Fogo has brought its mainnet back online after recovering and permanently removing 237 million of the 400 million FOGO tokens taken during a security breach that forced the Layer 1 blockchain to suspend operations.
The project said in its latest update that the network was functioning normally, while efforts to trace and recover the remaining affected assets continued in cooperation with centralised exchanges and law enforcement agencies.
Of the 400 million FOGO transferred during the incident, 237 million have now been recovered and taken permanently out of circulation. The remaining 163 million have not been reported as recovered.
“Efforts to recover the remaining affected assets are ongoing with CEXs and law enforcement,” Fogo said.
The project has not explained how the 237 million tokens were retrieved or described the procedure used to remove them from the total supply. It added that its investigation was still in progress and urged users to follow official Fogo channels for further updates.
The restart provides a clearer picture of the recovery effort after several days of uncertainty surrounding the stolen assets. However, Fogo has yet to publish a full explanation of how the security compromise took place.
Fogo first announced the incident on 28 August, saying an unknown individual had gained access to the Fogo Foundation and transferred 400 million FOGO to what it called a “bad actor”.
At that stage, the Foundation said the blockchain itself had not been compromised and was continuing to operate normally. The project began tracing the tokens and notified exchanges, law enforcement bodies and forensic investigators.
The situation changed the next day, when Fogo halted the network as validators prepared an upgrade. The suspension was intended to prevent the affected tokens from being moved further, although the project did not give a timetable for restoring the blockchain when it announced the stoppage.
The 400 million FOGO represented 4% of the network’s 10 billion-token genesis supply. It also amounted to more than 10% of the circulating supply at the time of the incident.
FOGO was trading at about $0.0075 when the network was halted, according to DefiLlama data. That valued the affected tokens at roughly $3m.
Restrictions on FOGO trading activity had begun shortly before the Foundation publicly disclosed the breach. Bitget suspended FOGO deposits and withdrawals approximately one hour before the first announcement, citing wallet maintenance. KuCoin later introduced similar restrictions.
Fogo has not said which addresses or systems within the Foundation were compromised, and its latest statement does not identify the method used in the attack. No full post-incident report has been released while the investigation remains ongoing.
The incident is one of several security-related events this year in which blockchain projects have relied on exchanges and law enforcement to contain stolen or improperly created assets.
In August, crypto.news reported that Harmony had proposed rolling back its chain after forged ONE tokens spread across its network. Under the proposed recovery plan, Harmony would return its two shards to checkpoints from 11 August, removing more than 109,000 regular transactions and 315 staking transactions. One wallet involved in that incident transferred 2.385 trillion forged ONE through 477 successful transactions in 106 seconds.
Maya Protocol also halted operations in August after an attacker exploited six linked software vulnerabilities. About $1.7m in Bitcoin and other assets was taken, including approximately 20 BTC, before the cross-chain protocol activated a global halt to limit further losses.
Blockchain networks have been stopped in different circumstances when developers or validators detect threats capable of affecting network operations or user assets.
MANTRA Chain resumed block production on 22 August after its mainnet was unable to process transactions for about 30 hours because of a Cosmos-EVM vulnerability. Validators installed version 8.4.0 to address the issue. MANTRA said two project-controlled wallets had been affected, while user balances remained unchanged.
Earlier this year, Humanity Protocol disclosed another security incident involving compromised administrative credentials. A malware-infected developer device exposed seven private keys that had been inadvertently backed up during the project’s June 2025 mainnet launch.
Those credentials enabled an attacker to withdraw 141.2 million H tokens from an Ethereum bridge and mint a further 300 million H on BNB Smart Chain. Humanity Protocol said the breach involved private keys rather than a weakness in its smart contracts or bridge infrastructure.
Fogo launched its mainnet in January 2026 after raising $7m through a Binance token sale at a valuation of $350m.
The Layer 1 blockchain was developed primarily for onchain trading and markets itself as a high-speed network. Its infrastructure targets a block time of 40 milliseconds and is designed to reduce exposure to maximal extractable value.
Before the interruption on 29 August, a guide published on Fogo’s website in March said the blockchain had maintained 100% uptime since launch. The halt ended that uninterrupted record several months after the mainnet went live.
Fogo has not said how long the network was offline before it restarted, nor has it detailed the validator upgrades carried out during the suspension.
The project said work with centralised exchanges and law enforcement would continue as it sought to recover the remaining affected tokens. Further information will be provided as the investigation develops.
