SOON said it detected a security incident in its operating environment on July 12. According to Foresight News, an external attacker gained unauthorized access through a misconfigured service and later moved into part of its internal environment because of insufficient access controls.

The company said the incident was limited to off-chain operational infrastructure and did not affect the SOON protocol, sequencer, or any user-facing smart contract vulnerability. BlockSec’s investigation found no on-chain loss of user funds. SOON restored NFT minting and token claim functions on July 21, then resumed mainnet RPC services and restarted block production on July 27. The network is now operating normally.