CoinYQ Dossier

The application chains stayed separate until recovery became shared

aelf was built around a simple wager: applications should not all wait in the same execution line. Its C# MainChain would index separate application chains, while ELF voters chose the operators who kept them moving. The August 2026 incident tested the part of that wager that was still shared.

A MainChain was asked to coordinate, not host everything

When aelf's plan was presented to investors on December 10, 2017, the proposed escape from shared-chain congestion was structural. A public testnet followed in 2018 and the MainChain launched in 2020. Applications could run on their own chains while sending block information back for indexing, so one busy product did not have to occupy the same execution queue as every other product.

That arrangement gave ELF two linked jobs. It paid for ordinary transactions and for application-chain indexing, and it carried votes for producer and candidate nodes. Holders chose the operators, but the documented Parliament process gave those operators the proposal machinery: producers submitted proposals, then producers and candidates voted on them.

Supply changes recorded migration as well as issuance

The first scheduled halving arrived on December 12, 2024 and reduced the MainChain reward from 0.125 to 0.0625 ELF per block. It changed new issuance within the published maximum of one billion ELF.

The next large number told a different story. On January 18, 2025, aelf reported burning 295,519,800 ERC-20 ELF that had been deposited during the Mainnet swap. Those Ethereum tokens represented assets already moved toward the native network, so the burn cleaned up a legacy representation; it did not erase 295,519,800 native ELF from users.

The first alert was only a preliminary diagnosis

On August 18, 2026, internal monitoring detected an unauthorized anomalous contract that appeared to attempt overflow and privilege escalation. aelf instructed every block producer to pause, began a hotfix and brought in an external auditor. The halt covered AELF MainChain and the tDVV application chain, turning the producer election from an abstract governance path into an operational emergency response.

That first notice did not settle the cause. The August 26 progress report described a more specific route: transaction parameters could deliver encoded .NET assemblies and instructions into the node contract-execution path. It linked 155 transactions to the activity—127 on AELF and 28 on tDVV—and reduced the payload set to five unique assemblies.

The investigation separated capabilities from proven impact

The five payloads could execute host commands, collect results, attempt outbound communication, access node-related key and configuration objects, and inspect infrastructure. aelf did not say that every payload ran on every node, that every targeted credential was obtained, or that sensitive data left the environment. Those questions remained with host, cloud, identity and network forensics.

Within the on-chain activity and wallet-key evidence reviewed by August 26, aelf found no evidence of unauthorized transfers from ordinary users or exposure of ordinary-user wallet keys. It simultaneously treated node signing keys and infrastructure credentials as potentially exposed and continued rotating or revoking them. The narrower user finding therefore cannot be expanded into a claim that every asset or credential was safe.

Public query endpoints could answer while production was still closed. The report said public transaction submission remained disabled and listed unfinished recovery gates: clean node rebuilds, key rotation, deterministic replay, permanent runtime isolation fixes and independent review. The latest official blog index examined through September 5 showed no later public completion report. The lasting consequence was specific: application workloads had been separated, but the software boundary and the elected response that restored them were still shared.

How the project changed

  1. 2017-12-10
    The plan reaches investors

    aelf's vision and plans were presented to investors; the reviewed official sources do not identify Auric Ma as the presenter.

  2. 2018
    Public testnet

    The C# multi-chain design became available on a public test network.

  3. 2020
    MainChain launch

    Native ELF and MainChain indexing entered production.

  4. 2024-12-12
    First halving

    The reward per block fell from 0.125 to 0.0625 ELF.

  5. 2025-01-18
    Legacy representation burned

    aelf reported burning 295,519,800 ERC-20 ELF deposited through the Mainnet swap.

  6. 2026-08-18
    AELF and tDVV paused

    aelf instructed block producers to stop after detecting anomalous unauthorized contract activity; its description was preliminary.

  7. 2026-08-26
    Investigation defines the scope

    The progress report counted 155 associated transactions and five unique .NET payloads, while leaving execution, credential access and exfiltration questions open.

Evidence and primary sources

Last evidence review: 2026-09-05

What is aelf?

aelf is a C# Layer 1 whose MainChain indexes application-specific chains. The plan was presented to investors on December 10, 2017, followed by a public testnet in 2018 and MainChain launch in 2020. ELF pays transaction and indexing fees and lets holders vote for block producers and candidate nodes. Native ELF lives on aelf; ERC-20 and BEP-20 versions are representations used across other networks.

