Loss: approximately $40M+ USD at-the-time across a portfolio of ERC-20 tokens — per Coinrail's contemporaneous public statements and subsequent industry-forensic analysis, the principal stolen assets were Pundi X (NPXS, the largest single-token component), Aston (ATX), NPER (NPER), TRON (TRX), and Dent (DENT) — with the aggregate at-time loss figure widely reported as approximately 30% of Coinrail's listed-asset holdings. The figure was always provisional given the nature of the long-tail-ERC-20 portfolio (illiquid markets, market-moving sell-pressure on the stolen tokens themselves), and contributors using it should treat ~$40M as the order-of-magnitude reference figure rather than as a precision number. Recovery: mixed and partial. Coinrail recovered approximately two-thirds of the stolen assets through coordination with token-issuer projects (notably Pundi X and several others co-operated to freeze and / or roll back the stolen-token balances at the contract level, taking advantage of the centralised mint-and-blacklist authority that several of the affected ERC-20 contracts retained) and through cooperative engagement with downstream exchanges that froze deposits matching the attacker-cluster wallets. The remaining one-third was lost or laundered to ground. Coinrail itself resumed trading on a partial / restricted basis on 2018-07-15 and continued operations through subsequent years on a smaller scale than at peak. OAK Techniques observed: OAK-T15.001 (Social-engineering of operator personnel — spear-phishing-led malware delivery, OAK-G01 / TraderTraitor cohort pattern) + OAK-T15.003 (Operator endpoint compromise) for the off-chain pre-positioning phase. On-chain manifestation: OAK-T11 broadly construed (custody-side compromise — operator-side hot-wallet key compromise) producing authorised withdrawals across the population of ERC-20 token contracts that Coinrail held in hot-wallet inventory. Structurally adjacent to OAK-T11.002 entry-vector class. Attribution: inferred-strong — South Korean intelligence and Korean Internet & Security Agency (KISA) reporting in 2018 placed the Coinrail event within the 2017–2018 wave of South Korean exchange compromises attributed to North Korean state-aligned actors; subsequent industry-forensic corroboration (Chainalysis, Recorded Future, Kaspersky) places the Coinrail event within the same 2017–2018 OAK-G01 / Lazarus cohort that includes Bithumb 2017, NiceHash 2017-12, Coincheck 2018-01, Bithumb 2018-06 (separate later-2018 incident), and Coinrail 2018-06. No DOJ indictment names the Coinrail 2018 case specifically at the OAK v0.1 cutoff. OAK-Gnn: OAK-G01 Lazarus Group / DPRK-attributed.
Key teaching point: Coinrail 2018 is the canonical OAK-record illustration of the multi-asset long-tail ERC-20 portfolio compromise shape — an exchange compromise where the load-bearing loss is distributed across many ERC-20 token contracts rather than concentrated in a single high-liquidity asset. The case is the cleanest available reference for the recovery-via-token-issuer-co-operation mechanism at exchange scale: several of the affected ERC-20 token contracts retained centralised mint-and-blacklist authority that allowed token-issuer projects to freeze, rollback, or replace the stolen-token balances at the contract level — a recovery mechanism that is unavailable for non-ERC-20 native-asset compromises (Bitcoin, Ethereum mainnet, Monero, Bitcoin Cash, etc.) and that has subsequently been deprecated as a recovery option as the post-2020 ERC-20 ecosystem moved toward immutable token contracts.
Coinrail was a South Korean cryptocurrency exchange headquartered in Seoul, operating since approximately 2017, with a listing surface heavily weighted toward long-tail ERC-20 tokens — at peak, Coinrail listed substantially more ERC-20 token markets than larger Korean rivals (Bithumb, Upbit, Korbit, Coinone), and its operational scale was correspondingly weighted toward the long-tail ERC-20 surface. On 2018-06-09 / 2018-06-10 (Korea Standard Time), Coinrail detected unauthorised withdrawals across a portfolio of ERC-20 token balances from its hot-wallet infrastructure. Coinrail announced the breach publicly on 2018-06-10 and engaged Korean Internet & Security Agency (KISA) and South Korean police on incident response.
