Ontology announced that its mainnet returned to normal operation on September 2 following an emergency security pause, instructing all sync-node operators to upgrade to version 3.1.5. Sync nodes serve as the infrastructure that maintains synchronized copies of the blockchain across the network.
According to the restoration notice, the new software is necessary to ensure compatibility with the restored chain and to maintain stable synchronization. Ontology urged operators to upgrade promptly, verify that their nodes are fully synchronized, and confirm normal operation following the update.
Older software versions now carry compatibility and synchronization risks, though the notice does not indicate that every unupgraded node has failed.
The restoration followed a pause that began on August 31. Ontology initially characterized the trigger as a potential security concern identified during a routine daily security check, suspending block production and leaving on-chain transactions unprocessed.
A September 1 update escalated that characterization, with the team confirming it had identified malicious attack activity targeting the network as remediation, testing, and a network upgrade progressed.
During the pause, Ontology advised users against initiating time-sensitive on-chain transactions and clarified that there was no need to move ONT, ONG, or other assets in response to the announcement. The team stated that block production would not resume until the network had been fully assessed and deemed safe.
Ontology also reported that its investigation determined the activity did not involve or compromise user assets. This remains the network’s official assessment, as the team has not published an independent forensic report.
The code offers clues, not an attack explanation
The v3.1.5 release provides a Linux AMD64 binary and checksum but does not include an incident explanation. The tagged code change disables registrations for several legacy native contracts at mainnet block 20,770,894, one block after the 20,770,893 height observed during the halt. Its parent commit modifies cross-chain message deserialization.
While the public code reveals the shape of the emergency software change, Ontology has not linked either commit to a specific attack vector. Its notices do not identify the vulnerability or attacker methodology, explicitly name the affected component, or provide forensic evidence or a formal postmortem.
The restoration announcement confirms the mainnet’s return, though it does not detail a service-by-service recovery across the broader ecosystem. It does not clarify whether public RPC providers, exchange deposits and withdrawals, wallets, or decentralized applications have all resumed normal operation.
The malicious-activity confirmation had already moved the incident beyond the initial pause, as CryptoSlate reported in a September 1 examination of network shutdowns.
Ontology stated that monitoring will continue alongside technical and security partners. For now, v3.1.5 communicates what operators must do, while the underlying reason for the emergency change remains undisclosed.
Also Read
- British Services Activity Rebounds to Four-Month High Amid Renewed Inflation and Persistent Job Losses
- BTC/USD Technical Outlook Hits New Low as Macro Stress Pushes Toward $70,000 Support
- Thailand’s SEC introduces Travel Rule requiring identity data on crypto transfers above 30,000 baht
- Divergent Asian Equities as Investors Await US Nonfarm Payrolls


