Worked example · 2024-09
Indodax hot-wallet drain — multi-chain — 2024-09-11
Summary
Indodax is Indonesia's largest centralised cryptocurrency exchange, founded in 2014 as Bitcoin Indonesia and rebranded to Indodax in 2018. The exchange supports a broad asset list (~200 listed assets) across Bitcoin, Ethereum, Tron, BNB Chain, Polygon, and additional chains; it serves several million Indonesian users and is regulated by Bappebti, Indonesia's commodity-futures trading authority.
On 2024-09-11 at approximately 02:18 UTC, Cyvers and PeckShield first surfaced unusual outbound activity on Indodax hot wallets across multiple chains. Within hours, attackers extracted approximately $22M in a near-simultaneous multi-chain drain. Indodax acknowledged the incident the same day, suspended deposits, withdrawals, and trading services while the team scoped the breach, and confirmed that cold-wallet reserves were unaffected.
The proximate cause — per SlowMist's and Cyvers's post-incident commentary — was compromise of Indodax's hot-wallet private keys, with a strong inference that key material for multiple chains was co-located in a single signing infrastructure. The simultaneity of the multi-chain outflows is the clearest signal: independent operator-side compromises of multiple separate signing pipelines is implausible on the observed timeline; a single operator-internal key-store compromise that fanned out across the chain surface is consistent with the on-chain pattern.
For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Stake.com (2023), and Phemex (2025). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the laundering chain, and the cluster-level OAK-G01 attribution are all on the public record.
The OAK-G01 / TraderTraitor attribution rests on (a) the laundering-chain shape — Tron-side proceeds bridged to Ethereum and routed through Tornado Cash via intermediary addresses with transaction-graph proximity to confirmed Lazarus-cluster wallets — and (b) the matching of the Indodax laundering pattern to the broader TraderTraitor campaign that Chainalysis and Match Systems were tracking at the time across the 2024 OAK-G01 wave (DMM Bitcoin, WazirX, with Radiant Capital and Phemex as later-quarter datapoints in the same cluster).
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-event | Operator-internal compromise of Indodax hot-wallet key material; key-storage co-location across chains inferred from the simultaneity of outflows | (off-chain entry vector — no exact OAK v0.1 match) |
| 2024-09-11 ~02:18 | Cyvers and PeckShield surface unusual outbound activity in Indodax hot wallets; first public flag of the incident | (external detection) |
| 2024-09-11 (hours 0–6) | Near-simultaneous multi-chain extraction across Ethereum, Tron, BNB Chain, Polygon, and additional supported chains; cumulative outflow reaches ~$18.2M on initial Cyvers count, revised to ~$22M as small-balance drains land on lower-priority chains | T5-equivalent (extraction event) |
| 2024-09-11 | Indodax acknowledges the incident publicly; suspends deposits, withdrawals, and trading; confirms cold wallets unaffected; commits to user reimbursement | (operator response) |
| 2024-09-12 | Indodax begins phased restoration of user services | (operator response) |
| 2024-09-11 onward | Attacker consolidates proceeds; Tron-side proceeds bridged to Ethereum; ETH and ERC-20 proceeds routed through Tornado Cash via multi-hop intermediary addresses | T7.003 (Cross-Chain Bridge Laundering) → T7.001 (Mixer-Routed Hop) |
| 2024-09 | Chainalysis, Match Systems, Elliptic, SlowMist forensic write-ups converge on TraderTraitor-shape laundering chain; cluster-proximity evidence to confirmed Lazarus wallets surfaces | G01 attribution (inferred-strong) |
| 2024-09 — Q4 | Indodax completes service restoration across all supported assets and chains | (operator response) |
What defenders observed
- Multi-chain key-store co-location is the recurring 2024–2025 OAK-G01 target shape on exchange custody. The Indodax outflows landed on multiple chains within a single drain window, in the same shape as Phemex four months later. The simplest hypothesis consistent with the on-chain evidence is that Indodax's hot-wallet signing pipeline read key material from a shared storage surface, and that one compromise of that surface yielded signing authority across all chains. Defender runbooks for multi-chain custody operators should treat key-store segregation per chain (or per chain-family) as a primary control, not an optional one. The Indodax–Phemex pair is the strongest 2024–2025 evidence on the exchange-custody side that the absence of this control turns one compromise into N.
