On the morning of January 26, 2018, Japanese crypto exchange Coincheck lost 523 million NEM tokens worth $534 million — the second-largest heist in cryptocurrency history, where the criminals knew the weak link and the victim left it there themselves.
💰 At 02:57 Tokyo time on January 26, 2018, 523 million NEM tokens disappeared from Coincheck exchange's single "hot" wallet — equivalent to $534 million at that day's rate. This wasn't a hack in the classical sense: no one broke the cryptography, brute-forced private keys, or exploited a blockchain vulnerability. The hackers simply gained access to a wallet that stored absolutely all client assets in one place, without multi-signature, without cold storage, without encryption by additional layers — as if a bank kept all depositors' money in a cardboard box by the front door. The exchange only discovered the loss at 11:25 — eight hours later, when users began complaining about the impossibility of withdrawing funds. By that point 260,000 clients had lost their savings, and the criminals had already distributed the stolen funds across thousands of addresses.
🔓 Coincheck's story began in 2012, when Koichiro Wada and Yusuke Otsuka — Tokyo Institute of Technology graduates with no finance experience — launched the exchange as a startup project in the spirit of crypto-anarchism of early bitcoin evangelists. By 2017 it had become Japan's largest platform for trading altcoins, processing tens of thousands of transactions daily. But the security architecture remained at garage-prototype level: instead of the standard separation of assets into "cold" wallets (offline storage, physically isolated from the internet) and "hot" wallets (online for quick withdrawals), Coincheck kept all NEM tokens in one hot wallet. This violated basic principles taught in first-year cryptography: single point of failure — single point of catastrophe. The team knew about the risk — at a press conference on January 27, the founders admitted: "We postponed implementing cold storage because the priority was transaction speed and user convenience." Technical debt worth half a billion dollars.
🕵️ The hack wasn't an act of hacker genius — it was exploitation of engineering negligence. The private key to the NEM wallet was stored on an internet-connected server without hardware isolation. The attackers penetrated through a phishing attack on one of Coincheck's employees or through compromise of an internal system — the exact vector was never publicly disclosed, but the result was the same: having gained server access, the perpetrators extracted the private key and initiated a mass transaction. The NEM blockchain recorded the transfer at 02:57, but the exchange had no real-time monitoring. Alert systems for large transactions didn't exist, automatic withdrawal limits weren't configured for technical wallets. Eight hours of silence — that's the time in which criminals managed to atomize assets through dozens of intermediate addresses, turning one monolithic trail into a labyrinth of microtransactions.
⚙️ NEM Foundation — the blockchain development team — reacted within a day, launching an automatic system for tagging stolen tokens. In the NEM blockchain there's a "mosaic" mechanism — metadata that can be attached to an address, marking it as compromised. On January 28, the foundation published a list of addresses where the funds went and asked exchanges worldwide to block attempts to cash out tagged tokens. This was the first case of mass blockchain forensics in real time: thousands of volunteers tracked NEM movement through block explorers, creating transaction graphs manually. By February 2018, analysts had identified about 80% of the stolen tokens, but the practical benefit was minimal — most hackers simply froze the funds, waiting for the noise to die down, or converted them through anonymous mixers into Monero and Zcash.
🔍 Technical autopsy revealed three critical errors. First: absence of multi-signature — a standard requiring transaction confirmation from several independent keys. If Coincheck had used a "3 of 5" scheme, hackers would have had to compromise three different servers simultaneously — an orders-of-magnitude harder task. Second: absence of asset segregation. Professional exchanges like Kraken and Bitfinex keep a maximum of 5-10% of total volume in hot wallets — the rest in cold storage, physically disconnected from the network. Coincheck kept 100% of NEM online because withdrawal from cold storage would require manual transaction signing and delays of several hours — unacceptable inconvenience for traders accustomed to instant transfers. Third: absence of real-time auditing. Modern exchanges use anomaly monitoring systems that flag transactions above a certain threshold or unusual activity patterns. Coincheck had no such system — the wallet emptied and no one received alerts.
💸 The paradox of the hack was that NEM as a blockchain worked perfectly — no protocol compromise occurred. This wasn't a code bug but a failure of human process: the team chose convenience over security, and management didn't conduct an audit, even though Coincheck was planning to obtain a license from the Financial Services Agency of Japan (FSA) and had been operating without regulatory approval since September 2017, when FSA introduced mandatory registration for crypto exchanges after previous scandals. Internal documents that surfaced later showed: the team knew about the need for cold storage back in fall 2017, but postponed the migration because it required stopping trading for several days — a loss of revenue the startup couldn't afford in the race for market share. In the end, the race ended on the roadside with half a billion dollars in the ditch.
📸 On January 27, 2018, a day after the hack, Coincheck founders Koichiro Wada and Yusuke Otsuka held a press conference that became a symbol of corporate collapse Japanese-style. They appeared before journalists in white shirts, bowed their heads at a 90-degree angle — the traditional dogeza, a gesture of deepest apology usually reserved for crimes against honor — and pronounced the standard formula: "Moushiwake gozaimasen deshita" ("There is no forgiveness for us"). But Western media saw theatricality rather than sincerity in this: while the press clicked shutters, Coincheck shareholders were already negotiating the company's sale to save themselves from bankruptcy. Public humiliation was part of the survival strategy — in Japanese corporate culture, displayed remorse can soften the anger of clients and regulators, even if real changes don't follow.