The proximate technical mechanism per public-record analysis was operator-side compromise of Coinrail's hot-wallet key material with authority to authorise withdrawals across the population of ERC-20 token contracts that Coinrail held in hot-wallet inventory. The exact entry vector was not publicly disclosed by Coinrail in technical detail; Korean press and Korean Internet & Security Agency-adjacent commentary in 2018 was consistent with the canonical 2017–2018 South-Korean-exchange pattern of spear-phishing-led malware delivery against operator endpoints, with lateral movement from the compromised endpoint to wallet-management infrastructure that authorised the multi-asset withdrawal. Coinrail's public statements and subsequent press coverage placed the principal stolen assets at Pundi X (NPXS) as the largest single-token component, with Aston (ATX), NPER (NPER), TRON (TRX), and Dent (DENT) as the next-largest components.
Coinrail's response is the case's most operationally distinctive feature for OAK's recovery-mechanism documentation. Within hours of the breach disclosure Coinrail engaged the affected ERC-20 token-issuer projects, several of which (Pundi X and adjacent projects) co-operated to freeze and / or roll back the stolen-token balances at the contract level, taking advantage of the centralised mint-and-blacklist authority that their ERC-20 contracts retained. Coinrail also coordinated with downstream Korean and international exchanges to freeze deposits matching the attacker-cluster wallets. The cumulative effect was that approximately two-thirds of the stolen assets were either frozen at the contract level, rolled back via token-issuer reissuance, or frozen at downstream exchange deposit endpoints; the remaining one-third was lost or laundered to ground. Coinrail itself resumed partial trading on 2018-07-15 and continued operations through subsequent years on a smaller scale than at peak.
For OAK's purposes the Coinrail 2018 case is the canonical reference for two structurally distinctive features. First, it is the canonical multi-asset long-tail ERC-20 portfolio compromise worked example — an exchange compromise where the load-bearing loss is distributed across many ERC-20 token contracts rather than concentrated in a single high-liquidity asset, with the operational implications that follow (illiquid downstream markets, market-moving sell-pressure on the stolen tokens themselves, and the contract-level recovery surface that ERC-20 mint-and-blacklist authority makes available). Second, it is the cleanest available reference for recovery-via-token-issuer-co-operation at exchange scale, a recovery mechanism that has been substantially deprecated as the post-2020 ERC-20 ecosystem moved toward immutable token contracts.
| When | Event | OAK ref |
|---|---|---|
| Pre-event (2018-Q1–Q2) | Spear-phishing-led malware delivery against a Coinrail operator endpoint with credentials and operational access to wallet-management infrastructure (candidate vector per industry-forensic analysis; not publicly disclosed in technical detail by Coinrail). The 2017–2018 South-Korean-exchange-targeting wave attributed to North Korean state-aligned actors covers this pre-event window. | T11 entry — operator-endpoint compromise (vector inferred from cohort) |
| 2018-06-09 / 2018-06-10 (KST) | Attacker reaches Coinrail wallet-management infrastructure via lateral movement from the compromised operator endpoint; issues authorised withdrawals across the population of ERC-20 token contracts that Coinrail held in hot-wallet inventory. Aggregate at-time loss ~$40M+ across Pundi X (NPXS, largest single-token component), Aston (ATX), NPER (NPER), TRON (TRX), Dent (DENT), and adjacent long-tail ERC-20 holdings. | T11 extraction — multi-asset ERC-20 portfolio drain |
| 2018-06-10 (KST) | Coinrail detects the unauthorised withdrawals; suspends trading; announces the breach publicly. | (operator detection / disclosure) |
| 2018-06-10 onward | Coinrail engages Korean Internet & Security Agency (KISA) and South Korean police on incident response. Coordinated outreach to affected ERC-20 token-issuer projects begins within hours of disclosure. | (law-enforcement and token-issuer engagement) |
| 2018-06-10 to 2018-06-15 (KST) | Pundi X and adjacent ERC-20 token-issuer projects co-operate to freeze and / or roll back the stolen-token balances at the contract level, taking advantage of the centralised mint-and-blacklist authority that their ERC-20 contracts retained. Several token issuers issue replacement tokens to restore Coinrail's pre-compromise position; downstream Korean and international exchanges freeze deposits matching the attacker-cluster wallets. | Recovery — token-issuer co-operation + downstream-exchange freezing |
