{"investigation":{"slug":"orbit-chain-bridge","entity_name":"Orbit Chain Bridge","trust_score":8,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Orbit Bridge is the cross-chain bridging protocol of Orbit Chain, developed by South Korean blockchain company Ozys. On December 31, 2023, attackers compromised seven of ten multisig private keys and drained approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Ethereum vault in the largest crypto hack of New Year's Eve 2023. The attack has been attributed with medium-to-high confidence to North Korea's Lazarus Group, with an additional alleged insider-threat dimension involving Ozys' former chief information security officer, who allegedly sabotaged the company firewall weeks before the exploit.","sections":[{"content":"On December 31, 2023 at approximately 20:52 UTC (January 1, 2024 at 05:52 KST), an unidentified attacker began draining the Orbit Bridge Ethereum vault in six sequential transactions, completing the operation by 06:25 KST. Total losses are estimated at approximately $81.5 million to $82 million, making it the largest crypto bridge exploit on record for that period. The stolen assets consisted of: 9,500 ETH (approximately $21.7 million), 231 WBTC (approximately $9.8 million), 30 million USDT, 10 million USDC, and 10 million DAI. The attacker pre-funded an intermediary wallet using 10 ETH sourced from Tornado Cash — a sanctioned cryptocurrency mixing service — prior to executing the heist. Stolen assets were subsequently distributed to eight separate wallets and converted in part to ETH and DAI.","heading":"Exploit Overview","sources":[{"url":"https://cointelegraph.com/news/cross-chain-protocol-orbit-bridge-suffers-exploit-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/orbit-chain-exploited-816-million-drained-cross-chain-bridge/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Orbit Bridge employed a 10-of-10 multisig security model for its Ethereum vault, requiring multiple private key holders to authorize transactions — a configuration generally considered best practice for cross-chain bridge custody. The attacker obtained unauthorized access to seven of ten multisig signers, which was sufficient to authorize outgoing transactions and drain the vault. Ozys confirmed the exploit did not result from a vulnerability in the Orbit Bridge smart contract itself, nor from the theft of a validator key. Security researchers noted that the multisig's real-world protection was undermined by the possibility that private keys were stored on the same systems, protected by identical credentials, or accessible to a single insider, effectively negating the separation-of-duties guarantee that multisig is intended to provide.","heading":"Attack Method: Multisig Compromise","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/new-year-new-attack-orbit-bridge-drained-for-82m/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 10, 2024, Ozys discovered that its former chief information security officer had allegedly made unauthorized changes to the company's internal firewall policies on November 22, 2023 — two days after that individual submitted a voluntary resignation request. The former CISO departed the company on December 6, 2023, without disclosing the changes or providing proper handover documentation. Ozys alleges these changes created the access conditions exploited in the attack approximately six weeks later. The company filed a civil lawsuit for damages and submitted a criminal petition to South Korean police requesting an investigation into the former employee's alleged involvement. Ozys did not publicly disclose the name of the former CISO. These allegations remain unproven in court as of the available record.","heading":"Alleged Insider Threat: Former CISO","sources":[{"url":"https://www.theblock.co/post/274411/orbit-bridge-firewall-sabotage-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://dailycoin.com/ozys-blames-former-ciso-for-81-5m-orbit-bridge-exploit/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/01/25/ozys-alleges-former-cisos-role-in-firewall-breach/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"MetaMask security researcher Taylor Monahan publicly noted that the Orbit Bridge attack methodology closely resembled patterns previously associated with North Korea's Lazarus Group, including the methodical compromise of multiple private keys and the use of Tornado Cash for pre-funding. Following these reports, Ozys notified South Korea's National Intelligence Service (NIS), which launched a full investigation alongside the Korean National Police Agency (KNPA) and KISA (Korea Internet and Security Agency). Attribution to Lazarus Group has not been formally confirmed by a government authority such as the FBI or U.S. Treasury as of the available record, distinguishing this case from confirmed Lazarus incidents such as the Harmony Horizon Bridge hack. The pattern-based attribution is considered medium-to-high confidence by the investigative community but remains officially unverified for Orbit Bridge specifically.","heading":"Lazarus Group Attribution","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/south-korean-agencies-investigate-82m-orbit-bridge-hack/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","name":"therecord.media","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/cross-chain-protocol-orbit-bridge-suffers-exploit-hack","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, stolen funds remained largely dormant for approximately five months. On June 8, 2024, the exploiter moved 12,932 ETH — valued at approximately $47.7 million — through seven transactions into Tornado Cash, the sanctioned Ethereum privacy mixer. Subsequent on-chain data indicated the hacker's remaining balance stood at approximately $71.2 million including ETH, wrapped Bitcoin, and stablecoins, as not all stolen assets (notably $20 million in DAI) were moved in the June 2024 batch. Further movements of ETH through Tornado Cash have been documented as recently as mid-2025. No stolen funds had been publicly confirmed as recovered as of the available record.","heading":"Post-Exploit Fund Movement and Laundering","sources":[{"url":"https://cointelegraph.com/news/orbit-chain-hacker-moves-nearly-48-million-via-tornado-cash","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/06/10/orbit-chain-hacker-moves-47-7-million-to-tornado-cash/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://dailycoin.com/orbit-chain-hacker-online-48m-tornado-cash/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash-total-17-242-eth-moved-after-81-5m-exploit","name":"blockchain.