Coincheck hack
The Japanese exchange Coincheck lost about 523M NEM tokens (~$530M) to attackers in January 2018 — then one of the largest crypto thefts. The coins had been stored in an internet-connected hot wallet; Coincheck pledged to reimburse affected users.
Also known as: Coincheck, NEM hack
Summary
In January 2018, the Tokyo-based exchange Coincheck reported that about 523 million NEM (XEM) tokens — worth roughly $530 million at the time — had been stolen, making it one of the largest cryptocurrency thefts to that point. [1][2]
Cause and response
Reporting indicated the affected NEM had been held in an internet-connected "hot" wallet rather than more secure cold storage, and that security measures such as multisignature had not been applied. Coincheck pledged to reimburse affected customers and was later acquired by Monex Group; Japan's Financial Services Agency increased scrutiny of domestic exchanges. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
HEX / PulseChain (Richard Heart)ProjectsCrypto projects (HEX, PulseChain, PulseX) created by Richard Heart (Richard Schueler). In July 2023 the U.S. SEC sued him for offering unregistered securities that raised $1B+ and for allegedly misappropriating ~$12M for luxury goods (including a 555-carat diamond). A court dismissed the case in 2024 for lack of U.S. jurisdiction; there was no finding of wrongdoing and Heart denies the allegations.
This page was last updated on Jun 15, 2026. View revision history.
