Ontology forces urgent node upgrade after restarting chain hit by malicious activity
Ontology said its mainnet resumed normal operation on Sept. 2 after an emergency security pause and told every sync-node operator to upgrade to version 3.1.5. Sync nodes are infrastructure that keep their copy of the blockchain synchronized with the network.
The restoration notice says the new software is required to maintain compatibility with the restored chain and ensure stable synchronization. Ontology told operators to upgrade as soon as possible, confirm that their nodes are fully synchronized, and verify normal operation afterward.
Older software therefore carries a compatibility and synchronization risk, although the notice does not say that every unupgraded node has already failed.

The restoration followed a pause that began Aug. 31. Ontology initially described the trigger as a potential security concern found during a daily security check and suspended block production, leaving on-chain transactions unprocessed.
A Sept. 1 update escalated that description, saying the team had identified malicious attack activity targeting the network while remediation, testing, and a network upgrade were underway.
During the pause, Ontology told users not to attempt time-sensitive on-chain transactions and said they did not need to move ONT, ONG, or other assets because of the announcement. It said block production would not restart until the network had been assessed and deemed safe to operate.
Ontology also said its investigation found that the activity did not involve or compromise user assets. That remains the network's assessment because it has not published an independent forensic report.
The code offers clues, not an attack explanation
The v3.1.5 release provides a Linux AMD64 binary and checksum but no incident explanation. The tagged code change disables registrations for several legacy native contracts at mainnet block 20,770,894, one block after the 20,770,893 height observed during the halt. Its parent commit changes cross-chain message deserialization.
The public code shows the shape of the emergency software change, but Ontology has not linked either commit to a specific attack path. Its notices do not identify the vulnerability or attacker method, explicitly name the affected component, or provide forensic evidence or a postmortem.
The restoration announcement confirms the mainnet's return, not a service-by-service recovery across the wider ecosystem. It does not establish whether public RPC providers, exchange deposits and withdrawals, wallets or dapps have all resumed normal operation.
The malicious-activity confirmation had already moved the incident beyond the initial pause, as CryptoSlate reported in a Sept. 1 examination of network shutdowns.
Ontology said monitoring will continue with technical and security partners. For now, v3.1.5 tells operators what they must do, while the reason for the emergency change remains undisclosed.
The post Ontology forces urgent node upgrade after restarting chain hit by malicious activity appeared first on CryptoSlate.