Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

ICON Network Exploited Through Replay Attack, Releasing 119.9M ICX Tokens

A vulnerability in ICON's withdrawal message verification allowed an attacker to replay two legitimate messages 1,490 times, releasing tokens from foundation assets. The network halted for 25 hours after a 92-minute response delay.
1 week ago 26 views
ICON Network Exploited Through Replay Attack, Releasing 119.9M ICX Tokens

A replay attack on the ICON network on August 27 exploited a flaw in withdrawal message verification, releasing 119.9 million ICX and 531,600 bnUSD from foundation-held assets, according to ICON's postmortem released August 30.

Two valid withdrawal messages were replayed 1,492 times across the network. Of these attempts, 1,490 calls succeeded, while two reverted. All successful calls credited the same relayer wallet.

The Technical Flaw

The vulnerability stemmed from a mismatch in serial-number checks during a standardization effort to set withdrawal messages to 32 bytes. Part of the serial number was routed through float64-range logic rather than exact integer arithmetic, creating a gap between what the cryptographic verification covered and what the uniqueness check examined.

The attacker could alter the high bits of the withdrawal identifier without changing the signed payload being verified. While the cryptographic signature remained identical within each replay set, the altered unsigned portion made each call appear unique to the contract's verification system. ICON said this implementation flaw was specific to its system because other supported chains used fixed-width integers that would not produce the same mismatch.

Response Timeline and Containment

ICON's monitoring system detected the exploit at 02:08 UTC, seven minutes after it began. However, technical staff did not begin investigating until 03:40—a 92-minute gap. The affected contract was paused at 03:53, 105 minutes after the initial alert.

By that time, the attacker had begun splitting ICX across exchange deposit addresses at 02:44. Fund distribution continued until approximately 05:20, and the attacker's movement of ICX into exchange custody continued even after ICON paused the contract. The network was halted at 06:18:54 and resumed approximately 25 hours later.

Confirmed Losses and Recovery

ICON reported confirmed losses to date of approximately 150.2 ETH and 31,204 USDC. The foundation said the vast majority of released ICX has been traced and frozen in active recovery. bnUSD and SODA were recovered in full, though exchange-held amounts remain subject to revision pending exact figures from exchanges on amounts held, converted, or withdrawn.

Public notices from Bitvavo, Bitget, and KuCoin confirm ICX deposits and withdrawals were suspended around the incident, though none identified itself as holding attacker funds or verified frozen amounts.

Audit Gap

A November 2025 relay audit reviewed selected relay and verifier code, including ICON verifier files, but did not include the affected migration-contract source in its published scope. None of its nine disclosed findings flagged the serial-number mismatch vulnerability.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.