OAK — OnChain Attack Knowledge

Worked example · 2024-09

BingX hot-wallet drain — multi-chain — 2024-09-20

Loss
approximately $44–52M extracted from BingX hot wallets across multiple chains (Ethereum, Avalanche, BNB Chain, Optimism, Polygon, Base, Arbitrum) in a near-simultaneous drain window beginning ~04:00 Singapore time (~20:00 UTC 2024-09-19). Initial PeckShield count placed losses at ~$26M; Cyvers and follow-on tracking by SlowMist and Halborn revised to ~$43–52M as additional small-balance drains landed across lower-priority chains within the same window. BingX is a Singapore-headquartered cryptocurrency exchange.
Recovery
none publicly disclosed at the on-chain layer; BingX absorbed the loss against operational reserves, paused affected hot-wallet operations, and offered the attacker a 10% bug-bounty for return of funds (no public acceptance). Subsequently launched a $150M "Shield Fund" for user-protection coverage. No public DOJ civil-forfeiture action has been filed as of the date of this example.
OAK Techniques observed
no exact OAK v0.1 entry-vector match — the entry vector was operator-internal hot-wallet private-key compromise across a multi-chain key-storage surface, structurally identical to Indodax (2024-09) and Phemex (2025-01). Closest sibling Technique class is the broader OAK-T11 custody-and-signing family, broadly construed. Downstream Techniques observed on-chain: OAK-T7.001 (Mixer-Routed Hop) and OAK-T8.001 (Common-Funder Cluster Reuse — the BingX attacker cluster was subsequently linked by ZachXBT to Phemex (2025-01) and Bybit (2025-02) attacker infrastructure).
Attribution
inferred-strong — no FBI press release, U.S. Treasury OFAC designation, or Singaporean law-enforcement public statement explicitly naming BingX has been published as of the date of this example. Initial attribution carried by Cyvers (Senior Security Operations Lead noted attacker rapid asset-swapping moves consistent with DPRK-attributed actor TTPs); attribution strengthened materially in February 2025 when ZachXBT, in the days following the Bybit hack, demonstrated that the BingX September 2024 attacker addresses sat in the same wallet cluster as the Phemex (January 2025) and Bybit (February 2025) attacker addresses — the latter of which carries explicit FBI / IC3 OAK-G01 attribution. By OAK convention this clears the inferred-strong bar: cluster-overlap-via-confirmed-case is the strongest grade of inferred-strong attribution available.
OAK-Gnn
OAK-G01 Lazarus Group / TraderTraitor / DPRK-attributed — inferred-strong via cluster-overlap with confirmed-grade Bybit case, per ZachXBT February 2025 cluster reconstruction.
Key teaching point
BingX is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a Singapore-headquartered exchange and the second confirmed September-2024 datapoint in the operator-internal sub-class alongside Indodax. Together with the broader 2024–2025 OAK-G01 wave (DMM May 2024 → WazirX July 2024 → Indodax September 2024 → BingX September 2024 → Radiant October 2024 → Phemex January 2025 → Bybit February 2025), the BingX case is structural rather than headline — it is the case that, in conjunction with Phemex, demonstrates the BingX–Phemex–Bybit cluster-overlap continuity that ZachXBT reconstructed in February 2025 and that establishes the late-2024 / early-2025 OAK-G01 wave as a single sustained campaign with shared address infrastructure.

Summary

BingX is a Singapore-headquartered centralised cryptocurrency exchange operating across spot, futures, and copy-trading product lines. On 2024-09-20 at approximately 04:00 Singapore time (~20:00 UTC the prior day), Cyvers's real-time monitoring infrastructure flagged unusual outbound activity from BingX hot wallets across multiple EVM-compatible chains. PeckShield surfaced a complementary observation within hours. The attack proceeded in two phases over a multi-hour window — a pattern consistent with sustained attacker access rather than a single one-shot exploit — using at least ten different exploit-recipient addresses to fan out the proceeds across the EVM-chain surface.

The proximate cause — per Cyvers, PeckShield, SlowMist, and Halborn's post-incident analyses — was operator-internal compromise of BingX's hot-wallet private-key material. The simultaneity of multi-chain outflows, the multi-phase pattern, and the multiple-recipient-address fan-out are jointly consistent with a single compromise of a shared signing pipeline that yielded authority across the affected chains. BingX Chief Product Officer Vivien Lin publicly acknowledged the incident the same day, confirmed cold-wallet reserves were unaffected, and committed to user reimbursement.

For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Stake.com (2023), Indodax (2024-09), and Phemex (2025-01). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the laundering chain, and the cluster-level OAK-G01 attribution are all on the public record.

