Skip to content
Yieldo

Coincheck

$534.0M
Funds stolen
Funds returned
26 Jan 2018
Date of incident
Technique
Hot Wallet Key Compromised
Classification
Key Compromise
Target type
CEX
Affected chains
NEM
Source
No public source link

On January 26, 2018, Coincheck, one of Japan's largest cryptocurrency exchanges, discovered that 523 million NEM tokens (XEM), worth roughly $534 million at the time, had been drained from its systems overnight. It remains one of the largest single thefts in crypto history, and Coincheck later confirmed the funds had left through a single wallet connected to the internet (Cointelegraph).

How the attack worked

Coincheck held its entire NEM balance, customer funds included, in a single hot wallet: a wallet whose private key lived on internet-connected infrastructure rather than offline. Unlike its Bitcoin and Ether holdings, which sat in cold storage, and in Bitcoin's case behind a multisignature address, NEM had neither cold storage nor multisig protection (Cointelegraph). Whoever carried out the attack obtained the private key to that wallet and used it to sign a series of transactions moving all 523 million XEM out at roughly 02:57 local time. Staff did not notice the outflow until 11:25 that morning, almost eight and a half hours later (BBC News).

Neither Coincheck nor investigators ever published how the key itself was obtained: no malware sample, phishing email, or compromised vendor was named publicly. What is documented is the structural failure: a single point of custody with no second-signature requirement, holding half a billion dollars of a fairly liquid altcoin.

Because NEM is a fully public blockchain, the destination of the stolen funds was visible on-chain immediately. Within a day, NEM's developers shipped an automated system tagging the stolen coins, and any address they touched, as tainted, giving cooperating exchanges a way to detect and block deposits of the funds. NEM Foundation vice president Jeff McDonald and the project explicitly ruled out a hard fork to claw the funds back, arguing the blockchain itself had done nothing wrong (Cointelegraph).

What happened next

The tagging slowed but did not stop the laundering: over the following months an estimated 40–50% of the stolen XEM moved off-chain through darknet channels, reportedly at around a 15% discount for Bitcoin, and NEM Foundation eventually wound the tracking effort down (Distributed Networks Institute; Bitcoin Insider). None of the stolen NEM was ever recovered from the attackers.

Coincheck compensated all roughly 260,000 affected users from its own corporate balance sheet, about 46.6 billion yen (roughly $440 million at the payout-date rate), a fixed amount independent of whether the coins themselves were ever clawed back (Bitcoin Insider). Japan's Financial Services Agency ordered the exchange to overhaul its security practices but did not force a shutdown; in April 2018 Monex Group acquired Coincheck for 3.6 billion yen (Wikipedia). The intruders who breached Coincheck's systems were never identified. Japanese authorities later charged dozens of individuals in separate cases for knowingly buying the tainted, discounted XEM through darknet markets, money-laundering charges distinct from the original breach (Wikipedia; Distributed Networks Institute).

What this means

  • A single hot wallet without multisignature is a single point of failure regardless of the underlying blockchain: the NEM protocol itself was never implicated, and the same design mistake could occur with any asset.
  • Custody architecture — hot vs cold, single-sig vs multisig — is invisible to depositors from outside; Coincheck disclosed the split only after the loss, so there was no way for a user to know NEM was treated differently from Bitcoin on the same platform.
  • Post-theft tagging works only where the chain is public and exchanges cooperate voluntarily; it does not stop over-the-counter or darknet laundering, which is why a large share of the funds still disappeared despite the tooling.
  • Full compensation is a company choice enabled by balance-sheet strength and regulatory pressure, not a guarantee: it came from Coincheck's own capital, not from recovered funds, and other exchanges hit by comparable losses have not always matched it.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.