{"investigation":{"slug":"orion-pools","entity_name":"Orion Pools","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Orion Pools is the automated market maker (AMM) and liquidity pool component of Orion Protocol, a DeFi liquidity aggregator founded in 2018 by Alexey Koloskov. On February 2, 2023, the protocol suffered a $3 million reentrancy exploit targeting its core exchange contract across Ethereum and BNB Chain, with stolen funds subsequently laundered through Tornado Cash. The project later rebranded to Lumia in late 2024, pivoting from a liquidity aggregator to a Layer 2 blockchain.","sections":[{"content":"Orion Pools is the decentralized liquidity pool and AMM product of Orion Protocol (ticker: ORN), a cryptocurrency trading infrastructure platform. Orion Protocol was founded in 2018 by Alexey Koloskov, who previously served as Chief Architect of the Waves DEX, and co-founder Kal Ali. The stated mission of the protocol was to aggregate liquidity from centralized exchanges (CEXs) and decentralized exchanges (DEXs) into a single platform without requiring users to undergo KYC or maintain multiple accounts. Orion Pools specifically offered Uniswap V2-style liquidity pools where users could contribute liquidity and earn a share of 0.3% transaction fees, split two-thirds to liquidity providers and one-third to governance stakers. The protocol raised $3.45 million in a funding round in July 2020. Orion launched its mainnet (Orion Terminal) on May 31, 2021. As of mid-2026, the protocol's total value locked (TVL) on DefiLlama stands at approximately $297,000, primarily across BSC ($208,567) and Ethereum ($86,228), representing a significant decline from earlier periods. In late 2024, Orion Protocol rebranded to Lumia, with all ORN tokens swapped to LUMIA at a 1:1 ratio, effective October 15, 2024, supported by exchanges including Binance, Crypto.com, and MEXC.","heading":"Project Overview","sources":[{"url":"https://defillama.com/protocol/orion-pools","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.orion.xyz/products/pools","name":"docs.orion.xyz","type":"other","credibility":3},{"url":"https://www.binance.com/en/support/announcement/binance-will-support-the-orion-orn-mainnet-swap-and-rebranding-to-lumia-lumia-066ba1773ce4480492b983f8d4764c91","name":"binance.com","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/alexey-koloskov","name":"iq.wiki","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 2, 2023, Orion Protocol suffered a critical smart contract exploit resulting in approximately $3 million in losses across two chains: approximately $2,836,206 on Ethereum and $191,030 on BNB Chain. The attack exploited a reentrancy vulnerability in the protocol's core exchange contract, specifically the ExchangeWithOrionPool (also referred to as ExchangeWithAtomic) function's swap logic. The vulnerable contract address on Ethereum was 0x98a877bb507f19eb43130b688f522a13885cf604. The attacker constructed a malicious fake token (designated ATK) with a self-destruct capability that triggered a reentrancy hook during the transfer() call. The exploit proceeded as follows: (1) the attacker deposited 0.5 USDC as initial collateral; (2) used a flash loan of 284,700 USDT; (3) initiated a swap along the path USDC-ATK-USDT, during which the ATK transfer() function re-entered the depositAsset function, artificially doubling the attacker's recorded balance; (4) the attacker then withdrew the inflated balance and converted profits to WETH. The known attacker addresses are 0x3dabf5e36df28f6064a7c5638d0c4e01539e35f1 and 0x837962b686fd5a407fb4e5f92e8be86a230484bd. Initial funding for the attack accounts is alleged to have originated from SimpleSwap, routed through Binance, with 0.4 BNB and 0.4 ETH also sourced from Tornado Cash. Following the exploit, the attacker deposited approximately 1,100 ETH of stolen funds into Tornado Cash for laundering. No public report of fund recovery has been identified. Multiple blockchain security firms including CertiK, PeckShield, SlowMist, QuillAudits, and BlockApex published post-mortems. CertiK's analysis notably confirmed that the compromised contract was outside the scope of their prior audit — CertiK had only audited Orion's token sale contracts in 2020-2021, not the exchange contract. SlowMist's assessment attributed the root cause to the absence of reentrancy guards on the exchange function.","heading":"February 2023 Reentrancy Exploit ($3 Million Loss)","sources":[{"url":"https://www.coindesk.com/business/2023/02/02/orion-protocol-loses-3m-of-crypto-in-trading-pool-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://rekt.news/orion-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/4se364ZqArmcLqzqsvXdUR-hunting-orion-the-usd3m-loss-from-a-reentrancy-attack","name":"certik.