Bithumb Review 2026: Korea Access, Hacks and BTC Error

Abstract:Bithumb dominates parts of South Korea’s KRW crypto market, but access comes with strict banking rules, Travel Rule controls and a complicated security history. We examine its 2026 620,000 BTC ledger error, past incidents, fees and withdrawal limits.

Bithumb is one of South Korea's major cryptocurrency exchanges, but it works very differently from a typical global USDT-based platform.

Its core market is Korean won trading. Access to that market is tied closely to Korean identity verification, local banking and the country's real-name account system. Since March 2025, Bithumb users who want to trade in the KRW market have needed to link an eligible KB Kookmin Bank account.

That structure can produce deep domestic liquidity, particularly when Korean retail activity is strong. It also means Bithumb is primarily a Korea-focused exchange rather than an obvious alternative for international traders.

In 2026, however, Bithumb attracted attention for a different reason.

On February 6, an internal reward-processing error created 620,000 BTC of erroneous account balances across 695 users. No equivalent amount of bitcoin moved on-chain, but some recipients were temporarily able to trade against those balances, disrupting Bithumb's market.

The incident exposed a risk that is easy to overlook when evaluating centralized exchanges: wallet security is only one part of the system. The integrity of the exchange's internal ledger, approval process and transaction controls can matter just as much.

The 620,000 BTC incident was not a hack

The February 2026 incident began with a promotional reward campaign.

At 19:00 on February 6, Bithumb processed rewards for 695 users. During that process, an incorrect unit or quantity was entered, resulting in 620,000 BTC being credited inside customer accounts.

Bithumb's published timeline says:

TimeEvent
19:00Erroneous rewards distributed
19:20Bithumb identified the problem
19:35Trading and withdrawal restrictions began
19:40Restrictions completed for affected accounts

The scale looked extraordinary because 620,000 BTC represented tens of billions of dollars at prevailing bitcoin prices.

But these were internal account entries, not 620,000 bitcoins transferred from Bithumb wallets across the Bitcoin network.

That distinction is critical.

Bithumb later said there had been no external transfer of the mistakenly credited bitcoin. It recovered 618,212 BTC of the erroneous balances directly, equal to roughly 99.7% of the total. Some users had already sold approximately 1,788 BTC of the credited balance before their accounts were restricted.

Those trades were enough to affect the market.

Bitcoin's price on Bithumb briefly fell sharply as users sold balances that should never have existed. The price dislocation demonstrated how an internal accounting error can spill into an exchange's live order book even without private keys or blockchain infrastructure being compromised.

The more important problem was internal control

Describing the event only as an employee typing the wrong unit understates what happened.

Subsequent disclosures showed that the error passed through controls that should have stopped an impossible transaction.

Bithumb later acknowledged deficiencies in its internal system controls. According to statements made after the incident, the erroneous distribution was dramatically larger than the exchange's actual bitcoin holdings, yet the reward process was not automatically blocked.

That raises more serious questions than the original input error:

  • Why could a reward process create balances exceeding actual holdings?
  • Why was the requested distribution not checked against available assets?
  • Why could erroneous balances reach tradable customer accounts?
  • Why were some recipients able to sell before the accounts were restricted?
  • What approval process existed for unusually large asset distributions?

These are operational-risk questions rather than blockchain-security questions.

That distinction matters when assessing any centralized exchange. Cold-wallet security can protect assets from an external attacker, but it cannot prevent every internal accounting, software or approval failure.

Bithumb said it would redesign its asset-payment process and strengthen internal controls following the incident.

For users, that remediation is more important than whether the event is labelled a “hack.”

Bithumb is built around the Korean won market

Bithumb's market structure is unusually concentrated around KRW trading pairs.

That makes it important in South Korea but difficult to compare directly with offshore exchanges where USDT is the main quote asset.

A BTC/KRW market can behave differently from BTC/USDT or BTC/USD because Korean traders operate within a partially segmented banking and regulatory environment.

At periods of strong domestic demand, Korean crypto prices have historically traded above global prices — the phenomenon commonly known as the Kimchi premium.

The reverse can also occur.

For this reason, a trader looking at Bithumb's BTC price should not assume that a difference from an international exchange represents a simple arbitrage opportunity.

A useful comparison requires:

  • converting the KRW price using the current foreign-exchange rate;
  • comparing the executable order-book price rather than the last trade;
  • including trading fees;
  • including crypto withdrawal fees;
  • confirming that the destination exchange or wallet is eligible for withdrawal;
  • accounting for Travel Rule requirements.
  • A visible price gap is not necessarily a realizable profit.

    KRW trading now depends on KB Kookmin Bank

    Bithumb changed its real-name banking partner from NH NongHyup Bank to KB Kookmin Bank on March 24, 2025.

    For users who want full KRW-market functionality, this is not a minor payment detail.

    Bithumb requires the relevant real-name bank account connection for services including KRW deposits, KRW withdrawals and KRW-market trading.

    This illustrates how closely Korean crypto exchanges are connected to the local banking system.

    It also explains why Bithumb's large trading volumes should not be interpreted as evidence that the platform is equally accessible to anyone globally.

