KuCoin reopened deposits and withdrawals for 17 digital assets on October 4, 2020, advancing a phased recovery from the security breach that had forced the exchange to suspend wallet services in September.
Two KuCoin notices dated October 4 documented the restoration. The first covered Enecuum, Aion, Polkadot, Zilliqa, Binance Coin, Matrix AI Network, Harmony, Insolar and Tezos. The second covered Safe Haven, TomoChain, VeChain, GoChain, High Performance Blockchain, Blockstack, Wanchain and VeThor Token.
For both groups, KuCoin said deposit addresses had changed and instructed customers not to send funds to their old addresses. The exchange also made clear that the restoration was incomplete: deposits and withdrawals for bitcoin, ether and tether were still awaiting reopening.
A controlled return of wallet access
The October 4 notices mattered because exchange recovery is not established merely by declaring customer balances intact. An exchange must also rebuild or replace compromised wallet infrastructure, reconcile its internal ledger, generate secure deposit addresses and restore withdrawals without exposing remaining assets to another loss.
KuCoin had disclosed on September 26 that unauthorized transfers affected bitcoin, ERC-20 tokens and other assets held in its hot wallets. It said its cold wallets were unaffected, promised that KuCoin and an insurance fund would cover any customer losses, and suspended deposits and withdrawals while conducting a security review. Those statements were company claims; the surviving notice did not provide an independently audited balance sheet or a complete valuation of the assets removed.
The October 4 reopening therefore supplied a narrower but directly verifiable operational fact. Seventeen named assets could again move into and out of the exchange, subject to customers using the replacement addresses. It did not establish that KuCoin had completed its investigation, recovered every stolen token or restored unrestricted service across the platform.
Recovery collided with token governance
The breach also demonstrated how recovery could depend on the design and governance of individual assets. Some token issuers and infrastructure providers could freeze addresses, replace contracts or coordinate token swaps. Those interventions could prevent an attacker from freely transferring particular tokens, but they also exposed the practical authority retained by project teams over assets commonly described as decentralized.
Blockchain-analysis firm Chainalysis estimated that more than $275 million in cryptocurrency had been stolen. Its account, updated with observations through 10:00 a.m. Eastern on October 2, traced movements involving bitcoin, ether, tether and numerous tokens. Chainalysis reported that stolen assets had been routed through centralized exchanges, mixing services and decentralized exchanges including Uniswap and Kyber.
That analysis illustrated a central limitation of the recovery figures circulating around October 4. A token being frozen, replaced or placed outside an attacker’s control was not necessarily the same as cash being returned to KuCoin. Values also changed with token prices, and different reports used different asset inventories and valuation times. For those reasons, this reconstruction does not combine the exchange’s recovery claims with Chainalysis estimates into a single calculated recovery percentage.
What remained unresolved on October 4
A contemporaneous report from The Block said KuCoin chief executive Johnny Lyu claimed that suspects had been identified and that law enforcement was involved. It also relayed his claim that assets worth $204 million had been put outside suspicious addresses’ control. Neither the suspects’ identities nor independent proof supporting that figure was publicly presented in the cited record.
As of October 4, the defensible conclusion was limited: KuCoin was restoring selected wallet functions, but its most important transfer rails remained closed and the breach investigation was still unresolved. The 17-asset reopening marked measurable progress, not completion of the recovery.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

