OAK — OnChain Attack Knowledge

Worked example · 2024-09

Indodax hot-wallet drain — multi-chain — 2024-09-11

Loss
approximately $22M extracted from Indodax hot wallets across multiple chains, including Ethereum (~$15M of the total in ERC-20s and ETH), Tron (TRX, USDT-TRC20), BNB Chain, and Polygon, in a near-simultaneous drain window beginning ~02:18 UTC on 2024-09-11. Indodax is Indonesia's largest cryptocurrency exchange, headquartered in Jakarta and operated by PT Indodax Nasional Indonesia. Reported figures span $18.2M (Cyvers initial count) to $22M (PeckShield, SlowMist, Match Systems revised figures as additional small-balance drains landed on lower-priority chains within the same window).
Recovery
none publicly disclosed at the on-chain layer; Indodax absorbed the loss against operational reserves and resumed user services in stages from 2024-09-12 with full restoration by mid-September 2024. No public DOJ civil-forfeiture action has been filed as of the date of this example.
Attribution
inferred-strong — see OAK-Gnn line below for attribution detail.
OAK Techniques observed
no exact OAK v0.1 entry-vector match — the entry vector was operator-internal hot-wallet private-key compromise across a multi-chain key-storage surface, structurally identical to the Phemex case at /examples/2025-01-phemex.md. Closest sibling Technique class is the broader OAK-T11 custody-and-signing family, broadly construed; Indodax is the fifth canonical worked example of the operator-side internal hot-wallet key compromise gap in the OAK v0.1 taxonomy, after KuCoin (2020), Coincheck (2018), Stake.com (2023), and Phemex (2025). The likely root cause — per SlowMist and Cyvers — is co-located key material across the multi-chain hot-wallet surface, such that a single compromise produced near-simultaneous outflows on multiple chains. Downstream Techniques observed on-chain: OAK-T7.001 (Mixer-Routed Hop — Tornado Cash on Ethereum, with multi-hop intermediary addresses) and OAK-T7.003 (Cross-Chain Bridge Laundering — bridging from Tron to Ethereum prior to mixer entry).
Actor
OAK-G01 Lazarus Group / TraderTraitor / DPRK-attributed.
Attribution status
inferred-strong — no FBI press release, U.S. Treasury OFAC designation, or Korean / Indonesian law-enforcement statement explicitly naming Indodax has been published as of the date of this example. Attribution is carried by industry forensic providers: Chainalysis, Match Systems, Elliptic, and SlowMist, who tied the post-event laundering pattern (Tron → Ethereum bridging followed by Tornado Cash entry through addresses sharing transaction-graph proximity to confirmed Lazarus-cluster wallets from prior 2023–2024 cases) to the canonical TraderTraitor laundering chain shape. By OAK convention this clears the inferred-strong bar: multiple independent industry forensics providers concur, and the laundering-chain evidence ties Indodax to the same TraderTraitor / OAK-G01 infrastructure that carries confirmed-grade attribution in adjacent 2024 cases (DMM Bitcoin, WazirX). Should the FBI, Treasury, or an allied government subsequently publish Indodax-specific attribution, this example should be upgraded to confirmed.
Key teaching point
Indodax is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a regulator-supervised regional exchange and is the timeline gap-filler between WazirX (July 2024) and Radiant Capital (October 2024) in the 2024 OAK-G01 wave. The wave runs:

Summary

Indodax is Indonesia's largest centralised cryptocurrency exchange, founded in 2014 as Bitcoin Indonesia and rebranded to Indodax in 2018. The exchange supports a broad asset list (~200 listed assets) across Bitcoin, Ethereum, Tron, BNB Chain, Polygon, and additional chains; it serves several million Indonesian users and is regulated by Bappebti, Indonesia's commodity-futures trading authority.

On 2024-09-11 at approximately 02:18 UTC, Cyvers and PeckShield first surfaced unusual outbound activity on Indodax hot wallets across multiple chains. Within hours, attackers extracted approximately $22M in a near-simultaneous multi-chain drain. Indodax acknowledged the incident the same day, suspended deposits, withdrawals, and trading services while the team scoped the breach, and confirmed that cold-wallet reserves were unaffected.

