Coincheck Hack
What happened
On January 26, 2018, attackers transferred 526,300,010 XEM out of Coincheck. The exchange's investigation concluded that malware likely enabled access to its network and theft of the NEM private key. Coincheck completed compensation in Japanese yen on March 12, 2018; this was reimbursement rather than recovery of stolen XEM.
Coincheck's account describes an endpoint and network compromise that exposed a wallet signing key. Possession of that key enabled unauthorized transfers. The exchange presents the intrusion sequence as its investigators' probable explanation.
Case & protocol details
How it happened
- According to Coincheck's suspected reconstruction, an attacker infected an employee device with malware and accessed the company network through it.
- Remote-control tools enabled interception of communications on the NEM server and theft of its private key.
- The attacker used the key to send XEM to external addresses.
- Coincheck records the unauthorized transfers between 00:02 and 08:26 JST on January 26, 2018.
Funds Recovery
Recovered
$534.0M
Net Loss
$0
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.