{"investigation":{"slug":"orange-finance","entity_name":"Orange Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Orange Finance is an Arbitrum-based automated liquidity management protocol designed for LPDfi (liquidity provider DeFi), enabling users to earn swap fees and options premiums via concentrated AMM vaults. On January 8, 2025, the protocol suffered a critical security breach in which an attacker compromised the admin private key, exploited a misconfigured multi-signature wallet that required only a single signature to execute, and drained approximately $843,556 across all active vaults. The protocol was flagged by ZachXBT and has not resumed normal operations since the incident.","sections":[{"content":"Orange Finance describes itself as an automated liquidity management protocol for LPDfi, a category of DeFi protocols that use liquidity provider positions as collateral or yield sources within derivative markets. Built on Arbitrum and integrated with Uniswap v3 and affiliated protocols such as Stryke (formerly Dopex), Orange Finance offered vault-based strategies that combined concentrated liquidity provisioning with delta-hedging via Aave borrowing. The protocol aimed to let users deposit a single asset and receive auto-managed LP positions without manually adjusting price ranges. Prior to its January 2025 exploit, Orange Finance claimed to be Arbitrum's largest liquidity manager with a TVL exceeding $1.5 million. The team — composed of co-founders Motoki Takahashi (CEO/BizDev), Shun Oikawa (COO/PdM), and Rubio Kishigami (Biz), alongside CTO Ryota Yamaguchi and frontend developer Atsushi Uchida — applied for and received an Arbitrum LTIPP grant of 150,000 ARB in 2024. The protocol completed three security audits with WatchPug, Zokyo, and yAudit prior to the exploit.","heading":"Protocol Overview","sources":[{"url":"https://www.orangefinance.io/","name":"orangefinance.io","type":"other","credibility":3},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/IYCNZKmmxDL5V94ScyCZVXqoRzl7kIkhRxUIpMkUE1Y","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://forum.arbitrum.foundation/t/orange-finance-ltipp-application-final/21664","name":"forum.arbitrum.foundation","type":"other","credibility":3},{"url":"https://blog.stryke.xyz/articles/elevating-defi-stryke-orange-finance-unite","name":"blog.stryke.xyz","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 8, 2025, Orange Finance suffered a critical access-control exploit resulting in the theft of approximately $843,556.90 in user assets. The attacker compromised the admin private key controlling the protocol's Safe (multi-signature) wallet. Critically, the Safe wallet had been misconfigured to require only a single signature to authorize transactions, eliminating the primary security guarantee of a multi-sig arrangement. Using this administrative access, the attacker executed a series of transactions: transferred ERC20 tokens from the Safe wallet, withdrew unclaimed SYK (Stryke) token rewards, disabled legitimate vault owners, replaced vault contract implementations with malicious versions, and approved excessive token withdrawals. Asset losses were distributed across multiple DEX platforms, with approximately $340,000 drained via Uniswap, $472,000 via PancakeSwap, and $20,000 via SushiSwap. Stolen assets — primarily stablecoins and WETH — were subsequently swapped into ETH and moved off-chain via the Stargate bridge. Of the total $843,556.90 in losses, roughly $783,966 represented deposited principal, $47,447 came from exploited token approvals, and $12,142 was unclaimed rewards. The attacker address identified in on-chain analysis is 0x496e5a7ba67735c7ee5eb81ef07b65b909a31345, with an associated attack contract at 0x17c8eA17F174B5fa49D5090933ff28cE2DF10a3c.","heading":"January 2025 Exploit: Private Key Compromise and Contract Takeover","sources":[{"url":"https://rekt.news/orange-finance-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/orange-finance-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/orangefinancesmartcontractprivatekeycompromised.