← Radar

Incident case file

Sign in to watch

Oraichain — ICS-20 EVM Precompile Unauthorized Mint (~1.51B ORAI)

Incident date 2026-08-07Last updated Aug 20, 2026

5 views

RecoveringOraichain L1Cross-chain exploit — Unauthorized mint via ICS-20 EVM precompileCluster: ORAI-MINT-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Ledger

Attacker

MISSING — not publicly disclosed. Attacker exploited ICS-20 EVM precompile between 23:25–23:31 UTC Aug 8. Investigation ongoing; no wallet addresses published by Oraichain team as of Aug 20, 2026.

Funds moved to

~600M ORAI transferred to Injective via IBC | ~57M+ ORAI swapped in OraiDEX liquidity pools | ~3,161 ATOM obtained via Cosmos Hub IBC | ~5,438 OSMO obtained via Osmosis IBC | ~3.9M ORAI across local intermediary accounts | ~200M ORAI staged in fresh vault. Total minted: ~1.51B ORAI (~98x supply inflation). Burn of all unauthorized balances prepared; reconciliation of protocol state in progress.

Linked

MISSING — attacker wallet(s) and exploit transaction hashes not publicly disclosed. Vulnerable module: ICS-20 EVM precompile (Oraichain's Cosmos↔EVM bridge layer). CEX coordination confirmed: MEXC suspended ORAI deposits/withdrawals (https://www.mexc.com/announcements/article/suspension-of-orai-deposits-and-withdrawals-17827791537401). KuCoin also engaged. Manual recovery: await full post-mortem from @oraichain (not published as of Aug 20, 2026).

Chronology

9 beats
  1. August 8–9, 2026 — Oraichain's ICS-20 EVM precompile was exploited to mint approximately 1.51 billion unauthorized ORAI tokens, representing a ~98x inflation of the total supply.

  2. Root cause (official Oraichain): 'Vulnerable ICS-20 EVM precompile minted the transfer amount instead of debiting the sender.' Every IBC transfer through the vulnerable path credited ORAI to the recipient without debiting the sender's balance, allowing unlimited token creation.

  3. 23:25–23:31 UTC, Aug 8: Exploit window — attacker executes IBC transactions through the vulnerable precompile, generating ~1.51B unauthorized ORAI.

  4. 23:31–04:00 UTC: Fund movement phase — unauthorized ORAI distributed across chains: - ~600M ORAI → Injective via IBC - ~57M+ ORAI swapped in OraiDEX liquidity pools - ~3,161 ATOM obtained via Cosmos Hub IBC - ~5,438 OSMO obtained via Osmosis IBC - ~3.9M ORAI across local intermediary accounts - ~200M ORAI staged in a fresh vault

  5. 04:00 UTC, Aug 9: Oraichain halts the network. Bridges, cross-chain routes, and public interfaces restricted. Exploit path identified and addressed. MEXC and KuCoin engaged to suspend ORAI deposits/withdrawals.

  6. Aug 9–10: Team coordinates with partners and CEXs to limit fund movements and freeze unauthorized balances. Preparations begin to burn all unauthorized minted balances and reconcile protocol state.

  7. Aug 10: @oraichain publishes official update confirming containment and recovery roadmap.

  8. Aug 12: Oraichain reports on-chain restoration in progress.

  9. As of Aug 20, 2026: No full post-mortem published. Attacker wallets not disclosed. Burn of unauthorized ORAI pending confirmation. Network restart timeline not announced.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)