ApeX Says Social-Engineering Attack Reached Legacy Reward Wallet
INDODAX has temporarily suspended deposits and withdrawals of ApeX Protocol’s APEX token after ApeX disclosed that an attacker gained control of a key stored on a former team member’s device and used it to convert reward tokens into APEX.
The Indonesian crypto exchange announced the restriction on September 10, saying it had temporarily closed APEX deposit and withdrawal functionality to protect customer transactions and assets. INDODAX directly referred customers to ApeX Protocol’s announcement about the underlying incident and said transfers would resume once it considered the service safe to operate again.
INDODAX did not announce a suspension of APEX trading in the notice.
The exchange’s action followed a September 9 statement from ApeX that disclosed a compromise involving a wallet connected to its older Trade-to-Earn Season 1 program.
ApeX said the incident occurred after a former team member’s device was targeted through social engineering. According to the project, the attacker obtained access to a key that remained on the device and then used it to redeem BANANA reward tokens for APEX through the Season 1 contract.
ApeX stressed that the incident was not caused by a vulnerability in its smart contracts.
“No ApeX contract was hacked, no code was broken,” the project said, adding that the relevant contract executed according to its existing design. ApeX said its trading platform and user funds were unaffected.
The project has since revoked the compromised key and flagged addresses associated with the attacker to exchanges and blockchain-monitoring partners.
More significantly, ApeX said it is reviewing its offboarding and key-management procedures following the incident. A full post-mortem is expected after that review is completed.
That review could become the most important part of the episode because the affected credential appears to have remained usable after the team member associated with the device had left the organization.
ApeX has not yet publicly explained when the employee departed, why the relevant key remained on the device, whether it should have been revoked during offboarding, how long the credential remained active or what controls governed access to the reward contract.
It has also not disclosed in its initial statement the total amount of BANANA redeemed or the resulting quantity and value of APEX obtained by the attacker.
The affected mechanism traces back to ApeX’s Trade-to-Earn reward programs.
ApeX launched the second iteration of Trade-to-Earn in January 2024, distributing BANANA tokens to users based on their trading activity. The project said at the time that 10 million APEX tokens were locked for 12 months to support a supply of 10 billion BANANA, initially at a redemption rate of 0.001 APEX per BANANA.
When the program later migrated to ApeX Omni, traders continued receiving BANANA through a series of biweekly reward periods. Users could exchange BANANA for USDT, provide it as liquidity or hold the tokens for eventual redemption into APEX.
That structure matters because the wallet involved in this week’s incident was therefore connected to a system capable of turning an incentive token into the protocol’s primary APEX token.
ApeX has since substantially changed its platform and incentive programs. ApeX Omni now operates as the project’s main decentralized trading platform, offering perpetual contracts, stock-related products, vaults and prediction-market products. ApeX’s website currently reports more than $687 billion in cumulative trading volume.
The project has emphasized that the latest compromise did not affect the current trading system or user custody arrangements. ApeX describes Omni as non-custodial, meaning users retain control over their assets rather than depositing them into a conventional centralized exchange wallet.
INDODAX nevertheless opted to halt APEX transfers while the incident is being investigated.
The Indonesian platform says it has more than 9.8 million registered members and lists more than 490 crypto assets against the rupiah. Its September 10 notice did not provide a timetable for restoring APEX deposits and withdrawals, saying only that access would reopen when operations could safely resume.
As of September 10, searches of other major exchange notices did not identify a comparable broad wave of APEX deposit and withdrawal suspensions linked to the incident.
The Bigger Failure May Have Happened During Offboarding
The important question here is not whether ApeX’s smart contracts worked.
According to ApeX, they did.
The more uncomfortable question is why a former team member’s device still contained a credential capable of interacting meaningfully with a token-redemption system.
That shifts the incident away from the familiar DeFi story of vulnerable code and toward something much more conventional: access control.
When an employee or contractor leaves a company, disabling email and workplace accounts is only part of the job. In a crypto organization, offboarding can also mean rotating private keys, removing multisig signers, invalidating API credentials, recovering hardware devices, revoking cloud permissions and identifying every contract or wallet to which that person once had access.
A missed key can be more dangerous than a missed password because blockchain systems frequently assume that possession of the correct cryptographic credential is sufficient authorization.
The contract cannot know that the person behind a valid signature left the company six months earlier.
That appears to be the central issue ApeX now needs to explain.
The attacker apparently did not force the contract to do something it was never supposed to do. ApeX says the attacker obtained a valid key and the Season 1 contract then performed its intended BANANA-to-APEX redemption function.
In security terms, that distinction is important.
Smart-contract audits are designed to identify failures in code. They do little to protect a protocol when a valid administrative or operational credential remains somewhere it should no longer exist.
The age of the reward program makes the incident more interesting.
Crypto projects frequently move rapidly from one incentive structure to another. Campaigns finish, products migrate and teams change, but the underlying contracts, wallets and privileges can remain onchain indefinitely unless someone deliberately decommissions them.
ApeX’s earlier Trade-to-Earn architecture illustrates the stakes. BANANA was not simply a promotional point displayed inside an app. The program was built around real APEX being locked to support eventual redemption of BANANA into APEX.
That means “legacy” infrastructure can still have financial consequences long after the campaign that created it has stopped being prominent.
INDODAX’s response is therefore understandable even though ApeX says customer funds and trading were unaffected. An exchange accepting deposits has to consider whether compromised or improperly redeemed tokens could be sent onto its platform before the full scope of the incident is understood.
The most useful information will come from ApeX’s promised post-mortem.
It should explain when the employee left, what authority the compromised key actually carried, why that authority survived departure, how much APEX was redeemed, whether other former employees or dormant devices retain similar credentials and whether the project has now performed a broader key-rotation audit.
Until those questions are answered, calling the incident merely a social-engineering attack describes how the attacker got in, but not why the door was still capable of opening.
The deeper issue is whether ApeX’s offboarding process failed to remove access that should have disappeared the moment that team member left.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

