Zaif Hack

USD loss unconfirmed Not disclosed
Bitcoin Bitcoin Cash Monacoin
Hot-wallet server compromise

What happened

On September 14, 2018, unauthorized access to Zaif's hot-wallet server enabled withdrawals of BTC, MONA and BCH. Tech Bureau's revised estimate was ¥7.03 billion in total, including ¥4.59 billion of customer assets.

Technical root cause

The compromised server administered exchange hot wallets. Tech Bureau withheld the specific intrusion method during the criminal investigation.

How it happened

  1. An external party accessed the server administering deposit and withdrawal wallets between approximately 17:00 and 19:00 Japan time.
  2. BTC, MONA and BCH were transferred out without authorization.
  3. Tech Bureau detected server abnormalities on September 17 and confirmed the breach the following day.
  4. It reported the incident to authorities and sought financial and technical support. Its September 21 update revised the loss estimate using September 18 closing prices.

Protocol details

Classification CeFi / Infrastructure
Protocol Type Exploit/Access control
Protocol links Website @zaifdotjp

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.