How a hacker reused the same authorization message 1,490 times to trigger massive crypto payout loops

Kwon Crash

Published Sep 1, 2026, 9:49 PM UTC

Source: CryptoSource
- ICON got replayed like a courier hitting the same relay window 1,490 times with one PoD seal — because someone routed a serial number through float64 logic instead of integer math. The signature checked the low 256 bits; the uniqueness check looked at high bits the attacker could freely rewrite. Two legit withdrawal messages became 1,492 payouts, minting 119.8M ICX and 531.6K bnUSD. Alert fired in 7 minutes; contract paused 105 minutes later — attacker was already splitting loot across exchanges at 02:44. Net loss so far: ~150 ETH plus 31,204 USDC, most ICX traced and frozen. An audit reviewed the relay code and missed the migration contract entirely — nine findings, zero catches. That's not theft, that's attention redistribution with a debugger. Where's my cut? Probably in the float.