주메뉴바로가기본문바로가기
비즈한국 비즈한국

The Ball Bithumb 'Wrongly' Set in Motion... Mandatory 'Financial-Grade Internal Controls' for Virtual Asset Exchanges

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] The fallout from Bithumb's '2,000 Bitcoin' mispayment incident is spreading throughout the industry. Although Bithumb CEO Lee Jae-won appeared before the National Assembly to acknowledge the system failure and apologize, the aftermath is expected to continue. On the 11th, financial authorities announced that they would impose internal control obligations at the level of general financial companies on virtual asset exchanges through the second phase of virtual asset legislation. The judgment is that although the incident was caused by a clerical error, there is a structural problem in the exchange's internal control system, given that it failed to be caught within Bithumb beforehand. In addition, the 'ledger trading' method, which enables the trading of phantom coins, has also emerged as a subject of controversy.

On February 6, an incident occurred at Bithumb where 2,000 Bitcoins were wrongly paid. Photo=Reporter Park Jung-hoon
On February 6, an incident occurred at Bithumb where 2,000 Bitcoins were wrongly paid. Photo=Reporter Park Jung-hoon

At an emergency pending issues inquiry regarding Bithumb held at the National Assembly's National Policy Committee on the 11th, Kwon Dae-young, Vice Chairman of the Financial Services Commission (FSC), announced that they would inspect the virtual asset holdings, operations, and internal control systems of all KRW-based virtual asset exchanges. Immediately after Bithumb's mispayment incident, the Financial Services Commission, the Korea Financial Intelligence Unit (KoFIU), the Financial Supervisory Service (FSS), and the Digital Asset eXchange Association (DAXA) formed a joint emergency response team to handle the situation.

The KoFIU and the FSS have launched an inspection into Bithumb, where the accident occurred, to examine user protection and anti-money laundering (AML) operations. For the remaining exchanges such as Upbit, Korbit, Coinone, and Gopax, on-site inspections led by the emergency response team are being promoted regarding the verification systems for held virtual assets and overall internal controls.

To enhance market transparency, financial authorities plan to include strict regulations at the level of the general financial industry in the second phase of the virtual asset bill. FSC Vice Chairman Kwon Dae-young stated, "We will impose internal control obligations equivalent to those of financial companies and mandate periodic inspections of virtual asset holdings through external institutions," adding, "We will impose no-fault liability for damages if user harm occurs due to computer failures or other incidents."

FSS Governor Lee Chang-jin also mentioned, "I believe that for the second phase bill, we must fully incorporate the stringent elements of legacy financial regulations—such as the Act on Corporate Governance of Financial Companies, the Electronic Financial Transactions Act, and the Financial Consumer Protection Act—into the exchange system." It can be said that the aftermath of the Bithumb mispayment incident has returned as a result of strengthened control over virtual asset exchanges.

On February 6 at 7 PM, Bithumb made a unit input error while distributing rewards to 695 event participants, paying out 2,000 Bitcoins per person instead of 2,000 KRW worth. The quantity of incorrectly paid Bitcoin was 620,000, which far exceeded the approximately 42,000 held by Bithumb. Bithumb realized the accident 20 minutes after payment and moved to contain it by blocking trades and withdrawals, recovering 618,212 out of the 620,000. Of the 1,788 that were sold for KRW or other virtual assets, 93% were recovered, but 125 (worth approximately 13 billion KRW) remain unrecovered.

Bithumb CEO Lee Jae-won attended the pending issues inquiry on the 11th to apologize for the mispayment incident but faced harsh criticism from ruling and opposition lawmakers. During the inquiry, another previous mispayment incident at Bithumb was revealed. When Representative Han Chang-min of the Social Democratic Party asked if there had been internal mispayment cases in the past, CEO Lee Jae-won replied, "When communicating with the audit department, I found that there were two cases where mispayments occurred and were subsequently recovered," and added, "A multi-payment system was initially set up and operated, but the incident occurred while two systems were being used interchangeably during the process of upgrading the operating system."

Bithumb CEO Lee Jae-won attended the National Assembly National Policy Committee's emergency pending issues inquiry on February 11, acknowledged internal control problems, and apologized for the mispayment incident. Photo=Yonhap News
Bithumb CEO Lee Jae-won attended the National Assembly National Policy Committee's emergency pending issues inquiry on February 11, acknowledged internal control problems, and apologized for the mispayment incident. Photo=Yonhap News

Reports also surfaced that a similar accident occurred in 2018. Representative Kim Seung-won of the Democratic Party of Korea pointed out, "In 2018, Bithumb exposed serious system vulnerabilities during the process of processing deposits for Ethereum-based tokens, causing customer damage. It was found that there was a case where a transaction not verified on the blockchain was recognized as a completed transaction and deposited into a customer's wallet," and added, "I believe this incident happened again because Bithumb shifted the blame to the morality of those who received the mistaken deposits without resolving its own system defects." Regarding Rep. Kim's report, CEO Lee responded that he would "investigate in detail," appearing unaware of the incident.

Criticism also followed that while Bithumb spent massive amounts on marketing, investment in internal control systems was insufficient. Representative Kim Hyun-jung of the Democratic Party of Korea said, "It's said that 100 million KRW is enough to build a system for preventing 'fat-finger' (input error) mistakes, but Bithumb spent 199.3 billion KRW on advertising and promotion expenses through the third quarter," adding, "They were buried in profit-seeking, and consumer protection was insufficient."

With this incident, the 'ledger trading' of virtual asset exchanges has also become a subject of controversy. The reason Bithumb could pay out nearly 15 times more Bitcoin than it actually held is because it engages in ledger trading, where only numbers on a ledger are changed without moving coins directly on the blockchain. It has sparked controversy in that, theoretically, it could be increased indefinitely to 10 million or more, beyond the 620,000 Bitcoins. Ledger trading is a method also used by other virtual asset exchanges and financial companies. Bithumb explained, "Ledger trading itself is a generally used method. However, unlike financial companies, there is no industry-specific law in the virtual asset market."

The problem is that Bithumb failed to prevent the mass mispayment because it only reconciled actual assets with ledger assets on a daily basis. Furthermore, the incident was compounded by the fact that the quantity of coins for event distribution was not limited through a separate wallet, and control devices did not function during the asset payout process. In the case of its competitor, Upbit, blockchain wallet holdings and internal ledger totals are reconciled every 5 minutes. It is also known to have prepared accident prevention measures by assigning separate personnel for event planning, asset management, and monitoring.

Because of this, voices were raised in the National Assembly calling for the introduction of a Proof of Liabilities (POL) system for exchanges. On the 11th, Representative Min Byung-duk of the Democratic Party of Korea argued to financial authorities, "POL is a technical check on whether the scale of payment obligations exceeds actual held assets. If this is introduced, safety can be secured through technology rather than relying on human caution or ex-post sanctions," adding, "It could have been prevented through behavioral regulations, but it wasn't done. (The authorities) are not offering opinions on relevant legislative bills.".

This article was automatically translated by AI. There may be errors compared to the original Korean article.
심지영 기자

금융, 가상자산, 핀테크, 투자 업계 중심으로 취재하고 있습니다. 언제든 제보주세요.

jyshim@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지