OrdiZK Hack
Incident Overview
OrdiZK conducted an exit scam, resulting in the deletion of its website and social media accounts. The project's deployer and team wallets hold around $1.4 million worth of ETH obtained through fraudulent activities.
The exit scam involving OrdiZK unfolded with the sudden disappearance of its website and social media presence. Investigations revealed that the project's deployer, along with other team wallets, orchestrated the scam, leading to significant financial losses. The deployer alone holds over $1 million worth of ETH, while the OrdiZK treasury and marketing wallets contain substantial amounts as well.
The scam involved dumping tokens, removing ETH from project contracts, and diverting funds allocated for sales taxes. As a result, investors and participants in the OrdiZK project were left without recourse, facing substantial losses due to the fraudulent activities of the project team.
Deployer/Scammer
https://etherscan.io/address/0xbfdd36f5…679c83
Example of sell TX:
https://etherscan.io/tx/0xf1e612c2…1d7b33
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to OrdiZK, these are the critical security checks that could have prevented this incident (March 2024).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next OrdiZK
The OrdiZK hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.