EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

PinGo suffered a second cyber attack-but the truth about the first attack was never revealed

2026-09-09 20:24:07
Bookmark

PinGo suffered a second cyber attack-and the first time was never explained

core points

The AI + DePIN (Decentralized Physical Infrastructure Network) project on the TON network PinGo confirmed that it suffered another cyber attack. Some of the stolen coins have been sold to the market by the attackers.

The

team stated that they had integrated and quarantined the remaining on-chain assets. However, the scale of the loss, the attack vector, and whether user funds have been affected have not been disclosed.

PINGO's daily trading volume is approximately US$15,000. With such weak liquidity, even a small sell-off can cause material damage-the lack of liquidity can be more fatal than the amount.

The most critical word in PinGo declarations is "another".

The second hack is a problem of another nature

A vulnerability can happen to anyone: a smart attacker, an undiscovered Bug, or a bad afternoon. But a second vulnerability in the same project usually means one of two scenarios: the original entry point has never been fixed, or the team has never figured out how the attacker first broke in.

To make matters worse, there are no public records showing PinGo's first incident. There are no PeckShield logs, no SlowMist entries, and no detailed post-mortem reports to consult. The team's own statement is the only basis for admitting the existence of the incident.

If the market is unaware of a project when it is breached, the next attack will not be an accident, but a sequel.

Timeline

  • 2024-Early 2025: PinGo was launched as the first AI + DePIN project on the TON network, aiming to build a market that converts idle computing power into AI model training resources.
  • September 2025: PINGO launched pre-IPO crowdfunding on MEXC, airdropping 120,000 PINGO and 30,000 USDT. Tokens began to be circulated to retail investors and were subsequently launched on Gate, CoinEx and Bitget Wallet.
  • April 2026: PinGo announced a partnership with Manadia to add distributed computing layers and further delve into the field of decentralized AI infrastructure.
  • First attack: Date not publicly confirmed. No loss data, no explanation of reasons, no independent reports. Only exists in PinGo's own expression.
  • September 9, 2026: confirmed the second attack. Assets have been quarantined and attackers are selling. Promise to publish detailed information.

How much was lost?

No one knows. No security company released specific figures.

However, judging from market data, it may be of more reference value for holders. PINGO has a market value of approximately $6 million to $7.5 million. The coin price fell by approximately 93% from its all-time high of $0.4025. According to CoinGecko data, daily trading volume is approximately US$15,000 to US$16,000, and prices_feed_across tracking platforms are divergent (ranging from US$0.02 to US$0.06), indicating outdated data or extremely illiquid.

This is crucial. When attackers sell in such a shallow order book, the value of the stolen dollars becomes almost irrelevant. Even moderate sell-offs can cause sharp price swings. No matter how much the team ultimately recovers, retail owners will suffer the consequences.

The pattern behind

PinGo is not an exception, it is a microcosm of the collapse of the cryptocurrency security system this year.

CertiK's Hack3d report shows that a total of 344 on-chain incidents resulted in the theft of US$1.31 billion in the first half of 2026. The two largest robberies-KelpDAO ($291 million) and Drift Protocol ($285 million, totaling approximately $577 million)-never touched a line of audited contract code. Currently, attacks caused by account leaks account for more than half of all DeFi attacks, surpassing smart contract exploits for the first time.

Throughout industry history, approximately 40% of the $16.69 billion stolen to date can be traced to private key leaks rather than clever code vulnerabilities.

This redefines PinGo's response. "We quarantined assets" is only effective if the problem lies in where the funds are stored. If the entry point is a leaked deployment key or a phishing developer, then moving funds to a new wallet will not solve anything. The vulnerability still exists in a laptop and a login credential.

Conclusion

PinGo took the right action in the first hour-reacting quickly, controlling the situation, and communicating. But what it still has not done is explain why it happened twice and what happened the first time.

Until a full post-mortem analysis report is released,"security isolation" is just a slogan rather than a real solution. With more than a billion dollars lost this year through stolen keys rather than broken code, the key question is not whether assets are stored in a safer place, but whether the people holding them are reliable.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP