Currencies39003
Market Cap$ 2.71T+0.65%
24h Spot Volume$ 31.40B+1.48%
DominanceBTC57.40%-0.44%ETH10.80%-0.05%
ETH Gas0.05 Gwei
Cryptorank
/

How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops


How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops

Share:

AI Overview

On Aug. 27 ICON suffered a replay exploit that reused two withdrawal messages 1,492 times (1,490 successful calls), releasing 119,866,000 ICX and 531,600 bnUSD from foundation-held assets; ICON's Aug. 30 postmortem puts net confirmed loss at about 150.2 ETH plus 31,204 USDC while most ICX has been traced, frozen and is in active recovery and bnUSD and SODA were recovered in full. The root cause was an implementation bug from a 32-byte migration that routed part of a serial number through float64-range logic and escaped prior audits; detection and containment lagged (alert 02:08 UTC, contract paused 03:53, network halted ~06:18 and resumed ~25 hours later) and exchange-held amounts remain uncertain, highlighting crypto security and CEX risk despite recovery efforts.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

According to the ICON Foundation, the Aug. 27 ICON replay exploit released 119,866,000 ICX and 531,600 bnUSD from foundation-held assets after two legitimate withdrawal messages were reused 1,492 times. Its Aug. 30 postmortem said 1,490 calls succeeded, while no user deposits, balances or positions were accessed.

The headline-sized ICX release is not the same as the confirmed loss. ICON put net loss to date at about 150.2 ETH plus 31,204 USDC, with the vast majority of the ICX traced, frozen and in active recovery. The foundation said bnUSD and SODA were recovered in full, but exchange-held amounts remain subject to revision. That distinction matters because ICON had not received exact exchange figures for how much ICX was held, converted or withdrawn.

Related Reading

Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE

The flaw let the attacker change part of a withdrawal identifier without changing the signed payload being verified. ICON traced the mismatch to a change intended to standardize withdrawal messages at 32 bytes, which routed part of the serial number through float64-range logic rather than exact integer arithmetic.

As a result, the contract's uniqueness check looked at high bits the attacker could vary, while cryptographic verification covered the unchanged low 256 bits. The signed payload and signature remained identical within each replay set, but the altered unsigned portion made the calls appear unique. Two calls reverted; every successful call credited the same relayer wallet. ICON said the flaw was specific to its implementation because other supported chains used fixed-width integers that could not produce the same mismatch.

Related Reading

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum


ICON replay exploit timeline showing 1,492 replay attempts, 1,490 successful calls, the first alert, investigation, contract pause, network halt and restart.

Detection of the ICON replay exploit came before containment

ICON's monitoring system fired at 02:08 UTC, seven minutes after the exploit began. Technical staff started investigating at about 03:40, a 92-minute gap. The affected contract was paused at 03:53, 105 minutes after the alert.

The attacker had begun splitting ICX across exchange deposit addresses at 02:44, according to ICON, and the distribution continued until about 05:20. The foundation said an ICON-side pause could not stop movement of funds already swept into exchange custody.

The network was halted at 06:18:54 and resumed at about 07:51 the next day, roughly 25 hours later. Public notices from Bitvavo, Bitget and KuCoin confirm that ICX deposits and withdrawals were suspended around the incident, though none identifies itself as holding attacker funds or verifies the amount frozen.

Related Reading

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk

A November 2025 relay audit reviewed selected relay and verifier code, including ICON verifier files, but its published scope did not list the affected migration-contract source. None of its nine disclosed findings flagged the serial-number mismatch. ICON said incident-related relay logic had been audited, but that the gap fell outside the findings.

The post How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops appeared first on CryptoSlate.

Read the article at CryptoSlate

In This News

Coins

$ 2.41K

-0.50%

$ 0.0103

+7.31%

$ 0.99973

-0.01%

$ 0.000758

+1.08%

$ 0.878

+1.25%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

In This News

Coins

$ 2.41K

-0.50%

$ 0.0103

+7.31%

$ 0.99973

-0.01%

$ 0.000758

+1.08%

$ 0.878

+1.25%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

USDC may be only as quantum-safe as its slowest wallet, bridge or blockchain

USDC may be only as quantum-safe as its slowest wallet, bridge or blockchain

The 813-logical-qubit record is not a Q-day clock, but it shows why host chains, wall...
Russia just switched on a crypto market that doesn’t fully exist yet

Russia just switched on a crypto market that doesn’t fully exist yet

Most provisions took effect Sept. 1, but draft rules and a July 2027 transition limit...