Fake LBTC Listing Lets Attacker Drain $6.9M From Ionic Money on Mode
Ionic Money, the Mode network lending protocol that rebranded from the twice-exploited Midas project, lost roughly $6.9 million after attackers posing as representatives of Lombard Finance persuaded the team to list a counterfeit version of the LBTC token as collateral.
01Background: the Midas connection

ZachXBT was first to point out that Ionic Money is effectively a renamed continuation of Midas, the protocol behind two earlier incidents in 2023: a $660,000 loss and a subsequent $600,000 exploit. Ionic's own introduction post on Medium describes the lineage between the two projects.
02How the exploit unfolded
Ionic first acknowledged an "ongoing exploit" on February 4th via a post on X, on the same platform where Mode Network operates its community channels.
According to analysis published by CertiK, the mechanics of the attack were straightforward: the attacker deployed a fake collateral asset, drained the vaults that accepted it, bridged the proceeds to Ethereum, and routed funds through Tornado Cash.
QuillAudits traced the attacker's on-chain history back to a wallet funded with just 0.01 ETH. From that starting point, the attacker built a fraudulent LBTC token contract designed to be indistinguishable from the legitimate asset.
Lombard Finance confirmed the situation in a statement, noting that "an unofficial LBTC has been deployed as collateral on the Ionic Money platform on Mode network."
03On-chain details
- Exploiter address: 0x9E34d89C013Da3BF65fc02b59B6F27D710850430
- Fake LBTC contract: 0x964dd444e3192f636322229080a576077b06fba3
- Minting of 250 counterfeit LBTC: transaction 0x9aa3fd43a6b0f85b4f1bf74f0c9e79773f238591d9c6fe666287bd2c8ac19009
With the fake tokens minted, the attacker supplied them to Ionic Money as collateral and began borrowing against them, withdrawing MBTC, uniBTC, wrsETH, WETH, STONE and other assets.
- Supplying fake LBTC to Ionic (example transaction): 0x37e53b15cb7f298bd8c45fcbbd914ba90feb3946f5511fc55bc986b7472956df
- Borrowing against the fake collateral (example transaction): 0x5db6d90a17a44bed6d9ed9ca73d800df2661751fa1a273e71fc2174ad3b6944f
Of the borrowed funds, 1,204 ETH (approximately $3.2 million) was bridged to Ethereum and sent into Tornado Cash.
- Laundering address on Ethereum: 0x15Ed470607601274df6ED71172614B67001901Eb
The remainder of the attacker's haul — an estimated 38.34 MBTC, worth more than $3.7 million — was still sitting in open loan positions on Mode at the time of writing, according to portfolio tracking on Parsec and its flow-of-funds view.
04The team's response
In comments posted to Ionic's Discord, a team member characterized the incident as "a sophisticated social engineering exploit," explaining that the attackers had presented a legitimate oracle, a legitimate whitelisted balancer pool, and a token contract with genuine bridging integrations tied to LBTC. In effect, the fraudulent asset was dressed up convincingly enough to pass internal scrutiny.

Some observers have suggested the incident may have involved an insider or compromised internal communications, though this has not been confirmed; alternative explanations point to compromised communication channels more broadly.
05Contagion to other Mode protocols
Because the attacker's borrowed MBTC could be moved and reused across the Mode ecosystem, the fallout extended beyond Ionic Money itself. Reporting indicated that Ironclad and Layerbank were both left holding exposure tied to the compromised MBTC.
Ironclad stated publicly that its markets remained solvent, but Merlin's team subsequently took a selective snapshot that protected certain positions while leaving other holders' MBTC collateral effectively wiped out.
06Summary
The technical execution required no sophisticated contract exploit: the attacker's core move was social engineering — impersonating the Lombard Finance team to get an unofficial, mintable LBTC token whitelisted as collateral on Ionic Money. Once listed, the fake token functioned as a free mint that could be exchanged for real, borrowable assets. As of the reporting, 1,204 ETH (about $3.2 million) had already passed through Tornado Cash, while an additional $3.7 million in loans remained open on Mode network. The episode follows Ionic's rebrand from Midas, a protocol that suffered two separate exploits in 2023, and adds to a run of recent incidents — including a RAT-malware-based attack on Radiant — in which the point of failure was human trust and process rather than smart contract code.
Get new scam files the moment we publish them — usually 2–3 emails a week.