Active exploit on Arbitrum Orbit chain 788988 draining bridge deposits via compromised validator whitelist; attacker can withdraw escrow after L1 block 26005988.
Security & Exploits ·
An active exploit is draining user deposits from a bridge on Arbitrum Orbit chain 788988, with an attacker having already manipulated the validator whitelist to enable a withdrawal. The compromised bridge at 0xC82dd3713f5eB5053D5A1a47f456435054ec77Dc holds 3.4018 ETH in user funds. An attacker at address 0x4428BE9125AE4e476514776a72ceDF2d5ce269C2 has executed transactions to disable the validator-AFK whitelist and stake a forged node, positioning themselves to confirm and withdraw the escrow after L1 block 26005988, expected around September 18, 2026.
The exploit leverages compromised validator permissions within the AnyTrust consensus mechanism. The attacker opened the validator whitelist, allowing injection of a malicious node into the network. Once the specified L1 block is reached, the attacker can finalize the fraudulent node and drain the escrow containing deposited assets. The same vulnerability reportedly affects two other Orbit chains—7889 and 78898—exposing additional systems to identical attack vectors.
A proposed mitigation exists but requires immediate action through the Safe multisig at 0x1AA00161Fe7381af1Fc4C45cB8895E3901b844Bd, which would need to execute a call to the rollup contract to disable the validator whitelist. It remains unclear whether the bridge operators have implemented this fix or what steps have been taken to pause deposits or secure the remaining escrow balance.