← Radar

Incident case file

Sign in to watch

ORBToken/ORBCore Reentrancy Exploit — $32.6K Loss

Incident date Sep 10, 2026Last updated Sep 24, 2026

0 views

ContainedBNB ChainReentrancy / tax-exempt reserve manipulationCluster: ORBTOKEN-BNB-2026-09

Estimated loss

$32.6K

Affected users

1
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0xd8b49172b1a33e77c2619a78e08471facff5dad3

Funds moved to

Extracted via repeated tax-free sells against the PancakeSwap liquidity pair, draining ~$32,610.72 directly from pool reserves.

Linked

Attacker EOA: 0xd8b49172b1a33e77c2619a78e08471facff5dad3. Attack contract: 0x4f33733a40fae6c19c3a4faf9bc08ce9a1806831. ORBToken: 0xc4d27261c06407053cad16cb825ecc0eee7ee7d7. ORBCore: 0x24b6308ab84b182d0598b73d21a42f4c2bb33c18. PancakeSwap Pair: 0x64fad72e5dde70b2960497744b348fd64cb4788c.

Chronology

1 beat
  1. On September 11, 2026, an attacker exploited ORBToken's receive() function, which auto-granted maximum allowance and triggered an external call into ORBCore's addPoolAndSell() function — a function that lacked a reentrancy guard and was whitelisted for tax-exempt sells. This allowed a repeated cycle of tax-free sells. The attacker compounded this with ORBCore's burnLP function, which destroyed large amounts of ORB directly from the PancakeSwap Pair's own reserves on each call (capped at 20% of pool ORB balance), followed by a sync() call to manipulate reserve balances for profit. The attack extracted approximately $32,610.72 from the protocol.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)