How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops
According to the ICON Foundation, the Aug. 27 ICON replay exploit launched 119,866,000 ICX and 531,600 bnUSD from foundation-held property after two official withdrawal messages have been reused 1,492 times. Its Aug. 30 postmortem mentioned 1,490 calls succeeded, whereas no person deposits, balances or positions have been accessed.
The headline-sized ICX launch isn’t the same as the confirmed loss. ICON put internet loss to date at about 150.2 ETH plus 31,204 USDC, with the overwhelming majority of the ICX traced, frozen and in energetic restoration. The basis said bnUSD and SODA have been recovered in full, however exchange-held quantities stay topic to revision. That distinction issues as a result of ICON had not obtained precise trade figures for the way a lot ICX was held, transformed or withdrawn.
The flaw let the attacker change a part of a withdrawal identifier with out altering the signed payload being verified. ICON traced the mismatch to a change supposed to standardize withdrawal messages at 32 bytes, which routed a part of the serial quantity by means of float64-range logic fairly than precise integer arithmetic.
As a consequence, the contract’s uniqueness examine checked out high bits the attacker may range, whereas cryptographic verification lined the unchanged low 256 bits. The signed payload and signature remained an identical inside every replay set, however the altered unsigned portion made the calls seem distinctive. Two calls reverted; each profitable name credited the same relayer pockets. ICON mentioned the flaw was particular to its implementation as a result of different supported chains used fixed-width integers that might not produce the same mismatch.
Detection of the ICON replay exploit got here earlier than containment
ICON’s monitoring system fired at 02:08 UTC, seven minutes after the exploit started. Technical workers began investigating at about 03:40, a 92-minute hole. The affected contract was paused at 03:53, 105 minutes after the alert.
The attacker had begun splitting ICX throughout trade deposit addresses at 02:44, in accordance to ICON, and the distribution continued till about 05:20. The basis mentioned an ICON-side pause couldn’t cease motion of funds already swept into trade custody.
The community was halted at 06:18:54 and resumed at about 07:51 the subsequent day, roughly 25 hours later. Public notices from Bitvavo, Bitget and KuCoin affirm that ICX deposits and withdrawals have been suspended round the incident, although none identifies itself as holding attacker funds or verifies the quantity frozen.
A November 2025 relay audit reviewed chosen relay and verifier code, together with ICON verifier information, however its revealed scope didn’t record the affected migration-contract supply. None of its 9 disclosed findings flagged the serial-number mismatch. ICON mentioned incident-related relay logic had been audited, however that the hole fell outdoors the findings.
The put up How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops appeared first on CryptoSlate.

