At 1:13 AM UTC on Saturday, August 29, 2026, late on Friday night in the US, the Fogo Foundation said an unknown actor had compromised it and 400 million FOGO tokens had been sent to a bad actor.
The blockchain kept running.
The clock had started, though.
Most crypto hacks come with a short window, often measured in hours, when stolen tokens can still be stopped before they get sold.
Here is how exchanges use that window, and what Fogo's weekend showed.
Key Takeaways
Many crypto hacks start with a stolen key or a compromised wallet, so the first job is stopping the thief from cashing out.
MEXC paused FOGO deposits and withdrawals on August 29, 2026, the day the breach was disclosed, and resumed them on September 4.
Of the three pause notices we reviewed, only MEXC's cited the project's request and set a reopening time, and MEXC was the one exchange Fogo's co-founder publicly thanked.
Fogo has recovered 237 million of the 400 million stolen tokens and removed them from supply, as of its September 2 update.
When a project's token is hacked, an exchange's pause on that token is a safety measure, not a sign your balance is gone.
Exchanges are the choke point, since attackers usually need them to sell at size, so pausing deposits and withdrawals buys time.
Fogo is a Layer 1 blockchain built on the Solana Virtual Machine.
The Foundation said an unknown actor "compromised" the organization, and 400 million FOGO ended up with a bad actor.
That is 400 million of a 10 billion total supply, worth roughly $3 million at that day's FOGO price.
The week, in UTC:
Exchange-side pauses, MEXC's included, went up the same day.
Search for "crypto exchange hack" and most results describe an exchange as the victim: a hot wallet drained, withdrawals frozen, customers waiting for answers.
That is one kind of incident.
Fogo was the other kind.
A project or its foundation gets compromised, its token is what gets stolen, and every exchange listing it has to decide what to do.
A breached exchange must secure its own wallets first, then work out what customers are owed.
When a project is hacked, the exchange's job is narrower and faster: close the doors the thief needs to walk through.
Stolen tokens are only worth something once they can be sold, and selling at size almost always means an exchange.
That makes every listing venue a potential first responder, whether or not it knows the project well.
The first move is nearly always the same: pause deposits and withdrawals for the affected token.
Closing deposits stops the attacker from moving stolen coins onto the exchange to sell.
Closing withdrawals stops anything already inside from leaving before the picture is clear.
Trading may keep running, because trades move balances inside the exchange rather than on the chain.
MEXC's help pages list the reasons a token can be paused, and a request from the project team is one of them, alongside maintenance and wallet upgrades.
Most pauses are maintenance, not hacks, and the announcement names the reason.
The real risk during a pause is sending tokens anyway, since a deposit to a closed channel can be delayed or lost.
Every transfer is public, so investigators and exchanges can flag the attacker's addresses within minutes and watch where the coins go.
Flagged coins are hard to sell anywhere that is paying attention.
So thieves often sit on funds for weeks, split them across hundreds of wallets, or push them through mixers and bridges, and every step is another chance to get caught.
Some chains can go further.
Fogo halted its network so validators could upgrade it to restrict the flagged addresses, a drastic step that only works when validators can coordinate quickly.
Recovery then depends on three groups working together: the project, the exchanges holding or watching the coins, and law enforcement.
FOGO trades on more than a dozen venues, and at least three published pause notices on August 29, so the question was never whether exchanges would act.
It was how they did it, and what users could see.
Exchange | Pause notice | Stated reason | Reopening notice | Named in the co-founder's thanks |
MEXC | Aug 29 | Request from the Fogo project team | Yes, dated Sep 4, 10:00 UTC | Yes |
Bitget | | Wallet maintenance | To be announced separately | No |
KuCoin | Aug 29, after the disclosure | Essential maintenance
| Says no further announcement will be issued | No |
Based on each exchange's public notices and Fogo's own updates, as of September 7, 2026.
On the clock, Bitget moved first, roughly an hour before the Foundation's public post, which is consistent with the Foundation's statement that it alerted exchanges immediately.
Speed was not what separated the three, though.
The other two notices cited maintenance rather than the incident: Bitget's said the resumption time would be announced separately, and KuCoin's said users would not be notified when services were restored.
MEXC's notice cited the project team's request on day one and closed the loop with a dated, timed resumption.
It was also the only exchange the project's co-founder singled out in his public thanks.
For a user trying to work out whether a token's outage was a hack, that difference in wording is the whole difference.
The public record is simple.
On August 29, 2026, the day the Foundation disclosed the breach, MEXC announced it had temporarily suspended FOGO deposits and withdrawals at the project team's request.
That pause held through the network halt and the restart.
On September 4, 2026, MEXC announced that deposits and withdrawals would resume at 10:00 AM UTC.
The more telling evidence came from the other side of the table.
On September 4, Fogo co-founder Robert Sagurton posted on X: "Appreciate all the support we got from the CEX's, and special hat tip to @MEXC on their response last weekend."
He said he "hadn't had a lot of experience with them prior," but that MEXC's "responsiveness and professionalism impressed our entire team."
That last line matters: this was not a favor for a long-time partner but standard procedure, run fast, for a project whose co-founder says he had little prior experience with the exchange.
If you hold a token that just got hacked, the pause is protecting you, not trapping you.
Your balance on the exchange is a ledger entry, and it does not move because the chain is under attack.
The price can still drop, but your holdings stay where they are.
Check the announcement center before you touch anything, and never send a token to a deposit address while that token's channel is closed.
Watch for two notices: the suspension and the dated resumption.
If you run a project, the lesson is blunt.
Know who to call at every exchange that lists your token before you need them, because the first hours are decided by who picks up.
Fogo's Foundation said it alerted exchanges immediately, and the pauses went up the same day.
What happened in the Fogo hack?
On August 29, 2026, the Fogo Foundation said it had been compromised and 400 million FOGO had been sent to a bad actor; the chain was halted about 15 hours later and restarted on September 2 with 237 million tokens recovered.
Why do exchanges halt withdrawals after a crypto hack?
A pause keeps stolen tokens from moving onto or off the exchange while the tainted addresses are identified.
How do I know if an exchange outage is a hack?
Check the official announcement center, where every pause states its reason, whether maintenance, a wallet upgrade, or a project team request.
What happens to stolen funds after a crypto exchange hack?
The attacker's addresses are flagged and tracked on-chain, and recovery depends on stopping the coins at a choke point before they are sold.
Can an exchange freeze stolen tokens?
An exchange can pause a token's deposit and withdrawal channels and restrict flagged addresses on its platform, but it cannot reverse blockchain transactions.
What did MEXC do during the Fogo hack?
MEXC suspended FOGO deposits and withdrawals on August 29, 2026, at the project team's request, and resumed them on September 4, 2026.
Which exchanges paused FOGO deposits and withdrawals after the hack?
MEXC, Bitget, and KuCoin all published pause notices on August 29, 2026; MEXC's cited the project's request and later set a reopening time, while the other two cited maintenance.
Are my funds on an exchange affected when a project gets hacked?
Your balance stays intact because it is recorded on the exchange's books, though the token's market price may fall.
What separates a bad weekend from a disaster is whether the people holding the exits move fast.
Fogo's co-founder says MEXC did, and the announcement log backs him up.
The next time a token you hold makes the news, start at the MEXC Announcement Center, where pause and resumption notices are posted.