Orbit Bridge hack — December 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 2, 2024 |
| Target type | Cross-chain bridge |
| Loss | $81,500,000Published estimates range $81,000,000 to $82,000,000Price at time of incident |
| Method | Infrastructure compromiseunexplained compromise of bridge operator systems; the operator ruled out a contract bug and validator key theft, and later attributed weakened firewall settings to a departed security officer |
| Chains | Ethereum |
| Audited beforehand | Theori (per Ozys' own statement that Orbit services were audited before launch and when new features were introduced; no public audit report of the bridge was cited) |
| Attributed to | Lazarus Group (DPRK), suspectedSuspected |
| Outcome | Unresolved |
What happened
Orbit Bridge, the cross-chain bridge run by South Korean developer Ozys as part of the Orbit Chain project, lost roughly $81.5 million from its Ethereum vault. Ozys CEO Jinhan Choi said the theft happened in six incidents between 05:52 and 06:25 KST on 1 January 2024 — the evening of 31 December 2023 UTC — and took ETH, WBTC, USDT, USDC and DAI. The vault was shut down at 07:21 KST. Published totals range from about $81 million to $82 million depending on how the assets were priced; CoinDesk measured net outflows from Orbit Chain at $81.88 million.
The mechanism has never been fully explained. Ozys stated that the exploit "did not result from a vulnerability in the Orbit Bridge smart contract or the theft of a validator key," which leaves the question of how the withdrawals were authorised open. The Block reported that the exact nature of the hack remained unknown.
On 25 January 2024 Jinhan Choi published a further statement saying the breach was not the result of an oversight by Ozys but "a deliberate act" by the company's former chief information security officer, who had made unauthorised changes to firewall settings in late November 2023 around the time he resigned, left on 6 December 2023 without a handover, and whose changes went undetected until 10 January 2024. Ozys said it had taken legal action against him and asked South Korean police to investigate his potential involvement in the hack. Secondary reports disagree on the sequence: CoinGape places the firewall change on 22 November, two days after the resignation request, while CoinSense places the change on 20 November, two days before it. No charges against him have been reported and no source establishes that he carried out the theft.
The stolen assets were swapped into ETH and DAI, split across eight addresses and left untouched for months. On 8 June 2024 the exploiter moved about $48 million through Tornado Cash, per Arkham Intelligence data reported by The Block. Reports that the methodology resembled DPRK-linked Lazarus Group activity prompted Ozys to notify South Korean authorities. Nothing has been recovered.
Law enforcement
Seoul Metropolitan Police notified 1 January 2024; investigations opened by South Korea's National Intelligence Service National Cyber Security Center, the National Police Agency's Cyber Terror Investigation Unit and KISA. Ozys said it was taking civil and criminal measures over its former CISO's firewall changes. No charges or arrests have been publicly reported.
Sources
- Ozys / Orbit Chain (statement by CEO Jinhan Choi)Primary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CoinGape (25 January 2024, on the former CISO disclosure)Secondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/orbit-chain/official-statement-regarding-orbit-bridge-exploit-551928f3dc52
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Orbit Bridge hack — December 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/orbit-bridgehttps://itokenly.com/hacks/orbit-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.