OAK — OnChain Attack Knowledge

Worked example · 2024-06

BtcTurk hot-wallet drain (first incident) — multi-chain — 2024-06-22

Loss
approximately $55M extracted from BtcTurk hot wallets across approximately ten chains in a near-simultaneous drain window on 2024-06-22. BtcTurk is a Turkish cryptocurrency exchange, one of the country's largest by user-count and trading volume, headquartered in Istanbul.
Recovery
approximately 10% of stolen funds frozen by Binance compliance team within hours of the on-chain manifestation; the freeze was the operationally decisive recovery primitive on the cooperating-exchange-account surface. The remainder of the loss was absorbed by BtcTurk against operational reserves; no public DOJ civil-forfeiture action has been filed as of the date of this example. The CEO subsequently departed the company; the operator-side custody-architecture review that followed the incident did not prevent a recurrence in August 2025 (see examples/2025-08-btcturk.md).
OAK Techniques observed
no exact OAK v0.1 entry-vector match — the entry vector was operator-internal hot-wallet private-key compromise across a multi-chain key-storage surface, structurally identical to KuCoin (2020), Coincheck (2018), Indodax (2024-09), Phemex (2025-01). Closest sibling Technique class is the broader OAK-T11 custody-and-signing family. The compromise enabled the attacker to bypass the multisig-protection threshold on at least ten BtcTurk hot wallets — i.e., the multisig was structurally protective against single-signer compromise but not against a key-storage-surface compromise that yielded multiple signing keys at once. Downstream Techniques observed on-chain: OAK-T7.001 (Mixer-Routed Hop) and partial OAK-T8.001 (Common-Funder Cluster Reuse).
Attribution
pseudonymous at v0.1 reporting horizon. No operator-side admission of operator-internal compromise as a specific named vector (social-engineering, internal-IT, insider misuse); no Turkish law-enforcement public attribution; no industry-forensic provider has published inferred-strong-grade OAK-G01 cluster-overlap attribution for the June 2024 BtcTurk case as of the date of this example. The incident is documented in OAK with explicit pseudonymous-unattributed framing rather than collapsed into a presumed-OAK-G01 default.
Key teaching point
multisig protection is not a substitute for key-storage segregation. The BtcTurk June 2024 case is the canonical 2024 worked example for the proposition that a multisig threshold scheme protects against single-signer compromise but does not protect against a key-storage-surface compromise that yields multiple keys at once. Defenders running multi-chain hot-wallet custody should treat per-chain (or per-chain-family) key-storage segregation as a primary control composing with the multisig threshold scheme — not as redundant with it.

Summary

BtcTurk is one of Turkey's largest centralised cryptocurrency exchanges, founded in 2013 and headquartered in Istanbul. The exchange supports a broad asset list and operates within the Turkish regulatory regime (under the supervision of the Capital Markets Board / SPK following the 2024 Turkish crypto-asset legislation framework). At the time of the incident, BtcTurk reportedly held approximately $55M in operational hot wallets across ten supported chains.

On 2024-06-22, BtcTurk's operational hot wallets were drained in a sequence of large outflows totalling approximately $55M to attacker-controlled addresses across multiple chains. Per Halborn's post-incident write-up and the operator-side public statement, the attacker obtained sufficient private-key material to bypass the multisig-protection threshold on at least ten BtcTurk hot wallets — i.e., the compromise was at the key-storage-surface layer rather than at the per-signer credential layer.

Within hours of the on-chain manifestation, Binance's compliance team identified attacker-controlled inbound balances at Binance and froze approximately 10% of the cumulative stolen value, in coordination with BtcTurk's incident-response team and the broader industry forensic surface. The freeze was the operationally decisive recovery primitive on the cooperating-exchange-account surface. The remainder of the loss was absorbed by BtcTurk against operational reserves.

For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Indodax (2024-09), Phemex (2025-01). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the Binance-coordinated partial recovery, and the structural lesson on multisig-vs-key-storage-segregation are all on the public record. The attribution is recorded as pseudonymous-unattributed rather than collapsed into a presumed-OAK-G01 default — no industry-forensic provider has published cluster-overlap evidence tying BtcTurk June 2024 to the broader 2024 OAK-G01 cohort at v0.1's reporting horizon.

