Skip to content
Incident record

Coincheck NEM Theft, January 2018: What Happened & What to Check

Roughly 523 million NEM was taken from a Coincheck hot wallet held without multi-signature protection. The incident reshaped Japanese exchange supervision.

Resolved Discovered Disclosed
Share X in @
Schematic of the Coincheck incident showing the key compromise stage as the failure point.
Schematic of the Coincheck incident showing the key compromise stage as the failure point.

At a glance

AFFECTED ENTITY
Coincheck
CHAIN(S)
NEM
ATTACK CLASS
Key compromise
REPORTED LOSS
approx. 523 million NEM(Coincheck, 26 Jan 2018)
OFFICIAL RESPONSE
coincheck.com

Hot wallet, single signature

The technical facts were unusually plain. A large customer balance sat in an internet-connected wallet, secured by a single key, with no multi-signature requirement. Once that key was compromised the assets moved.

Coincheck was operating during the transitional period of Japan’s registration regime. The incident therefore also became a supervisory case study — the regulator could point at a registered-and-supervised market and show precisely what it had not yet caught.

The regulatory consequence

The FSA responded with business improvement orders and a much more intrusive inspection posture. Readers assessing any Japanese exchange today are looking at a regime shaped by this failure — see our Japan jurisdiction page.

What to take from it

The question worth asking of any custodian is not whether it has cold storage, but what proportion of customer assets sits outside it at any moment, and what protects that portion. Coincheck compensated its customers; the next firm in the same position may not be able to.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Coincheck detects the unauthorised transfer, suspends NEM withdrawals and trading, and publicly discloses the incident. Coincheck
  2. The Japanese FSA issues a business improvement order to Coincheck. Financial Services Agency (Japan)

What to check

Coincheck's own announcements and the Japanese Financial Services Agency's subsequent business improvement orders are the authoritative record.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Coincheck, Official announcements (26 Jan 2018)
  2. Financial Services Agency (Japan), Supervisory actions (29 Jan 2018)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.