Search the site
Press ESC to close
LIVE
Loading...
Updating...

SOON Mainnet Resumes Operations Following Infrastructure Security Breach

Wei Liang Mo
Fact-checked
2 min read
393 words
Share

The Layer 2 scaling solution SOON has announced the full restoration of its mainnet services following a temporary suspension triggered by a security incident. The disruption, which began on July 12, 2026, led to the immediate halting of the network's sequencer and associated operational environments. According to the project's development team, the breach was localized to infrastructure configurations rather than the underlying blockchain protocol, ensuring that user assets remained secure throughout the recovery process.

Root Cause and Response Measures

A technical post-mortem revealed that the incident originated from configuration errors and permission management flaws within the operational infrastructure. These vulnerabilities allowed external attackers to gain unauthorized access to specific services. However, the team emphasized that the core components of the ecosystem remained intact.

  • The sequencer and consensus mechanism were not compromised.
  • No vulnerabilities were discovered within user smart contracts.
  • Protocol-level security remained resilient against the intrusion.

In response to the threat, the SOON team initiated a comprehensive security overhaul. This included the replacement of all affected credentials and the complete rebuilding of infrastructure components to reinforce the network against future exploits. To ensure transparency and technical integrity, the project engaged the cybersecurity firm BlockSec to conduct an independent third-party review of the environment.

Restoration Timeline and Network Status

The recovery of the SOON ecosystem was executed in phases to ensure stability. On July 21, the platform successfully restored NFT minting and token claiming functions, allowing users to interact with their digital assets. The final stage of the recovery concluded on July 27, when mainnet RPC services and block production returned to standard operating parameters.

The incident originated from configuration errors and permission management issues in the operational infrastructure. External attackers gained unauthorized access through misconfigured services, but no protocol vulnerabilities were involved.

Remote Procedure Call (RPC) services are essential for allowing decentralized applications (dApps) and wallets to communicate with the blockchain, making their restoration a critical milestone for network usability.

The successful resolution of this incident highlights the importance of robust DevOps practices and infrastructure security in the decentralized finance (DeFi) space. While the suspension of the sequencer caused a temporary halt in transaction processing, the proactive involvement of security experts like BlockSec suggests a commitment to long-term network resilience. As of July 28, all systems are reported to be functioning normally, with no further threats detected.

Frequently Asked Questions

Quick answers to the most common questions about this topic.