{"investigation":{"slug":"orbit-bridge","entity_name":"Orbit Bridge","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Orbit Bridge is a cross-chain interoperability protocol developed by South Korean blockchain firm Ozys that suffered one of the largest bridge exploits in crypto history on December 31, 2023, losing approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI. The attacker allegedly compromised seven of ten multisig signatories after a former chief information security officer allegedly weakened the company firewall before departing, and blockchain analysts have linked the attack's patterns to North Korea's Lazarus Group, though no formal attribution has been confirmed by authorities. As of 2025, the majority of stolen funds remain unrecovered, with the attacker having laundered over 17,000 ETH through Tornado Cash.","sections":[{"content":"Orbit Bridge is the cross-chain interoperability protocol of Orbit Chain, a project developed by Ozys, a South Korean blockchain technology company operating under the motto 'Connecting the Unconnected.' The protocol enables users to transfer assets across multiple blockchain networks and has supported the cross-chain bridging of more than $3.5 billion in assets over its operational lifetime. Prior to the December 2023 exploit, Orbit Bridge was integrated with major South Korean blockchain ecosystems including Kakao's Klaytn platform and WEMIX, a gaming-focused blockchain by Wemade. The protocol used a ten-of-ten multisig wallet structure to govern its Ethereum vault, a security design intended to prevent unilateral asset movement. At the time of the exploit, Orbit Bridge's total value locked (TVL) stood at approximately $152 million, meaning the hack drained over half of all funds held in the protocol.","heading":"Background","sources":[{"url":"https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","name":"","type":"other","credibility":3},{"url":"https://blockworks.co/news/80-million-lost-orbit-bridge","name":"","type":"other","credibility":3},{"url":"https://www.newsbtc.com/news/company/ton-foundation-bolsters-drive-to-a-cross-chain-future-together-with-ozys-orbit-bridge/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 31, 2023, beginning at approximately 21:08 UTC, an unidentified attacker executed a series of five unauthorized withdrawals from Orbit Bridge's Ethereum vault. The transactions drained 9,500 ETH (approximately $21.5 million), 231 WBTC (approximately $9.8 million), 30 million USDT, 10 million USDC, and 10 million DAI, with a final USDT transaction completing at approximately 21:25 UTC. The bridge contract was deactivated by 22:21 UTC. Stolen funds were distributed across eight freshly created wallets. The attacker subsequently swapped the stablecoins and WBTC holdings into ETH before consolidating assets. Orbit Chain confirmed the exploit publicly on January 1, 2024, and notified South Korea's National Intelligence Service by approximately 10:35 a.m. local time. The exploit represented approximately 35 percent of Orbit Bridge's total value locked and was the ninth-largest cross-chain bridge hack recorded at the time. Orbit Chain attempted to communicate with the attacker via on-chain messages and requested major global cryptocurrency exchanges to freeze the stolen assets. The company engaged blockchain security firm ChainLight to lead forensic analysis.","heading":"The New Year's Eve Hack","sources":[{"url":"https://news.bitcoin.com/orbit-bridge-hack-confirmed-over-81-5-million-lost-in-cryptocurrency-assets/","name":"","type":"other","credibility":3},{"url":"https://rekt.news/orbit-bridge-rekt","name":"","type":"other","credibility":3},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-orbit-chains-81m-new-years-eve-hack-a-24028","name":"","type":"other","credibility":3},{"url":"https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain analysis identified the primary attacker address as 0x9263e7873613ddc598a701709875634819176aff. This address received initial funding via Tornado Cash through an intermediary address (0x70462bfb204bf3ccb0560f259072f8e3a85b3512), indicating the attacker took deliberate steps to obscure the source of funds used to bootstrap the attack wallet prior to execution. The exploit required control of at least seven of the ten multisig signatories governing the Ethereum vault, a threshold sufficient to authorize withdrawals under the protocol's governance rules. Early analyst assessments, including from on-chain researcher Officer CIA, indicated a high likelihood that exactly seven of the ten signers were compromised. Following the exploit, the stolen stablecoins and WBTC were largely swapped into ETH. The attacker's wallets remained dormant for approximately five months. On June 8, 2024, the attacker moved approximately 12,932 ETH across seven transactions to a new address, then routed approximately $48 million through Tornado Cash. In early 2025, the attacker again transferred an additional 4,320 ETH (approximately $18.81 million at the time) through Tornado Cash, bringing total laundered ETH to 17,242 ETH (approximately $66.35 million). As of mid-2025, the attacker's address was reported to still hold approximately 9,511 ETH and 20 million DAI.","heading":"On-Chain