September 03, 07:00

Ontology forces node upgrade after mainnet restarts following malicious activity

Ontology forces urgent node upgrade after restarting chain hit by malicious activity

CryptoSlate

Ontology required every sync-node operator to upgrade to version 3.1.5 after its mainnet resumed normal operation on Sept. 2. The restoration notice said the software is required to maintain compatibility with the restored chain. It also said the software is required to ensure stable synchronization. Ontology told operators to confirm that their nodes are fully synchronized. Ontology told operators to verify normal operation afterward. The pause began Aug. 31. Ontology initially described the trigger as a potential security concern found during a daily security check. Ontology suspended block production during the pause. On-chain transactions remained unprocessed. A Sept. 1 update said the team had identified malicious attack activity targeting the network. Remediation, testing, and a network upgrade were underway at that time. Ontology told users not to attempt time-sensitive on-chain transactions during the pause. Ontology said users did not need to move ONT because of the announcement. Ontology also named ONG and other assets in that guidance. Ontology said block production would not restart until the network had been assessed and deemed safe to operate. Ontology said its investigation found that the activity did not involve or compromise user assets. That finding remains Ontology's assessment because the network has not published an independent forensic report. The v3.1.5 release provides a Linux AMD64 binary and checksum. The software change disables registrations for several legacy native contracts at mainnet block 20,770,894. The halt was observed at block 20,770,893. The parent commit changes cross-chain message deserialization. Ontology has not linked either commit to a specific attack path. Ontology's notices do not identify the vulnerability or attacker method. The notices do not explicitly name the affected component. The notices do not provide forensic evidence or a postmortem. Ontology has not confirmed service-by-service recovery across public RPC providers, exchange deposits and withdrawals, wallets, or dapps. Ontology said monitoring will continue with technical and security partners.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.