EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/coincheck-hack-2018
223/430

File EL-0208CriticalResolvedData Breach / Financial Theft

Coincheck Hack

Also filed as Coincheck Exchange Breach · Japanese Crypto Exchange Hack

The Coincheck Hack was a major cyberattack targeting the Japanese cryptocurrency exchange, Coincheck, in January 2018. The attackers successfully stole a significant amount of digital assets, primarily Bitcoin and other cryptocurrencies. The incident highlighted the vulnerability of centralized crypto exchanges to sophisticated, state-sponsored theft.

  • #cryptocurrency
  • #coincheck
  • #lazarus-group
  • #japan
  • #hacking
  • #crypto-theft
Notoriety8/10
Event
26 Jan 2018
Disclosed
26 Jan 2018
Target
Coincheck
Actor
Lazarus Group
Scale
Multiple BTC and other crypto assets (estimated millions of USD)
Status
Resolved

01Summary

The attack occurred on January 26, 2018, when the Coincheck exchange reported a massive theft of digital assets. While the exact technical method was not fully disclosed, the scale of the loss suggested a highly sophisticated breach, likely involving internal access or a zero-day exploit. The Lazarus Group, a notorious North Korean state-sponsored hacking collective, was widely attributed to the operation. The theft was purely financially motivated, aiming to liquidate the stolen crypto assets. Coincheck subsequently implemented enhanced security measures, including multi-signature wallets and increased cold storage protocols, in response to the breach.

02Background

The cryptocurrency exchange market, particularly in Asia, was rapidly expanding in the mid-2010s, attracting significant investment and making it a prime target for state-sponsored financial theft. Coincheck, being one of the largest exchanges in Japan, represented a high-value target for groups like the Lazarus Group.

03Key revelations

  1. 01The theft demonstrated the vulnerability of centralized crypto exchanges to nation-state actors.
  2. 02The operation was highly coordinated, suggesting professional, state-level resources.
  3. 03The incident forced major exchanges globally to overhaul their cold storage and key management protocols.

04Technical analysis

The attack vector is believed to have involved compromising the exchange's internal systems or key management infrastructure. The attackers likely gained access to the private keys or the ability to initiate large-scale withdrawals. The method was characterized by rapid, high-volume exfiltration of funds across multiple blockchain addresses, making tracing difficult but confirming the theft's scale.

Attack vector
Internal System Compromise / Key Theft
Attack method
Exfiltration and Theft
Initial access
Compromised Credentials or Internal Network Access
Lateral movement
Internal Network Pivoting
Persistence
Backdoor Installation (Suspected)
Exfiltration
Blockchain Transactions (High Volume)
Malware type
Stealer/Exfiltration

MITRE ATT&CK techniques

  • T1071.001
  • T1566.001

05Threat actor

The Lazarus Group is a highly sophisticated, state-sponsored hacking collective attributed to North Korea. They are known for conducting diverse financial crimes, including ransomware, cryptocurrency theft, and spear-phishing campaigns, often with the goal of generating foreign currency for the DPRK regime.

Aliases

  • APT31
  • Hidden Cobra

APT designations

  • Lazarus Group

MITRE groups

  • T1566.001

Attribution sources

  • Coincheck
  • Security Researchers
  • Industry Reports

06Victims and impact

Countries affected

  • Japan

07Data exposed

Data types

  • Cryptocurrency Assets
  • User Account Data (Suspected)

08Financial damage

The damage was the loss of the stolen crypto assets, estimated to be in the tens of millions of USD.

09Timeline

  1. 2018-01-26The theft of digital assets from Coincheck was discovered and publicly reported.

10Key figures

  • CoincheckVictim/Responder · Coincheck株式会社JapaneseOverhauled security protocols and recovered from the breach.

11On the record

The incident served as a major wake-up call for the entire global cryptocurrency industry regarding security standards.

Industry Analysts, Post-breach analysis

12Reaction and fallout

Public reaction

The public reaction was one of heightened alarm, leading to increased scrutiny of crypto exchange security practices globally. Many investors became more cautious about keeping large sums of funds on centralized platforms.

Political impact

The incident increased regulatory pressure on cryptocurrency exchanges worldwide, prompting governments to consider stricter operational and security requirements for digital asset custodians.

Geopolitical consequences

It reinforced the narrative of cryptocurrency as a potential vector for state-sponsored financial warfare, drawing increased attention from international intelligence agencies.

13Legal

No specific criminal charges were publicly filed against the perpetrators, but the incident contributed to a more rigorous legal and regulatory environment for crypto exchanges in Japan and globally.

14Aftermath

Policy changes

  • Increased mandatory cold storage requirements for crypto exchanges.

Regulatory changes

  • Stricter KYC/AML compliance for digital asset service providers.

Security improvements

  • Implementation of multi-signature wallets (MultiSig).
  • Enhanced air-gapped cold storage solutions.
  • Mandatory internal security audits and penetration testing.

15Significance and legacy

Significance

The Coincheck Hack is a landmark case demonstrating the successful application of nation-state cyber capabilities against a major financial institution in the digital asset space. It set a new, higher standard for security expectations within the cryptocurrency industry, moving the focus from simple theft to systemic, state-level risk management.

Legacy

The incident accelerated the shift toward decentralized finance (DeFi) models and forced centralized exchanges to adopt enterprise-grade security measures previously reserved for traditional banking institutions. It remains a key case study in cyber risk for the financial sector.

16Disclosure and media

Authentication
Industry Consensus and Forensic Analysis

Media partners

  • Cointelegraph
  • The Hacker News

17Related files

Related events

  • Mt. Gox Hack (2010)
  • Bangladesh Bank Heist (2016)

18Field notes

  1. 01The Lazarus Group is known for targeting various sectors, including financial institutions, media, and government entities, not just crypto.
  2. 02The hack contributed to the initial wave of regulatory discussions in Japan regarding the need for stronger oversight of crypto exchanges.

19Resolution

Coincheck publicly stated that the funds were stolen and that they were working with law enforcement and security experts to mitigate the damage and prevent recurrence.

20Sources

References

  1. [1]Coincheck Official Statements
  2. [2]Industry Security Reports
Fact sheetEL-0208

Dates

Event
26 Jan 2018
Started
26 Jan 2018
Ended
26 Jan 2018
Duration
1 days
Discovered
26 Jan 2018
Disclosed
26 Jan 2018
Resolved
26 Jan 2018
Ongoing
No

Target

Organisation
Coincheck株式会社
Type
Technology Company
Sector
Cryptocurrency Exchange
Country
Japan

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korea
Nation-state
Democratic People's Republic of Korea (DPRK)
Affiliation
Military/Intelligence Unit
Motivation
Financial gain and state-sponsored theft of digital assets.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Multiple BTC and other crypto assets (estimated millions of USD)
Sensitivity
Confidential
Published
No
Sold (dark web)
No

Money

Crypto
Bitcoin (BTC)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.