IoTeX’s ioTube cross-chain bridge was exploited on February 21, 2026 after an attacker obtained control of a privileged key connected to its Ethereum-side infrastructure. IoTeX said during the incident that it had contained the situation and was securing the chain; its contemporaneous estimate put the impact at about $2 million in USDC, USDT, IOTX and WBTC.
The breach mattered because ioTube connected Ethereum and other networks with the IoTeX ecosystem. A bridge is not the same system as the layer-one chain it serves, but bridge reserves and wrapped assets depend on operators enforcing the connection correctly. On February 21, that distinction became operationally important: IoTeX maintained that its core consensus and native chain assets were not compromised even as the network stopped processing blocks while the response proceeded.
What the event-day record established
IoTeX’s first public alert said it was investigating suspicious activity involving an IoTeX token safe and that its initial loss estimate was substantially below figures circulating publicly. In a second February 21 statement, the project said the incident was contained, described the confirmed impact as around $2 million and said it was working with exchanges, security partners and law enforcement to trace and freeze assets.
Contemporaneous reporting by The Block, published at 12:17 p.m. Eastern and updated at 12:29 p.m. Eastern, attributed the breach to a compromised private key that enabled control over the TokenSafe and MinterPool contracts. On-chain researchers cited by the publication estimated roughly $4.3 million of reserve tokens had been removed and also counted newly minted CIOTX and CCS when producing estimates above $8 million. IoTeX co-founder Raullen Chai disputed those larger loss figures and told the publication that the amount then identified was around $2 million.
Those figures measured different things. The project’s estimate described the impact it considered confirmed during an unfinished response. The higher estimates combined reserve assets with minted tokens valued at observed market prices, even though liquidity, freezing and redemption constraints could make nominal token value different from realizable loss. Coinburn therefore does not collapse the estimates into a single event-day total.
Why the control failure mattered
The incident exposed a governance problem as much as a theft. A privileged bridge key could affect contracts holding reserves and contracts issuing cross-chain representations. If validation can be bypassed through administrative control, users face not only the loss of deposited assets but uncertainty over which wrapped tokens remain backed.
IoTeX’s decision to secure the chain and coordinate freezes reduced the attacker’s available exit paths, according to the project. It also interrupted a network whose consensus was not itself described as breached. That tradeoff showed how an application-layer bridge incident can propagate into chain operations, exchange deposits and token liquidity even when the base protocol’s consensus rules remain intact.
The event-day record did not establish how the key was obtained, who controlled the attacker addresses or what amount would ultimately be recovered. Claims of a long-planned operation and links to other exploits remained preliminary and should not be treated as attribution.
Later primary clarification
IoTeX’s February 23 technical update said the compromised Validator owner account was used to install malicious code, bypass checks, take control of MintPool and TokenSafe, mint 410 million CIOTX and drain approximately $4.4 million of bridge reserves. A March 28 retrospective placed the malicious upgrade at 01:51 UTC on February 21, detection at 08:01 UTC, the first public alert at 09:39 UTC and the precautionary chain suspension at 10:03 UTC. Those details were published after February 21 and clarify the mechanism and timeline; they were not all available to market participants during the incident.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

