What remains incomplete
aelf, which operates the AELF MainChain and its tDVV dAppChain, has brought back public node access and several core services following a controlled recovery triggered by malicious smart‑contract activity. The incident stopped block production for roughly a week, and full restoration is still pending.
According to a September 14 update, both public nodes were back online, together with the aelfscan explorer, FairyVault transfers, Awaken trading, Forest NFT browsing, and the TMRW DAO staking interface. By September 15, the MainChain and tDVV status endpoints responded and showed increasing block heights, although the checks did not verify that users could actually submit transactions.
The aelfscan, FairyVault, Awaken, Forest, and TMRW DAO frontends were accessible, but no end‑to‑end transfers, trades, or reward claims were performed during those verification steps.
aelf noted that exchange deposits and withdrawals are resuming incrementally, with timing varying across platforms. Bithumb announced that ELF deposits and withdrawals would resume on September 14 at 14:00 KST, while MEXC set its restart for September 5 and advised users to create new deposit addresses, as the old ones are no longer valid. These schedules indicate planned resumption but do not confirm that funds can actually be moved at the moment.
INDODAX’s September 2 notice still listed ELF wallet deposits and withdrawals as closed. Since that notice may be outdated, users should verify each exchange’s current status before attempting any transfers.
The suspension of block production also affected staking directly. aelf confirmed that no staking rewards were issued during the roughly week‑long outage. Restoring the TMRW DAO interface does not create rewards for the missed period; none can be claimed.
In an August 26 update, aelf reported that investigators uncovered 155 transactions tied to the malicious activity—127 on the AELF MainChain and 28 on the tDVV dAppChain. The update also highlighted five distinct .NET assemblies that could interface with host systems, node keys, and configuration files, indicating risks that extend beyond the smart contracts.
aelf warned that the presence of these capabilities does not guarantee that every payload was executed, every credential was compromised, or any data was actually transmitted. While its review through August 26 uncovered no unauthorized transfers of user assets or exposure of user wallet keys, it noted that the assessment did not cover potential exposure of node or infrastructure credentials.
The complete post‑incident review, technical appendix, and final root‑cause analysis have not yet been released. aelf stated that these documents will be published once the outstanding work—including an independent review—is finished. For now, the restored services indicate operational progress rather than a definitive security clearance.
Also Read
- CLARITY Act Stalls in Senate Cloture Vote 49‑50, Prospects Remain Uncertain
- Cardano Integrates with Coinbase-Built x402 Open Payment Protocol
- Major Bitcoin Core update changes default wallet protocols, risking temporary disruption across popular apps
- Senate Block on Clarity Act Leaves Crypto Industry Navigating Regulatory Uncertainty


