Cardano Temporarily Splits Into Two Chains After Attacker Uses AI-Generated Script to Exploit a Known Bug

Cardano (ADA) News: Network Splits in Two as Attacker Uses AI-Generated Script to Exploit Bug

Markets

Share this article

By Shaurya Malwa

Nov 23, 2025, 12:30 p.m.

(Unsplash)
  • A malformed transaction caused a brief chain split in Cardano, leading to an emergency patch and network-wide upgrade.
  • The incident is under investigation as a potential cyberattack, with a former testnet participant’s wallet identified as the source.
  • Cardano co-founder Charles Hoskinson described the event as a targeted attack by a disgruntled stake-pool operator.

A malformed transaction pushed Cardano into a brief chain split on Saturday, as older and newer node versions validated transaction data submitted to the network differently.

The mismatch caused some block producers to follow a “poisoned” chain while others stayed on the normal one, prompting an emergency patch and network-wide upgrade instructions.

STORY CONTINUES BELOW

Don’t miss another story.Subscribe to the Crypto Daybook Americas Newsletter today.See all newslettersBy signing up, you will receive emails about CoinDesk products and you agree to ourterms of useandprivacy policy.

The incident — which has since been traced to a wallet belonging to a former testnet participant — is being investigated as a potential cyberattack.

Cardano ecosystem governance body Intersect said in a post-mortem report that the divergence emerged when newer nodes accepted a malformed transaction that older nodes rejected.

The inconsistency exploited a bug in an underlying software library that validation logic failed to trap. Once propagated, block producers began building on different branches of the chain, creating what the group called a “poisoned” ledger and a parallel “healthy” chain.

Devs rushed to deploy patched node software, and operators were instructed to upgrade to rejoin the canonical chain.

Exchanges and wallet providers paused deposits and withdrawals throughout the incident as a precaution, though Intersect said no user funds were lost and most retail wallets were insulated because they relied on components that safely ignored the malformed transaction.

Cardano co-founder Charles Hoskinson characterized the event as a targeted, premeditated attack by a disgruntled stake-pool operator who had been seeking ways “to harm the brand and reputation” of Input Output Global (IOG).

He warned the disruption affected all users from block producers losing rewards to DeFi protocols encountering inconsistent state and said restoring full network uniformity could take weeks.

Loading…

Meanwhile, an X user posting as “Homer J.” claimed responsibility, saying he acted alone, did not short or sell ADA, and did not intend to cause harm.

The user said he relied on AI-generated terminal commands to block external traffic while trying to replicate the malformed transaction and only realized the extent of the disruption when block explorers froze.

“I’m ashamed of my carelessness,” he wrote. “I didn’t have evil intentions, but I endangered the network and caused unnecessary stress.”

Loading…

ADA fell more than 6% following the disruption, leading losses among major tokens, as traders likely reacted to the apparent lack of coordinating large-scale upgrades in decentralized proof-of-stake networks.

More For You

By CoinDesk Research

Nov 14, 2025

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence’s Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

By Siamak Masnavi, AI Boost

1 hour ago

Jan van Eck, president and CEO of asset manager VanEck, speaks at Consensus Invest 2018 (CoinDesk)

Jan van Eck questioned whether Bitcoin offers enough encryption and privacy, saying some longtime holders are examining Zcash as the market reassesses long-term assumptions.

What to know:

  • VanEck CEO Jan van Eck questioned whether Bitcoin has “enough encryption” and “enough privacy” in a CNBC interview.
  • Some longtime Bitcoin holders are looking at Zcash’s stronger privacy features, he said.
  • The remarks drew both support from technologists focused on quantum risks and sharp pushback from some long-term (“OG”) Bitcoin advocates.


Sign In 

Leave a Reply

Your email address will not be published. Required fields are marked *