Skip to main content
Sign in

Audit log

Every state-changing event for Oraichain — EVM Cross-Chain Unauthorized Minting Exploit (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-16 17:04:42Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    A1AVNANtnYWz…JG9QTB8Rsha256 → base58
    verifying row…
    canonical bytes (13973 B) ▸
    {"actor":"system:backfill","investigation_id":"29747fbf-1f8b-44eb-832b-5034d8905351","kind":"publish","page_slug":"oraichain-evm-cross-chain-unauthorized-minting-exploit-august-2026","published_at":"2026-08-16T17:04:42.084Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Oraichain — EVM Cross-Chain Unauthorized Minting Exploit (August 2026)","sections":[{"content":"On August 9, 2026, Oraichain publicly disclosed that a vulnerability in an EVM cross-chain transfer path had enabled the unauthorized minting of ORAI tokens. The team halted all mainnet operations at 04:00 UTC, restricting bridges, cross-chain routes, and public interfaces network-wide. Oraichain is an AI-integrated Layer 1 blockchain that uses ORAI as its native token for gas, governance, and staking. The unauthorized minting constituted a supply-integrity failure: tokens were created outside of protocol-authorized controls, placing all existing ORAI holders at risk of dilution. The team disclosed the incident on X (formerly Twitter) and requested that users refrain from transferring ORAI or performing any mainnet transactions until further notice. A full network halt of this scope — affecting all users, validators, and integrators simultaneously — is among the most severe immediate responses a Layer 1 team can execute, and signals that the team judged the risk as critical.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Crypto Times: Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"CryptoRank: Oraichain cross-chain vulnerability — unauthorized ORAI minted, network paused","type":"news_article","url":"https://cryptorank.io/news/feed/cad7c-2281967"},{"credibility":1,"name":"Oraichain on X (@oraichain)","type":"official","url":"https://x.com/oraichain"}]},{"content":"Oraichain disclosed that the root cause was a vulnerability in its EVM cross-chain transfer path — the mechanism by which assets are relayed between the Oraichain native chain and EVM-compatible environments. This class of vulnerability typically involves insufficient validation of cross-chain receipts or messages, allowing an attacker to trigger the minting function without a corresponding lock or burn of assets on the originating chain. The exploit is categorized as a supply-integrity failure rather than a funds-drain attack, meaning the primary harm was inflation of ORAI supply rather than direct theft of existing holder balances. The specific technical root cause (e.g., signature verification bypass, quorum flaw, or replay attack) had not been disclosed in a formal post-mortem as of the article date of August 16, 2026. The dollar value of losses and the specific attacker wallet addresses were not disclosed by the team in initial statements. One source — derived from a rendered view of Oraichain's X profile — indicated that approximately 3.9 million unauthorized ORAI tokens were deposited to centralized exchanges before the halt; this figure is flagged as low confidence pending official confirmation from Oraichain or verifiable on-chain data. The incident belongs to the same exploit class as the Harmony ONE unauthorized minting event that occurred on August 12, 2026, in which a quorum verification flaw allowed minting of approximately 4 billion ONE tokens.","heading":"Technical Nature of the Exploit","severity":"critical","sources":[{"credibility":2,"name":"Crypto Times: Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"CryptoRank: Oraichain cross-chain vulnerability — unauthorized ORAI minted, network paused","type":"news_article","url":"https://cryptorank.io/news/feed/cad7c-2281967"},{"credibility":2,"name":"Harmony ONE minting exploit for comparative context — Decrypt","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"}]},{"content":"Following disclosure, the Oraichain team took the following containment actions: (1) halted the entire mainnet beginning at 04:00 UTC on August 9, 2026; (2) restricted all bridge contracts, cross-chain routes, and public-facing interfaces; (3) coordinated with centralized exchange partners — including MEXC — to limit further