Coincheck Hack

REPORTED LOSS $534M
Critical Private Key Compromised (Unknown Method) nem

What happened

On January 26, 2018, attackers transferred 526,300,010 XEM out of Coincheck. The exchange's investigation concluded that malware likely enabled access to its network and theft of the NEM private key. Coincheck completed compensation in Japanese yen on March 12, 2018; this was reimbursement rather than recovery of stolen XEM.

Technical Root Cause

Coincheck's account describes an endpoint and network compromise that exposed a wallet signing key. Possession of that key enabled unauthorized transfers. The exchange presents the intrusion sequence as its investigators' probable explanation.

Case & protocol details

Classification Infrastructure / CeFi / Key Compromise
Protocol Type Exploit/Other
Official Website coincheck.com/
Protocol Twitter/X @coincheckjp

How it happened

  1. According to Coincheck's suspected reconstruction, an attacker infected an employee device with malware and accessed the company network through it.
  2. Remote-control tools enabled interception of communications on the NEM server and theft of its private key.
  3. The attacker used the key to send XEM to external addresses.
  4. Coincheck records the unauthorized transfers between 00:02 and 08:26 JST on January 26, 2018.

Funds Recovery

100.0%

Recovered

$534.0M

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.