ICON Suffers Record-Breaking Crypto Heist via Reused Withdrawal Messages
A hacker exploited a vulnerability in ICON's migration contract to trigger massive payout loops, releasing 119.9 million ICX and 531,600 bnUSD from foundation-held assets.
The attack occurred on August 27, when the hacker reused two legitimate withdrawal messages 1,490 times to bypass the contract's uniqueness check.
ICON's monitoring system detected the issue at 02:08 UTC, but it took another 92 minutes for technical staff to investigate and pause the affected contract at 03:53.
The network was halted on August 30 and resumed the next day after roughly 25 hours.