$616 000 USD

MAY 2024

GLOBAL

ORION NETWORK

DESCRIPTION OF EVENTS

"EARN MORE WITH ORION. SAVE TIME WITH ORION. STAY SECURE WITH ORION." "Best prices. Your wallet. Global access."

 

"Orion is on a transformative mission to redefine DeFi trading, seamlessly connecting the vast liquidity of both centralized and decentralized exchanges directly from your wallet. We aim to be the people's platform, ensuring democratized access to the best crypto prices while redistributing wealth back to our users worldwide.

 

Our vision aims to dominate the web3 space and continuously innovate the DeFi trading experience. We strive to be the world’s go-to crypto trading platforms, synonymous with innovation, community strength, and unparalleled market access."

 

"ORN is not just a digital asset; it's a passport to Orion's evolving ecosystem. As Orion embarks on its transformative journey, ORN holders are positioned to be at the forefront, ensuring they remain integral to Orion's future endeavors. Whether you're a referrer, a trader, or a liquidity node, the benefits of holding ORN are set to amplify over time."

 

"Root cause is that victim contract didn't manage liability correctly. "setLiability" must be called once per tokens. But there's another function that changes assetBalances, "requestReleaseStake". Using this function, hacker could" "call "setLiability" twice with ORN token. After that, he could withdraw much more tokens using this vulnerability."

 

$616 (SlowMist/ChainAegis) or $645 (Phalcon).

 

"According to the SlowMist security team, the liquidity aggregator protocol Orion's contract was attacked, resulting in a loss of approximately $616,000."

 

"We detected potential suspicious activity related to @TradeOnOrion"

 

"Dear developer, this is a white hat rescue hack. I wish no harm on your project and I appreciate what you're doing in defi world. Provide address to which I should transfer the assets back. Given the scale of the exploit, could we please consider a 10% bounty."

 

"Dear white hacker, thank you very much for the finding. Please return the funds back to the address. We agree to the bounty amount. Coule you please contact us by @truenico or email for further cooperation? Thank you!"

 

Explore This Case Further On Our Wiki

Orion Network is a protocol designed to help connect decentralized finance to centralized exchange liquidity. Orion Network suffered from a vulnerability where the setLiability function could be called multiple times. The exploit was described as complicated by analysis firms. The hacker reported that they were a whitehat hacker. They requested a 10% bounty in exchange for returning the rest of the funds.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2019 - 2025 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.