Orbit Chain's Ethereum Bridge Drained of $81.5M in Year-End Multisig Breach
Orbit Chain's Ethereum bridge lost $81.5 million in the closing hours of 2023, in what appears to have been a compromise of the bridge's multisig. Orbit Chain — distinct from the L2-focused Orbiter — is a standalone network positioned as a hub connecting other established blockchain ecosystems.
01Timeline

The attack began just after 9PM UTC on December 31, 2023, and was first flagged publicly only a few minutes later. Orbit Chain's official acknowledgment referenced an unauthorized access event confirmed at 08:52:47 PM UTC on December 31 — preceding the withdrawal transactions — and the team also issued warnings about likely opportunistic phishing attempts targeting affected users in the aftermath.
At the time of initial reporting, Orbit's team had not disclosed the precise attack vector. The prevailing assumption was that signer keys on Orbit's ETH Vault multisig had been compromised, though some observers suggested the possibility of a transaction-replay bug, potentially related to a known issue flagged in Theori's 2022 Q1 security audit (page 7) of the bridge contracts.
Later disclosure: an insider angle
On January 25, Ozys — Orbit's development company — published a statement implicating its former Chief Information Security Officer. According to the statement, two days after announcing his voluntary retirement on November 20, the security specialist who had led Ozys' push toward ISMS certification made the firewall vulnerable, and left the company on December 6 without any handover communication, verbal or written. Ozys said investigations into the matter were continuing.
02The withdrawals
The drain unfolded as a sequence of large withdrawals from the bridge:
- 10M DAI at 21:08 UTC
- 231 WBTC (~$9.8M)
- 9,500 ETH (~$21.5M)
- 10M USDC
- 30M USDT, completing at 21:25 UTC
The bridge was subsequently deactivated at 22:21 UTC. Per Peckshield's attack-flow analysis, the centralized stablecoins and WBTC taken were swapped into ETH. A full list of attacker-controlled addresses holding the stolen funds was compiled by researcher Tay.
Attacker's primary address: 0x9263e7873613ddc598a701709875634819176aff
The attacker's address was reportedly funded via Tornado Cash, routed through an intermediary address.
03Possible attribution
The transaction pattern points toward a Lazarus Group operation, with researcher Tay linking the methodology to earlier attacks on Belt Finance and Klayswap.

04Scale in context
The stolen sum represents more than half of Orbit Bridge's total value locked at the time. It adds to what was already a substantial 2023 tally for the suspected group: Lazarus-linked activity accounted for at least $250 million in losses across the year, including the Atomic Wallet, AlphaPo, Stake, and CoinEx incidents.
As Tay put it:
Looks like 2024 is going to be another year of handing DPRK billions of dollars on a silver platter. Embarrassing af.
Note: this article reflects the original reporting timeline, including the January 25 follow-up disclosure from Ozys; investigations into the incident were described as ongoing at that point.
Get new scam files the moment we publish them — usually 2–3 emails a week.