T
iTokenly

IoTeX (ioTube bridge) hack — February 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 21, 2026
Target typeCross-chain bridge
Loss$4,400,000Published estimates range $4,300,000 to $8,800,000Price at time of incident
MethodPrivate key compromiseA private key controlling the owner account of the ioTube Validator contract on Ethereum was used to upgrade that contract to a malicious implementation which bypassed signature and validation checks, handing the attacker control of the bridge's TokenSafe reserve and its minting pool. IoTeX says the key was obtained after an employee machine was compromised in a suspected social engineering attack and the intruder dwelled in its infrastructure.
ChainsEthereum, Other
Attributed toUnidentified actor that IoTeX says Chainalysis linked to the group behind the $49 million Infini exploitSuspected
OutcomeUsers reimbursed

What happened

IoTeX's ioTube cross-chain bridge was exploited on 21 February 2026. By IoTeX's own account the attacker had first compromised an employee machine, in what the project described as a suspected social engineering attack, and had persisted inside its infrastructure for a prolonged period before using a private key that controlled the ioTube Validator contract on Ethereum. At 01:51 UTC the key was used to upgrade that contract to a malicious version that bypassed the bridge's signature and validation checks, giving the attacker control of the TokenSafe reserve and the minting pool. IoTeX detected the breach at 08:01 UTC, issued its first public alert at 09:39 UTC and suspended the chain at 10:03 UTC. IoTeX says its layer-1 chain itself was never compromised and that the incident was confined to the Ethereum-side bridge contracts.

The loss figures were disputed. IoTeX put the drained bridge reserves at about $4.4 million in WBTC, ETH, USDC, USDT, DAI, PAXG, UNI, BUSD and CCS. The analysis firm Specter arrived at about $4.3 million. PeckShield gave a figure above $8 million, and headline numbers as high as $8.8 million circulated because they counted the value of tokens the attacker minted rather than took. IoTeX says 410 million CIOTX were minted; other accounts, including The Block and Halborn, put the mint at about 111 million CIOTX plus 9.3 million CCS. IoTeX froze roughly 45 million of the attacker-held tokens at the network level within 72 hours through a mainnet upgrade, and later deprecated CIOTX across the chains it had been issued on. An initial statement from co-founder Raullen Chai put the loss near $2 million; the project later revised the number upward.

Proceeds were swapped into ether and partly bridged toward Bitcoin through THORChain, which analysts said made recovery unlikely. Chai offered a 10% white-hat bounty of about $440,000 for return within 48 hours; it was not taken up. IoTeX committed to compensating affected users in full from its foundation treasury and opened a claims portal on 2 March 2026.

Sources

  1. IoTeXPrimary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.iotex.io/blog/how-iotex-responded-to-the-iotube-bridge-incident-a-full-month-in-review/

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "IoTeX (ioTube bridge) hack — February 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/iotex-iotube-bridge
https://itokenly.com/hacks/iotex-iotube-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.