- The TraderTraitor / OAK-G01 laundering signature is identifiable at the chain-graph level even without explicit FBI attribution. Chainalysis and Match Systems both surfaced the Indodax laundering chain as TraderTraitor-shape within days of the incident, on the basis of (a) the bridging-then-mixer pattern characteristic of the campaign and (b) cluster-proximity of intermediary addresses to confirmed Lazarus wallets in the broader 2023–2024 case set. Defender risk teams treating OAK-G01 as a per-incident cluster underweight this continuity; the 2024 OAK-G01 wave should be modelled as a single sustained campaign with shared laundering rails and shared address-cluster overlap.
- Operator-internal hot-wallet key compromise is a recurring 2024 OAK-G01 pattern, not an exception. Indodax sits in the same entry-vector class as KuCoin (2020), Coincheck (2018), Stake.com (2023), and the broader 2023 wave (Atomic Wallet, Alphapo / CoinsPaid, CoinEx). The 2024 supply-chain wave (DMM via Ginco, WazirX via Liminal) sits next to it, not above or below it: T11.001 third-party-vendor compromise and operator-internal compromise are parallel OAK-G01 surfaces, both productive, both unmapped at the Technique-level entry vector in OAK v0.1.
- Regulator-supervised exchanges are not custody-architecture-protected. Indodax is regulated by Bappebti, Indonesia's commodity-futures authority, and operates under formal Indonesian crypto-asset trading licensing. The regulatory regime governs disclosure, anti-money-laundering, and customer-funds-segregation but does not specify hot-wallet key-management architecture or per-chain segregation. The Indodax case is a useful teaching point that licensing posture is not a substitute for custody-architecture controls, and that defender threat models should not treat regulator supervision as a proxy for operational-security maturity. The Bithumb 2017 case at
/examples/2017-06-bithumb.mdand the Coincheck 2018 case at/examples/2018-01-coincheck.mdmake the same point in earlier regulatory regimes; Indodax updates the lesson to the 2024 Indonesian-licensing context. - Attribution latency is variable and the FBI surface does not always fire. As of this writing, no FBI / Treasury / Korean-government / Indonesian-government public attribution has named Indodax. Industry forensic providers carry the attribution. Contributors should not interpret the absence of an FBI release as evidence against attribution — the FBI publication surface is selective and follows DOJ prosecutorial priorities, not a uniform per-incident protocol.
What this example tells contributors writing future Technique pages
- The operator-internal hot-wallet key compromise gap continues to be the most-exploited OAK v0.1 taxonomy gap. Indodax is the fifth canonical worked example of this gap (after KuCoin, Coincheck, Stake.com, Phemex), and the third within the 2024–2025 OAK-G01 wave (alongside Phemex 2025 and the operator-side aspects of WazirX). A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise, with sub-sub-Techniques for (a) social-engineered employee access, (b) internal-IT compromise via malware, (c) insider misuse, and (d) multi-chain key-store co-location amplification (Phemex, Indodax). Indodax adds the regulator-supervised exchange colour to a sub-sub-Technique that the corpus has otherwise documented mostly through unregulated or lightly-regulated exchange examples.
inferred-strongis the right marker for Indodax, notconfirmed. No FBI / Treasury / DOJ / allied-government statement explicitly names Indodax as of the date of this example. The attribution rests on (a) industry-forensic concurrence (Chainalysis, Match Systems, Elliptic, SlowMist) and (b) laundering-chain shape and cluster-proximity evidence to confirmed Lazarus / TraderTraitor wallets. Per OAK convention, this is the canonicalinferred-strongprofile — multi-firm concurrence plus cluster-graph evidence to confirmed wallets, without an explicit government release. A downstream contributor should upgrade Indodax toconfirmedif and only if a U.S. or allied government public statement explicitly names Indodax.- The 2024 OAK-G01 wave should be cross-referenced consistently. Contributors writing the DMM Bitcoin example (May 2024,
/examples/2024-05-dmm-bitcoin.md), the WazirX example (July 2024,/examples/2024-07-wazirx.md), the Radiant Capital example (October 2024,/examples/2024-10-radiant-capital.md), the Phemex example (January 2025,/examples/2025-01-phemex.md), and the Bybit example (February 2025,/examples/2025-02-bybit.md) should now treat Indodax as a fifth datapoint in the wave between WazirX and Radiant. The temporal density of the wave (DMM → WazirX → Indodax → Radiant → Phemex → Bybit) is the analytically important feature. - Recovery-rate documentation should not be skipped just because the rate is zero. Indodax absorbed the loss internally and there is no public recovery action; the recovery rate is effectively zero at the on-chain layer. Recording this explicitly is more useful than omitting it — it sets the realistic floor for cases in this entry-vector / laundering-rail combination, alongside Stake.com's ~2.4% as the comparable lower-bound case.
