CryptoReal
CASE FILE — Sep 11, 2024

Indonesia's Top Exchange Bleeds $25 Million Across Six Chains

On September 10, 2024, Indodax, the largest cryptocurrency exchange in Indonesia, suffered a multi-chain security breach that drained roughly $25.22 million from its hot wallets.

Credit: Cyvers, Lookonchain, SlowMist, William Sutanto, Arkham Intel, Bein Crypto

01How the incident surfaced

Blockchain security firm Cyvers was first to flag the activity, posting that its monitoring system had detected multiple suspicious transactions moving across different networks tied to Indodax-controlled wallets. Within hours, on-chain analysts including Lookonchain had assembled a breakdown of the losses:

  • 6.14M USDT
  • 1,047 ETH (~$2.48M)
  • 25 BTC (~$1.41M)
  • 2.2M MATIC (~$849K)
  • 1.4M ARB (~$749.6K)
  • 2M ENA (~$465K)
  • Additional assets bringing the total to approximately $25.22 million

02Attribution and attack method

Yosi Hammer, Head of AI at Cyvers, noted that the speed, complexity, and overall pattern of the operation bore strong resemblance to techniques historically used by North Korea's Lazarus Group, while cautioning that it was too early to confirm any specific group's involvement.

SlowMist's investigation pointed away from a straightforward hot-wallet key compromise, instead suggesting the withdrawal system itself had been breached. According to that analysis, the attackers were able to trigger withdrawals that appeared legitimate, including change addresses that routed funds back into Indodax's own infrastructure to mask the activity.

The hot wallets identified as compromised were:

Sums referenced in this case file

03Exchange response

Indodax responded by placing the platform into full maintenance mode to preserve system integrity. Co-founder William Sutanto stated on X that user funds remained "100% safe both in crypto and rupiah," even as the exchange took itself offline.

04Movement of stolen funds

The attackers proceeded to convert and disperse the stolen assets into a new set of wallets across multiple networks:

Cyvers later reported that more than 150 individual transactions were involved in laundering the funds, complicating efforts to trace the full flow of assets.

05Scale in context

Despite the size of the theft, it represented a small fraction of Indodax's holdings — Arkham data showed the exchange's wallets still held over $400 million in assorted tokens after the incident.

This was not Indodax's first brush with fraud. In June 2023, Indonesian authorities arrested two individuals who had impersonated the exchange on social media, defrauding victims of roughly 625 million Indonesian Rupiah (about $40,500) before being caught.

06Takeaway

The incident underscores the recurring vulnerability of centralized exchanges to both unsophisticated impersonation scams and highly coordinated, potentially state-linked hacking operations. As attackers ranging from opportunistic scammers to advanced persistent threat groups continue to target exchange infrastructure, the case renews scrutiny of how platforms manage hot wallet exposure and withdrawal system integrity.

Indodax
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.