South Korean cryptocurrency exchange Bithumb mistakenly credited customers with roughly 620,000 BTC (reported at ~$40B–$44B) after an internal system/configuration error during a promotional payout intended to distribute small rewards of about ₩2,000 (~$1.40). The error reportedly resulted in ~695 accounts receiving outsized balances (in some cases ~2,000 BTC per account), briefly disrupting the exchange’s order books and causing a sharp, short-lived BTC price dislocation on Bithumb (reported at roughly a 17% drop versus other markets).
Bithumb stated the incident was not a hack or external breach and said customer assets remained secure. The exchange reported it detected the issue quickly and restricted trading and withdrawals on affected accounts within about 35 minutes, recovering ~99.7% of the mistakenly credited bitcoin; some recipients reportedly sold portions before controls were applied, contributing to the temporary price impact. Bithumb said it would implement follow-up measures to prevent recurrence, including improved verification and monitoring controls.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-13, the Bank of Korea said crypto exchanges should adopt safeguards similar to stock-market circuit breakers after the Bithumb payout error. The central bank cited weak internal controls, poor supervisory approval, and a malfunctioning fraud-detection system, and recommended real-time ledger-to-blockchain reconciliation and trading halts during abnormal transactions or sharp price swings.
On 2026-04-09, Bithumb moved to freeze seven bitcoin through a local court as a pre-lawsuit measure tied to the February payout error. The exchange said months of recovery efforts had reduced the outstanding amount to seven BTC, and a civil unjust-enrichment case was expected to follow.
On 2026-04-06, South Korea’s Financial Services Commission directed domestic crypto exchanges to reconcile internal ledgers with actual holdings every five minutes, after finding weak reconciliation practices and flaws in trade-halting mechanisms. The regulator also ordered daily publication of asset-matching balances, monthly external verification by accounting firms, and completion of the new system by the end of May.
On or around 2026-02-11, the governor of South Korea's Financial Supervisory Service publicly urged stronger regulatory mechanisms to prevent similar incidents. He specifically highlighted the need to address crypto 'naked selling' risks if digital assets are to be treated more like traditional financial instruments.
By 2026-02-11, Bithumb said it would compensate traders affected by the exchange's internal bitcoin price plunge by paying the difference plus a 10% bonus. The announcement came as scrutiny grew over the exchange's ability to create temporary synthetic balances beyond its actual holdings.
Following the Bithumb error, South Korean financial authorities held emergency discussions and said the incident exposed weaknesses in crypto-exchange controls. Regulators signaled possible on-site inspections or searches if further irregularities are found.
Shortly after the Feb. 6 incident, Bithumb said it had recovered 99.7% of the mistakenly issued bitcoin, while continuing to track the remainder that had been sold, converted, or withdrawn. The exchange also indicated it could pursue legal action against users who do not return the funds.
Within about 35 minutes of detecting the mistake on 2026-02-06, Bithumb restricted trading and withdrawals on affected accounts and moved to reverse the false balances. The exchange later said the incident was an internal operational error, not a hack, and that customer custody remained secure.
On 2026-02-06, Bithumb mistakenly set a promotional payout in bitcoin instead of Korean won, incorrectly crediting about 620,000 BTC across 695 customer accounts. The error caused a sharp temporary dislocation on Bithumb, with its BTC/KRW price falling roughly 17% versus other markets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
8 references tracked. Mallory keeps watching after this page renders.
koreatimes.co.kr
Open sourcecoindesk.com
Open sourcebiz.chosun.com
Open sourcekoreatimes.co.kr
Open sourcetomshardware.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.