Skip to main content
Sign in

Orbit Chain Bridge

avoid.net/orbit-chain-bridge8/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·W7yvHi…88Dd

Summary

Orbit Bridge is the cross-chain bridging protocol of Orbit Chain, developed by South Korean blockchain company Ozys. On December 31, 2023, attackers compromised seven of ten multisig private keys and drained approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Ethereum vault in the largest crypto hack of New Year's Eve 2023. The attack has been attributed with medium-to-high confidence to North Korea's Lazarus Group, with an additional alleged insider-threat dimension involving Ozys' former chief information security officer, who allegedly sabotaged the company firewall weeks before the exploit.

Connected Entities

1 entities
Organizations
Orbit Chain Bridge
Relationships
    Have evidence about Orbit Chain Bridge?

    Timeline(11 events)

    2018

    Orbit Chain launched by Ozys as a cross-chain bridging protocol supporting multiple public blockchains.

    20 November 2023

    Ozys' former Chief Information Security Officer submits a voluntary resignation request.

    22 November 2023

    The former CISO allegedly makes unauthorized changes to Ozys' internal firewall policies without notifying the company, according to Ozys' later allegations.

    6 December 2023

    The former CISO departs Ozys without disclosing firewall changes or providing handover documentation.

    31 December 2023

    At approximately 20:52 UTC, an attacker pre-funds an intermediary wallet with 10 ETH sourced from Tornado Cash and begins executing the Orbit Bridge exploit.

    2024

    Six transactions drain approximately $81.5 million (ETH, WBTC, USDT, USDC, DAI) from the Orbit Bridge Ethereum vault between 05:52–06:25 KST. Development team notified at 07:05 KST; vault shut down at 07:21 KST.

    2024

    Seoul Metropolitan Police notified at 10:00 KST. KISA notified at 10:35 KST. Security firm Theori engaged for joint investigation.

    10 January 2024

    Investigators discover that the former CISO had arbitrarily changed firewall policies on November 22, 2023. Ozys notifies South Korea's National Intelligence Service; NIS opens formal investigation.

    11 January 2024

    Orbit Chain announces an $8 million USD public bounty for intelligence leading to attacker identification or fund recovery.

    25 January 2024

    Ozys publicly alleges that its former CISO sabotaged the firewall and files civil lawsuit and criminal complaint against the former employee.

    8 June 2024

    After approximately five months of dormancy, the exploiter moves 12,932 ETH (approximately $47.7 million) through Tornado Cash across seven transactions.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 21 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 5/30/2026, 6:33:12 PM

    last updated: 8/29/2026, 1:34:08 AM

    avoid.net — verified advice for a post-truth world