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Ozys immediately coordinated a response with Seoul Metropolitan Police (notified at 10:00 a.m. KST January 1, 2024), KISA (notified at 10:35 a.m.), and security firm Theori. The Ethereum vault was shut down at 07:21 a.m. KST. In January 2024, Orbit Chain offered an $8 million USD public bounty for intelligence leading to the identification of the attacker or recovery of stolen assets. The company published an asset recovery and ecosystem normalization plan for affected users. No confirmed recovery has been publicly announced. The protocol's native ORC token declined approximately 20% in the immediate aftermath of the exploit.","heading":"Company Response and Bounty","sources":[{"url":"https://socket.dev/blog/orbit-chain-offers-8M-bounty","name":"socket.dev","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/orbit-bridge-exploit-asset-recovery-and-ecosystem-normalization-plan-draft-3aa7ac2a6e4a","name":"medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Orbit Chain is a proof-of-stake cross-chain protocol developed by Ozys, a South Korean blockchain technology company founded in 2017. Orbit Chain launched in 2018 with the stated goal of enabling seamless multi-chain asset transfers across networks including Bitcoin, Ethereum, Ripple, Tron, Klaytn, ICON, and others. The CEO of Ozys is TK Taekyu Park, who previously held roles at Samsung. Ozys also operates other DeFi products including KLAYswap and Belt Finance. Ozys joined the Klaytn Governance Council and at one point held a strategic partnership with Alameda Research, which subsequently collapsed following Alameda's insolvency in late 2022.","heading":"Background: Ozys and Orbit Chain","sources":[{"url":"https://www.cypherhunter.com/en/p/ozys/","name":"cypherhunter.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/hashed-ozys-ad5aeade42ed","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/alameda-research-strategically-partners-with-orbit-chain-b88d1021c9f5","name":"medium.com","type":"other","credibility":3},{"url":"https://orbitchain.io/","name":"orbitchain.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2018","event":"Orbit Chain launched by Ozys as a cross-chain bridging protocol supporting multiple public blockchains.","source":"","date_original":"2018-01-01"},{"date":"2023-11-20","event":"Ozys' former Chief Information Security Officer submits a voluntary resignation request.","source":""},{"date":"2023-11-22","event":"The former CISO allegedly makes unauthorized changes to Ozys' internal firewall policies without notifying the company, according to Ozys' later allegations.","source":""},{"date":"2023-12-06","event":"The former CISO departs Ozys without disclosing firewall changes or providing handover documentation.","source":""},{"date":"2023-12-31","event":"At approximately 20:52 UTC, an attacker pre-funds an intermediary wallet with 10 ETH sourced from Tornado Cash and begins executing the Orbit Bridge exploit.","source":""},{"date":"2024","event":"Six transactions drain approximately $81.5 million (ETH, WBTC, USDT, USDC, DAI) from the Orbit Bridge Ethereum vault between 05:52–06:25 KST. Development team notified at 07:05 KST; vault shut down at 07:21 KST.","source":"","date_original":"2024-01-01"},{"date":"2024","event":"Seoul Metropolitan Police notified at 10:00 KST. KISA notified at 10:35 KST. Security firm Theori engaged for joint investigation.","source":"","date_original":"2024-01-01"},{"date":"2024-01-10","event":"Investigators discover that the former CISO had arbitrarily changed firewall policies on November 22, 2023. Ozys notifies South Korea's National Intelligence Service; NIS opens formal investigation.","source":""},{"date":"2024-01-11","event":"Orbit Chain announces an $8 million USD public bounty for intelligence leading to attacker identification or fund recovery.","source":""},{"date":"2024-01-25","event":"Ozys publicly alleges that its former CISO sabotaged the firewall and files civil lawsuit and criminal complaint against the former employee.","source":""},{"date":"2024-06-08","event":"After approximately five months of dormancy, the exploiter moves 12,932 ETH (approximately $47.7 million) through Tornado Cash across seven transactions.","source":""}],"sources_used":[{"url":"https://cointelegraph.com/news/cross-chain-protocol-orbit-bridge-suffers-exploit-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/01/02/orbit-chain-loses-81m-in-cross-chain-bridge-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/orbit-chain-exploited-816-million-drained-cross-chain-bridge/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-orbit-bridge-hack-december-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/new-year-new-attack-orbit-bridge-drained-for-82m/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/274411/orbit-bridge-firewall-sabotage-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://dailycoin.com/ozys-blames-former-ciso-for-81-5m-orbit-bridge-exploit/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/01/25/ozys-alleges-former-cisos-role-in-firewall-breach/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://cryptonews.com/news/south-korean-agencies-investigate-82m-orbit-bridge-hack/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://therecord.media/korean-police-investigating-cryptocurrency-theft-orbit-chain","name":"therecord.media","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/orbit-chain-hacker-moves-nearly-48-million-via-tornado-cash","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/06/10/orbit-chain-hacker-moves-47-7-million-to-tornado-cash/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://dailycoin.com/orbit-chain-hacker-online-48m-tornado-cash/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://blockchain.news/flashnews/eth-alert-orbit-chain-hack-wallet-launders-4-320-eth-via-tornado-cash-total-17-242-eth-moved-after-81-5m-exploit","name":"blockchain.news","type":"other","credibility":3},{"url":"https://socket.dev/blog/orbit-chain-offers-8M-bounty","name":"socket.dev","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/orbit-bridge-exploit-asset-recovery-and-ecosystem-normalization-plan-draft-3aa7ac2a6e4a","name":"medium.com","type":"other","credibility":3},{"url":"https://www.cypherhunter.com/en/p/ozys/","name":"cypherhunter.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/hashed-ozys-ad5aeade42ed","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/orbit-chain/alameda-research-strategically-partners-with-orbit-chain-b88d1021c9f5","name":"medium.com","type":"other","credibility":3},{"url":"https://orbitchain.io/","name":"orbitchain.io","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:33:12.458029+00:00","updated_at":"2026-08-29T01:34:08.642+00:00"}}