aelf Is Back Online After 7 Days Dark, But a Week of Staking Rewards Is Gone for Good
aelf restarted block production and brought back its public nodes, explorer and DAO interface after a week-long halt triggered by malicious contract activity. But the halt generated zero staking rewards, exchange access still varies by venue, and the full root-cause report isn't published yet. Here's what that actually means for your bags.
So aelf is back online. Does that mean your bags are safe?
Short answer, sort of. Longer answer, the chain is producing blocks again, the frontends load, and you still shouldn't trust any of it until the post-mortem drops. Anon, let me save you some gas fees.
The raw numbers on aelf's seven-day blackout
Here's what we know. aelf, the network that runs its AELF MainChain alongside a tDVV dAppChain, went dark for roughly one week. Not slow blocks. Not congestion. Block production stopped outright after malicious smart contract activity, and the team pulled a controlled recovery.
Then on Sept 14, the recovery update landed. Both public nodes came back. So did aelfscan, FairyVault transfers, Awaken trading, Forest NFT browsing, and the TMRW DAO staking interface.
By Sept 15, the MainChain and tDVV chain status endpoints were reachable and block heights were climbing. That's the good news.
Here's the catch. Nobody ran an end-to-end transfer, a trade, or a reward claim during those checks. Advancing block height proves the engine turns over. It doesn't prove you can move your money.
Now the staking part, and this one stings. aelf generated zero network staking rewards during the halt. Zero. Restoring the TMRW DAO interface doesn't conjure them back. There's nothing from that week to claim. The UI is a door to an empty room.
The Aug 26 incident update gives us the numbers that actually matter. Investigators identified 155 transactions tied to the malicious activity. 127 on AELF. 28 on tDVV. They also found five unique.NET assemblies capable of touching host systems plus node-related keys and configuration.
That last bit is the scary one. That's not a bad smart contract. That's infrastructure-level access.
Why node access changes the whole risk math
Most degen incidents live at the contract layer. Someone writes a bad function, someone else finds it, liquidity drains, we all post screenshots. That's a Tuesday.
This was different. Assemblies that can interact with host systems and node keys mean the blast radius was potentially the machines running the network, not just the code sitting on top of it.
And to be fair to aelf, the team never claimed those capabilities were executed. They said it doesn't prove every payload ran, every targeted credential got grabbed, or data actually left the building. Their evidence review turned up no unauthorized transfers of ordinary user assets and no exposed user wallet keys as of Aug 26.
But. And this is a big but. That conclusion carved out node and infrastructure credential exposure. So the clean bill of health covers your wallet. It doesn't cover the machines that decide which blocks exist.
Compare that to the other chains that have yanked the emergency brake over the past year. Stopping a network buys you time to think. It doesn't buy your funds back, and it doesn't un-leak a private key. The halt was the right call. It just isn't a security fix.
Anyone treating a chain restart as a clean slate is reading the wrong document.
The exchange situation is messier than the blog post suggests
Deposits and withdrawals are resuming gradually and they differ by venue. Which means you check your own exchange before you touch anything. Not Twitter. Not the aelf blog. Your exchange.
Bithumb scheduled ELF deposits and withdrawals back on for Sept 14 at 14:00 KST. MEXC said Sept 5 and warned users to generate brand new deposit addresses because the old ones are invalid. If you sent ELF to a stale MEXC address, that's a support ticket, not a trade.
INDODAX is a different story. Its Sept 2 notice still described ELF wallet deposits and withdrawals as closed. That notice is dated, so it might just be stale. But the trench rule is simple. Assume nothing, verify everything, and don't move size until the venue says green.
This is the alpha nobody is sharing. Restored nodes are a team announcement. Restored exchange access is a separate, venue-by-venue grind that nobody wants to put on a chart.
What to watch from here
Three things.
First, the full post-incident review. aelf says the technical appendix and final root-cause assessment are still unpublished, pending remaining work plus an independent review. Until that lands, everything above is operational progress, not a security all-clear. Read that document the way you'd read a token contract. The details are where the risk lives.
Second, watch whether transactions actually settle. There's a real difference between a chain minting blocks and a chain confirming transfers. Test with dust first. Always.
Third, watch TVL and volume on Awaken and FairyVault. If liquidity snaps back fast, the market is shrugging. If it trickles, the whales are waiting on that independent review too, and they're usually right about timing.
My take, and it's a hot one. A one-week halt from a network-level compromise is a bigger red flag than most traders are pricing. Not because aelf did anything wrong. Because the failure mode was deep. Five assemblies touching host systems isn't a bug story, it's an intrusion story. I'm not market-buying this dip. I'd rather pay more later for a chain with a published root-cause doc and one exchange confirmation I can actually screenshot.
The trenches don't sleep. But apparently the trench rewards took a week off.