en de

Validator Statement: Virtue Incident

Following the oracle exploit affecting the Virtue protocol in late August 2026, part of the validator set applied a deny-list to the attacker's addresses. A recovery plan has since been proposed that would require validator consent for handling those blocked assets.

PANDABYTE did not apply the deny-list, and we will not support any mechanism that gives validators or any other party the ability to move assets they do not hold. Under the current protocol this is not possible, and enabling it would require a protocol change. We will not support that — once such a capability exists, it exists for every future case.

This is not a judgement on Virtue or on the users who lost their positions, and it does not stand in the way of remediation that works without validator intervention.

PANDABYTE stays neutral. Our role is to process valid transactions according to the protocol rules, not to decide who may transact. Our responsibility is to the IOTA protocol, its decentralization and its integrity.