Skip to content
Upbit Flags MultiversX EGLD for Trading Caution After Mainnet Exploit Attempt

Upbit Flags MultiversX EGLD for Trading Caution After Mainnet Exploit Attempt

Finance.Biggo • September 21, 2026

South Korea's largest cryptocurrency exchange has placed MultiversX's EGLD token under a formal trading caution designation after the blockchain network confirmed an attempted exploit targeting a virtual-machine-level vulnerability on its mainnet.

Upbit announced the designation on Sept. 21, covering EGLD trading pairs against the Korean won, Bitcoin and Tether. The exchange said the unresolved security incident involving the MultiversX blockchain could have caused, or could potentially cause, user losses. The move follows a suspension of EGLD deposits and withdrawals that took effect at 5:47 p.m. KST on Sept. 19.

A trading caution label is not a delisting or a full trading halt. It functions as a formal warning that a project faces conditions that may elevate risk for users. Upbit said it reviewed the situation under Article 17(1)(e) of South Korea's Virtual Asset User Protection Act Enforcement Decree, which addresses security incidents affecting wallets, distributed ledgers or other infrastructure used to issue, transfer or store virtual assets that remain unexplained or unresolved.

What Happened on the MultiversX Mainnet

MultiversX first disclosed on Sept. 19 that it was investigating a potential mainnet issue, emphasizing user safety and stable network operation. The project's initial statement did not classify the event as an exploit or disclose any confirmed financial loss.

A subsequent update from the project said an actor had attempted to exploit a VM-level atomicity issue. The attempt generated invalid state changes, prompting developers to halt network progression while engineers worked on a repair. The team prepared a software fix for testing through a shadow fork, which allows developers to reproduce mainnet conditions without immediately applying changes to the live network.

Deployment of the fix would proceed subject to successful testing and require coordination with validators, exchanges and infrastructure providers, according to the project. No firm restart deadline appeared in the public updates reviewed.

Security tracker SlowMist separately recorded the incident as an attempted VM-level atomicity exploit involving invalid on-chain state changes. Its public database did not list a confirmed loss amount.

MultiversX said engineers were evaluating a targeted recovery procedure designed to preserve finalized legitimate transaction history while correcting invalid state changes linked to the incident. The project has not yet published the exact recovery method or identified which transactions, smart contracts or account states require correction. Its official status page showed several services, including the Public API, xPortal, Explorer, Wallet, Bridge and xExchange, as experiencing degraded performance during the incident response. A full technical incident report is expected after investigators complete their work.

Exchange Restrictions Spread

Upbit's action came as multiple exchanges restricted MultiversX transfers following the network disruption.

Bithumb suspended EGLD deposits and withdrawals on Sept. 19 after MultiversX block production stopped. The exchange said transfer services would remain unavailable until it confirmed network stability. Notably, Bithumb had restored EGLD deposits and withdrawals only three days earlier following a scheduled network upgrade, according to a Sept. 16 service notice.

Kraken took a different approach. Its public status page placed EGLD trading pairs into cancel-only mode, allowing users to cancel existing orders while preventing new trades. Deposits and withdrawals remained unavailable on the platform.

Coinbase separately reported delayed EGLD sends and receives beginning Sept. 19 because of the MultiversX network issue. Buying, selling and fiat services were not affected by the transfer disruption.

MultiversX told users not to submit or rebroadcast transactions and advised against moving EGLD or ESDT tokens through exchange deposit and withdrawal routes or cross-chain bridges until the project issues an all-clear.

Review Timeline and Potential Outcomes

The Upbit designation does not immediately remove EGLD from the exchange. Under its digital asset trading-support termination policy, Upbit will review whether the reasons behind the caution notice have been fully resolved before deciding whether to lift the warning, extend the review or end trading support.

The current review period runs from Sept. 21 through the fourth week of October. Upbit identified Oct. 19-23 as the expected decision window, though the review can be extended if further investigation is required. A failure to fully resolve the underlying security concerns could lead to termination of EGLD trading support.

When transfers eventually resume, withdrawals will return first. Deposit support will require a separate announcement after the trading caution review begins. Deposits made after publication of the caution notice cannot be credited normally and fall under Upbit's return process. Since transfer services were already suspended, users remain unable to use standard EGLD deposits or withdrawals.

EGLD declined while the network issue and exchange restrictions developed. CoinGecko historical data show EGLD closing at $4.14 on Sept. 18, before falling to $3.87 on Sept. 19 and $3.78 on Sept. 20. The move represented a decline of roughly 8.7% from the Sept. 18 close.

Trading activity increased during the disruption. CoinGecko recorded approximately $10.18 million in EGLD volume on Sept. 20, compared with roughly $3.35 million on Sept. 18.

Note: Price and volume data sourced from CoinGecko historical records referenced in the incident coverage. The timing places the price decline alongside the security incident and exchange restrictions, though market data alone do not establish that the exploit attempt caused every part of the move.

The episode came shortly after MultiversX activated its Supernova mainnet upgrade, which reduced targeted block time from six seconds to 600 milliseconds and shortened cross-shard settlement. No MultiversX statement reviewed has connected the VM-level atomicity exploit attempt to Supernova, and the upgrade and security incident should not be treated as causally linked without further technical evidence.

For EGLD holders, the immediate priority is monitoring official channels. Upbit has previously updated its stance on tokens as conditions changed, and caution designations can be temporary or can lead to further exchange actions depending on how the underlying situation develops. Until verified statements from MultiversX and the affected exchanges clarify the scope of the incident and the remediation timeline, the full picture remains incomplete.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (1)

Countries (1)

Ransomware Groups (1)