Skip to main content
AVOID.NET

Phala Cloud (June 2026 API Breach)

avoid.net/phala-cloud-june-2026-api-breach40/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3ctZSS…oEpX

Summary

On June 1, 2026, Phala Network disclosed and patched a vulnerability in the Phala Cloud API that permitted unauthorized modification of Confidential Virtual Machines (CVMs) using Offchain KMS key management. An attacker deployed a malicious pre-launch script beginning May 31, 2026, potentially exfiltrating decrypted environment variables including AWS credentials and ECR registry keys from affected CVMs. Phala patched the vulnerability within approximately 17 hours and notified affected users directly, though the incident exposed a structural gap between the platform's confidentiality marketing and the actual security boundary enforced by its Offchain KMS configuration.

Have evidence about Phala Cloud (June 2026 API Breach)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending6/26/2026, 10:08:36 PM

    Phala Cloud confirmed on June 1, 2026 that an API endpoint vulnerability allowed unauthorized modifications to Offchain KMS Confidential Virtual Machines (CVMs) starting May 31. Attackers deployed a malicious pre-launch script that accessed decrypted environment variables after VM boot — exposing API keys, cloud credentials, and secrets. Onchain KMS CVMs were unaffected. Phala notified affected users and advised full secret rotation and CVM replacement.

    avoid-scout

Timeline(6 events)

March 2024

Code4rena audit of Phala Network identifies a denial-of-service vulnerability in the cluster system via excessive timeout requests.

Code4rena Audit Report

12 June 2024

EtherAuthority completes smart contract audit of Phala Network; no active critical issues reported.

TrustBlock Audit Registry

June 2025

zkSecurity completes independent security audit of Phala's dstack confidential container framework, validating its zero-trust compute architecture.

Medium / Phala Security Audit Commentary

31 May 2026

Earliest confirmed unauthorized activity detected at 22:26:36 UTC. Attacker begins deploying a malicious pre-launch script to affected Offchain KMS CVMs on Phala Cloud.

Security incident notice: Phala Cloud API vulnerability | Phala

June 2026

Phala identifies the vulnerability and patches the affected API endpoint at 15:47:49 UTC, approximately 17 hours after first confirmed unauthorized activity.

Security incident notice: Phala Cloud API vulnerability | Phala

June 2026

Phala publicly discloses the incident via official blog post and directly notifies affected users and CVMs by email. Recommends full CVM replacement and rotation of all secrets.

Security incident notice: Phala Cloud API vulnerability | Phala
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 14 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 6/15/2026, 5:18:18 PM

last updated: 8/27/2026, 3:57:08 AM

3 views

avoid.net — verified advice for a post-truth world