Orbit Chain bridge hack
About $81.5M was drained from the Orbit Bridge (by South Korea's Ozys) on Dec 31, 2023 – Jan 1, 2024, via weak withdrawal/signature validation. Ozys later said a former security chief had weakened its firewall weeks earlier and pursued legal action.
Also known as: Orbit Chain, Orbit Bridge, Ozys
Summary
Orbit Chain operates the Orbit Bridge, a cross-chain bridge built by the South Korean firm Ozys. Beginning late on December 31, 2023 (UTC), an attacker drained about $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the bridge's Ethereum vault in a series of transactions, exploiting weaknesses in its withdrawal and signature-validation logic. [1][2]
Aftermath
The stolen funds were swapped to ETH/DAI and dispersed across wallets. In January 2024, Ozys said that while reviewing firewall policy it discovered its former Chief Information Security Officer had "arbitrarily" weakened the firewall in November 2023, shortly before leaving the company, and that it was pursuing civil and criminal action. Ozys's earlier projects (e.g., KlaySwap, Belt Finance) had also been hacked. [1][3]
Bracketed numbers refer to the numbered sources listed below.
Sources (3)
- Official Statement Regarding 'Orbit Bridge Exploit' — Orbit Chain (Ozys)
- $80M lost in first hack of 2024 (Orbit Bridge) — Blockworks
- Orbit Chain loses $86 million in the last hack of 2023 — BleepingComputer
See also
World Liberty Financial (WLFI) — Justin Sun token freezeProjectsWLFI, a DeFi project linked to Donald Trump and his family, blacklisted/froze the wallet of major investor Justin Sun in Sept 2025 — ~540–595M unlocked WLFI tokens (~$107M) plus ~2.4B locked. Sun sued, alleging an undisclosed admin 'blacklist backdoor'; WLFI denied it and threatened a countersuit. The dispute is ongoing.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
