Indodax Hack

Reported loss $25.2M
Ethereum Optimism Polygon
Access Control Exploit

What happened

Indodax suffered an apparent hot-wallet breach in September 2024. Blockchain security reporting placed the outflow at more than $20 million across several networks. Indodax suspended services and said it was working with external cybersecurity investigators; it later said customer balances and reserves remained fully covered.

Technical root cause

Insufficiently protected or otherwise compromised hot-wallet operational controls allowed unauthorized withdrawals. The exact access path remains undisclosed. This distinction matters because exchange custody failures can occur without a disclosed blockchain-contract bug.

How it happened

  1. Investigators identified unauthorized transfers from Indodax hot-wallet infrastructure across several networks.
  2. The exchange suspended services while it investigated the breach.
  3. Indodax said it engaged external cybersecurity investigators and later said customer balances and reserves remained covered.
  4. The public evidence does not establish whether the initial route involved leaked keys, phishing, malware, or another operational failure.

Protocol details

Classification Infrastructure / CeFi / Frontend & Infrastructure
Protocol Type CEX
Protocol links Website @indodax

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.