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.sentnl.io/resources/explained-orange-finance-falls-to-multi-sig-exploit-january-2025","name":"sentnl.io","type":"other","credibility":3},{"url":"https://ashourics.medium.com/orange-finance-exploit-a-deep-technical-analysis-of-defi-security-architecture-failures-85fcf4380e62","name":"ashourics.medium.com","type":"other","credibility":3},{"url":"https://crypto.news/arbitrums-largest-liquidity-manager-orange-finance-loses-840k-in-hacker-attack/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Post-incident analysis identified multiple overlapping security failures beyond the immediate private key compromise. First, the Safe multi-signature wallet that controlled the admin role was misconfigured to permit execution with a single signature, negating the purpose of multi-sig governance and creating a centralized point of failure. Second, the protocol operated with no real-time monitoring framework capable of detecting anomalous admin-level transactions. Third, there were no documented key management procedures, backup policies, or access control auditing frameworks in place. The protocol had completed three external audits (WatchPug, Zokyo, yAudit) focused on smart contract code, yet none identified the operational security gap in the multi-sig configuration. This discrepancy illustrates a known limitation of code-only audits: they do not assess key management practices, operational security, or deployment configuration. Security researchers and analysts noted that the attack did not exploit a bug in the contract code itself, but rather the operational failure to properly configure privileged access. Stryke Protocol, which was integrated with Orange Finance's vaults, was indirectly affected and closed its associated vaults as a precaution, though Stryke reported retaining approximately 50% of TVL in secured positions.","heading":"Security Failures: Operational and Architectural Deficiencies","sources":[{"url":"https://www.sentnl.io/resources/explained-orange-finance-falls-to-multi-sig-exploit-january-2025","name":"sentnl.io","type":"other","credibility":3},{"url":"https://ashourics.medium.com/orange-finance-exploit-a-deep-technical-analysis-of-defi-security-architecture-failures-85fcf4380e62","name":"ashourics.medium.com","type":"other","credibility":3},{"url":"https://zircon.tech/blog/security-breach-at-orange-finance-a-wake-up-call-for-web3-projects/","name":"zircon.tech","type":"other","credibility":3},{"url":"https://github.com/orange-finance/alpha-contract/blob/main/audit-report/Orange_Finance_Audit_Report_by_WatchPug.pdf","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following detection of the exploit, Orange Finance posted a warning on X (formerly Twitter) on January 8, 2025, advising all users to immediately revoke token approvals for compromised contract addresses and cease interaction with the protocol. The team acknowledged that the contract was no longer under their control. The initial team statement described uncertainty about the attack vector, stating the team was 'not sure what happened.' Orange Finance subsequently disabled all deposit and withdrawal functions via their UI and paused the Stryke vault in coordination with the Stryke team. The team engaged Seal 911, a DeFi emergency response group, to assist with the investigation. An on-chain message was sent to the attacker's address offering a white-hat arrangement: funds returned in exchange for guaranteed non-involvement of law enforcement, with a 24-hour response window and a contact email of orangefinance0108@gmail.com. No public acknowledgment of fund return was reported. The team published a Google Spreadsheet with wallet-level loss breakdowns to document affected users. A follow-up investigation report dated January 9, 2025 was published on Mirror detailing the incident timeline and loss methodology. Compensation plans were referenced but the ultimate outcome for affected users is not publicly confirmed.","heading":"Team Response and Recovery Efforts","sources":[{"url":"https://www.cryptopolitan.com/orange-finance-compromised-contract-arbitrum/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/orangefinancesmartcontractprivatekeycompromised.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/gN17YMrLhKKg9YT9a391U74pWr9IhqBUDWUqDyDamjE","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-559683-20250108","name":"mitrade.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Orange Finance has been flagged by on-chain investigator ZachXBT as a notable security incident. ZachXBT's investigations channel on Telegram, which tracks DeFi exploits and fraud cases, catalogued the Orange Finance incident as a significant access-control failure. The exploit was also documented by automated security monitoring platform CyversAlerts, which published on-chain alert data around the time of the attack. The incident was subsequently referenced as a cautionary example in the broader DeFi security community, with at least one other Arbitrum-based protocol reportedly targeted by an attempted copycat attack shortly after the Orange Finance exploit, from which white-hat hackers were able to prevent further losses. As of the available public