The 2018 Coincheck hack stands as one of the largest cryptocurrency thefts in history, where over $500 million worth of NEM (XEM) tokens were stolen from a Tokyo-based exchange. The hack exposed critical vulnerabilities in Japan’s cryptocurrency security landscape, mainly due to Coincheck’s decision to store all NEM tokens in a single hot wallet without proper multi-signature protection. Following the theft, sophisticated laundering techniques ensued within Japan, involving the use of over-the-counter (OTC) swaps, mixing services, and complex transaction chains to obscure the stolen tokens’ origins. Despite efforts by the NEM Foundation to tag and track these stolen funds, laundering activities continued, implicating numerous individuals and triggering one of Japan’s most extensive crypto crime investigations. This case profoundly highlighted the weaknesses in regulatory oversight and operational security in Japanese exchanges at the time, prompting stringent enforcement actions and reforms in AML practices within the country’s crypto industry. The Coincheck hack illustrates the deep intersection of cybercrime and money laundering in Japan’s digital asset ecosystem, serving as a cautionary tale of the risks posed by inadequate security and regulatory measures.​
In January 2018, Coincheck, a major Japanese crypto exchange, suffered a historic hack leading to the theft of over $500 million worth of NEM (XEM) coins from its poorly secured hot wallet. The attackers exploited a virus infection on Coincheck employee computers to obtain private keys and transfer out the vast monolithic XEM reserve. Despite blockchain tracking and alerts from NEM developers marking suspicious addresses, the stolen coins were laundered through various techniques including OTC swaps and crypto conversions. The resulting laundering network involved numerous individuals in Japan, some of whom were arrested or charged, with cases including seizure of illicit cryptocurrency assets marking a legal first in Japan. The incident led to stringent regulatory actions by Japan’s FSA imposing security and AML improvements across the industry and set precedents in crypto crime enforcement. The hack remains a landmark case illustrating vulnerabilities in exchange security and challenges of laundering enforcement in Japan’s cryptocurrency landscape.