Skip to main content
πŸ“– Tronsell Wiki

Coincheck Hack Explained: The $534 Million NEM Heist

Complete guide to the Coincheck hack β€” understand how $534 million in NEM tokens were stolen, the security failures, the regulatory aftermath in Japan, and the lessons learned for the crypto industry.

πŸ‡―πŸ‡΅ Coincheck Hack at a Glance
Date of Hack January 26, 2018
Tokens Stolen 523 million NEM
Value at Time ~$534M
Exchange Coincheck (Japan)
Key Failure Hot wallet storage
Key Lesson Cold storage is essential

πŸ‡―πŸ‡΅ What Was the Coincheck Hack?

The Coincheck hack was a major security breach that occurred on January 26, 2018, when approximately 523 million NEM tokens (worth about $534 million at the time) were stolen from the Japanese cryptocurrency exchange Coincheck. At the time, it was the largest cryptocurrency theft in history.

Coincheck was one of Japan's largest cryptocurrency exchanges, with millions of users and billions of dollars in trading volume. The hack sent shockwaves through the Japanese crypto industry and prompted a regulatory crackdown by the country's Financial Services Agency (FSA).

πŸ“Œ The Scale of the Theft

523 million NEM tokens stolen. At the time, this was worth approximately $534 million, making it the largest cryptocurrency heist in history (surpassing the Mt. Gox hack). At today's NEM prices, the stolen tokens would be worth significantly less, but the impact on users and the industry was immense.

523M
NEM Tokens Stolen
$534M
Value at Time (2018)
#1
Largest Hack at the Time
2018
Year of Hack

βš™οΈ How the Coincheck Hack Happened

The Coincheck hack was shockingly simple β€” it exploited a fundamental security failure that should have been prevented.

The Attack Vector

Coincheck stored the majority of its NEM tokens in a hot wallet (online) rather than cold storage. Hackers gained access to the hot wallet's private keys and were able to withdraw 523 million NEM tokens over a period of time.

The hack was discovered when users reported that their NEM balances were missing. Coincheck then suspended trading and withdrawals, revealing the massive theft.

πŸ”“Hot Wallet Keys Compromised
β†’
πŸ’ΈNEM Tokens Withdrawn
β†’
⏳Hack Discovered
β†’
⏹️Trading Suspended
⚠️ The Simple Failure

Coincheck kept $534 million worth of NEM tokens in a hot wallet β€” a single point of failure. If the tokens had been stored in cold storage, the hack would have been impossible. This was a basic security oversight that cost users and the company dearly.

πŸ”“ Security Failures at Coincheck

The Coincheck hack exposed several critical security weaknesses that allowed the theft to occur.

❄️
No Cold Storage

Coincheck stored the majority of its NEM tokens in a hot wallet rather than cold storage. This was the primary failure that enabled the hack.

πŸ”‘
Inadequate Private Key Security

The private keys for the hot wallet were not sufficiently secured, allowing hackers to gain access and withdraw funds.

πŸ“Š
Poor Monitoring

The exchange lacked sufficient monitoring to detect the unauthorized withdrawals in real-time.

Over-Reliance on Hot Wallets

Coincheck kept a disproportionate amount of funds in hot wallets, contrary to industry best practices.

πŸ“Š The Hot Wallet Problem

The Coincheck hack is a textbook example of why cold storage is essential. Keeping large amounts of funds in hot wallets creates a single point of failure that hackers can exploit. Reputable exchanges now keep 95%+ of funds in cold storage.

πŸ’₯ The Aftermath: Regulatory Response and Compensation

The Coincheck hack had immediate and long-lasting consequences for the exchange, its users, and the Japanese crypto industry.

User Compensation

Coincheck announced a compensation plan for affected users. The exchange reimbursed users for the stolen NEM tokens at a rate of approximately 88.5 yen per token (the price at the time of the hack). Total compensation was approximately $400 million.

Regulatory Response

The hack prompted an immediate regulatory crackdown by Japan's Financial Services Agency (FSA). The FSA:

  • Issued a business improvement order to Coincheck
  • Conducted on-site inspections of other exchanges
  • Required exchanges to strengthen security measures
  • Mandated better cold storage practices
  • Increased oversight and reporting requirements

Acquisition by Monex Group

In April 2018, Coincheck was acquired by Monex Group, a Japanese online brokerage firm. The acquisition was seen as a vote of confidence in the exchange's future and helped restore user trust.

