OAK — OnChain Attack Knowledge

Mitigation · OAK-M35 · operational

OAK-M35 — Whitehat-Rescue Coordination

Class
operational
Audience
protocol, designer, vendor
Maps to Techniques
OAK-T9.001, OAK-T9.002, OAK-T9.003, OAK-T9.004, OAK-T9.005, OAK-T10.001, OAK-T10.002, OAK-T10.003, OAK-T10.004, OAK-T10.005, OAK-T11.001, OAK-T11.002, OAK-T11.003

Description

Whitehat-rescue coordination is the post-incident operational mitigation that maximises recoverable funds when an exploit is in progress or has just landed. Where M32 (bug bounty) is the proactive pre-incident discovery layer and M34 (emergency pause) is the bleed-stop layer, M35 is the negotiation-and-recovery layer that handles the funds already in attacker control and the funds still extractable by a whitehat racing the exploit. The structural artefact M35 deploys is a pre-published rescue-channel address (an on-chain contact address with monitored message-channel capability), a public bounty offer at incident disclosure (typically 5–10% of recovered funds, occasionally up to 20%), and a no-prosecution commitment for any actor who returns funds via the rescue channel. The combination converts a post-incident game-theoretic landscape from "attacker keeps everything by default" to "attacker has a credible alternative path that returns most of the funds to the protocol while preserving a meaningful payment to the actor".

The 2023–2024 cohort of canonical recoveries demonstrates the mitigation's value. Euler Finance (March 2023): $197M extracted; protocol team opened on-chain message channel with self-identified attacker "Jacob"; bounty offer + no-prosecution commitment; $197M returned in full over weeks of negotiation. ParaSpace (March 2023): BlockSec's whitehat team intervened mid-exploit, frontrunning the attacker on extraction transactions; ~$5M rescued from a larger exposure window. Ronin Bridge (August 2024): Sky Mavis publicly framed the post-incident posture as whitehat-friendly with no-prosecution commitment; the rescue / partial-recovery sequence proceeded against this framing. Tapioca (October 2024): post-exploit negotiated return with bounty payment, illustrating the mature-form pattern at smaller scale. The cumulative pattern: when the rescue posture is credible, attackers and whitehats both have a path to monetise the incident without exhausting the residual surface; when no rescue posture exists, the default is full extraction.

The structural distinction from M32 is that M35 is reactive: it is invoked only after the incident is in progress. A protocol cannot rely on M35 alone — many incidents result in attackers ignoring the rescue channel and laundering the funds (the entire DPRK / Lazarus cohort, the bulk of T7-mapped laundering cohorts, and most fast-rug T1.x / T5.x cases route around any rescue offer). M35 is most effective against the subset of attackers who are (a) financially motivated rather than state-sponsored, (b) operating at a scale where the bounty is non-trivial, and (c) operating in a jurisdiction where prosecution risk is real. Against the DPRK-linked or DPRK-trained adversary cluster the rescue offer is rarely accepted; against the financially-motivated freelance-exploit cohort the acceptance rate has been materially non-zero.

How it applies

  • OAK-T9.001 / T9.002 / T9.003 / T9.004 / T9.005 (smart-contract exploit classes): the canonical M35 surface. The Euler March 2023 case is the worked example: T9.002 (flash-loan precondition) + T9.004 (missing solvency check on donateToReserves); on-chain message-channel negotiation; full $197M return. Subsequent cases (Tapioca October 2024, others in the cohort) illustrate the same pattern at smaller scale. The success-rate distribution across the T9 family is roughly aligned with attacker attribution: financially-motivated solo-exploit cases are the highest acceptance-rate sub-cohort.
  • OAK-T10.001 / T10.002 / T10.003 / T10.004 / T10.005 (bridge attack classes): the Ronin August 2024 case is the canonical bridge-layer M35 reference. Sky Mavis's whitehat-rescue framing post-incident, including the no-prosecution commitment and the rescue-channel publication, defined the recovery posture; the bridge-pause-and-rescue sequence operated against this framing. Bridge-side M35 is structurally harder than protocol-side M35 because the cross-chain capital surface and the validator-set surface (T10.001) introduce additional rescue-coordination complexity.
  • OAK-T11.001 / T11.002 / T11.003 (custody / wallet / multisig compromise): M35 at the custody layer is structurally weak relative to the contract layer. The Bybit-Feb-2025 cohort proceeded with rescue-coordination posture (publicised bounty, hash-target tracking, exchange-side cooperation) but the recovery rate was materially lower than the typical contract-layer rescue case because the attacker (DPRK-attributed) was operating outside the financial-motivation acceptance regime. M35 here is correctly understood as a low-base-rate residual-recovery layer, not a primary control.

