On August 29, the team of the L1 blockchain Fogo made an emergency decision to halt the mainnet and initiate a network upgrade. The reason is unauthorized access, as a result of which an unknown party obtained 400 million FOGO, exceeding 10% of the current circulating supply of the token.
The project's official statement emphasizes that the halt is preventive in nature and aims to block further movement of the compromised assets. As part of the upgrade, restrictions are planned for addresses associated with suspicious activity, but the specific implementation mechanisms and timelines for resuming network operations have not yet been disclosed.
Timeline of the incident
Notably, approximately 15 hours before the network halt, the Fogo Foundation had already reported the compromise of the organization, claiming that 400 million FOGO had moved to an "unscrupulous party." At that time, the foundation stated that the blockchain's operation was not disrupted, but subsequent events refuted this optimistic scenario.
The scale of losses is significant: the stolen 400 million FOGO constitutes 4% of the genesis supply of 10 billion tokens and more than 10% of the circulating volume. At the time of the attack, FOGO was trading around $0.0075, valuing the stolen package at approximately $3 million. Meanwhile, the attack vector and the specific affected addresses remain unknown.
Exchange reaction and context
Exchanges responded immediately: Bitget suspended deposits and withdrawals of FOGO about an hour before the project's public announcement, citing wallet maintenance. Later, KuCoin took similar measures. This indicates that information about the incident spread faster than official statements.
It is worth recalling that the Fogo mainnet was launched in January 2026 after a successful token sale on Binance, which raised $7 million at a valuation of $350 million. The project positions itself as a high-speed L1 blockchain for on-chain trading with a block time of 40 ms and reduced MEV impact. This incident calls into question the platform's claimed reliability.
It should be noted that on August 25, Cosmos Labs had already called for suspending operations of networks based on the Cosmos EVM module after a series of attacks on three blockchains. Later, the company admitted that it had underestimated the severity of the vulnerability. The current case with Fogo is likely related to the same issue, which heightens community concerns about the security of L1 solutions.
Expert opinion: This incident is a warning signal for the entire L1 blockchain sector. Halting the mainnet, even temporarily, undermines investor and user trust in decentralized systems. I recommend that projects review their security protocols and incident response mechanisms to minimize such risks in the future.