🎉 Gate xStocks Trading is Now Live! Spot, Futures, and Alpha Zone – All Open!
📝 Share your trading experience or screenshots on Gate Square to unlock $1,000 rewards!
🎁 5 top Square creators * $100 Futures Voucher
🎉 Share your post on X – Top 10 posts by views * extra $50
How to Participate:
1️⃣ Follow Gate_Square
2️⃣ Make an original post (at least 20 words) with #Gate xStocks Trading Share#
3️⃣ If you share on Twitter, submit post link here: https://www.gate.com/questionnaire/6854
Note: You may submit the form multiple times. More posts, higher chances to win!
📅 July 3, 7:00 – July 9,
Orbit Chain was attacked for $80 million, and multiple coin assets were stolen.
Orbit Chain project suffers a large-scale attack, with losses as high as $80 million
At the beginning of the New Year 2024, the cross-chain bridge platform Orbit Chain encountered a major security incident, with estimated losses reaching 80 million USD. According to data from the security monitoring platform, the attackers had already begun small-scale probing attacks a day earlier and used the stolen small amount of ETH to cover transaction fees for the subsequent large-scale attack.
Orbit Chain, as a cross-chain platform that allows users to transfer cryptocurrency assets between different blockchains, has undoubtedly suffered a severe blow to its operations and user confidence due to the recent attack. Currently, the project team has taken emergency measures, suspended the operation of the cross-chain bridge contract, and is attempting to communicate with the attackers.
Attack Method Analysis
The attack mainly involved directly invoking the withdraw function of the Orbit Chain bridging contract to transfer assets. In-depth analysis revealed that this function uses a signature verification mechanism to ensure the legitimacy of withdrawals. In blockchain transactions, signature verification is a commonly used security measure to confirm the identity and authority of the transaction initiator.
The design requirement of the withdraw function is that at least 70% of the administrators (i.e., 7 out of 10 administrators) must sign the withdrawal transaction for it to be executed. This multi-signature mechanism was supposed to provide a high level of security, but in this incident, it was successfully breached by the attackers.
Attack Timeline
Flow of Stolen Funds
The attacker will disperse the stolen funds to five different addresses, specifically including:
Security Advisory
This incident once again highlights the importance of security design in blockchain projects, especially cross-chain bridges.
Code security is crucial. As the core of the blockchain system, contract code must strictly adhere to security standards and best practices to avoid common vulnerabilities.
A完善的权限管理和身份验证机制是保护资产安全的关键。Multi-signature, strict access control, and other measures can effectively reduce the risk of unauthorized operations.
Continuous security monitoring and rapid response mechanisms are crucial for the timely detection and handling of potential threats.
Regular security audits and timely fixes of identified vulnerabilities are necessary measures to maintain the long-term security of the system.
This incident has undoubtedly sounded the alarm for the entire cryptocurrency industry, reminding all parties to always prioritize security while pursuing innovation.