    An overseas trader may be able to visit Bithumb's website and monitor markets while still being unable to reproduce the funding and withdrawal setup available to an eligible Korean customer.

    Korea's crypto rules go beyond exchange registration

    South Korea requires virtual-asset service providers to comply with anti-money-laundering rules and register under the country's financial transaction reporting framework.

    KRW exchanges face an additional requirement because real-name fiat accounts depend on banking relationships.

    The regulatory framework became more substantial when the Virtual Asset User Protection Act took effect on July 19, 2024.

    Among other requirements, the rules require virtual-asset service providers to separate customer deposits from their own funds and maintain customer crypto assets separately.

    Regulatory rules also require at least 80% of the economic value of customer virtual assets to be held in cold wallets.

    The framework additionally addresses unfair trading, transaction monitoring and supervisory powers.

    Those protections are meaningful.

    They should not, however, be confused with the protection attached to an ordinary insured bank deposit.

    A cryptocurrency position can still lose market value, and regulated exchanges can still experience technical, operational or security incidents.

    The February 2026 Bithumb error is a particularly clear example of that difference.

    Travel Rule restrictions matter before you buy

    Moving crypto out of Bithumb can involve more friction than users of some offshore exchanges expect.

    South Korea applies Travel Rule requirements to virtual-asset transfers.

    For transfers of KRW 1 million or more, Bithumb generally requires information about the receiving exchange or wallet and the recipient. Whether the withdrawal is permitted can depend on the destination.

    Bithumb supports several different routes.

    Some exchanges are connected through the CODE Travel Rule system. Others can be used through Bithumb's whitelist process. Personal wallets may require proof that the wallet belongs to the user.

    For certain destinations, ownership verification is therefore part of the withdrawal process rather than something users encounter only during account opening.

    Bithumb also warns that repeated withdrawals below the KRW 1 million threshold can be reviewed if they appear designed to avoid monitoring requirements.

    All crypto withdrawals are also subject to fraud-detection checks, and transfers identified as matching financial-crime patterns can be temporarily restricted.

    The practical implication is simple:

    Check how you will withdraw the asset before you buy it.

    This is especially important for smaller tokens and for users intending to move funds to an overseas exchange.

    A cheap trade can still become an expensive transfer

    Bithumb frequently changes fee programs and has historically used aggressive fee promotions.

    That makes a single permanent headline trading fee less useful than it appears.

    Users should verify the applicable fee inside the live market and calculate the entire transaction rather than focusing only on the maker or taker percentage.

    For a KRW crypto trade, the real cost can include:

    Trading fee + spread + slippage + KRW premium/discount + withdrawal fee

    Withdrawal fees are charged separately and differ by asset.

    On highly liquid BTC or ETH markets, trading fees may represent a meaningful part of the cost.

    For smaller assets, order-book depth and withdrawal restrictions can matter much more.

    A token showing a strong price on Bithumb is not necessarily profitable to sell elsewhere if the destination exchange is unsupported or the withdrawal network is unavailable.

    Bithumb's earlier security record still matters

    The 2026 incident was operational rather than an external hack, but it sits on top of an older security history that should not be omitted.

    2017: customer information incident

    In 2017, personal information linked to Bithumb users was exposed after an employee's computer was compromised.

    This was primarily a data-security incident rather than the same type of exchange-wallet compromise seen in later cases.

    The distinction is important because stolen customer information can still enable secondary phishing or account attacks even when the exchange's crypto wallets are unaffected.

    2018: exchange cyberattack

    In June 2018, Bithumb disclosed a cyberattack and initially estimated losses at approximately KRW 35 billion.

    The figure was subsequently revised as assets were recovered.

    Bithumb halted deposits and withdrawals and moved assets as part of its response.

    2019: EOS and XRP withdrawals

    Another incident followed in March 2019, involving abnormal withdrawals of EOS and XRP from a hot wallet.

    Bithumb said at the time that it suspected involvement by insiders and stated that customer assets were protected.

    These events involved different failure modes and should not be collapsed into a statement that Bithumb was simply “hacked several times.”

    The more useful takeaway is that the exchange has experienced risks across several layers:

    • customer-data security;
    • hot-wallet security;
    • possible internal access;
    • internal ledger and operational controls.

    That history gives users more reason to distinguish between different types of exchange risk.

    Security certification does not eliminate operational risk

    Bithumb's current security posture is significantly more formalized than it was during its earlier incidents.

    The exchange publishes information-security certifications including ISMS-P and international ISO standards covering areas such as information security, privacy and cloud controls.

    These certifications indicate that defined management systems and processes have been independently assessed against particular standards.

    They should not be interpreted as proof that errors or breaches are impossible.

    The 620,000 BTC event demonstrates why.

    A platform can have sophisticated cybersecurity controls and still fail at transaction approval, balance validation or internal accounting.

    Security due diligence therefore needs to ask two separate questions:

    Can an attacker steal the assets?

    and

    Can the platform's own systems create an incorrect asset state?

    Centralized exchanges need controls for both.

