Mitigation · OAK-M35 · operational
OAK-M35 — Whitehat-Rescue Coordination
Description
Whitehat-rescue coordination is the post-incident operational mitigation that maximises recoverable funds when an exploit is in progress or has just landed. Where M32 (bug bounty) is the proactive pre-incident discovery layer and M34 (emergency pause) is the bleed-stop layer, M35 is the negotiation-and-recovery layer that handles the funds already in attacker control and the funds still extractable by a whitehat racing the exploit. The structural artefact M35 deploys is a pre-published rescue-channel address (an on-chain contact address with monitored message-channel capability), a public bounty offer at incident disclosure (typically 5–10% of recovered funds, occasionally up to 20%), and a no-prosecution commitment for any actor who returns funds via the rescue channel. The combination converts a post-incident game-theoretic landscape from "attacker keeps everything by default" to "attacker has a credible alternative path that returns most of the funds to the protocol while preserving a meaningful payment to the actor".
The 2023–2024 cohort of canonical recoveries demonstrates the mitigation's value. Euler Finance (March 2023): $197M extracted; protocol team opened on-chain message channel with self-identified attacker "Jacob"; bounty offer + no-prosecution commitment; $197M returned in full over weeks of negotiation. ParaSpace (March 2023): BlockSec's whitehat team intervened mid-exploit, frontrunning the attacker on extraction transactions; ~$5M rescued from a larger exposure window. Ronin Bridge (August 2024): Sky Mavis publicly framed the post-incident posture as whitehat-friendly with no-prosecution commitment; the rescue / partial-recovery sequence proceeded against this framing. Tapioca (October 2024): post-exploit negotiated return with bounty payment, illustrating the mature-form pattern at smaller scale. The cumulative pattern: when the rescue posture is credible, attackers and whitehats both have a path to monetise the incident without exhausting the residual surface; when no rescue posture exists, the default is full extraction.
The structural distinction from M32 is that M35 is reactive: it is invoked only after the incident is in progress. A protocol cannot rely on M35 alone — many incidents result in attackers ignoring the rescue channel and laundering the funds (the entire DPRK / Lazarus cohort, the bulk of T7-mapped laundering cohorts, and most fast-rug T1.x / T5.x cases route around any rescue offer). M35 is most effective against the subset of attackers who are (a) financially motivated rather than state-sponsored, (b) operating at a scale where the bounty is non-trivial, and (c) operating in a jurisdiction where prosecution risk is real. Against the DPRK-linked or DPRK-trained adversary cluster the rescue offer is rarely accepted; against the financially-motivated freelance-exploit cohort the acceptance rate has been materially non-zero.
How it applies
- OAK-T9.001 / T9.002 / T9.003 / T9.004 / T9.005 (smart-contract exploit classes): the canonical M35 surface. The Euler March 2023 case is the worked example: T9.002 (flash-loan precondition) + T9.004 (missing solvency check on
donateToReserves); on-chain message-channel negotiation; full $197M return. Subsequent cases (Tapioca October 2024, others in the cohort) illustrate the same pattern at smaller scale. The success-rate distribution across the T9 family is roughly aligned with attacker attribution: financially-motivated solo-exploit cases are the highest acceptance-rate sub-cohort. - OAK-T10.001 / T10.002 / T10.003 / T10.004 / T10.005 (bridge attack classes): the Ronin August 2024 case is the canonical bridge-layer M35 reference. Sky Mavis's whitehat-rescue framing post-incident, including the no-prosecution commitment and the rescue-channel publication, defined the recovery posture; the bridge-pause-and-rescue sequence operated against this framing. Bridge-side M35 is structurally harder than protocol-side M35 because the cross-chain capital surface and the validator-set surface (T10.001) introduce additional rescue-coordination complexity.
- OAK-T11.001 / T11.002 / T11.003 (custody / wallet / multisig compromise): M35 at the custody layer is structurally weak relative to the contract layer. The Bybit-Feb-2025 cohort proceeded with rescue-coordination posture (publicised bounty, hash-target tracking, exchange-side cooperation) but the recovery rate was materially lower than the typical contract-layer rescue case because the attacker (DPRK-attributed) was operating outside the financial-motivation acceptance regime. M35 here is correctly understood as a low-base-rate residual-recovery layer, not a primary control.
Limitations
- Acceptance is attacker-discretion. The mitigation only succeeds if the attacker chooses to engage with the rescue channel. State-sponsored actors (DPRK / Lazarus, the bulk of the OAK-G01 attribution cohort) reliably do not engage; the historical recovery rate against this cluster via rescue-coordination is near zero. M35 is calibrated against the financially-motivated cohort; the state-sponsored cohort requires the attribution-and-sanctions / off-ramp-interdiction layer (M07 + M27 + venue-side controls).
- Bounty calibration trade-offs. Too low a bounty (sub-1% of recovered funds) provides insufficient incentive against the full-launder alternative; too high a bounty (20%+) approaches a moral-hazard frontier where the bounty becomes a structural payment for exploits. Industry-canonical calibration has settled in the 5–10% range for the recoverable subset; the Euler case anchored the 10% precedent. The negotiation latitude here is per-incident.