The proximate cause — per SlowMist's and Cyvers's post-incident commentary — was compromise of Indodax's hot-wallet private keys, with a strong inference that key material for multiple chains was co-located in a single signing infrastructure. The simultaneity of the multi-chain outflows is the clearest signal: independent operator-side compromises of multiple separate signing pipelines is implausible on the observed timeline; a single operator-internal key-store compromise that fanned out across the chain surface is consistent with the on-chain pattern.

For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), Stake.com (2023), and Phemex (2025). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the laundering chain, and the cluster-level OAK-G01 attribution are all on the public record.

The OAK-G01 / TraderTraitor attribution rests on (a) the laundering-chain shape — Tron-side proceeds bridged to Ethereum and routed through Tornado Cash via intermediary addresses with transaction-graph proximity to confirmed Lazarus-cluster wallets — and (b) the matching of the Indodax laundering pattern to the broader TraderTraitor campaign that Chainalysis and Match Systems were tracking at the time across the 2024 OAK-G01 wave (DMM Bitcoin, WazirX, with Radiant Capital and Phemex as later-quarter datapoints in the same cluster).

Timeline (UTC)

When Event OAK ref
Pre-event Operator-internal compromise of Indodax hot-wallet key material; key-storage co-location across chains inferred from the simultaneity of outflows (off-chain entry vector — no exact OAK v0.1 match)
2024-09-11 ~02:18 Cyvers and PeckShield surface unusual outbound activity in Indodax hot wallets; first public flag of the incident (external detection)
2024-09-11 (hours 0–6) Near-simultaneous multi-chain extraction across Ethereum, Tron, BNB Chain, Polygon, and additional supported chains; cumulative outflow reaches ~$18.2M on initial Cyvers count, revised to ~$22M as small-balance drains land on lower-priority chains T5-equivalent (extraction event)
2024-09-11 Indodax acknowledges the incident publicly; suspends deposits, withdrawals, and trading; confirms cold wallets unaffected; commits to user reimbursement (operator response)
2024-09-12 Indodax begins phased restoration of user services (operator response)
2024-09-11 onward Attacker consolidates proceeds; Tron-side proceeds bridged to Ethereum; ETH and ERC-20 proceeds routed through Tornado Cash via multi-hop intermediary addresses T7.003 (Cross-Chain Bridge Laundering) → T7.001 (Mixer-Routed Hop)
2024-09 Chainalysis, Match Systems, Elliptic, SlowMist forensic write-ups converge on TraderTraitor-shape laundering chain; cluster-proximity evidence to confirmed Lazarus wallets surfaces G01 attribution (inferred-strong)
2024-09 — Q4 Indodax completes service restoration across all supported assets and chains (operator response)

