YFarmX

Tools Crypto Exploit Tracker exploit-0065

Exploit record

IoTeX ioTube Bridge

Loss
$4M
Attack vector
Access Control
Chain
Ethereum
Sector
Bridge

What happened

On February 21, 2026, IoTeX's ioTube bridge lost about $4.4M on the Ethereum side after attackers compromised the Validator owner account and upgraded it to bypass the bridge's security checks.

Once the owner account was in hostile hands, the attacker replaced the Validator logic with something that effectively waved everything through. That broke the trust boundary protecting the MintPool and TokenSafe contracts, letting the attacker mint bridge-side assets and drain reserve tokens. IoTeX managed to freeze and blacklist a meaningful slice of the fallout, but not before real value had already left.

On-chain references

  • Attacker Address0x6487B5006904f3Db3C4a3654409AE92b87eD442f

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026