Incident case file
Sign in to watchORE Protocol Stake Program Account-Check Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 6qTUG5NT1NTFk3rohxWku9F4JkWesLY4hNWrRCXr8kj
Timeline: On June 15, 2026 at 01:48 UTC, ORE protocol maintainers identified an attack on the stake program leading to unfair yield distribution. Attacker 6qTUG5NT1NTFk3rohxWku9F4JkWesLY4hNWrRCXr8kj exploited a missing account check in the stake program's deposit instruction, allowing them to inflate their recorded stake balance without actually depositing tokens — granting an unfairly large share of the stake pool (approximately 6% of the total) and a corresponding share of yield distribution. The stake program isolates user funds via independent per-account token accounts, meaning the attacker could not withdraw deposits belonging to other users; no user funds were ever at risk. ORE maintainers halted all yield transfers from the mining program to the staking program at approximately 01:52 UTC, roughly four minutes after detection. By that point, the attacker had earned approximately 25.5 ORE (~$2,125) in unearned yield. The attack was flagged early by community members @bootapollo and @blacklung0x of godl protocol. Because the affected stake program (STkEAu2cEyQp5ktgUauRVq8es6mEP2w6ixw4NEd5tDJ) and its associated liquid-staking wrapper (stORE) are frozen with no upgrade authority, the bug could not be patched in place. ORE published a full post-mortem ('Security Update') on June 17, 2026, and provided a one-click migration path to new contracts via ore.com/stake. PrivacyCash, which maintains the largest stORE shield pool, agreed to waive its 0.35% withdrawal fee for one week to facilitate migration. Yield distribution resumed approximately 24-48 hours after the post-mortem's publication. No deadline exists for migration.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)