On August 29, the team behind the L1 blockchain Fogo paused the mainnet and initiated a network upgrade after an unknown party acquired 400 million FOGO tokens, representing over 10% of the token's circulating supply.
In the last hour the Fogo Mainnet has been temporarily halted as a precautionary measure following the detection of unauthorized activity.
The halt is being initiated to prevent further movement of the affected assets. During the halt, the network will be upgraded to restrict…
— Fogo (@fogo) August 29, 2026
"The halt is being initiated to prevent further movement of the affected assets," the announcement stated.
The project indicated that the upgrade aims to limit addresses linked to the unauthorized activity, although no timeline for the restart was provided. The specifics of how these restrictions will function were also not disclosed by the team.
About 15 hours prior to the network's halt, Fogo Foundation reported a compromise within the organization, claiming that 400 million FOGO had been obtained by a "malicious actor." At that time, the Foundation asserted that the blockchain's functionality remained intact.
The project has not revealed details about the attack vector or which addresses were affected. The 400 million FOGO tokens represent 4% of the total genesis supply of 10 billion tokens and over 10% of the circulating market volume. According to CoinGecko, FOGO was trading at approximately $0.0075 at the time of the incident, valuing the compromised tokens at around $3 million.
Approximately one hour before the project's first public announcement, Bitget suspended deposits and withdrawals of FOGO, citing wallet maintenance. KuCoin later announced a similar measure, as noted by The Block.
The Fogo mainnet was launched in January 2026 following a $7 million token sale on Binance, which valued the project at $350 million. The project markets itself as a high-speed L1 blockchain designed for on-chain trading, featuring a block time of 40 milliseconds and reduced MEV impact.
It is worth noting that on August 25, Cosmos Labs called for a halt to networks utilizing the Cosmos EVM module due to ongoing attacks on three blockchains. The company later acknowledged that it had mistakenly assessed the vulnerability as not sufficiently dangerous.
