The ICON Foundation says an attacker reused two legitimate withdrawal messages 1,492 times in an exploit on 27 August, causing 119,866,000 ICX and 531,600 bnUSD to be released from assets held by the foundation.
Of those attempts, 1,490 calls succeeded, according to ICON’s 30 August postmortem. The foundation said the attack did not access user deposits, balances or positions.
The large amount of ICX released does not represent the confirmed net loss. ICON currently estimates its losses at about 150.2 ETH and 31,204 USDC. It said most of the ICX had been traced, frozen or was subject to active recovery.
ICON also said the bnUSD and SODA involved in the incident had been recovered in full. However, figures relating to assets held by exchanges could still change because the foundation had not received exact information on how much ICX had been held, converted or withdrawn by those platforms.
How the exploit worked
The vulnerability allowed the attacker to alter part of a withdrawal identifier without changing the signed data checked by the system.
ICON linked the problem to a previous change designed to standardise withdrawal messages at 32 bytes. That change caused part of the serial number to be processed using float64-range logic instead of precise integer arithmetic.
This created a mismatch between the contract’s uniqueness check and its cryptographic verification. The uniqueness check examined high-order bits that the attacker could modify, while the signed payload and signature continued to cover the same unchanged lower 256 bits.
As a result, the attacker could make repeated transactions appear to be different withdrawals even though the signed message remained identical within each replay group. Two calls failed, but every successful call credited the same relayer wallet.
ICON said the weakness was specific to its own implementation. Other chains supported by the system use fixed-width integers and therefore could not produce the same discrepancy.
The foundation’s monitoring system detected unusual activity at 02:08 UTC, seven minutes after the exploit began. Technical staff began investigating at about 03:40, leaving a 92-minute gap between the alert and the start of the investigation.
The affected contract was paused at 03:53, 105 minutes after the initial alert.
According to ICON, the attacker began sending ICX to exchange deposit addresses at 02:44. Those transfers continued until about 05:20. The foundation said pausing the ICON-side contract could not prevent funds from being moved after they had already been swept into exchange custody.
Network halted for about 25 hours
The ICON network was halted at 06:18:54 and restarted at about 07:51 the following day, approximately 25 hours later.
Public notices issued by Bitvavo, Bitget and KuCoin confirmed that ICX deposits and withdrawals were suspended around the time of the incident. None of those notices identified the exchange as holding funds linked to the attacker or confirmed how much had been frozen.
A relay audit carried out in November 2025 examined selected relay and verifier code, including files belonging to the ICON verifier. However, the published scope of that review did not include the source code for the affected migration contract.
The audit disclosed nine findings, but none mentioned the serial-number mismatch. ICON said the relay logic connected to the incident had been audited, while adding that the specific gap had not appeared among the audit findings.
Also known as “Akiba”, Liam Wright is a reporter, podcast producer and Editor-in-Chief at CryptoSlate. He believes decentralised technology has the potential to make…
CryptoSlate says it may use artificial intelligence tools to support research, editing and production workflows. The publication says its journalism remains human-led, with its editorial team responsible for every article. It provides a full AI usage disclaimer.
The opinions of CryptoSlate’s writers are their own and do not represent the publication’s views. CryptoSlate says information in its articles should not be treated as investment advice and that it does not endorse any project mentioned or linked in its content.
It also warns that buying and trading cryptocurrencies is a high-risk activity and advises readers to carry out their own due diligence before acting on information in its articles. CryptoSlate accepts no responsibility for losses incurred through cryptocurrency trading and directs readers to its company disclaimers for further information.
CryptoSlate also promotes a “Follow the signal” service for readers who do not want to miss market-moving updates.