The OAK-G01 attribution rests primarily on the February 2025 ZachXBT cluster reconstruction. In the days following the 2025-02-21 Bybit hack, ZachXBT demonstrated that the BingX September 2024 attacker addresses, the Phemex January 2025 attacker addresses, and the Bybit February 2025 attacker addresses shared address-cluster infrastructure — including consolidation wallets reused across all three campaigns. The Bybit case carries explicit FBI / IC3 OAK-G01 attribution published within five days of that event; the BingX case inherits inferred-strong attribution by cluster overlap.

Timeline (UTC)

When Event OAK ref
Pre-event Operator-internal compromise of BingX hot-wallet key material; key-storage co-location across chains inferred from the simultaneity of outflows (off-chain entry vector — no exact OAK v0.1 match)
2024-09-19 ~20:00 (04:00 SGT 2024-09-20) Cyvers real-time monitoring surfaces unusual outbound activity in BingX hot wallets across multiple EVM chains; PeckShield complementary observation within hours (external detection — Cyvers / PeckShield)
2024-09-19 hours 0–6 First-phase multi-chain extraction across Ethereum, Avalanche, BNB, Optimism, Polygon, Base, Arbitrum; cumulative outflow at ~$26M on initial PeckShield count T5-equivalent (extraction event, phase 1)
2024-09-20 hours 6–18 Second-phase extraction continues; revised cumulative figure ~$43–52M as additional drains land on lower-priority chains; at least ten recipient addresses observed T5-equivalent (extraction event, phase 2)
2024-09-20 BingX Chief Product Officer Vivien Lin publicly acknowledges incident; confirms cold wallets unaffected; commits to user reimbursement (operator response)
2024-09-20 onward BingX team sends on-chain message to attacker offering 10% bug-bounty for return of funds; no public acceptance (operator response — bounty offer)
2024-09 onward Stage-1 laundering: rapid asset-swapping across DEX venues (TTPs Cyvers flagged as DPRK-consistent) T7.001-equivalent
2024-09 onward Cyvers, SlowMist, Halborn publish post-incident analyses; initial Lazarus-suspicion published by Cyvers (industry forensic record)
2024-09 onward BingX launches $150M "Shield Fund" user-protection programme (operator response — recovery posture)
2025-02-22 ZachXBT publishes cluster reconstruction in days following Bybit hack: BingX (2024-09), Phemex (2025-01), Bybit (2025-02) attacker addresses share infrastructure G01 attribution (inferred-strong) via cluster overlap with confirmed-grade Bybit
2025-02 onward Halborn, Quill Audits, broader industry forensic-research community publish retrospective write-ups consolidating the Lazarus attribution to BingX (industry forensic concurrence)

What defenders observed

  • Multi-chain key-store co-location is the recurring 2024–2025 OAK-G01 target shape on exchange custody. The BingX outflows landed on at least seven EVM-compatible chains within a single drain window. Together with the Indodax–Phemex pair, the BingX case is the third confirmed 2024–2025 OAK-G01 incident where the operator's hot-wallet signing pipeline read key material from a shared storage surface, and where one compromise of that surface yielded signing authority across all chains. Defender runbooks for multi-chain custody operators should treat key-store segregation per chain (or per chain-family) as a primary control.
  • Cyvers's real-time monitoring infrastructure is the load-bearing pre-disclosure detection surface for 2024–2025 exchange custody incidents. The BingX, Indodax, and (later) BtcTurk drains were each first surfaced publicly by Cyvers's mempool-and-explorer monitoring before operator-side acknowledgement. Defender risk teams treating operator-side incident announcements as the primary signal underweight the lead-time available from third-party monitoring; for hot-wallet-drain-shape incidents, third-party detection lead-time is consistently 30 minutes to several hours.
  • The 10% on-chain bounty primitive has not produced returns at this incident scale. BingX's offer is part of a 2024–2025 cohort of on-chain bounty offers (Phemex, BtcTurk, Garden Finance) that have not, in the OAK-G01-attributed cases, produced attacker-side acceptance. The primitive is operationally cheap and worth offering; defenders should not model it as a recovery surface in their threat models for OAK-G01-attributed incidents.
  • Cluster-overlap attribution can lag the incident by months. The BingX September 2024 incident was carried at inferred-weak confidence on Cyvers's TTP-pattern attribution alone for approximately five months before ZachXBT's February 2025 cluster reconstruction promoted the attribution to inferred-strong. Defenders should expect this lag pattern on the OAK-G01 cohort: per-incident TTP-pattern attribution is suggestive but not definitive; cluster-overlap attribution to a confirmed case is the load-bearing evidentiary surface.
  • Two-phase extraction is a forensic signal of sustained attacker access. The BingX drain proceeded in two phases hours apart. This pattern, distinct from a one-shot signing-key compromise, suggests the attacker maintained operational access after the initial extraction — likely because the compromised key-storage surface was not rotated mid-incident. Defender incident-response runbooks should treat hot-wallet-key rotation within minutes of detected compromise as a first-order priority; the BingX two-phase pattern is the strongest 2024 evidence that delayed rotation extends attacker access.

