The company Realio confirmed the attack and stated that the realio.fund web application was compromised, access to the platform has been stopped, and movement of funds in client wallets has been blocked. The Freehold and Districts projects were not affected, and the Algorand and Stellar bridges will remain closed indefinitely.
Independent blockchain researchers recorded mass transfers across the Ethereum, $BNB Chain, Algorand, Stellar, and native Realio networks. The transactions went to addresses created just hours before the attack. It is believed that the attack is related to compromised signature keys stored on the platform, rather than a smart contract hack.
The majority of the stolen funds were not in free circulation in investor wallets but in blockchain reserves. 43.85 million RIO were withdrawn from the Algorand ASA treasury, and 69.87 million from the Stellar treasury. In total, this amounts to 113.7 million tokens, or 91.4% of the total theft volume—this volume was previously not accounted for in the token's supply.
10.7 million RIO were stolen from users, representing 3.27% of the circulating supply on the day before the attack. This includes 5.73 million RIO withdrawn from accounts on the native network, 2.2 million from $BNB Chain wallets, 2.12 million from Algorand and Stellar wallets, and 638,286 tokens from Ethereum accounts, with this network seeing the highest number of affected users.
Due to low liquidity, the hackers' proceeds amounted to only 3.7% of the nominal value of the stolen assets. For example, on the Stellar decentralized exchange, 2,976,145 RIO were sold in 533 transactions for a mere 115,296 XLM ($21,900). The order book was too thin: continuous sales drove down the price faster than orders could be filled. Trading on the Stellar exchange was suspended for several hours.
Out of the 124.4 million stolen tokens, only 5,732,041 RIO on the native network have been liquidated so far, which has now halted operations. 68,220,776 RIO in the Stellar network and 43,409,824 RIO in Algorand remain in the attackers' accounts.
Recently, unknown individuals stole about $7.5 million from an account on the TAC blockchain, the project team reported. The hackers exploited a vulnerability in a special component of the software code—the precompilation layer of the Cosmos EVM module.





