Worked example · 2025-01
Phemex hot-wallet theft — multi-chain — 2025-01-23
Summary
On January 23, 2025, at 11:30 UTC, Phemex's operations team detected unusual outbound activity in the exchange's hot wallets. Within hours, attackers extracted approximately $73M across at least 16 blockchains in a near-simultaneous multi-chain drain. Phemex CEO Federico Variola publicly acknowledged the incident the same day, confirmed that cold-wallet reserves were unaffected, and suspended deposits and withdrawals while the team scoped the breach.
The proximate cause — per SlowMist's monthly security report and Halborn's post-mortem — was compromise of Phemex's hot-wallet private keys, with a strong inference that key material for multiple chains was co-located in a single storage system. The simultaneity of the multi-chain outflows is the clearest signal: independent operator-side compromises of 16 separate signing pipelines is implausible on the observed timeline; a single operator-internal key-store compromise that fanned out across the chain surface is consistent with the on-chain pattern.
For OAK's purposes the entry vector is off-chain and operator-internal, structurally identical to KuCoin (2020), Coincheck (2018), and Stake.com (2023). OAK v0.1 does not have an on-chain Technique that captures this entry vector; the case is documented here in the worked-example layer because the on-chain manifestation, the laundering chain, and the cluster-level OAK-G01 attribution are all on the public record.
The OAK-G01 attribution is the load-bearing finding for this example. In the days following the Bybit hack on February 21, 2025, on-chain investigators (most prominently ZachXBT, with corroboration from Arkham Intelligence, Merkle Science, and SlowMist) demonstrated that the Phemex attacker wallets and the Bybit attacker wallets shared address-cluster infrastructure — including consolidation wallets that the Bybit attacker reused. The Bybit case carries explicit FBI / IC3 OAK-G01 attribution published within five days of that event. The cluster-overlap evidence, combined with the laundering-chain shape (Tornado Cash + THORChain + ChangeNOW + cross-chain bridging), places Phemex squarely inside the late-2024 / early-2025 OAK-G01 wave rather than as an isolated incident.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-event | Operator-internal compromise of Phemex hot-wallet key material; key-storage co-location across chains inferred from the simultaneity of outflows (per SlowMist / Halborn) | (off-chain entry vector — no exact OAK v0.1 match) |
| 2025-01-23 ~11:30 | Phemex operations team detects unusual outbound activity in hot wallets | (operator detection) |
| 2025-01-23 hours 0–6 | Near-simultaneous multi-chain extraction across ~16 blockchains (ETH, BTC, SOL, XRP, BNB, MATIC, AVAX, ARB, OP, BASE, others); cumulative outflow reaches ~$69M on initial PeckShield count | T5-equivalent (extraction event) |
| 2025-01-23 | Phemex CEO Federico Variola posts public acknowledgement on X; confirms cold wallets unaffected; suspends deposits and withdrawals | (operator response) |
| 2025-01-24 | Phemex begins manual review and progressive restoration of USDT / USDC withdrawals | (operator response) |
| 2025-01-23 onward | Attacker begins consolidating proceeds into a multi-chain attacker cluster; over 275 transactions on EVM-compatible chains alone in the first wave | T8.001 signal |
| 2025-01 onward | Stage-1 laundering: Ethereum-side proceeds routed through Tornado Cash | T7.001 (Mixer-Routed Hop) |
| 2025-01 onward | Stage-1 laundering: secondary mixer routing through eXch | T7.001 |
| 2025-01 onward | Stage-2 laundering: cross-chain rotation via THORChain, ChangeNOW, Bitget bridging services, DLN Trade; small portions transferred to Wintermute and to deposit addresses at OKX and CoinEx | T7.003 (Cross-Chain Bridge Laundering) |
| 2025-02 | Phemex completes phased restoration of withdrawal services across all supported assets | (operator response) |
| 2025-02-21 | Bybit hack (~$1.46B); FBI / IC3 publishes OAK-G01 attribution within five days | (separate incident, see examples/2025-02-bybit.md) |
| 2025-02 onward | On-chain investigators (ZachXBT, Arkham, Merkle Science, SlowMist) demonstrate address-cluster overlap between Phemex attacker wallets and Bybit attacker wallets | G01 attribution (inferred-strong) via cluster overlap with confirmed-grade Bybit case |
| 2025-02 onward | Attacker continues drawdown of remaining balances (e.g., ~50 BTC and ~4M XRP later wave); cumulative loss tracked to ~$73–85M depending on counting window | T8.001 signal |
What defenders observed
- Multi-chain key-store co-location is now a documented OAK-G01 target shape. The Phemex outflows landed on ~16 chains within a single drain window. The simplest hypothesis consistent with the on-chain evidence is that Phemex's hot-wallet signing pipeline read key material from a shared storage surface, and that one compromise of that surface yielded signing authority across all chains. Defender runbooks for multi-chain custody operators should treat key-store segregation per chain (or per chain-family) as a primary control, not an optional one. The Phemex case is the strongest 2025 evidence that the absence of this control turns one compromise into N.
