Cryptocurrency [loss] $3M+

Tweet by PeckShield

2023-02-02 [vendor] Orion Protocol [chain] ethereum
Primary Source ↗
Financial Loss $2.9M (2,900,000 USD)
Blockchain(s) Ethereum

Incident Details

The decentralized exchange Orion Protocol suffered a loss of 1,757 ETH (about $2.9 million) from the company treasury funds thanks to a reentrancy attack.Orion Protocol CEO Alexey Koloskov wrote a Twitter thread confirming the attack, but claiming that although they weren’t sure how the hack was perpetrated, it wasn’t due to the fault of their own code. Koloskov wrote that he thought the issue “might have been caused by a vulnerability in mixing third-party libraries in one of the smart contracts used by our experimental and private brokers.”

Total loss estimated at $2,900,000.

Technical Details

Initial Attack Vector
Reentrancy attack on smart contract
Vendor / Product
Orion Protocol

Timeline

  1. 2023-02-02 Breach occurred
  2. 2023-02-02 Publicly disclosed