Orange Finance Hack
What happened
On January 8, 2025, Orange Finance said all active vaults were exploited after an attacker gained control of its Safe wallet. The project reported approximately $843,557 in losses: deposited assets, excessively approved assets, and unclaimed rewards. Its follow-up attributes the incident to a Safe configuration that permitted single-signature execution together with inadequate key-management and internal controls.
How it happened
- The attacker transferred ERC-20 assets from the Safe wallet and withdrew unclaimed rewards.
- It changed vault ownership settings and replaced vault implementations with attacker-controlled versions.
- It burned positions and transferred vault token balances to its own address.
- It withdrew overly approved user assets and swapped stolen ERC-20 tokens for ETH.
Protocol details
Security review history
- WatchPug View report
- Zokyo View report
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.