Orbit Chain cross-chain bridges attacked, resulting in losses of approximately 80 million USD.

Orbit Chain project suffers an attack, resulting in a loss of approximately 80 million USD

At the beginning of the New Year 2024, the cross-chain bridge platform Orbit Chain encountered a major security incident, with losses amounting to approximately $80 million. According to the security monitoring platform, the attackers had already begun small-scale probing a day earlier and used the stolen ETH to fund subsequent large-scale attacks.

Currently, the project party has suspended the operation of the cross-chain bridge contract and is attempting to communicate with the attacker. Security experts have conducted an in-depth analysis of the incident, revealing the specific methods of the attack and the flow of funds.

How did the $80 million theft of Orbit Chain happen, the first major case of the year?

Attack Method Analysis

Attackers primarily transfer assets by directly calling the withdraw function of the Orbit Chain bridging contract. This function employs a signature verification mechanism to ensure the legality of withdrawals. Further analysis reveals that the contract requires at least 70% of the administrators (i.e., 7 out of 10 administrators) to sign the withdrawal transaction in order to execute it.

Experts speculate that this incident is likely due to the server storing the administrator's private key being subjected to a phishing attack. This highlights the importance of properly safeguarding private keys within a multi-signature mechanism.

How did the Orbit Chain theft of 80 million USD happen, the first major case of the year?

Attack Timeline

  • December 30, 2023: The attacker began small-scale probing attacks, stealing a small amount of ETH and distributing it to other attack addresses as transaction fees.
  • On the evening of December 31, 2023: Multiple attack addresses simultaneously launched large-scale attacks on assets such as DAI, WBTC, ETH, USDC, and USDT.

How did the $80 million theft of Orbit Chain happen, the first major case of the year?

Flow of Stolen Funds

The attacker will disperse the stolen funds to 5 different addresses:

  • 30 million USDT
  • 10 million DAI
  • 10 million USDC
  • 231 wBTC (approximately 10 million USD)
  • 9500 ETH (approximately 21.5 million USD)

How did the $80 million theft of Orbit Chain happen, the first major case of the year?

Security Insights

This event reminds us once again that security should always be the top priority when designing and implementing blockchain systems. Specific recommendations include:

  1. Enhance the security of contract code by following best practices and security standards.
  2. Improve the identity verification and permissions management mechanisms
  3. Adopt advanced security measures such as multi-signature.
  4. Conduct regular security audits and vulnerability assessments.
  5. Establish an emergency response plan to improve incident handling capability.

In today's rapidly developing decentralized finance landscape, both project teams and users should remain vigilant at all times, prioritizing security to jointly maintain the healthy development of the blockchain ecosystem.

Orbit Chain was hacked for $80 million, how did the first major case of the year occur?

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 8
  • Share
Comment
0/400
Lionish_Lionvip
· 11h ago
FOLLOW ME for institutional-grade trading insights. No fairy tales - just logic-based market analysis. 🧠📊
Reply0
ser_ngmivip
· 11h ago
The beginning of 2024 is full of disasters.
View OriginalReply0
ChainPoetvip
· 11h ago
Another bridge has been killed, the first critical hit of the New Year
View OriginalReply0
MetaverseLandladyvip
· 11h ago
Cross-chain bridges? Only the authentic Wallet is the safest!
View OriginalReply0
DEXRobinHoodvip
· 11h ago
What standard backer is the big show for the new year?
View OriginalReply0
LoneValidatorvip
· 11h ago
My comment is: Another weak bridge has an incident.
View OriginalReply0
DoomCanistervip
· 11h ago
New Year's first leek, are we playing people for suckers already?
View OriginalReply0
MEVEyevip
· 11h ago
Another big fat sheep can't escape.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)