Skip to content
Incident record

KuCoin Hot Wallet Compromise, September 2020: What Happened & What to Check

Roughly $281m left KuCoin hot wallets. A large share was recovered through token contract upgrades and freezes by issuers.

Resolved Discovered Disclosed
Share X in @
Schematic of the KuCoin incident showing the key compromise stage as the failure point.
Schematic of the KuCoin incident showing the key compromise stage as the failure point.

At a glance

AFFECTED ENTITY
KuCoin
CHAIN(S)
Bitcoin, Ethereum
ATTACK CLASS
Key compromise
REPORTED LOSS
approx. US$281 million(KuCoin, 26 Sep 2020)
OFFICIAL RESPONSE
www.kucoin.com

The recovery is the interesting part

The breach itself was conventional: hot wallet keys compromised, assets moved. What made this incident instructive was what happened next. A large share of the stolen value was recovered because token issuers intervened — freezing balances, upgrading contracts, or reissuing supply to the exchange.

What that reveals

For a customer, the outcome was good. For anyone reasoning about decentralisation, it was clarifying: a great many ERC-20 tokens have an issuer with the technical ability to freeze or reassign holdings. That capability is usually documented, rarely read, and only visible when it is exercised.

The check worth running on any token you hold in size is whether its contract includes pause, blacklist, upgrade or mint authority, and who controls it. That is public, on-chain and verifiable — unlike most claims about decentralisation.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. KuCoin detects unauthorised withdrawals, suspends deposits and withdrawals, and publicly discloses the incident. KuCoin
  2. KuCoin reports progressive recovery of assets, substantially assisted by token issuers freezing or reissuing affected balances. KuCoin

What to check

KuCoin published incident updates and a recovery accounting on its own channels; those statements are the authoritative record.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. KuCoin, Incident statements and recovery updates (26 Sep 2020)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.