M2 Hack
What happened
On October 31, 2024, the centralized cryptocurrency exchange M2, endorsed by David O'Leary and based in Abu Dhabi, experienced a hack resulting in a $13.7 million loss from multiple hot wallets.
The October 31 attack targeted M2’s hot wallets, resulting in the unauthorized transfer of Bitcoin, Ether, and Solana assets valued at nearly $13.7 million. According to on-chain investigator ZachXBT, the breach was carried out by attackers leveraging a vulnerability within the exchange’s online wallet infrastructure. The stolen assets were transferred away from M2’s wallets over a brief period, despite the exchange's swift response to prevent further escalation.
M2 immediately suspended affected wallets, activated additional security controls, and restored user funds, resuming normal operations shortly after. This quick action limited the duration of exposure, though the initial vulnerability remains under investigation, with further insights expected as M2 collaborates with cybersecurity and law enforcement agencies.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report explore.m2.com
- report Report twitter.com
- report Report cointelegraph.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.