movements of unauthorized tokens. MEXC confirmed it had temporarily suspended ORAI deposits and withdrawals at the request of the Oraichain project team, as documented in an official MEXC announcement. The team stated publicly that the exploit path had been identified and addressed, and that ongoing investigation and account reconciliation were underway. The team also announced plans to burn the unauthorized minted balances and reconcile protocol state to restore canonical ORAI supply. By approximately August 11, 2026, the network was reported to have come back online. As of the August 16, 2026 reporting date, a detailed technical post-mortem had not been published, and the timeline for supply reconciliation had not been formally announced.","heading":"Team Response and Containment","severity":"high","sources":[{"credibility":1,"name":"MEXC: Suspension of ORAI Deposits and Withdrawals","type":"official","url":"https://www.mexc.com/announcements/article/suspension-of-orai-deposits-and-withdrawals-17827791537401"},{"credibility":1,"name":"Oraichain on X (@oraichain)","type":"official","url":"https://x.com/oraichain"},{"credibility":2,"name":"CryptoRank: Oraichain cross-chain vulnerability — unauthorized ORAI minted, network paused","type":"news_article","url":"https://cryptorank.io/news/feed/cad7c-2281967"}]},{"content":"The ORAI token experienced a reported price decline of approximately 17.9% over the seven-day window surrounding the incident, consistent with market repricing of supply-integrity risk. Unlike a direct treasury theft, a minting exploit does not deplete existing balances but introduces unauthorized supply that, if liquidated on exchanges before a freeze, permanently dilutes existing holders. If any unauthorized tokens were sold on markets prior to the exchange freezes — a fact unconfirmed in current reporting — those losses to holders would be unrecoverable through the planned burn. The planned burn of unauthorized minted balances, if completed and independently verifiable on-chain, would restore canonical supply. However, the credibility of supply restoration depends on transparent public disclosure of the total minted quantity, the burn transaction hashes, and an independent reconciliation of pre- and post-incident token supply figures — none of which had been published as of August 16, 2026. The broader week of August 9–15, 2026, saw confirmed crypto security losses exceed $37 million, spanning a $25.6 million phishing drain, a $7.9 million cross-chain breach at Coinsbuy, the Harmony ONE minting exploit, a 200,000 XRP theft from the Coreum-XRPL Bridge, and a pricing-logic flaw at USM Protocol.","heading":"Market Impact and Token Supply Risk","severity":"high","sources":[{"credibility":2,"name":"Crypto Times: Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"Oraichain ORAI price data — CoinGecko","type":"other","url":"https://www.coingecko.com/en/coins/oraichain-token"}]},{"content":"Oraichain is a Layer 1 blockchain that positions itself as an AI-integrated oracle and smart contract platform. Its native token ORAI is used for transaction fees, validator staking, and governance. The protocol operates its own mainnet and supports EVM-compatible execution via a cross-chain bridge architecture. The August 2026 exploit specifically affected the EVM cross-chain transfer path, suggesting the vulnerability resided in the bridge or relay infrastructure rather than the core Oraichain consensus engine. Prior to this incident, Oraichain had not been associated with major security incidents in publicly available reporting reviewed for this investigation. The protocol's decision to execute a full network halt — rather than a targeted bridge pause — indicates the team could not initially isolate the exploit to a single component and elected to prioritize containment over uptime.","heading":"Background: Oraichain Protocol","severity":"low","sources":[{"credibility":1,"name":"Oraichain official site","type":"official","url":"https://orai.io/"},{"credibility":1,"name":"Token Economics — Oraichain Docs","type":"official","url":"https://docs.orai.io/oraichain/tokenomics"}]},{"content":"As of August 16, 2026, the following material facts had not been publicly confirmed by Oraichain or independently verified: (1) the total quantity of ORAI tokens minted without authorization; (2) the dollar value of any tokens liquidated on exchanges before