Japan’s Financial Services Agency began an on-site inspection of Coincheck on February 2, 2018, one week after unauthorized access resulted in the removal of NEM tokens from the Tokyo cryptocurrency exchange. The inspection converted a major security incident into a direct test of Japan’s recently introduced supervisory framework for virtual-currency businesses.
The FSA said it acted under Article 63-15, Paragraph 1 of the Payment Services Act. That provision authorized officials to enter an operator’s premises, question personnel, and examine its business, finances, books and other materials. Finance Minister Taro Aso said the immediate purpose was user protection while the agency investigated Coincheck’s position and response.
Scrutiny widened beyond Coincheck
The February 2 notice also disclosed that the FSA had issued system-risk reporting orders on February 1 to every listed exchange operator other than Coincheck: 16 registered virtual-currency exchange providers and 15 operators working under transitional, or “deemed,” status.
That sector-wide demand mattered as much as the physical inspection. It indicated that the agency was treating the Coincheck incident as a potential warning about controls across the exchange industry, rather than solely as a problem at one company. The requested reports concerned operators’ system-risk management arrangements.
Japan’s registration system for virtual-currency exchange providers had taken effect on April 1, 2017. Coincheck was still operating under the law’s transitional provisions while its registration application remained under review. The FSA’s November 2017 guidance said applicants were expected to possess an adequate financial base and systems capable of supporting secure operations and legal compliance.
A security incident became a supervisory test
The NEM Foundation said on February 1 that approximately 526 million XEM had been reported missing from Coincheck wallets after the January 26 security breach. It attributed the loss to the exchange wallet and said the NEM protocol itself remained secure. That was an institutional statement from an organization associated with the network, not an independent forensic finding or a final determination about responsibility.
Reuters reported on February 2 that 10 FSA officials entered Coincheck’s office and that the inspection covered customer compensation, the company’s financial condition, system management and consumer-protection efforts. Reuters also reported that Coincheck had proposed repaying approximately ¥46.3 billion to affected customers, while the FSA had not yet confirmed that the company possessed sufficient reimbursement funds.
Those distinctions were important on February 2. A promised repayment was not a completed payment, and an inspection was not a finding that compensation could be delivered. The identity of the attacker, the complete technical path of the breach and the final amount recoverable by customers remained unresolved.
Market stress formed the backdrop
The inspection arrived during a broad cryptocurrency selloff. Bloomberg consolidated pricing, as reported contemporaneously, placed bitcoin at $8,378 at 8:05 a.m. London time on February 2, down 8% and at its lowest level since November 24, 2017. That observation concerned BTC priced in U.S. dollars at a specific intraday timestamp; it was neither a universal market close nor proof that the Coincheck inspection caused the decline.
Regulatory concern, security failures and doubts about exchange controls were all weighing on sentiment, but the surviving reports do not permit a defensible allocation of that day’s price movement among individual headlines.
What February 2 established
The verified development was procedural but consequential: Japan’s regulator exercised its statutory inspection authority at Coincheck and required system-risk information from 31 other operators. It showed that Japan’s exchange-registration regime was moving from application screening and written orders toward direct examination.
As of February 2, the inspection had not produced published findings, resolved Coincheck’s registration, verified customer repayment or established criminal attribution. Those limits define the event-day record and prevent later outcomes from being projected backward into the initial regulatory action.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