record, no funds were returned by the attacker, no law enforcement action has been publicly announced, and the Orange Finance UI remains offline. The protocol's TVL on DeFiLlama dropped to near-zero following the incident.","heading":"ZachXBT Flagging and Community Risk Assessment","sources":[{"url":"https://t.me/s/investigations","name":"t.me","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/white-hat-hackers-arbitrum-orange-attack/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/orange-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/orange-finance-hack","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the exploit, Orange Finance had a modest but documented track record on Arbitrum. The protocol successfully applied for the Arbitrum Long Term Incentives Pilot Program (LTIPP), requesting 150,000 ARB tokens (approximately $300,000 at the time of application) to incentivize TVL growth. The grant application reported a TVL of $1.32 million, 170 depositors, 18 daily active users, and 27 daily transactions at the time of submission. The application conditioned grant distribution on achieving TVL milestones of $2.5 million and $1.25 million; if not met, funds were to be returned. The protocol had also expanded to Berachain prior to the exploit, with Orange Vaults launched in partnership with Stryke. No prior security incidents had been publicly reported before January 2025. The team's backgrounds span law, aerospace engineering, and smart contract development — the team appears to have been a legitimate but small protocol with limited operational security infrastructure relative to the value it was custodying.","heading":"Arbitrum Grant and Pre-Exploit Track Record","sources":[{"url":"https://forum.arbitrum.foundation/t/orange-finance-ltipp-application-final/21664","name":"forum.arbitrum.foundation","type":"other","credibility":3},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/_lqeem2-b20xw4kFWERYtVyXHgSvvpFNiTUvyDi5irg","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://defillama.com/protocol/orange-finance","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023","event":"Orange Finance publishes 2023 roadmap on Mirror, outlining plans for Uniswap v3 automated liquidity management vaults on Arbitrum.","source":"","date_original":"2023-01-01"},{"date":"2023-06","event":"Orange Finance Alpha Orange Vault launches on Arbitrum, targeting the USDC.e/ETH pool with delta-hedging via Aave.","source":"","date_original":"2023-06-01"},{"date":"2024-04","event":"Orange Finance submits LTIPP grant application to the Arbitrum Foundation requesting 150,000 ARB, reporting $1.32M TVL and 170 depositors.","source":"","date_original":"2024-04-01"},{"date":"2024-06","event":"Orange Finance and Stryke Protocol announce vault integration partnership, enabling liquidity management for Stryke's options AMM.","source":"","date_original":"2024-06-01"},{"date":"2024-12","event":"Orange Finance expands to Berachain, launching Orange Vaults with Stryke. Protocol TVL reaches approximately $1.5M on Arbitrum.","source":"","date_original":"2024-12-01"},{"date":"2025-01-08","event":"Attacker compromises Orange Finance admin private key, exploits single-signature multi-sig misconfiguration, upgrades all smart contracts, and drains approximately $843,556 across all active vaults on Arbitrum. Stolen assets converted to ETH and bridged via Stargate.","source":""},{"date":"2025-01-08","event":"Orange Finance posts warning on X advising users to revoke all contract approvals. Team states they are 'not sure what happened' and that contracts are no longer under their control.","source":""},{"date":"2025-01-08","event":"Orange Finance sends on-chain message to attacker's address offering white-hat arrangement with 24-hour deadline and guarantee of no law enforcement involvement.","source":""},{"date":"2025-01-08","event":"Stryke Protocol pauses associated vaults and disables deposits/withdrawals as a precautionary measure following the exploit.","source":""},{"date":"2025-01-09","event":"Orange Finance publishes follow-up incident report on Mirror detailing loss breakdown by wallet, attack steps, and notes engagement of Seal 911 for investigation.","source":""},{"date":"2025-01-09","event":"A separate Arbitrum-based protocol targeted by a copycat attack similar to Orange Finance's exploit; white-hat hackers successfully prevent fund loss.","source":""},{"date":"2025-01-09","event":"CyversAlerts and multiple on-chain security monitors publish alerts cataloguing the Orange Finance exploit. Incident flagged by ZachXBT's investigations channel.","source":""}],"sources_used":[{"url":"https://www.orangefinance.io/","name":"orangefinance.