Orion Protocol: Fake token reentrancy — depositAsset() double-credit via ATK token transfer hook
Orion Protocol lost $3M when a fake token's transfer function re-entered the exchange contract's deposit accounting, doubling the attacker's ledger balance and enabling a massive artificial withdrawal.
Summary #
Orion Protocol suffered a DEX Aggregator / Liquidity Aggregator on 2023-02-02, resulting in a loss of approximately $3M.
What happened #
Orion Protocol lost $3M when a fake token's transfer function re-entered the exchange contract's deposit accounting, doubling the attacker's ledger balance and enabling a massive artificial withdrawal.