Japan’s financial regulator said on Monday it would inspect all cryptocurrency exchanges and ordered Coincheck to get its act together after hackers stole $530 million worth of digital money from its exchange in one of the biggest cyber heists on record.
The theft highlights the vulnerabilities in trading an asset that global policymakers are struggling to regulate and the broader risks for Japan as it aims to leverage the fintech industry to stimulate economic growth.
The Financial Services Agency (FSA) on Monday ordered improvements to operations at Tokyo-based Coincheck, which on Friday suspended trading in all cryptocurrencies except bitcoin after hackers stole 58 billion yen ($534 million) of NEM coins, among the most popular digital currencies in the world.
Coincheck said on Sunday it would return about 90 percent with internal funds, though it has yet to figure out how or when.
The NEM coins were stored in a “hot wallet” instead of the more secure “cold wallet”, which operates on platforms not directly connected to the internet, Coincheck said. It also does not use an extra layer of security known as a multi-signature system.
The hack has drawn into focus Japan’s approach to regulating cryptocurrency exchanges. Last year, it became the first country to regulate exchanges at the national level – a move that won praise for boosting innovation and protecting consumers, and that contrasts sharply with crackdowns in South Korea and China.
The FSA said it ordered Coincheck to submit a report on the hack and measures for preventing a recurrence by Feb. 13, and that it will, if necessary, conduct on-site inspections of other cryptocurrency exchanges.
The regulator also said it has yet to confirm whether Coincheck had sufficient funds for the reimbursement.
But the regulator does not have any rules banning the use of “hot wallets” by exchanges, nor does it set requirements on how much should be kept in “cold wallets,” an FSA official said at a briefing.
In response to FSA’s order for improvements, Coincheck said in a statement that it would promptly strengthen its customer protection and governance, and develop its risk management systems.