The project said user deposits remain safe, but stakers must migrate to a new smart contract before rewards resume after the exploit.
ORE said its staking program was affected by a smart contract bug (self-executing blockchain code) that allowed an attacker to improperly claim 25.5 Solana in yield, valued at $2,125 in the post. The project said user deposits were not affected. Stakers will need to migrate to a new contract before yield payments resume, indicating the protocol is replacing the compromised rewards mechanism while keeping deposited funds intact.