M2 Exchange hack — October 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 1, 2024 |
| Target type | Centralised exchange |
| Loss | $13,700,000Price at time of incident |
| Method | Other or undisclosedSimultaneous draining of hot wallets on Bitcoin, Ethereum and Solana. M2 never published a root cause. QuillAudits characterised it as an access-control failure in M2's hot wallet infrastructure, but presented that as an inference, not something M2 confirmed. Recorded as 'other' because no source establishes the mechanism. |
| Chains | Bitcoin, Ethereum, Solana |
| Outcome | Users reimbursed |
What happened
On 31 October 2024 at about 03:16 local time (UTC+4), attackers drained hot wallets belonging to M2, an Abu Dhabi-based exchange and custodian licensed by the ADGM Financial Services Regulatory Authority. Roughly $13.7 million in customer assets was taken in a coordinated sweep that hit wallets on Bitcoin, Ethereum and Solana at the same time.
M2 said it contained the incident within 16 minutes, at 03:32, and published a notice stating that "the situation has been fully resolved and customer funds have been restored", adding that it had "taken full responsibility for any potential losses". The exchange did not disclose how the wallets were compromised and published no technical post-mortem. The security firm QuillAudits described the event as an access-control failure in M2's hot wallet infrastructure, but framed that as an inference rather than a confirmed cause. The simultaneous loss of wallets on three unrelated chains is the only concrete signature available publicly.
Customer balances were made whole out of M2's own reserves, not by recovering the stolen assets. Blockchain investigator ZachXBT flagged the theft publicly, and the analytics firm Cyvers traced the flows, reporting that the proceeds were consolidated into ether and that around $10 million was still sitting unmoved in attacker-controlled Ethereum addresses several days later.
The $13.7 million figure is consistent across all reporting and was not disputed. No actor has been named and no arrests have been reported. The speed of the stated resolution and the absence of any technical account drew scepticism from researchers at the time.
Law enforcement
M2 said it was 'actively cooperating with relevant legal and regulatory authorities'. The firm is licensed as a trading platform and custodian by the Financial Services Regulatory Authority in Abu Dhabi Global Market. No arrests or charges have been reported.
Sources
- CryptoSlateSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
- ProtosSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "M2 Exchange hack — October 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/m2-exchangehttps://itokenly.com/hacks/m2-exchangePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.