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/IYCNZKmmxDL5V94ScyCZVXqoRzl7kIkhRxUIpMkUE1Y","name":"mirror.xyz","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://forum.arbitrum.foundation/t/orange-finance-ltipp-application-final/21664","name":"forum.arbitrum.foundation","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.stryke.xyz/articles/elevating-defi-stryke-orange-finance-unite","name":"blog.stryke.xyz","type":"other","archive_url":"http://web.archive.org/web/20260607112326/https://blog.stryke.xyz/articles/elevating-defi-stryke-orange-finance-unite","credibility":3,"archive_timestamp":"2026-06-07T11:23:26+00:00"},{"url":"https://rekt.news/orange-finance-rekt/","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260415153701/https://rekt.news/orange-finance-rekt","credibility":3,"archive_timestamp":"2026-04-15T15:37:01+00:00"},{"url":"https://www.web3isgoinggreat.com/single/orange-finance-hack","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260829232315/https://www.web3isgoinggreat.com/single/orange-finance-hack","credibility":3,"archive_timestamp":"2026-08-29T23:23:15+00:00"},{"url":"https://quadrigainitiative.com/casestudy/orangefinancesmartcontractprivatekeycompromised.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260306120547/https://quadrigainitiative.com/casestudy/orangefinancesmartcontractprivatekeycompromised.php","credibility":3,"archive_timestamp":"2026-03-06T12:05:47+00:00"},{"url":"https://www.sentnl.io/resources/explained-orange-finance-falls-to-multi-sig-exploit-january-2025","name":"sentnl.io","type":"other","archive_url":"http://web.archive.org/web/20260422151733/https://www.sentnl.io/resources/explained-orange-finance-falls-to-multi-sig-exploit-january-2025","credibility":3,"archive_timestamp":"2026-04-22T15:17:33+00:00"},{"url":"https://ashourics.medium.com/orange-finance-exploit-a-deep-technical-analysis-of-defi-security-architecture-failures-85fcf4380e62","name":"ashourics.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251126142858/https://ashourics.medium.com/orange-finance-exploit-a-deep-technical-analysis-of-defi-security-architecture-failures-85fcf4380e62","credibility":3,"archive_timestamp":"2025-11-26T14:28:58+00:00"},{"url":"https://crypto.news/arbitrums-largest-liquidity-manager-orange-finance-loses-840k-in-hacker-attack/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260207200834/https://crypto.news/arbitrums-largest-liquidity-manager-orange-finance-loses-840k-in-hacker-attack/","credibility":3,"archive_timestamp":"2026-02-07T20:08:34+00:00"},{"url":"https://zircon.tech/blog/security-breach-at-orange-finance-a-wake-up-call-for-web3-projects/","name":"zircon.tech","type":"other","archive_url":"http://web.archive.org/web/20260412171217/https://zircon.tech/blog/security-breach-at-orange-finance-a-wake-up-call-for-web3-projects/","credibility":3,"archive_timestamp":"2026-04-12T17:12:17+00:00"},{"url":"https://github.com/orange-finance/alpha-contract/blob/main/audit-report/Orange_Finance_Audit_Report_by_WatchPug.pdf","name":"github.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptopolitan.com/orange-finance-compromised-contract-arbitrum/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20250910091341/https://www.cryptopolitan.com/orange-finance-compromised-contract-arbitrum/","credibility":3,"archive_timestamp":"2025-09-10T09:13:41+00:00"},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/gN17YMrLhKKg9YT9a391U74pWr9IhqBUDWUqDyDamjE","name":"mirror.xyz","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-559683-20250108","name":"mitrade.com","type":"other","archive_url":"https://web.archive.org/web/20260829051121/https://www.mitrade.com/insights/news/live-news/article-3-559683-20250108","credibility":3,"archive_timestamp":"2026-08-29T05:11:21+00:00"},{"url":"https://t.me/s/investigations","name":"t.me","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptopolitan.com/white-hat-hackers-arbitrum-orange-attack/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20250909191646/https://www.cryptopolitan.com/white-hat-hackers-arbitrum-orange-attack/","credibility":3,"archive_timestamp":"2025-09-09T19:16:46+00:00"},{"url":"https://defillama.com/protocol/orange-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250914185746/https://defillama.com/protocol/orange-finance","credibility":3,"archive_timestamp":"2025-09-14T18:57:46+00:00"},{"url":"https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/_lqeem2-b20xw4kFWERYtVyXHgSvvpFNiTUvyDi5irg","name":"mirror.xyz","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:26.261692+00:00","updated_at":"2026-08-29T23:26:13.170959+00:00"}}