← Back to insights

“Our Two RPCs Show Different Heights. Risk Won’t Reopen Withdrawals Yet.”

A paused chain creates endless ETA questions. A mismatched block height, a reopening gate, and a named approver reveal the message an infrastructure seller should read twice.

A fictional illustrative Telegram scenario shows two RPC endpoints at different heights and withdrawals closed pending risk approval
#Ontology mainnet#RPC services#Node operations#Incident recovery#Telegram prospecting

Signals to watch

  • A team names what is still wrong after the pause, such as RPC height disagreement, an indexer mismatch, or an upgrade that has not been rehearsed
  • A wallet, exchange, risk, security, or operations owner says what must happen before deposits, withdrawals, signing, or another function can reopen
  • The message includes a test, report, stable-block window, or deadline that turns general urgency into a checkable job

At 08:47, three Web3 Telegram groups light up at once.

“Ontology mainnet is paused. Any ETA?”

“Does this mean every wallet should disable deposits and withdrawals?”

“Our two RPC endpoints show different block heights. Risk wants a consistency report before it will reopen withdrawals.”

If you sell RPC access, node operations, blockchain monitoring, wallet or exchange integration, which message deserves a closer look?

The third one.

The first two are reasonable questions, but they reveal no work for an outside provider. The third message names something that is wrong, a report that is needed, and a business operation that cannot reopen without it.

Every Telegram-style message, person, company, and work scene in this article is fictional and representative. None is a customer quote. The public Ontology notices are real; the group messages are examples of what a seller might see around an incident.

“Before we reopen” changes the meaning of a message

During a chain pause, almost everyone asks when the network will return. That is not surprising, and it is not a sales signal by itself.

The language worth noticing often comes after the word before:

  • “before we reopen withdrawals”
  • “before the wallet enables transfers”
  • “before operations signs the upgrade”
  • “before the indexer is trusted again”

That phrase tells you a team has its own gate. Even if block production resumes, somebody inside the company still needs evidence before the product can return to normal.

For a seller, that is a much more useful starting point than “the chain is down.” You can ask what evidence is missing, who needs it, and what happens if it does not arrive.

What happened, in plain language

Ontology’s public status changed between two official notices.

On 31 August, Ontology announced an immediate mainnet pause. Block production stopped and on-chain transactions would not be processed during the pause. At that time, the company said it had not identified a confirmed security incident and saw no indication that user assets had been lost or compromised.

Ontology's initial notice showing the immediate mainnet pause, the status at that time, and the user-asset boundary The first notice records what Ontology knew at that time. It does not mean the investigation later found nothing.

On 1 September, Ontology published a second update. It said the investigation had identified malicious attack activity targeting the network. It also said user assets were not involved or compromised.

Ontology's later update confirming malicious activity targeting the network while stating that user assets were not affected The second notice changes the incident status while keeping the stated user-asset boundary.

Ontology said the network would remain paused while it deployed an upgrade, checked network integrity and stability, and carried out testing. It set a goal of restoring operations within the next 24 hours, but only if the required checks, repair work, and upgrade procedures succeeded. That was a target, not a promised restart time.

Ontology's later notice listing upgrade and verification work and making the 24-hour restoration goal conditional The 24-hour statement was conditional. It should not be repeated to a prospect as a guaranteed deadline.

Those facts help you speak accurately. They do not tell you which exchange has a stuck indexer, which wallet has disabled transfers, or which node operator lacks an upgrade environment. That information appears inside each team’s own conversation.

The useful message usually contains three parts

When a chain incident is moving quickly, look for a message that combines a failure, a gate, and an owner.

Something is still wrong

“The network is paused” describes a public event. A team-specific problem sounds different:

“Our primary RPC says block 18,420,510, but the backup is 17 blocks behind.”

RPC means the connection a wallet or application uses to read chain data and send transactions. If two RPC endpoints return different heights, the team may not know which view to trust yet.

Other examples are equally ordinary:

“The explorer is caught up, but our deposit balances still do not match yesterday’s snapshot.”

“The validator upgrade is ready, but we have never tested the rollback.”

“Reads work again; transaction submission still fails in the mobile wallet.”

Each sentence points to work that has not finished. It does not prove a service provider is needed, but it gives you something concrete to ask about.

A real operation cannot reopen

The strongest messages connect the technical problem to something the company cares about:

“Risk will not reopen deposits until the two endpoints match.”

“Wallet operations needs one successful test deposit and withdrawal.”

“The product team is keeping transfers disabled until the Android and iOS builds both pass.”

Now the issue is no longer a dashboard with a red light. Deposits, withdrawals, transfers, or a release are waiting.

