IOTA restored value-transfer confirmations on its mainnet on December 30, 2019, after releasing an emergency update to the IOTA Reference Implementation, or IRI. The repair ended an interruption that prevented the network’s primary node software from accepting a Coordinator milestone and calculating a consistent ledger state.

The IOTA Foundation’s incident chronology records the release of IRI `v1.8.3-RELEASE` at 01:58 UTC. The Coordinator service resumed at 02:32 UTC, successfully issued milestone 1,293,082 one minute later, and was producing stable confirmations by 02:45 UTC. The Foundation announced the incident resolved at 02:55 UTC and instructed IRI node operators to upgrade.

A transaction-bundle edge case

According to the Foundation’s technical account, IRI mishandled an unusual transaction shared between two distinct bundles. After recording the transaction as accounted for in one bundle, the software ignored it while processing the other. That behavior produced what the developers described as a corrupt ledger state from which affected IRI nodes could not recover normally.

The nodes responded by rejecting milestones rather than accepting a ledger state they could not reconcile. That safety behavior stopped value transfers from receiving confirmation. It is therefore more precise to describe the incident as a halt in confirmations than as the disappearance of the network or the loss of its transaction history.

The Foundation said the unusual transaction structure might have been deliberately constructed as an attack, but the available record did not establish intent on December 30. It also said user funds were never endangered. That was an attributable contemporaneous claim from the protocol’s operator, not an independently audited finding.

Patch, restart and operational weaknesses

The engineering timeline shows that developers identified the offending bundle at 16:30 UTC on December 29 and the root cause at 17:20 UTC. An initial repair tested at 18:55 UTC did not let nodes recover through IRI’s milestone-repair mechanism. Pull request 1699, containing the ledger-service fix, was created at 00:39 UTC on December 30 and approved at 01:22 UTC.

Internal nodes began upgrading at 01:28 UTC. By 02:45 UTC, the Foundation reported that many external nodes had also updated through an automated upgrade service. Huobi, which had suspended IOTA deposits and withdrawals during the disruption, subsequently restored those services, according to contemporaneous reporting.

The incident exposed an operational problem beyond the software defect. The Foundation’s post-incident chronology said a PagerDuty alert tied to mainnet confirmations failed to notify the team at 02:55 UTC on December 29. Investigation did not begin until 07:35 UTC. That gap mattered because the Coordinator—then a Foundation-operated component responsible for final confirmation—had stopped issuing additional milestones after IRI nodes rejected milestone 1,293,082.

Why the interruption mattered

IOTA was promoted as a distributed ledger for machine-to-machine and internet-of-things transactions. An edge case capable of halting value-transfer confirmation challenged the reliability expected of infrastructure intended for automated commerce. The centralized role of the Coordinator also remained material: although the defect was in IRI rather than the Coordinator itself, confirmation depended on the Foundation restoring software compatibility and restarting the service.

The unaffected beta Hornet implementation gave developers a comparison point during diagnosis, but it was not the primary production node implementation on December 30. Its behavior could inform the repair without eliminating the immediate dependence on patched IRI nodes.

Later clarification

Reports published during December 30 described the disruption as lasting more than 15 hours. The Foundation’s subsequently completed incident chronology placed the confirmation outage from 02:50 UTC on December 29 through 02:50 UTC on December 30—a 24-hour window—with the public resolution announcement following five minutes later. That later timing clarification is used here only to reconcile the incomplete event-day estimates.

Primary sourceIOTA Foundation incident summary — Mainnet 29/12/2019

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.