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/decoding-orion-protocols-reentrancy-exploit-quillaudits-396de59449f7","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2023/02/reentrancy-exploit-siphons-3m-off-orion-protocol","name":"cryptodaily.co.uk","type":"other","credibility":3},{"url":"https://blockapex.io/orion-protocol-hack-analysis/","name":"blockapex.io","type":"other","credibility":3}],"severity":"medium"},{"content":"In the immediate aftermath of the February 2023 exploit, CEO Alexey Koloskov stated publicly that 'all funds are safe and secure,' a claim that was inconsistent with the confirmed $3 million loss. Koloskov subsequently clarified that only an 'internal broker account' had been affected and that user accounts remained secure. He attributed the vulnerability to 'mixing third-party libraries in one of the smart contracts used by our experimental and private brokers' rather than core protocol code, framing it as an issue with third-party integrations rather than Orion's own development. In response, the protocol was paused, cybersecurity firm PeckShield was engaged to assist with root cause identification, and Orion Protocol announced it would develop all future contracts entirely in-house to avoid similar vulnerabilities from external library dependencies. No details of user compensation or a bug bounty payment to the attacker have been publicly documented in available sources.","heading":"Team Response and Postmortem","sources":[{"url":"https://www.coindesk.com/business/2023/02/02/orion-protocol-loses-3m-of-crypto-in-trading-pool-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/orion-protocol-suffers-3m-hack-due-to-third-party-vulnerabilities/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/208394/decentralized-exchange-orion-protocol-hacked-for-3-million","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Orion Protocol's audit history reveals a material coverage gap that contributed to the February 2023 exploit. CertiK conducted an audit of Orion's token sale contracts in July 2020 and performed a broader audit review in October 2020 around the Terminal mainnet launch; however, the core exchange contract (ExchangeWithOrionPool) that was ultimately exploited was explicitly noted by CertiK as 'Out of Audit Scope.' This means the most critical contract handling user funds and swap logic had not undergone formal third-party security review prior to the attack. DefiSafety also maintained a protocol quality report on Orion Protocol. The CertiK audit that was performed focused on informational-level findings and did not cover the vulnerable contract. This gap between audited and unaudited components is considered a significant security risk factor for DeFi protocols.","heading":"Smart Contract Audit Coverage Gaps","sources":[{"url":"https://www.certik.com/resources/blog/4se364ZqArmcLqzqsvXdUR-hunting-orion-the-usd3m-loss-from-a-reentrancy-attack","name":"certik.com","type":"other","credibility":3},{"url":"https://www.defisafety.com/app/pqrs/86","name":"defisafety.