Markets Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Cardano Temporarily Splits Into Tw Markets Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Cardano Temporarily Splits Into Tw

Cardano Temporarily Splits Into Two Chains After Attacker Uses AI-Generated Script to Exploit a Known Bug

Share
Share this article
Copy linkX (Twitter)LinkedInFacebookEmail

Cardano Temporarily Splits Into Two Chains After Attacker Uses AI-Generated Script to Exploit a Known Bug

The divergence emerged when newer nodes accepted a malformed transaction that older nodes rejected.

By Shaurya Malwa
Nov 23, 2025, 12:30 p.m.

What to know:

  • A malformed transaction caused a brief chain split in Cardano, leading to an emergency patch and network-wide upgrade.
  • The incident is under investigation as a potential cyberattack, with a former testnet participant's wallet identified as the source.
  • Cardano co-founder Charles Hoskinson described the event as a targeted attack by a disgruntled stake-pool operator.

A malformed transaction pushed Cardano into a brief chain split on Saturday, as older and newer node versions validated transaction data submitted to the network differently.

The mismatch caused some block producers to follow a “poisoned” chain while others stayed on the normal one, prompting an emergency patch and network-wide upgrade instructions.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
Sign me up

The incident — which has since been traced to a wallet belonging to a former testnet participant — is being investigated as a potential cyberattack.

Cardano ecosystem governance body Intersect said in a post-mortem report that the divergence emerged when newer nodes accepted a malformed transaction that older nodes rejected.

The inconsistency exploited a bug in an underlying software library that validation logic failed to trap. Once propagated, block producers began building on different branches of the chain, creating what the group called a “poisoned” ledger and a parallel “healthy” chain.

Devs rushed to deploy patched node software, and operators were instructed to upgrade to rejoin the canonical chain.

Exchanges and wallet providers paused deposits and withdrawals throughout the incident as a precaution, though Intersect said no user funds were lost and most retail wallets were insulated because they relied on components that safely ignored the malformed transaction.

Cardano co-founder Charles Hoskinson characterized the event as a targeted, premeditated attack by a disgruntled stake-pool operator who had been seeking ways “to harm the brand and reputation” of Input Output Global (IOG).

He warned the disruption affected all users from block producers losing rewards to DeFi protocols encountering inconsistent state and said restoring full network uniformity could take weeks.

Loading...

Meanwhile, an X user posting as “Homer J.” claimed responsibility, saying he acted alone, did not short or sell ADA, and did not intend to cause harm.

The user said he relied on AI-generated terminal commands to block external traffic while trying to replicate the malformed transaction and only realized the extent of the disruption when block explorers froze.

“I’m ashamed of my carelessness,” he wrote. “I didn’t have evil intentions, but I endangered the network and caused unnecessary stress.”

Loading...

ADA fell more than 6% following the disruption, leading losses among major tokens, as traders likely reacted to the apparent lack of coordinating large-scale upgrades in decentralized proof-of-stake networks.

Cardano

More For You

Protocol Research: GoPlus Security

Commissioned byGoPlus

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
View Full Report

More For You

VanEck CEO Concerned About Bitcoin's Encryption and Privacy, Says Firm Could Walk Away

Jan van Eck questioned whether Bitcoin offers enough encryption and privacy, saying some longtime holders are examining Zcash as the market reassesses long-term assumptions.

What to know:

  • VanEck CEO Jan van Eck questioned whether Bitcoin has “enough encryption” and “enough privacy” in a CNBC interview.
  • Some longtime Bitcoin holders are looking at Zcash’s stronger privacy features, he said.
  • The remarks drew both support from technologists focused on quantum risks and sharp pushback from some long-term ("OG") Bitcoin advocates.
Read full story
Latest Crypto News

VanEck CEO Concerned About Bitcoin's Encryption and Privacy, Says Firm Could Walk Away

Bitcoin's Plunge Brings Strategy's Holdings to Near Breakeven, but Key Test Lies 18 Months Ahead

XRP Drops With Market as Bitcoin Weakness Pulls Altcoins Into Oversold Territory

As DATs Face Pressure, Institutions Could Soon Look to BTCFi for Their Next Strategic Shift

Coinbase to Add 24/7 Trading for SHIB, Bitcoin Cash, Dogecoin, and Others

Top Stories

Hobbyist Miner Beats "1 in 180 Million Odds" to Win $265K Bitcoin Block Using Just One Old ASIC

Is Strategy Stock the Preferred Hedge Against Crypto Losses? Tom Lee Thinks So

Turning ‘$11K to Half a Billion Dollars From Trading Memecoins’: Tales From a Crypto Wealth Manager

'Liquidity Crisis': $12B in DeFi Liquidity Sits Idle as 95% of Capital Goes Unused

Coinbase 'Negative Premium' at Widest Level since Q1, Signalling Weak U.S. Demand

Aerodrome Finance Hit by 'Front-End' Attack, Users Urged to Avoid Main Domain

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.