MultiversX Confirms Exploit as Mainnet Block Production Stops

MultiversX Confirms Exploit as Mainnet Block Production Stops

Key insights:

  • MultiversX paused block creation following the confirmation of invalid state changes due to a VM-layer exploit. 
  • A fix for a shadow fork is under testing by engineers, before coordinating a mainnet deployment.
  • Users should avoid transactions, exchange deposits, withdrawals, and bridge transfers until further notice.

MultiversX has paused its mainnet after attackers exploited a virtual machine vulnerability that caused invalid state changes on the blockchain. The network halted block production while engineers test a fix and assess a targeted recovery plan designed to protect legitimate user balances and confirmed transaction history.

MultiversX confirms exploit and halts blocks

MultiversX initially disclosed a potential mainnet issue on Sept. 19 during an active investigation. The project said user protection and secure network operation remained its immediate priorities.

However, a later network statement confirmed a more serious development. Attackers had exploited atomicity issues at the virtual machine layer, which resulted in invalid state changes on the chain.

The project responded by pausing block production to contain the incident. This measure also aims to prevent additional invalid changes while engineers prepare and validate the remediation.

At that stage, MultiversX had not disclosed the total value affected by the exploit. It also had not confirmed whether attackers successfully removed user funds or identified specific wallets involved.

The network therefore moved from investigating a potential technical problem to managing a confirmed security incident.

Engineers test fix before mainnet restart

The engineering team has prepared a fix. Is testing it through a shadow fork. This can enable developers to test changes without impacting the network.

If the testing process is successful the engineering team will coordinate the deployment with validators, exchanges and infrastructure providers. The coordination matters because those services interact directly with the network and can affect deposits, withdrawals, staking activity and transaction processing.

MultiversX has not provided a firm timetable for restoring normal block production. Instead, the project tied the next phase to successful testing and coordination with its infrastructure partners.

Meanwhile, engineers are examining a targeted recovery plan. The suggested solution would maintain the known history of transactions and user states, but deal with only the invalid changes associated with the exploit.

That approach might decrease unwanted modifications of the chain. It also places greater importance on accurately separating legitimate activity from transactions affected by the vulnerability.

Users face restrictions during the response

MultiversX has urged users not to submit or rebroadcast transactions while the network remains paused. The project also warned against depositing or withdrawing EGLD and ESDT through exchanges or cross-chain bridges.

Those restrictions extend beyond direct network users. Before an exchange or a bridge accepts deposits and withdrawals, it is essential to be able to get accurate blockchain state.

This could mean that they can continue to use the service for some period of time without their assets being directly affected by the exploit. The time-out also allows for standard transactions to wait until validators and infrastructure providers are given additional instructions.

The price of EGLD had settled around $4.12 in the reporting period. The price of the token fluctuated between $3.99 and $4.20, with an intraday range of approximately 5.3%.

The data on the available prices does not confirm that the security incident caused these movements. There are several other factors that can cause Crypto assets to move, such as the overall market state and trading volume.

This incident highlights other network vulnerabilities

The MultiversX incident illustrates the dangers of having vulnerabilities at the virtual machine level. Issues at this level can impact transactions and application state changes in the applications using the blockchain that it underlies.

Furthermore, this incident illustrates the need for more than just coordination at the core development team level. Operations may need to resume safely, which will require all Validators, exchanges, wallets, bridges and infrastructure providers to have instructions that are compatible.

MultiversX has built a wider ecosystem around EGLD through wallet integrations, analytics tools, decentralized applications, and staking infrastructure. That connectivity can increase the operational consequences of a mainnet disruption.

The project said it will provide further updates as its response progresses. It also plans to publish a complete technical incident report after completing the recovery process.

Conclusion

MultiversX now faces the task of restoring its mainnet without compromising legitimate blockchain history. The time taken to bring the network back into normal service will be dependent upon the amount of time required for planned testing of the shadow fork and targeted recovery.

The immediate concern for EGLD and ESDT users is to follow the official instructions while engineers validate the fix. Additional technical disclosures should help to explain what was vulnerable, what changes were effected, and what process will take place to end the exploit.

Scroll to Top