{"id":44798,"date":"2023-02-03T18:25:44","date_gmt":"2023-02-03T22:25:44","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=44798"},"modified":"2023-02-03T18:25:48","modified_gmt":"2023-02-03T22:25:48","slug":"orion-protocol-suffers-3m-hack-on-core-smart-contract","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/orion-protocol-suffers-3m-hack-on-core-smart-contract\/","title":{"rendered":"Orion Protocol Suffers $3M Hack On Core Smart Contract"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-decentralized-exchange-platform-orion-protocol-was-hacked-suffering-a-loss-of-3-million-due-to-a-reentrancy-issue-in-its-core-contract\"><a href=\"https:\/\/coinscreed.com\/staging\/square-ceo-discusses-plans-to-create-a-decentralized-exchange-for-bitcoin.html\" target=\"_blank\" rel=\"noreferrer noopener\">Decentralized exchange platform Orion Protocol<\/a> was hacked, suffering a loss of $3 million due to a reentrancy issue in its core contract.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-1024x576.jpg\" alt=\"Orion Protocol Suffers $3M Hack On Core Smart Contract\" class=\"wp-image-44800\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Orion Protocol Suffers $3M Hack On Core Smart Contract<\/figcaption><\/figure>\n\n\n\n<p>Orion Protocol, a decentralized exchange platform, was the victim of a $3 million hack as a result of reentrancy problems from outside libraries. Users can access liquidity pools on both <a href=\"https:\/\/www.google.com\/search?q=Orion+Protocol+Suffers+%243M+Hack+On+Core+Smart+Contract&client=opera&ei=HIfdY_21KYKJ9u8P0L2f8AE&ved=0ahUKEwj9s5X3r_r8AhWChP0HHdDeBx4Q4dUDCA4&uact=5&oq=Orion+Protocol+Suffers+%243M+Hack+On+Core+Smart+Contract&gs_lcp=Cgxnd3Mtd2l6LXNlcnAQAzIFCCEQoAEyBQghEKABOhMIABCPARDqAhC0AhCMAxDlAhgBOhMILhCPARDqAhC0AhCMAxDlAhgBOhYILhCPARDUAhDqAhC0AhCMAxDlAhgBSgQIQRgASgQIRhgAULUMWLUMYJITaAJwAHgAgAHMAogBzAKSAQMzLTGYAQCgAQGgAQKwAQrAAQHaAQQIARgK&sclient=gws-wiz-serp\" target=\"_blank\" rel=\"noreferrer noopener\">centralized and decentralized exchanges<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> directly from their non-custodial wallet thanks to the Orion protocol.<\/p>\n\n\n\n<p>However, a hacker was able to take over the protocol due to an imperfect reentrancy issue and steal nearly $3 million, according to a report published on January 3 by the securities firm Peckshield.<\/p>\n\n\n\n<p>The contract was made vulnerable to the exploit when the hacker repeatedly invoked the &#8220;depositAsset&#8221; method. Tornado Cash provided the first 0.4BNB to Orion, and SimpleSwap provided the last 0.4ETH.<\/p>\n\n\n\n<p>The hacker locked up roughly 657 ETH in his wallet address before attempting to extract about 1100 ETH using <a href=\"https:\/\/coinscreed.com\/staging\/deribit-attack-hackers-move-stolen-ether-via-tornado-cash-mixer.html\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash<\/a>. In a Twitter conversation, the CEO of Orion Protocol, Alexey Koloskov, acknowledged the attack and claimed that a flaw in one of the external libraries that Orion used during development was to blame.<\/p>\n\n\n\n<p>Koloskov asserted that all user monies are secure and that the stolen money actually came from Orion's Treasury.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe want to reassure our users that no user experienced any loss during this incident. The assets at risk were in internal broker\u2019s accounts run by ourselves-the Orion team.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Koloskov stated that the Orion team will give priority to creating all of its contracts internally in order to avoid potential vulnerabilities from third-party libraries.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized exchange platform Orion Protocol was hacked, suffering a loss of $3 million due to a reentrancy issue in its core contract. Orion Protocol, a decentralized exchange platform, was the victim of a $3 million hack as a result of reentrancy problems from outside libraries. Users can access liquidity pools on both centralized and decentralized [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":44800,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[12665,13241],"class_list":["post-44798","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-decentralized","tag-orion-protocol"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/croc_1675461222877.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/44798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=44798"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/44798\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/44800"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=44798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=44798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=44798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}