Orange Finance Hack

Reported loss $840K
Arbitrum
Private Key Compromised (Unknown Method)

What happened

On January 8, 2025, Orange Finance said all active vaults were exploited after an attacker gained control of its Safe wallet. The project reported approximately $843,557 in losses: deposited assets, excessively approved assets, and unclaimed rewards. Its follow-up attributes the incident to a Safe configuration that permitted single-signature execution together with inadequate key-management and internal controls.

How it happened

  1. The attacker transferred ERC-20 assets from the Safe wallet and withdrew unclaimed rewards.
  2. It changed vault ownership settings and replaced vault implementations with attacker-controlled versions.
  3. It burned positions and transferred vault token balances to its own address.
  4. It withdrew overly approved user assets and swapped stolen ERC-20 tokens for ETH.

Protocol details

Classification Infrastructure / Yield Aggregator / Key Compromise
Protocol Type Liquidity manager
Implementation language Solidity

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.