aelf Restores Core Services After Emergency Shutdown; Exchange Access Varies by Platform
Key Takeaways
- •aelf's AELF MainChain and tDVV dAppChain resumed public full-node services on September 14, 2026, nearly a month after malicious smart-contract activity triggered an emergency shutdown.
- •An August 26 review tied 155 transactions to the malicious activity, split as 127 on AELF and 28 on tDVV, and found no unauthorized transfers or key exposure affecting ordinary-user wallets.
- •Block production stopped for about one week, meaning no network staking rewards were generated in that period and the missing payouts cannot be claimed by participants.
- •Operators with wallet keys or keystores stored on Block Producer nodes or operations environments were advised to rotate those credentials, though aelf noted this does not indicate the credentials were stolen.
- •Exchange deposits and withdrawals for ELF are resuming gradually with availability differing by venue, requiring holders to confirm each platform's live status, as illustrated by MEXC's requirement that users generate new deposit addresses.

aelf has restored its core blockchain services following an emergency shutdown, but the project cautioned that access through cryptocurrency exchanges still depends on each platform. While the network is running again, deposits and withdrawals are resuming gradually, and availability differs from one venue to the next.
Network back online after emergency shutdown
On September 14, 2026, aelf announced that its main network was back online, nearly a month after the project first disclosed the malicious activity behind the shutdown. According to aelf's recovery update, public full-node services for the AELF MainChain and the tDVV dAppChain — a companion chain that runs applications — were available again.
A full node is a computer that keeps a complete copy of the blockchain. While they were offline, and services built on aelf could not read or write data, making their restoration the first step back toward normal use.
Before reopening the network to the public, aelf said all Block Producers — the machines that create new blocks — had resumed work in an isolated test environment. Old producer addresses were replaced, and upgraded nodes passed functional testing before public access returned.
Shutdown followed a security incident
The emergency shutdown stemmed from a security incident. In an August 26 update, aelf said it had informed the community on August 18 about malicious smart-contract activity affecting both AELF and tDVV, and had then moved the network into controlled recovery. Smart contracts are automated programs that run on a blockchain.
That earlier review counted 155 transactions tied to the malicious activity, split as 127 on AELF and 28 on tDVV, plus five unique software payloads after removing duplicates.
What the restoration covers
The recovery update lists specific services that are working again: aelfscan block exploration (a tool for viewing on-chain activity), FairyVault normal transfers, Awaken trading, Forest NFT collection browsing, and the TMRW DAO staking interface.
aelf did not claim that every feature of every application has reopened. The named list is what has been confirmed; anything not on it should be treated as unconfirmed rather than assumed fully operational.
Staking rewards — the payouts a network distributes to users who commit tokens to it — are one clear gap. aelf said block production stopped for about one week, and no network staking rewards were generated during that period. The shortfall applies equally to all staking participants, meaning the missing rewards cannot be claimed.
For everyday holders, the August 26 review said it had found no unauthorized transfers or key exposure affecting ordinary-user wallets. That conclusion did not cover node and infrastructure credentials, which remained under investigation at the time.
aelf issued separate instructions for operators: a wallet key or keystore stored or used on a Block Producer node, node host, or operations environment should be treated as an operator credential and rotated, rather than handled as an ordinary-user wallet. The guidance is dated, and aelf noted it does not mean those credentials were stolen.
The project also said the full post-incident review and technical appendix will be released later, following completion of the investigation, recovery validation, credential fixes, permanent fixes, and an independent review. That forthcoming report is the document to watch for the incident's complete accounting; until it is published, the restoration is not a final security all-clear.
Exchange access varies by platform
The network's return does not mean every exchange has reopened ELF trading. aelf said exchange deposits and withdrawals were resuming gradually and that availability could differ by venue, urging users to check their own exchange's official announcements and enabled service status.
One example illustrates how venue rules differ. MEXC's September 5, 2026 notice scheduled ELF deposits and withdrawals to resume at 07:00 UTC that day, after a deposit-address update. The exchange required users to generate a new ELF deposit address and said older addresses were no longer valid. That, however, is an announced schedule rather than confirmation for any individual account.
Before moving funds, users should confirm on the exchange itself whether deposits, withdrawals, and trading are each enabled, as the three functions can reopen at different times. Exchange disruptions are not unique to aelf; the sector has seen venues pause or shut down, such as CoinEx winding down after nine years, which is why checking the specific platform matters more than any network-wide status.
Independent reporting has echoed the mixed picture. A September 15 CryptoSlate report said it observed reachable MainChain and tDVV status endpoints with advancing block heights, as well as reachable service front ends. The outlet did not, however, submit an end-to-end transfer, trade, or reward claim.
The practical takeaway for ELF holders is to treat the network recovery and their exchange access as two separate checks. Only an exchange's live notice confirms whether deposits or withdrawals can actually be made at a given moment.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Source: CoinLineup — https://coinlineup.com/aelf-core-restored-exchange-access