Event Overview

Recently, on-chain analyst Specter reported that IoTeX's private key may have been compromised, leading to the complete draining of its token vault with an estimated loss of $4.3 million.

Attack Details

Multiple contract assets were transferred by the attacker, including USDC, USDT, IOTX, PAYG, WBTC, and BUSD. The stolen funds were later converted into ETH, with 45 ETH already bridged to the Bitcoin network.

Industry Impact

This incident has raised concerns about smart contract security, prompting experts to call for improved private key management and on-chain monitoring solutions.