|

Ontology forces urgent node upgrade after restarting chain hit by malicious activity

Timeline of Ontology

Ontology stated its mainnet resumed regular operation on Sept. 2 after an emergency safety pause and instructed each sync-node operator to upgrade to model 3.1.5. Sync nodes are infrastructure that hold their copy of the blockchain synchronized with the community.

The restoration notice says the brand new software program is required to keep up compatibility with the restored chain and guarantee secure synchronization. Ontology instructed operators to upgrade as quickly as potential, verify that their nodes are totally synchronized, and confirm regular operation afterward.

Older software program due to this fact carries a compatibility and synchronization danger, though the discover doesn’t say that each unupgraded node has already failed.

Timeline of Ontology's Aug. 31 mainnet pause, Sept. 1 malicious-activity confirmation, Sept. 2 restoration, mandatory v3.1.5 sync-node upgrade, public code clues and still-undisclosed security details.
Ontology resumed mainnet operations after malicious activity, whereas requiring all sync nodes to upgrade to v3.1.5 as remediation continues.

The restoration adopted a pause that started Aug. 31. Ontology initially described the set off as a potential security concern discovered throughout a every day safety verify and suspended block manufacturing, leaving on-chain transactions unprocessed.

A Sept. 1 update escalated that description, saying the staff had recognized malicious assault activity concentrating on the community whereas remediation, testing, and a community upgrade have been underway.

During the pause, Ontology instructed customers to not try time-sensitive on-chain transactions and stated they didn’t want to maneuver ONT, ONG, or different property due to the announcement. It stated block manufacturing wouldn’t restart till the community had been assessed and deemed secure to function.

Ontology additionally stated its investigation discovered that the activity didn’t contain or compromise consumer property. That stays the community’s evaluation as a result of it has not revealed an unbiased forensic report.

Related Reading

Stopping a blockchain doesn’t always recover stolen funds – What actually happened when 3 networks pulled the plug


The code gives clues, not an assault rationalization

The v3.1.5 release supplies a Linux AMD64 binary and checksum however no incident rationalization. The tagged code change disables registrations for a number of legacy native contracts at mainnet block 20,770,894, one block after the 20,770,893 peak observed during the halt. Its parent commit modifications cross-chain message deserialization.

The public code exhibits the form of the emergency software program change, however Ontology has not linked both decide to a particular assault path. Its notices don’t establish the vulnerability or attacker methodology, explicitly identify the affected element, or present forensic proof or a postmortem.

The restoration announcement confirms the mainnet’s return, not a service-by-service restoration throughout the broader ecosystem. It doesn’t set up whether or not public RPC suppliers, change deposits and withdrawals, wallets or dapps have all resumed regular operation.

The malicious-activity affirmation had already moved the incident past the preliminary pause, as CryptoSlate reported in a Sept. 1 examination of network shutdowns.

Ontology stated monitoring will proceed with technical and safety companions. For now, v3.1.5 tells operators what they have to do, whereas the explanation for the emergency change stays undisclosed.

The put up Ontology forces urgent node upgrade after restarting chain hit by malicious activity appeared first on CryptoSlate.

Similar Posts