Replay Exploit on ICON Releases Over $100 Million Worth of Assets
A massive replay exploit occurred on August 27 on the ICON blockchain, releasing over 119.9 million ICX and 531,600 bnUSD from foundation-held assets.
The attack re-used two valid withdrawal messages 1,492 times, taking advantage of a flaw in ICON's implementation that allowed the attacker to change part of a withdrawal identifier without changing the signed payload being verified.
The contract's uniqueness check was fooled by the mismatch between exact integer arithmetic and float64-range logic, which looked at high bits the attacker could vary while cryptographic verification covered the unchanged low 256 bits.
ICON's monitoring system fired seven minutes after the exploit began, but a 92-minute human-response gap allowed funds to reach exchanges before the contract was paused. The network was halted at 06:18:54 and resumed about 25 hours later.