Orbit Bridge 2024 Ethereum vault exploit
On January 1, 2024, an unidentified attacker removed approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Orbit Bridge Ethereum vault. The Ethereum vault was shut down, and later recovery and partial service-resumption plans remained incomplete.
Incident facts
- Incident title
- Orbit Bridge 2024 Ethereum vault exploit
- Bridge
- Orbit Bridge
- Incident date
- 2024-01-01
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Orbit Chain, Ethereum
- Affected assets
- ETH, WBTC, USDT, USDC, DAI
- Attack category
- Unknown
- Reported loss
- $81.5 million
- Amount confidence
- High
- Loss amount basis
- Official Incident Statement, Official Recovery Plan, And Contemporaneous Reporting
- Recovery
- Unknown
- Reimbursement
- In Progress
- Restart
- Partially Reopened
- Current outcome
- Limited After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-06-14
- Last verified
- 2026-06-14
Amount and valuation
Orbit Chain reported approximately $81.5 million at the time of the exploit; a later recovery plan rounded the total to approximately $82 million.
The record uses the official $81.5 million estimate as the canonical display amount and retains the $81–82 million public range.
ETH, WBTC, USDT, USDC, and DAI removed in six incidentsapproximately $81.5 million
Canonical display amount for this seed record.
five stolen asset typesapproximately $82 million
Rounded official estimate retained as the upper end of the range.
Why this remains unresolved
- Complete recovery of the Ethereum-vault assets is not established.
- The exact root cause and attacker attribution remain unresolved.
- Only part of the wider bridge functionality had resumed in the reviewed official updates.
Timeline events
Orbit Bridge Ethereum vault exploit disclosed2024-01-01
Orbit Chain reported that an unidentified attacker removed five asset types from the Ethereum vault and that the vault was shut down shortly after detection.
Official reporting places the incident at approximately 5:52 a.m. KST on January 1, 2024.
Asset recovery and ecosystem normalization plan announced2024-02-14
Ozys published a draft recovery plan combining company resources, partner support, long-term support assets, and future business proceeds while acknowledging that immediate full recovery from its own resources was limited.
The plan was forward-looking and is not treated as completed reimbursement or recovery.
XRP bridge functionality resumed after security inspection2024-09-06
Orbit Chain later reported that XRP bridge functionality had resumed after security inspection, while Ethereum-based asset migration and recovery-related work remained outstanding.
Partial service resumption does not establish full restoration of the affected Ethereum vault or user assets.
Evidence records
- Official Statement Regarding Orbit Bridge ExploitOrbit Chain / Ozys · Tier 1 · High reliability · primary · 2024-01-25Claim scope: Incident Case
Primary source for the $81.5 million estimate, affected assets, Ethereum-vault shutdown, and unresolved root-cause investigation.
- Orbit Bridge Exploit Asset Recovery and Ecosystem Normalization Plan DraftOrbit Chain / Ozys · Tier 1 · High reliability · primary · 2024-02-14Claim scope: Recovery
Primary source for the rounded $82 million total and the proposed long-term asset recovery and normalization structure.
- Orbit Bridge Strategies for Service Resumption DraftOrbit Chain / Ozys · Tier 1 · High reliability · primary · 2024-02-28Claim scope: Restart
Primary source distinguishing planned non-Ethereum partial reopening from the unresolved Ethereum vault.
- Orbit Bridge Follow-up PlanOrbit Chain / Ozys · Tier 1 · High reliability · primary · 2024-09-27Claim scope: Restart
Primary source for XRP bridge resumption and the remaining Ethereum-asset migration and lockup work.
- Orbit Chain Loses $81M in Cross-Chain Bridge ExploitCoinDesk · Tier 2 · High reliability · secondary · 2024-01-02Claim scope: Amount
Contemporaneous secondary source supporting the approximately $81 million public estimate and affected Ethereum-vault context.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final recovered amount and user reimbursement outcome require further review.
- The official investigation did not identify a smart-contract flaw or validator-key theft as the established cause.
- The relationship between earlier firewall-policy changes and the exploit was not conclusively established in the reviewed sources.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.