Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$80,321▼ 1.14%ETH$2,573▼ 2.61%SOL$108.17▼ 3.20%TOTAL CRYPTO$2.73T▼ 4.95%S&P 5007,650.50▼ 0.54%NASDAQ26,522.55▲ 0.89%DOW51,682.64▼ 3.11%GOLD4,424.90▼ 3.20%WTI96.08▲ 9.39%BRENT99.29▲ 5.88%EUR/USD1.1490▼ 0.80%USD/JPY156.86▼ 1.56%DXY100.22▲ 1.33%
Crypto

MultiversX Halts Mainnet After VM Layer Exploit

MultiversX stopped its mainnet on Sept 20 after attackers used an atomicity bug at the virtual machine layer. A fix is being tested in a shadow fork.

Pexels – DS stories

MultiversX has halted its mainnet after confirming that attackers exploited an atomicity vulnerability at the virtual machine layer, producing invalid state changes on the chain. The announcement came on September 20, roughly a day after the team first said it was investigating an unexplained issue on the live network.

The engineering team has prepared a fix and is validating it in a shadow fork environment. If the validation succeeds, the update will be coordinated with validators, exchanges and infrastructure partners before deployment, according to reporting by Gate News, citing PANews.

The halt followed a vaguer statement on September 19, when MultiversX opened an investigation into a potential mainnet issue and promised an update within 12 hours. At that stage no exploit, interruption or loss of funds had been confirmed, and EGLD traded near $4.12. By the time the halt was announced, the price had slid further, with 24-hour losses of roughly 10% on some trackers.

Recovery plan targets invalid changes only

MultiversX is also evaluating a targeted recovery plan. The goal is to preserve finalized transaction history and legitimate user states while removing only the changes created by the exploit. The team has not yet said when the chain will restart or how long the shadow fork validation will take.

That wording matters for anyone with funds on the chain. A targeted recovery implies validators will reorganize state around the attack window, which can reverse legitimate transactions that happened to land in the same block range. MultiversX has not published figures for affected accounts or the value of the invalid changes, so the eventual scope is still unknown.

Exchanges pull the plug on deposits

KuCoin suspended EGLD deposits on September 19 at 18:20 UTC, citing essential maintenance. Other venues were expected to follow as the coordinated fix approaches. Exchanges typically freeze deposits on a halted chain to avoid crediting users for transactions that could later be rolled back or invalidated.

The incident resembles the Radix Network exploit reported a day earlier, on September 19. Radix validators halted that chain after an engine vulnerability let an attacker steal assets, according to Gate’s news feed. Two smart contract platforms taking emergency action within 24 hours of each other suggests a rough stretch for layer-1 security, though the two bugs are unrelated and sit in different layers of the stack.

What atomicity means here

An atomicity bug at the VM layer lets an attacker split what should be an all-or-nothing operation into partial effects. In practice that can mean a transfer or contract call that records one side of the transaction without the other, leaving state inconsistent with the ledger’s own rules. That is what MultiversX says produced the invalid state changes now being carved out of the chain.

Virtual machine attacks are harder to spot than contract-level bugs because the flaw lives in the interpreter that runs every contract on the chain, not in one application. A patch cannot simply disable a single token or contract. It has to change consensus rules, which is why the fix needs validator coordination and why the team is testing it away from the live network first.

A bad month for independent chains

The MultiversX halt is the third chain-level security event in under three weeks. Core DAO planned an emergency hard fork on September 2 after validators drew excess rewards from the network. BounceBit discontinued its own layer-1 in August after the theft of 286.5 million BB tokens and reissued the coin on the BNB Chain. And Harmony, hit by an exploit that minted nearly 4 billion unauthorized ONE tokens in August, proposed sunsetting its chain entirely on September 6 and migrating ONE to Ethereum as an ERC-20 token.

Harmony’s announcement is the starkest of the set. The team said the threats posed by state-sponsored hackers and AI agents had become too great to counter alone, and that operating independent validator infrastructure no longer made sense for a chain with roughly $10.7 million in market capitalization and $151,000 in decentralized finance activity. MultiversX is a much larger network, but the direction of the pressure is the same: paying for validators, audits and incident response gets harder as activity and capital drift toward bigger chains.

The AI angle is not decorative. Anthropic’s year-long study of 832 accounts banned for cybercrime found the share rated medium risk or higher rose from about 33% in the first half of the study to 56% in the second half. OpenAI has claimed its GPT-6 Astra model reached critical-level cybersecurity capabilities. Chain teams now write incident reports with model-driven attack discovery in mind, and Harmony cited the trend directly as a reason to stop running its own network.

What holders should watch

The next official update is expected once the shadow fork validation concludes. Users with funds in MultiversX smart contracts or liquidity pools face the same constraint seen in other chain recoveries: if validators reorganize state, transactions after the attack block could be reversed, including legitimate ones caught in the same window. Deposits and withdrawals on exchanges remain the safest signal of recovery, since venues usually wait for explicit all-clears before reopening them.

EGLD has fallen about 14% over the past week, a slide that began before the exploit was disclosed, and the token is down roughly 75% from a year ago. MultiversX, formerly Elrond, was one of the headline performers of the 2021 bull market before the rebrand and the long decline that followed. The halt lands on a market that had already been shrinking, and the eventual recovery plan will show how much history the team can protect without splitting the chain into two competing ledgers.

MultiversX has asked users to rely on its official channels for the coordinated deployment schedule. Until then, deposits on major exchanges stay closed and the chain itself remains stopped, a rare full stop for a top-100 network.

SourcesGate News (Sept 20); KuCoin announcement (Sept 19); crypto.news; Cointelegraph (Harmony coverage, Sept 7).
Share: X