IOTA Validators Freeze Attacker Wallets Following Virtue Protocol Exploit

The IOTA community is responding to the recent security incident involving the Virtue CDP protocol, with community validators reportedly applying a deny-list to wallets associated with the attacker. According to TokenLabs.network, more than one-third of the network’s stake is participating in the measure, preventing transactions linked to the attacker from gathering the consensus quorum required…

4 minutes

Read Time

IOTA

The IOTA community is responding to the recent security incident involving the Virtue CDP protocol, with community validators reportedly applying a deny-list to wallets associated with the attacker. According to TokenLabs.network, more than one-third of the network’s stake is participating in the measure, preventing transactions linked to the attacker from gathering the consensus quorum required to land on-chain.

The move comes as Virtue continues remediation work following an exploit that left its VUSD stablecoin materially undercollateralized. The protocol has been frozen, with borrowing, repayments, deposits, withdrawals, liquidations and flash loans temporarily halted while the team investigates the incident and prepares a recovery plan.

The situation has also raised questions about security infrastructure within emerging decentralized finance ecosystems. While the exploit targeted Virtue’s pricing system rather than the underlying IOTA protocol itself, the incident demonstrates how vulnerabilities in external oracle infrastructure can create serious consequences for applications built on blockchain networks.

Virtue has urged users not to purchase VUSD with the expectation that it will be redeemed at its intended one-dollar value. The protocol said remediation remains underway and warned that users should be cautious of scams and impersonators claiming to offer compensation or recovery services.

How the Virtue Exploit Happened

According to Virtue’s incident report, the attack began on August 28 when the Switchboard price feed used by the protocol for IOTA pricing was manipulated. The attacker reportedly gained control of signing keys used by all fourteen oracles on Switchboard’s IOTA mainnet queue, allowing arbitrary IOTA prices to be reported.

The vulnerability was linked to a mechanism used to rotate oracle signing keys. Virtue said that, on the affected deployment, the mechanism could reportedly be invoked without an existing privileged authority, giving the attacker control over the authorized signer set.

Related: IOTA Mainnet Release v1.30.1 Introduces Protocol 33 for Trade Infrastructure

The manipulated data still passed Virtue’s configured verification checks because the feed came from the expected source and was signed by registered oracles. However, the protocol acknowledged that its controls did not include sufficient price magnitude checks, such as deviation limits or price bands.

During the attack, the IOTA price feed was reportedly pushed to $10 million per token, allowing the attacker to deposit one IOTA and mint millions of VUSD. The feed was later pushed dramatically lower, triggering liquidations against otherwise healthy positions.

Virtue said 47 liquidation events affected 45 users. The protocol has stated that making those users whole is its first priority and that it has reconstructed the affected positions using on-chain data.

IOTA Validators Move to Limit Further Damage

The response from IOTA community validators represents an unusual layer of coordinated defense. By applying a deny-list to attacker wallets, participating validators can refuse to support transactions associated with those addresses, preventing them from reaching the required consensus threshold.

TokenLabs.network said more than one-third of the network’s stake was participating in the measure. The apparent goal is to prevent the attacker from moving assets on-chain and potentially selling assets while Virtue and the wider ecosystem work on remediation.

The decision also highlights the difficult balance between decentralization and emergency intervention. Supporters may view the action as a practical attempt to protect users during an active security crisis, while others may question how such coordinated transaction blocking fits within the principles of permissionless blockchain infrastructure.

Related: IOTA Targets Global Trade Infrastructure as the $35 Trillion Market Faces a Trust Problem

For affected Virtue users, the immediate focus remains remediation. The protocol has said it will publish details of its recovery process before taking action and will not make unilateral decisions regarding Stability Pool balances that may have received collateral from the forced liquidations.

The incident is also a reminder that DeFi security depends on more than smart contract code alone. Oracles, signing systems and external infrastructure can become critical points of failure, particularly when protocols rely on price data to determine collateral values and trigger liquidations.

As remediation continues, Virtue has warned users to remain alert for scams. The team said it will never contact users first through direct messages, request wallet connections or signatures, ask for recovery fees, or operate a claim portal. For now, the Virtue exploit has become a major test of how the IOTA ecosystem responds when vulnerabilities in connected infrastructure threaten users and decentralized financial applications.

About The Author

About the Author

AltCoinsAnalysis.Com

The site primarily publishes price narratives, project updates, regulatory headlines, and speculative market insights, targeting traders and investors who want quick reads on potential opportunities in the crypto space. Its content style is opinionated and momentum-focused, often centered around market hype cycles such as altcoin seasons, ETF developments, and major token announcements.

Search the Archives

Access over the years of investigative journalism and breaking reports