Indodax Hack
What happened
Indodax suffered an apparent hot-wallet breach in September 2024. Blockchain security reporting placed the outflow at more than $20 million across several networks. Indodax suspended services and said it was working with external cybersecurity investigators; it later said customer balances and reserves remained fully covered.
Insufficiently protected or otherwise compromised hot-wallet operational controls allowed unauthorized withdrawals. The exact access path remains undisclosed. This distinction matters because exchange custody failures can occur without a disclosed blockchain-contract bug.
How it happened
- Investigators identified unauthorized transfers from Indodax hot-wallet infrastructure across several networks.
- The exchange suspended services while it investigated the breach.
- Indodax said it engaged external cybersecurity investigators and later said customer balances and reserves remained covered.
- The public evidence does not establish whether the initial route involved leaked keys, phishing, malware, or another operational failure.
Protocol details
Evidence
- report Report news.bitcoin.com
- report @CryptoCatVC incident report x.com
- report @tayvano_ incident report x.com
- analysis Website reference cointelegraph.com
- analysis DeFiLlama defillama.com
- analysis INDODAX: Update Maintenance & Proof of Reserve blog.indodax.com
- analysis The Block: Indonesian exchange Indodax faces $20 million loss theblock.co
- analysis Bappebti media brief on alleged Indodax hack bappebti.go.id
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.