Curriculum·G402 Treasury and Operational Controls·about 31 min
The hot-cold boundary at institutional scale
By the end of this lesson you can
- →Define the hot-cold boundary and why only an operational minimum should sit in a hot wallet
- →Explain how Coincheck's roughly 530 million dollar loss came from keeping a huge balance in one hot wallet
- →Compute the exposure of a hot wallet as the amount that can be lost in a single online compromise
- →Set a hot-wallet float sized to operations, not convenience, and protect even that
Graduate · enrolled learners
This lesson opens with Coincheck, January 2018.
- What happened
- Coincheck was a large Japanese cryptocurrency exchange. In January 2018 attackers stole about 530 million dollars of the NEM token in a single event. The assets had been kept in a hot wallet, one connected to the internet for operational use, holding an enormous balance, and that hot wallet was not protected by multisig even though the NEM protocol supported it. When attackers gained access to the wallet's key, most likely through malware and social engineering against staff, there was nothing between them and the entire balance: it was online, it was large, and it took a single set of credentials to move. The exchange had collapsed the hot-cold boundary by keeping far more than it needed for operations in the one place an online compromise could reach, so a routine intrusion became one of the largest thefts on record.
- The decision point
- A hot wallet is online so an institution can operate, process withdrawals, rebalance, meet demand, and everything online is reachable by an attacker who compromises it, so the amount in a hot wallet is the amount the institution can lose in a single intrusion. The hot-cold boundary is the deliberate line between the small operational float kept hot and the bulk of assets kept cold, offline, and out of any single online compromise's reach. Coincheck erased that line: it held roughly 530 million dollars in a hot wallet, so a single credential compromise exposed a half-billion dollars, and it compounded the error by not even protecting that hot wallet with the multisig its asset supported. Setting the boundary is the core operational decision, size the hot float to what operations actually require and no more, sweep the rest to cold, and protect even the float, because a hot wallet's balance is not a convenience, it is the blast radius of the next intrusion.
- Recorded loss
- $530,000,000
What you will be able to answer
- →How did Coincheck lose about 530 million dollars?
- →What is a hot wallet's exposure?
- →What is the hot-cold boundary, and how do you set it?
- →What compounded Coincheck's exposure?
Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.
It is free. We do not sell the list and there is nothing to buy at the end of it.
Sources and review
- https://www.reuters.com/article/us-japan-cryptocurrency-idUSKBN1FF29X
- https://www.investopedia.com/terms/h/hot-wallet.asp
- https://www.bbc.com/news/world-asia-42845505
Confidence high·Volatility low·Reviewed 2026-09-16·Owner unassigned
Contested
The Coincheck loss is commonly cited around 530 million dollars (about 58 billion yen) of NEM in January 2018; the exact figure depends on the NEM price at the time. That the assets were in a hot wallet without multisig is documented in Coincheck's own statements and reporting.
The precise intrusion method (malware and social engineering) was reconstructed after the fact; the core lesson, an oversized unprotected hot wallet, holds regardless of the exact entry vector.
