KuCoin disclosed a security breach on September 26, 2020, saying unauthorized transfers had removed Bitcoin, ERC-20 tokens and other digital assets from its hot wallets. The exchange suspended deposits and withdrawals, redeployed its hot wallets and said its cold-wallet holdings were unaffected.
The announcement established an important fact without establishing the incident’s final size. KuCoin had not completed its asset inventory, published a comprehensive loss calculation or provided an independently verified account of the intrusion by the end of September 26. That distinction matters: the breach and service suspension were confirmed, but many of the numbers later associated with the incident were not yet part of the settled record.
The timeline KuCoin reported
KuCoin’s initial notice said it detected large withdrawals beginning at 03:05:37 in UTC+8 on September 26, 2020. That timestamp corresponds to 19:05:37 UTC on September 25, illustrating why reports using different time zones assigned different calendar dates to the first transactions. Coinburn uses September 26 because that was the date in KuCoin’s incident record and disclosure.
In a September 26 livestream recap, KuCoin provided a more detailed company-reported sequence. It said its risk-management system issued an alert for an abnormal ether transaction at 02:51 UTC+8, followed by alerts involving additional ETH and ERC-20 transfers. KuCoin said it formed an incident team at 03:15, shut down the wallet server at 03:20 and began moving remaining hot-wallet assets to cold storage at 04:20.
The recap identified an Ethereum transaction hash and a recipient address associated with the abnormal activity. These identifiers made part of the asset movement publicly inspectable, but they did not by themselves establish the complete loss across every blockchain or determine who controlled the destination addresses.
KuCoin publicly announced the incident at 10:41 UTC+8. It said deposits and withdrawals would remain suspended during a security review and promised that affected user funds would be covered by KuCoin and what it described as its insurance fund. That reimbursement statement was a company commitment, not proof on September 26 that every liability had already been measured or funded.
What was verified—and what remained a claim
The strongest verified development was operational: assets left exchange-controlled hot wallets without authorization, KuCoin replaced those wallets, and customers temporarily lost the ability to deposit or withdraw. Those measures signaled that KuCoin considered the incident serious enough to isolate wallet infrastructure and restrict access while investigating.
Chief executive Johnny Lyu attributed the outflow to leakage of hot-wallet private keys. Because that explanation came from KuCoin’s internal investigation, it should be treated as the exchange’s contemporaneous finding rather than an independent forensic conclusion. KuCoin also said cold wallets were safe and the affected funds represented a small portion of its holdings, but it did not publish reserve data on September 26 that would allow outsiders to verify either assertion quantitatively.
Independent reporting documented visible transfers and attempted to value selected addresses. Those estimates were necessarily incomplete and sensitive to the addresses included, token liquidity, price source and valuation time. A defensible September 26 account therefore avoids presenting a later headline loss figure as if KuCoin had confirmed it that day.
Why it mattered
The incident exposed a central tension in exchange-based cryptocurrency markets. Blockchain transfers can be publicly traceable while the custody systems authorizing them remain opaque. Customers could watch assets move on public ledgers, yet they still depended on KuCoin for an accurate inventory, an explanation of the compromise and restoration of withdrawals.
For the wider market, the immediate institutional question was not simply the nominal value transferred. It was whether counterparties could identify and restrict suspicious addresses across multiple networks without disrupting legitimate users or confusing issuer intervention with recovery. On September 26, those efforts were only beginning, and their eventual effectiveness was not yet knowable.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

