Fogo Halts Mainnet After Attacker Moves 400 Million FOGO Tokens in Wallet Breach

1 hour ago 2 sources negative

Key takeaways:

  • Fogo's halt exposes trade-off between network security and transaction finality for Layer 1s.
  • Bitget and KuCoin suspensions highlight exchanges' critical role in limiting attacker liquidity.
  • Governance of frozen tokens post-restart will be key test for Fogo's credibility.

Layer 1 blockchain Fogo abruptly halted its mainnet on Saturday after detecting unauthorized activity linked to a compromised wallet, with an unknown attacker transferring 400 million FOGO tokens — a move that escalated the project's response roughly 15 hours after the Fogo Foundation initially claimed the underlying network was unaffected.

The affected tokens represented approximately 4% of FOGO's 10 billion-token genesis supply and more than 10% of the token's circulating supply, worth around $3 million at the time of the incident, with FOGO trading near $0.0075. The Foundation announced the breach on X early Aug. 29, stating it had alerted cryptocurrency exchanges, law enforcement agencies, and forensic specialists.

The network pause was initiated to prevent further movement of the affected assets while validators upgraded the blockchain to restrict addresses connected to the unauthorized activity. Notably, the Foundation did not provide a restart time or explain precisely how those restrictions would be implemented. The halt marked a sharp reversal from the Foundation's initial assessment late Friday, in which it said an unknown actor had compromised the organization but insisted there was "no impact to the Fogo blockchain."

Centralized exchanges reacted swiftly. Bitget suspended FOGO deposits and withdrawals about an hour before the Foundation publicly disclosed the incident, describing the suspension as wallet maintenance. KuCoin later followed suit, suspending FOGO deposits and withdrawals as well. The cooperation of exchanges is critical because deposits linked to identified addresses can potentially be blocked before the tokens are converted or sold, limiting the attacker's ability to dump more than 10% of the circulating supply onto the market.

The incident raises broader questions about transaction finality and the degree of control validators can exercise during security emergencies. Freezing attacker-controlled assets can limit losses and improve recovery chances, but it also tests the governance model of a Layer 1 blockchain that has marketed itself as infrastructure for high-speed onchain trading, targeting block times of around 40 milliseconds. The shutdown ends Fogo's claimed 100% uptime record since its mainnet launch in January, which followed a $7 million Binance token sale at a $350 million valuation.

The Foundation has not disclosed how the compromise occurred, which wallets or systems were affected, or whether the attacker gained access to private keys or internal infrastructure. Holders are left watching for the mainnet restart, the fate of the frozen tokens, and whether additional assets remain exposed.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.