{"investigation":{"slug":"m2-exchange","entity_name":"M2 Exchange","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"M2 Exchange is an Abu Dhabi-based centralized cryptocurrency exchange licensed by the ADGM FSRA that suffered a $13.7 million hot wallet breach on October 31, 2024, attributed to an access control vulnerability spanning Bitcoin, Ethereum, and Solana. The exchange claims to have covered all customer losses from company reserves within hours of the incident, though the lack of a public post-mortem and two CEO transitions within eighteen months raise unresolved transparency questions.","sections":[{"content":"M2 Exchange (operating at m2.com) launched in October 2023 as a centralized crypto trading and custody platform headquartered in Abu Dhabi, United Arab Emirates. The platform targets both retail and institutional clients across more than 150 countries, excluding the United States. Co-founders include Bijan Alizadeh-Fard, who also co-founded Abu Dhabi-based venture firms Phoenix Group and Cypher Capital, and Stefan Kimmel, formerly of Kraken and the Commercial Bank of Dubai. The exchange offers spot trading, perpetual futures, earn products, staking, margin trading, an OTC desk, crypto loans, and institutional custody services across more than 50 listed assets. Its native utility token is MMX, which has a fixed supply of 500 million tokens and was audited by CertiK. M2 holds ADGM Financial Services Permission under two registered entities: M2 Limited (registration 220090) and M2 Custody Limited (registration 220130). Custody infrastructure is integrated with Fireblocks, an institutional MPC custody provider. The platform experienced two CEO transitions within its first eighteen months: Stefan Kimmel moved to the board in late 2024, succeeded by Saadeddine Zaher, who was in turn succeeded by James Greenwood, formerly Chief Technology and Operations Officer at Bitstamp.","heading":"Background","sources":[{"url":"https://beincrypto.com/learn/m2-review/","name":"","type":"other","credibility":3},{"url":"https://www.adgm.com/media/announcements/virtual-assets-trading-platform-m2-receives-financial-services-permission-from-adgm","name":"","type":"other","credibility":3},{"url":"https://www.fintechfutures.com/job-cuts-new-hires/crypto-platform-m2-reshuffles-leadership-with-ex-bitstamp-exec-james-greenwood-named-ceo","name":"","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/m2-exchange","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 31, 2024, at approximately 3:16 AM local time, an attacker exploited an access control vulnerability in M2's hot wallet infrastructure, draining approximately $13.7 million across Bitcoin, Ethereum, and Solana. The stolen assets comprised roughly $3.7 million in USDT, 97 million SHIB tokens, and 1,378 ETH. On-chain analysts identified the primary Ethereum hot wallet as 0xE26abc37b06B819243B4B104270Cc18f7C835FcE; funds were routed to an intermediate address (0xb5f798096bd4D969466E2284Bda01F7A51049d3A) and then consolidated at 0x968b6984cba14444f23ee51be90652408155e142. Corresponding Bitcoin and Solana addresses were also implicated. The attacker swapped SHIB and USDT into ETH on Ethereum, a common obfuscation step, and as of November 4, 2024, approximately $10 million in ETH remained unmixed and stationary in the attacker's wallets. M2 stated the vulnerability was remediated within 16 minutes of detection; the exchange covered all customer losses from company reserves rather than recovering the stolen assets, and said it was cooperating with UAE legal and regulatory authorities. No post-mortem was published, no independent audit of the remediation was released, and as of mid-2025 no arrests or attribution have been publicly reported. Security firm Cyvers flagged the incident as consistent with an absence of multi-factor authentication and multi-signature controls on the hot wallet layer.","heading":"The Hack","sources":[{"url":"https://cryptoslate.com/uaes-m2-crypto-exchange-hacked-for-13-7m-assures-full-fund-recovery/","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/m2-crypto-exchange-exploit","name":"","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/m2-hack","name":"","type":"other","credibility":3},{"url":"https://protos.com/crypto-exchange-m2-reimburses-victims-after-14m-halloween-hack/","name":"","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/m2-exchange-reports-hack-restores-13-7m-in-eth-sol-and-btc/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"M2 Exchange operates under a Financial Services Permission (FSP) granted by the Financial Services Regulatory Authority (FSRA) of the Abu Dhabi Global Market (ADGM), dated August 16, 2023. The permission authorizes M2 to operate a multilateral trading facility (MTF) and to provide virtual asset custody services to retail and institutional clients in the UAE. ADGM/FSRA is distinct from Dubai's Virtual Assets Regulatory Authority (VARA); M2 holds no known VARA license. The FSRA framework requires client asset segregation and adherence to financial