GoPlus says Realio attack on Aug. 25 led to roughly $6.2 million in stolen RIO

GoPlus says Realio attack on Aug. 25 led to roughly $6.2 million in stolen RIO

N
News Editor
2026-08-27 10:33:41
GoPlus said Realio Network, a platform focused on RWA tokenized issuance and management, was attacked on Aug. 25 after its signing stack was compromised. The attacker drained treasury and custody wallets across five chains — Ethereum, BNB Chain, Algorand, Stellar and Realio’s native chain — stealing a total of 127.9 million RIO worth about $6.2 million. GoPlus added that around $317,000 has already been cashed out. According to GoPlus Security, the incident stemmed from misuse of the platform’s signing key rather than a smart contract flaw. It said realio[.]fund had been using a single hot signer to manage treasury, reserve funds and user custody subaccounts. Once that permission was obtained, the attacker could sign transfers directly across multiple chains without user approval and without re-keying. Realio said access to the platform has been suspended, and all inbound and outbound transfers for user wallets have been halted. The team said it is preparing a recovery plan, verifying the details of the incident, and will work with law enforcement to identify the attacker.

GoPlus said Realio Network, an RWA tokenized issuance and management platform, was attacked on Aug. 25 after the attacker took control of the platform’s signing stack and drained treasury and custody wallets across five chains.

The affected networks were Ethereum, BNB Chain, Algorand, Stellar and Realio’s native chain. In total, 127.9 million RIO were stolen, with an estimated value of about $6.2 million, according to GoPlus. It added that the attacker has already cashed out roughly $317,000.

GoPlus points to compromised signing keys

GoPlus Security said the root cause was the misuse of the platform’s signing key. It said realio[.]fund had previously used a single hot signer to centrally manage treasury funds, reserves and user custody subaccounts.

With that level of access, the attacker was able to sign transfers directly across multiple chains. GoPlus said the process did not require user approval, did not require re-keying, and did not involve a smart contract vulnerability.

Realio halts access and wallet transfers

Realio said platform access has been suspended and all inbound and outbound transfers for user wallets have been stopped. The team said it is working on a recovery plan, verifying the details of the incident, and will cooperate with law enforcement to determine the attacker’s identity.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.