Fogo, a Layer 1 blockchain built around the Solana Virtual Machine, temporarily stopped mainnet activity after a security incident involving the project’s foundation. An unknown party gained access to foundation-controlled holdings and moved 400 million FOGO tokens to an external address.
The transfer represents about 4 percent of the 10 billion token genesis supply and more than 10 percent of tokens then circulating, a much larger share of immediately tradable supply than of the full allocation.
In the last hour the Fogo Mainnet has been temporarily halted as a precautionary measure following the detection of unauthorized activity.
The halt is being initiated to prevent further movement of the affected assets. During the halt, the network will be upgraded to restrict…
— Fogo (@fogo) August 29, 2026
At prices near $0.0075 around the time of the disclosure, the tokens were worth roughly $3 million.
The first public notice came late Friday.
The Fogo Foundation said an unidentified actor had compromised the organization and sent the tokens to a “bad actor.”
It reported that trading venues, law enforcement, and forensic investigators had already been contacted.
At that stage the foundation insisted the chain itself was still producing blocks and processing transactions as usual.
That framing treated the event as an organizational and wallet problem rather than a failure of consensus or core protocol code.
On Saturday the project announced that mainnet had been paused as a precaution.
The stated purpose was to stop any additional movement of the affected tokens while validators prepared a network upgrade that would restrict addresses tied to the incident.
No restart schedule was given, and the team did not spell out exactly how the address restrictions would be enforced.
Users were told to rely only on official channels for further information.
The sequence matters because it shows how quickly an off-chain compromise can force on-chain intervention.
Fogo had marketed itself as a low-latency network aimed at trading and real-time applications, with block times on the order of 40 milliseconds.
A Saturday halt ended an uptime record the project had previously highlighted.
Several exchanges, including Bitget and KuCoin, limited FOGO deposits and withdrawals around the same period, reducing the chance that stolen tokens could be sold quickly.
FOGO’s market price fell sharply after the news, with reports of declines in the high teens to about 20 percent.
Details that remain undisclosed are as important as what has been confirmed.
The foundation has not described the attack path, whether private keys or other internal systems were taken, or which specific wallets were involved.
It has also not said whether any of the 400 million tokens have been recovered or frozen.
That uncertainty leaves open questions about liquidity risk: a large block of circulating supply in an attacker’s hands can pressure markets even if the protocol’s code was never broken.
Fogo launched public mainnet earlier in 2026 after a strategic token sale and positioned the network as infrastructure for fast on-chain trading.
The incident is a reminder that foundation treasuries and operational security sit outside the consensus layer.
A chain can keep producing blocks while the organization that holds a large token allocation is breached.
Pausing the blockchain based network and planning address restrictions is an attempt to contain that mismatch. Whether the upgrade restores confidence will depend on how quickly validators ship it, how clearly the team explains the root cause, and whether crypto exchanges and investigators can limit further movement of the tokens.