Orbit Bridge 2024 Ethereum vault exploit
On January 1, 2024, an unidentified attacker removed approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Orbit Bridge Ethereum vault. The Ethereum vault was shut down, and later recovery and partial service-resumption plans remained incomplete.
Incident facts
- Incident title
- Orbit Bridge 2024 Ethereum vault exploit
- Bridge
- Orbit Bridge
- Incident date
- 2024-01-01
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Orbit Chain, Ethereum
- Affected assets
- ETH, WBTC, USDT, USDC, DAI
- Attack category
- Unknown
- Reported loss
- $81.5 million
- Recovery
- Unknown
- Reimbursement
- In Progress
- Restart
- Partially Reopened
- Current outcome
- Limited After Incident
- Resolution
- Unresolved
- Last reviewed
- 2026-06-14
- Last verified
- 2026-06-14
Timeline events
Orbit Bridge Ethereum vault exploit disclosed2024-01-01
Orbit Chain reported that an unidentified attacker removed five asset types from the Ethereum vault and that the vault was shut down shortly after detection.
Asset recovery and ecosystem normalization plan announced2024-02-14
Ozys published a draft recovery plan combining company resources, partner support, long-term support assets, and future business proceeds while acknowledging that immediate full recovery from its own resources was limited.
XRP bridge functionality resumed after security inspection2024-09-06
Orbit Chain later reported that XRP bridge functionality had resumed after security inspection, while Ethereum-based asset migration and recovery-related work remained outstanding.
Evidence records
- Official Statement Regarding Orbit Bridge ExploitOrbit Chain / Ozys · Tier 1 · 2024-01-25
- Orbit Bridge Exploit Asset Recovery and Ecosystem Normalization Plan DraftOrbit Chain / Ozys · Tier 1 · 2024-02-14
- Orbit Bridge Strategies for Service Resumption DraftOrbit Chain / Ozys · Tier 1 · 2024-02-28
- Orbit Bridge Follow-up PlanOrbit Chain / Ozys · Tier 1 · 2024-09-27
- Orbit Chain Loses $81M in Cross-Chain Bridge ExploitCoinDesk · Tier 2 · 2024-01-02
Known unknowns
- The final recovered amount and user reimbursement outcome require further review.
- The official investigation did not identify a smart-contract flaw or validator-key theft as the established cause.
- The relationship between earlier firewall-policy changes and the exploit was not conclusively established in the reviewed sources.