{"investigation":{"slug":"m2","entity_name":"M2","trust_score":39,"severity_base":null,"score_modifier":-10,"confidence":1,"status":"published","content_type":"investigation","summary":"M2 is a UAE-based cryptocurrency exchange licensed by the Abu Dhabi Global Market (ADGM) Financial Services Regulatory Authority, operating as a regulated Multilateral Trading Facility and custodian since late 2023. On October 31, 2024, the exchange suffered a $13.7 million hot wallet breach attributed to an access control vulnerability across the Bitcoin, Ethereum, and Solana networks. M2 subsequently reimbursed all affected customers from its own assets and stated it had engaged law enforcement and regulatory authorities.","sections":[{"content":"M2 was founded in 2023 and is headquartered in Abu Dhabi, UAE. It operates as M2 Limited and M2 Custody Limited, both licensed by the Financial Services Regulatory Authority (FSRA) within the Abu Dhabi Global Market (ADGM) free zone. The ADGM license was granted on November 28, 2023, recognizing M2 as a fully regulated Multilateral Trading Facility (MTF) and custodian — one of the stricter virtual asset frameworks in the MENA region. The exchange offers spot trading, virtual asset custody (including offline cold storage), and AED fiat on/off-ramp services. M2 claims to serve customers in more than 150 countries. Co-founder Bijan Alizadeh-Fard also co-founded Phoenix Group and Cypher Capital. The exchange has had multiple CEO tenures; Stefan Kimmel (formerly Kraken MENA) served as early CEO, with James Greenwood subsequently taking the role alongside Bill Qian as Managing Director.","heading":"Company Background","sources":[],"severity":"medium"},{"content":"On October 31, 2024, at approximately 3:16 AM (GMT+4), M2's hot wallets were drained across three blockchain networks — Bitcoin, Ethereum, and Solana — in an incident first detected and publicly reported by blockchain security firm Cyvers and on-chain investigator ZachXBT. Total losses were estimated at approximately $13.7 million. The stolen assets included approximately 1,378 ETH, 97 million SHIB tokens, and $3.7 million in USDT. The attacker consolidated the drained altcoins by swapping SHIB and USDT into ETH; approximately $10 million in ETH remained on the Ethereum network at the time of detection. On-chain addresses associated with the exploit include Ethereum origin address 0xE26abc37b06B819243B4B104270Cc18f7C835FcE, intermediate EOA 0xb5f798096bd4D969466E2284Bda01F7A51049d3A, primary Ethereum consolidation address 0x968b6984cba14444f23ee51be90652408155e142, Bitcoin address bc1qu4kh7wa38xpkrp8frgxl4sak88wx0jug8n3vfj, and Solana address EKko14NvgqdvNttUb8JjXkVGuUs6BTikjfN3hqW4LQoL. M2 stated it detected the breach and responded within 16 minutes, at 3:32 AM.","heading":"October 2024 Hot Wallet Breach","sources":[],"severity":"medium"},{"content":"Security researchers and analysts attributed the breach to an access control vulnerability in M2's hot wallet infrastructure. The flaw allegedly allowed an attacker to bypass standard authorization checks and initiate unauthorized withdrawal transactions without triggering multi-factor authentication (MFA) or multi-signature (multi-sig) approval requirements. QuillAudits noted in its post-mortem analysis that the absence of MFA and multi-sig controls on the hot wallets were contributing factors. The attacker's first transaction moved funds from M2's hot wallet to an externally owned account (EOA), from which funds were distributed across multiple addresses before consolidation. M2 did not publicly disclose the precise technical root cause in its official statements, describing the event only as a 'cybersecurity incident.'","heading":"Access Control Vulnerability","sources":[],"severity":"medium"},{"content":"On-chain investigator ZachXBT was among the first to publicly report the M2 hack, flagging the suspicious fund movements before M2 issued an official statement. Blockchain security firm Cyvers independently detected the anomalous transactions and provided initial on-chain data, identifying the three compromised wallet addresses across Bitcoin, Ethereum, and Solana. ZachXBT's public flagging of the incident is consistent with his pattern of monitoring exchange wallets and alerting the community to active drains. M2's official acknowledgment on November 1, 2024 confirmed the breach and stated that it had contacted police and relevant legal authorities.","heading":"ZachXBT and Cyvers On-Chain Detection","sources":[],"severity":"medium"},{"content":"On November 1, 2024, M2 announced that all affected customer funds had been 'fully restored,' with the exchange assuming full financial responsibility for the losses rather than recovering the stolen assets themselves. M2 stated it had 'implemented enhanced security controls' and was cooperating with law enforcement and regulatory authorities. The claim of detecting and resolving the breach within 16 minutes drew skepticism from portions of the crypto security community, given the scale of funds drained and the absence of detailed technical disclosure. The reimbursement was funded by M2's own reserves, not from asset recovery.","heading":"Reimbursement and Response","sources":[],"severity":"medium"},{"content":"M2 operates within the ADGM free zone under FSRA supervision, which requires compliance with technology governance, market surveillance, and consumer protection standards. The ADGM framework is considered one of the more rigorous virtual asset regimes in the MENA region. The October 2024 hack occurred approximately one year after M2 received its ADGM license, raising questions about whether the exchange's hot wallet security posture was consistent with its regulated status. M2 stated it engaged police and legal authorities following the breach, consistent with ADGM reporting obligations. No public regulatory enforcement action against M2 has been reported as of the time of this investigation.","heading":"UAE Regulatory Context","sources":[],"severity":"medium"}],"timeline":[{"date":"2023-11-28","event":"M2 receives ADGM license from the FSRA, recognized as a regulated Multilateral Trading Facility and custodian.","source":"","source_url":"https://www.adgm.com/media/announcements/m2-secures-adgm-licence-and-plans-rollout-of-fully-regulated-crypto-services-to-uae"},{"date":"2024-10-31","event":"M2 hot wallets drained of approximately $13.7 million across Bitcoin, Ethereum, and Solana networks at approximately 3:16 AM GMT+4. ZachXBT and Cyvers publicly identify suspicious transactions.","source":"","source_url":"https://cryptoslate.com/uaes-m2-crypto-exchange-hacked-for-13-7m-assures-full-fund-recovery/"},{"date":"2024-10-31","event":"M2 states it detected the breach and responded within 16 minutes (by 3:32 AM), implementing emergency controls.","source":"","source_url":"https://www.fxleaders.com/news/2024/11/02/crypto-exchange-m2-recovers-13-7-million-after-breach-resolved-in-16-minutes/"},{"date":"2024-11","event":"M2 officially announces the breach has been resolved, all affected customer funds fully restored from exchange reserves, and that law enforcement and legal authorities have been engaged.","source":"","source_url":"https://protos.com/crypto-exchange-m2-reimburses-victims-after-14m-halloween-hack/","date_original":"2024-11-01"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:00.394138+00:00","updated_at":"2026-08-29T01:35:56.031+00:00"}}