Skip to main content
AVOID.NET
← MultiversX (EGLD)1 decision on this page

Audit log

Every state-changing event for MultiversX (EGLD): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-04 23:10:26Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 453,400,144
    sig
    sbsEotdWbWfs…MrDnhsrTexplorer ↗
    hash
    3VrA5aFD4bmJ…wvKZHEkZsha256 → base58
    verifying row…full verify ↗
    canonical bytes (16427 B) ▸
    {"actor":"system:backfill","investigation_id":"1ed0417b-43c3-4515-83ee-e082fefff6be","kind":"publish","page_slug":"multiversx-egld","published_at":"2026-10-04T23:10:26.902Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"MultiversX (EGLD)","sections":[{"content":"On September 19, 2026, the MultiversX mainnet stopped producing new blocks after an actor attempted to exploit an atomicity flaw at the virtual machine (VM) layer. MultiversX confirmed via its official X account (@MultiversX): 'We have confirmed that a[n] actor attempted to exploit a VM-level atomicity issue. The attempt caused invalid state changes, and network progression remains paused to prevent any further impact.' The development team immediately paused network progression to contain the issue and began preparing a software patch for validation on a shadow fork. Users were instructed not to submit or rebroadcast transactions and to refrain from using EGLD and ESDT deposit and withdrawal routes through exchanges or bridges until an all-clear was issued. Block production resumed on September 24, 2026, following deployment of a recovery upgrade, representing a halt of approximately five calendar days.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":1,"name":"MultiversX official X post confirming VM-level atomicity exploit","type":"official","url":"https://x.com/MultiversX/status/2101341591277391953"},{"credibility":2,"name":"MultiversX restarts after exploit halt, but Kraken still bars new EGLD trades — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/multiversx-restarts-after-exploit-halt-but-kraken-still-bars-new-egld-trades/"},{"credibility":2,"name":"MultiversX Restarts Block Production After Five-Day Exploit Halt — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/24088"}]},{"content":"The exploit involved an atomicity gap at the virtual machine level. In blockchain VM design, atomicity requires that a transaction either executes fully or not at all; where that guarantee fails, a transaction can take partial effect and leave behind an on-chain state the chain itself considers invalid. According to reporting by CryptoTicker and community analysis, the specific vulnerability allowed a malicious contract to call 'executeOnDestContextByCaller' inside an asynchronous callback. This enabled the attacker to perform actions not in the name of its direct caller but in the name of any contract it chose to invoke, bypassing standard access controls. The attacker's reported target was the egld-esdt-swap contract, which is the contract responsible for creating and swapping Wrapped EGLD (WEGLD) to and from native EGLD. The team evaluated a targeted recovery approach to preserve finalized transaction history and legitimate user state while addressing only the incident-related invalid changes. A full technical incident report was committed to but had not been publicly released as of the investigation date.","heading":"Technical Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"EGLD withdrawals frozen: Upbit decides from Oct 19 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"},{"credibility":2,"name":"MultiversX Confirms an Attempted Exploit of a VM-level Atomicity Issue — CryptoWisser","type":"news_article","url":"https://www.cryptowisser.com/news/multiversx-halts-network-after-hacker-exploits-atomicity-flaw/"},{"credibility":2,"name":"MultiversX: Mainnet Hit by Hacker Attack, Network Suspended — PANews","type":"news_article","url":"https://panews.io/articles/01a0bc51-1585-7403-bd94-35d2ba84560d"}]},{"content":"MultiversX stated that the attacker's accounts were identified and frozen through coordination with major cryptocurrency exchanges, which were provided a blacklist of associated wallet addresses. The co-founder's public communications indicated the incident was contained. Because EGLD as a native asset cannot be frozen on-chain by the protocol itself, the containment strategy relied on exchange-level enforcement: exchanges receiving the blacklist could refuse to process deposits from the flagged addresses, preventing the attacker from converting proceeds. MultiversX reported no confirmed net loss of user funds, and the protocol stated that user balances remained secure. The User Protection Fund was referenced in reporting by ETHNews as part of MultiversX's safeguarding infrastructure in connection with this incident, though specific deployment details were not confirmed in available sources. No individual or group has been publicly named as responsible for the attack, and no law enforcement action had been publicly announced as of the investigation date.","heading":"Attacker Response and Containment","severity":"high","sources":[{"credibility":2,"name":"MultiversX Says Funds Safe, Attacker Accounts Frozen After Exploit — ETHNews","type":"news_article","url":"https://ethnews.com/multiversx-says-funds-safe-attacker-accounts-frozen-after-exploit/"},{"credibility":2,"name":"MultiversX hit by Upbit warning after mainnet exploit — crypto.news","type":"news_article","url":"https://crypto.news/multiversx-hit-by-upbit-warning-after-mainnet-exploit/"},{"credibility":2,"name":"EGLD withdrawals frozen: Upbit decides from Oct 19 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"}]},{"content":"Multiple major cryptocurrency exchanges restricted EGLD services following the September 19 incident. Upbit (South Korea), which handles approximately one-fifth of total EGLD trading volume and is the single largest market for EGLD, suspended EGLD/KRW, EGLD/BTC, and EGLD/USDT deposits and withdrawals at 5:47 p.m. KST on September 19 and applied a formal trading caution designation on September 21. Kraken placed EGLD in cancel-only mode at 21:00 UTC on September 19, noting that its funding-gateway flagged possible EGLD delays as early as September 16. Bithumb also suspended EGLD deposits and withdrawals on September 19. Coinbase reported delayed EGLD sends and receives beginning September 19. Bitvavo suspended native-network EGLD deposits and withdrawals; Binance closed the native MultiversX network route, leaving only BEP-20 (BNB Smart Chain) transfers available. Kraken closed its incident and resumed EGLD/EUR trading on approximately October 1, 2026. Upbit's formal review of whether to continue listing EGLD was scheduled for October 19–23, 2026; a delisting would remove a venue representing significant daily turnover. EGLD price declined approximately 8.7%, from roughly $4.14 on September 18 to approximately $3.78 on September 20, while trading volume surged from $3.35 million to $10.18 million over the same period.","heading":"Exchange Restrictions and Market Impact","severity":"high","sources":[{"credibility":2,"name":"MultiversX hit by Upbit warning after mainnet exploit — crypto.news","type":"news_article","url":"https://crypto.news/multiversx-hit-by-upbit-warning-after-mainnet-exploit/"},{"credibility":2,"name":"EGLD withdrawals frozen: Upbit decides from Oct 19 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"},{"credibility":2,"name":"MultiversX restarts after exploit halt, but Kraken still bars new EGLD trades — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/multiversx-restarts-after-exploit-halt-but-kraken-still-bars-new-egld-trades/"},{"credibility":2,"name":"MultiversX Restarts Block Production After Five-Day Exploit Halt — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/24088"}]},{"content":"On September 24, 2026, the @CodeMultiversX team announced that a recovery upgrade had been deployed and that block production had resumed on the MultiversX mainnet gateway. The recovery was described as a deliberate halt followed by a coordinated restart: validators reached agreement on which state to resume from before restarting block production. MultiversX's official communication noted that trading, deposits, and withdrawals might remain paused at some exchanges for several more days following the mainnet restart, and encouraged users to verify exchange-specific updates before transacting. The distinction between network-level recovery and exchange-level confidence in on-chain settlement safety was noted across multiple sources: each exchange independently verified that its internal balances matched the post-recovery chain state before reopening services.","heading":"Network Recovery","severity":"medium","sources":[{"credibility":2,"name":"MultiversX restarts after exploit halt, but Kraken still bars new EGLD trades — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/multiversx-restarts-after-exploit-halt-but-kraken-still-bars-new-egld-trades/"},{"credibility":2,"name":"MultiversX Restarts Mainnet After Exploit Halt, Kraken Locks EGLD — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/multiversx-restarts-mainnet-after-exploit-halt-kraken-egld-september-2026/"}]},{"content":"As of October 4, 2026, several material items remain unresolved. First, MultiversX committed to publishing a full technical incident report after completing its response procedures, but this report had not been released publicly as of the investigation date. Second, Upbit's review of the EGLD listing was scheduled for October 19–23, 2026, with no outcome yet known; given Upbit's position as the single largest EGLD market, a negative decision would carry significant liquidity implications. Third, Bitvavo continued to maintain native-network EGLD maintenance restrictions as of available reporting. Fourth, while MultiversX stated that attacker accounts were frozen through exchange coordination and that no net user losses occurred, no independent verification of these claims from a Tier 1 source was available; the quantified loss figure, if any, and the total value of assets that transited through attacker wallets remain unconfirmed. The full technical incident report, once published, will be the authoritative source on exploit mechanics and any loss quantification.","heading":"Open Items and Outstanding Risks","severity":"medium","sources":[{"credibility":2,"name":"EGLD withdrawals frozen: Upbit decides from Oct 19 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"},{"credibility":2,"name":"MultiversX hit by Upbit warning after mainnet exploit — crypto.news","type":"news_article","url":"https://crypto.news/multiversx-hit-by-upbit-warning-after-mainnet-exploit/"}]},{"content":"This is not MultiversX's first significant security incident. In June 2022, when the network operated under the name Elrond, approximately 1.65 million EGLD tokens (then valued at roughly $113 million) were minted by