What defenders observed

  • Multi-chain key-store co-location is the recurring 2024–2025 OAK-G01 target shape on exchange custody. The Indodax outflows landed on multiple chains within a single drain window, in the same shape as Phemex four months later. The simplest hypothesis consistent with the on-chain evidence is that Indodax's hot-wallet signing pipeline read key material from a shared storage surface, and that one compromise of that surface yielded signing authority across all chains. Defender runbooks for multi-chain custody operators should treat key-store segregation per chain (or per chain-family) as a primary control, not an optional one. The Indodax–Phemex pair is the strongest 2024–2025 evidence on the exchange-custody side that the absence of this control turns one compromise into N.
  • The TraderTraitor / OAK-G01 laundering signature is identifiable at the chain-graph level even without explicit FBI attribution. Chainalysis and Match Systems both surfaced the Indodax laundering chain as TraderTraitor-shape within days of the incident, on the basis of (a) the bridging-then-mixer pattern characteristic of the campaign and (b) cluster-proximity of intermediary addresses to confirmed Lazarus wallets in the broader 2023–2024 case set. Defender risk teams treating OAK-G01 as a per-incident cluster underweight this continuity; the 2024 OAK-G01 wave should be modelled as a single sustained campaign with shared laundering rails and shared address-cluster overlap.
  • Operator-internal hot-wallet key compromise is a recurring 2024 OAK-G01 pattern, not an exception. Indodax sits in the same entry-vector class as KuCoin (2020), Coincheck (2018), Stake.com (2023), and the broader 2023 wave (Atomic Wallet, Alphapo / CoinsPaid, CoinEx). The 2024 supply-chain wave (DMM via Ginco, WazirX via Liminal) sits next to it, not above or below it: T11.001 third-party-vendor compromise and operator-internal compromise are parallel OAK-G01 surfaces, both productive, both unmapped at the Technique-level entry vector in OAK v0.1.
  • Regulator-supervised exchanges are not custody-architecture-protected. Indodax is regulated by Bappebti, Indonesia's commodity-futures authority, and operates under formal Indonesian crypto-asset trading licensing. The regulatory regime governs disclosure, anti-money-laundering, and customer-funds-segregation but does not specify hot-wallet key-management architecture or per-chain segregation. The Indodax case is a useful teaching point that licensing posture is not a substitute for custody-architecture controls, and that defender threat models should not treat regulator supervision as a proxy for operational-security maturity. The Bithumb 2017 case at /examples/2017-06-bithumb.md and the Coincheck 2018 case at /examples/2018-01-coincheck.md make the same point in earlier regulatory regimes; Indodax updates the lesson to the 2024 Indonesian-licensing context.
  • Attribution latency is variable and the FBI surface does not always fire. As of this writing, no FBI / Treasury / Korean-government / Indonesian-government public attribution has named Indodax. Industry forensic providers carry the attribution. Contributors should not interpret the absence of an FBI release as evidence against attribution — the FBI publication surface is selective and follows DOJ prosecutorial priorities, not a uniform per-incident protocol.

What this example tells contributors writing future Technique pages

  • The operator-internal hot-wallet key compromise gap continues to be the most-exploited OAK v0.1 taxonomy gap. Indodax is the fifth canonical worked example of this gap (after KuCoin, Coincheck, Stake.com, Phemex), and the third within the 2024–2025 OAK-G01 wave (alongside Phemex 2025 and the operator-side aspects of WazirX). A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise, with sub-sub-Techniques for (a) social-engineered employee access, (b) internal-IT compromise via malware, (c) insider misuse, and (d) multi-chain key-store co-location amplification (Phemex, Indodax). Indodax adds the regulator-supervised exchange colour to a sub-sub-Technique that the corpus has otherwise documented mostly through unregulated or lightly-regulated exchange examples.
  • inferred-strong is the right marker for Indodax, not confirmed. No FBI / Treasury / DOJ / allied-government statement explicitly names Indodax as of the date of this example. The attribution rests on (a) industry-forensic concurrence (Chainalysis, Match Systems, Elliptic, SlowMist) and (b) laundering-chain shape and cluster-proximity evidence to confirmed Lazarus / TraderTraitor wallets. Per OAK convention, this is the canonical inferred-strong profile — multi-firm concurrence plus cluster-graph evidence to confirmed wallets, without an explicit government release. A downstream contributor should upgrade Indodax to confirmed if and only if a U.S. or allied government public statement explicitly names Indodax.
  • The 2024 OAK-G01 wave should be cross-referenced consistently. Contributors writing the DMM Bitcoin example (May 2024, /examples/2024-05-dmm-bitcoin.md), the WazirX example (July 2024, /examples/2024-07-wazirx.md), the Radiant Capital example (October 2024, /examples/2024-10-radiant-capital.md), the Phemex example (January 2025, /examples/2025-01-phemex.md), and the Bybit example (February 2025, /examples/2025-02-bybit.md) should now treat Indodax as a fifth datapoint in the wave between WazirX and Radiant. The temporal density of the wave (DMM → WazirX → Indodax → Radiant → Phemex → Bybit) is the analytically important feature.
  • Recovery-rate documentation should not be skipped just because the rate is zero. Indodax absorbed the loss internally and there is no public recovery action; the recovery rate is effectively zero at the on-chain layer. Recording this explicitly is more useful than omitting it — it sets the realistic floor for cases in this entry-vector / laundering-rail combination, alongside Stake.com's ~2.4% as the comparable lower-bound case.

