Summary
On December 31, 2023 (reported January 1, 2024), the Orbit Chain cross-chain bridge lost about $81.5 million when the attacker gained signing control over a majority of validators (analysts cite 7 of 10) and authorized withdrawals from the Ethereum-side vault, draining roughly 30M USDT, 10M USDC, 10M DAI, about 9,500 ETH and 231 WBTC across five transactions to fresh wallets, plus a further transaction disabling the bridge. The root cause was validator private-key/credential compromise enabling improper authorization, not a smart-contract logic flaw; the attack wallet was funded via Tornado Cash. A later statement from developer Ozys alleged that a departing security lead had arbitrarily weakened the firewall policy in November 2023 before leaving without handover, which Ozys treats as the leading access hypothesis, though the causal link remains unproven. The methodical transaction pattern led analysts and South Korean authorities to suspect North Korea's Lazarus Group, but attribution was not formally confirmed. Funds were later laundered via Tornado Cash and not recovered.
How to avoid it in your code
- Hold each validator key on independent, geographically distributed HSMs so one breach cannot yield the threshold.
- Harden and continuously monitor network segmentation and firewall config; alert on any change and require dual approval for edits.
- Enforce mandatory key rotation and credential revocation immediately on staff offboarding, especially security and admin roles.
- Run on-chain anomaly monitoring with automatic circuit-breakers on abnormal withdrawal size, velocity, or fresh-destination patterns.
- Apply withdrawal allowlists plus per-window rate limits and time-locks on large vault outflows to force a human review window.
References
- https://rekt.news/orbit-bridge-rekt
- https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit
- https://decrypt.co/211436/over-80-million-stolen-in-orbit-chain-exploit-assets-remain-unmoved
- https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52
- https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023
Related vulnerabilities
All Web3 →- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- HIGHWEB3-CURVE-DNS-2025
On May 12, 2025, attackers hijacked Curve Finance's primary domain, curve.fi, at the registrar and DNS level and pointed visitors at a wallet-draining clone of the site. Curve's smart contracts and on-chain funds were never touched; this was a Web2 attack on the domain, the soft underbelly that no Solidity audit can protect. The nameservers for curve.fi were swapped to attacker-controlled infrastructure at the registrar (iwantmyname, the same registrar implicated in Curve's 2022 hijack), and the clone prompted users to approve malicious token transactions. On-chain analysts estimated user losses around $520,000, most of it taken in the first ninety minutes. Curve repointed the domain to neutral nameservers, then permanently migrated to curve.finance and signaled a move toward decentralized (ENS) hosting.
- CRITICALWEB3-KILOEX-2025
On April 14, 2025 the perpetuals DEX KiloEx lost about $7.5 million across BNB Chain, Base, opBNB, and Taiko to what was reported as oracle price manipulation but was really an access-control failure. KiloEx's price feed (KiloPriceFeed.setPrices) was meant to be reachable only through a keeper-gated call chain, but the top-level MinimalForwarder.execute function was publicly callable and validated an attacker-supplied signature against attacker-supplied data, letting anyone forge a trusted call that reached setPrices and write an arbitrary price. The attacker set a market price far below true value, opened a leveraged position, then set the price far above value and closed it in the same flow, extracting fabricated profit from the vault; the sequence was repeated across all four chains, with a single transaction netting $3.12M. Reporting that framed it as flash-loan oracle manipulation was imprecise: no market liquidity was moved, the price was simply written directly through the unprotected forwarder. After KiloEx offered a 10% (~$750K) whitehat bounty and no legal action, the attacker returned essentially all of the funds by April 18, 2025.
- CRITICALWEB3-BYBIT-2025
On 21 February 2025, the crypto exchange Bybit lost about $1.5 billion in ether, the largest hack in history, to North Korea's Lazarus Group. Bybit had done what custody best-practice prescribes: the funds sat in a cold wallet behind a multisig requiring several human signers. The attackers beat it anyway, not by stealing keys but by tampering with what the signers saw. Weeks earlier they had compromised a developer at Safe, the multisig-wallet provider, and slipped malicious code into the Safe web app, so that when Bybit's executives reviewed a routine transfer, the screen showed a legitimate transaction while their hardware wallets were actually signing a malicious one that handed the wallet to the attacker. It is the defining lesson that a multisig is only as trustworthy as the screen you approve it on, and that blind-signing is the modern crypto catastrophe.
- CRITICALWEB3-PHEMEX-2025
On January 23, 2025, exchange Phemex lost about $85M (early estimates started near $29M before rising) after attackers drained hot wallets across roughly 11-16 blockchains in a synchronized series of more than 125 transactions consistent with a compromised set of hot-wallet private keys; Phemex said the affected signing devices were identified and isolated, pointing to compromised signing infrastructure rather than an on-chain contract flaw. The attacker prioritized high-value tokens and swapped freezable assets into non-freezable ones before any freezes could land. Cold wallets stayed secure and Phemex covered the losses, resuming operations within days under Fireblocks MPC custody with keys split across distributed nodes. Flow-of-funds tracing (Merkle Science) and on-chain analysts (ZachXBT, Arkham), later supported by the FBI, attributed the theft to North Korea's Lazarus Group: on February 22, 2025 the attackers consolidated proceeds from the subsequent Bybit hack into the existing Phemex hacker address, retroactively linking the two incidents on-chain. Stolen funds were laundered via Tornado Cash and not recovered.