Ontology has brought its mainnet back online after an emergency security pause triggered by malicious activity, and is now directing all sync-node operators to upgrade to version 3.1.5 as soon as possible. The restoration was announced on September 2, 2026, marking a shift from containment to recovery. Operators must follow the official upgrade instructions, confirm full synchronization with mainnet, and verify normal node operation after applying the patch.
The incident began on August 31, when Ontology paused block production following what it initially called a potential security concern discovered during a daily security check. That suspension left on-chain transactions unprocessed. On September 1, the project escalated its description, saying it had identified malicious attack activity targeting the network while remediation, testing, and a network upgrade were already underway. During the pause, users were told not to attempt time-sensitive transactions and that they did not need to move ONT, ONG, or other assets. Ontology also said its investigation found the activity did not involve or compromise user assets, although no independent forensic report has been published.
The v3.1.5 release provides a Linux AMD64 binary and checksum but no incident explanation. The tagged code change disables registrations for several legacy native contracts at mainnet block 20,770,894, one block after the height 20,770,893 observed during the halt. Its parent commit changes cross-chain message deserialization. While the public code shows the shape of the emergency software change, Ontology has not linked either commit to a specific attack path, identified the vulnerability or attacker method, named the affected component, or provided a postmortem.
The restoration announcement confirms the mainnet's return, not a service-by-service recovery across the wider ecosystem. It does not yet establish whether public RPC providers, exchange deposits and withdrawals, wallets, or dapps have all resumed normal operation. Ontology said it will continue monitoring network security, stability, and performance while coordinating with technical and security partners on longer-term reliability. For now, v3.1.5 tells operators what they must do, while the reason for the emergency change remains undisclosed.