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to AVOID.NET's internal records, ZachXBT — a pseudonymous blockchain investigator known for exposing crypto fraud — flagged Orion Pools as a risk entity. The specific basis and date of ZachXBT's flag have not been independently located in publicly archived posts as of this investigation. Community risk signals include the February 2023 exploit, the subsequent laundering of stolen funds through Tornado Cash with no reported recovery, the initial misleading public communications from leadership following the hack, and the project's subsequent complete rebranding to Lumia in 2024. The rebranding from ORN to LUMIA, combined with the pivot from a DEX aggregator to a Layer 2 blockchain infrastructure project, represents a substantial change in project scope following the security incident.","heading":"ZachXBT Flag and Community Risk Signals","sources":[{"url":"https://www.coindesk.com/business/2023/02/02/orion-protocol-loses-3m-of-crypto-in-trading-pool-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://rekt.news/orion-protocol-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC, CFTC, DOJ, or other regulatory enforcement actions against Orion Protocol, Orion Pools, Alexey Koloskov, or affiliated entities have been identified in available public records as of this investigation. The project does not appear to have been named in any known court filings related to the February 2023 exploit. The stolen funds routed through Tornado Cash have not been attributed to any sanctioned entity in publicly available OFAC records. The absence of enforcement actions does not constitute regulatory clearance.","heading":"Regulatory and Legal Status","sources":[{"url":"https://defillama.com/protocol/orion-pools","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In late 2024, Orion Protocol completed a full rebranding to Lumia, describing itself as a 'hyper-liquid re-stake rollup Layer 2 blockchain.' The ORN token was swapped 1:1 for LUMIA, with the swap executed across major centralized exchanges including Binance (effective October 15, 2024), Crypto.com, MEXC, and CoinSpot. Trading for LUMIA/USDT pairs reopened on Binance on October 18, 2024. This rebranding marked a significant strategic pivot away from the liquidity aggregation model under which the February 2023 exploit occurred. The relationship between Orion Pools (the AMM product) and the Lumia Layer 2 infrastructure has not been clearly defined in available public documentation.","heading":"Rebranding to Lumia (2024)","sources":[{"url":"https://www.binance.com/en/support/announcement/binance-will-support-the-orion-orn-mainnet-swap-and-rebranding-to-lumia-lumia-066ba1773ce4480492b983f8d4764c91","name":"binance.com","type":"other","credibility":3},{"url":"https://crypto.news/binance-will-facilitate-users-swapping-orn-to-lumia-this-october/","name":"crypto.news","type":"other","credibility":3},{"url":"https://crypto.com/en/product-news/orn-to-lumia-mainnet-token-swap-and-rebranding","name":"crypto.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2018","event":"Orion Protocol founded by Alexey Koloskov and Kal Ali.","source":"","date_original":"2018-01-01"},{"date":"2020-07","event":"CertiK publishes audit of Orion token sale contracts. Core exchange contracts not included in scope.","source":"","date_original":"2020-07-01"},{"date":"2020-07","event":"Orion Protocol raises $3.45 million in funding.","source":"","date_original":"2020-07-01"},{"date":"2021-05-31","event":"Orion Terminal mainnet launches, including the Orion Pools AMM product.","source":""},{"date":"2023-02-02","event":"Reentrancy exploit drains approximately $3 million from Orion Protocol's exchange contract on Ethereum ($2.84M) and BNB Chain ($191K). Attacker uses a fake token (ATK) and flash loans to manipulate pool accounting.","source":""},{"date":"2023-02-02","event":"CEO Alexey Koloskov states 'all funds are safe and secure' hours after the exploit. Protocol is paused and PeckShield engaged for investigation.","source":""},{"date":"2023-02-03","event":"Attacker begins depositing stolen ETH into Tornado Cash for laundering. Approximately 1,100 ETH laundered; ~$1M ETH remained in attacker address.","source":""},{"date":"2024-02-26","event":"Orion Protocol announces rebranding to Lumia, positioning as a Layer 2 hyper-liquid restake rollup blockchain.","source":""},{"date":"2024-10-15","event":"ORN-to-LUMIA token swap goes live across major exchanges at 1:1 ratio. Binance reopens LUMIA/USDT trading on October 18, 