CryptoReal
CASE FILE — Feb 25, 2026

One Compromised Validator Key, Millions Gone: Inside the IoTeX ioTube Bridge Breach

On February 21, 2026, an attacker gained control of the owner key for the ioTube bridge's validator contract, giving them administrative authority over every asset the bridge held. There was no exploit and no clever contract logic involved — just a compromised credential and a short sequence of on-chain actions that pulled roughly $4.4 million in real bridged assets out of the TokenSafe and minted 410 million CIOTX tokens with nothing backing them, according to IoTeX's own figures.

Three numbers, one incident

Onchain investigator Specter was the first to publicize the breach, putting the drain at roughly $4.3 million. PeckShield raised that to over $8 million about ninety minutes later. By the time IoTeX co-founder Raullen Chai told The Block the loss was closer to "around $2M," three separate figures were circulating publicly — and each one was defensible, because each was measuring a different slice of the same operation.

The attacker removed $4.4 million in actual bridge reserves — USDC, USDT, WBTC, WETH, IOTX, PAXG, DAI, BUSD and UNI — straight from the TokenSafe. Separately, per Defimon Alerts, the same stolen access was used to mint 821 million CIOTX (roughly $4.09M at the time) and 9.3 million CCS tokens, the latter described by Chai as a deprecated token with no real market value.

IoTeX's own later accounting referenced 410 million CIOTX minted, a number that doesn't match the on-chain mint record. An advanced Etherscan filter shows 10 confirmed mint transactions totaling roughly 821 million, and IoTeX has not explained the gap between the two figures. The team's $2 million "net loss" framing depends on its claim that 86% of the minted supply is now frozen with no liquidity path.

The figure hardest to dispute is a simple one: 66.77 BTC, worth roughly $4.29 million, sitting untouched in four newly created Bitcoin wallets as of February 23 — visible to anyone who looks.

Market and exchange fallout

IOTX fell 22% on the news, from $0.0054 to under $0.0042, and was trading near $0.00467 as of February 24 — about 98% below its all-time high of $0.255 from November 2021. South Korean exchange Upbit added IOTX to its trading-alert list and paused deposits.

IoTeX responded by pushing an emergency patch to chain delegates that blacklists the attacker's addresses — with consensus set to resume automatically once enough patched delegates came online — pausing the bridge pending an independent audit, and working with exchanges to freeze funds where possible. The L1 chain is now back online. Meanwhile, the attacker had already routed funds through THORChain and parked the proceeds on Bitcoin.

01How the timeline actually unfolded

Specter's initial alert on February 21 read: "The private key of IoTeX may have been compromised, resulting in their token safe being drained for a total loss of approximately $4.3M." The post identified USDC, USDT, IOTX, WBTC and BUSD as drained, noted stolen assets already converted to ETH with 45 ETH bridged to Bitcoin, and named three attacker addresses — a precise, technical alert that landed while much of the industry was asleep.

Roughly ninety minutes on, PeckShieldAlert pushed the estimate higher: "The IoTeX[.]io Bridge has been hacked for over $8M worth of crypto due to a compromised private key. The hacker has swapped the stolen funds to $ETH and has started bridging them to BTC via Thorchain." That jump wasn't a revision so much as a broader scope — Specter had tallied what left the vault, while PeckShield appeared to be counting the minted tokens on top of it. Neither was wrong; they were describing different halves of the same attack.

DefimonAlerts then supplied the technical detail, pegging the gross figure near $8.46 million and identifying the contract at fault: TransferValidatorWithPayload. Per that report, the attacker had taken ownership of both the TokenSafe and the MinterPool — draining the former while printing from the latter.

IoTeX issued its first public statement 79 minutes after Specter's original post: "Our team is fully engaged, working around the clock to assess and contain the situation. Initial estimates indicate the potential loss is significantly lower than circulating rumors suggest." It offered no dollar figure, no technical explanation, and no acknowledgment of what three independent security firms had already mapped on-chain — and it was posted while the attacker was still actively moving funds through THORChain.

Several hours later, IoTeX settled on a number: $2 million. Chai repeated that figure to The Block — "around $2M USD for now" — and characterized the minted tokens as "of little consequence." By then, roughly eight hours had elapsed since the first public alert, and the drain phase of the attack had been over for most of that window.

02The mechanism: an upgrade function with no safeguards

The bridge itself wasn't broken through code — it was administered by someone who should never have held the keys. At the center of the incident is a single externally owned account that owned the TransferValidatorWithPayload contract on Ethereum. That account's key privilege was the ability to call upgrade() — an ordinary maintenance function when used legitimately, and effectively a master switch when it isn't.

