Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.
← back to incident ledger

phishing drainerDemo

Apr 12, 2025 · $180.8K · human op

Narrative

On 2025-04-12, Orca suffered a phishing drainer incident resulting in approximately $180,830 in losses. The exploit targeted the human_op layer. A flash loan was used to amplify the attack. Attribution: mev_searcher. This is a demonstration entry — not a real incident.

Victims

Classification

Root cause
phishing_drainer
Secondary causes
Attack layer
human_op
Strategy
human_exploit
Actor role
target
Attribution
mev_searcher
Attacker address
0x7407b382400c441c5d05e12498e59e733958084f
Flash loan
yes
Audited at time
no
Bounty at time
yes

AADAPT mappings

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0040DEMO:AADAPT.T1566.003

Evidence

Disclosure date
Apr 12, 2025
Funds recovered
$7.3K
Audit firms at time
Post-mortem URLs (synthetic)
  • https://medium.com/orca/post-mortem-orca-2025-04-12
  • https://rekt.news/orca-rekt
  • https://blog.orca.xyz/incident-report
tx hashes (4)
  • 0xd4cfa396b0184a313109a260cde32417b75068dbb2284cfc380f5aabab985bdc
  • 0x99ce5c8f9ba3608982470e7b78116a278d7a256a76d5798dc74b9cefff24575b
  • 0x32e381ee0eabe825d92ac5831898d9eb994a6dcb6cc5a05e22b734bb452b7035
  • 0xf6d12f0c61d976b5acb3ef23deb2921fc388d98bb8ff967336fda08cfc8e46d6