T
iTokenly

Orion Protocol hack — February 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 2, 2023
Target typeDecentralised exchange
Loss$3,000,000Price at time of incident
MethodReentrancyReentrancy in Orion's exchange contract (0x98a877bb507f19eb43130b688f522a13885cf604 on Ethereum). The attacker deployed a fake ERC-20 token whose transfer function called back into Orion, borrowed stablecoins via flash loan, and routed a swap through the fake token so that a re-entrant depositAsset call executed mid-swap. The deposited amount was counted twice, and the inflated internal balance was withdrawn.
ChainsEthereum, BNB Chain
OutcomeUnresolved

What happened

On 2 February 2023 an attacker took about $3 million from Orion Protocol, a liquidity-aggregating trading platform. CoinDesk reported initial estimates from on-chain analysts putting the split at roughly $2.8 million on Orion's Ethereum implementation and $200,000 on its BSC implementation. PeckShield first flagged the transactions, noting that the protocol was being paused as it reported. The attack was a reentrancy exploit. The attacker deployed a fake ERC-20 token, borrowed stablecoins through a flash loan, and routed a swap through that token. Because the fake token's transfer function called back into Orion's exchange contract, the attacker could re-enter and invoke depositAsset in the middle of the swap, so the deposited assets were counted twice; the inflated internal balance was then withdrawn. CertiK, analysing the vulnerable contract, described "a reentrant call to deposit tokens during the swap, thus causing the deposit tokens to also be counted in the swap process". DailyCoin, reporting Orion's post-mortem, put the flash loan at 284,700 USDT. Orion paused deposits. Chief executive Alexey Koloskov said no user experienced any loss and listed staking, the Orion Pool, the bridge, liquidity providers and depositless trading as secure, with the exploit contained to an internal broker account. He attributed the vulnerability to a mix of third-party libraries rather than Orion's core code, and said future contracts would be built in-house. CertiK noted that the compromised contract was not audited by CertiK, which had audited only Orion's token and sale contracts. Most proceeds were routed through Tornado Cash; roughly $1 million in ETH remained in the attacker's Ethereum address at the time of Orion's post-mortem. Published figures consistently say about $3 million and no more precise total has been released.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x98a877bb507f19eb43130b688f522a13885cf604

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. CertiKSecondary · retrieved 2026-08-01
  4. DailyCoin (reporting Orion Protocol's post-mortem)Secondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Orion Protocol hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/orion-protocol
https://itokenly.com/hacks/orion-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.