According to BlockBeats news, on February 24, IoTeX announced that in response to the hacking incident of its cross-chain bridge ioTube, it would offer a 10% white hat bounty (approximately $440,000) to the attacker, on the condition that they return approximately $4.4 million of stolen assets within 48 hours and promise not to pursue legal liability.
The attack occurred on February 21, originating from the leak of the validator private key of ioTube on the Ethereum side, which led to the illegal control of the bridge contract. IoTeX stated that this incident is a security issue at the operational level of the cross-chain bridge and did not affect its Layer 1 mainnet or smart contracts themselves.
IoTeX co-founder and CEO Raullen Chai stated that the team has issued a no accountability statement to the attackers through on-chain information and has traced the related flow of funds, including approximately 66.6 BTC (about 4.3 million dollars) stored in multiple Bitcoin addresses. At the same time, the recharge addresses of related trading platforms have been marked and frozen.
The security organization PeckShield estimates that the impact of this incident on assets may exceed 8 million dollars, and some assets have been exchanged for ETH and cross-chain transferred to BTC via THORChain. IoTeX subsequently revised the loss to approximately 4.3 million dollars, stating that this data does not include additional minted tokens.
IoTeX also announced the release of the mainnet upgrade version v2.3.4, which adds a default malicious address blacklist mechanism and requires node operators to complete the upgrade as soon as possible. The team stated that if the assets cannot be recovered, a compensation plan will be announced within 48 hours.
