Loading market data...

ICON Replay Exploit Released 119M ICX, Most Recovered After 25-Hour Halt

ICON Replay Exploit Released 119M ICX, Most Recovered After 25-Hour Halt

On Aug. 27, an attacker exploited a replay vulnerability in ICON's migration contract, releasing 119,866,000 ICX and 531,600 bnUSD from foundation-held assets. The exploit reused two legitimate withdrawal messages 1,492 times, with 1,490 calls succeeding. No user deposits, balances, or positions were accessed, and most of the ICX has been traced and frozen, but the incident exposed a gap in the network's monitoring and audit coverage.

How the flaw worked

The bug let the attacker change part of a withdrawal identifier without altering the signed payload being verified. A change to standardize withdrawal messages at 32 bytes routed part of the serial number through float64-range logic rather than exact integer arithmetic. The contract's uniqueness check looked at high bits the attacker could vary, while cryptographic verification covered the unchanged low 256 bits. That mismatch meant two different identifiers could pass both checks.

The flaw was specific to ICON's implementation. Other supported chains used fixed-width integers that couldn't produce the same mismatch, so the replay only worked on ICON.

The response timeline

ICON's monitoring system fired at 02:08 UTC, seven minutes after the exploit began. Technical staff started investigating at about 03:40 — a 92-minute gap after the alert. The affected contract was paused at 03:53, 105 minutes after the alert. But by then the attacker had already started splitting ICX across exchange deposit addresses at 02:44, and distribution continued until about 05:20. An ICON-side pause couldn't stop funds already swept into exchange custody.

The network was halted at 06:18:54 and resumed at about 07:51 the next day, roughly 25 hours later. Exchanges Bitvavo, Bitget, and KuCoin suspended ICX deposits and withdrawals around the incident.

Recovery and losses

Net loss to date is about 150.2 ETH plus 31,204 USDC. bnUSD and SODA were recovered in full, but exchange-held amounts remain subject to revision. Most of the ICX was traced, frozen, and in active recovery. Two of the 1,492 calls reverted; every successful call credited the same relayer wallet.

The audit gap

A November 2025 relay audit reviewed selected relay and verifier code but did not list the affected migration-contract source. None of its nine disclosed findings flagged the serial-number mismatch. ICON said incident-related relay logic had been audited, but the gap fell outside the findings.

The unresolved question is whether the audit scope will be expanded to cover migration contracts, and whether the exchange-held amounts will be fully recovered. ICON hasn't said when the recovery process will conclude.