On August 29, the team behind the L1 blockchain Fogo was forced to urgently halt the mainnet and initiate a network upgrade. The reason was the unauthorized acquisition by an unknown party of 400 million FOGO tokens, which constitutes more than 10% of the asset's circulating supply. This event dealt a serious blow to trust in the project, which positions itself as a high-speed platform for on-chain trading.
Incident details and response measures
The network halt was undertaken as a preventive measure to block further movement of the compromised funds. The project's official statement emphasizes that the upgrade is aimed at restricting addresses associated with suspicious activity. However, the team has not disclosed either the exact timeline for the restart or the mechanisms that will be applied to restrict access.
Notably, approximately 15 hours before the halt, the Fogo Foundation had already reported the compromise of the organization, claiming that 400 million FOGO had moved to a "bad-faith party." At that time, the foundation assured that the blockchain's operation was not disrupted, but subsequent events proved otherwise. The attack vector and affected addresses remain unknown, raising additional questions about the project's security level.
Market consequences and exchange reactions
At the time of the incident, FOGO was trading at around $0.0075, valuing the stolen package at approximately $3 million. This is a significant amount for a project that raised $7 million during its token sale on Binance in January 2026 at a valuation of $350 million. Exchanges reacted immediately: Bitget suspended FOGO deposits and withdrawals about an hour before the official announcement, citing wallet maintenance. Later, KuCoin took similar measures, indicating coordination between the platforms.
It is important to note that this is not the first case of attacks on blockchains using the Cosmos EVM module. Earlier, on August 25, Cosmos Labs had already called for suspending the operation of such networks after a series of incidents, but later admitted that it had underestimated the degree of vulnerability. The current situation with Fogo confirms that problems in the Cosmos ecosystem remain unresolved.
My analysis: This incident highlights systemic risks for young L1 projects, which often sacrifice security for speed and marketing. Halting the mainnet is an extreme measure that, while protecting funds, causes long-term reputational damage. Investors should reconsider their approach to evaluating such assets, prioritizing code audits and team transparency over merely stated technical characteristics.