OAK — OnChain Attack Knowledge

Worked example · 2023-09

CoinEx exchange hot-wallet compromise — Multi-chain (ETH, TRON, Polygon) — 2023-09-12

Loss
approximately $54-70M across multiple chains (Ethereum, TRON, Polygon, and others). The attacker executed a coordinated multi-chain extraction from CoinEx's hot wallets, draining assets simultaneously across the Ethereum, TRON, and Polygon networks.
OAK Techniques observed
OAK-T11.001 (Third-Party Signing-Vendor UI / Signing-Flow Compromise — broadly construed; the exchange's hot-wallet signing infrastructure was compromised across multiple chains simultaneously, enabling the coordinated multi-chain drain). OAK-T7.001 (Mixer-Routed Laundering — the extracted assets were rapidly routed through mixing and cross-chain laundering infrastructure characteristic of DPRK OAK-G01 tradecraft).
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed.
Attribution
inferred-strong The FBI and CISA issued a joint cybersecurity advisory attributing the CoinEx breach to the DPRK's Lazarus Group (OAK-G01), citing wallet-cluster analysis, laundering-route tracing, and cross-incident attribution continuity with the broader TraderTraitor campaign.
Key teaching point
The CoinEx September 2023 hack is the canonical multi-chain simultaneous-extraction DPRK case: the attacker drained ETH, TRON, and Polygon hot wallets in a coordinated operation, demonstrating OAK-G01's operational capability to compromise and drain exchange signing infrastructure across independent blockchain networks in a single operation. The multi-chain extraction pattern — Ethereum + TRON + Polygon simultaneously — is the structural signature that distinguishes the post-2022 OAK-G01 exchange-targeting playbook from the single-chain extraction pattern of the 2017-2019 wave.

Summary

CoinEx, a Hong Kong-based cryptocurrency exchange founded in 2017, suffered a coordinated hot-wallet compromise on 2023-09-12. The attacker gained access to CoinEx's hot-wallet signing infrastructure and executed a synchronised multi-chain extraction, draining assets from hot wallets on Ethereum, TRON, Polygon, and several other chains simultaneously.

The total loss was estimated at approximately $54-70M, with estimates varying based on asset-valuation timing and the inclusion of lesser-liquidity tokens. The multi-chain extraction pattern — in which the attacker demonstrated pre-positioned access to signing infrastructure across independent blockchain networks — is the structural signature of the matured post-2022 OAK-G01 exchange-targeting playbook, reflecting multi-year operational learning from the single-chain Yapizon (2017), Bithumb (2018), and Upbit (2019) breaches.

CoinEx suspended deposits and withdrawals, transferred remaining assets to cold storage, and committed to a user-reimbursement programme. The exchange published a post-mortem and engaged with blockchain analytics firms and law enforcement. The FBI and CISA subsequently issued a joint advisory formally attributing the breach to DPRK's Lazarus Group.

Timeline (UTC)

When Event OAK ref
2023-09-12 Attacker executes coordinated multi-chain extraction from CoinEx hot wallets on Ethereum, TRON, Polygon, and other chains simultaneously (~$54-70M) T11.001 (multi-chain signing-infrastructure compromise)
2023-09-12 T+hours CoinEx suspends deposits/withdrawals; transfers remaining assets to cold storage; discloses breach (defender response)
2023-09 to 2023-12 Extracted assets routed through mixing and cross-chain laundering infrastructure; FBI/CISA joint advisory attributes breach to OAK-G01 T7.001 (OAK-G01 characteristic laundering tradecraft)
2023-09 to 2024 CoinEx implements user-reimbursement programme; security architecture overhaul (remediation)

Realised extraction

Approximately $54-70M across multiple chains; attributed to OAK-G01. Partial recovery status not confirmed at v0.1. CoinEx committed to user reimbursement.

Multi-chain extraction as structural signature

The simultaneous-extraction pattern across Ethereum, TRON, and Polygon is the operational fingerprint that distinguishes the post-2022 OAK-G01 exchange-targeting tradecraft from the 2017-2019 wave:

  • 2017-2019 wave (Yapizon, Bithumb, Upbit): single-chain or single-network extraction (Bitcoin-dominant in 2017; Ethereum-dominant by 2019). Exchange signing infrastructure was chain-isolated; the attacker had to compromise per-chain signing surfaces.
  • 2022+ wave (CoinEx, Stake.com, BingX): multi-chain simultaneous extraction. OAK-G01 operators had matured to pre-position access across all chains an exchange supports, executing extraction in a single coordinated time window to maximise yield before the exchange's incident response could isolate per-chain signing surfaces.

The CoinEx case is the reference for the multi-chain extraction sub-pattern within T11.001.

Public references

  • CoinEx official breach disclosure and post-mortem, September 2023
  • FBI / CISA joint cybersecurity advisory on DPRK TraderTraitor campaign, 2023-2024
  • Chainalysis, Elliptic, and TRM wallet-cluster attribution reports on CoinEx and broader OAK-G01 campaign
  • SlowMist, PeckShield, and BlockSec forensic analyses, September 2023

Techniques demonstrated (2)