How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops

NewsTue, 01 Sep 2026 17:40:14 UTC1 hour ago
How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops

According to the ICON Foundation, the Aug. 27 ICON replay exploit released 119,866,000 ICX and 531,600 bnUSD from foundation-held assets after two legitimate withdrawal messages were reused 1,492 times. Its Aug. 30 postmortem said 1,490 calls succeeded, while no user deposits, balances or positions were accessed.

The headline-sized ICX release is not the same as the confirmed loss. ICON put net loss to date at about 150.2 ETH plus 31,204 USDC, with the vast majority of the ICX traced, frozen and in active recovery. The foundation said bnUSD and SODA were recovered in full, but exchange-held amounts remain subject to revision. That distinction matters because ICON had not received exact exchange figures for how much ICX was held, converted or withdrawn.

Related Reading

Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE

The flaw let the attacker change part of a withdrawal identifier without changing the signed payload being verified. ICON traced the mismatch to a change intended to standardize withdrawal messages at 32 bytes, which routed part of the serial number through float64-range logic rather than exact integer arithmetic.

โ€ฆ Continue reading the full article at the original source below.

Read from Source ยท cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related