Orbit Chain suffered an attack of $80 million, raising alarm bells for the security of cross-chain bridges.

robot
Abstract generation in progress

Orbit Chain was attacked, resulting in a loss of approximately 80 million USD.

On January 1, 2024, a security risk monitoring platform discovered that the Orbit_Chain project had been attacked, resulting in losses of approximately $80 million. Analysis showed that the attackers had initiated a small-scale attack a day earlier and used stolen ETH as the source of transaction fees for the subsequent large-scale attack.

Orbit Chain is a cross-chain bridge platform that allows users to use encrypted assets from different blockchains on one chain. Currently, the project team has suspended the cross-chain bridge contract and is attempting to communicate with the attacker.

How did Orbit Chain get hacked for $80 million, the first major case of the year?

Event Analysis

The attack primarily executed asset transfers by directly invoking the withdraw function of the Orbit Chain: Bridge contract. The withdraw function uses verified signatures to ensure the safety and legitimacy of the disbursement.

Further analysis shows that the signature verification function (_validate) returns the number of owner signatures. If this number is greater than or equal to the required value, the funds will be released. On-chain data indicates that there are a total of 10 administrator addresses for this contract, and the required value is 7, meaning that 70% of administrators' signatures are needed to withdraw assets.

In summary, this incident may have been caused by a phishing attack on the server that stores the administrator's private keys.

How did Orbit Chain get hacked for 80 million dollars, the first major case of the year?

Attack Process

On-chain data shows that the attacker began a small-scale attack on the Orbit_Chain project on December 30, 2023, at 15:39:35 (UTC), and distributed the stolen small amount of ETH to other attack addresses as transaction fees.

How did the $80 million theft of Orbit Chain, the first major case of the year, happen?

Subsequently, on December 31, 2023, at 21:00 (UTC), multiple attack addresses began large-scale attacks on assets such as DAI, WBTC, ETH, USDC, and USDT of the Orbit_Chain project.

How did Orbit Chain get hacked for 80 million USD, the first major case of the year?

Fund Tracking

As of the time of publication, the transfer status of the stolen funds is as follows: The attackers have dispersed the stolen funds to five different addresses. Specifically, they include:

  1. 50 million US dollars in stablecoins (30 million USDT, 10 million DAI, and 10 million USDC)
  2. 231 wBTC (approximately 10 million USD)
  3. 9500 ETH (approximately 21.5 million USD)

How did Orbit Chain get hacked for 80 million dollars, the first major case of the year?

How did Orbit Chain's $80 million theft happen, the first major case of the year?

How did Orbit Chain's $80 million theft happen, the first major case of the year?

How did Orbit Chain's $80 million theft happen, the first major case of the year?

How did Orbit Chain get hacked for $80 million, the first major case of the year?

How did Orbit Chain get hacked for 80 million dollars, the first major case of the year?

How did the $80 million theft of Orbit Chain happen, the first major case of the year?

How did Orbit Chain's $80 million theft happen, the first major case of the year?

Security Insights

This cross-chain bridge security incident again emphasizes the importance of security in the design and implementation of blockchain systems:

  1. Code Security: The contract code is the core of the blockchain system, and it should strictly follow security standards during writing and review to avoid common vulnerabilities.

  2. Authentication and Identity Verification: Ensure that only authorized users or contracts can perform critical operations to prevent unauthorized access and asset loss. Implementing robust authentication mechanisms, multi-signature, and permission management measures can effectively restrict access rights.

How did Orbit Chain get hacked for 80 million dollars, the first major incident of the year?

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
gas_guzzlervip
· 08-05 12:49
Stolen again!
View OriginalReply0
MetaverseMigrantvip
· 08-05 12:47
Old Year New Hacker, scatter wealth begins
View OriginalReply0
MagicBeanvip
· 08-05 12:46
New Year's first surprise? Laughing to death.
View OriginalReply0
RugPullAlarmvip
· 08-05 12:43
I mentioned before that the first risk of cross-chain bridges is who audits the smart contracts?
View OriginalReply0
FloorSweepervip
· 08-05 12:39
just another weak bridge getting rekt... seen this movie b4 tbh
Reply0
Hash_Banditvip
· 08-05 12:37
damn another bridge getting rekt... when will they learn to patch these exploits smh
Reply0
OnchainHolmesvip
· 08-05 12:30
Being played for suckers right at the start of the new year?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)