- The Phemex–Bybit cluster overlap is the highest-leverage public detection signal of the wave. Within roughly four weeks, the same OAK-G01 attacker infrastructure was used to attack two distinct Singapore-headquartered exchanges. Defender risk teams treating OAK-G01 as a per-incident cluster (the pre-2024 default) underweighted the operational continuity. The 2024–2025 OAK-G01 wave should be modelled as a single sustained campaign with shared address infrastructure, shared social-engineering pretexts, and shared laundering rails — not as a sequence of independent events.
- Tornado Cash + cross-chain rails are now the modal OAK-G01 laundering rail despite the 2022 OFAC designation. The Phemex laundering chain combined Tornado Cash (still operationally usable post-OFAC for attackers willing to accept sanctions exposure on the off-ramp), THORChain (the Bybit laundering rail per
[coindeskthorchainlazarus2025]), eXch, and ChangeNOW. Defender compliance teams treating Tornado Cash as a "solved" surface after the 2022 designation underweighted the residual operational utility for OAK-G01 actors — the actor accepted the sanctions exposure because the laundering throughput was worth it. - Operator-internal hot-wallet key compromise is a recurring 2024–2025 OAK-G01 pattern, not an exception. Phemex sits in the same entry-vector class as KuCoin (2020), Coincheck (2018), Stake.com (2023), and the broader 2023 wave (Atomic Wallet, Alphapo / CoinsPaid, CoinEx). The 2024–2025 supply-chain wave (DMM, WazirX, Bybit) sits next to it, not above or below it: T11.001 third-party-vendor compromise and operator-internal compromise are parallel OAK-G01 surfaces, both productive, both unmapped at the Technique-level entry vector in OAK v0.1.
- Attribution latency is variable and the FBI surface does not always fire. Bybit got an FBI public attribution in five days; DMM Bitcoin took seven months; Phemex has not received a public FBI / Treasury attribution as of this writing despite the cluster overlap with Bybit being on the public record. Contributors should not interpret the absence of an FBI release as evidence against attribution — the FBI publication surface is selective and the absence of a release does not downgrade industry-forensic attribution.
What this example tells contributors writing future Technique pages
- The operator-internal hot-wallet key compromise gap continues to be the most-exploited OAK v0.1 taxonomy gap. Phemex is the fourth canonical worked example of this gap (after KuCoin, Coincheck, Stake.com) and the second within the late-2024 / early-2025 OAK-G01 wave (alongside the operator-side aspects of WazirX, which chains from a T11.001 vendor compromise). A future v0.x update should add a T11.x sub-Technique covering operator-internal key compromise, with sub-sub-Techniques for (a) social-engineered employee access (Stake.com, Atomic Wallet), (b) internal-IT compromise via malware (KuCoin, Coincheck candidate vectors), (c) insider misuse, and (d) multi-chain key-store co-location amplification (Phemex). The Phemex pattern in particular is novel within the corpus and deserves its own sub-sub-Technique line.
inferred-strongis the right marker for Phemex, notconfirmed. No FBI / Treasury / DOJ statement explicitly names Phemex. The attribution rests on (a) industry-forensic concurrence (SlowMist, Merkle Science, Elliptic, Arkham, ZachXBT) and (b) wallet-cluster overlap with the Bybit case, which itself isconfirmed-grade. Per OAK convention, cluster-overlap-via-confirmed-case is the strongest grade ofinferred-strongavailable — a downstream contributor should upgrade Phemex toconfirmedif and only if a U.S. government public statement explicitly names Phemex.- The Phemex–Bybit linkage is a structural feature of the corpus, not a footnote. Contributors writing the Bybit example already capture the FBI-attribution surface; the Phemex example should be cross-referenced from the Bybit example and from the OAK-G01 actor page as the proximate-prior case in the cluster. The temporal density of the late-2024 / early-2025 OAK-G01 wave (DMM May 2024 → WazirX July 2024 → Radiant October 2024 → Phemex January 2025 → Bybit February 2025) should be visible in the Discussion sections of all five examples.