Using that access, the attacker called upgrade() and swapped in a malicious contract version stripped of the original's signature checks and validation logic.

The bridge's own upgrade mechanism became the point of entry. Once the validator layer was replaced, ownership of the TokenSafe and MinterPool passed cleanly to attacker-controlled addresses — no alarm triggered, no threshold enforced, no second signature demanded. The contracts simply followed their new owner's instructions. As QuillAudits summarized it, this wasn't a smart-contract exploit at all, but a breach of trust at the ownership layer.

How the key was actually obtained has not been publicly confirmed. IoTeX's own statement referred to "a sophisticated, long-planned attack by professional actors targeting multiple chains," and Chai told The Block the operation appeared to have been in preparation for six to eighteen months. That timeframe suggests something more deliberate than an opportunistic phishing click — possibly insider access, an extended social-engineering campaign, or an infrastructure compromise that went unnoticed for over a year.

Whatever the entry vector, the deeper design flaw is arguably worse than the key loss itself: a single EOA held unchecked upgrade authority over contracts safeguarding millions in bridged funds, with no multisig requirement, no timelock, and nothing capable of intervening between the upgrade() call and the drain that followed. The system was built on the assumption that the key would never be compromised, and had no fallback for the moment it was.

Sums referenced in this case file

03Tracing the drain, the mint, and the exit

Onchain records show 189 transactions executed on a Saturday morning, carried out without delay.

The drain. With control of the TokenSafe established, every reserve asset was moved out in quick succession. Per IoTeX's own Security Incident Update, nine tokens were taken: 1.36K USDC, 1.14K USDT, 635 WETH, 6.12 WBTC, 20,159 DAI, 8.72 PAXG, 13.85M IOTX, 45,825 BUSD, and 2,835 UNI — roughly $4.4 million in total.

The mint. Separately, the MinterPool was used to produce 821 million CIOTX across 7 transactions, confirmed on-chain, split across three beneficiary addresses:

The 821 million total matches Defimon Alerts' earlier estimate and is backed by the seven mint transactions above. IoTeX's own February 22 statement instead cited 410 million CIOTX minted — a figure the on-chain record doesn't support, and one IoTeX hasn't reconciled. Possible explanations include burns or freezes that occurred between the mint and IoTeX's accounting, an incomplete trace at the time of reporting, or a deliberate choice of framing — but none has been confirmed.

The attacker also minted 9.3 million CCS tokens, which remain unspent in the secondary exploit wallet. On paper, the combined mint value could be read as roughly $8 million, though Chai maintains the CCS portion is worthless since the token was deprecated long ago. Using Coingecko pricing (which may be stale), the 821 million CIOTX would be worth about $3.7 million and the 9.3 million CCS about $4.3 million — a hypothetical combined total near $8 million as of February 25 — though whether any of that reflects real, sellable liquidity is a separate matter.

Following the money. Both the drained assets and the minted tokens moved through two primary wallets:

From there, Uniswap and other DEXs absorbed the mixed basket of stolen tokens in exchange for ETH. The ETH then moved through THORChain — no KYC, no custodian, no freeze capability — passing through relay wallets before emerging as Bitcoin in four addresses that didn't exist before February 21:

Independent researcher 0xOwnerpaiN identified each destination as funds arrived:

Combined, the four wallets held 66.77 BTC (~$4.49M) as of February 25. Rather than cashing out, the attacker parked the funds and went silent — no mixer, no further hops, no withdrawal attempts. 0xOwnerpaiN did observe Wallet #2 growing in real time, from 14.2 BTC to 19.96 BTC, as ETH continued converting through THORChain even after the breach became public — meaning the drain phase had ended, but the laundering process was still active.

04Recovery efforts, unresolved figures, and a possible connection to a prior hack

On February 22, IoTeX published its most detailed statement yet — a formal recovery roadmap laying out figures the team had avoided specifying until then. According to that update, $4.4 million was drained from the TokenSafe, and 410 million CIOTX were minted via the MinterPool — IoTeX's own number, versus the 821 million shown in the on-chain mint record.

IoTeX stated that 86% of the minted tokens were locked or frozen through various chain-level controls: 315 million CIOTX stuck on Ethereum and Base with no bridge route out, 40.5 million sitting in blacklisted attacker wallets on the IoTeX chain, and 52.4 million deposited to Binance, which the team said it was working to freeze. Only 1.7 million CIOTX — about 0.4% of the total minted — had reportedly been swapped on a DEX and was considered unrecoverable. If accurate, these numbers would support IoTeX's $2 million net-loss estimate — though the Binance freeze has not been independently verified, and the blacklisting of 29 attacker addresses is a unilateral step taken by IoTeX on its own chain rather than a third-party confirmation.