    New listings can move differently in Korea

    Bithumb supports a substantial range of cryptocurrencies, but the context of those listings is different from a globally distributed USDT exchange.

    Korean exchange announcements can have an immediate effect on local demand.

    Trading-support notices, investment warnings, network suspensions and termination announcements can all influence price and liquidity.

    Users holding a smaller asset should monitor:

    • new trading-support announcements;
    • deposit-opening times;
    • supported blockchain networks;
    • investment-warning notices;
    • withdrawal suspensions;
    • trading-support termination dates.

    A delisted token may continue to support withdrawals for a limited period even after trading stops.

    Waiting until the final days can create unnecessary risk if the receiving exchange does not support the same network.

    For international users, Bithumb's volume can be misleading

    Bithumb can report substantial spot trading volume, but that does not automatically make it a practical exchange for an overseas user.

    The platform is deeply integrated with South Korea's identity, banking and compliance infrastructure.

    A foreign resident's ability to use the exchange can depend on factors such as:

    • Korean residence status;
    • accepted identification;
    • Korean mobile verification;
    • customer verification;
    • access to an eligible real-name bank account.

    Requirements can change, so eligibility needs to be checked directly rather than inferred from nationality alone.

    Buying a verified account, using somebody else's identity or connecting another person's bank account is not a reasonable workaround. It creates compliance, ownership and withdrawal problems precisely when access to funds matters most.

    For someone outside Korea, the more useful role of Bithumb may sometimes be as a source of Korean market information rather than as the exchange where the trade is executed.

    What matters most before using Bithumb

    Bithumb's value is straightforward for the right user: it provides direct access to one of the world's most active KRW crypto markets.

    But using it well requires understanding the Korean infrastructure around the exchange.

    Before funding an account, verify:

    • whether you are eligible for full account verification;
    • whether you can connect the required real-name bank account;
    • the current trading fee for the market;
    • whether the KRW price carries a meaningful premium or discount;
    • whether the intended withdrawal destination is supported;
    • which Travel Rule procedure applies;
    • the correct token network and destination address.

    For larger positions, test the complete path with a smaller amount first.

    That means testing not only the trade, but also the withdrawal.

    The lesson from Bithumb's history is broader than “the exchange has been hacked before.”

    The 2017, 2018 and 2019 incidents involved security risks. The February 2026 episode showed something different: an exchange can also create market disruption through its own internal ledger and control systems.

    For a centralized exchange, both matter.

    Frequently asked questions

    What happened with Bithumb's 620,000 BTC error?

    On February 6, 2026, Bithumb mistakenly credited a total of 620,000 BTC to 695 customer accounts during a promotional reward process. The balances existed on Bithumb's internal ledger rather than representing 620,000 BTC sent across the Bitcoin blockchain.

    Bithumb restricted affected trading and withdrawals within 35 minutes. It reported recovering approximately 99.7% of the erroneous amount and said none of the mistakenly credited bitcoin was transferred externally.

    Was the 620,000 BTC incident a hack?

    No. Bithumb said the incident was unrelated to an external hack or security breach.

    It was an internal asset-distribution and control failure. Subsequent disclosures acknowledged deficiencies in the controls that should have prevented such an unusually large balance from being created.

    Did Bithumb really own 620,000 BTC?

    No. The mistaken credits were internal ledger balances and greatly exceeded Bithumb's actual bitcoin holdings.

    That is one reason the incident raised concerns about internal controls: the system allowed balances far beyond available holdings to reach customer accounts before the error was stopped.

    Which bank does Bithumb use for KRW deposits?

    Bithumb switched its KRW deposit and withdrawal banking partner to KB Kookmin Bank on March 24, 2025.

    Eligible users need the required real-name account connection for KRW deposits, withdrawals and KRW-market trading.

    Can foreigners use Bithumb?

    Access depends on Bithumb's current identity, residence, mobile-verification and banking requirements.

    The exchange is designed primarily around the South Korean market, so many international users cannot access the same KRW deposit and withdrawal functionality available to eligible Korean customers.

    Has Bithumb been hacked before?

    Bithumb has experienced several earlier security incidents, including a 2017 customer-data breach, a 2018 cyberattack initially estimated at approximately KRW 35 billion and abnormal EOS and XRP withdrawals in 2019.

    These incidents had different causes and should be evaluated separately rather than treated as one repeated event.

    What is Bithumb's Travel Rule limit?

    For crypto withdrawals worth KRW 1 million or more, additional Travel Rule information and destination checks generally apply. Requirements vary according to the receiving exchange or wallet.

    Users should verify the destination and withdrawal method before purchasing an asset they intend to transfer elsewhere.

    Is Bithumb mainly a Korean exchange?

    Yes. Its defining market is KRW-denominated crypto trading, and its fiat access is closely connected to South Korean identity verification, banking and virtual-asset regulations.

    That domestic focus is also why Bithumb prices and volumes can sometimes behave differently from global USDT markets.

Disclaimer

The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Previous Post

Bitstamp by Robinhood Review 2026: MiCA, Fees, Security and Risks

Next

XT.COM Review 2026: Fees, Reserves and Wallet Incident