- Recovery-rate documentation should not be skipped just because the rate is zero. Phemex absorbed the loss internally and there is no public DOJ civil-forfeiture action; the recovery rate is effectively zero at the on-chain layer. Recording this explicitly is more useful than omitting it — it sets the realistic floor for cases in this entry-vector / laundering-rail combination, alongside Stake.com's ~2.4% as the comparable lower-bound case.
Public references
[chainalysisphemex2025]— Chainalysis on the Phemex cluster and OAK-G01 January 2025 attribution context.[slowmistphemex2025]— SlowMist monthly security report (January 2025) describing the Phemex incident, the multi-chain drain pattern, and the laundering chain through Tornado Cash and cross-chain rails.[halbornphemex2025]— Halborn post-incident technical write-up of the Phemex hack, including the multi-chain key-store co-location root-cause hypothesis.[merklesciencephemex2025]— Merkle Science flow-of-funds analysis tracing the Phemex attacker cluster across chains.[phemexpostmortem2025]— Phemex hot-wallet security incident update and timeline (operator-side disclosure).[zachxbtphemexbybit2025]— ZachXBT public on-chain analysis demonstrating Phemex / Bybit attacker-cluster overlap.[chainalysis2024dprk]for cumulative OAK-G01 / DPRK-attributed totals context (2024 ~$1.34B; 2025 ~$2.02B).[coindeskthorchainlazarus2025]for the THORChain laundering rail context that connects Phemex (small-share THORChain usage) to Bybit (full-amount THORChain laundering).
Discussion
Phemex is the OAK example that closes the timeline gap between Radiant Capital (October 2024) and Bybit (February 2025) in the late-2024 / early-2025 OAK-G01 wave. The wave runs:
- DMM Bitcoin (May 2024, ~$305M) — T11.001 third-party-vendor compromise via Ginco.
confirmedattribution by FBI / DC3 / NPA in December 2024. Seeexamples/2024-05-dmm-bitcoin.md. - WazirX (July 2024, ~$234.9M) — T11.001 + T11.003 third-party-vendor compromise via Liminal followed by in-use multisig manipulation.
confirmedattribution. Seeexamples/2024-07-wazirx.md. - Radiant Capital (October 2024, ~$50M+) — DeFi protocol-side compromise; OAK-G01-attributed.
- Phemex (January 2025, ~$73M) — operator-internal hot-wallet key compromise with multi-chain key-store co-location amplification.
inferred-strongattribution via wallet-cluster overlap with Bybit. This document. - Bybit (February 2025, ~$1.46B) — T11.001 third-party-vendor compromise via Safe{Wallet}.
confirmedattribution within five days. Seeexamples/2025-02-bybit.mdandexamples/2025-02-bybit-thorchain-laundering.md.
The temporal density is the analytically important feature. Five major OAK-G01 events landed in nine months, with cumulative attributed loss of approximately $2.1B — substantially more than the entirety of the 2023 OAK-G01 custody-compromise wave (Atomic Wallet, Alphapo, Stake.com, CoinEx, totalling ~$255M). The 2024–2025 wave is two orders of magnitude denser per unit of calendar time and one order of magnitude larger per event. Phemex's role in the wave is structural rather than headline: it is the case that demonstrates OAK-G01 was running operator-internal compromise and third-party-vendor compromise as parallel productive workstreams in the same window, with shared address infrastructure connecting them. The cluster-overlap evidence between Phemex and Bybit is what makes this legible — without Phemex, Bybit reads as a discontinuous escalation; with Phemex, Bybit reads as the continuation of a single sustained campaign.
The contrast with the 2023 wave is also instructive at the laundering-rail level. The 2023 OAK-G01 cases (Stake.com in particular) ran Sinbad / Yonmix on the Bitcoin side as the post-Tornado-Cash-sanctions replacement mixer rail. The 2024–2025 wave returned to Tornado Cash usage (Phemex) alongside the new dominant rail of THORChain (Bybit, Phemex small-share). The laundering-rail mix is selected per-chain and per-incident; the actor-cluster continuity is the constant. Contributors writing OAK-G01 examples should expect rail diversification within the same campaign — single-rail laundering-chain analysis is no longer sufficient to characterise a 2024+ OAK-G01 case.
The unmapped entry-vector gap — operator-internal hot-wallet key compromise — is now four worked examples deep (KuCoin, Coincheck, Stake.com, Phemex) and remains the single most-exploited gap in OAK v0.1. The Phemex-specific wrinkle (multi-chain key-store co-location) is novel within the corpus and is the strongest single-case argument for promoting this entry vector to a Technique-level entry in a future v0.x update.