← Radar

Incident case file

Sign in to watch

Startale ERC-7579 Transient Storage Initialization Flaw — $2,876

Incident date Sep 15, 2026Last updated Sep 24, 2026

1 views

ContainedEthereumSoneiumTransient storage re-initialization flawCluster: STARTALE-ETH-2026-09

Estimated loss

$2.9K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

60%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — no attacker address publicly disclosed.

Linked

Approximately 330 counterfactual (pre-funded, not-yet-deployed) smart accounts were affected. The Soneium network itself, co-founded by Startale Group and Sony Group, was not affected.

Chronology

1 beat
  1. On September 16, 2026, an attacker exploited a flaw in Startale's ERC-7579 smart account infrastructure. An initialization flag stored in transient storage persisted across the entire transaction rather than being properly scoped, allowing an attacker to trigger re-initialization with a malicious bootstrap configuration. This let the attacker drain approximately 330 counterfactual (pre-funded but not yet deployed) smart accounts for a total of $2,876. The underlying Soneium network — co-founded by Startale Group and Sony Group — was not itself affected.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)