MultiversX Mainnet Incident Triggers EGLD Exchange Restrictions After VM-Level Exploit Attempt

Daily Feed
MultiversX Mainnet Incident Triggers EGLD Exchange Restrictions After VM-Level Exploit Attempt

MultiversX is dealing with a serious mainnet incident after an attempted VM-level exploit triggered invalid state changes and forced the network to pause progression. Exchanges moved quickly, EGLD came under scrutiny, and the project says a fix is being tested before anything is restored.

  • Upbit placed EGLD under trading caution review on Sept. 21
  • MultiversX said an actor “attempted to exploit a VM-level atomicity issue”
  • Kraken, Bithumb, and Coinbase restricted EGLD activity in different ways
  • No firm restart deadline has been published yet

Here’s what matters: MultiversX said an attempted exploit caused invalid state changes, and the network stopped progressing while the team worked on recovery. That is not a minor cosmetic bug. A blockchain’s whole value proposition depends on the state being correct, which is why exchanges do not wait around when something smells off.

The sequence of events is pretty clear. MultiversX disclosed on Sept. 19 that it was investigating a potential mainnet issue. It later said an actor had “attempted to exploit a VM-level atomicity issue”. In blockchain terms, that means the execution layer, the virtual machine that processes transactions, appears to have allowed a bad state transition that should not have happened. Atomicity is supposed to mean a transaction completes fully or not at all. When that guarantee breaks, you can end up with incorrect ledger updates, and that is the sort of thing nobody wants to discover in production.

For readers less fluent in crypto jargon: a mainnet is the live blockchain, where real assets move. A VM-level issue points to the chain’s execution engine rather than a wallet app or a front-end glitch. And invalid state changes means the chain recorded changes that do not line up with how the network is supposed to behave.

MultiversX said it prepared a software fix and planned to test it through a shadow fork. That is a way of replaying mainnet conditions in a controlled environment before touching the live network. It is sensible, because rushing a patch onto a fragile chain is how you turn a bad day into a complete mess. The project said deployment would proceed “subject to successful testing” and would require coordination with validators, exchanges, and infrastructure providers.

That coordination is not optional. If validators are out of sync, exchanges are still accepting transfers, or bridge operators move too early, users can wind up with deposits that do not reconcile cleanly. In crypto, one sloppy recovery step can create three new problems before lunch.

MultiversX also told users not to submit or rebroadcast transactions and not to move EGLD or ESDT tokens through exchange deposit and withdrawal routes or cross-chain bridges until an all-clear is issued. ESDT is MultiversX’s token standard. Cross-chain bridges are the tools that move assets between blockchains. When the underlying chain is unstable, those routes are not clever workarounds, they are a fast way to create a headache.

Upbit reacted fast. On Sept. 21, the South Korean exchange placed EGLD/KRW, EGLD/BTC and EGLD/USDT under trading caution review, warning that the unresolved incident could have caused, or could still cause, user losses. Upbit had already suspended EGLD deposits and withdrawals at 5:47 p.m. KST on Sept. 19. Under its notice, withdrawals are expected to return first when transfers resume, while deposit support will need a separate announcement after the review begins.

Upbit cited Article 17(1)(e) of South Korea’s Virtual Asset User Protection Act Enforcement Decree, which gives it a compliance basis to act when an unresolved blockchain issue could expose users to losses. That is the grown-up version of risk management: if the rails look compromised, the exchange does not keep selling tickets and hoping for the best.

Other venues tightened the screws too. Bithumb suspended EGLD deposits and withdrawals on Sept. 19 after block production stopped, just three days after it had restored those functions following a scheduled network upgrade. Kraken moved EGLD trading pairs into cancel-only mode, meaning users can cancel open orders but cannot place new ones. Coinbase reported delayed EGLD sends and receives beginning Sept. 19, though it said buying, selling, and fiat services were not affected.

Cancel-only is exactly what it sounds like: you can get out of existing orders, but you cannot open fresh ones. It is a containment move, not a vote of confidence.

