Key Takeaways
- PinGo, the AI + DePIN project on the TON network, has confirmed another cyberattack. Some stolen tokens have already been sold into the market by the attacker.
- The team says it consolidated and isolated its remaining on-chain assets. It has not disclosed the loss size, the attack vector, or whether user funds were touched.
- PINGO’s daily volume sits near $15,000. On a book that thin, even a small dump does real damage – the dollar figure may end up mattering less than the liquidity.
The most important word in PinGo’s statement is “another.”

On September 9, 2026, the project told its community it had suffered a fresh cyberattack. It said it moved fast, pulled the remaining on-chain assets together, and locked them away. Internal response procedures are running. Details on the scale of the losses, it said, are coming soon.
That is a reasonable first hour. It is not an answer.
A Second Hack Is a Different Kind of Problem
One breach can happen to anyone. A clever attacker, a missed bug, a bad afternoon. A second breach at the same project usually means one of two things: the original entry point was never closed, or the team never worked out how the attacker got in to begin with.
Here’s what makes it worse. There is no public record of PinGo’s first incident. No PeckShield log, no SlowMist entry, no detailed post-mortem you can pull up and read. The team’s own statement is the only acknowledgement that it happened at all.
If a project can be breached without the market noticing, the next breach isn’t a surprise. It’s a sequel.
The Timeline
- 2024–early 2025 – PinGo launches as the first AI + DePIN project on TON, pitching a marketplace that turns idle computing power into a resource for training AI models.
- September 2025 – PINGO runs a pre-listing Kickstarter on MEXC, with 120,000 PINGO and 30,000 USDT in airdrops. The token reaches retail. Listings follow on Gate, CoinEx and Bitget Wallet.
- April 2026 – PinGo announces a partnership with Manadia to add a distributed compute layer, pushing further into decentralised AI infrastructure.
- First attack – date not publicly confirmed. No loss figure, no cause, no independent reporting. It exists only as a reference in PinGo’s own words.
- September 9, 2026 – Second attack confirmed. Assets isolated. Attacker already selling. Full details promised.
How Much Was Lost?
Nobody has said. No security firm has published a number.
What the market data tells us is arguably more useful for holders. PINGO’s market cap sits somewhere around $6 million to $7.5 million. The token trades roughly 93% below its all-time high of $0.4025. Daily volume is around $15,000–$16,000 on CoinGecko, and price feeds across trackers currently disagree – anywhere from $0.02 to $0.06 – which suggests stale or thin data.
That last point is the one that matters. When an attacker sells into a book this shallow, the dollar value of the theft becomes almost irrelevant. Even a modest dump moves the price hard. Retail holders absorb that regardless of what the team eventually recovers.
The Pattern Behind It
PinGo isn’t an outlier. It’s a symptom of how crypto security broke this year.
CertiK’s Hack3d report counted $1.31 billion stolen across 344 on-chain incidents in the first half of 2026. The two largest heists – KelpDAO at $291 million and Drift Protocol at $285 million, roughly $577 million combined – never touched a line of audited contract code. Compromised accounts now cause more than half of all DeFi attacks by incident count, overtaking smart contract exploits for the first time.
Across the industry’s entire history, about 40% of the $16.69 billion ever stolen traces back to compromised private keys, not clever code.
That reframes PinGo’s response. “We isolated the assets” only helps if the problem was where the money sat. If the entry point was a leaked deployment key or a phished developer, then moving funds to a fresh wallet fixes nothing. The vulnerability still has a laptop and a login.
Conclusion
PinGo did the right things in the first hour – move fast, contain, communicate. What it still hasn’t done is explain how this happened twice, or what happened the first time at all.
Until a proper post-mortem lands, “secure isolation” is a phrase, not a fix. And in a year where over a billion dollars walked out through stolen keys rather than broken code, the question isn’t whether the assets are somewhere safer. It’s whether the person holding them is.
Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

