What Happened to the Stolen FOGO After 237M Tokens Were Removed?
On September 2, 2026, Fogo restarted its mainnet following a security incident. According to disclosures from the project, approximately 400 million FOGO tokens were stolen during the incident. Around 237 million tokens were reportedly recovered and subsequently removed from the circulating supply. Simple arithmetic would leave approximately 163 million tokens, but this figure should only be treated as a rough estimate based on the disclosed numbers rather than an independently verified final amount of outstanding stolen assets.
From an on-chain risk-monitoring perspective, “stolen,” “controlled,” “recovered” and “removed” represent different asset states. When assets move from a legitimate control address to an address associated with an attacker, the blockchain establishes that a transfer occurred, but not necessarily the identity or intent of the controller. If those assets later return to an address controlled by the project, they may be classified as recovered or re-controlled. If they are subsequently permanently removed from supply, their disposition changes again. Treating these different states as one category can result in duplicated calculations or inaccurate risk reporting.
For this reason, post-incident analysis should not stop at a single final number. Compliance and security teams need to maintain records of the source address, receiving address, timestamps, transaction hashes, subsequent destinations and current asset status. Organizing the information along an incident timeline makes it possible to distinguish assets that have been recovered, assets that have been permanently removed, assets that remain under external control and assets whose current status still requires investigation.
How Can KYT Track Stolen FOGO and Separate Recovered Assets From Unresolved Funds?
One of the core functions of KYT is to turn individual blockchain transactions into a traceable flow of funds. In a stolen-asset investigation, analysts can begin with known legitimate control addresses and follow subsequent transfers using block height, timestamps, transaction hashes and token-transfer records. If an attacker distributes the assets across multiple wallets or routes them through intermediary addresses, investigators need to continue mapping the relationships between those addresses rather than monitoring only the original destination.
Recovery creates another important stage in the investigation. When a portion of the stolen tokens returns to an address under project control, the relevant transactions should be incorporated into the incident timeline and the asset status should be updated. If those tokens are subsequently burned or permanently removed from supply, the corresponding transaction should also be recorded. This prevents assets that have already been recovered and processed from being incorrectly counted as unresolved.
KYT can also support continuous monitoring of assets that remain in external wallets. A suspected stolen-asset balance that remains dormant in one address presents a different monitoring situation from funds that suddenly move to an exchange. If previously identified assets are transferred into exchange deposit addresses, cross-chain bridges or other services, the new movement can generate additional investigation signals. The objective is not simply to label an address as “bad,” but to maintain an accurate record of how the asset's risk status changes over time.
Cross-chain movement creates an additional layer of complexity. If stolen assets are bridged, swapped or otherwise transferred into another blockchain environment, monitoring only the original network may leave part of the fund trail unexplained. KYT analysis can combine timestamps, transaction amounts, source and destination addresses and protocol activity to investigate potentially connected movements across different networks.
Why Does KYT Monitoring Need to Continue After a Stolen-Asset Incident?
A mainnet restart, asset recovery or token removal does not necessarily mean that the entire security investigation is complete. Blockchain assets can continue moving long after an incident, and attacker-controlled addresses may remain dormant before becoming active again. Assets whose final status has not been confirmed therefore require ongoing monitoring rather than a one-time investigation.
Risk teams can establish different monitoring rules according to asset status. Tokens confirmed as recovered and permanently removed can remain documented as part of the historical incident record, while assets still associated with external or unknown control can remain under active monitoring. New large transfers, exchange deposits, bridge interactions or transfers into newly created wallets can generate additional alerts for investigation. This approach allows investigators to focus resources on assets that still present an active tracking requirement rather than repeatedly analyzing funds that have already been resolved.
It is also important to distinguish blockchain evidence from identity attribution. Transaction data can establish that a particular address received or transferred a specific amount of FOGO at a particular time, but the transaction itself does not prove the identity of the person or organization controlling that address. KYT can enrich investigations through known-entity labels, historical fund relationships, exchange addresses and other on-chain indicators, but definitive identity attribution may require KYC information, law-enforcement data or other external evidence.
For exchanges, wallet providers, custodians and token projects, major theft incidents demonstrate why KYT should track more than the original loss amount. A complete monitoring framework needs to answer where the assets are now, which addresses they passed through, which portions have been recovered, which have been permanently removed and which assets still require investigation. By maintaining dynamic asset statuses together with continuous fund-flow monitoring, organizations can preserve a more complete risk picture throughout and after a major blockchain security incident.