| 2018-06 onward | Korean Internet & Security Agency (KISA) and Korean intelligence reporting place the Coinrail event within the 2017–2018 wave of South Korean exchange compromises attributed to North Korean state-aligned actors. | G01 attribution — inferred-strong |
| 2018-07-15 (KST) | Coinrail partially resumes trading on a restricted basis; subsequent operational scale-down across the months following the breach. | (operational partial-recovery) |
| 2018-Q3–Q4 | Industry-forensic corroboration (Chainalysis, Recorded Future, Kaspersky) places the Coinrail event within the 2017–2018 OAK-G01 / Lazarus cohort that includes Bithumb 2017, NiceHash 2017-12, Coincheck 2018-01, and Bithumb 2018-06. | Cohort attribution — inferred-strong |
| 2018 → 2020 | Stolen tokens that escaped the freezing-and-rollback recovery (~one-third of the at-time loss) laundered through chain-hopping, mixer routing, and the canonical 2018-era Lazarus-cluster laundering rails. | T7-class long-tail laundering on the unrecovered fraction |
| 2020 onward | Coinrail continues operations on a smaller scale than at peak; the operating entity remains in business through the OAK v0.1 cutoff. | (continuing operations) |
- Pre-event: the load-bearing failure was the canonical 2017–2018 T11 / T11.002 South-Korean-exchange pattern — operator endpoint with persistent operational reach to wallet-management infrastructure capable of authorising withdrawals across the full hot-wallet inventory; spear-phishing-led malware delivery against the endpoint produces lateral movement to wallet-management infrastructure; authorised-from-the-signing-host withdrawals drain the hot-wallet inventory at scale. The defender lesson is identical to the lesson the NiceHash 2017 case carries (and to the broader 2015–2024 lineage of single-engineer-endpoint-with-wallet-management-reach compromises), and contributors writing T11 / T11.002 Technique pages should treat Coinrail 2018 as one of the 2018-era cohort references for the lineage.
- At-event (multi-asset extraction): the load-bearing distinction from the canonical 2017–2018 cohort is the multi-asset shape of the extraction — distributed across the population of ERC-20 token contracts that Coinrail held in hot-wallet inventory rather than concentrated in a single high-liquidity asset. The defender-side implication is that hot-wallet inventory composition matters for the operational shape of an extraction event: an exchange holding a long-tail ERC-20 portfolio in a single hot-wallet signing-authority surface produces a multi-asset drain when that signing authority is compromised, with the additional operational complications of illiquid downstream markets and market-moving sell-pressure on the stolen tokens themselves. The post-2020 industry baseline of segregating signing authority across asset classes — and of holding only operational-liquidity-required hot-wallet inventory rather than the full asset-listing surface in a single hot-wallet authority — is in part retro-engineered against this multi-asset-extraction shape.
- Post-event (recovery — token-issuer co-operation): Coinrail's response is the case's most operationally distinctive feature. Within hours of the breach disclosure Coinrail engaged the affected ERC-20 token-issuer projects; several co-operated to freeze and / or roll back the stolen-token balances at the contract level. The cumulative effect was approximately two-thirds recovery of the stolen assets at the contract level. The defender lesson is two-sided: (1) for pre-2020-era ERC-20 holdings where token-issuer projects retained centralised mint-and-blacklist authority, exchange-incident-response runbooks should explicitly include rapid token-issuer outreach as a recovery mechanism distinct from on-chain forensic tracing; (2) for post-2020-era holdings where token-issuer projects have substantially deprecated the centralised mint-and-blacklist authority in favour of immutable token contracts, this recovery mechanism is no longer available, and exchange incident-response runbooks should not rely on it.
- Post-event (downstream-exchange freezing): Coinrail's coordinated outreach to downstream Korean and international exchanges produced effective freezing of attacker-cluster deposits — a recovery mechanism that is distinct from contract-level freezing and that remains operationally available for post-2020-era exchange compromises. The defender lesson is that fast (within-hours) outreach to downstream exchange incident-response contacts is itself a recovery mechanism that exchange-incident runbooks should explicitly include; the post-2020 industry baseline of standing inter-exchange incident-response communication channels (notably the "T+0 outreach" patterns Chainalysis and similar tracing-providers facilitate) is partly retro-engineered against the lessons of the 2017–2018 cohort, of which Coinrail is one of the cleanest references.
