Bithumb's $40B Bitcoin Blunder: How a Crypto Exchange Accidentally Made 695 Users Instant Millionaires
#Vulnerabilities

Bithumb's $40B Bitcoin Blunder: How a Crypto Exchange Accidentally Made 695 Users Instant Millionaires

Privacy Reporter
5 min read

South Korean crypto exchange Bithumb mistakenly credited users with $40 billion in Bitcoin during a promotional campaign, briefly making hundreds of people instant millionaires before recovering nearly all funds within hours.

In what could be one of the most spectacular promotional mishaps in cryptocurrency history, South Korean exchange Bithumb accidentally credited 695 users with approximately $40 billion worth of Bitcoin during a marketing campaign, briefly turning ordinary customers into multi-millionaires before recovering the vast majority of funds within 35 minutes.

Featured image

The incident occurred on February 6, 2026, when Bithumb was running a promotional campaign offering new users ₩100,000 (about $68) in benefits. The plan was straightforward: new registrants would receive ₩20,000 ($13) after their first transaction, with additional bonuses including points and Starbucks vouchers tied to completing verification steps and entering promotional codes.

However, a technical error transformed this modest promotion into a financial windfall of unprecedented proportions. Instead of the intended small payments, the system mistakenly credited 620,000 Bitcoin—worth approximately $42 billion at the time—to the accounts of 695 users. This worked out to roughly $61 million per user if distributed equally, though the actual distribution likely varied.

The 35-Minute Window of Opportunity

The window between the erroneous credit and Bithumb's recovery efforts was remarkably short. According to the company's announcement, they detected the issue within 35 minutes and immediately implemented measures to recover the overpaid assets. Some users, recognizing the unusual balances in their accounts, attempted to sell their newfound wealth, but Bithumb claims to have recovered 99.7% of the Bitcoin on the day of the incident.

For the remaining 0.3% (approximately 1,788 BTC) that had already been sold, Bithumb injected company assets to ensure complete consistency between customer deposits and exchange-held assets. The company emphasized that "customer assets are being safely stored as before" and that all virtual assets, including Bitcoin, are held at levels that match or exceed user deposits.

CEO Compensation Package

Following the incident, Bithumb CEO Lee Jae-won announced a comprehensive compensation scheme for affected users. All customers connected to the platform during the error received ₩20,000 in compensation. Additionally, users who sold Bitcoin at depressed prices caused by the incident received refunds of their selling prices plus 10% of the transaction value.

The exchange also implemented several customer-friendly measures: trading fees for all tokens were paused for seven days beginning February 9, and a ₩100 billion ($68.5 million) Customer Protection Fund was established to safeguard users in any future similar incidents.

AI-Powered Prevention Measures

In a move characteristic of 2026's tech landscape, Bithumb announced the development of "Safe Guard," an "Anomalous Transaction Detection and Automatic Blocking AI System" designed to prevent similar incidents. The system will automatically detect and block transactions that appear abnormal for any reason.

Beyond AI solutions, Bithumb implemented additional technical safeguards including strengthened asset verification systems and a two-payment process for asset transfers and reward payments. These measures aim to prevent single-point failures that could lead to similar massive overpayments.

Regulatory Response

Despite Bithumb's quick response and comprehensive remediation efforts, regulatory scrutiny intensified. Lee Eog-weon, chairman of the Korean Financial Services Commission (FSC), called an emergency meeting on February 8 to discuss the incident. The meeting included officials from Korea's financial crime authority and financial institutions regulator.

While regulators acknowledged Bithumb's steps to remedy the situation and protect customer assets, they announced further investigations into user damages and plans for on-site inspections. The incident highlights the growing regulatory attention on cryptocurrency exchanges in South Korea, which has been developing comprehensive frameworks for digital asset oversight.

Market Impact The accidental overpayment had immediate market consequences. The price of Bitcoin briefly fell sharply as the market reacted to the sudden influx of sell orders from users attempting to capitalize on their unexpected balances. However, the rapid recovery of most funds helped stabilize the situation relatively quickly.

Technical Analysis

From a technical perspective, the incident reveals several vulnerabilities common in cryptocurrency exchange operations:

  1. Bulk payment systems: The error suggests a flaw in the bulk payment processing system that failed to properly validate transaction amounts against intended promotional values.

  2. Real-time monitoring gaps: While Bithumb detected the issue within 35 minutes, this represents a significant delay for a platform processing millions in transactions daily.

  3. Asset verification processes: The need for a two-payment process indicates that single-transaction verification was insufficient for high-value transfers.

  4. Risk management protocols: The incident exposed weaknesses in pre-transaction validation and amount verification systems.

Industry Implications

This incident serves as a cautionary tale for the entire cryptocurrency industry. While Bithumb's response was relatively swift and comprehensive, the potential for such errors to undermine user trust and market stability remains significant. Other exchanges will likely review their own promotional campaign systems and bulk payment processes in light of this event.

The establishment of a dedicated Customer Protection Fund by Bithumb could set a precedent for other exchanges, potentially becoming an industry standard for handling technical errors and security incidents.

User Perspective

For the 695 users who briefly saw their accounts swell with millions in Bitcoin, the experience was undoubtedly surreal. While most had their balances corrected quickly, the incident raises questions about user rights and compensation when exchanges make errors in their favor versus errors that benefit users.

Some users who managed to sell small portions of their accidental windfall before recovery may face additional scrutiny or potential clawback attempts, though Bithumb's compensation package appears designed to address such scenarios.

Looking Forward

As cryptocurrency exchanges continue to grow in both user base and transaction volume, incidents like this highlight the critical importance of robust technical infrastructure, comprehensive testing procedures, and rapid incident response capabilities. Bithumb's experience demonstrates that even well-established exchanges can make catastrophic errors, but also shows that prompt, transparent, and user-focused responses can help mitigate long-term damage to reputation and user trust.

The introduction of AI-powered monitoring systems like Safe Guard represents the industry's ongoing efforts to leverage technology to prevent human and technical errors. However, this incident also underscores that technology alone cannot prevent all mistakes—comprehensive processes, multiple verification layers, and clear operational protocols remain essential.

As regulators continue their investigations and the cryptocurrency industry watches closely, Bithumb's $40 billion blunder will likely be studied as a case example in crypto exchange risk management for years to come.

Comments

Loading comments...