πŸ“Œ The FSA's Crackdown

The Coincheck hack was a wake-up call for Japanese regulators. The FSA significantly increased its oversight of cryptocurrency exchanges, leading to stricter security requirements and more rigorous licensing processes.

🌍 The Impact on the Crypto Industry

The Coincheck hack had a significant impact on the cryptocurrency industry, shaping security practices and regulatory frameworks.

❄️
Cold Storage Became Standard

The hack reinforced the absolute necessity of cold storage for the majority of funds. Today, 95%+ of funds on reputable exchanges are held offline.

πŸ›οΈ
Regulatory Scrutiny

The hack led to increased regulatory oversight of cryptocurrency exchanges worldwide, particularly in Japan.

πŸ”’
Enhanced Security Requirements

Exchanges were required to implement stronger security measures, including multi-signature wallets and regular security audits.

πŸ“‹
Proof of Reserves

The hack highlighted the need for transparency, leading to the adoption of Proof of Reserves by many exchanges.

πŸ“Š The Coincheck Legacy

Coincheck survived the hack and continues to operate today. The exchange's compensation plan, regulatory compliance, and subsequent acquisition by Monex Group have been studied as a case study in crisis management and recovery.

πŸ“š Lessons Learned from Coincheck

The Coincheck hack teaches us critical lessons about security, regulation, and risk management.

  • Cold storage is essential: Never keep large amounts of crypto in hot wallets. The majority of funds must be stored offline.
  • Hot wallet security is critical: If you must keep funds in hot wallets, ensure they are properly secured and monitored.
  • Regulatory compliance matters: The hack prompted a regulatory crackdown that changed the Japanese crypto industry.
  • User compensation is possible: Coincheck's compensation plan showed that exchanges can recover from major hacks with the right approach.
  • Transparency builds trust: Coincheck's communication and compensation helped maintain user trust.
  • Third-party audits are essential: Regular security audits can identify and fix vulnerabilities before they are exploited.
πŸ“Œ Key Takeaway

The Coincheck hack is a cautionary tale about the importance of cold storage. If you're choosing an exchange, look for one that stores 95%+ of funds in cold storage and has a proven track record of security.

❓ Frequently Asked Questions About the Coincheck Hack

What was the Coincheck hack?

The Coincheck hack was a major security breach in January 2018 when approximately 523 million NEM tokens (worth about $534 million at the time) were stolen from the Japanese exchange's hot wallet. It was one of the largest cryptocurrency thefts in history.

How was Coincheck hacked?

The hack occurred because Coincheck stored the majority of its NEM tokens in a hot wallet (online) rather than cold storage. Hackers gained access to the hot wallet's private keys and were able to withdraw 523 million NEM tokens over a period of time.

How much was stolen from Coincheck?

Approximately 523 million NEM tokens were stolen from Coincheck. At the time of the hack (January 2018), this was worth about $534 million, making it the largest cryptocurrency heist at that time.

What happened after the Coincheck hack?

Coincheck suspended trading and withdrawals, announced a compensation plan for affected users, and was later acquired by Monex Group. The hack also led to increased regulatory scrutiny from Japan's Financial Services Agency (FSA).

What lessons were learned from Coincheck?

The hack reinforced the absolute necessity of cold storage for the majority of funds, the importance of robust hot wallet security, and the need for stringent regulatory oversight of cryptocurrency exchanges.

Did Coincheck users get their money back?

Yes, Coincheck announced a compensation plan for affected users, reimbursing them for the stolen NEM tokens at approximately 88.5 yen per token. Total compensation was approximately $400 million.

What is NEM?

NEM (New Economy Movement) is a blockchain platform and cryptocurrency launched in 2015. It features a unique consensus mechanism called Proof-of-Importance (PoI) and was one of the top cryptocurrencies at the time of the Coincheck hack.

What is the difference between hot and cold storage?

Hot storage keeps private keys online for quick access and trading. Cold storage keeps private keys offline (air-gapped) for maximum security. Cold storage is much more secure but less convenient for frequent transactions. The Coincheck hack happened because the exchange kept too much in hot storage.

πŸ‡―πŸ‡΅ Learn from Coincheck β€” Secure Your Crypto

The Coincheck hack was a turning point for the Japanese crypto industry. Learn from history and protect your funds with cold storage, 2FA, and secure exchanges.