CryptoReal
CASE FILE — Nov 1, 2024

M2's 16-Minute "Full Recovery" Claim Draws Scrutiny After $13.7M Multi-Chain Breach

M2 Exchange, an Abu Dhabi-based crypto trading platform, disclosed on October 31 that it had suffered a $13.7 million security breach — and, unusually, said the matter was already closed by the time it went public.

The exchange stated it had detected and contained the incident within 16 minutes. Independent researcher ZachXBT later corroborated the attack, noting that it touched three separate networks: Ethereum, Bitcoin, and Solana.

The rapid self-disclosure, paired with an equally rapid claim of resolution, has left outside observers questioning what parts of the incident have not been fully explained.

Credit: M2, ZachXBT, Cyvers, Hacken

01Timeline of detection

Suspicious activity across the ETH, SOL, and BTC chains was first flagged overnight on October 30 by Cyvers' automated monitoring systems. According to reporting on the incident, that alert reportedly went out via LinkedIn and may not have reached M2's team in time to prevent further losses.

M2 subsequently issued a brief public statement that offered little technical detail. It took a follow-up analysis from Hacken to identify the actual root cause: the breach stemmed from an access control failure. Hacken's writeup laid out the mechanics of the exploit in more depth than M2's own disclosure.

02How the funds moved

Once the attacker gained control, assets began exiting M2's hot wallet at address 0xE26abc37b06B819243B4B104270Cc18f7C835FcE. The funds first landed in an externally owned account, 0xb5f798096bd4D969466E2284Bda01F7A51049d3A, before being forwarded again to a second EOA, 0x968b6984cba14444f23ee51be90652408155e142, for further distribution.

Losses broke down across three chains:

Ethereum (~$10.1 million):

Sums referenced in this case file
  • 97 million SHIBA tokens
  • $3.7 million in USDT
  • 1,378 ETH

All of the Ethereum-side assets were converted into ETH shortly after being taken.

Bitcoin: 41 BTC, valued at roughly $2.87 million, was also drained.

Solana: additional funds were removed via Solana as well, though these transfers have proven harder to trace on-chain.

Attacker-controlled addresses:

The bulk of the stolen assets currently sit in two wallets: roughly $10.1 million in ETH at 0x968b6984cba14444f23ee51be90652408155e142, and about $2.87 million in BTC at bc1qu4kh7wa38xpkrp8frgxl4sak88wx0jug8n3vfj.

03M2's response

M2's official update claimed the multi-chain exploit was detected, contained, and resolved within 16 minutes — a turnaround time that has drawn skepticism given the scale and cross-chain nature of the attack.

The statement said: "We would like to report that the situation has been fully resolved and customer funds have been restored." M2 added that it had "taken full responsibility for any potential losses" and reaffirmed its "unwavering commitment to safeguarding customers' interests."

Beyond those assurances, the statement offered few specifics on the underlying security failure, focusing instead on service restoration and promises of additional controls going forward. M2 also said it would cooperate with "relevant legal and regulatory authorities."

04Open questions

Despite M2's framing of the incident as resolved, the roughly $13 million in assets identified above remain in attacker-controlled wallets and have not moved since the theft. The gap between the exchange's confident public messaging and the unrecovered funds has fueled doubts about how complete the "resolution" actually was.

M2 Exchange
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.