The team behind the Layer-1 blockchain Fogo was forced to urgently halt its mainnet operations. The cause is unauthorized activity that resulted in an unknown address receiving 400 million FOGO tokens. This is a significant blow to the project: the seized amount exceeds 10% of the total coins in circulation on the market.

The network halt is a preventive measure aimed at freezing the movement of compromised assets. In parallel, the team has initiated an urgent protocol update designed to restrict addresses involved in the incident. Exact timelines for resuming blockchain operations have not yet been announced, nor has the mechanics of future restrictions.

Timeline of the incident

Notably, approximately 15 hours before the network halt, the Fogo Foundation had already reported the compromise of the organization. At that time, the foundation stated that 400 million FOGO had ended up with an "unscrupulous party," but assured that blockchain operations were not disrupted. However, as subsequent events showed, the situation turned out to be more serious than initially assumed.

Currently, the project has not disclosed the attack vector or published a list of affected addresses. All that is known is that the stolen 400 million FOGO constitutes 4% of the genesis supply of 10 billion tokens. At the time of the incident, the price of FOGO was fluctuating around $0.0075, valuing the stolen package at approximately $3 million.

The reaction from exchanges was swift: even before the project's official announcement, Bitget suspended FOGO deposits and withdrawals, citing technical work on the wallet. Following suit, KuCoin took similar measures.

Context and prospects

It is worth recalling that the Fogo mainnet was launched in January 2026 after a successful token sale on Binance, which raised $7 million at a project valuation of $350 million. Fogo positions itself as a high-speed L1 blockchain for on-chain trading, offering a block time of just 40 ms and reduced MEV impact. The incident calls into question the network's claimed resilience.

This case once again raises the issue of security within the Cosmos ecosystem and EVM-compatible networks. Earlier, on August 25, Cosmos Labs had already called for suspending network operations following a series of attacks on three blockchains, and later admitted it had underestimated the danger of the vulnerability. Now we see further confirmation that the problem is systemic in nature, rather than isolated attacks.

My comment: Halting a mainnet is always a last-resort measure that undermines trust in a project's decentralization. Even if the team manages to successfully carry out the update and bring the network back online, reputational losses could be irreversible. Investors should be extremely cautious with assets whose networks can be halted unilaterally—this contradicts the very philosophy of blockchain.