CryptoReal
CASE FILE — Jan 9, 2025

Compromised Admin Key Drains $843,556 From Orange Finance on Arbitrum

Arbitrum-based yield protocol Orange Finance lost $843,556.90 on January 9, 2025, after an attacker gained control of the project's administrative private key and used it to take over the protocol's smart contracts. The breach occurred overnight, sometime between Tuesday and Wednesday, leaving the team unable to intervene before funds began moving out.

01Mechanism

With the key in hand, the attacker pushed a contract upgrade that replaced Orange Finance's logic with code under their own control, then began pulling value out of the protocol's pools and vaults. The team later confirmed what had happened in a short statement: "The contract is no longer Orange," they wrote. Security firm PeckShield flagged the exploit shortly afterward, posting an alert urging holders to stop interacting with the compromised contracts and to revoke any related token approvals — by which point most of the outflow had already occurred.

Attacker address: 0x496e5a7ba67735c7ee5eb81ef07b65b909a31345

Attack contract: 0x17c8eA17F174B5fa49D5090933ff28cE2DF10a3c

02Transaction trail

Per the reconstruction published by the protocol, the attacker's on-chain actions ran as follows:

Sums referenced in this case file

From there, the funds were forwarded to a second address, 0xeB0f537A7a1C3E38d4F57026982c11F6886233D7, and finally bridged off the chain through Stargate, in this transaction.

03Losses by source

Combined, these figures break down into $783,966.93 in direct deposit losses, $47,447.26 attributable to exploited approvals, and $12,142.71614 in unclaimed SYK rewards, for a total loss of $843,556.90.

04Response

Orange Finance's first statement after the breach told users to stay away from the protocol and explained how to revoke contract approvals. A follow-up post confirmed that the team had also opened a direct line to the attacker, proposing a deal in exchange for returning the funds:

"If you respond positively to our offer within 24 hours, we guarantee that no law enforcement agencies will be involved, and the matter will be treated as a white-hat hack."

05Root-cause findings

A post-incident review from the team identified several gaps that allowed the breach to happen: there was no system in place to monitor for suspicious activity, controls around who could exercise privileged functions were weak, and — the central issue — the multi-signature wallet intended to protect admin operations only required one signer to approve a transaction. Orange Finance says it will share a full breakdown of losses by user, while it has not yet disclosed how the key was exposed in the first place — an inquiry the team says is still underway.

Orange FinancePrivate Key Leak
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.