🎉 Congratulations to the following users for winning in the #Gate CBO Kevin Lee# - 6/26 event!
KaRaDeNiZ, Sakura_3434, Anza01, asiftahsin, GateUser-d0654db3, milaluxury, Ryakpanda, 静.和, milaluxury, 币大亨1
💰 Each winner will receive $5 Points!
🎁 Rewards will be distributed within 14 working days. Please make sure to complete identity verification to be eligible.
📌 Event details: https://www.gate.com/post/status/11782130
🙏 Thank you all for your enthusiastic participation — more exciting events are on the way!
Orbit Chain suffers an attack of $80 million: Analysis of the first major security incident of 2024
Orbit Chain Project Suffers $80 Million Loss, Analysis of the Biggest Security Incident at the Start of the New Year
On January 1, 2024, a cross-chain bridge platform, Orbit Chain, suffered a significant security attack, resulting in losses of approximately $80 million. Security monitoring platform data shows that the attackers began small-scale probing attacks a day earlier and used a small amount of stolen ETH to cover transaction fees for the subsequent large-scale attack.
Currently, the project team has taken emergency measures to suspend the operation of the cross-chain bridge contract and is attempting to establish contact with the attacker. Security experts have conducted an in-depth analysis of the incident, and the following are the main findings:
Analysis of Attack Methods
Attackers primarily transfer assets by directly calling the withdraw function in the Bridge contract of Orbit Chain. This function uses a signature verification mechanism to ensure the legitimacy of the withdrawal operation. Specifically:
According to on-chain data, the contract is jointly managed by 10 administrator addresses, of which at least 7 administrators (70%) need to sign to execute withdrawal operations.
Experts speculate that this incident was likely caused by a phishing attack on the server storing the administrator's private key.
Attack Timeline
Capital Flow
As of the time the report was released, the stolen funds have been transferred to 5 different addresses. The specific amounts are as follows:
Security Insights
This event once again highlights the importance of security design in blockchain systems:
Code Security: As the core of the blockchain system, contract code must strictly adhere to security best practices to avoid common vulnerabilities.
Permission Management: Strengthen identity verification mechanisms, implement multi-signature and strict access control to prevent unauthorized operations.
Continuous Monitoring: Establish a real-time monitoring system to promptly detect and respond to potential threats.
Emergency Response: Develop and完善 emergency plans to respond quickly when incidents occur, minimizing losses to the greatest extent.
This incident reminds us that while blockchain technology is rapidly developing, security issues remain one of the biggest challenges facing the industry. Project teams, developers, and users need to stay highly vigilant and work together to maintain the security of the ecosystem.