What this example tells contributors writing future Technique pages

  • BingX is the fourth 2024 OAK-G01 worked example and the third on the operator-internal-key-compromise sub-class. The 2024 OAK-G01 wave runs DMM Bitcoin (May, T11.001 vendor-compromise) → WazirX (July, T11.001 + T11.003) → Indodax (September, operator-internal) → BingX (September, operator-internal) → Radiant (October, DeFi protocol). The temporal density of September 2024 — two operator-internal-compromise exchange events within two weeks — is analytically important and reinforces that operator-internal compromise was running as a sustained productive workstream alongside the third-party-vendor workstream throughout 2024.
  • inferred-strong is the right marker for BingX, with the load-bearing evidence being the February 2025 cluster reconstruction. Cluster-overlap-via-confirmed-case is the strongest grade of inferred-strong available — a downstream contributor should upgrade BingX to confirmed if and only if a U.S. or Singaporean government public statement explicitly names BingX. Per OAK convention the absence of an FBI release is not evidence against attribution.
  • The Cyvers TTP-pattern initial attribution is a separate evidentiary surface from the cluster-overlap attribution. The BingX case had two attribution waves: a same-day TTP-pattern attribution by Cyvers (asset-swapping moves consistent with DPRK actors) and a five-months-later cluster-overlap attribution by ZachXBT. The two waves should be treated as complementary not redundant — TTP-pattern attribution is suggestive of cohort membership; cluster-overlap attribution to a confirmed case is the evidentiary load-bearing surface. Contributors writing future OAK-G01 examples should record both waves explicitly when they exist.
  • The BingX–Phemex–Bybit triple cluster overlap is a structural feature of the late-2024 / early-2025 OAK-G01 wave. Three Singapore-or-Singapore-adjacent exchanges, three operator-side custody compromises, three attacker-cluster-shared-infrastructure cases within five months. Contributors writing the OAK-G01 actor page and any cohort-level Discussion should treat this triple as a single sustained sub-campaign within the broader 2024–2025 wave.

Public references

Discussion

BingX is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a Singapore-headquartered exchange and the second confirmed September-2024 datapoint in the operator-internal sub-class alongside Indodax. Together with the broader 2024–2025 OAK-G01 wave (DMM May 2024 → WazirX July 2024 → Indodax September 2024 → BingX September 2024 → Radiant October 2024 → Phemex January 2025 → Bybit February 2025), the BingX case is structural rather than headline — it is the case that, in conjunction with Phemex, demonstrates the BingX–Phemex–Bybit cluster-overlap continuity that ZachXBT reconstructed in February 2025 and that establishes the late-2024 / early-2025 OAK-G01 wave as a single sustained campaign with shared address infrastructure.

The two-phase extraction pattern is the BingX-specific analytical contribution. The 2024 OAK-G01 cohort otherwise documents predominantly one-shot signing-key compromises (DMM, WazirX) or near-simultaneous multi-chain drains compressed into a single window (Indodax, Phemex). The BingX two-phase pattern — extraction phase 1, multi-hour gap, extraction phase 2 — suggests sustained attacker access rather than a one-shot extraction, with the most likely operational explanation being that the compromised key-storage surface was not rotated between phases. Defender incident-response runbooks for hot-wallet-drain-shape incidents should treat hot-wallet-key rotation within minutes of detected compromise as a first-order priority; the BingX two-phase pattern is the strongest 2024 evidence on this dimension.

The inferred-strong attribution rests on two evidentiary surfaces: the same-day Cyvers TTP-pattern attribution (asset-swapping moves consistent with DPRK actors) and the February 2025 ZachXBT cluster-overlap attribution to the confirmed-grade Bybit case. The five-month lag between the incident and the cluster-overlap attribution reinforces a recurring 2024–2025 pattern: per-incident TTP-pattern attribution is suggestive of cohort membership; cluster-overlap attribution to a confirmed case is the evidentiary load-bearing surface; the FBI / Treasury publication surface fires selectively and absence of a release does not downgrade industry-forensic attribution.

For OAK's broader credibility, including BingX in the corpus closes a structural gap between Indodax (operator-internal, regulator-supervised regional-exchange surface) and Phemex (operator-internal, multi-chain key-store co-location amplification) in the 2024–2025 OAK-G01 wave. Without BingX, the September 2024 → January 2025 interval reads as discontinuous; with BingX, the wave is legible as a single sustained campaign with continuous productive output across both the operator-internal and third-party-vendor entry-vector workstreams.

Techniques demonstrated (3)