Ionic Money hack — February 2025
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | February 5, 2025 |
| Target type | Lending protocol |
| Loss | $8,600,000Published estimates range $6,900,000 to $8,800,000Price at time of incident |
| Method | Social engineeringAttackers impersonated the Lombard Finance team and persuaded Ionic Money to list a counterfeit LBTC token contract under their own control as accepted collateral on the Mode network deployment. They then minted 250 of the fake LBTC, deposited them as collateral and borrowed out the lending pools' real assets — MBTC, uniBTC, wrsETH, WETH and STONE among them — leaving depositors with worthless collateral backing loans that were never repaid. |
| Chains | Other, Ethereum |
| Outcome | Project shut down |
What happened
Ionic Money was a lending market on the Mode network, relaunched from the Midas protocol, which had itself been exploited twice in 2023. In early February 2025 attackers who had spent time posing as the Lombard Finance team persuaded Ionic to list a counterfeit LBTC token — a contract they had deployed in January 2025 and controlled — as accepted collateral. rekt.news dates the exploit 4 February; QuillAudits and the outlets reporting its monitoring date it 5 February.
Once the fake asset was live and carried a price, the attackers minted 250 of the counterfeit LBTC, deposited them and borrowed against them. QuillAudits listed MBTC, uniBTC, wrsETH, WETH and STONE among the assets drawn out; Halborn names MBTC and iBTC. The collateral was worthless, so the loans were never going to be repaid, and the lending pools' depositors carried the loss.
Published totals do not agree. Halborn put the amount borrowed against the fake collateral at $8.6 million and QuillAudits at about $8.8 million, but rekt.news put the loss at roughly $6.9 million. Around $3.5 million was bridged to Ethereum and passed through Tornado Cash, which rekt broke down as 1,204 ETH worth about $3.2 million into Tornado Cash with a further $3.7 million left sitting on Mode. Part of the damage landed outside Ionic — the borrowed tokens were swapped into MBTC and used to borrow again from Ironclad and LayerBank, and when Merlin honoured a pre-exploit snapshot for MBTC holders those two protocols were left holding the devalued token.
ZachXBT pointed out at the time that Ionic was a relaunch of the twice-exploited Midas protocol; separate coverage noted that Ionic had launched on an outdated 2022 audit inherited from Midas. Ionic never published a post-mortem. In June 2026 the team announced a permanent shutdown and told users to withdraw from all deployed chains; users reported that pools lacked the liquidity to let them do so, and some were still asking for the return of ezETH that the exploit had not touched.
Sources
- HalbornSecondary · retrieved 2026-08-01
- rekt.newsSecondary · retrieved 2026-08-01
- TechFlow (reporting QuillAudits monitoring)Secondary · retrieved 2026-08-01
- ChainCatcher (reporting QuillAudits monitoring)Secondary · retrieved 2026-08-01
- CryptoDifferAggregator · retrieved 2026-08-01
- Phemex NewsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ionic Money hack — February 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ionic-moneyhttps://itokenly.com/hacks/ionic-moneyPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.