Indonesian cryptocurrency exchange Indodax has fallen victim to a sophisticated security breach that resulted in the theft of approximately $22 million worth of digital assets. The attack, which struck early on September 10, 2024, targeted the exchange’s hot wallets across multiple blockchain networks, exposing critical vulnerabilities in centralized custody systems. At the time of the breach, Bitcoin was trading at approximately $57,648 and Ethereum around $2,389, underscoring the significant value at risk in the current market environment.
The Exploit Mechanics
The attack on Indodax was characterized by its multi-chain coordination, a hallmark of increasingly sophisticated threat actors in the cryptocurrency space. Security researchers from Merkle Science confirmed that the hackers simultaneously compromised hot wallets on Ethereum, Polygon, Tron, Bitcoin, and Optimism networks. The stolen assets included over $14 million in Ethereum-based tokens, $2.4 million in TRX, approximately $1.5 million in Bitcoin representing 26.25 BTC, $2.5 million in MATIC, and $870,000 worth of ETH on the Optimism network.
What made this attack particularly notable was the laundering strategy employed by the perpetrators. Rather than converting stolen tokens into stablecoins such as USDT or USDC — a common tactic seen in previous exchange hacks — the attackers opted to swap assets for native tokens like ETH, TRX, and POL. This shift in methodology reflects the increased scrutiny and blacklisting efforts by Tether and other stablecoin issuers, making stablecoin conversion a significantly riskier proposition for malicious actors seeking to cash out.
The synchronized nature of the multi-chain attack indicates a well-strategized and premeditated operation. The attackers had clearly mapped out Indodax’s hot wallet infrastructure across all supported networks and executed their exploit with precise timing to maximize the haul before detection systems could trigger alerts.
Affected Systems
Indodax is one of Indonesia’s largest cryptocurrency exchanges and a key player in the Southeast Asian digital asset market. According to Arkham Intelligence data, the exchange’s wallets still held over $400 million in various tokens even after the breach, suggesting that while the attack was severe, it did not drain the entire reserve. The exchange had recorded $11 million in trading volume on the day prior to the attack, indicating active and healthy market participation before the incident.
The breach prompted an immediate and complete halt of all platform operations. Indodax initially announced the shutdown as scheduled “maintenance,” though the true nature quickly became apparent as on-chain analysts began tracing the movement of stolen funds across multiple blockchains. Compounding concerns about the depth of the compromise, suspicious activity was also detected on Indodax’s social media channels, including a dubious giveaway announcement posted on Instagram, suggesting the security failure may have extended beyond financial infrastructure into the exchange’s communications systems.
The Mitigation Strategy
Indodax’s incident response involved several critical steps executed in rapid succession. The exchange immediately froze withdrawals from all compromised hot wallets and initiated emergency transfers of remaining funds to secure cold storage facilities. Within days, Indodax publicly committed to fully reimbursing all affected users from its own reserves, a move designed to preserve user trust and comply with regulatory expectations in Indonesia’s increasingly regulated crypto market.
Blockchain forensics teams from Merkle Science and CertiK were quickly engaged to trace the flow of stolen funds. Their analysis revealed that swap services were extensively used to convert stolen tokens into native tokens with higher liquidity, providing investigators with valuable on-chain evidence that could aid in recovery efforts and potential attribution of the attack.
Lessons Learned
The Indodax hack reinforces several critical security principles that the cryptocurrency industry continues to learn at significant cost. Hot wallets remain the primary attack vector for exchange breaches, and their exposure should be minimized through automated, frequent sweeps to cold storage. The multi-chain nature of this attack demonstrates that security protocols must be comprehensive across all supported networks, as attackers will target the weakest link in an exchange’s infrastructure. Additionally, the attackers’ strategic shift away from stablecoin laundering provides encouraging evidence that industry-wide blacklisting and tracing efforts are producing measurable changes in criminal behavior.
User Action Required
For Indodax users, the immediate priority is to monitor official communications from the exchange and exercise extreme caution regarding any unsolicited messages, particularly on social media platforms that may have been compromised as part of the broader attack. For the wider cryptocurrency community, this incident reinforces the fundamental principle of self-custody: hardware wallets and multi-signature arrangements remain the gold standard for personal crypto security, and no more funds than necessary for active trading should ever reside on a centralized exchange.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.
26 BTC stolen is barely 1.5 million USD. the rest was in TRX and ERC-20 tokens. feels like the attackers knew exactly which chains had the weakest monitoring
Sanjaya P. targeting TRX and Optimism ETH specifically tells you they studied the deposit patterns. multi-chain but surgical, not opportunistic
Indodax is the largest Indonesian exchange and they still ran multi-chain hot wallets with no cold storage rotation. 22M gone in minutes
26.25 BTC stolen and they could not freeze anything because it was already being swapped across chains within hours. This is exactly why time-locked withdrawals need to become industry standard.
time locked withdrawals would have saved so many people. 24 hour delay is annoying but its better than losing everything
Piotr time locks would help but the real issue is key management. multi-sig with geographic distribution would have prevented the initial compromise
fatima k. is right, key management on multi chain setups always the weak spot here. $22m gone fast.
indodax users finding out about this on twitter before the exchange told them is the most 2024 thing ever
indodax is one of the biggest exchanges in southeast asia and they still had hot wallet security this bad. $22m gone across 5 chains in one attack
salt_miner_ indodax was actually one of the more compliant exchanges in SEA. if they got hit this bad it makes you wonder about the smaller ones nobody audits
se_asia_watch indodax was supposed to be the compliant one. if they got hit this hard the smaller indonesian exchanges must be terrifying
salt_miner_ indodax had 5M+ Indonesian users and still ran hot wallets with no timelock. $22M across ETH, TRX, BTC, MATIC and OP, all gone in one coordinated hit
biggest exchange in southeast asia and still this level of hot wallet exposure is embarrassing
hot wallets across 5 chains all compromised simultaneously. this was coordinated, not some opportunistic grab
chain_hop_ 5 chains in one coordinated strike means their key management was the same across everything. one compromise = total loss. basic opsec failure
chain_hop_grief same key management across 5 chains is the part that kills me. one compromise and everything is gone. basic segregation
chain_hop_grief_ shared key management across 5 chains means one compromise drains everything. basic separation of duties, indodax skipped it entirely
chain_hop_grief shared keys across 5 chains is the textbook definition of single point of failure. mossad level opsec and they skipped multisig
The laundering through swap services is getting faster every year. Recovery chances after 24 hours are basically zero.
swap services speed up the flow but the five chain split still leaves traces on the bigger bridges
five chains drained that fast means the hot wallet keys were exposed for weeks before anyone noticed
shared keys across chains is asking for this exact drain. never again.
14M in ETH tokens, 2.4M in TRX, 1.5M in BTC, 2.5M MATIC, 870k on Optimism. the multi-chain diversification of stolen assets is getting more sophisticated
rekt_archivist numbers line up with the eth and trx moves. swaps are cleaning it quicker now.