- Post-event (attribution): the case sits within the 2017–2018 OAK-G01 / Lazarus cohort but the public-record attribution rests on the South Korean intelligence finding plus industry-forensic corroboration; no DOJ indictment names the Coinrail 2018 case specifically at the OAK v0.1 cutoff. Contributors writing operator-accountability or attribution-axis material should preserve the
inferred-strongnotation rather than over-claiming aconfirmedattribution that the public record does not support.
- Coinrail 2018 is the canonical OAK-record reference for the multi-asset long-tail ERC-20 portfolio compromise shape. Most exchange-hack worked examples in OAK's corpus document compromises concentrated in a single high-liquidity asset (Bitcoin: Mt. Gox, Bitfinex, NiceHash; Ethereum: Bitstamp, KuCoin Ethereum-side; NEM: Coincheck). Coinrail 2018 documents an exchange compromise where the load-bearing loss is distributed across many ERC-20 token contracts. Contributors writing T11-class Technique pages should cross-reference Coinrail as the case that demonstrates the multi-asset-extraction-shape variation within the broader T11 family, with the operational implications that follow — illiquid downstream markets, market-moving sell-pressure on the stolen tokens themselves, and the contract-level recovery surface that ERC-20 mint-and-blacklist authority makes available for the 2017–2018 era.
- Recovery-via-token-issuer-co-operation is its own analytic shape and deserves an explicit M-axis treatment. OAK's mitigation taxonomy currently emphasises pre-event controls (custody-design, signing-authority management, anomaly detection) and post-event on-chain forensics. The Coinrail case demonstrates a distinct post-event recovery mechanism — rapid token-issuer outreach producing contract-level freezing or rollback of stolen-token balances — that was operationally available for the 2017–2018-era ERC-20 ecosystem and that remains available (in attenuated form) for those post-2020-era token contracts that have retained centralised mint-and-blacklist authority. Contributors writing M-axis pages on post-event recovery mechanisms should treat token-issuer-co-operation as a distinct mitigation class, with Coinrail 2018 as the canonical reference for the maximum-availability era and with explicit notes about the post-2020-era deprecation.
- The 2017–2018 OAK-G01 cohort framing should explicitly include Coinrail 2018. The cohort surface — Bithumb 2017, NiceHash 2017-12, Coincheck 2018-01, Coinrail 2018-06, Bithumb 2018-06 (separate later-2018 incident), Zaif 2018-09, DragonEx 2019-03, Upbit 2019-11 — is the load-bearing geographic-and-operational-scope evidence for the OAK-G01 cluster's 2017–2019 tradecraft surface. Contributors writing the OAK-G01 actor page or G01-attributed worked examples should treat the cohort as a coherent unit and should cross-reference each case as a member of the cohort rather than treating each as an isolated event.
inferred-strongis the right attribution-strength marker for Coinrail 2018. The same attribution-surface pattern that applies to NiceHash 2017, Coincheck 2018, and KuCoin 2020 applies here: South Korean intelligence finding plus industry-forensic corroboration (Chainalysis, Recorded Future, Kaspersky), no DOJ / Treasury naming. Contributors writing the OAK-G01 actor page should preserve this notation rather than over-claiming aconfirmedattribution that the public record does not support.
