An attacker moved 124.4 million RIO out of Realio-controlled wallets and user accounts across five chains on August 25 but realized roughly $234,000 from it, according to an independent on-chain incident report, against a nominal value of about $6.3 million at prevailing prices.
Realio confirmed the attack in a post on Tuesday evening, saying the realio.fund webapp had been compromised, platform access halted, and no funds were moving in or out of user wallets.
The report is published by realiostats, a community-led project that tracks RIO circulating supply across all seven chains and states it is not affiliated with or endorsed by the Realio team. It is maintained by the operator of a RIO validator and solicits delegations, a position readers should weigh; its code and methodology are public, and it publicly flagged and corrected an erroneous figure its own automated pipeline produced during the incident.
What Moved
The sweeps ran between 03:31 and 10:15 UTC across Ethereum, BNB Chain, Algorand, Stellar, and Realio’s native chain into accounts created the same morning.
Most of the total was not in circulation. The Algorand ASA reserve gave up 43.85 million RIO, and the Stellar treasury gave up 69.87 million—totaling 113.7 million, or 91.4% of the take, all previously excluded from circulating supply.
The portion taken from users totals 10.7 million RIO, equal to 3.27% of circulating supply the day before. It breaks down as 5.73 million swept from 2,374 native chain accounts, 2.2 million from 163 BNB Chain wallets, 2.12 million from Algorand and Stellar user wallets, and 638,286 from 121 Ethereum accounts.
The Ethereum leg was larger in people than in value. A second, deprecated RIO contract was swept from 184 further accounts, along with USDC and ETH, bringing the Ethereum total to 263 addresses. The legacy token trades at roughly 5% of current RIO, making that portion worth about $1,200.
The Gap Between Taken and Realized
The analysis prices the attacker’s total realized proceeds at $234,480, read at 19:15 UTC with RIO at $0.0508—about 3.7% of the nominal value taken.
The constraint is liquidity. Selling on the Stellar decentralized exchange produced 2,976,145 RIO sold across 533 trades for 115,296 XLM, roughly $21,900, an effective $0.0074 per RIO against a $0.0508 spot price. The report attributes this to an order book thin enough that continuous selling walks the price down faster than it fills.
The BNB chain leg moved fastest and fared similarly. The full 2.2 million RIO left the collecting address within 46 minutes of the sweep ending, routed through intermediary contracts into the RIO/USDT and RIO/WBNB pairs, realizing roughly $24,000—about $0.011 per RIO, an 80% discount. The entire RIO/USDT pool holds around $4,500.
The largest single item in the realized total is 64.87 ETH, worth about $160,000, which the report notes is not RIO proceeds. The same address on Ethereum held no ETH sixteen minutes before the sweep began. Ethereum victims lost 32.63 ETH between them; the remaining balance is unsourced, and the report declines to speculate.
One figure cannot be established from chain data: 2,066,161 RIO was deposited to a MEXC address, and whatever it sold for happened on internal exchange books.
What Is Actually Frozen
Realio’s post states the market impact was limited and that the attacker was not able to sell much before everything was frozen.
The on-chain record supports the first part and qualifies the second. Of the 124.4 million taken, the report finds only the 5,732,041 on the native chain is genuinely immobilized, and only while that chain stays down. The attacker still holds 68,220,776 RIO in the Stellar receiving account and 43,409,824 in the Algorand receiving account, and both EVM legs were dispersed the same morning.
Selling on the Stellar DEX paused at 18:14:51 UTC, roughly three and a half hours before Realio’s post. It had paused once before, at 09:47, and resumed at 12:00, running hardest through the afternoon.
The Algorand side has been static since 08:29:02, after MEXC and KuCoin suspended RIO deposits on that network following community alerts. Realio said it has identified deposits by the attacker into both exchanges and is in contact with them.
The report draws a distinction between the two: an exchange can suspend deposits because a company decides to, while the Stellar DEX is part of the ledger itself, with no deposit step, no listing to pull, and nobody to petition.
Neither the Algorand nor the Stellar asset has clawback enabled. The Stellar issuer carries auth_clawback_enabled set to false and auth_immutable set to true, meaning it cannot be changed later.
The Halted Chain
Realio’s native chain stopped producing blocks at 10:38:05 UTC at height 19,573,265, 23 minutes after the last native sweep transfer, at the lead developer’s request.
In the validator Discord at 19:01, Realio’s lead developer said the chain would stay halted for the time being, possibly a few days, while the team investigates, ensures no further damage can be done, and plans next steps with validators.
The report notes that a Cosmos network restarting from a pre-incident height would reverse those transfers outright, making the native portion potentially recoverable rather than lost—a decision for the team and validator set. Chain halts have featured in several incidents this year: BounceBit shut its chain permanently on August 21 after an exploit involving 286.5 million BB, reissuing its token on BNB Chain from a pre-attack snapshot.
What the Pattern Indicates
The analysis stops short of naming a cause but records several observations.
Every sampled Algorand source account held exactly 0.20 ALGO—the protocol minimum for an account plus one asset opt-in. The report reads thousands of accounts sitting at precisely that minimum as the shape of automatically generated custodial sub-accounts rather than independent self-custody wallets.
No sampled account had been rekeyed, which would be the signature of a phishing or approval-drainer campaign. The Stellar receiving account was created and funded by the realio.fund treasury itself at 03:31, before any sweep began. Deposits continued arriving at the drained addresses during the operation and were swept again.
Taken together, the report concludes this points to compromise of signing keys held by the platform rather than a smart contract exploit or a campaign against individual users. Realio’s own statement that realio.fund wallets were drained is consistent with that reading. Key compromise has been the recurring failure mode this year rather than contract logic—Stake DAO lost control of a deployer key in May, allowing an attacker to mint 5.4 trillion vsdCRV on Arbitrum before the bridge was closed.
Realio said Freehold and Districts are not impacted, that the Algorand and Stellar bridges will remain closed indefinitely, and that users should not use the realio.fund webapp. It said it believes centralized exchanges can safely resume deposits and withdrawals on BNB Chain and that it will work with law enforcement.