💴 But Coincheck did what Mt.Gox didn't — announced full compensation to victims from its own funds. All 260,000 clients received refunds at the rate of 88,549 yen per NEM token (about $0.81), totaling $425 million — $100 million less than market value at the time of the hack, but it was a real payment, not a promise of "we'll sort it out in five years of litigation," as happened with Mt.Gox victims. Where did a hacked exchange find almost half a billion? Partially from reserves accumulated during 2017 — the period of bitcoin fever, when Coincheck's commissions amounted to tens of millions per month. Partially from emergency financing by investors who understood: without compensation the exchange is dead, and with it — their investments. By March 2018, payments were completed — unprecedented speed for the crypto industry, where reimbursement disputes usually drag on for years.
🏛️ The FSA responded lightning-fast: on January 29, the regulator conducted an unscheduled inspection of Coincheck, and by February sent orders to improve security measures to all registered exchanges in Japan. New requirements included mandatory cold storage for at minimum 80% of client assets, multi-signature for all large transactions, regular external security audits, and implementation of KYC/AML procedures at the level of traditional banks — identity verification with biometrics, monitoring of suspicious transfers, reporting to antitrust authorities. Two exchanges — FSHO and Bit Station — couldn't meet the new standards and closed within a month. Coincheck got a reprieve: FSA didn't revoke the license application but put the company under supervision — every week the team had to report progress in infrastructure modernization.
🤝 On April 6, 2018, ten weeks after the hack, Monex Group — a Japanese financial holding with $25 billion in assets, owner of one of the country's largest online brokerage platforms — announced the purchase of Coincheck for 3.6 billion yen ($33.5 million). The price was ridiculously low for an exchange that in 2017 brought in tens of millions in profit monthly, but the logic was simple: Coincheck was a hair's breadth from bankruptcy, and Monex was getting a ready client base of 260,000 people, a technology platform, and most importantly — a path to FSA licensing. The regulator approved the deal in September 2018, and Coincheck became the first hacked exchange in history to receive an official license after catastrophe. The reason: under Monex's wing, the company conducted a complete restructuring — implemented cold storage from BitGo, hired a CISO with banking sector experience, installed a real-time audit system from Chainalysis.
🔐 Monex didn't just buy a damaged asset — it turned Coincheck into a showcase of corporate crypto rehabilitation. By November 2018, the exchange resumed trading, but with a limited set of coins: instead of dozens of altcoins, only BTC, ETH, XRP and four other tokens remained — those for which proven cold storage solutions existed. Withdrawals now required two-factor authentication and a 24-hour delay for large amounts — sacrifice to convenience, but guarantee of security. Users returned: by the end of 2018, trading volumes recovered to 80% of pre-hack levels. Reputation was restored not by marketing but by real changes — and support from the regulator, who used Coincheck as proof that the Japanese crypto market could self-reform.
🚨 February 2021 — Tokyo prosecutors brought charges against 31 people in the Coincheck case. These weren't the hackers but intermediaries: owners of small OTC exchanges and operators of anonymous wallets who helped convert stolen NEM into fiat. Not one of the actual hack perpetrators was arrested — they remained shadows in server logs. Some of the accused admitted they received tokens through darknet exchanges where stolen NEM sold at a 30-40% discount: buyers knew the origin but risked it for profit. The total amount of confiscated assets was less than $5 million — a drop in the ocean, and most funds remained frozen in wallets, awaiting their moment.
🌐 NEM Foundation continued marking addresses for another two years, but by 2020 the system became ineffective: hackers learned to fragment tokens into microtransactions below the flagging threshold, use atomic swaps to convert to other cryptocurrencies without centralized exchange participation, and even create fake marking tags to confuse analysts. Blockchain forensics showed its limits: transaction transparency doesn't mean confiscation capability if there's no centralized node through which money passes.
📌 2026. Coincheck operates as one of Japan's top-5 crypto exchanges by trading volume, processing $200-300 million daily. It survived the FTX collapse in 2022, Terra/Luna collapse, the 2023 bear market — and stayed afloat thanks to one decision: acknowledge the catastrophe, pay the bills immediately, and submit to the regulator. Mt.Gox went bankrupt because CEO Mark Karpelès spent two years denying the scale of the problem and trying to hide the balance sheet hole; Coincheck survived because the founders bowed their heads before cameras and opened the books to FSA. In 2024, the exchange launched an institutional custodial storage service for corporations — a product unthinkable for a company with a hacking history, but possible thanks to six years of flawless work under Monex supervision. The Coincheck lesson: in the crypto industry, reputation is killed not by catastrophe but by the attempt to cover it up. Transparency is more expensive than pride, and sometimes dogeza before cameras costs half a billion dollars — if followed by real actions, not empty promises.