What problem does aelf solve?

The original design tried to keep unrelated applications from competing in one execution queue. Separate application chains could choose their own workloads while the MainChain supplied indexing and a shared route between them. That removed one kind of congestion but created another dependency: every application chain still relied on node software, cross-chain indexing and an elected producer set. In August 2026, malicious contract activity reached that shared operational boundary and both AELF MainChain and tDVV entered controlled recovery.

How does aelf work?

ELF pays for MainChain transactions and for indexing application-chain blocks. Holders stake votes behind producer and candidate nodes; block producers submit Parliament proposals, and producers plus candidates vote to approve, reject or abstain. The published maximum is 1,000,000,000 ELF. On December 12, 2024, the first halving cut the block reward from 0.125 to 0.0625 ELF. The January 2025 destruction of 295,519,800 ERC-20 ELF removed tokens deposited during the Mainnet swap, so it should not be described as an equal burn of native MainChain balances. In an emergency, the elected operators can also coordinate a stop: on August 18, 2026, aelf instructed all producers to pause while it investigated anomalous contract activity.

Key facts

  • aelf's plan was presented to investors on 2017-12-10; the public testnet followed in 2018 and MainChain in 2020.
  • The C# MainChain indexes application-specific chains rather than placing every workload in one execution queue.
  • ELF pays transaction and indexing fees, and holders use it to vote for block producers and candidate nodes.
  • Holders elect nodes; producers submit Parliament proposals, and producers plus candidate nodes vote on them.
  • aelf documents a 1,000,000,000 ELF maximum. The 2024-12-12 halving reduced the reward from 0.125 to 0.0625 ELF per block.
  • On 2025-01-18, 295,519,800 ERC-20 ELF held from the Mainnet swap were burned; this was not the same as burning that quantity of native ELF balances.
  • The August 26 report linked 155 transactions to the incident: 127 on AELF and 28 on tDVV, with five unique .NET payload assemblies.
  • Payload capabilities were observed, but execution on every node, credential acquisition and exfiltration were not proven.
  • The August 26 report found no evidence of unauthorized ordinary-user transfers in its reviewed scope, while treating node and infrastructure credentials as potentially exposed.
  • As of that report, public transaction submission was disabled and production services had not formally reopened; no later public completion report was found in the official blog index reviewed through September 5.

Official links

Categories

Related coins

Frequently asked questions

Why does aelf use application chains?

They let unrelated applications run in separate execution environments while the MainChain indexes their blocks. This can isolate workload pressure, although cross-chain indexing and common node operations remain shared dependencies.

What does ELF do?

ELF pays transaction and application-chain indexing fees. Holders also use it to vote for block producers and candidate nodes.

Do all ELF holders vote directly on protocol proposals?

Not in the documented Parliament path. Holders choose producer and candidate nodes; block producers submit proposals, and producers plus candidate nodes vote approve, reject or abstain.

What changed at the first halving?

On December 12, 2024, the MainChain block reward fell from 0.125 to 0.0625 ELF. aelf documents a maximum supply of 1,000,000,000 ELF.

What was the 295,519,800 ELF burn?

It was a January 18, 2025 burn of ERC-20 ELF deposited during the Mainnet swap. It removed a legacy representation from Ethereum; it was not an equal deletion of native user balances on the MainChain.

What did investigators confirm about the August 2026 incident?

By August 26 they had associated 155 transactions with the activity—127 on AELF and 28 on tDVV—and deduplicated five .NET payload assemblies. The payloads had dangerous capabilities, but the report did not prove that each ran on every node or that credentials or data were successfully taken.

Were ordinary users' assets or keys stolen?

The August 26 report said its review had found no evidence of unauthorized ordinary-user transfers or exposure of ordinary-user wallet keys. That conclusion was limited to the evidence reviewed and did not cover the unresolved possible exposure of node and infrastructure credentials.

Had aelf reopened after the pause?

As of the August 26 progress report, production networks had not formally reopened and public transaction submission was disabled. The official blog index reviewed through September 5 contained no later public completion report, which does not establish the state of every private operational channel.

External trackers

Choose a tracking site for aelf: