. A relay chain cooldown governs how quickly a parachain can apply runtime upgrades: roughly an hour for the first, and around a day before another can follow. It cannot be shortened, so a parachain response has to work without a runtime lever for that period.
Remediation
The signature validation flaw is fixed and deployed. The mandatory delay on outbound withdrawals has been widened as a precaution.
— Energy Web Team

Earlier this week, on
February 3, 2026, Energy Web
became aware of a security incident involving an
unauthorized change to front-end routing for
energywebx.com. For a brief period, this may have caused some visitors to be
redirected away from the intended Energy Web X interface. What we can confirm (as of the publication date above) The unauthorized routing change was
reverted promptly, and
containment measures were implemented immediately.The incident was
limited to the website front-end routing layer. Core Energy Web applications and services
remained operational, although some users may have experienced
unintended redirects.
Based on our review to date, there is
no evidence that
back-end services, protocol infrastructure, smart contracts, or on-chain components were compromised. Verification and monitoring activities are ongoing.
- We have no evidence at this time of user funds being lost as a result of this incident, and we have not received verified reports of loss attributable to it.
- energywebx.com is operating normally again. We continue heightened monitoring and are implementing additional standard security hardening measures.
Safety reminder (especially for staking & bridging)
Always double-check the domain before connecting your wallet or approving any transaction — phishing pages often use look-alike URLs.
- Use only official links shared via Energy Web channels, and bookmark the correct site once verified.
- Never share your seed phrase or private keys — Energy Web support will never ask for them.
If you believe you may have interacted with an unintended page, please contact us via
info@energyweb.org and include any relevant details (e.g., wallet address and transaction hash, if applicable).
— Energy Web Team