Public references
[indodaxpostmortem2024]— Indodax operator-side incident statement covering the multi-chain drain, service-suspension timeline, and reimbursement commitment.[cyversindodax2024]— Cyvers real-time monitoring alert and follow-up forensic post identifying the multi-chain outflow pattern.[peckshieldindodax2024]— PeckShield headline figures and on-chain analytics for the Indodax September 2024 drain.[slowmistindodax2024]— SlowMist incident analysis covering the multi-chain key-store co-location root-cause hypothesis and laundering-chain breakdown.[matchsystemsindodax2024]— Match Systems forensic flow-of-funds analysis tying the Indodax laundering chain to the broader TraderTraitor / OAK-G01 cluster.[chainalysisindodax2024]— Chainalysis on the Indodax cluster and OAK-G01 / TraderTraitor September 2024 attribution context.[elliptictraderTraitor2024]— Elliptic on the 2024 TraderTraitor campaign laundering-chain shape across DMM, WazirX, Indodax.[chainalysis2024dprk]for cumulative OAK-G01 / DPRK-attributed totals context.
Discussion
Indodax is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a regulator-supervised regional exchange and is the timeline gap-filler between WazirX (July 2024) and Radiant Capital (October 2024) in the 2024 OAK-G01 wave. The wave runs:
- DMM Bitcoin (May 2024, ~$305M) — T11.001 third-party-vendor compromise via Ginco.
confirmedattribution by FBI / DC3 / NPA in December 2024. See/examples/2024-05-dmm-bitcoin.md. - WazirX (July 2024, ~$234.9M) — T11.001 + T11.003 third-party-vendor compromise via Liminal followed by in-use multisig manipulation.
confirmedattribution. See/examples/2024-07-wazirx.md. - Indodax (September 2024, ~$22M) — operator-internal hot-wallet key compromise with multi-chain key-store co-location amplification.
inferred-strongattribution via TraderTraitor-shape laundering chain and cluster-proximity evidence. This document. - Radiant Capital (October 2024, ~$50M+) — DeFi protocol-side compromise; OAK-G01-attributed. See
/examples/2024-10-radiant-capital.md. - Phemex (January 2025, ~$73M) — operator-internal hot-wallet key compromise with multi-chain key-store co-location amplification.
inferred-strongattribution via wallet-cluster overlap with Bybit. See/examples/2025-01-phemex.md. - Bybit (February 2025, ~$1.46B) — T11.001 third-party-vendor compromise via Safe{Wallet}.
confirmedattribution. See/examples/2025-02-bybit.md.
The Indodax–Phemex pair establishes that operator-internal hot-wallet key compromise was running as a sustained workstream alongside the third-party-vendor compromise workstream (DMM, WazirX, Bybit) throughout the 2024–2025 OAK-G01 wave. Both workstreams were productive on the same calendar timeline, both sit in the OAK-T11 entry-vector taxonomy gap that OAK v0.1 does not address with a clean entry-vector match, and both should be promoted to first-class entry-vector Techniques in a future v0.x update.
The unmapped entry-vector gap — operator-internal hot-wallet key compromise — is now five worked examples deep (KuCoin, Coincheck, Stake.com, Phemex, Indodax) and remains the single most-exploited gap in OAK v0.1. Indodax adds the regulator-supervised regional-exchange colour to the gap and reinforces that the gap is not specific to unregulated, North-America-headquartered, or DeFi-adjacent operator categories — it spans the global-exchange custody-operator surface as a class.