The 0G Foundation announced on the X platform that a targeted attack compromised its rewards contract on December 11. Attackers exploited the emergency withdrawal function of the 0G rewards contract, used to distribute affiliate rewards, to steal 520,010 $0G tokens, which were subsequently bridged and distributed via Tornado Cash. The attackers also obtained a leaked private key from an Alibaba Cloud instance that managed NFT state and rewards updates and stored the private key locally. Multiple Alibaba Cloud instances were compromised due to a critical vulnerability (CVE-2025-66478) in Next.js that was exploited on December 5. The attackers moved laterally via internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, compute, Aiverse, Perpdex, Ascend, and other services. The confirmed total loss is 520,010 $0G, 9.93 ETH, and 4200 USDT. Apart from the reward distribution contract, neither the core chain infrastructure nor user funds were affected.