Ontology has restored normal operation on its mainnet after an emergency security pause linked to malicious activity, but all sync-node operators have been told to install new software urgently.
The blockchain network resumed operation on 2 September following a halt that began on 31 August. Operators must upgrade to version 3.1.5 to remain compatible with the restored chain and maintain stable synchronisation.
Sync nodes hold copies of the blockchain and keep them aligned with the wider network. Ontology said operators should install the update as soon as possible, ensure their nodes have fully synchronised and then check that they are operating normally.
The requirement creates a compatibility and synchronisation risk for nodes still running older software. However, Ontology has not said that every node which has not yet upgraded has failed.
The suspension was initially described by Ontology as the result of a potential security concern identified during a routine daily security check. Block production was stopped, meaning transactions submitted on-chain could not be processed.
A further update on 1 September gave a clearer explanation, stating that the team had detected malicious attack activity targeting the network. At that point, remediation work, testing and a network upgrade were in progress.
During the disruption, Ontology advised users not to make time-sensitive on-chain transactions. It also said users did not need to move ONT, ONG or any other assets because of the incident.
The network said block production would remain paused until it had been assessed and considered safe to restart. Ontology later reported that its investigation had found no evidence that user assets had been involved or compromised. That remains the network’s own assessment, as no independent forensic report has been released.
Details of emergency software change remain unclear
The v3.1.5 release includes a Linux AMD64 binary and a checksum, but does not contain an explanation of the incident.
Public code associated with the release shows that registrations for several legacy native contracts are disabled at mainnet block 20,770,894. That is one block after height 20,770,893, which was observed during the halt.
The parent commit includes changes to cross-chain message deserialisation. Those changes indicate the broad nature of the emergency software update, but Ontology has not connected either commit to a specific attack route.
The network’s public notices do not identify the vulnerability, explain how the attacker operated, name the affected component or provide forensic evidence. They also do not include a post-incident report.
The announcement confirms that the mainnet has restarted, but it does not demonstrate that every service across the wider Ontology ecosystem has returned to normal. It remains unclear whether public RPC providers, exchange deposits and withdrawals, wallets and decentralised applications have all resumed normal operation.
The confirmation of malicious activity moved the incident beyond the initial security pause. CryptoSlate had reported on the development in a 1 September examination of blockchain network shutdowns.
Ontology said it would continue monitoring the network alongside technical and security partners. For node operators, the immediate instruction is clear: install version 3.1.5 and verify synchronisation. The precise reason for the emergency change, however, remains undisclosed.
Ontology is down 1.52% over the past 24 hours and is currently ranked 343rd by market capitalisation.
