Japan’s Financial Services Agency issued a business-improvement order to Coincheck on January 29, 2018, escalating its response to the exchange’s disclosure that NEM belonging to customers had been transferred outside its control.

The regulator described the outflow at approximately ¥58 billion, an incident-time valuation reported by Coincheck after the transfers occurred on January 26. The order did not determine who carried out the unauthorized transfers or guarantee that customers would recover their money. It required the company to investigate what happened, improve its response and show that its governance and technology controls could protect users.

The action mattered beyond one exchange. Japan had introduced a registration system for cryptocurrency exchange businesses in April 2017, positioning itself as an early major economy to place the sector inside a dedicated statutory framework. Coincheck was operating as a transitional, or “deemed,” exchange while its registration application remained under review. The incident therefore tested whether the new framework could address operational failures at a large platform that had not completed registration.

What the regulator required

The FSA’s surviving account says Coincheck was ordered to establish the facts and causes of the incident, respond appropriately to customers, strengthen management oversight of system risk, clarify responsibility, build effective risk controls and devise measures to prevent recurrence. A written report was due by February 13, 2018.

The January 29 order was an improvement order, not an instruction to close Coincheck. That distinction was material because customers were already facing restrictions imposed by the company. Coincheck’s January 28 notice said withdrawals of yen and other currencies were suspended, deposits of non-yen assets were stopped, and yen deposits remained available. The company said it was investigating the cause and working to reinforce security, but it did not provide a reopening schedule.

Contemporaneous reporting also attributed two important custody details to Coincheck: the NEM was held in an internet-connected “hot wallet,” and the wallet did not use NEM’s multisignature functionality. Those statements helped explain why custody architecture became central to the regulatory response, but they did not, by themselves, establish the complete intrusion path or allocate legal responsibility.

Compensation was a plan, not a completed payment

Before the order, Coincheck announced a proposed yen reimbursement for approximately 523 million XEM held by about 260,000 affected customers. It set the proposed rate at ¥88.549 per XEM, based on what it described as the volume-weighted average XEM/JPY price on Zaif from 12:09 JST on January 26 through 23:00 JST on January 27.

Multiplying the stated quantity by that rate produces approximately ¥46.31 billion. That calculation is separate from the approximately ¥58 billion incident valuation, which reflected Coincheck’s rate around the time of the outflow. The two figures therefore used different measurement methods and windows. On January 29, Coincheck had not specified when or how reimbursement would occur, so the announcement remained a company commitment rather than verified payment.

Why the order mattered

The episode exposed a gap between formal regulatory coverage and operational resilience. Registration rules could establish supervisory authority, but they could not prevent losses when wallet security, governance or internal controls were inadequate. The FSA indicated that other cryptocurrency exchanges would also face urgent system-risk checks and possible inspections, turning the Coincheck event into a sector-wide supervisory concern.

For customers, the immediate uncertainties on January 29 concerned access to funds, the timing and enforceability of compensation, and whether Coincheck could continue operating safely. For Japan’s regulator, the central question was whether rapid growth at cryptocurrency businesses had outpaced the controls expected of firms holding customer assets.

Later confirmation

Subsequent FSA records confirmed that the January 29 order followed a January 26 reporting demand, that an on-site inspection began on February 2, and that Coincheck submitted its ordered report on February 13. Those later records corroborate the chronology; they are not evidence that those outcomes were known on January 29.

Primary sourceFSA press conference confirming the January 29 Coincheck order

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.