[coinrailpress2018]— Coinrail Co., Ltd. Statement on the June 2018 security incident. 2018-06-10 onward; primary-source operator disclosure across the breach response, recovery coordination, and partial-resumption announcement.[reuterscoinrail2018]— Reuters. South Korean cryptocurrency exchange Coinrail hacked, loses up to 30 percent of coins. 2018-06-10 / 2018-06-11; contemporaneous press coverage of the breach disclosure.[coindeskcoinrail2018]— CoinDesk. Coinrail Loses Over $40 Million in Tokens Following Hack. 2018-06-11; contemporaneous press coverage of the breach disclosure including the principal-stolen-asset breakdown (Pundi X, Aston, NPER, TRON, Dent).[koreaheraldcoinrail2018]— Korea Herald. Coinrail hacked, $40 million in cryptocurrency stolen. 2018-06-11; primary-source Korean press coverage of the breach disclosure.[kisacoinrail2018]— Korean Internet & Security Agency (KISA) / Korean intelligence reporting. Coinrail incident, attribution to North Korean state-aligned actors within the 2017–2018 South Korean exchange-targeting wave. 2018; primary-source intelligence finding.[chainalysiscoinrail2018]— Chainalysis primary forensic analysis of the Coinrail laundering cluster; cross-references the OAK-G01-attributed cohort and the chain-hopping / mixer-routing pattern observed in the months following the event.[recordedfuturedprkfinancial2018]— Recorded Future. North Korea Targeting of cryptocurrency exchanges and adjacent infrastructure. 2018; industry-forensic attribution covering the cohort that includes Coinrail 2018-06.[pundixcoinrail2018]— Pundi X. Pundi X NPXS response to Coinrail incident — token-balance freeze and replacement. 2018-06-11 onward; primary-source token-issuer announcement of the contract-level recovery action.
Coinrail 2018 is the OAK record's canonical reference for the multi-asset long-tail ERC-20 portfolio compromise shape and for the recovery-via-token-issuer-co-operation mechanism. The case sits cleanly within the 2017–2018 OAK-G01 cohort on the attribution axis, but its operational-shape distinction from the canonical cohort cases is the multi-asset distribution of the loss across the ERC-20 token-portfolio surface. Contributors writing the OAK-G01 actor page or G01-attributed worked examples should treat Coinrail as the canonical reference for the multi-asset-extraction-shape variation within the broader G01 cohort, alongside NiceHash 2017 (single-asset BTC), Coincheck 2018 (single-asset NEM / XEM), and Bithumb 2018-06 (predominantly single-asset).
The recovery-via-token-issuer-co-operation mechanism deserves to be flagged as the case's most operationally distinctive feature for OAK's mitigation-axis documentation. Coinrail's rapid (within-hours) outreach to affected ERC-20 token-issuer projects produced contract-level freezing or rollback of approximately two-thirds of the stolen-token balances. The mechanism was operationally available for the 2017–2018-era ERC-20 ecosystem because many ERC-20 token contracts of that era retained centralised mint-and-blacklist authority — a design pattern that has been substantially deprecated in the post-2020-era ERC-20 ecosystem in favour of immutable token contracts. Contributors writing M-axis pages on post-event recovery mechanisms should treat token-issuer-co-operation as a distinct mitigation class with explicit notes on the post-2020-era deprecation, and should treat Coinrail 2018 as the canonical reference for the maximum-availability era of the mechanism.
The cohort-level attribution framing matters for OAK's attribution discipline. The 2017–2018 OAK-G01 cohort — Bithumb 2017, NiceHash 2017-12, Coincheck 2018-01, Coinrail 2018-06, Bithumb 2018-06, Zaif 2018-09, DragonEx 2019-03, Upbit 2019-11 — is the load-bearing geographic-and-operational-scope evidence for the OAK-G01 cluster's 2017–2019 tradecraft surface, and Coinrail 2018 is one of the cleanest mid-cohort references. Contributors writing the OAK-G01 actor page should treat the cohort as a coherent unit; the load-bearing evidence for G01's 2017–2019 tradecraft is the cohort surface in aggregate, not any single case in isolation.
Finally, the Coinrail case is one of the cleaner illustrations available of the partial-recovery shape on the OAK record. Approximately two-thirds of the stolen-asset value was recovered through contract-level freezing-and-rollback plus downstream-exchange deposit-freezing; approximately one-third was lost or laundered to ground. Contributors writing future exchange-hack worked examples in which the recovery is structured (rather than binary at the win-or-lose boundary) should describe the recovery mechanisms and their effective coverage with the same care that on-chain extraction mechanics get; the OAK convention from Bitfinex 2016 and Coincheck 2018 applies — conflating "users were eventually made whole" with "the on-chain stolen funds were recovered" mis-prices recoverability as an industry property, and the Coinrail case is a particularly clean illustration of the structurally distinct recovery mechanisms that produced the partial outcome.