Limitations

  • Acceptance is attacker-discretion. The mitigation only succeeds if the attacker chooses to engage with the rescue channel. State-sponsored actors (DPRK / Lazarus, the bulk of the OAK-G01 attribution cohort) reliably do not engage; the historical recovery rate against this cluster via rescue-coordination is near zero. M35 is calibrated against the financially-motivated cohort; the state-sponsored cohort requires the attribution-and-sanctions / off-ramp-interdiction layer (M07 + M27 + venue-side controls).
  • Bounty calibration trade-offs. Too low a bounty (sub-1% of recovered funds) provides insufficient incentive against the full-launder alternative; too high a bounty (20%+) approaches a moral-hazard frontier where the bounty becomes a structural payment for exploits. Industry-canonical calibration has settled in the 5–10% range for the recoverable subset; the Euler case anchored the 10% precedent. The negotiation latitude here is per-incident.
  • No-prosecution commitment is bounded by jurisdiction. The protocol team can credibly commit to not pursuing civil action and not coordinating private-investigator / forensic engagement against the attacker, but cannot credibly commit on behalf of public prosecutors in jurisdictions where the attacker may be reachable. The Euler case demonstrated this as a practical matter: the attacker's actual prosecution-risk profile depended on jurisdiction and on third-party action, not on the protocol's commitment alone. The commitment is a credibility signal, not a binding indemnity.
  • Front-running rescue requires specialised capability. The ParaSpace case (BlockSec rescue) is the worked example: rescuing in-flight funds requires the rescuer to (a) understand the exploit precisely, (b) deploy a counter-exploit that wins the block-ordering race, and (c) operate within the protocol's pre-published rescue-channel framing. The capability set is concentrated in a small number of specialist firms (BlockSec, certain audit firms, certain MEV-aware whitehat operators). Most protocols do not have this capability in-house and must coordinate via the specialist-firm channel post-incident.
  • Reactive control by definition. M35 cannot prevent the incident; it only operates on the residual surface and the post-incident negotiation. The composition is M16 + M32 (prevention) + M03 + M06 + M11 (detection) + M34 (bleed-stop) + M35 (recovery) + M22 (rotation). M35 alone is structurally insufficient as a security posture.
  • Incentive-alignment risk. A widely-publicised, credibly-paid M35 bounty programme creates a structural incentive that the protocol team must manage carefully against a moral-hazard reading: in some adversarial framings, "the protocol will pay X% on recovery" is read as "an attempted exploit has a guaranteed downside floor". Mature operators frame the rescue posture explicitly as post-incident-only, with M32 (bug bounty) as the proactive disclosure path that pays without any prior exploitation.

Reference implementations

  • Euler Finance March 2023 (the canonical reference): on-chain message-channel disclosure to attacker address; published bounty + no-prosecution commitment; weeks-long negotiation; full $197M recovered. The Euler case is the textbook M35 success and has been widely adopted as the template for subsequent rescue-coordination postures.
  • ParaSpace March 2023 (the rescue-via-counter-exploit reference): BlockSec whitehat team intervened mid-exploit; counter-extracted residual exposure into a known rescue address; coordinated return to the protocol. The case demonstrates the specialist-firm-rescue capability layer.
  • Ronin Bridge August 2024: Sky Mavis whitehat-friendly post-incident framing with no-prosecution commitment; rescue-channel publication; the recovery sequence operated against this framing. Bridge-layer reference for M35 deployed at scale.
  • Tapioca October 2024: smaller-scale, fast-resolution case; negotiated return with bounty payment; illustrates the pattern's applicability outside the largest incidents.
  • Industry coordination tooling: SEAL 911 / SEAL ISAC, BlockSec rescue operations, Hexagate / Forta detection-to-rescue coordination, and several audit-firm side responder teams collectively form the inter-organisational rescue-coordination network. The mature-form M35 deployment integrates the protocol's runbook with the specialist-firm channel.
  • Pre-incident artefact set (the M35 mature-form posture): rescue-channel address published in the protocol's documentation and on-chain registry, with monitored message capability; standard bounty schedule (5–10% with negotiated upside); written no-prosecution commitment; designated incident-coordinator point-of-contact; SEAL 911 / equivalent off-hours escalation path. This artefact set is what converts M35 from ad-hoc-judgement to procedure.

Citations

  • [chainalysiseuler2023] — primary reference for the Euler March 2023 recovery; canonical M35 success case at scale.
  • [halborneuler2023] — Halborn forensic post-mortem; documents the rescue-coordination sequence and its outcome.
  • [blocksec2023euler] — BlockSec analysis of the Euler exploit including the rescue-channel framing.
  • [elliptipeuler2023] — Elliptic recovery-tracing analysis; documents the on-chain message-channel negotiation between Euler Labs and the self-identified attacker "Jacob".
  • [eulerlabs2023statement] — Euler Labs's own post-mortem, the protocol-side primary-source reference for the rescue posture.
  • [skymavisronin2024] — Ronin Bridge August 2024 incident acknowledgement; whitehat-rescue framing and no-prosecution commitment.
  • [ronin2024postmortem] — Ronin Bridge August 2024 post-mortem; the recovery-coordination sequence at the bridge layer.
  • [hypernativeronin2024] — front-running / sequencing analysis from the Ronin August 2024 case; reference for the rescue-versus-MEV race profile.
  • [chainalysis2024dprk] — broader cohort context for the DPRK-attributed sub-cohort that materially does not accept rescue offers; the bound on M35 acceptance rate.

Techniques mitigated (13)