Fogo Blockchain Halts Network After 400M FOGO Token Theft
Key Takeaways
- •An attacker compromised the Fogo Foundation and transferred 400 million FOGO tokens, valued at roughly $3 million at the time.
- •The stolen tokens account for 4% of Fogo's 10 billion-token genesis supply and more than 10% of its circulating supply.
- •Fogo paused its network on Saturday to prevent further movement of the compromised tokens while validators implemented changes, with no stated restart time.
- •Bitget and KuCoin suspended FOGO deposits and withdrawals around the time the Foundation disclosed the incident.
- •The Foundation has not identified how its systems were compromised, and the outage contradicts its previously claimed 100% mainnet uptime during the chain's first year.

Layer 1 blockchain Fogo halted its network on Saturday, roughly 15 hours after the Fogo Foundation disclosed that an attacker had obtained 400 million FOGO tokens in an incident the organization has yet to fully explain.
The affected tokens were valued at about $3 million when FOGO was trading near $0.0075. The network pause was announced at 12:29 p.m. ET on Saturday, within the preceding hour, as validators prepared to upgrade the network.
Fogo said the temporary halt was intended to prevent further movement of the compromised assets while validators implemented changes to the blockchain. The Foundation did not provide an estimated time for the network to resume operations or disclose technical details about the restrictions imposed during the pause.
The 400 million FOGO tokens represent 4% of the blockchain's 10 billion-token genesis supply and more than 10% of its circulating supply, making the incident significant relative to the amount of FOGO currently available in the market.
The decision to halt the network echoes containment measures taken by other blockchain teams after major token thefts, a tactic that can freeze compromised assets onchain but also interrupts all activity for users of the chain. According to the Foundation's description, the incident stemmed from a compromise of the organization itself rather than a flaw in the blockchain's code, a pattern seen in previous crypto industry incidents where attackers gained control of a team's wallets or internal systems rather than exploiting protocol logic. The Foundation has not, however, confirmed the specific mechanism involved.
Foundation Reports Organizational Compromise
The Fogo Foundation first disclosed the incident in a post at 9:13 p.m. ET on Friday, stating that an unidentified attacker had compromised the organization and transferred 400 million FOGO tokens to an unauthorized recipient.
The Foundation said cryptocurrency exchanges, law enforcement agencies and forensic specialists had been notified following the discovery. At that stage, however, it maintained that the blockchain itself continued to function normally.
The organization has not identified the method used to compromise its systems or explained which wallets or addresses were affected. It has also not provided details on whether the stolen tokens originated from operational reserves, treasury holdings or another source controlled by the Foundation.
This lack of information leaves several key aspects of the incident unresolved, including how the attacker gained access, whether additional assets were at risk, and what measures are being taken to secure the Foundation's infrastructure.
Exchanges Suspend FOGO Transfers
Trading infrastructure also moved to restrict activity involving FOGO around the time of the disclosure.
Bitget suspended FOGO deposits and withdrawals approximately one hour before the Foundation's first public announcement, citing wallet maintenance as the reason. KuCoin subsequently announced a similar suspension.
The exchange restrictions could limit the movement of the affected tokens while the Foundation and validators investigate the incident. It remains unclear whether other trading platforms will introduce comparable measures or whether the compromised tokens can still be transferred through other channels.
The Fogo Foundation experienced a compromise by an unknown actor which unfortunately resulted in 400mm FOGO tokens being sent to a bad actor. The Foundation alerted exchanges immediately and is actively communicating with law enforcement as well as forensic experts. There is… — Fogo (@fogo) August 29, 2026
The incident also raises questions about Fogo's previously stated network reliability record. A guide published on Fogo's website in March had claimed that the mainnet maintained 100% uptime since its launch. That information had not been updated after Saturday's network halt.
Fogo's High-Speed Trading Focus
Fogo launched its mainnet in January following a $7 million Binance token sale conducted at a reported $350 million valuation. The project positions itself as a high-performance Layer 1 blockchain designed specifically for onchain trading.
Its architecture targets block times of around 40 milliseconds while seeking to reduce users' exposure to maximal extractable value, commonly known as MEV. These features are intended to support faster transaction execution and more efficient trading applications.
For a project whose value proposition centers on supporting trading applications, an extended outage and the uncertainty around the stolen tokens carry particular weight: trading-focused users and applications depend on continuous availability, and the incident comes within the chain's first year of mainnet operation.
The network's decision to halt operations while validators upgrade the blockchain highlights the project's immediate focus on containing the compromised tokens and preventing additional movement while the security incident is investigated.
As of the latest disclosure, Fogo had not provided a timeline for restoring the network or a detailed explanation of the exploit. The Foundation's continuing investigation, together with actions by validators and exchanges, is expected to determine the extent of the compromise and the measures required before normal operations resume. Key open questions include how the attacker gained access to the Foundation's systems, whether the validator upgrade will be able to freeze or recover the stolen tokens, and what remediation the Foundation will disclose once the investigation progresses.