Worked example · 2024-06
BtcTurk hot-wallet drain (first incident) — multi-chain — 2024-06-22
Summary
BtcTurk is one of Turkey's largest centralised cryptocurrency exchanges, founded in 2013 and headquartered in Istanbul. The exchange supports a broad asset list and operates within the Turkish regulatory regime (under the supervision of the Capital Markets Board / SPK following the 2024 Turkish crypto-asset legislation framework). At the time of the incident, BtcTurk reportedly held approximately $55M in operational hot wallets across ten supported chains.
On 2024-06-22, BtcTurk's operational hot wallets were drained in a sequence of large outflows totalling approximately $55M to attacker-controlled addresses across multiple chains. Per Halborn's post-incident write-up and the operator-side public statement, the attacker obtained sufficient private-key material to bypass the multisig-protection threshold on at least ten BtcTurk hot wallets — i.e., the compromise was at the key-storage-surface layer rather than at the per-signer credential layer.
Within hours of the on-chain manifestation, Binance's compliance team identified attacker-controlled inbound balances at Binance and froze approximately 10% of the cumulative stolen value, in coordination with BtcTurk's incident-response team and the broader industry forensic surface. The freeze was the operationally decisive recovery primitive on the cooperating-exchange-account surface. The remainder of the loss was absorbed by BtcTurk against operational reserves.
For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Indodax (2024-09), Phemex (2025-01). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the Binance-coordinated partial recovery, and the structural lesson on multisig-vs-key-storage-segregation are all on the public record. The attribution is recorded as pseudonymous-unattributed rather than collapsed into a presumed-OAK-G01 default — no industry-forensic provider has published cluster-overlap evidence tying BtcTurk June 2024 to the broader 2024 OAK-G01 cohort at v0.1's reporting horizon.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-event | Operator-internal compromise of BtcTurk hot-wallet key material; key-storage surface yielded sufficient private-key material to bypass multisig protection across at least ten hot wallets | (off-chain entry vector — no exact OAK v0.1 match) |
| 2024-06-22 | Near-simultaneous multi-chain extraction begins across at least ten BtcTurk hot wallets; cumulative outflow reaches ~$55M | T5-equivalent (extraction event) |
| 2024-06-22 | BtcTurk publicly acknowledges incident; suspends deposits, withdrawals, and trading services; confirms cold-wallet reserves unaffected; commits to user reimbursement | (operator response) |
| 2024-06-22 (within hours) | Binance compliance team identifies attacker-controlled inbound balances at Binance; freezes approximately 10% of cumulative stolen value in coordination with BtcTurk and industry-forensic surface | L1-equivalent recovery primitive (cooperating-exchange freeze) |
| 2024-06 onward | Halborn publishes post-incident technical write-up | (industry forensic record) |
| 2024-06 onward | Stage-1 laundering: proceeds routed through standard 2024 mixer rails on Ethereum and BTC sides | T7.001-equivalent (Mixer-Routed Hop) |
| 2024-Q3 | BtcTurk CEO departs the company in the post-incident leadership review window | (operator response — leadership change) |
| 2024-2025 | BtcTurk completes service restoration; operator-side custody-architecture review (review did not prevent recurrence in August 2025; see examples/2025-08-btcturk.md) |
(recovery state) |
What defenders observed
- Multisig protection is not a substitute for key-storage segregation. The BtcTurk June 2024 case is the canonical 2024 worked example for the proposition that a multisig threshold scheme protects against single-signer compromise but does not protect against a key-storage-surface compromise that yields multiple keys at once. The attacker did not need to compromise N independent signers in N independent compromises; one compromise of the key-storage surface yielded enough keys to bypass the threshold across at least ten hot wallets. Defender runbooks for multi-chain hot-wallet custody should treat per-chain (or per-chain-family) key-storage segregation as a primary control composing with the multisig threshold scheme.
- Cooperating-exchange-account freezes are the load-bearing post-incident recovery primitive on the off-chain side. Binance's compliance team froze approximately 10% of stolen funds within hours via cooperating-exchange-account-freeze authority. The primitive depends on (a) attacker conversion through CEX deposit addresses, (b) industry-forensic-surface coordination speed, and (c) the receiving CEX's compliance-team responsiveness. None of these conditions are unconditional, but when they hold, the primitive delivers the most operationally-decisive recovery surface available for non-stablecoin-denominated thefts. The 2024 BtcTurk recovery rate (~10%) is consistent with the upper-bound of what cooperating-exchange-freeze authority typically delivers when invoked promptly.
- Two consecutive incidents on the same operator within fourteen months is itself a defender-discipline signal. BtcTurk suffered the June 2024 incident and recurred in August 2025 with a broadly similar attack shape (operator-internal multi-chain hot-wallet compromise, cumulative loss ~$48M). The recurrence pattern within fourteen months is structurally distinct from the single-event pattern of most operator-side custody compromises in the OAK corpus. Defender / risk-team practice during the 12–18 months following any operator-internal hot-wallet incident should treat per-chain key-storage segregation, custody-architecture review depth, and personnel-rotation hygiene as continuing rather than one-shot operational requirements.
- Operator-side initial framing as "technical issue" should not be taken at face value. As with FixedFloat and other 2024 operator-side initial-response patterns, BtcTurk's initial communications characterised the incident in cautious and technically-minimal language. The defender / risk-team lesson is that operator-side public framing in the first 24–48 hours of a hot-wallet incident is unreliable as a primary signal; the on-chain pattern (large concurrent multi-chain outflows to non-operator-controlled addresses) is the load-bearing primary signal.
