Worked example · 2024-09
BingX hot-wallet drain — multi-chain — 2024-09-20
Summary
BingX is a Singapore-headquartered centralised cryptocurrency exchange operating across spot, futures, and copy-trading product lines. On 2024-09-20 at approximately 04:00 Singapore time (~20:00 UTC the prior day), Cyvers's real-time monitoring infrastructure flagged unusual outbound activity from BingX hot wallets across multiple EVM-compatible chains. PeckShield surfaced a complementary observation within hours. The attack proceeded in two phases over a multi-hour window — a pattern consistent with sustained attacker access rather than a single one-shot exploit — using at least ten different exploit-recipient addresses to fan out the proceeds across the EVM-chain surface.
The proximate cause — per Cyvers, PeckShield, SlowMist, and Halborn's post-incident analyses — was operator-internal compromise of BingX's hot-wallet private-key material. The simultaneity of multi-chain outflows, the multi-phase pattern, and the multiple-recipient-address fan-out are jointly consistent with a single compromise of a shared signing pipeline that yielded authority across the affected chains. BingX Chief Product Officer Vivien Lin publicly acknowledged the incident the same day, confirmed cold-wallet reserves were unaffected, and committed to user reimbursement.
For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Stake.com (2023), Indodax (2024-09), and Phemex (2025-01). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the laundering chain, and the cluster-level OAK-G01 attribution are all on the public record.
The OAK-G01 attribution rests primarily on the February 2025 ZachXBT cluster reconstruction. In the days following the 2025-02-21 Bybit hack, ZachXBT demonstrated that the BingX September 2024 attacker addresses, the Phemex January 2025 attacker addresses, and the Bybit February 2025 attacker addresses shared address-cluster infrastructure — including consolidation wallets reused across all three campaigns. The Bybit case carries explicit FBI / IC3 OAK-G01 attribution published within five days of that event; the BingX case inherits inferred-strong attribution by cluster overlap.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-event | Operator-internal compromise of BingX hot-wallet key material; key-storage co-location across chains inferred from the simultaneity of outflows | (off-chain entry vector — no exact OAK v0.1 match) |
| 2024-09-19 ~20:00 (04:00 SGT 2024-09-20) | Cyvers real-time monitoring surfaces unusual outbound activity in BingX hot wallets across multiple EVM chains; PeckShield complementary observation within hours | (external detection — Cyvers / PeckShield) |
| 2024-09-19 hours 0–6 | First-phase multi-chain extraction across Ethereum, Avalanche, BNB, Optimism, Polygon, Base, Arbitrum; cumulative outflow at ~$26M on initial PeckShield count | T5-equivalent (extraction event, phase 1) |
| 2024-09-20 hours 6–18 | Second-phase extraction continues; revised cumulative figure ~$43–52M as additional drains land on lower-priority chains; at least ten recipient addresses observed | T5-equivalent (extraction event, phase 2) |
| 2024-09-20 | BingX Chief Product Officer Vivien Lin publicly acknowledges incident; confirms cold wallets unaffected; commits to user reimbursement | (operator response) |
| 2024-09-20 onward | BingX team sends on-chain message to attacker offering 10% bug-bounty for return of funds; no public acceptance | (operator response — bounty offer) |
| 2024-09 onward | Stage-1 laundering: rapid asset-swapping across DEX venues (TTPs Cyvers flagged as DPRK-consistent) | T7.001-equivalent |
| 2024-09 onward | Cyvers, SlowMist, Halborn publish post-incident analyses; initial Lazarus-suspicion published by Cyvers | (industry forensic record) |
| 2024-09 onward | BingX launches $150M "Shield Fund" user-protection programme | (operator response — recovery posture) |
| 2025-02-22 | ZachXBT publishes cluster reconstruction in days following Bybit hack: BingX (2024-09), Phemex (2025-01), Bybit (2025-02) attacker addresses share infrastructure | G01 attribution (inferred-strong) via cluster overlap with confirmed-grade Bybit |
| 2025-02 onward | Halborn, Quill Audits, broader industry forensic-research community publish retrospective write-ups consolidating the Lazarus attribution to BingX | (industry forensic concurrence) |
What defenders observed
- Multi-chain key-store co-location is the recurring 2024–2025 OAK-G01 target shape on exchange custody. The BingX outflows landed on at least seven EVM-compatible chains within a single drain window. Together with the Indodax–Phemex pair, the BingX case is the third confirmed 2024–2025 OAK-G01 incident where the operator's hot-wallet signing pipeline read key material from a shared storage surface, and where one compromise of that surface yielded signing authority across all chains. Defender runbooks for multi-chain custody operators should treat key-store segregation per chain (or per chain-family) as a primary control.
