Bithumb disclosed on March 30, 2019 that it had detected abnormal cryptocurrency withdrawals from company-controlled assets and suspended cryptocurrency deposits and withdrawals while it investigated the incident.
The South Korean exchange said its monitoring system identified the activity at approximately 22:15 Korea Standard Time on March 29. Contemporaneous Korean reporting placed the suspension of cryptocurrency transfers at approximately 23:00. Bithumb said Korean-won deposits and withdrawals remained available.
The development mattered because it exposed a risk that blockchain settlement alone could not address: a centralized exchange’s internal controls over wallet credentials, employees and treasury assets. Bithumb’s first explanation pointed toward possible insider involvement, but that remained the company’s preliminary assessment rather than an established criminal finding.
What Bithumb said
Bithumb stated that it found no evidence of an external intrusion during its initial inspection. The exchange characterized the incident as involving insiders and acknowledged that its security work had concentrated more heavily on outside attacks than on verification of internal personnel.
The company said the withdrawn cryptocurrency belonged to Bithumb rather than its customers. It also said customer assets were protected in cold wallets and that it moved remaining cryptocurrency into cold storage after detecting the activity. Those were contemporaneous representations by the affected exchange; no independently published audit was available on March 30 to confirm the completeness of its asset segregation or the absence of customer losses.
Bithumb reported the matter to police and relevant authorities and said it was working with the Korea Internet & Security Agency and security companies. The Korea Internet & Security Agency separately confirmed to Electronic Times that Bithumb had submitted a report concerning suspicious activity and that the cause was being examined.
The amount remained unsettled
Bithumb’s March 30 statement did not provide a final loss total. Contemporaneous blockchain observers and news organizations traced roughly 3 million EOS from a wallet attributed to Bithumb. Separate reports identified approximately 20 million XRP as potentially connected to the same incident.
Those quantities should not be treated as a completed forensic accounting. Public blockchains can verify transfers between addresses, but attributing every address, establishing authorization and determining ultimate recoveries require additional evidence. Reports also produced differing dollar and Korean-won valuations because token prices, valuation times and included assets varied. For that reason, this reconstruction does not adopt a single currency-denominated loss estimate.
Contemporaneous tracing indicated that portions of the EOS were sent toward several trading or conversion services. That movement increased the operational importance of rapid coordination among exchanges, but it did not by itself prove who controlled the destination accounts or whether the assets had been converted, frozen or recovered by March 30.
Why the incident mattered
The event separated protocol security from custodial security. Neither the EOS nor XRP network was reported to have failed. The apparent weakness was at the intermediary layer, where an exchange controlled online wallet keys and decided how company and customer balances were stored.
Bithumb’s assurance that customer holdings remained in cold storage reduced the immediate claim from a customer-loss event to a company-asset incident. It did not eliminate counterparty risk. Customers still depended on Bithumb’s accounting, wallet segregation and ability to restore withdrawals after its review.
The insider explanation also required caution. An absence of detected external intrusion was not proof that a particular employee committed a crime. On March 30, the responsible person, precise access method, complete asset total and recovery prospects were unresolved.
No defensible broader-market reaction can be isolated from this announcement using the surviving event-day record. Cryptocurrency markets traded continuously across venues, and the cited sources did not establish that movements in bitcoin, EOS, XRP or the total market were caused by Bithumb’s disclosure. The verified significance was institutional: a major exchange had stopped cryptocurrency transfers, disclosed unauthorized movement of company assets and placed its internal wallet controls under investigation.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

