🚨 GoPlus Security Alert:
Aug 25:
@realio_network’s realio[.]fund got hit. Attackers seized the platform’s signing stack and swept treasury + custodial wallets across 5 chains.
127.9M $RIO gone ($6.2M). Attacker has cashed out ~$317K so far.
Root cause: platform signing keys were taken over.
realio[.]fund ran one hot signer for treasury, reserves, and user custody sub-accounts. Once that capability was in hostile hands, they could sign transfers straight out on Ethereum, BNB Chain, Algorand, Stellar, and Realio’s native chain.
No user approval.
No rekey.
No contract bug.
A multi-chain RWA issuer put user funds and treasury signing on the same webapp surface. Economically, that keyset is just a cluster of hot wallets.
Last night, the webapp fell victim to an attack. Access to the platform has been halted, and no more funds are moving in or out of user wallets. This report, created by an independent community member, provides a detailed summary of the event: The team is working on a recovery plan and verification of the incident details. Please do not purchase $RIO on Algorand or Stellar; the bridges to these chains will remain closed indefinitely. Freehold and Districts are not impacted by this. Please do not use the webapp anymore; Freehold is the only wallet we are actively maintaining going forward. We have identified deposits by the attacker into both
@MEXC and
@kucoincom and are in contact with them. The market impact on $RIO was limited, and the attacker was not able to sell much before everything was frozen. We believe CEXs can safely begin enabling deposits/withdrawals on BNB Chain again. We will work with law enforcement to identify the attacker.
Show more