Crypto Exchange Hack Timeline
Over $3 billion has been stolen from crypto exchanges since 2011. Here is the complete history of every major hack.
2011: Mt. Gox - First Major Hack
Hacker compromised auditor account. Manipulated BTC price to $0.01. 2,000 BTC stolen. Price crashed to $0.01 for 10 minutes before recovering.
2014: Mt. Gox - The Big One
850,000 BTC stolen ($450M at the time, worth $50B+ today). Exchange filed for bankruptcy. Creditor repayments finally began in July 2024 - a decade later. Root cause: Transaction malleability exploit.
2016: Bitfinex - 120,000 BTC Stolen
Hackers used compromised API keys to steal 120,000 BTC ($72M). Bitfinex issued BFX tokens to affected users. All tokens were eventually redeemed at $1 each. 30 BTC recovered in 2024.
2018: Coincheck - $530M NEM Hack
Japanese exchange Coincheck lost 526 million NEM tokens ($530M). Funds stored in hot wallet instead of cold storage. Largest crypto hack at the time.
2019: Binance - $40M Stolen
Hackers used phishing and virus to steal 7,000 BTC. Binance covered all losses from SAFU insurance fund. CEO CZ initially considered rolling back blockchain, then rejected the idea.
2020: KuCoin - $281M Stolen
Hackers compromised hot wallet private keys. Stole Bitcoin, Ethereum, ERC-20 tokens. KuCoin recovered most funds through cooperation with exchanges and projects.
2022: Ronin Bridge - $624M Stolen
North Korean Lazarus Group compromised validator nodes of Ronin Bridge (Axie Infinity). Largest DeFi hack ever. FBI attributed it to Lazarus Group.
2022: Wormhole - $320M Stolen
Solana-Ethereum bridge exploit. Hackers minted 120,000 wETH without collateral. Jump Crypto covered the loss.
2024: WazirX - $230M Stolen
Indian exchange WazirX lost $230M in multi-sig wallet hack. Lazaarus Group suspected. Exchange filed for bankruptcy protection.
2025: Bybit - $1.5B Stolen
Largest crypto hack in history. North Korean hackers compromised Bybit cold wallet using social engineering and malware. CEO Ben Zhou confirmed loss.
Lessons for Traders
- Never keep all funds on one exchange
- Use exchanges with Proof of Reserves
- Enable all security features
- Keep large amounts in hardware wallets
SEBI Disclaimer
Cryptocurrency investments are subject to market risks. This article is for educational purposes only.
The Common Vectors: Warm Pockets and Sloppy Keys
Across two decades of losses, the vectors repeat with depressing regularity:
- Hot-wallet compromise: keys held on servers with broad third-party access (Mt. Gox 2014, KuCoin 2020, Bybit 2025) are the industry's open wound.
- Private-key phishing or leak inside the exchange's own team: the least glamorous and most lethal vector in half the incidents.
- Bridges and operational tools: Ronin's 2022 theft and Wormhole's 2022 theft both leveraged signatures merged from a handful of validator-like roles.
The pattern is not that exchanges are hacked by enthusiasts; it is that scaling exchanges accumulate privileged access, and people-sized keys fail at company scale.
Hot-Wallet Discipline: The Post-Mortem Fix
Every major incident lands on the same engineering remedy, and the markets as go with it:
- Segment hot wallets by currency and cap each below your day's likely withdrawal demand times a safety multiple.
- Automate the sweep: hot wallets are refilled from cold vaults on a schedule, never by hand.
- After the Bybit 2025 incident, the industry standard for top exchanges climbed toward a 95/5 cold/hot split with punitive internal latency on movement.
Audit Verification: Reading a Reserve Report Honestly
Proof of Reserves marketing converged after 2022. The checklist that reads through the shine:
- Confirm a named external auditor, not in-house "review"; the report should name the accounts and methods.
- Trace asset-specific addresses on-chain to custody entities you can independently identify.
- Compare covered liabilities to the total user ledger, and if only some currencies are proven, treat the rest as unproven.
Insurance and the Shortfall Reality
Insurance funds and coverages are not guaranteed payouts: they are funded from exchange reserve pools and rehypothecated assets:
- Bybit capped the interesting by fully covering user balances from reserves, an outlier; most prior incidents paid fractions or waited years (Mt. Gox paid part in BTC, years later).
- Verify which perils the coverage actually includes; most insurance explicitly excludes user-loss events tied to operational theft or gross negligence.
- A the exchange agility: whether withdrawals froze and whether covered amounts were drawn from segregated reserves tells you more than the headline "insured".
Your Own Withdrawal Playbook
The retail protect is behavioural, not architectural:
- Move idle funds to cold storage after the day's trading is done; an account that never holds a big balance is uninteresting to thieves.
- Keep a withdrawal-whitelist check habit and a hardened multi-factor setup (hardware key) rather than SMS OTPs.
- On hearing of any major incident, do not trade into the panic; wait for the exchange's official sequencing statement and verify the victim-share explicitly.
The hacks from Mt. Gox to Bybit followed one script: prized keys, hot liquidity and slow audits. The exchange that scatters keys, sweeps hot balances and audits with named firms is the exception the market rewards; the trader who keeps lean balances, hardened keys and a cold-storage habit is the one who survives even the exchanges that get the script wrong.