services standards comparable to those applied to traditional asset classes. M2's two registered entities (M2 Limited and M2 Custody Limited) provide a structural separation between trading and custody activities. Following the October 2024 breach, M2 stated it was cooperating with UAE legal and regulatory authorities, but no public statement from the FSRA or any other regulator regarding the incident or any enforcement action has been identified. M2 is not registered or licensed in the United States and explicitly excludes US persons from its services.","heading":"Regulatory Status","sources":[{"url":"https://www.adgm.com/media/announcements/virtual-assets-trading-platform-m2-receives-financial-services-permission-from-adgm","name":"","type":"other","credibility":3},{"url":"https://www.adgm.com/media/announcements/m2-secures-adgm-licence-and-plans-rollout-of-fully-regulated-crypto-services-to-uae","name":"","type":"other","credibility":3},{"url":"https://www.thenationalnews.com/business/money/2023/10/11/adgm-licensed-m2-crypto-platform-rolls-out-services-for-investors/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"M2 states that client funds are segregated from company operational assets and that digital assets are stored predominantly in cold storage via Fireblocks-integrated MPC custody. The exchange claims to conduct external security audits, and its MMX token contract was audited by CertiK. Following the October 2024 hack, M2 covered all affected customer balances from company reserves, avoiding any customer loss. However, M2 has not published a proof-of-reserves report, and no independent verification of its solvency or the completeness of customer fund coverage post-hack is publicly available. The exchange does not appear to carry publicly disclosed insurance covering customer assets against future hacks. The 16-minute remediation claim has not been independently verified; the attacker's wallets still held approximately $10 million in ETH as of November 4, 2024, suggesting the breach was contained by isolating infrastructure rather than recovering stolen assets. M2 has not disclosed what specific access controls were added post-incident. Customer support is limited to non-telephone channels. Two CEO transitions within the platform's first eighteen months represent ongoing leadership instability that may affect operational continuity.","heading":"User Protections","sources":[{"url":"https://beincrypto.com/learn/m2-review/","name":"","type":"other","credibility":3},{"url":"https://www.ccn.com/news/crypto/crypto-exchange-m2-security-breach/","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/m2-crypto-exchange-exploit","name":"","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/m2-exchange","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"M2 Exchange presents an elevated risk profile relative to major global centralized exchanges, primarily due to the confirmed $13.7 million hot wallet breach in October 2024 and the unresolved transparency gaps that followed. Key risk factors include: (1) a proven hot wallet security failure attributed to absent multi-factor authentication and inadequate access controls, with no public post-mortem published; (2) no publicly disclosed proof of reserves or independent solvency verification; (3) no publicly disclosed insurance fund for customer assets; (4) two CEO transitions within approximately eighteen months of launch, suggesting potential strategic instability; (5) stolen funds largely unrecovered and attacker unidentified as of available reporting. Mitigating factors include M2's active ADGM/FSRA license — one of the more rigorous crypto regulatory regimes in the Gulf — client asset segregation policy, Fireblocks MPC custody integration, and the exchange's decision to cover all customer losses from company reserves following the breach. Retail users should note that no formal deposit protection scheme (analogous to FDIC or FSCS) applies to crypto held on M2. The exchange is a legitimate, licensed entity, not a scam or exit-fraud operation, but the combination of a recent major security failure, limited post-incident transparency, and leadership churn warrants caution for users holding significant balances.","heading":"Risk Assessment","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/m2-crypto-exchange-exploit","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/uaes-m2-crypto-exchange-hacked-for-13-7m-assures-full-fund-recovery/","name":"","type":"other","credibility":3},{"url":"https://www.adgm.com/media/announcements/virtual-assets-trading-platform-m2-receives-financial-services-permission-from-adgm","name":"","type":"other","credibility":3},{"url":"https://www.fxleaders.com/news/2024/11/02/crypto-exchange-m2-recovers-13-7-million-after-breach-resolved-in-16-minutes/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-08-16","event":"ADGM FSRA grants M2 Limited and M2 Custody Limited Financial Services Permission to operate an MTF and custody service in Abu Dhabi.","source":""},{"date":"2023-10","event":"M2 