← Radar

Incident case file

Sign in to watch

ORE Protocol Stake Program Account-Check Exploit

Incident date June 15, 2026

1 views

ResolvedSolanaSmart contract exploit — missing account check / inflated stake balanceCluster: ORE-SOL-2026-06

Estimated loss

$2.1K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 6qTUG5NT1NTFk3rohxWku9F4JkWesLY4hNWrRCXr8kj

Funds moved to: Attacker unfairly acquired 25.5 ORE (~$2,125) in staking yield by inflating their recorded stake balance without depositing real tokens. No user deposits were ever at risk; each stake account is isolated. Yield distribution was halted approximately 4 minutes after detection.
Affected stake program: STkEAu2cEyQp5ktgUauRVq8es6mEP2w6ixw4NEd5tDJ. Affected LST program: LStwN2E5Uw6MCtuxHRLhy8RY9hxqW2XRpLzettb696y. Affected stORE mint: sTorERYB6xAZ1SSbwpK3zoK2EEwbBrc7TZAzg1uCGiH. New stake program (post-migration): stakecNP3FpiExZPCgZfqRgumVzi6dNqnfrjwXyTgeH. New LST program: storeD7bEkywTTMrje19WRoyrkEhbhrvyjVnLxWih6a. New stORE mint: storenSbvkfzircixnaosc5CbzNZVrHJ6S3EKrS1yqR. Attack was flagged early by community members @bootapollo and @blacklung0x of godl protocol.

Timeline: On June 15, 2026 at 01:48 UTC, ORE protocol maintainers identified an attack on the stake program leading to unfair yield distribution. Attacker 6qTUG5NT1NTFk3rohxWku9F4JkWesLY4hNWrRCXr8kj exploited a missing account check in the stake program's deposit instruction, allowing them to inflate their recorded stake balance without actually depositing tokens — granting an unfairly large share of the stake pool (approximately 6% of the total) and a corresponding share of yield distribution. The stake program isolates user funds via independent per-account token accounts, meaning the attacker could not withdraw deposits belonging to other users; no user funds were ever at risk. ORE maintainers halted all yield transfers from the mining program to the staking program at approximately 01:52 UTC, roughly four minutes after detection. By that point, the attacker had earned approximately 25.5 ORE (~$2,125) in unearned yield. The attack was flagged early by community members @bootapollo and @blacklung0x of godl protocol. Because the affected stake program (STkEAu2cEyQp5ktgUauRVq8es6mEP2w6ixw4NEd5tDJ) and its associated liquid-staking wrapper (stORE) are frozen with no upgrade authority, the bug could not be patched in place. ORE published a full post-mortem ('Security Update') on June 17, 2026, and provided a one-click migration path to new contracts via ore.com/stake. PrivacyCash, which maintains the largest stORE shield pool, agreed to waive its 0.35% withdrawal fee for one week to facilitate migration. Yield distribution resumed approximately 24-48 hours after the post-mortem's publication. No deadline exists for migration.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)