MultiversX has confirmed that the mainnet issue it began investigating on September 19 was a security incident involving an attempted exploitation of a virtual-machine-level atomicity flaw, escalating what had initially been described only as a “potential issue” into a protocol-level incident.
The attempted exploit caused invalid state changes on the network, according to MultiversX. Network progression remains paused to prevent further impact while engineers test a fix and determine how to repair the affected state.
The response is particularly notable because MultiversX is not simply discussing restarting the network from its last uncontested point. Instead, the team says it is evaluating a targeted recovery mechanism intended to preserve finalized transaction history and legitimate user state while addressing only changes connected to the incident.
That makes the recovery process potentially as important as the vulnerability itself. Questions remain over exactly what state was altered, which transactions or balances are affected, how MultiversX will identify changes as invalid, and how those corrections can be implemented without disturbing legitimate activity that had already been finalized.
Attack Triggered Invalid State Changes and a Network Pause
MultiversX said an actor attempted to exploit an atomicity issue at the virtual machine level. In blockchain execution, atomicity generally refers to ensuring that an operation either completes with the intended set of state changes or fails without leaving behind unintended partial effects.
The project has not yet published the technical details of the flaw, the exploit transaction sequence, the affected contracts or accounts, or any estimate of financial damage. It has also not disclosed whether the incident created unauthorized token balances, altered smart-contract storage, affected token supply, or generated other state inconsistencies.
What is confirmed is that the resulting state was serious enough for MultiversX to pause network progression rather than allow the chain to continue building on top of potentially invalid data.
Engineers have prepared a fix and are testing it on a shadow fork, allowing the team to reproduce mainnet conditions and validate the patch against a copy of the network state before deploying it publicly. If the testing succeeds, MultiversX plans to coordinate the mainnet deployment with validators, exchanges and other infrastructure providers.
Coordinated protocol deployments are particularly important when validator software changes are involved. Other networks have similarly required node operators to upgrade around security-sensitive releases, including bridge-security fixes and tighter validator controls introduced through BNB Chain’s recent Pasteur upgrade.
For users, MultiversX’s instructions are unusually restrictive. The team says users should not submit new transactions or rebroadcast existing ones and should avoid EGLD and ESDT deposit and withdrawal routes through both exchanges and bridges until an all-clear is issued.
Exchange restrictions during security investigations are not unusual. Crypto.com, for example, recently suspended deposits for multiple assets over a security concern, while Kraken, KuCoin and Bitget have also dealt with crypto funding disruptions when underlying network infrastructure changed.
The Targeted Recovery Plan Could Become the Bigger Story
The most consequential part of MultiversX’s disclosure may ultimately be what happens after the vulnerability itself is patched.
Rather than describing a conventional rollback that would discard all blocks after a selected point, MultiversX says its proposed approach would preserve finalized transaction history and legitimate user state while correcting only incident-related invalid changes.
That distinction matters.
Blockchain finality normally gives users and infrastructure providers confidence that completed transactions will not later disappear from canonical history. A targeted state correction could potentially retain the historical record of those transactions while changing the resulting state that the network considers valid.
MultiversX has not yet explained how that correction would technically be implemented, however, and it would be premature to characterize it as any specific form of state patch, rollback or fork.
The unanswered questions are significant. Investors will want to know whether balances were incorrectly created or modified, whether smart-contract storage needs to be rewritten, whether any ESDT token state was affected, and whether messages destined for bridges, exchanges or other external systems were generated from invalid state.
The last point is especially sensitive. Once an invalid transaction creates an effect outside the originating blockchain, correcting the source-chain state does not necessarily reverse what an exchange, bridge or other external system has already processed. That helps explain why MultiversX has explicitly told users to avoid those routes.
Similar containment decisions have become a recurring feature of crypto incident response. Following a compromised key at ApeX Protocol, for example, the incident prompted questions over apparently abnormal token activity before the mechanism was clarified.
Supernova’s Timing Raises Questions, but Not Yet a Causal Link
The incident comes only days after MultiversX activated Supernova on mainnet on September 10, making the timing impossible to ignore. Supernova is one of the largest architectural changes in the network’s history, cutting block time from six seconds to roughly 600 milliseconds and separating execution from the consensus-critical path.
However, MultiversX has not said that the VM atomicity vulnerability was introduced by Supernova, and there is currently no public evidence establishing that connection.
That distinction is particularly important because Supernova has already experienced a separate post-upgrade issue. On September 12, MultiversX disclosed a problem affecting the recording and claiming of staking rewards and explicitly said that issue followed the Supernova upgrade.
The team has used no equivalent language tying the September 19-20 security incident to Supernova. Until the promised technical incident report identifies the vulnerable code path and when it entered production, treating the upgrade as the cause would be speculation.
For EGLD Investors, Recovery Integrity Matters More Than Restart Speed
There will naturally be pressure to bring MultiversX back online quickly, particularly while exchanges, bridges and applications remain constrained. But from an investor perspective, restarting fast is less important than proving that the recovered state is correct.
A chain can resume block production and still leave unresolved questions around balances, bridge backing or external settlement. Liquid Network recently illustrated that distinction when it restarted block production while transactions and peg operations remained restricted during its own recovery process.
MultiversX therefore has several separate milestones to clear: validate the vulnerability fix, define the incident-related invalid state, execute any recovery procedure, coordinate validator and infrastructure upgrades, reconcile exchange and bridge activity, and only then reopen normal user flows.
EGLD has already shown market pressure around the incident. Market trackers on September 20 showed the token trading around the high-$3 range, with a mid-single-digit decline over 24 hours depending on the venue. The more important variable from here is likely to be whether the technical report reveals a tightly contained edge case or a broader weakness in execution logic.
The Hardest Question Is Who Decides What Gets Reversed
The phrase “targeted recovery” sounds cleaner than a rollback, but technically and economically it creates a demanding governance problem.
Someone has to establish the exact boundary between legitimate and illegitimate state.
If the affected set is tiny and cryptographically obvious, that process may be relatively straightforward. If the exploit interacted with decentralized exchanges, liquidity pools, bridges or subsequent transactions from other users, the dependency tree could become much harder to unwind.
This is why the eventual incident report needs to disclose more than the vulnerability itself. It should identify the exploit sequence, affected state, methodology used to classify invalid changes, recovery mechanism, validator coordination process and treatment of any external transactions that may already have crossed infrastructure boundaries.
Taking infrastructure offline during an investigation can be the safest option when the alternative is allowing further damage. Swiss Bitcoin Pay recently made that trade-off when it shut down servers after detecting a suspected internal-system breach. The harder part is demonstrating that the system is safe when it comes back.
For MultiversX, that proof will not come from simply announcing that blocks are moving again. It will come from explaining precisely what went wrong, what was changed during recovery, and why users can trust the resulting state.
Until then, the VM flaw is only half the story. The other half is whether MultiversX can selectively repair a finalized blockchain state without creating a larger confidence problem than the exploit it is trying to contain.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