Evidence","sources":[{"url":"https://rekt.news/orbit-bridge-rekt","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/299192/orbit-chain-exploiter-moves-48-million-through-tornado-cash-after-months-of-post-hack-dormancy","name":"","type":"other","credibility":3},{"url":"https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash","name":"","type":"other","credibility":3},{"url":"https://dailycoin.com/orbit-chain-hacker-online-48m-tornado-cash/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple blockchain security researchers and analysts have alleged a connection between the Orbit Bridge exploit and North Korea's Lazarus Group, though no formal attribution has been publicly confirmed by South Korean or international law enforcement agencies as of mid-2025. Blockchain analytics firm Match Systems published a report on January 3, 2024, asserting that the attacker's use of tools including SWFT, Avalanche Bridge, and the Sinbad mixer aligned with patterns previously associated with Lazarus Group. Match Systems noted the attacker's account received funding from sources that had withdrawn from Tornado Cash, consistent with Lazarus operational methodology. The firm also alleged the same criminal group may have been responsible for the 2023 hacks of Atomic Wallet, CoinsPaid, and CoinEx. MetaMask security developer Taylor Monahan separately stated the Orbit attack followed similar patterns to known North Korean hacking campaigns. South Korea's National Intelligence Service, National Police Agency Cyber Terror Investigation Unit, and Korea Internet and Security Agency (KISA) were all engaged in the investigation. Ozys confirmed it had notified the NIS of the Lazarus hypothesis. The NIS stated publicly: 'We are currently investigating the cause and the perpetrator of the incident. While no direct link to North Korea has been confirmed so far, we are collaborating with relevant agencies and considering the possibility.' The FBI had previously attributed the 2023 Atomic Wallet and CoinsPaid hacks to Lazarus, lending additional indirect weight to the hypothesis for Orbit Bridge. Attribution remains alleged and unconfirmed.","heading":"Lazarus Group Attribution","sources":[{"url":"https://cryptonews.com/news/south-korean-agencies-investigate-82m-orbit-bridge-hack/","name":"","type":"other","credibility":3},{"url":"https://icoholder.com/en/news/lazarus-group-suspected-in-orbit-chain-hack-blockchain-analysts-uncover-common-tactics-in-high-profile-attacks","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/orbit-bridge-hacker-suspected-in-coinspaid-and-coinex-breaches/","name":"","type":"other","credibility":3},{"url":"https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 25, 2024, Ozys published a statement alleging that its former chief information security officer had deliberately weakened the company's internal firewall before departing the company. According to Ozys, the former CISO made unauthorized changes to firewall policies on November 22, 2023, two days after submitting a voluntary resignation request. The employee formally left the company on December 6, 2023, without disclosing the changes. Ozys stated it discovered the firewall modifications in January 2024 during post-incident investigation. The company alleges the weakened firewall may have provided an access pathway that contributed to the hack. Ozys did not publicly disclose the name of the former employee. The company filed a civil lawsuit for damages against the former CISO and submitted a petition to South Korean police requesting a criminal investigation into the employee's possible involvement. Ozys also stated it was separately investigating whether the former CISO may have been connected to or acting in coordination with the alleged Lazarus Group attackers. These allegations remain unproven in a court of law as of the date of this investigation.","heading":"Former CISO Allegations and Internal Security Failure","sources":[{"url":"https://www.theblock.co/post/274411/orbit-bridge-firewall-sabotage-exploit","name":"","type":"other","credibility":3},{"url":"https://dailycoin.com/ozys-blames-former-ciso-for-81-5m-orbit-bridge-exploit/","name":"","type":"other","credibility":3},{"url":"https://crypto.news/ex-orbit-bridge-employee-accused-of-facilitating-80m-attack/","name":"","type":"other","credibility":3},{"url":"https://bsc.news/post/orbit-bridge-accuses-former-team-member-for-82m-hack","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Ozys published a draft Asset Recovery and Ecosystem Normalization Plan. The plan categorized the $82 million recovery target into three tiers: approximately $40 million designated as immediate recovery assets to be funded from Ozys' own capital holdings, partner grants, and business unit sales; approximately $21 million as priority recovery assets funded through profits from existing and new services; and approximately $21 million as long-term support assets funded through voluntary partner lock-ups and contributions. Ozys stated its goal was full restoration of the Orbit ecosystem within two years. The company separately announced a governance proposal for a renewal of the ORC token, including plans to migrate token governance to the Ethereum ecosystem and open a new staking and governance system in January 2025. Orbit Chain stated it resumed partial bridging services after the exploit while investigations continued. As of the publicly available reporting through mid-2025, no material recovery of the stolen $81.5 million has been reported. The attacker has not been arrested or publicly identified. Approximately 17,242 ETH of stolen funds has been laundered through Tornado Cash, with an estimated 9,511 ETH and 20 million DAI still held in attacker-controlled wallets as of early 2025. Negotiations between Orbit Chain and the attacker were reportedly attempted and failed.","heading":"Recovery Efforts","sources":[{"url":"https://medium.com/orbit-chain/orbit-bridge-exploit-asset-recovery-and-ecosystem-normalization-plan-draft-3aa7ac2a6e4a","name":"","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/governance-proposal-for-the-renewal-of-orbit-chain-orc-tokens-a278eb3af1ce","name":"","type":"other","credibility":3},{"url":"https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash","name":"","type":"other","credibility":3},{"url":"https://livedarknet.com/p/negotiations-fail-after-82m-orbit-bridge-hack/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Orbit Bridge presents an extreme risk profile for users and counterparties. The protocol suffered the loss of over half its TVL in a single exploit event, with no confirmed recovery of stolen funds as of mid-2025. The attack vector involved compromise of the multisig governance structure, which is the foundational security primitive of the protocol. The alleged involvement of a state-sponsored threat actor (Lazarus Group) and an alleged internal security sabotage by a former senior security officer compound the severity of the incident. The attacker funded the exploit wallet through Tornado Cash and subsequently laundered the majority of proceeds through the same mixer, indicating sophisticated operational security and deliberate obfuscation of asset trails. The stolen assets have appreciated in value since the hack due to ETH price appreciation, and the attacker still controls tens of millions of dollars in unretrieved funds. Orbit Bridge's bridge contract was deactivated following the hack. The ORC token experienced significant price decline following the exploit. No independent security audit finding has been publicly cited as having identified or prevented the multisig key compromise vector. Users who held assets in the Orbit Bridge Ethereum vault at the time of the exploit suffered direct losses with no confirmed compensation mechanism delivered as of the date of this report.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","name":"","type":"other","credibility":3},{"url":"https://www.infosecurity-magazine.com/news/crypto-stolen-cyber-attack-orbit/","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/orbit-bridge-hack-pushes-december-crypto-losses-100m","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-11-20","event":"Orbit Bridge's CISO submits voluntary resignation request to Ozys.","source":""},{"date":"2023-11-22","event":"Alleged: Former CISO makes unauthorized changes to Ozys internal firewall policies, weakening security posture (alleged by Ozys; unproven in court).","source":""},{"date":"2023-12-06","event":"Former CISO formally departs Ozys without disclosing firewall changes.","source":""},{"date":"2023-12-31","event":"Exploit begins at 21:08 UTC. Five unauthorized withdrawals drain 9,500 ETH, 231 WBTC, 30M USDT, 10M USDC, and 10M DAI from Orbit Bridge's Ethereum vault across approximately 17 minutes.","source":""},{"date":"2023-12-31","event":"Bridge contract deactivated at approximately 22:21 UTC to prevent further losses.","source":""},{"date":"2024","event":"Orbit Chain publicly confirms the exploit. National Intelligence Service notified by 10:35 a.m. KST.","source":"","date_original":"2024-01-01"},{"date":"2024-01-02","event":"ChainLight engaged for forensic analysis. Orbit Chain attempts on-chain communication with attacker. Requests to exchanges to freeze stolen assets submitted.","source":""},{"date":"2024-01-03","event":"Match Systems publishes report alleging the Orbit attacker used tools and patterns consistent with Lazarus Group, and may have also conducted the Atomic Wallet, CoinsPaid, and CoinEx hacks.","source":""},{"date":"2024-01-10","event":"South Korea's NIS, National Police Agency, and KISA confirm joint investigation is underway. NIS states no direct North Korea link confirmed but possibility is being examined. Negotiations with attacker reported to have failed.","source":""},{"date":"2024-01-25","event":"Ozys publicly alleges former CISO deliberately weakened company firewall prior to the hack. Civil lawsuit and police petition filed against the unnamed former employee.","source":""},{"date":"2024-02-14","event":"Ozys publishes draft Asset Recovery and Ecosystem Normalization Plan, targeting $82M recovery over two years through company capital, partner grants, and new business revenue.","source":""},{"date":"2024-06-08","event":"After approximately five months of dormancy, attacker moves 12,932 ETH across seven transactions, routing approximately $48 million through Tornado Cash.","source":""},{"date":"2025","event":"Attacker transfers an additional 4,320 ETH (approximately $18.81 million) through Tornado Cash. Total laundered through Tornado Cash reaches 17,242 ETH (approximately $66.35 million). Attacker reported to still hold approximately 9,511 ETH and 20M DAI.