The market noticed. CoinGecko historical data show EGLD closed at $4.14 on Sept. 18, fell to $3.87 on Sept. 19, and dropped again to $3.78 on Sept. 20. That is roughly an 8.7% decline from the Sept. 18 close. CoinGecko also recorded about $10.18 million in EGLD volume on Sept. 20, up from roughly $3.35 million on Sept. 18.

Those numbers do not prove a single clean narrative. The move could reflect panic, arbitrage, repositioning, or plain old volatility while traders tried to figure out whether the network was merely paused or actually compromised. Still, when exchanges start restricting transfers and issuing caution notices, the mood tends to be less “strategic dip-buying” and more “everyone grab the exits, but politely.”

MultiversX’s official status page reportedly showed degraded performance for Public API, xPortal, Explorer, Wallet, Bridge and xExchange, while Gateway and Index were listed as operational. The project said it will publish a full technical incident report after investigators finish the response and finalize their findings.

Security tracker SlowMist logged the episode as an attempted VM-level atomicity exploit involving invalid on-chain state changes. That is useful context, but it does not answer the most important unresolved questions: whether user funds were actually affected, which transactions or states need correction, and how long recovery will take.

One extra wrinkle is worth keeping in perspective. MultiversX recently activated its Supernova mainnet upgrade, which reduced targeted block time from six seconds to 600 milliseconds and shortened cross-shard settlement. That is a serious speed boost. But there is no statement reviewed here connecting the exploit attempt to Supernova, so blaming the upgrade would be speculation dressed up as analysis. Timing is not evidence. It is just timing.

The bigger lesson is simple. Performance upgrades are nice. Fast finality is nice. None of that matters if state integrity gets bent out of shape. A chain can be quick as hell and still be a liability if users and exchanges cannot trust what it records.

There is also a more uncomfortable truth for the crypto crowd: when a public chain hits a serious incident, the “decentralized” ecosystem still leans heavily on centralized exchanges, wallet providers, and infrastructure operators to keep things from turning into a complete circus. That is not an argument against decentralization. It is just the reality of how the rails work right now.

Key questions and takeaways

  • What happened on MultiversX?
    MultiversX said an actor attempted to exploit a VM-level atomicity issue on mainnet, which led to invalid state changes and a pause in network progression.

  • What did exchanges do?
    Upbit placed EGLD under trading caution review, Kraken moved pairs to cancel-only mode, Bithumb suspended deposits and withdrawals, and Coinbase reported delayed sends and receives.

  • Was user money confirmed stolen?
    Not in the public updates reviewed. The available information points to an attempted exploit and state disruption, but not a confirmed theft report.

  • Has MultiversX fully restored the network?
    Not yet, based on the latest public updates. The project is still testing a fix and has not published a firm restart deadline.

  • Did the Supernova upgrade cause the issue?
    There is no reviewed statement linking the incident to Supernova. The timing is interesting, but it does not prove causation.

  • What should EGLD users do right now?
    Follow official network and exchange notices, avoid submitting or rebroadcasting transactions, and wait for an explicit all-clear before using deposits, withdrawals, or bridges.

For now, EGLD remains under active scrutiny, and the real test for MultiversX is not speed, it is whether the network can recover cleanly without turning a security incident into a credibility problem. Fast broken chains are just a more efficient way to have a problem.

In a separate market context, traders have been watching other token moves like Infinit (IN) Jumps 10% on Upbit as Volume Spikes 500% in extreme conditions, while Meteora (MET2) Soars on Upbit as Greed Hits 94 and Volume has also caught attention on the same exchange, showing how quickly risk appetite can swing when liquidity and sentiment get punchy.

And yes, some coverage around this incident has been a mess, because the HTML content provided is incomplete and does not always carry enough context to make a clean judgment without the surrounding details. That is why raw headlines are often a trap, especially when a chain is on fire and everyone wants a neat answer yesterday.

For readers tracking exchange and market infrastructure more broadly, the UK network context at one.network/uk is a reminder that monitoring systems matter just as much as the asset itself when the goal is keeping traffic, whether financial or otherwise, from crashing into a wall.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog