Worked example · 2018-09
Zaif exchange hack — Multi-asset (BTC, BCH, MONA) — 2018-09-14
Summary
Zaif, a Japanese cryptocurrency exchange operated by Tech Bureau, Inc., suffered a hot-wallet compromise on 2018-09-14. The attacker gained access to Zaif's hot-wallet signing infrastructure and drained approximately 6.7 billion yen (~$60M at then-current exchange rates) in Bitcoin (BTC), Bitcoin Cash (BCH), and MonaCoin (MONA) — the latter being a Japan-origin cryptocurrency with significant domestic adoption.
The Japan Financial Services Agency (FSA) had previously issued business-improvement orders to Tech Bureau, Inc. in 2018, documenting deficiencies in internal controls, risk management, and security governance. The September 2018 breach confirmed that the documented control deficiencies had not been adequately remediated before the attack. The FSA issued a third business-improvement order post-breach.
In the aftermath, Fisco Ltd., a Japanese financial information and investment company, acquired Zaif's operations from Tech Bureau and committed to reimbursing affected users for the stolen assets. The acquisition-and-reimbursement model — where a larger financial entity absorbs the failed exchange rather than allowing a disorderly collapse — became the template for subsequent Japanese exchange interventions (including the later Bitpoint and DMM Bitcoin cases).
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| pre-2018-09 | Japan FSA issues business-improvement orders to Tech Bureau (Zaif parent) documenting internal-control and security deficiencies | (standing T15.003 surface) |
| 2018-09-14 | Attacker compromises Zaif hot-wallet infrastructure; ~$60M (6.7B yen) in BTC + BCH + MONA drained | T15.003 (operator-endpoint compromise) → T11.001 (signing-flow compromise) |
| 2018-09-18 | Zaif discloses breach (4-day delay); FSA issues third business-improvement order | (disclosure + regulatory response) |
| 2018-10 to 2019 | Fisco Ltd. acquires Zaif; commits to reimbursing affected users | (acquirer remediation) |
Realised extraction
Approximately $60M (6.7B yen) in BTC, BCH, and MONA; no confirmed recovery of the stolen assets. Fisco Ltd. committed to user reimbursement as part of the acquisition.
Regulatory context
The Zaif breach is a canonical case of exchange regulatory failure in which a known-deficient operator surface was exploited before mandated remediation was complete. The Japan FSA's pre-breach business-improvement orders documented the standing T15.003 surface; the breach demonstrated the gap between regulatory identification of deficiencies and operator remediation speed. This case is frequently referenced in Japanese and international crypto-regulatory discussions as a justification for mandatory security-audit deadlines and stricter enforcement timelines.
Public references
- Japan Financial Services Agency (FSA) business-improvement orders to Tech Bureau, Inc., 2018
- Fisco Ltd. Zaif acquisition announcement and user-reimbursement commitment, 2018-2019
- Zaif breach disclosure and community reporting, September 2018
- Japanese cryptocurrency exchange regulatory framework and FSA enforcement history