Ontology orders v3.1.5 node upgrade after mainnet restart

Ontology ordered all sync-node operators to install mandatory v3.1.5 after restarting mainnet on Sept. 2 following a security pause for detected malicious activity.

Ontology ordered all sync-node operators to install mandatory v3.1.5 after restarting mainnet on Sept. 2. The upgrade is required to maintain compatibility with the restored chain and keep nodes synchronized.

Block production was paused on Aug. 31 after a routine security check flagged a potential issue. A Sept. 1 update identified malicious activity targeting the network and noted remediation, testing and a network upgrade were underway. During the pause, users were advised not to attempt time-sensitive on-chain transactions and were told they did not need to move ONT, ONG or other assets. Block production resumed only after the team assessed the network and deemed it safe to operate.

The v3.1.5 release is mandatory for all sync nodes and includes a Linux AMD64 binary and checksum for operators. The emergency change disables registrations for several legacy native contracts at mainnet block 20,770,894, one block after the 20,770,893 height observed during the halt. A parent commit alters cross-chain message deserialization. The project published the code changes but has not linked those commits to a specific attack path.

Operators were instructed to upgrade as soon as possible, confirm their nodes are fully synchronized and verify normal operation after the update. The notice warned older software may be unable to follow the restored chain and could face compatibility and synchronization failures, though it did not state that all unupgraded nodes had already failed.

The investigation found user assets were not involved or compromised. The project has not released an independent forensic report or a detailed postmortem and has not publicly identified a specific vulnerability or attacker method.

The restoration announcement confirmed mainnet had resumed but did not confirm recovery across public RPC providers, exchange deposit and withdrawal services, wallets or decentralized applications. Monitoring and further investigation will continue with technical and security partners while remediation proceeds.

Articles by this author