Realio confirmed the attack and stated that the web application realio.fund has been compromised, access to the platform has been halted, and fund movements on client wallets have been blocked. The Freehold and Districts projects are unaffected, and the Algorand and Stellar bridges will remain closed indefinitely.
Independent blockchain researchers have detected mass transfers on the Ethereum, BNB Chain, Algorand, Stellar, and Realio native networks. The transactions were sent to addresses created just hours before the attack. The incident is suspected to be linked to a compromise of signature keys stored on the platform, rather than a smart contract exploit.
Most of the stolen funds were not in circulation on investors' wallets, but rather in blockchain reserves. 43.85 million RIO were withdrawn from the Algorand ASA vault, and 69.87 million from the Stellar treasury. In total, this amounts to 113.7 million tokens, or 91.4% of the total theft — a volume previously unaccounted for in the token offering.
Users lost 10.7 million RIO, representing 3.27% of the circulating supply the day before the attack. Of this, 5.73 million RIO were withdrawn from native network accounts, 2.2 million from BNB Chain wallets, 2.12 million from Algorand and Stellar wallets, and 638,286 tokens from Ethereum accounts—where the highest number of users were affected.
Due to low liquidity, the hackers' proceeds amounted to only 3.7% of the nominal value of the stolen assets. For example, on the decentralized exchange Stellar, 2,976,145 RIO were sold across 533 trades for just 115,296 XLM ($21,900). The order book was too thin: continuous selling depressed the price faster than orders could be filled. Trading on the Stellar exchange was halted for several hours.
Of the 124.4 million stolen tokens, only 5,732,041 RIO have been sold so far on the native network, which is currently offline. The attackers still hold 68,220,776 RIO on the Stellar network and 43,409,824 RIO on Algorand.
Recently, unknown actors stole approximately $7.5 million from a single account on the TAC blockchain, the project team reported. The hackers exploited a vulnerability in a specific component of the codebase—the pre-compilation layer of the Cosmos EVM module.



