Cardano’s mainnet experienced a rare chain partition on November 21, 2025 after a malformed staking-delegation transaction exploited a long-standing deserialization bug, briefly producing a “poisoned” branch containing the transaction and a parallel healthy branch that rejected it. The network continued producing blocks on both sides until emergency node upgrades restored convergence later that day; Intersect […]Cardano’s mainnet experienced a rare chain partition on November 21, 2025 after a malformed staking-delegation transaction exploited a long-standing deserialization bug, briefly producing a “poisoned” branch containing the transaction and a parallel healthy branch that rejected it. The network continued producing blocks on both sides until emergency node upgrades restored convergence later that day; Intersect […]

Cardano Attack Sparks Clash: Hoskinson Invokes Feds, Solana Chief Objects

2025/11/24 15:30
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Cardano’s mainnet experienced a rare chain partition on November 21, 2025 after a malformed staking-delegation transaction exploited a long-standing deserialization bug, briefly producing a “poisoned” branch containing the transaction and a parallel healthy branch that rejected it. The network continued producing blocks on both sides until emergency node upgrades restored convergence later that day; Intersect said no user funds were lost and that a CIP-135 disaster-recovery playbook was prepared but ultimately not needed.

Should Cardano’s Attacker Face The Feds?

What turned a technical postmortem into an industry flashpoint was the public fallout between Cardano founder Charles Hoskinson and Solana co-founder Anatoly Yakovenko over whether the incident should be treated as a federal crime.

Yakovenko opened by praising the protocol behavior rather than the politics: “I am gonna go out on a limb and actually say this is pretty cool. Nakamoto style consensus without proof of work is extremely hard to build. The protocol functioned as designed in the presence of bugs.” He was reacting to Berry Ales’ observation that Cardano “recovered from a minority chain and got rid of the symptom while preserving most of the history and progress since the incident.” Hoskinson replied tersely: “Thanks man. It was a wild day.”

The exchange sharpened when Yakovenko framed exploit traffic as inherent to permissionless networks and warned against involving law enforcement. “Communicating arbitrary bits is fundamentally speech, even if they break the receiver,” he wrote. “The fact that it’s not always the case in the US is lame. Don’t send the feds after the poor guy who f’d up vulnerability disclosure.”

Hoskinson’s counterclaim was that this was not disclosure at all. “It was a premeditated attack by a disgruntled SPO with extensive knowledge of Cardano and who had already observed the testnet fork, the patch efforts, and was in direct contact with the core devs,” he said. According to Hoskinson, the attacker watched the Preview testnet incident, waited through patching efforts, then reproduced it on mainnet.

“We spent hours studying it, reconstructing for mainnet, and then delegating to my personal pool Rats as a message. He only admitted this act after I doxed him in a video then claiming it was a terrible mistake, but somehow neglected to mention it during the entire day while we were fixing it.”

He then argued that intentional exploitation of public infrastructure crosses into criminal territory: “Blackhats exploiting bugs to cause harm to public infrastructure is not a new thing. Its a federal crime because of the catastrophic harm to society such acts could carry. Cardano is a large network and many people derive their entire livelihood from the network’s operation. He hurt every single person in our ecosystem.”

Yakovenko accepted the ugliness of blackhat behavior but maintained that legal escalation is strategically risky in open systems. “Yea. I get it. We have had shitheads that watch public branches for any bug fixes and try to exploit them immediately. It’s a huge pia. Any potential bugs have to be fixed in private and rolled out p2p patches first. It has a chilling effect on the industry if you call in the Feds.” In his “mental model,” if operators run “a system that accepts arbitrary public messages, they are taking on the risk of what happens with any message they receive,” and only permissioned systems with explicit liability framing should be regulated as such.

Hoskinson pressed that model against the realities of regulated finance and cross-chain norms. “Furthermore, are you going to tell all the regulated financial entities that are building on Solana that if they lose money from hackers while using Solana, they shouldn’t file a criminal complaint?” He followed with a direct hypothetical: “So if a blackhat found an exploit in solana and it forked the network resulting in huge losses for your defi community, they should accept its a risk of solana and the blackhat did nothing wrong? What is the remedy?”

Yakovenko’s answer separated moral blame from deterrence. “The blackhat is an absolute piece of shit. The remedy is that we need multiple implementations and formal verification to minimize the risk of that happening… We have to make it impossible.” In his view, prosecution is not a reliable control because serious attackers do not expect to be caught, so resilience must come from engineering redundancy and verification, not the threat of the state.

Intersect’s incident report says the wallet responsible for the malformed transaction has been identified and that authorities including the FBI are being engaged. The immediate Cardano story is a fast-patched validation mismatch that re-converged without rollback. The bigger story is a live, founder-to-founder clash over whether permissionless security failures are primarily a matter for protocol design or criminal law—and what precedent the answer sets for every PoS network, Solana included.

At press time, ADA traded at $0.41.

Cardano price
시장 기회
Clash 로고
Clash 가격(CLASH)
$0.018657
$0.018657$0.018657
-0.22%
USD
Clash (CLASH) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!