Valid signatures, unauthorised transfers
The transactions that drained Orbit Bridge were correctly signed. From the contract’s point of view nothing anomalous occurred — the authorised signers approved a withdrawal, and it processed.
That makes this a key-management failure, and it puts Orbit alongside Ronin, Harmony and Multichain. Four bridge incidents in this tracker, four failures of who holds the keys rather than what the code says.
What that pattern should change
Bridge security discussion tends to focus on contract audits. The record here suggests the higher-yield questions are about signer independence, key custody practice, and whether anomalous withdrawals are detected by anything other than a user noticing.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- Unauthorised withdrawals are executed from Orbit Bridge with valid signatures. Orbit Chain
- Orbit Chain publicly confirms the incident and reports it to Korean authorities. Orbit Chain
What to check
Orbit Chain published statements and worked with Korean authorities; those official communications are the record.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Orbit Chain, Official statements (1 Jan 2024)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.