At 1:13 AM UTC on Saturday, August 29, 2026, late on Friday night in the US, the Fogo Foundation said an unknown actor had compromised it and 400 million FOGO tokens had been sent to a bad actor.
The blockchain kept running.
The clock had started, though.
Most crypto hacks come with a window, often a short one, when stolen tokens can still be stopped before they get sold.
Here is how project teams and exchanges use that window, and what the Fogo case showed.
Key Takeaways
- Many crypto hacks start with a stolen key or a compromised wallet, so the first job is stopping the thief from cashing out.
- When a project is hacked, its team is the first responder, and exchanges assist by acting quickly on the information the team provides.
- Pausing deposits is the primary step, since it keeps stolen tokens from entering an exchange to be sold; pausing withdrawals is a secondary step that keeps compromised funds in place and easier to trace.
- At the Fogo team's request, MEXC suspended FOGO deposits and withdrawals on August 29, 2026, restricted the accounts linked to the addresses the team submitted, and followed up with a stolen asset report and law enforcement request.
- Fogo has recovered 237 million of the 400 million stolen tokens and removed them from supply, as of its September 2 update.
- Fogo's co-founder publicly credited MEXC's responsiveness and professionalism despite little prior experience with the exchange.
Fogo is a Layer 1 blockchain built on the Solana Virtual Machine.
The Foundation said an unknown actor "compromised" the organization, and 400 million FOGO ended up with a bad actor.
That is 400 million of a 10 billion total supply, worth roughly $3 million at that day's FOGO price.
The sequence, in UTC:
August 29: At the project team's request, MEXC suspends FOGO deposits and withdrawals, restricts the accounts linked to the addresses the team submitted, and begins the stolen asset report and law enforcement request process.
MEXC's pause went up the same day the breach was disclosed.
Search for "crypto exchange hack" and most results describe an exchange being breached: a hot wallet drained, withdrawals frozen, customers waiting for answers.
That is one kind of incident.
Fogo was the other kind.
A project or its foundation gets compromised, its token is what gets stolen, and the exchanges listing it are asked to help contain the damage.
In both cases, the people at risk are users, which is why the response has to start fast.
When a project is hacked, the project team is the first responder: it confirms what happened, informs its partners and community, and sends exchanges the addresses involved.
Exchanges are the second responder, assisting where they can: pausing deposits, restricting accounts linked to those addresses, and reporting any stolen funds that reached the platform.
Stolen tokens are only worth something once they can be sold, which is why that hand-off from project team to exchange matters so much.
What an exchange does depends on the situation and on what the project team asks for, but the primary step is pausing deposits for the affected token.
Pausing deposits keeps more stolen tokens from entering the exchange, and keeps the attacker from depositing them to sell.
Pausing withdrawals is a secondary step, not always necessary, that keeps compromised funds from moving on to other platforms and makes it easier for the project team to trace where they went.
Trading may keep running, because trades move balances inside the exchange rather than on the chain.
MEXC's help pages list the reasons a token can be paused, and a request from the project team is one of them, alongside maintenance and wallet upgrades.
Most pauses are maintenance, not hacks, and the announcement names the reason.
The real risk during a pause is sending tokens anyway, since a deposit to a closed channel can be delayed or lost.
Every transfer is public, so investigators and exchanges can flag the attacker's addresses within minutes and watch where the coins go.
Flagged coins are hard to sell anywhere that is paying attention.
So thieves often sit on funds for weeks, split them across hundreds of wallets, or push them through mixers and bridges, and every step is another chance to get caught.
Some chains can go further.
Fogo halted its network so validators could upgrade it to restrict the flagged addresses, a drastic step that only works when validators can coordinate quickly.
Recovery then depends on three groups working together: the project, the exchanges holding or watching the coins, and law enforcement.
Hacks have been frequent this year, and they rarely land during business hours.
Exchanges do not run the investigation; the project team does.
What an exchange can do is act quickly on what the team sends, and that assistance usually follows the same order.
- Pause deposits for the token, and withdrawals too if the team asks, while the team investigates.
- Restrict the accounts linked to the addresses the team submits, so any stolen funds that arrived cannot be traded out.
- File a stolen asset report for funds that reached the exchange, and work through the law enforcement request that follows.
- Share what the pause and the restrictions show, so the team can trace where the rest of the tokens went.
- Reopen when the project team confirms it is safe.
None of this needs a long relationship with the project.
It needs a clear request, the addresses involved, and an exchange team that picks up quickly.
Here is what MEXC did, in order.
On August 29, 2026, the day the Foundation disclosed the breach, MEXC suspended FOGO deposits and withdrawals at the project team's request while the team investigated.
MEXC also restricted the accounts linked to the addresses the Fogo team submitted, then followed up with a stolen asset report for the funds that had reached the exchange and with the law enforcement request that followed.
The pause stayed in place through the network halt and restart, and MEXC resumed FOGO deposits and withdrawals on September 4, 2026.
The more telling evidence came from the other side of the table.
On September 4, Fogo co-founder Robert Sagurton posted on X: "Appreciate all the support we got from the CEX's, and special hat tip to @MEXC on their response last weekend."
He said he "hadn't had a lot of experience with them prior," but that MEXC's "responsiveness and professionalism impressed our entire team."
That last line matters: this was not a favor for a long-time partner but standard procedure, run fast, for a project whose co-founder says he had little prior experience with the exchange.
If you hold a token that just got hacked, the pause is protecting you, not trapping you.
Your balance on the exchange is a ledger entry, and it does not move because the chain is under attack.
The price can still drop, but your holdings stay where they are.
Check the announcement center before you touch anything, and never send a token to a deposit address while that token's channel is closed.
Watch the announcement center for the pause notice and for any update on when the channel reopens.
If you run a project, the most useful thing you can do is reach your exchange partners quickly with the addresses involved, so they can start assisting right away.
Fogo's Foundation said it alerted exchanges immediately, and the pauses went up the same day.
What happened in the Fogo hack?
On August 29, 2026, the Fogo Foundation said it had been compromised and 400 million FOGO had been sent to a bad actor; the chain was halted about 15 hours later and restarted on September 2 with 237 million tokens recovered.
Why do exchanges halt withdrawals after a crypto hack?
Not always, and not every exchange: a withdrawal pause is a secondary step, taken at the project team's request, that keeps compromised funds from moving to other platforms while they are traced.
How do I know if an exchange outage is a hack?
Check the official announcement center, where a pause notice states its reason, whether maintenance, a wallet upgrade, or a project team request.
What happens to stolen funds after a crypto exchange hack?
The attacker's addresses are flagged and tracked on-chain, and recovery depends on stopping the coins at a choke point before they are sold.
Can an exchange freeze stolen tokens?
An exchange can pause the token's deposit channel and restrict accounts linked to the addresses a project team reports, but it cannot reverse transactions on the blockchain itself.
What did MEXC do during the Fogo hack?
At the Fogo team's request, MEXC suspended FOGO deposits and withdrawals on August 29, 2026, restricted accounts linked to the addresses the team submitted, followed up with a stolen asset report and law enforcement request, and resumed deposits and withdrawals on September 4, 2026.
Are my funds on an exchange affected when a project gets hacked?
Your balance stays intact because it is recorded on the exchange's books, though the token's market price may fall.
What limits the damage is a fast hand-off: a project team that reaches its partners quickly, and exchanges that act on the information they are given.
Fogo's co-founder says MEXC did exactly that.
The next time a token you hold makes the news, start at the MEXC Announcement Center, where pause and resumption notices are posted.