an attacker who exploited the Maiar DEX smart contract. The official incident and recovery report for that event was published on the MultiversX blog. The 2026 atomicity exploit is a separate and distinct incident; it is included here solely for historical context regarding the protocol's security track record.","heading":"Historical Context: 2022 Bridge Exploit","severity":"low","sources":[{"credibility":1,"name":"Elrond Incident and Recovery Report — The MultiversX Blog","type":"official","url":"https://multiversx.com/blog/incident-and-recovery-report"}]}],"sources_used":[{"credibility":1,"name":"MultiversX official X post confirming VM-level atomicity exploit","type":"official","url":"https://x.com/MultiversX/status/2101341591277391953"},{"credibility":2,"name":"MultiversX hit by Upbit warning after mainnet exploit — crypto.news","type":"news_article","url":"https://crypto.news/multiversx-hit-by-upbit-warning-after-mainnet-exploit/"},{"credibility":2,"name":"MultiversX restarts after exploit halt, but Kraken still bars new EGLD trades — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/multiversx-restarts-after-exploit-halt-but-kraken-still-bars-new-egld-trades/"},{"credibility":2,"name":"MultiversX Restarts Mainnet After Exploit Halt, Kraken Locks EGLD — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/multiversx-restarts-mainnet-after-exploit-halt-kraken-egld-september-2026/"},{"credibility":2,"name":"MultiversX Restarts Block Production After Five-Day Exploit Halt — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/24088"},{"credibility":2,"name":"MultiversX: Mainnet Hit by Hacker Attack, Network Suspended — PANews","type":"news_article","url":"https://panews.io/articles/01a0bc51-1585-7403-bd94-35d2ba84560d"},{"credibility":2,"name":"MultiversX Confirms an Attempted Exploit of a VM-level Atomicity Issue — CryptoWisser","type":"news_article","url":"https://www.cryptowisser.com/news/multiversx-halts-network-after-hacker-exploits-atomicity-flaw/"},{"credibility":2,"name":"EGLD withdrawals frozen: Upbit decides from Oct 19 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"},{"credibility":2,"name":"MultiversX Says Funds Safe, Attacker Accounts Frozen After Exploit — ETHNews","type":"news_article","url":"https://ethnews.com/multiversx-says-funds-safe-attacker-accounts-frozen-after-exploit/"},{"credibility":1,"name":"Elrond Incident and Recovery Report — The MultiversX Blog","type":"official","url":"https://multiversx.com/blog/incident-and-recovery-report"}],"summary":"On September 19, 2026, an actor exploited a virtual-machine-level atomicity flaw on the MultiversX mainnet, producing invalid on-chain state changes and forcing a network-wide block-production halt lasting approximately five days. MultiversX resumed mainnet operations on September 24 following a coordinated recovery upgrade, and the protocol reported no confirmed net loss of user funds; however, the attacker's wallets were identified and frozen with exchange assistance, multiple major exchanges restricted EGLD deposits, withdrawals, and trading, and EGLD declined roughly 8.7% during the halt. As of the investigation date (October 4, 2026), Upbit's formal review of whether to continue listing EGLD was scheduled for October 19–23, 2026.","timeline":[{"date":"2026-09-16","event":"Kraken first flagged possible EGLD funding-gateway delays at 9:58 a.m. ET, before the public exploit disclosure.","source":"TokenPost","source_url":"https://www.tokenpost.com/news/technology/24088"},{"date":"2026-09-19","event":"MultiversX mainnet stops producing blocks after an actor attempts to exploit a VM-level atomicity issue, causing invalid state changes. Bithumb and Coinbase suspend or delay EGLD services. Kraken places EGLD in cancel-only mode at 21:00 UTC. Upbit suspends EGLD deposits and withdrawals at 5:47 p.m. KST.","source":"crypto.news / CryptoSlate / TokenPost","source_url":"https://crypto.news/multiversx-hit-by-upbit-warning-after-mainnet-exploit/"},{"date":"2026-09-21","event":"MultiversX confirms via @MultiversX on X that a VM-level atomicity exploit caused invalid state changes; engineering is preparing a fix for shadow-fork validation. Upbit formally designates EGLD/KRW, EGLD/BTC, and EGLD/USDT as caution markets. MultiversX states attacker accounts have been identified and frozen through exchange coordination.","source":"MultiversX / crypto.news / ETHNews","source_url":"https://x.com/MultiversX/status/2101341591277391953"},{"date":"2026-09-24","event":"@CodeMultiversX announces recovery upgrade deployed and block production resumed on the MultiversX mainnet. Chain halt lasted approximately five calendar days.","source":"CryptoSlate / SpendNode","source_url":"https://cryptoslate.com/multiversx-restarts-after-exploit-halt-but-kraken-still-bars-new-egld-trades/"},{"date":"2026-10-01","event":"Kraken closes its EGLD incident; EGLD/EUR trading resumes on Kraken.","source":"CryptoTicker","source_url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"},{"date":"2026-10-19","event":"Upbit review window opens (October 19–23) for decision on whether to continue listing EGLD following the exploit and trading caution designation. Outcome pending as of investigation date.","source":"crypto.news / CryptoTicker","source_url":"https://cryptoticker.io/en/egld-withdrawals-frozen-exchanges/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 2fd10f7d-04b8-43e2-a021-ffd1a83ba0a6
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.