ICON Foundation Replay Exploit Postmortem Details Migration Contract Flaw
ICON Foundation Aug. 30 postmortem attributes Aug. 27 replay exploit to serial-number logic error, confirming net loss of 150.2 ETH and 31,204 USDC with most ICX recovered.
ICON Foundation disclosed that a replay exploit on its migration contract allowed two legitimate withdrawal messages to be reused 1,490 times on Aug. 27.
The calls released 119,866,000 ICX and 531,600 bnUSD from foundation holdings. Net loss stands at approximately 150.2 ETH plus 31,204 USDC, with bnUSD and SODA recovered in full and most ICX traced and frozen.
The flaw stemmed from a serial-number check that routed part of the identifier through float64-range logic instead of fixed-width integers, letting the attacker vary high bits while the signed payload remained identical.
The network was paused at 06:18:54 UTC on Aug. 27 and resumed roughly 25 hours later. No user deposits or positions were accessed, though exchange-held amounts remain subject to revision.