Security incident · 2023-12-31
Orbit Bridge
According to the public DefiLlama incident dataset, Orbit Bridge (Ethereum) suffered a security incident on 2023-12-31, with about $81.7M reported lost.
| Date | 2023-12-31 |
|---|---|
| Reported loss | $81.7M |
| Chain | Ethereum |
| Target type | DeFi Protocol |
| Technique class | Input Validation |
| Technique | Signature Verification Flaw |
| Bridge incident | Yes |
| Within 2023 | #7 by loss that year, 5.0% of all reported losses that year |
How this kind of attack works
The contract did not check the parameters it received, and the attacker passed crafted data that made it do something it should not.
Would a pre-payment check have helped
Missing input validation is a contract code defect for code audits.

