Orbit Chain Hack
Incident Overview
Orbit Chain suffered a private key compromise exploit on Dec 31, 2023, resulting in a loss of 81,540,000 USD worth of various assets.
Orbit Chain, a South Korean cross-chain project, experienced a private key compromise exploit on its Orbit Bridge. The attacker drained funds from the Bridge Contract, swapping them to ETH and DAI, and distributing the stolen assets among several EOA addresses. The attacker was funded via TornadoCash, and some experts tie the incident to the Lazarus Group, a global hacking syndicate. The Orbit Chain team is working with law enforcement agencies to investigate the incident. Blockchain experts suggests that the root cause is the compromise of 7 out of 10 multisig signers wallets. The team sent an on-chain message to the exploiter, warning that some transactions were detected in 'C' exchange and calling for discussion.
Losses reached 81,540,000 USD worth assets in total, including:
- 30,000,000 USDT
- 9,530 ETH
- 10,000,000 DAI
- 10,000,000 USDC
- 230.879 WBTC
Attacker Address:
https://etherscan.io/address/0x9263e787…176aff
Funds Holders as of January 6, 2024:
https://etherscan.io/address/0x009b60aa…fffcc5
https://etherscan.io/address/0x5e22cb02…8dc085
https://etherscan.io/address/0x3a886a63…b4f730
https://etherscan.io/address/0x157a409c…3dd664
https://etherscan.io/address/0xf49de491…f179fd
https://etherscan.io/address/0x589257E0…e36B7D
https://etherscan.io/address/0x817bb176…F4C0EF
Malicious Transactions:
https://etherscan.io/tx/0xd8ca4294…b80ac8
https://etherscan.io/tx/0x64a6f486…1a3f0e
https://etherscan.io/tx/0x639d27e5…48ae0a
https://etherscan.io/tx/0xe0bada18…7271f9
https://etherscan.io/tx/0xafdc3627…1b07ca
https://etherscan.io/tx/0x958aeec5…d95f16
TornadoCash Funding Transaction:
https://etherscan.io/tx/0x5e35f4b1…bd09dd
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Orbit Chain, these are the critical security checks that could have prevented this incident (December 2023).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Web Archive https://archive.is/t0Rup
Learn to Prevent the Next Orbit Chain
The Orbit Chain hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.