This is also why “the chain has restarted” is not enough. An exchange may wait for a number of stable blocks. A wallet may allow users to see balances but still block transaction submission. An indexer may need time to catch up and compare its records. Every company opens its own gate.

Someone has to approve the result

Look for the team or person who says yes:

“Risk must sign the report.”

“Security wants to witness the rollback test.”

“Wallet operations owns the reopening decision.”

“The release manager needs the result by 18:00 UTC.”

An owner tells you where the decision sits. It still does not prove the person writing in Telegram has purchasing authority. But it is much more useful than a vague “we need this fixed soon.”

Put the three parts together and the message becomes easy to read:

Two RPCs disagree + withdrawals stay closed + risk needs a report.

That is a possible job. “Mainnet paused, any ETA?” is still only a question.

Three ways to continue the conversation

The first reply should help the other person explain the blockage. It should not sound as though you diagnosed their infrastructure from one group message.

When RPC endpoints disagree

You could ask:

“Is risk waiting for a one-time height and block-hash comparison, or do they need the endpoints monitored for a period before reopening?”

That reveals whether the output is a quick report or ongoing observation. It also gives the buyer a chance to name the methods, duration, and person who accepts the result.

When an exchange wants to observe stable blocks

Imagine the message says:

“We will watch 200 blocks after production resumes. Risk signs before deposits reopen.”

Do not assume the seller should provide “200-block monitoring.” Ask:

“Do you already have the 200-block rule and only need the report, or is the team still deciding which exceptions should stop the count?”

The difference matters. One team needs somebody to collect and present data. The other still needs to design its reopening rule.

When a node upgrade has no rollback rehearsal

You could ask:

“Is the missing piece a safe test environment, or a runbook that shows the team how to return to the previous state if the upgrade fails?”

This separates an environment problem from a procedure problem without promising either before you know the node count, versions, access rules, and deadline.

These questions sound simple because they are meant to be answered. A long list about consensus, snapshots, caches, finality, and procurement would turn the first contact into an interrogation.

Avoid two mistakes while the status is changing

First, do not repeat an old notice as the current truth.

Ontology’s initial notice said no confirmed security incident had been identified at that time. The later official update said malicious attack activity had been found. If you read only the first announcement, your outreach will already be behind the event.

Second, do not turn the 24-hour recovery goal into the buyer’s deadline. Ontology made that goal conditional on checks and the upgrade succeeding. The exchange in your group may use a later reopening window. The node operator may need the upgrade sooner. The wallet team may wait longer. Ask for the team’s own deadline.

Also avoid saying that user funds were lost, naming a root cause, or blaming a vendor. The reviewed official notices said user assets were not compromised and did not publish a final technical root cause.

How TOP Prospect helps when the same story is in five groups

The important sentence may not appear in the first group you read.

One group says, “Our RPC heights disagree.” An hour later, somebody in another authorized source says, “Risk still won’t open withdrawals.” A third message mentions a report due at 16:00. Viewed separately, they may look like ordinary incident chatter. Viewed with their timestamps and nearby context, they may describe one team’s blocked reopening process.

In TOP Prospect, a salesperson can monitor Telegram sources they are authorized to use and look beyond the chain name. Useful phrases include:

  • “before reopening”
  • “risk needs to sign”
  • “heights do not match”
  • “still disabled”
  • “rollback not tested”
  • “report due”

TOP can preserve the matched message, source, time, and nearby discussion for human review. It cannot inspect a node, decide which height is correct, certify an upgrade, authenticate the writer, or confirm that an outside provider may join the incident. The seller still verifies those facts directly.

The point is not to collect every message about a mainnet pause. It is to stop the one sentence tied to a real reopening decision from disappearing under hundreds of ETA questions.

When you see “the chain is paused,” keep reading.

When you see “our two RPCs disagree, withdrawals stay closed, and risk needs the report,” stop and ask what is missing.

Frequently asked questions

Did Ontology confirm an attack when it first paused the mainnet?

No. The first notice said no confirmed security incident had been identified at that time. A later official update reported malicious attack activity targeting the network.

Did Ontology guarantee that mainnet operations would resume within 24 hours?

No. The later update described a goal to restore operations within the next 24 hours, conditional on security checks, remediation, and upgrade procedures completing successfully.

Can TOP Prospect verify that an RPC, validator, wallet, or exchange is ready to reopen?

No. It can preserve matched Telegram messages and nearby context from sources the user is authorized to monitor. Node state, identity, authority, acceptance results, and vendor access require direct human verification.

Sources and further reading

Human-authored disclosure

This article is human-authored. TOP Prospect processes only Telegram groups the user has explicitly authorized and connected. Its output supports human sales judgement; it does not replace human decisions and does not automatically contact or message group members.

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage