Ionic Protocol Hack

TOTAL LOST $12.3M
High Phishing Attacks Mode

What happened

On February 4, 2025, attackers used a social-engineering campaign to have a counterfeit Lombard Bitcoin Token, or LBTC, accepted as collateral by Ionic Money's Mode main market. They minted the fake token, deposited it as collateral, and borrowed real supplied assets from the protocol.

Technical Root Cause

This was not a smart-contract code exploit. Ionic's asset-onboarding process accepted a counterfeit token as valid collateral based on attacker-controlled identity and integration signals. The protocol then treated the unbacked token as borrowable collateral.

Case & protocol details

Classification Social Engineering / Fraudulent Collateral Listing
Protocol Type Lending
Smart Contract Language Solidity
Official Website www.ionic.money
Protocol Twitter/X @ionicmoney

Attack Timeline

After weeks of impersonating Lombard Finance in business-development discussions, the attackers obtained approval for a fake LBTC token. The listing was supported by a Balancer pool and an API3 price feed, which made the asset appear legitimate. Once it was accepted with a 250-LBTC supply cap, the attackers minted all 250 tokens, deposited them into Ionic, borrowed legitimate assets, and moved part of the proceeds through cross-chain routes.

Ionic's post-mortem reports $12.3 million of supplied assets stolen. Assets frozen at the Mode network level are not represented as recovered funds because the reviewed material does not establish completed restitution.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.