An attacker exploited a flaw in ICON’s withdrawal protocol on Aug. 27 by replaying two legitimate withdrawal messages 1,492 times, releasing 119.9 million ICX and 531,600 bnUSD. The ICON Foundation confirms actual losses of 150.2 ETH and 31,204 USDC, with the majority of funds traced and frozen. The vulnerability originated from a technical implementation error where float64 logic was used instead of integer arithmetic for withdrawal identifiers, allowing the attacker to bypass uniqueness checks while keeping valid cryptographic signatures. During the 92-minute window before detection, the attacker rapidly distributed funds to exchange deposit addresses. The network was halted 4 hours and 17 minutes after the exploit began.
Source: Read the original article

