Japanese cryptocurrency exchange Zaif disclosed on September 20, 2018, that unauthorized access to an online wallet had resulted in the loss of bitcoin, bitcoin cash and monacoin provisionally valued at approximately ¥6.7 billion.

The announcement made the breach one of the year’s largest cryptocurrency-exchange losses and raised an immediate institutional question: how had a registered operator suffered a major hot-wallet compromise after Japan’s Financial Services Agency had already ordered it to improve its controls twice in 2018?

Zaif’s operator, Tech Bureau, estimated on September 20 that approximately ¥4.5 billion of the missing cryptocurrency belonged to customers and ¥2.2 billion represented company assets. Those were preliminary yen valuations, not independently audited loss figures, and cryptocurrency prices could change their value while the investigation continued.

A breach discovered over several days

According to Tech Bureau’s account relayed in contemporaneous reporting, unauthorized transfers occurred during an approximately two-hour period on September 14, 2018. The company detected a server abnormality on September 17 and confirmed unauthorized access on September 18. Its public disclosure followed on September 20.

The compromised system was described as a hot wallet used for deposits and withdrawals. Unlike cold-storage arrangements kept offline, a hot wallet remains connected to operational systems so an exchange can process customer transactions. That accessibility also creates a larger attack surface.

The surviving September 20 record established the affected assets and estimated value, but it did not establish who conducted the attack, precisely how access was obtained or whether all relevant wallet movements had been identified. No attribution to a particular person or group was verified on that date.

Financial support was proposed, not completed

Fisco, a listed Japanese financial-services company affiliated with a cryptocurrency exchange, announced on September 20 that it planned to support Tech Bureau. The contemplated arrangement included ¥5 billion in financial assistance, acquisition of a majority interest and the dispatch of directors and an auditor.

That proposal mattered because the estimated customer loss exceeded Tech Bureau’s disclosed company-asset portion of the theft. It nevertheless remained a proposed support arrangement on September 20. The announcement was not proof that funding had been transferred, that a final transaction had closed or that every customer claim would be repaid.

The episode therefore combined two distinct risks: the technical risk created by keeping transferable assets online and the balance-sheet risk of meeting customer obligations after those assets disappeared.

Japan’s licensing framework faced another test

Tech Bureau was not an unknown or unregistered operator. Japan’s regulatory records show that the company had been registered as a cryptocurrency-exchange business in September 2017.

The FSA had issued a business-improvement order on March 8, 2018, concerning system-risk management and customer-response controls. A second order followed on June 22 after regulators identified deficiencies involving governance, legal compliance, anti-money-laundering controls, customer-asset segregation and other internal systems.

That history made the Zaif loss more consequential than an isolated security incident. Japan had placed cryptocurrency exchanges inside a formal supervisory framework, yet registration and prior enforcement had not prevented a large loss at an inspected firm. The breach put pressure on regulators to determine whether operators’ written controls were functioning in practice.

What remained unresolved on September 20

An FSA chronology published after the event records that the agency began an on-site inspection of Tech Bureau on September 20. That later document clarifies the same-day regulatory response but does not change what remained unknown when the breach was disclosed.

As of September 20, the loss estimate was provisional, the attack method and perpetrator were unidentified, the proposed Fisco support was not final, and the timetable for restoring affected services or making customers whole had not been established.

Primary sourceFisco — System and financial support for Tech Bureau, September 20, 2018

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.