2024.","source":""}],"sources_used":[{"url":"https://defillama.com/protocol/orion-pools","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250906132628/https://defillama.com/protocol/orion-pools","credibility":3,"archive_timestamp":"2025-09-06T13:26:28+00:00"},{"url":"https://docs.orion.xyz/products/pools","name":"docs.orion.xyz","type":"other","archive_url":"http://web.archive.org/web/20260122183604/https://docs.orion.xyz/products/pools","credibility":3,"archive_timestamp":"2026-01-22T18:36:04+00:00"},{"url":"https://www.binance.com/en/support/announcement/binance-will-support-the-orion-orn-mainnet-swap-and-rebranding-to-lumia-lumia-066ba1773ce4480492b983f8d4764c91","name":"binance.com","type":"other","archive_url":"http://web.archive.org/web/20260529145346/https://www.binance.com/en/support/announcement/binance-will-support-the-orion-orn-mainnet-swap-and-rebranding-to-lumia-lumia-066ba1773ce4480492b983f8d4764c91","credibility":3,"archive_timestamp":"2026-05-29T14:53:46+00:00"},{"url":"https://iq.wiki/wiki/alexey-koloskov","name":"iq.wiki","type":"other","archive_url":"http://web.archive.org/web/20260312162057/https://iq.wiki/wiki/alexey-koloskov","credibility":3,"archive_timestamp":"2026-03-12T16:20:57+00:00"},{"url":"https://www.coindesk.com/business/2023/02/02/orion-protocol-loses-3m-of-crypto-in-trading-pool-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260726075328/https://www.coindesk.com/business/2023/02/02/orion-protocol-loses-3m-of-crypto-in-trading-pool-exploit","credibility":3,"archive_timestamp":"2026-07-26T07:53:28+00:00"},{"url":"https://rekt.news/orion-protocol-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260607080246/https://rekt.news/orion-protocol-rekt","credibility":3,"archive_timestamp":"2026-06-07T08:02:46+00:00"},{"url":"https://www.certik.com/resources/blog/4se364ZqArmcLqzqsvXdUR-hunting-orion-the-usd3m-loss-from-a-reentrancy-attack","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829145016/https://www.certik.com/blog/4se364ZqArmcLqzqsvXdUR-hunting-orion-the-usd3m-loss-from-a-reentrancy-attack","credibility":3,"archive_timestamp":"2026-08-29T14:50:16+00:00"},{"url":"https://quillaudits.medium.com/decoding-orion-protocols-reentrancy-exploit-quillaudits-396de59449f7","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017165545/https://quillaudits.medium.com/decoding-orion-protocols-reentrancy-exploit-quillaudits-396de59449f7","credibility":3,"archive_timestamp":"2025-10-17T16:55:45+00:00"},{"url":"https://cryptodaily.co.uk/2023/02/reentrancy-exploit-siphons-3m-off-orion-protocol","name":"cryptodaily.co.uk","type":"other","archive_url":"http://web.archive.org/web/20260726001629/https://cryptodaily.co.uk/2023/02/reentrancy-exploit-siphons-3m-off-orion-protocol","credibility":3,"archive_timestamp":"2026-07-26T00:16:29+00:00"},{"url":"https://blockapex.io/orion-protocol-hack-analysis/","name":"blockapex.io","type":"other","archive_url":"http://web.archive.org/web/20260611001119/https://blockapex.io/orion-protocol-hack-analysis/","credibility":3,"archive_timestamp":"2026-06-11T00:11:19+00:00"},{"url":"https://cryptoslate.com/orion-protocol-suffers-3m-hack-due-to-third-party-vulnerabilities/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260725202520/https://cryptoslate.com/orion-protocol-suffers-3m-hack-due-to-third-party-vulnerabilities/","credibility":3,"archive_timestamp":"2026-07-25T20:25:20+00:00"},{"url":"https://www.theblock.co/post/208394/decentralized-exchange-orion-protocol-hacked-for-3-million","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.defisafety.com/app/pqrs/86","name":"defisafety.com","type":"other","archive_url":"http://web.archive.org/web/20251217115338/https://www.defisafety.com/app/pqrs/86","credibility":3,"archive_timestamp":"2025-12-17T11:53:38+00:00"},{"url":"https://crypto.news/binance-will-facilitate-users-swapping-orn-to-lumia-this-october/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251015093232/https://crypto.news/binance-will-facilitate-users-swapping-orn-to-lumia-this-october/","credibility":3,"archive_timestamp":"2025-10-15T09:32:32+00:00"},{"url":"https://crypto.com/en/product-news/orn-to-lumia-mainnet-token-swap-and-rebranding","name":"crypto.com","type":"other","archive_url":"http://web.archive.org/web/20260121012932/https://crypto.com/en/product-news/orn-to-lumia-mainnet-token-swap-and-rebranding","credibility":3,"archive_timestamp":"2026-01-21T01:29:32+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:44.523355+00:00","updated_at":"2026-08-29T15:48:29.983933+00:00"}}