Public references

  • [indodaxpostmortem2024] — Indodax operator-side incident statement covering the multi-chain drain, service-suspension timeline, and reimbursement commitment.
  • [cyversindodax2024] — Cyvers real-time monitoring alert and follow-up forensic post identifying the multi-chain outflow pattern.
  • [peckshieldindodax2024] — PeckShield headline figures and on-chain analytics for the Indodax September 2024 drain.
  • [slowmistindodax2024] — SlowMist incident analysis covering the multi-chain key-store co-location root-cause hypothesis and laundering-chain breakdown.
  • [matchsystemsindodax2024] — Match Systems forensic flow-of-funds analysis tying the Indodax laundering chain to the broader TraderTraitor / OAK-G01 cluster.
  • [chainalysisindodax2024] — Chainalysis on the Indodax cluster and OAK-G01 / TraderTraitor September 2024 attribution context.
  • [elliptictraderTraitor2024] — Elliptic on the 2024 TraderTraitor campaign laundering-chain shape across DMM, WazirX, Indodax.
  • [chainalysis2024dprk] for cumulative OAK-G01 / DPRK-attributed totals context.

Discussion

Indodax is OAK's canonical 2024 Q3 worked example of operator-internal hot-wallet key compromise on a regulator-supervised regional exchange and is the timeline gap-filler between WazirX (July 2024) and Radiant Capital (October 2024) in the 2024 OAK-G01 wave. The wave runs:

  1. DMM Bitcoin (May 2024, ~$305M) — T11.001 third-party-vendor compromise via Ginco. confirmed attribution by FBI / DC3 / NPA in December 2024. See /examples/2024-05-dmm-bitcoin.md.
  2. WazirX (July 2024, ~$234.9M) — T11.001 + T11.003 third-party-vendor compromise via Liminal followed by in-use multisig manipulation. confirmed attribution. See /examples/2024-07-wazirx.md.
  3. Indodax (September 2024, ~$22M) — operator-internal hot-wallet key compromise with multi-chain key-store co-location amplification. inferred-strong attribution via TraderTraitor-shape laundering chain and cluster-proximity evidence. This document.
  4. Radiant Capital (October 2024, ~$50M+) — DeFi protocol-side compromise; OAK-G01-attributed. See /examples/2024-10-radiant-capital.md.
  5. Phemex (January 2025, ~$73M) — operator-internal hot-wallet key compromise with multi-chain key-store co-location amplification. inferred-strong attribution via wallet-cluster overlap with Bybit. See /examples/2025-01-phemex.md.
  6. Bybit (February 2025, ~$1.46B) — T11.001 third-party-vendor compromise via Safe{Wallet}. confirmed attribution. See /examples/2025-02-bybit.md.

The Indodax–Phemex pair establishes that operator-internal hot-wallet key compromise was running as a sustained workstream alongside the third-party-vendor compromise workstream (DMM, WazirX, Bybit) throughout the 2024–2025 OAK-G01 wave. Both workstreams were productive on the same calendar timeline, both sit in the OAK-T11 entry-vector taxonomy gap that OAK v0.1 does not address with a clean entry-vector match, and both should be promoted to first-class entry-vector Techniques in a future v0.x update.

The unmapped entry-vector gap — operator-internal hot-wallet key compromise — is now five worked examples deep (KuCoin, Coincheck, Stake.com, Phemex, Indodax) and remains the single most-exploited gap in OAK v0.1. Indodax adds the regulator-supervised regional-exchange colour to the gap and reinforces that the gap is not specific to unregulated, North-America-headquartered, or DeFi-adjacent operator categories — it spans the global-exchange custody-operator surface as a class.

Techniques demonstrated (3)