Incident case file
Sign in to watchORBToken/ORBCore Reentrancy Exploit — $32.6K Loss
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 11, 2026, an attacker exploited ORBToken's receive() function, which auto-granted maximum allowance and triggered an external call into ORBCore's addPoolAndSell() function — a function that lacked a reentrancy guard and was whitelisted for tax-exempt sells. This allowed a repeated cycle of tax-free sells. The attacker compounded this with ORBCore's burnLP function, which destroyed large amounts of ORB directly from the PancakeSwap Pair's own reserves on each call (capped at 20% of pool ORB balance), followed by a sync() call to manipulate reserve balances for profit. The attack extracted approximately $32,610.72 from the protocol.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)