Timeline (UTC)

When Event OAK ref
Pre-event Operator-internal compromise of BtcTurk hot-wallet key material; key-storage surface yielded sufficient private-key material to bypass multisig protection across at least ten hot wallets (off-chain entry vector — no exact OAK v0.1 match)
2024-06-22 Near-simultaneous multi-chain extraction begins across at least ten BtcTurk hot wallets; cumulative outflow reaches ~$55M T5-equivalent (extraction event)
2024-06-22 BtcTurk publicly acknowledges incident; suspends deposits, withdrawals, and trading services; confirms cold-wallet reserves unaffected; commits to user reimbursement (operator response)
2024-06-22 (within hours) Binance compliance team identifies attacker-controlled inbound balances at Binance; freezes approximately 10% of cumulative stolen value in coordination with BtcTurk and industry-forensic surface L1-equivalent recovery primitive (cooperating-exchange freeze)
2024-06 onward Halborn publishes post-incident technical write-up (industry forensic record)
2024-06 onward Stage-1 laundering: proceeds routed through standard 2024 mixer rails on Ethereum and BTC sides T7.001-equivalent (Mixer-Routed Hop)
2024-Q3 BtcTurk CEO departs the company in the post-incident leadership review window (operator response — leadership change)
2024-2025 BtcTurk completes service restoration; operator-side custody-architecture review (review did not prevent recurrence in August 2025; see examples/2025-08-btcturk.md) (recovery state)

What defenders observed

  • Multisig protection is not a substitute for key-storage segregation. The BtcTurk June 2024 case is the canonical 2024 worked example for the proposition that a multisig threshold scheme protects against single-signer compromise but does not protect against a key-storage-surface compromise that yields multiple keys at once. The attacker did not need to compromise N independent signers in N independent compromises; one compromise of the key-storage surface yielded enough keys to bypass the threshold across at least ten hot wallets. Defender runbooks for multi-chain hot-wallet custody should treat per-chain (or per-chain-family) key-storage segregation as a primary control composing with the multisig threshold scheme.
  • Cooperating-exchange-account freezes are the load-bearing post-incident recovery primitive on the off-chain side. Binance's compliance team froze approximately 10% of stolen funds within hours via cooperating-exchange-account-freeze authority. The primitive depends on (a) attacker conversion through CEX deposit addresses, (b) industry-forensic-surface coordination speed, and (c) the receiving CEX's compliance-team responsiveness. None of these conditions are unconditional, but when they hold, the primitive delivers the most operationally-decisive recovery surface available for non-stablecoin-denominated thefts. The 2024 BtcTurk recovery rate (~10%) is consistent with the upper-bound of what cooperating-exchange-freeze authority typically delivers when invoked promptly.
  • Two consecutive incidents on the same operator within fourteen months is itself a defender-discipline signal. BtcTurk suffered the June 2024 incident and recurred in August 2025 with a broadly similar attack shape (operator-internal multi-chain hot-wallet compromise, cumulative loss ~$48M). The recurrence pattern within fourteen months is structurally distinct from the single-event pattern of most operator-side custody compromises in the OAK corpus. Defender / risk-team practice during the 12–18 months following any operator-internal hot-wallet incident should treat per-chain key-storage segregation, custody-architecture review depth, and personnel-rotation hygiene as continuing rather than one-shot operational requirements.
  • Operator-side initial framing as "technical issue" should not be taken at face value. As with FixedFloat and other 2024 operator-side initial-response patterns, BtcTurk's initial communications characterised the incident in cautious and technically-minimal language. The defender / risk-team lesson is that operator-side public framing in the first 24–48 hours of a hot-wallet incident is unreliable as a primary signal; the on-chain pattern (large concurrent multi-chain outflows to non-operator-controlled addresses) is the load-bearing primary signal.
  • Pseudonymous-unattributed framing is the right default in the absence of cluster-overlap evidence. The BtcTurk June 2024 case has no published cluster-overlap evidence tying it to the broader 2024 OAK-G01 cohort. Industry-forensic providers did not publish inferred-strong-grade attribution. OAK records the attribution as pseudonymous-unattributed rather than presuming OAK-G01 by default. Contributors writing future cases should preserve this discipline — DPRK-suspicion is not the same as cluster-overlap evidence.

