Coincheck halted withdrawals on January 26, 2018, after the Tokyo-based exchange detected that NEM tokens under its control had been sent outside the platform without authorization. By the end of the Japanese business day, the response had widened from NEM-specific restrictions to a freeze on withdrawals of every supported currency, including Japanese yen, and a suspension of trading in cryptocurrencies other than bitcoin.
The disclosure made the security of exchange custody—not the operation of the NEM blockchain—the immediate issue. At a late-night news conference, Coincheck described roughly 520 million XEM as missing and valued them at approximately ¥58 billion using its own rate at about 03:00 Japan Standard Time on January 26. That was a company valuation at a particular moment, not an independently consolidated market price.
The shutdown unfolded in stages
Coincheck's surviving incident timeline says it detected an abnormality at approximately 11:25 JST on January 26. It announced a pause in NEM deposits at 12:07, NEM trading at 12:38 and NEM withdrawals at 12:52. At 16:33 it announced that withdrawals of all currencies, including yen, would stop. At 17:23 it halted trading in cryptocurrencies other than bitcoin, followed at 18:50 by restrictions on credit-card, Pay-easy and convenience-store deposits.
That sequence matters because it separates the asset known to have been transferred from the much broader customer-protection measures imposed while the exchange investigated. Coincheck said it had not identified a comparable unauthorized transfer of yen or other cryptocurrencies at that point. A platform-wide withdrawal freeze therefore should not be read as evidence that every listed asset had been stolen.
What Coincheck knew—and did not know
Contemporaneous coverage of the January 26 press conference reported that the affected NEM was held in a hot wallet, meaning its signing environment was connected to online systems, and that Coincheck had not implemented NEM's multisignature capability for that wallet. Those admissions pointed to weaknesses in the exchange's custody controls. They did not establish that NEM's underlying ledger or consensus rules had failed.
Several essential facts remained unresolved on January 26: the attacker's identity, the complete intrusion path, whether the transferred XEM could be recovered, how many customers would ultimately be affected and whether or how customers would be compensated. Claims beyond those boundaries would import later findings into an event-day record.
The scale estimate nevertheless carried institutional weight. The Associated Press reported the ¥58 billion company figure and compared it with the roughly ¥48 billion associated with Mt. Gox's 2014 loss. The comparison explained the immediate attention, but the figures were not perfectly comparable: they reflected different assets, valuation dates, accounting questions and stages of investigation.
Coincheck was also operating while its exchange-registration application remained under review. That status made the incident a test of Japan's still-developing supervision of cryptocurrency intermediaries as well as a private security failure. The event demonstrated that a regulated or registration-pending market structure could still concentrate customer assets behind operational controls that users could not inspect directly.
Later clarification
Coincheck later specified that 526,300,010 XEM was transferred between 00:02 and 08:26 JST on January 26. Its surviving timeline notes that the initially announced incident time of 02:57 was corrected to 00:02 on January 31. These later records sharpen the quantity and window; they were not facts available in final form during January 26.
On February 2, Japan's Financial Services Agency confirmed that it had begun an on-site inspection after the January 26 unauthorized access and outflow. That later regulatory response confirms the institutional significance of the event, but it does not change what Coincheck had established by the close of January 26.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