freezes were implemented; (3) specific attacker wallet addresses; (4) the detailed technical root cause of the EVM cross-chain path vulnerability; (5) a formal timeline for supply reconciliation and burn execution; and (6) independent confirmation that the network restart is free of the underlying vulnerability. This investigation will be updated when a formal post-mortem is published or when on-chain burn transactions can be verified. No regulatory findings, law enforcement actions, or court filings have been associated with this incident.","heading":"Outstanding Unknowns","severity":"medium","sources":[{"credibility":2,"name":"Crypto Times: Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"}]}],"sources_used":[{"credibility":2,"name":"Crypto Times: Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"CryptoRank: Oraichain cross-chain vulnerability — unauthorized ORAI minted, network paused","type":"news_article","url":"https://cryptorank.io/news/feed/cad7c-2281967"},{"credibility":1,"name":"MEXC: Suspension of ORAI Deposits and Withdrawals","type":"official","url":"https://www.mexc.com/announcements/article/suspension-of-orai-deposits-and-withdrawals-17827791537401"},{"credibility":1,"name":"Oraichain on X (@oraichain)","type":"official","url":"https://x.com/oraichain"},{"credibility":1,"name":"Oraichain official site","type":"official","url":"https://orai.io/"},{"credibility":1,"name":"Token Economics — Oraichain Docs","type":"official","url":"https://docs.orai.io/oraichain/tokenomics"},{"credibility":2,"name":"Decrypt: Harmony ONE sinks 37% after attacker mints 4 billion tokens","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"},{"credibility":2,"name":"The Block: Harmony confirms exploit involving unauthorized minting of ONE tokens","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"credibility":2,"name":"Oraichain ORAI price data — CoinGecko","type":"other","url":"https://www.coingecko.com/en/coins/oraichain-token"}],"summary":"On August 9, 2026, Oraichain — an AI-focused Layer 1 blockchain — suffered a supply-integrity exploit in which a vulnerability in its EVM cross-chain transfer path enabled the unauthorized minting of ORAI tokens. The team halted the entire network at 04:00 UTC, restricted all bridges and cross-chain routes, and coordinated with centralized exchanges including MEXC to freeze fund movements. As of mid-August 2026, the exploit path had been addressed, the network had been restored, and the team was preparing to burn the unauthorized minted balances to reconcile canonical ORAI supply.","timeline":[{"date":"2026-08-09","event":"Vulnerability in Oraichain EVM cross-chain transfer path exploited, enabling unauthorized minting of ORAI tokens. Network halted at 04:00 UTC. Bridges, cross-chain routes, and public interfaces restricted.","source":"Oraichain on X; CryptoRank","source_url":"https://cryptorank.io/news/feed/cad7c-2281967"},{"date":"2026-08-09","event":"MEXC temporarily suspended ORAI deposits and withdrawals at the request of the Oraichain project team.","source":"MEXC official announcement","source_url":"https://www.mexc.com/announcements/article/suspension-of-orai-deposits-and-withdrawals-17827791537401"},{"date":"2026-08-10","event":"Oraichain issued follow-up statement confirming exploit path had been identified and addressed, and announcing plans to burn unauthorized minted balances to restore canonical supply.","source":"Oraichain on X; CryptoRank","source_url":"https://cryptorank.io/news/feed/cad7c-2281967"},{"date":"2026-08-11","event":"Oraichain network reported to have come back online following patching and reconciliation efforts.","source":"Oraichain on X","source_url":"https://x.com/oraichain"},{"date":"2026-08-12","event":"Harmony Protocol suffered a separate but structurally similar unauthorized minting exploit, with approximately 4 billion ONE tokens minted via a quorum verification flaw.","source":"Decrypt; The Block","source_url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"},{"date":"2026-08-16","event":"Crypto Times weekly security roundup reported the Oraichain incident alongside other exploits totaling more than $37 million in confirmed losses for the week of August 9–15, 2026. No formal Oraichain post-mortem had been published.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 3f69c61e-3bd3-4530-8a17-025c2eeb99cd
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.