Notably, the non-IOTX assets — the $4.4 million in USDC, USDT, WBTC, WETH and other tokens pulled from the TokenSafe, converted to roughly 2,183 ETH and bridged to Bitcoin via THORChain — remain fully in the attacker's possession, with no recovery path identified so far. The 9.3 million CCS tokens are the one exception: they remain unspent in the secondary exploit wallet, untouched by the attacker even though Etherscan lists their value around $4.3 million — a figure Chai disputes, noting CCS was "deprecated long time ago so have no value." Whatever the true liquidity of that position, its practical exit value appears close to zero, and the attacker's real leverage likely lies in the TokenSafe assets and the BTC already secured.

The February 22 statement also included a white-hat bounty offer, which IoTeX formalized to CoinDesk on February 23: $440,000 (10%) in exchange for returning roughly $4.4 million within 48 hours, with a promise of no legal action and no cooperation with law enforcement on identifying details. IoTeX also flagged the primary exploit address on Etherscan as Fake_Phishing2054654 and sent an on-chain message directly to the attacker: "This is regarding the ioTube bridge exploit on Feb. 21, 2026. All fund movements across Ethereum, IoTeX, and bitcoin have been fully traced." As of February 25 — the day the 48-hour window expires — no response has been reported.

SpecterAnalyst separately flagged a wallet-funding link between the IoTeX attacker's EOA and the $49.5 million Infini stablecoin hack from February 2025 — a case that hasn't been addressed directly in IoTeX's statements. That earlier incident involved a former contract developer who kept admin privileges after his engagement ended, then carried out a delayed drain using a comparable playbook: insider-level key access, a deferred strike, and cross-chain laundering through Tornado Cash. Chai's comment about a "planned attack that could have been developing for six to eighteen months" reads differently in light of that potential connection, though no analytics firm or law enforcement body had made a formal attribution as of February 23.

Outside observers remain doubtful the core losses will be reversed. Nick Motz, CEO of ORQO Group, told CoinDesk: "Containment is not the same as recovery. The assets with actual market value were swapped and bridged. Those are, in my assessment, unlikely to be recovered." Nanak Nihal Khalsa, co-founder of human.tech, offered a similar assessment: "It's hard to predict how much, if any, can be recovered."

IoTeX's outstanding commitments include a detailed compensation plan for affected bridge users, a community AMA with the founding team, a full post-mortem, an accelerated rollout of IIP-55 (which would decentralize bridge validation across a multi-party validator set), new mandatory multisig and 24-hour timelock requirements for validator keys, and an expanded bug bounty program. Notably, IIP-55 was drafted in December 2025 — two months before the breach — and is only now being fast-tracked.

On the chain side, there is at least a resolution: on February 24 at 06:06 AM UTC, IoTeX confirmed its L1 was back online running v2.3.4, with all 29 attacker wallets permanently blacklisted at the protocol level. That same update named the FBI for the first time, confirmed a formal response to DAXA (the Korean Digital Asset Exchange Association), and committed the IoTeX Foundation Treasury to covering 100% of losses for affected bridge users. The bridge itself, however, remains paused pending an independent security audit, with no completion date given.

05The bigger pattern

The technique behind the ioTube breach mirrors what previously hit Infini and Step Finance — protocols with audited contracts, public security reviews, and years of clean operational history that still lost control of their vaults because a single key ended up in the wrong hands. Exactly how that key left IoTeX's infrastructure and reached an attacker remains publicly unknown, and given the pattern with similar incidents, it may never be fully disclosed — private-key compromises rarely produce the kind of detailed post-mortem that a code exploit does, since acknowledging a human failure doesn't come with a patch to point to.

To its credit, IoTeX moved relatively fast: the February 22 statement, the v2.3.4 patch, and coordination with Binance all followed within days. But 66.77 BTC (~$4.29M) remains sitting untouched on Bitcoin, the compensation plan is still just a promise, and IIP-55 — the governance change that could have made this specific attack far harder to pull off — existed on paper for two months before the breach without being prioritized.

Chainalysis has reported that private-key compromises accounted for 88% of all crypto stolen in Q1 2025, a statistic the industry has been aware of for some time. Increasingly, the attack surface isn't the smart contract itself — it's whoever holds the keys, on whatever device and however secured, on whichever quiet weekend morning an attacker has been waiting for.

IoTeXPrivate Key Leak
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.