I got tired of watching people announce opposite views from the same repo.
Reading the code is useful. Running it is better. So I turn up a private local chain and tested the off switch myself.
Two doors.
The local command is dead on mainnet. 404.
The gossip path still works, one signed message stopped a node. Then it stopped three.
That is not what halted mainnet on Sep 19. I was in the validator chat. Operators stopped their own machines by hand.
The switch existing and the switch being pressed are different claims. @Justin_Bons was right that it exists. @SasuRobert was right about the channel, and wrong that there is no off switch. @vinibarbosabr already put the files on the table.
I pressed the button to verify it all...
@MultiversX @CodeMultiversX
Sep 24, 2026 · 12:06 PM UTC
5
18
98
8,285
Why is it even there?
This looks like an old emergency hard-fork tool, not a hidden implant. After a bad state you need a way to freeze nodes, export, and restart from a clean point. That is a reason to build it. It is not a reason to leave a single key in the default config for six years with no public custody.
The key in the files is only a public key. I cannot prove anyone still holds the matching private key. I cannot prove the foundation holds it. I cannot prove it is lost. No published custody, no rotation log, no on-chain record. “Who owns the switch” is unproven. We will probably never know.
What is proven is narrower: the door is in the software, gossip is on, the signature check works, and closing the API does not close that door.
It is not removed yet. After this went public, @SasuRobert opened a change to delete the whole feature: config, API route, gossip hook. That merge request is still open. Until it lands and validators run that binary, the door I tested is still in the tree.
You can call the old design an acceptable emergency tool. Just say that. Do not say the door is not there.
Test Yourself : github.com/PhyByte/MVX-OFF-S…
Pending Removal: github.com/multiversx/mx-cha…
1
1
18
561





