IoTeX, a DePIN-focused blockchain, suffered a private key intrusion on its cross-chain bridge contracts. Attackers drained multiple assets including USDC, USDT, IOTX, and WBTC from the vault. The official statement pegs the loss at approximately $2 million, adding that risks have been contained and on-chain operations plus deposit/withdrawal services should resume within 24 to 48 hours.
Blockchain security firm PeckShield reported that the attacker gained full control over two contracts — TokenSafe and MinterPool — via compromised private keys. Stolen assets also include BUSD and PAYG. PeckShield's preliminary estimate stood at $8.8 million, while another analyst, Specter, calculated $4.3 million. The discrepancy? IoTeX co-founder Raullen Chai told The Block that the same key was used to mint millions of CIOTX and CCS tokens, but those tokens "have no real value" and have been frozen, hence they should not count toward the loss.
Private Key Attacks Accounted for 88% of Stolen Funds in Q1 2025
According to blockchain security statistics, 88% of stolen funds in Q1 2025 came from private key compromises. Over the year, such attacks made up only 13% of incidents but caused nearly $1 billion in losses, with per-event averages far exceeding smart contract exploits. The logic is brutal: breaking into a private key grants admin-level access, unrestricted by code boundaries.
The Structural Weakness of Cross-Chain Bridges
Cross-chain bridges remain one of the most frequently breached infrastructure types in crypto. From the $625 million Ronin Bridge hack and $320 million Wormhole exploit in 2022, to the $126 million Multichain incident in 2023, and numerous smaller attacks since — the pattern is consistent: attackers target private keys or validator control.
The issue isn't contract quality. Most bridge contracts pass audits. The problem lies in the architecture: every cross-chain bridge needs an entity — a set of validators, a multi-sig wallet, or a private key — to vouch for asset correspondence between chains. That "guarantor" becomes the biggest attack surface. You can audit the contracts a hundred times, but if the private key management process or the device holding it is compromised, all audit reports become expensive placebos.
In 2026, cross-chain bridges are still the weakest link in crypto infrastructure. The risk is baked into their DNA: as long as the design requires someone to hold a key, that key can always be stolen.