- Cyvers's real-time monitoring infrastructure is the load-bearing pre-disclosure detection surface for 2024–2025 exchange custody incidents. The BingX, Indodax, and (later) BtcTurk drains were each first surfaced publicly by Cyvers's mempool-and-explorer monitoring before operator-side acknowledgement. Defender risk teams treating operator-side incident announcements as the primary signal underweight the lead-time available from third-party monitoring; for hot-wallet-drain-shape incidents, third-party detection lead-time is consistently 30 minutes to several hours.
- The 10% on-chain bounty primitive has not produced returns at this incident scale. BingX's offer is part of a 2024–2025 cohort of on-chain bounty offers (Phemex, BtcTurk, Garden Finance) that have not, in the OAK-G01-attributed cases, produced attacker-side acceptance. The primitive is operationally cheap and worth offering; defenders should not model it as a recovery surface in their threat models for OAK-G01-attributed incidents.
- Cluster-overlap attribution can lag the incident by months. The BingX September 2024 incident was carried at
inferred-weakconfidence on Cyvers's TTP-pattern attribution alone for approximately five months before ZachXBT's February 2025 cluster reconstruction promoted the attribution toinferred-strong. Defenders should expect this lag pattern on the OAK-G01 cohort: per-incident TTP-pattern attribution is suggestive but not definitive; cluster-overlap attribution to a confirmed case is the load-bearing evidentiary surface. - Two-phase extraction is a forensic signal of sustained attacker access. The BingX drain proceeded in two phases hours apart. This pattern, distinct from a one-shot signing-key compromise, suggests the attacker maintained operational access after the initial extraction — likely because the compromised key-storage surface was not rotated mid-incident. Defender incident-response runbooks should treat hot-wallet-key rotation within minutes of detected compromise as a first-order priority; the BingX two-phase pattern is the strongest 2024 evidence that delayed rotation extends attacker access.
What this example tells contributors writing future Technique pages
- BingX is the fourth 2024 OAK-G01 worked example and the third on the operator-internal-key-compromise sub-class. The 2024 OAK-G01 wave runs DMM Bitcoin (May, T11.001 vendor-compromise) → WazirX (July, T11.001 + T11.003) → Indodax (September, operator-internal) → BingX (September, operator-internal) → Radiant (October, DeFi protocol). The temporal density of September 2024 — two operator-internal-compromise exchange events within two weeks — is analytically important and reinforces that operator-internal compromise was running as a sustained productive workstream alongside the third-party-vendor workstream throughout 2024.
inferred-strongis the right marker for BingX, with the load-bearing evidence being the February 2025 cluster reconstruction. Cluster-overlap-via-confirmed-case is the strongest grade ofinferred-strongavailable — a downstream contributor should upgrade BingX toconfirmedif and only if a U.S. or Singaporean government public statement explicitly names BingX. Per OAK convention the absence of an FBI release is not evidence against attribution.- The Cyvers TTP-pattern initial attribution is a separate evidentiary surface from the cluster-overlap attribution. The BingX case had two attribution waves: a same-day TTP-pattern attribution by Cyvers (asset-swapping moves consistent with DPRK actors) and a five-months-later cluster-overlap attribution by ZachXBT. The two waves should be treated as complementary not redundant — TTP-pattern attribution is suggestive of cohort membership; cluster-overlap attribution to a confirmed case is the evidentiary load-bearing surface. Contributors writing future OAK-G01 examples should record both waves explicitly when they exist.
