Japan Domestic VASP Crypto Asset Breach History (2014-2026)
ConfidenceLikelyUpdated2026-07-29Review by2027-01-29Sources3Machine-translatedOriginal (JA)
On this page
Overview
This entry organizes major asset-loss incidents affecting Japanese exchange operators or domestic customers, limited to amounts, asset quantities, and outcomes confirmed by public authorities and the companies involved. It presents the chronology of incidents, legislation, and self-regulation, but does not claim that a single incident caused a specific rule unless an official source states that relationship.
Major Incident Timeline
Amounts are contemporaneous estimates; crypto-asset quantities and yen conversions are kept distinct. The table uses public materials for Mt.Gox, Coincheck, Zaif, BITPoint, and DMM Bitcoin. A Liquid incident from a different period is excluded because it could not be established on the same basis. ^[Sources: https://www.fsa.go.jp/news/30/virtual_currency/20180308.html; https://www.fsa.go.jp/news/30/virtual_currency/20180925.html; https://www.remixpoint.co.jp/corporate/press/2019/; https://www.npa.go.jp/bureau/cyber/koho/caution/caution20241224.html; https://www.dmm.com/bitcoin/news/20241202_01.html.]
| Date | VASP | Breach scale | Outcome |
|---|---|---|---|
| 2014-02 | Mt.Gox | About 850,000 BTC (reported as about 750,000 customer BTC and 100,000 company BTC) | Legal proceedings followed, ultimately under civil rehabilitation |
| 2018-01 | jp-exchange-coincheck | About 523 million XEM, then approximately ¥58 billion | FSA business-improvement order; later acquired by Monex Group |
| 2018-09 | jp-exchange-zaif (former Tech Bureau) | Approximately ¥6.7 billion | FSA business-improvement order; Zaif business transferred to Fisco Cryptocurrency Exchange |
| 2019-07 | BITPoint Japan | Approximately ¥3.02 billion | Then-parent Remixpoint disclosed the incident and implemented service suspension and resumption measures |
| 2024-05 | jp-exchange-dmm-bitcoin | 4,502.9 BTC, then approximately ¥48.2 billion | NPA and partners attributed the theft to TraderTraitor; customer accounts and entrusted assets transferred to SBI VC Trade |
Regulatory Reflection (3 Phases)
- 2017 Payment Services Act amendment — Introduced the registration framework for crypto-asset exchange operators
- 2018-2020 self-regulation and operator rules — JVCEA became a certified association under the Payment Services Act; legislation and self-regulation developed customer-asset management and performance-guarantee crypto assets corresponding to online holdings
- 2020 FIEA and related amendments — Brought crypto-asset derivatives into the Financial Instruments and Exchange Act framework and amended customer-asset rules for exchange operators
These phases show the order in which the frameworks took effect, not a one-to-one causal relationship with individual incidents.
Significance of the Lazarus Attribution
For the DMM Bitcoin incident, Japan’s National Police Agency published a joint statement with the FBI and the US Department of Defense Cyber Crime Center attributing the activity to TraderTraitor, associated with North Korean authorities. The statement describes attackers approaching an employee of contractor jp-custody-ginco under the guise of recruitment, inducing execution of a malicious Python script, and abusing session information from a communications system to manipulate a transaction request. It does not state that the signing key itself was stolen.
Related
- jp-exchange-coincheck · jp-exchange-zaif · jp-exchange-custodiem · jp-exchange-dmm-bitcoin
- jp-foreign-exchange-bitforex — Record of an overseas operator warned for unregistered business in Japan
- japan-financial-regulation — Payment Services Act / FIEA framework
- jp-custody-ginco — DMM incident intrusion vector
Sources: Compiled from public information (FSA business improvement orders and administrative actions, JVCEA announcements, IR releases and press conferences and third-party committee investigation reports of the relevant entities, National Police Agency / Cyber Police Bureau announcements, Chainalysis / Elliptic public research)
Discovery
Keep reading
Read next
- Japan domestic VASP parent-company / shareholder-structure mapThe FSA crypto-asset exchange service provider registry lists 26 operators as of 2026-06-30. This page starts from the parent-company attributes of that official population and separately la...
- Domestic Web3 / Crypto-Asset Public Policy Body Layer (METI Web3 Policy Office / LDP web3 PT / Cabinet Secretariat)Japanese Web3 and crypto-asset policy involves the FSA's financial regulation, METI's industrial policy, cross-government work by the Cabinet Secretariat and Digital Agency, and policy propo...
- JVCEA: Overview of the Self-Regulatory Framework1. Membership screening: Reviews the structure and compliance of VASPs applying for membership, both before and after FSA registration 2. Token review (White List): Prior-review framework fo...
Links here
- Bybit Lazarus $14.6 億 hack detailed analysis (2025-02) — largest crypto-asset outflow in history2025-02-21, approximately $14.6 億 (about 2,200 億円) equivalent of ETH + stETH + mETH and others flowed out of Bybit's ETH cold wallet. This is the largest crypto-asset theft in history, excee...
- Coincheck NEM 580 億円 outflow incident detailed analysis (2018-01)In the early hours of 2018-01-26, approximately 5.2 億 XEM (worth about 580 億円 at the time) flowed out of Coincheck's NEM (XEM) hot wallet to external addresses. At the time this was the larg...
- Crypto-asset custody provider landscape matrix — Japan + Global institutional custody 10 社 technology / regulation / customer comparisonThe institutional crypto-asset custody market is differentiated along three axes: (1) technology model (cold storage / MPC / hybrid) × (2) license tier (Trust Charter / VASP / vendor only) ×...
- DMM Bitcoin outflow incident detailed analysis(2024-05)— 4,502.9 BTC attributed to LazarusOn the evening of 2024-05-31, 4,502.9 BTC(equivalent to approx. 482 億円)was illicitly drained from DMM Bitcoin. At the time, it was the largest domestic outflow incident after the jp exchange...
- FSA Business Improvement Order (BIO) domestic VASP administrative-action history (2018-2026)A Business Improvement Order (BIO) is, among the administrative actions the Financial Services Agency issues to supervised operators, a mid-level action ordering the submission and execution...