Exchange publicly launches retail and institutional services, initially offering BTC and ETH trading with AED fiat pairs.","source":"","date_original":"2023-10-01"},{"date":"2024-10-15","event":"Stefan Kimmel steps down as CEO and moves to the M2 Board of Directors; Saadeddine Zaher appointed CEO.","source":""},{"date":"2024-10-31","event":"Attacker exploits hot wallet access control vulnerability at approximately 3:16 AM, draining ~$13.7M across Bitcoin, Ethereum, and Solana chains.","source":""},{"date":"2024-10-31","event":"M2 claims the breach was contained within 16 minutes; exchange covers all customer losses from company reserves and states services are restored.","source":""},{"date":"2024-11","event":"M2 issues public statement confirming the incident, stating cooperation with UAE legal and regulatory authorities and implementing enhanced security controls.","source":"","date_original":"2024-11-01"},{"date":"2024-11-04","event":"On-chain analysts confirm approximately $10 million in ETH remains unmixed in the attacker's consolidation wallet; no attacker identified.","source":""},{"date":"2025","event":"James Greenwood, former CTOO of Bitstamp, named CEO of M2, marking a second CEO transition within the platform's first fifteen months.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://beincrypto.com/learn/m2-review/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.adgm.com/media/announcements/virtual-assets-trading-platform-m2-receives-financial-services-permission-from-adgm","name":"","type":"other","archive_url":"http://web.archive.org/web/20260307081704/https://www.adgm.com/media/announcements/virtual-assets-trading-platform-m2-receives-financial-services-permission-from-adgm","credibility":3,"archive_timestamp":"2026-03-07T08:17:04+00:00"},{"url":"https://www.fintechfutures.com/job-cuts-new-hires/crypto-platform-m2-reshuffles-leadership-with-ex-bitstamp-exec-james-greenwood-named-ceo","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://skynet.certik.com/projects/m2-exchange","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829041010/https://skynet.certik.com/projects/m2-exchange","credibility":3,"archive_timestamp":"2026-08-29T04:10:10+00:00"},{"url":"https://cryptoslate.com/uaes-m2-crypto-exchange-hacked-for-13-7m-assures-full-fund-recovery/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260509225253/https://cryptoslate.com/uaes-m2-crypto-exchange-hacked-for-13-7m-assures-full-fund-recovery/","credibility":3,"archive_timestamp":"2026-05-09T22:52:53+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/m2-crypto-exchange-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260515112654/https://www.quillaudits.com/blog/hack-analysis/m2-crypto-exchange-exploit","credibility":3,"archive_timestamp":"2026-05-15T11:26:54+00:00"},{"url":"https://www.web3isgoinggreat.com/single/m2-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20251124180853/https://www.web3isgoinggreat.com/single/m2-hack","credibility":3,"archive_timestamp":"2025-11-24T18:08:53+00:00"},{"url":"https://protos.com/crypto-exchange-m2-reimburses-victims-after-14m-halloween-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609153802/https://protos.com/crypto-exchange-m2-reimburses-victims-after-14m-halloween-hack/","credibility":3,"archive_timestamp":"2026-06-09T15:38:02+00:00"},{"url":"https://www.cryptopolitan.com/m2-exchange-reports-hack-restores-13-7m-in-eth-sol-and-btc/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829085327/https://www.cryptopolitan.com/m2-exchange-reports-hack-restores-13-7m-in-eth-sol-and-btc/","credibility":3,"archive_timestamp":"2026-08-29T08:53:27+00:00"},{"url":"https://www.adgm.com/media/announcements/m2-secures-adgm-licence-and-plans-rollout-of-fully-regulated-crypto-services-to-uae","name":"","type":"other","archive_url":"http://web.archive.org/web/20260611065234/https://www.adgm.com/media/announcements/m2-secures-adgm-licence-and-plans-rollout-of-fully-regulated-crypto-services-to-uae","credibility":3,"archive_timestamp":"2026-06-11T06:52:34+00:00"},{"url":"https://www.thenationalnews.com/business/money/2023/10/11/adgm-licensed-m2-crypto-platform-rolls-out-services-for-investors/","name":"","type":"other","archive_url":"http://web.archive.org/web/20250926105414/https://www.thenationalnews.com/business/money/2023/10/11/adgm-licensed-m2-crypto-platform-rolls-out-services-for-investors/","credibility":3,"archive_timestamp":"2025-09-26T10:54:14+00:00"},{"url":"https://www.ccn.com/news/crypto/crypto-exchange-m2-security-breach/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.fxleaders.com/news/2024/11/02/crypto-exchange-m2-recovers-13-7-million-after-breach-resolved-in-16-minutes/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829085736/https://www.fxleaders.com/news/2024/11/02/crypto-exchange-m2-recovers-13-7-million-after-breach-resolved-in-16-minutes/","credibility":3,"archive_timestamp":"2026-08-29T08:57:36+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.958961+00:00","updated_at":"2026-08-30T12:05:02.12161+00:00"}}