- The BingX–Phemex–Bybit triple cluster overlap is a structural feature of the late-2024 / early-2025 OAK-G01 wave. Three Singapore-or-Singapore-adjacent exchanges, three operator-side custody compromises, three attacker-cluster-shared-infrastructure cases within five months. Contributors writing the OAK-G01 actor page and any cohort-level Discussion should treat this triple as a single sustained sub-campaign within the broader 2024–2025 wave.
Public references
- Cyvers — BingX Hack Detection — primary real-time monitoring detection source; senior-security-operations attribution to DPRK-consistent TTPs.
- Halborn — Explained: The BingX Hack (September 2024) — post-incident technical analysis covering the multi-chain drain pattern and the operator-internal key compromise root-cause hypothesis.
- CoinDesk — Crypto Exchange BingX Hacked, Onchain Data Shows Over $43M Drained — industry-press initial-disclosure coverage with PeckShield and Cyvers figures.
- Cybernews — Singaporean crypto exchange BingX offers 10% bounty after $44M hack — coverage of the on-chain bounty offer and operator response.
- Daily Hodl — BingX Suffers $52,000,000 Hack: Blockchain Security Firm — secondary press coverage with revised loss figure and Cyvers DPRK-suspicion quote.
- QuillAudits — Inside the $44.7M BingX Exploit: What Went Wrong? — independent post-incident technical write-up.
- CryptoSlate — North Korea-linked hack costs crypto exchange BingX $52 million — DPRK-attribution coverage.
Discussion
BingX is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a Singapore-headquartered exchange and the second confirmed September-2024 datapoint in the operator-internal sub-class alongside Indodax. Together with the broader 2024–2025 OAK-G01 wave (DMM May 2024 → WazirX July 2024 → Indodax September 2024 → BingX September 2024 → Radiant October 2024 → Phemex January 2025 → Bybit February 2025), the BingX case is structural rather than headline — it is the case that, in conjunction with Phemex, demonstrates the BingX–Phemex–Bybit cluster-overlap continuity that ZachXBT reconstructed in February 2025 and that establishes the late-2024 / early-2025 OAK-G01 wave as a single sustained campaign with shared address infrastructure.
The two-phase extraction pattern is the BingX-specific analytical contribution. The 2024 OAK-G01 cohort otherwise documents predominantly one-shot signing-key compromises (DMM, WazirX) or near-simultaneous multi-chain drains compressed into a single window (Indodax, Phemex). The BingX two-phase pattern — extraction phase 1, multi-hour gap, extraction phase 2 — suggests sustained attacker access rather than a one-shot extraction, with the most likely operational explanation being that the compromised key-storage surface was not rotated between phases. Defender incident-response runbooks for hot-wallet-drain-shape incidents should treat hot-wallet-key rotation within minutes of detected compromise as a first-order priority; the BingX two-phase pattern is the strongest 2024 evidence on this dimension.
The inferred-strong attribution rests on two evidentiary surfaces: the same-day Cyvers TTP-pattern attribution (asset-swapping moves consistent with DPRK actors) and the February 2025 ZachXBT cluster-overlap attribution to the confirmed-grade Bybit case. The five-month lag between the incident and the cluster-overlap attribution reinforces a recurring 2024–2025 pattern: per-incident TTP-pattern attribution is suggestive of cohort membership; cluster-overlap attribution to a confirmed case is the evidentiary load-bearing surface; the FBI / Treasury publication surface fires selectively and absence of a release does not downgrade industry-forensic attribution.
For OAK's broader credibility, including BingX in the corpus closes a structural gap between Indodax (operator-internal, regulator-supervised regional-exchange surface) and Phemex (operator-internal, multi-chain key-store co-location amplification) in the 2024–2025 OAK-G01 wave. Without BingX, the September 2024 → January 2025 interval reads as discontinuous; with BingX, the wave is legible as a single sustained campaign with continuous productive output across both the operator-internal and third-party-vendor entry-vector workstreams.