logo

How CertiK's Formal Verification Engine Could Have Detected ICX's EnableTokenTransfer Issue

ID: 3cceb52e-f0e7-52ce-8b86-3218a0beb70f

STIX ID: report--3cceb52e-f0e7-52ce-8b86-3218a0beb70f

Feed Name: CertiK Blog

Threat Score
55/100

Date Published: 2018-06-17

Date Updated: 2026-06-11

...
...

On Jun 16th 2018 a logic bug was reported in ICON's ICX token contract: a require statement used 'msg.sender != walletAddress' instead of 'msg.sender == walletAddress', which allowed anyone other than the owner to enable or disable token transfers. Attackers exploited this to disable ICX transfers and halt thousands of transactions; while tokens were not stolen, the incident disrupted functionality and prompted mitigation and public statements from the ICON team and offers of formal verification from CertiK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.