CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • CryptoPotato Crypto Fund
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • bitcoin
    BTC$27,996.00
  • ethereum
    ETH$1,785.83
    • Market Updates
    • BTC Analysis
    • ETH Analysis
    • XRP Analysis
    • Interviews
    • Opinions
    CryptoPotato
    CryptoPotato
    • Crypto News
    • Margin Trading
    • Guides
      • Bitcoin & Crypto Guides 101
      • Bitcoin For Beginners
      • Editorials
    • DeFi & NFT
    • Buy
    • Language
    • Crypto News
    • Bitcoin For Beginners
    • Cryptocurrency Guides 101
    • Editorials
    • Bitcoin & Crypto Margin Trading
    • DeFi & NFT News
    • Bitcoin Price Analysis
    • CryptoPotato Crypto Fund
    • Ethereum (ETH) Price Analysis
    • Ripple (XRP) Price Analysis
    • Market Updates
    • Interviews
    • Buy Bitcoin with Card
    Home » Crypto News » Orion Protocol Hacked for $3 Million Through Reentrancy Attack

    Orion Protocol Hacked for $3 Million Through Reentrancy Attack

    Author: Andrew Throuvalas

    Last Updated Feb 3, 2023 @ 21:37

    Another reentrancy bug gets targeted by hackers – but no users were exposed to the affected contract. 

    Orion Protocol – a liquidity aggregator for both CeFi and DeFi exchanges – saw its core contract hacked on Thursday across both its Ethereum and Binance Smart Chains (BSC) deployments. 

    The hacker netted over 1700 ETH, cumulatively worth over $3 million at writing time. 

    Another Reentrancy Hack

    As explained by the blockchain security company PeckShield on Twitter, Thursday’s hack was made possible “due to incomplete reentrancy protection.” A reentrancy bug refers to when an attacker may withdraw funds repeatedly from a smart contract at no cost. 

    PeckShield elaborated that the swapThroughOrionPool function lets anyone with crafted tokens to hijack their transfer into re-entering the deposit asset function. This lets users increase their balance without any actual cost of funds. 

    In this case, the hacker used a newly constructed token called ATK, and a self-destructing smart contract, to manipulate Orion’s pools. 

    ADVERTISEMENT

    4/ The hack is started first on BSC w/ initial fund 0.4 BNB from @TornadoCash. The ETH hack draws initial fund 0.4 ETH from @SimpleSwap_io. After hack, the gain of 1100 ETH is deposited into @TornadoCash and other 657 ETH stays in the hacker’s account: https://t.co/wGG6RA0qii pic.twitter.com/lRj9HGEgQc

    — PeckShield Inc. (@peckshield) February 3, 2023

    Alexey Koloskov, CEO of Orion, published a thread explaining the exploit shortly after it occurred. 

    “We have reasons to believe that the issue was not a result of any shortcomings in our core protocol code, but rather might have been caused by a vulnerability in mixing third-party libraries in one of the smart contracts used by our experimental and private brokers,” he said. 

    Koloskov noted that the exploited contract wasn’t of major import to the public, but was mainly used by one of its experimental brokers with the company treasury. User funds, he said, are 100% safe. 

    Nevertheless, Orion’s Deposit function has been closed, and will not be re-opened until the bug is patched and proper audits have taken place. 

    The DeFi Honeypot

    Money stolen through DeFi hacks is growing over time: In 2022, $3.8 billion was stolen, with $1.7 billion in crypto taken by North Korean hackers alone. 

    Much of that money was taken by the North Korean Lazarus Group, which is suspected to have executed the $100 million Harmony bridge hack in June. 

    Some of the most lucrative targets for crypto hacks have been blockchain bridges – where cryptocurrencies backing their tokenized variants circulating on other blockchains are stored.

     In October, Binance Smart Chain (BSC) was paused by validators after a hacker minted 2 Million BNB (worth $600 million at the time) out of thin air by exploiting the blockchain bridge. Much of the BNB was quickly whisked away to other chains in the aftermath. 

    SPECIAL OFFER (Sponsored)
    Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

    PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.

    You Might Also Like:

    • hack_cover
      Over $5M Stolen From Ankr Protocol, Binance Pauses Withdrawals
    • hackers_cover
      Hacktober Finished With $657 Million Losses From Crypto Exploits
    • Hack
      Defrost Finance Drained for $12M - Flash Loan Attack or Rug Pull?
    Tags: DeFi Hacking
    Enjoy reading? Share with your friends
    Facebook Twitter LinkedIn Telegram

    About The Author

    Andrew Throuvalas
    More posts by this author

    Andrew is a content writer with a passion for Bitcoin. He became familiar with Bitcoin back in 2013, but began diligently studying the blockchain technology and its economic implications in 2017. Ever since, he’s believed in the network’s power to replace the current global monetary system, and provide financial freedom to billions worldwide.
    Contact: Medium | LinkedIn | Twitter

  • bitcoin
    BTC$27,996.00
  • ethereum
    ETH$1,785.83
  • Join Our Community

    FacebookTwitter YouTubeTelegram


    Editorials
    15 Months Later, What Changed Since November 2021? Interview With Phantom Wallet CEO

    15 Months Later, What Changed Since November 2021? Interview With Phantom Wallet CEO

    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    Join Our Newsletter
    Become a CryptoPotato VIP
    One Weekly Email Can Change Your Crypto Life.
    Sign-up FREE to receive our extended weekly market update and coin analysis report
    We NEVER send spam. You can unsubscribe at any time.
    Invalid email address
    Thanks for subscribing!
    Footer Logo
    About
    Advertise on CryptoPotato
    About Us | Contact Us | Careers
    Editorial Policy
    Terms of service | Privacy Policy | GDPR
    More Sections
    IEO List | Evaluations
    Airdrops
    Scholarship
    Disclaimer
    Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
    © Copyright CryptoPotato 2016 - 2021
    Scroll to top
    One Weekly Email Can Change Your Crypto Life.

    Sign-up FREE to receive our extended weekly market update and coin analysis report

    We never send SPAM. You can unsubscribe at any moment
    Invalid email address
    Thanks for subscribing!