ICON Foundation Hit with $150M+ Loss Due to Replay Vulnerability Exploit
The ICON Foundation reported a significant security breach on August 27, when an attacker exploited a replay vulnerability in their system. The exploit resulted in the release of approximately 119,866,000 ICX and 531,600 bnUSD from foundation-held assets.
The issue was caused by a flaw in the implementation of withdrawal messages, which allowed the attacker to reuse two legitimate withdrawal messages 1,490 times. This meant that the contract's uniqueness check looked at high bits that could be varied by the attacker, while cryptographic verification covered only the unchanged low 256 bits.
The attack was specific to ICON's implementation, as other supported chains used fixed-width integers that couldn't produce the same mismatch. The foundation stated that no user deposits, balances, or positions were accessed during the exploit.
As a result of the breach, the ICON Foundation has reported a net loss of approximately 150.2 ETH plus 31,204 USDC. However, it's worth noting that the vast majority of the stolen ICX has been traced and frozen in active recovery, with bnUSD and SODA recovered in full.
The distinction between the actual loss and the headline-sized release is significant, as ICON had not received exact exchange figures for how much ICX was held, converted, or withdrawn. The foundation emphasized that the flaw was due to its implementation and was not a result of any vulnerabilities in other supported chains.