- Pseudonymous-unattributed framing is the right default in the absence of cluster-overlap evidence. The BtcTurk June 2024 case has no published cluster-overlap evidence tying it to the broader 2024 OAK-G01 cohort. Industry-forensic providers did not publish
inferred-strong-grade attribution. OAK records the attribution aspseudonymous-unattributedrather than presuming OAK-G01 by default. Contributors writing future cases should preserve this discipline — DPRK-suspicion is not the same as cluster-overlap evidence.
What this example tells contributors writing future Technique pages
- The operator-internal hot-wallet key compromise gap continues to be the most-exploited OAK v0.1 taxonomy gap. BtcTurk June 2024 is the sixth canonical worked example of this gap (after KuCoin, Coincheck, Stake.com, Phemex, Indodax). A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise, with sub-sub-Techniques for (a) social-engineered employee access, (b) internal-IT compromise via malware, (c) insider misuse, (d) multi-chain key-store co-location amplification (Phemex, Indodax, BtcTurk), and (e) repeated-incidents-on-same-operator (BtcTurk 2024–2025 pair).
pseudonymous-unattributedis the right marker for BtcTurk June 2024, notinferred-strong. No industry-forensic provider has published cluster-overlap evidence tying BtcTurk June 2024 to OAK-G01 or any other Group-level cluster. Contributors writing the worked-example layer should reserveinferred-strongfor cases where multi-firm concurrence plus cluster-graph evidence to confirmed wallets exists, and usepseudonymous-unattributedas the default in the absence of such evidence.- Cooperating-exchange-account-freeze is a real but conditional recovery primitive deserving of explicit Mitigation-page treatment. Binance's ~10% recovery on BtcTurk June 2024 is the strongest 2024 evidence that cooperating-exchange-account-freeze authority delivers operationally-decisive recovery surface for non-stablecoin thefts. Contributors writing the OAK Mitigations layer should preserve this primitive explicitly: it is conditional on attacker conversion through CEX deposits, industry-forensic coordination speed, and receiving-CEX compliance-team responsiveness, but when the conditions hold, the primitive recovers a substantial fraction.
- Repeated-incidents-on-same-operator is itself a structural pattern deserving its own analytical treatment. BtcTurk is the strongest 2024–2025 case of this pattern in the corpus; the June 2024 → August 2025 pair sits within a fourteen-month window with similar attack shapes. Contributors writing the operator-cohort-attribution and Mitigations layers should treat repeated-incidents as a discrete defender-discipline dimension distinct from single-event-recovery analysis.
Public references
- Halborn — Explained: The BtcTurk Hack (June 2024) — primary post-incident technical analysis covering the multi-chain drain pattern and the multisig-bypass mechanism.
- Rekt News — BTCTurk — industry-coverage retrospective on the BtcTurk June 2024 incident.
- CCN — Top 5 Crypto Hacks That Shook the Industry in 2024 — industry-press round-up including BtcTurk in the 2024 top-5 cohort.
- Erdal Ozkaya — BtcTurk Hack: A Deep Dive into the Incident, Lessons Learned — independent technical write-up.
Discussion
BtcTurk June 2024 is OAK's canonical 2024 Q2 worked example of operator-internal hot-wallet key compromise with multi-chain multisig-bypass and one of the few 2024–2025 hot-wallet-drain cases to record meaningful cooperating-exchange-account-freeze recovery. The cooperating-exchange-account-freeze primitive — Binance's ~10% recovery within hours of the on-chain manifestation — is the operationally-decisive recovery surface; without it, the realised loss would have approached the full ~$55M figure rather than the ~$49.5M post-freeze figure.
The multisig-vs-key-storage-segregation distinction is the BtcTurk-specific analytical contribution. The 2024–2025 corpus has multiple cases at the operator-internal-key-compromise surface (KuCoin, Coincheck, Stake.com, Phemex, Indodax, BingX); BtcTurk is the case that anchors the proposition that a multisig threshold scheme is not a substitute for key-storage segregation. Defender runbooks for multi-chain hot-wallet custody should treat per-chain (or per-chain-family) key-storage segregation as a primary control composing with the multisig threshold scheme — not as redundant with it.
The repeated-incidents-on-same-operator pattern is the second BtcTurk-specific contribution, fully visible only with the August 2025 recurrence. The fourteen-month interval between the June 2024 incident and the August 2025 recurrence — both with broadly similar operator-internal-multi-chain-hot-wallet-compromise shapes — is structurally distinct from the single-event pattern of most operator-side custody compromises in the OAK corpus. Defenders running operator-cohort-attribution should treat the BtcTurk pair as evidence that custody-architecture-review-after-an-incident is not by itself sufficient to prevent a recurrence on the same operator within an 18-month window; the architectural change must be substantive and verified, not procedural.
The pseudonymous-unattributed attribution framing is the third BtcTurk-specific contribution. The 2024–2025 OAK-G01 wave is heavily attributed via cluster-overlap evidence to confirmed-grade cases (DMM, WazirX, Bybit). BtcTurk June 2024 has no such evidence on the public record at v0.1's reporting horizon. The case anchors the proposition that DPRK-suspicion is not the same as cluster-overlap evidence and that pseudonymous-unattributed is the right default in the absence of forensic concurrence — even where the on-chain pattern is broadly consistent with OAK-G01 TTPs.
For OAK's broader credibility, including BtcTurk June 2024 in v0.1 closes two structural gaps: it adds the multisig-vs-key-storage-segregation analytical surface to the operator-internal-key-compromise sub-class, and it documents the cooperating-exchange-account-freeze recovery primitive at meaningful scale — the strongest 2024 evidence that the primitive can be invoked promptly enough to recover a non-trivial fraction of an exchange-scale theft.