KuCoin’s risk system flagged an abnormal Ether transaction at 18:51 UTC on September 25, 2020, beginning the exchange’s response to a hot-wallet breach that ultimately involved Bitcoin, Ether and numerous tokens. The timestamp is a conversion from 02:51 on September 26 in UTC+8, the timezone used in KuCoin’s incident chronology.

The development mattered because it exposed a concentrated point of failure in centralized cryptocurrency custody while involving assets spread across several public blockchains. It also demonstrated the different controls available for native cryptocurrencies, centrally issued tokens and assets traded through decentralized protocols.

KuCoin did not disclose the incident publicly before the end of September 25 UTC. Its first announcement, released on September 26, said large withdrawals had been detected from 03:05:37 in UTC+8—19:05:37 UTC on September 25—and that part of the Bitcoin, ERC-20 and other assets held in its hot wallets had been transferred out. The company said its cold wallets were unaffected, but those were company assertions rather than independently audited findings available on the event date.

The response unfolded across the UTC date boundary

KuCoin’s subsequent chronology said its systems produced another alert at 19:01 UTC on September 25 because hot-wallet balances were abnormal. The exchange formed a response team at 19:15 and shut down its wallet server at 19:20, although abnormal transactions reportedly continued. At 20:20, the wallet team began moving remaining assets into cold storage. These UTC times are Coinburn calculations from KuCoin’s stated UTC+8 timestamps.

The exchange later published the transaction identifier for the first abnormal Ether movement and six additional Ethereum transaction identifiers. KuCoin attributed the outflow to exposure of hot-wallet private keys, said the affected wallets had been replaced and suspended deposits and withdrawals for a security review. It also pledged that its insurance fund would cover affected customer funds. On September 26, however, Chief Executive Johnny Lyu said the exchange was still compiling the affected-token list and evaluating the total value. The coverage pledge therefore remained a contemporaneous corporate commitment, not proof that losses had already been reimbursed.

Why the asset mix mattered

A hot wallet must remain connected closely enough to process customer activity, making its signing credentials operationally useful but more exposed than offline cold storage. Control of a hot-wallet private key can authorize valid-looking blockchain transfers even when the person signing them is unauthorized. Turning off an exchange application also may not stop movements already signed or initiated through compromised credentials.

The diverse asset mix complicated containment. Bitcoin and Ether transfers generally cannot be reversed by an exchange administrator. Some token issuers, by contrast, can freeze particular addresses or replace affected tokens through issuer-controlled contracts. Centralized exchanges can block deposits associated with flagged addresses, while non-custodial exchange protocols do not maintain customer accounts that can be frozen in the same manner. Those distinctions made coordination among KuCoin, issuers, trading venues and blockchain investigators institutionally significant.

What remained unknown on September 25

No defensible dollar total, complete asset inventory or independently established cause was public by the end of September 25 UTC. Valuing a multi-asset theft also requires selecting asset quantities, token prices and a measurement time. Consequently, later estimates should not be treated as figures available during the event itself.

Later context

On September 28, Chainalysis estimated that more than $275 million had been stolen, including 1,008 BTC, 11,543 ETH and multiple token balances. Elliptic’s analysis, published September 29 and updated through 17:00 UTC on October 2, put the total at approximately $281 million, including about $152 million in Ethereum-based tokens. The difference reflects separate analytical snapshots, asset coverage and valuation methods; neither figure was an event-day market quotation. Both firms dated the theft to September 25 and documented subsequent attempts to exchange affected tokens through decentralized protocols.

Primary sourceKuCoin Security Incident Update

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.