Incident case file
Sign in to watchStartale ERC-7579 Transient Storage Initialization Flaw — $2,876
Incident date Sep 15, 2026Last updated Sep 24, 2026
1 views
ContainedEthereumSoneiumTransient storage re-initialization flawCluster: STARTALE-ETH-2026-09
Estimated loss
$2.9K
Affected users
Number of affected users is not confirmed
Group joining is coming soon.
Investigation
60%
Facts and investigation
Ledger
Attacker
TODO
Funds moved to
TODO — no attacker address publicly disclosed.
Linked
Approximately 330 counterfactual (pre-funded, not-yet-deployed) smart accounts were affected. The Soneium network itself, co-founded by Startale Group and Sony Group, was not affected.
Chronology
1 beatOn September 16, 2026, an attacker exploited a flaw in Startale's ERC-7579 smart account infrastructure. An initialization flag stored in transient storage persisted across the entire transaction rather than being properly scoped, allowing an attacker to trigger re-initialization with a malicious bootstrap configuration. This let the attacker drain approximately 330 counterfactual (pre-funded but not yet deployed) smart accounts for a total of $2,876. The underlying Soneium network — co-founded by Startale Group and Sony Group — was not itself affected.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)