PinGo suffered a second cyber attack-and the first time was never explained
core points
The AI + DePIN (Decentralized Physical Infrastructure Network) project on the TON network PinGo confirmed that it suffered another cyber attack. Some of the stolen coins have been sold to the market by the attackers.
Theteam stated that they had integrated and quarantined the remaining on-chain assets. However, the scale of the loss, the attack vector, and whether user funds have been affected have not been disclosed.
PINGO's daily trading volume is approximately US$15,000. With such weak liquidity, even a small sell-off can cause material damage-the lack of liquidity can be more fatal than the amount.
The most critical word in PinGo declarations is "another".
The second hack is a problem of another nature
A vulnerability can happen to anyone: a smart attacker, an undiscovered Bug, or a bad afternoon. But a second vulnerability in the same project usually means one of two scenarios: the original entry point has never been fixed, or the team has never figured out how the attacker first broke in.
To make matters worse, there are no public records showing PinGo's first incident. There are no PeckShield logs, no SlowMist entries, and no detailed post-mortem reports to consult. The team's own statement is the only basis for admitting the existence of the incident.
If the market is unaware of a project when it is breached, the next attack will not be an accident, but a sequel.
Timeline
- 2024-Early 2025: PinGo was launched as the first AI + DePIN project on the TON network, aiming to build a market that converts idle computing power into AI model training resources.
- September 2025: PINGO launched pre-IPO crowdfunding on MEXC, airdropping 120,000 PINGO and 30,000 USDT. Tokens began to be circulated to retail investors and were subsequently launched on Gate, CoinEx and Bitget Wallet.
- April 2026: PinGo announced a partnership with Manadia to add distributed computing layers and further delve into the field of decentralized AI infrastructure.
- First attack: Date not publicly confirmed. No loss data, no explanation of reasons, no independent reports. Only exists in PinGo's own expression.
- September 9, 2026: confirmed the second attack. Assets have been quarantined and attackers are selling. Promise to publish detailed information.
How much was lost?
No one knows. No security company released specific figures.
However, judging from market data, it may be of more reference value for holders. PINGO has a market value of approximately $6 million to $7.5 million. The coin price fell by approximately 93% from its all-time high of $0.4025. According to CoinGecko data, daily trading volume is approximately US$15,000 to US$16,000, and prices_feed_across tracking platforms are divergent (ranging from US$0.02 to US$0.06), indicating outdated data or extremely illiquid.
This is crucial. When attackers sell in such a shallow order book, the value of the stolen dollars becomes almost irrelevant. Even moderate sell-offs can cause sharp price swings. No matter how much the team ultimately recovers, retail owners will suffer the consequences.
The pattern behindPinGo is not an exception, it is a microcosm of the collapse of the cryptocurrency security system this year.
CertiK's Hack3d report shows that a total of 344 on-chain incidents resulted in the theft of US$1.31 billion in the first half of 2026. The two largest robberies-KelpDAO ($291 million) and Drift Protocol ($285 million, totaling approximately $577 million)-never touched a line of audited contract code. Currently, attacks caused by account leaks account for more than half of all DeFi attacks, surpassing smart contract exploits for the first time.
Throughout industry history, approximately 40% of the $16.69 billion stolen to date can be traced to private key leaks rather than clever code vulnerabilities.
This redefines PinGo's response. "We quarantined assets" is only effective if the problem lies in where the funds are stored. If the entry point is a leaked deployment key or a phishing developer, then moving funds to a new wallet will not solve anything. The vulnerability still exists in a laptop and a login credential.
Conclusion
PinGo took the right action in the first hour-reacting quickly, controlling the situation, and communicating. But what it still has not done is explain why it happened twice and what happened the first time.
Until a full post-mortem analysis report is released,"security isolation" is just a slogan rather than a real solution. With more than a billion dollars lost this year through stolen keys rather than broken code, the key question is not whether assets are stored in a safer place, but whether the people holding them are reliable.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
TON