Ionic Protocol Hack
What happened
On February 4, 2025, attackers used a social-engineering campaign to have a counterfeit Lombard Bitcoin Token, or LBTC, accepted as collateral by Ionic Money's Mode main market. They minted the fake token, deposited it as collateral, and borrowed real supplied assets from the protocol.
This was not a smart-contract code exploit. Ionic's asset-onboarding process accepted a counterfeit token as valid collateral based on attacker-controlled identity and integration signals. The protocol then treated the unbacked token as borrowable collateral.
Case & protocol details
Attack Timeline
After weeks of impersonating Lombard Finance in business-development discussions, the attackers obtained approval for a fake LBTC token. The listing was supported by a Balancer pool and an API3 price feed, which made the asset appear legitimate. Once it was accepted with a 250-LBTC supply cap, the attackers minted all 250 tokens, deposited them into Ionic, borrowed legitimate assets, and moved part of the proceeds through cross-chain routes.
Ionic's post-mortem reports $12.3 million of supplied assets stolen. Assets frozen at the Mode network level are not represented as recovered funds because the reviewed material does not establish completed restitution.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.