What this example tells contributors writing future Technique pages

  • The operator-internal hot-wallet key compromise gap continues to be the most-exploited OAK v0.1 taxonomy gap. BtcTurk June 2024 is the sixth canonical worked example of this gap (after KuCoin, Coincheck, Stake.com, Phemex, Indodax). A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise, with sub-sub-Techniques for (a) social-engineered employee access, (b) internal-IT compromise via malware, (c) insider misuse, (d) multi-chain key-store co-location amplification (Phemex, Indodax, BtcTurk), and (e) repeated-incidents-on-same-operator (BtcTurk 2024–2025 pair).
  • pseudonymous-unattributed is the right marker for BtcTurk June 2024, not inferred-strong. No industry-forensic provider has published cluster-overlap evidence tying BtcTurk June 2024 to OAK-G01 or any other Group-level cluster. Contributors writing the worked-example layer should reserve inferred-strong for cases where multi-firm concurrence plus cluster-graph evidence to confirmed wallets exists, and use pseudonymous-unattributed as the default in the absence of such evidence.
  • Cooperating-exchange-account-freeze is a real but conditional recovery primitive deserving of explicit Mitigation-page treatment. Binance's ~10% recovery on BtcTurk June 2024 is the strongest 2024 evidence that cooperating-exchange-account-freeze authority delivers operationally-decisive recovery surface for non-stablecoin thefts. Contributors writing the OAK Mitigations layer should preserve this primitive explicitly: it is conditional on attacker conversion through CEX deposits, industry-forensic coordination speed, and receiving-CEX compliance-team responsiveness, but when the conditions hold, the primitive recovers a substantial fraction.
  • Repeated-incidents-on-same-operator is itself a structural pattern deserving its own analytical treatment. BtcTurk is the strongest 2024–2025 case of this pattern in the corpus; the June 2024 → August 2025 pair sits within a fourteen-month window with similar attack shapes. Contributors writing the operator-cohort-attribution and Mitigations layers should treat repeated-incidents as a discrete defender-discipline dimension distinct from single-event-recovery analysis.

Public references

Discussion

BtcTurk June 2024 is OAK's canonical 2024 Q2 worked example of operator-internal hot-wallet key compromise with multi-chain multisig-bypass and one of the few 2024–2025 hot-wallet-drain cases to record meaningful cooperating-exchange-account-freeze recovery. The cooperating-exchange-account-freeze primitive — Binance's ~10% recovery within hours of the on-chain manifestation — is the operationally-decisive recovery surface; without it, the realised loss would have approached the full ~$55M figure rather than the ~$49.5M post-freeze figure.

The multisig-vs-key-storage-segregation distinction is the BtcTurk-specific analytical contribution. The 2024–2025 corpus has multiple cases at the operator-internal-key-compromise surface (KuCoin, Coincheck, Stake.com, Phemex, Indodax, BingX); BtcTurk is the case that anchors the proposition that a multisig threshold scheme is not a substitute for key-storage segregation. Defender runbooks for multi-chain hot-wallet custody should treat per-chain (or per-chain-family) key-storage segregation as a primary control composing with the multisig threshold scheme — not as redundant with it.

The repeated-incidents-on-same-operator pattern is the second BtcTurk-specific contribution, fully visible only with the August 2025 recurrence. The fourteen-month interval between the June 2024 incident and the August 2025 recurrence — both with broadly similar operator-internal-multi-chain-hot-wallet-compromise shapes — is structurally distinct from the single-event pattern of most operator-side custody compromises in the OAK corpus. Defenders running operator-cohort-attribution should treat the BtcTurk pair as evidence that custody-architecture-review-after-an-incident is not by itself sufficient to prevent a recurrence on the same operator within an 18-month window; the architectural change must be substantive and verified, not procedural.

The pseudonymous-unattributed attribution framing is the third BtcTurk-specific contribution. The 2024–2025 OAK-G01 wave is heavily attributed via cluster-overlap evidence to confirmed-grade cases (DMM, WazirX, Bybit). BtcTurk June 2024 has no such evidence on the public record at v0.1's reporting horizon. The case anchors the proposition that DPRK-suspicion is not the same as cluster-overlap evidence and that pseudonymous-unattributed is the right default in the absence of forensic concurrence — even where the on-chain pattern is broadly consistent with OAK-G01 TTPs.

For OAK's broader credibility, including BtcTurk June 2024 in v0.1 closes two structural gaps: it adds the multisig-vs-key-storage-segregation analytical surface to the operator-internal-key-compromise sub-class, and it documents the cooperating-exchange-account-freeze recovery primitive at meaningful scale — the strongest 2024 evidence that the primitive can be invoked promptly enough to recover a non-trivial fraction of an exchange-scale theft.

Techniques demonstrated (3)