Oraichain August 2026 unauthorized cross-chain ORAI mint
During August 8–9, 2026, Oraichain detected abnormal mainnet activity and identified a vulnerability in an EVM cross-chain transfer path that enabled unauthorized ORAI minting. The network was halted from 04:00 UTC on August 9 and bridges, cross-chain routes and public interfaces were restricted. Oraichain later returned the network online and reported on-chain restoration complete, while about 3.9 million unauthorized ORAI remained traced to MEXC and KuCoin for freeze-and-return efforts.
Incident facts
- Incident title
- Oraichain August 2026 unauthorized cross-chain ORAI mint
- Bridge
- Oraichain EVM cross-chain transfer path
- Incident date
- Approx. 2026-08-08
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Oraichain
- Affected assets
- ORAI
- Attack category
- Message Verification Failure
- Reported loss
- No canonical USD loss is assigned. Oraichain later reported approximately 3.9 million unauthorized ORAI still traced to centralized exchanges; that quantity is an outstanding-assets claim, not a gross-loss valuation.
- Amount confidence
- Unknown
- Loss amount basis
- Reported By Project
- Recovery
- Unknown
- Reimbursement
- Unknown
- Restart
- Partially Reopened
- Current outcome
- Limited After Incident
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-23
- Last verified
- 2026-08-23
Amount and valuation
No canonical USD loss is assigned. Oraichain later reported approximately 3.9 million unauthorized ORAI still traced to centralized exchanges; that quantity is an outstanding-assets claim, not a gross-loss valuation.
Do not treat the monitoring feed value of USD 0 as zero economic impact and do not infer USD loss from market prices.
approximately 3.9 million unauthorized ORAI traced from the attacker wallet to MEXC and KuCoin after on-chain restoration
Outstanding attacker-linked asset quantity after restoration; not established as the original gross unauthorized mint amount or permanent loss.
Why this remains unresolved
- The final disposition and return/burn of approximately 3.9 million attacker-linked ORAI traced to MEXC and KuCoin remains unresolved in the reviewed first-party update.
- On-chain restoration completion is protocol-state and canonical-supply restoration; it is not proof of full attacker-fund recovery or user reimbursement.
- The network returned online, but a separately dated full reopening of the affected EVM cross-chain transfer path is not established.
Timeline events
Oraichain network returns online after containment2026-08
Oraichain announced that the network was back online after the incident response. This proves network return-to-service but not a separately verified full reopening of every affected cross-chain route.
Month precision avoids inventing a calendar date from the reviewed summary.
Unauthorized ORAI minting detected through EVM cross-chain transfer pathApprox. 2026-08-08
Oraichain identified a vulnerability in an EVM cross-chain transfer path that enabled unauthorized ORAI minting during the August 8–9 incident period.
Safe high-level verification-boundary description only; no exploit reproduction detail.
Oraichain halts network and restricts cross-chain routes2026-08-09
Oraichain halted the network from 04:00 UTC on August 9 and restricted bridges, cross-chain routes and public interfaces as containment while investigating and reconciling state.
On-chain restoration completed while attacker-linked ORAI remained outstanding2026-08-12
Oraichain reported on-chain restoration complete and said approximately 3.9 million unauthorized ORAI had been traced from the attacker wallet to MEXC and KuCoin. The project submitted fraud reports and on-chain evidence and requested freezes and return for permanent burn.
Protocol-state restoration is kept distinct from attacker-fund recovery and reimbursement.
Evidence records
- Oraichain official incident updateOraichain · Tier 1 · High reliability · primary · 2026-08-12Claim scope: Incident Case
First-party incident authority for abnormal activity, EVM cross-chain transfer-path vulnerability and unauthorized ORAI minting.
- Oraichain official incident updateOraichain · Tier 1 · High reliability · primary · 2026-08-12Claim scope: Shutdown
First-party authority for the August 9 containment halt and restrictions on bridges, cross-chain routes and public interfaces.
- Oraichain official incident updateOraichain · Tier 1 · High reliability · primary · 2026-08-12Claim scope: Restart
First-party authority that the Oraichain network returned online; does not independently prove full reopening of every affected cross-chain route.
- Oraichain official incident updateOraichain · Tier 1 · High reliability · primary · 2026-08-12Claim scope: Recovery
First-party authority that on-chain restoration was complete while attacker-linked ORAI remained under exchange freeze/return efforts.
- Oraichain official incident updateOraichain · Tier 1 · High reliability · primary · 2026-08-12Claim scope: Amount
First-party authority for approximately 3.9 million unauthorized ORAI traced to MEXC and KuCoin after on-chain restoration; not a gross-loss amount.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The incident-specific first-party material does not safely map the affected production path to the OBridge or OraiBridge product name.
- The original gross unauthorized ORAI mint quantity and realized economic loss are not normalized from the reviewed update.
- Completed reimbursement is not established.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.