South Korean cryptocurrency exchange Bithumb disclosed on June 20, 2018, that cryptocurrencies initially valued at approximately 35 billion won had been stolen between late June 19 and early June 20.
The exchange halted cryptocurrency deposits and withdrawals while it examined its systems. Bithumb said remaining customer assets had been transferred to offline cold wallets and promised to cover the loss from its own resources. Those were contemporaneous company assurances, not conclusions from an independent audit.
The disclosure mattered because Bithumb was a major gateway between South Korean won and digital assets. Its interruption demonstrated that distributed ledgers did not remove the operational risks created when customers entrusted assets and private-key control to a centralized trading venue.
A preliminary loss estimate
Bithumb’s initial 35 billion won figure was an estimate of the cryptocurrencies it believed had been taken. Reuters converted that amount to approximately $31.5 million in its June 20 report. The dollar figure therefore reflected Reuters’ contemporaneous conversion of the exchange’s won estimate, not a wallet-by-wallet valuation or a final recovery accounting.
Bithumb did not identify every affected asset, publish the relevant wallet addresses or explain the intrusion method in its event-day notice. It also did not establish publicly whether the compromise involved a private key, an internal system, an employee account or another access path. Suggestions that a particular wallet architecture or attacker caused the loss remained unverified on June 20.
Yonhap reported that Seoul police sent officers to Bithumb’s headquarters to collect computer records and data. Its Korean-language account said the exchange detected unusual activity at approximately 11 p.m. Korea Standard Time on June 19, restricted deposits around 1:30 a.m. on June 20 and reported the incident to the Korea Internet & Security Agency at approximately 9:40 a.m. Those times came through Bithumb and Yonhap rather than a published police or KISA incident log.
Cold storage limited exposure, according to Bithumb
Bithumb said customer assets were secured in cold wallets after the theft was detected. Cold storage removes signing credentials from continuously internet-connected infrastructure, but the announcement did not disclose how much cryptocurrency had remained online, when each transfer occurred or whether all exposed systems had been identified.
The distinction between company and customer assets was also important. Bithumb said it would compensate affected customers from its own reserves, effectively presenting the event as a loss the operator could absorb. That commitment did not independently establish the exchange’s reserve position or prove on June 20 that every customer balance was immediately withdrawable, particularly while transfer services were suspended.
The incident followed Coinrail’s disclosure of a separate South Korean exchange breach on June 11. Together, the events intensified questions about custody controls, incident reporting and the limited regulatory structure then surrounding cryptocurrency exchanges. They did not demonstrate a failure of Bitcoin or another underlying blockchain’s consensus mechanism.
A narrow market observation
Reuters reported that bitcoin on Bitstamp, identified as BTC=BTSP, traded at $6,612.92 at 03:51 GMT on June 20, down 1.8% at that observation point. This was a single-exchange intraday measurement, not a global closing price or a complete event study. The timing was consistent with weaker sentiment after the announcement, but it could not establish that the Bithumb disclosure alone caused the move in a continuously traded market.
Later clarification
On June 22, Bithumb said it was investigating with KISA, the National Police Agency and security company AhnLab. On June 28, the exchange revised its provisional loss estimate from 35 billion won to approximately 19 billion won, attributing the reduction to recovery work, cooperation with exchanges and cryptocurrency organizations, and rapid transfers into cold storage. That later estimate clarifies the record but does not replace what market participants knew on June 20.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

