Fogo's mainnet has not produced a block since Saturday afternoon, roughly 46 hours after validators stopped the network in response to the theft of 400 million FOGO tokens from the Fogo Foundation.
The halt has frozen every position on the chain, including $987,291 of deposits across four protocols, and the Foundation has not said when the network will restart, how it was compromised, or which addresses received the tokens. Its only published plan is to upgrade the network so those addresses are restricted, an action available to Fogo because seven operators run its voting validator set.
The 400 million tokens represent 10.3% of FOGO's 3.88 billion circulating supply and 4% of the 10.05 billion in existence, worth about $2.9 million at Monday's price. FOGO traded at $0.007333, down 3% over 24 hours and 18.4% over seven days, for a market capitalization of $28.5 million and a fully diluted valuation of $73.7 million, according to CoinGecko. The token set an all-time low of $0.00704157 at 23:47 UTC on Sunday, during the halt, and trades 88% below the $0.062549 record it reached on Jan. 15, the day Fogo launched its public mainnet after a Binance token sale.
The Foundation's first account of the incident said the chain itself was unaffected. "The Fogo Foundation experienced a compromise by an unknown actor which unfortunately resulted in 400mm FOGO tokens being sent to a bad actor," it posted at 9:13 p.m. ET on Aug. 28. "The Foundation alerted exchanges immediately and is actively communicating with law enforcement as well as forensic experts. There is no impact to the Fogo blockchain, which continues to operate as normal."
Fifteen hours later the network stopped. "In the last hour the Fogo Mainnet has been temporarily halted as a precautionary measure following the detection of unauthorized activity," Fogo posted at 12:29 p.m. ET on Aug. 29. "The halt is being initiated to prevent further movement of the affected assets. During the halt, the network will be upgraded to restrict the addresses associated with the incident." That post remains the most recent word from the project. Fogo has not disclosed the attack vector, the addresses involved, what restricting them means at the client level, or a restart time.