- No-prosecution commitment is bounded by jurisdiction. The protocol team can credibly commit to not pursuing civil action and not coordinating private-investigator / forensic engagement against the attacker, but cannot credibly commit on behalf of public prosecutors in jurisdictions where the attacker may be reachable. The Euler case demonstrated this as a practical matter: the attacker's actual prosecution-risk profile depended on jurisdiction and on third-party action, not on the protocol's commitment alone. The commitment is a credibility signal, not a binding indemnity.
- Front-running rescue requires specialised capability. The ParaSpace case (BlockSec rescue) is the worked example: rescuing in-flight funds requires the rescuer to (a) understand the exploit precisely, (b) deploy a counter-exploit that wins the block-ordering race, and (c) operate within the protocol's pre-published rescue-channel framing. The capability set is concentrated in a small number of specialist firms (BlockSec, certain audit firms, certain MEV-aware whitehat operators). Most protocols do not have this capability in-house and must coordinate via the specialist-firm channel post-incident.
- Reactive control by definition. M35 cannot prevent the incident; it only operates on the residual surface and the post-incident negotiation. The composition is M16 + M32 (prevention) + M03 + M06 + M11 (detection) + M34 (bleed-stop) + M35 (recovery) + M22 (rotation). M35 alone is structurally insufficient as a security posture.
- Incentive-alignment risk. A widely-publicised, credibly-paid M35 bounty programme creates a structural incentive that the protocol team must manage carefully against a moral-hazard reading: in some adversarial framings, "the protocol will pay X% on recovery" is read as "an attempted exploit has a guaranteed downside floor". Mature operators frame the rescue posture explicitly as post-incident-only, with M32 (bug bounty) as the proactive disclosure path that pays without any prior exploitation.
Reference implementations
- Euler Finance March 2023 (the canonical reference): on-chain message-channel disclosure to attacker address; published bounty + no-prosecution commitment; weeks-long negotiation; full $197M recovered. The Euler case is the textbook M35 success and has been widely adopted as the template for subsequent rescue-coordination postures.
- ParaSpace March 2023 (the rescue-via-counter-exploit reference): BlockSec whitehat team intervened mid-exploit; counter-extracted residual exposure into a known rescue address; coordinated return to the protocol. The case demonstrates the specialist-firm-rescue capability layer.
- Ronin Bridge August 2024: Sky Mavis whitehat-friendly post-incident framing with no-prosecution commitment; rescue-channel publication; the recovery sequence operated against this framing. Bridge-layer reference for M35 deployed at scale.
- Tapioca October 2024: smaller-scale, fast-resolution case; negotiated return with bounty payment; illustrates the pattern's applicability outside the largest incidents.
- Industry coordination tooling: SEAL 911 / SEAL ISAC, BlockSec rescue operations, Hexagate / Forta detection-to-rescue coordination, and several audit-firm side responder teams collectively form the inter-organisational rescue-coordination network. The mature-form M35 deployment integrates the protocol's runbook with the specialist-firm channel.
- Pre-incident artefact set (the M35 mature-form posture): rescue-channel address published in the protocol's documentation and on-chain registry, with monitored message capability; standard bounty schedule (5–10% with negotiated upside); written no-prosecution commitment; designated incident-coordinator point-of-contact; SEAL 911 / equivalent off-hours escalation path. This artefact set is what converts M35 from ad-hoc-judgement to procedure.
Citations
[chainalysiseuler2023]— primary reference for the Euler March 2023 recovery; canonical M35 success case at scale.[halborneuler2023]— Halborn forensic post-mortem; documents the rescue-coordination sequence and its outcome.[blocksec2023euler]— BlockSec analysis of the Euler exploit including the rescue-channel framing.[elliptipeuler2023]— Elliptic recovery-tracing analysis; documents the on-chain message-channel negotiation between Euler Labs and the self-identified attacker "Jacob".[eulerlabs2023statement]— Euler Labs's own post-mortem, the protocol-side primary-source reference for the rescue posture.[skymavisronin2024]— Ronin Bridge August 2024 incident acknowledgement; whitehat-rescue framing and no-prosecution commitment.[ronin2024postmortem]— Ronin Bridge August 2024 post-mortem; the recovery-coordination sequence at the bridge layer.[hypernativeronin2024]— front-running / sequencing analysis from the Ronin August 2024 case; reference for the rescue-versus-MEV race profile.[chainalysis2024dprk]— broader cohort context for the DPRK-attributed sub-cohort that materially does not accept rescue offers; the bound on M35 acceptance rate.
Techniques mitigated (13)
- OAK-T9.001 Oracle Price Manipulation
- OAK-T9.002 Flash-Loan-Enabled Exploit
- OAK-T9.003 Governance Attack
- OAK-T9.004 Access-Control Misconfiguration
- OAK-T9.005 Reentrancy
- OAK-T10.001 Validator / Signer Key Compromise
- OAK-T10.002 Message-Verification Bypass
- OAK-T10.003 Cross-Chain Replay
- OAK-T10.004 Optimistic-Bridge Fraud-Proof Gap
- OAK-T10.005 Light-Client Verification Bypass
- OAK-T11.001 Third-Party Signing-Vendor UI / Signing-Flow Compromise
- OAK-T11.002 Wallet-Software Distribution Compromise
- OAK-T11.003 In-Use Multisig Smart-Contract Manipulation