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260214073042/https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","credibility":3,"archive_timestamp":"2026-02-14T07:30:42+00:00"},{"url":"https://blockworks.co/news/80-million-lost-orbit-bridge","name":"","type":"other","archive_url":"http://web.archive.org/web/20260227024748/https://blockworks.co/news/80-million-lost-orbit-bridge","credibility":3,"archive_timestamp":"2026-02-27T02:47:48+00:00"},{"url":"https://www.newsbtc.com/news/company/ton-foundation-bolsters-drive-to-a-cross-chain-future-together-with-ozys-orbit-bridge/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830010055/https://www.newsbtc.com/news/company/ton-foundation-bolsters-drive-to-a-cross-chain-future-together-with-ozys-orbit-bridge/","credibility":3,"archive_timestamp":"2026-08-30T01:00:55+00:00"},{"url":"https://news.bitcoin.com/orbit-bridge-hack-confirmed-over-81-5-million-lost-in-cryptocurrency-assets/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260216114755/https://news.bitcoin.com/orbit-bridge-hack-confirmed-over-81-5-million-lost-in-cryptocurrency-assets/","credibility":3,"archive_timestamp":"2026-02-16T11:47:55+00:00"},{"url":"https://rekt.news/orbit-bridge-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513153300/https://rekt.news/orbit-bridge-rekt","credibility":3,"archive_timestamp":"2026-05-13T15:33:00+00:00"},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-orbit-chains-81m-new-years-eve-hack-a-24028","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830044450/https://www.bankinfosecurity.com/cryptohack-roundup-orbit-chains-81m-new-years-eve-hack-a-24028","credibility":3,"archive_timestamp":"2026-08-30T04:44:50+00:00"},{"url":"https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","name":"","type":"other","archive_url":"http://web.archive.org/web/20260518221547/https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","credibility":3,"archive_timestamp":"2026-05-18T22:15:47+00:00"},{"url":"https://www.theblock.co/post/299192/orbit-chain-exploiter-moves-48-million-through-tornado-cash-after-months-of-post-hack-dormancy","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829182057/https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash","credibility":3,"archive_timestamp":"2026-08-29T18:20:57+00:00"},{"url":"https://dailycoin.com/orbit-chain-hacker-online-48m-tornado-cash/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260829132538/https://dailycoin.com/orbit-chain-hacker-online-48m-tornado-cash/","credibility":3,"archive_timestamp":"2026-08-29T13:25:38+00:00"},{"url":"https://cryptonews.com/news/south-korean-agencies-investigate-82m-orbit-bridge-hack/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://icoholder.com/en/news/lazarus-group-suspected-in-orbit-chain-hack-blockchain-analysts-uncover-common-tactics-in-high-profile-attacks","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.com/news/orbit-bridge-hacker-suspected-in-coinspaid-and-coinex-breaches/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.theblock.co/post/274411/orbit-bridge-firewall-sabotage-exploit","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://dailycoin.com/ozys-blames-former-ciso-for-81-5m-orbit-bridge-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260124003103/https://dailycoin.com/ozys-blames-former-ciso-for-81-5m-orbit-bridge-exploit/","credibility":3,"archive_timestamp":"2026-01-24T00:31:03+00:00"},{"url":"https://crypto.news/ex-orbit-bridge-employee-accused-of-facilitating-80m-attack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251014204743/https://crypto.news/ex-orbit-bridge-employee-accused-of-facilitating-80m-attack/","credibility":3,"archive_timestamp":"2025-10-14T20:47:43+00:00"},{"url":"https://bsc.news/post/orbit-bridge-accuses-former-team-member-for-82m-hack","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/orbit-chain/orbit-bridge-exploit-asset-recovery-and-ecosystem-normalization-plan-draft-3aa7ac2a6e4a","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/orbit-chain/governance-proposal-for-the-renewal-of-orbit-chain-orc-tokens-a278eb3af1ce","name":"","type":"other","archive_url":"http://web.archive.org/web/20260713041950/https://medium.com/orbit-chain/governance-proposal-for-the-renewal-of-orbit-chain-orc-tokens-a278eb3af1ce","credibility":3,"archive_timestamp":"2026-07-13T04:19:50+00:00"},{"url":"https://livedarknet.com/p/negotiations-fail-after-82m-orbit-bridge-hack/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414123954/https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","credibility":3,"archive_timestamp":"2026-04-14T12:39:54+00:00"},{"url":"https://www.infosecurity-magazine.com/news/crypto-stolen-cyber-attack-orbit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251110142709/https://www.infosecurity-magazine.com/news/crypto-stolen-cyber-attack-orbit/","credibility":3,"archive_timestamp":"2025-11-10T14:27:09+00:00"},{"url":"https://cointelegraph.com/news/orbit-bridge-hack-pushes-december-crypto-losses-100m","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829182714/https://cointelegraph.com/news/orbit-bridge-hack-pushes-december-crypto-losses-100m","credibility":3,"archive_timestamp":"2026-08-29T18:27:14+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:36.174442+00:00","updated_at":"2026-08-30T05:14:08.782463+00:00"}}