Bitcoin hacks, thefts and losses: what caused them and what would have stopped them

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Notes

2026-10-09

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

Bitcoin hacks, thefts and losses: what caused them and what would have stopped them

Study note, 2026-10-09. This is defensive research only. It covers causes, outcomes and defences, with no exploit code, attack procedures or tooling. Amounts are given at the value reported at the time unless stated. Anything not confirmed against a source fetched for this note is marked (unverified). Contested or fringe claims are kept and labelled.

Saved primary documents are in ../sources/hacks/. Where a government or court page could not be fetched (DOJ and FBI pages block automated requests), the URL is listed under Gaps at the end so it can be opened in a browser.


1. At a glance

Incident Date Loss (at the time) What was compromised Root cause found Outcome
Mt. Gox price crash and account theft 2011-06-19 accounts worth >$8.75M affected an auditor's account credentials; the user database leaked compromised credentials on an insider's computer; no anomaly limits on trading exchange carried on; no prosecution identified for this event (unverified)
Mt. Gox collapse theft from late 2011; collapse Feb 2014 ~850,000 BTC reported lost, ~650,000 after 200,000 were found (~$473M at filing) hot-wallet keys or the wallet system; theft went unnoticed for years stolen keys or wallet access, plus no monitoring or reconciliation of holdings; the exchange blamed "transaction malleability", which research rejected bankruptcy, then civil rehabilitation; BTC repayments since July 2024; deadline now 2026-10-31; two Russians charged in the US (2023)
Bitstamp 2015-01-04 <19,000 BTC (~$5M) hot-wallet file and passphrase on a server spear-phishing of staff (per a leaked report, unverified) exchange reopened about a week later; no arrests known (unverified)
Bitfinex 2016-08 119,754 BTC (~$71M) servers, then the keys and credentials that authorise withdrawals network intrusion that defeated multisig because the attacker could sign as Bitfinex ~94,000 BTC seized in 2022; hacker pleaded guilty (2023), 5-year sentence, released early (Jan 2026)
Coincheck (NEM token, not BTC) 2018-01-26 ~523M XEM (~$530M) one hot wallet with a single key hot wallet, no multisig, malware sent by email to staff (reported) customers repaid in yen; 31 people charged for trading the stolen coins; the thief was never identified
QuadrigaCX collapse 2018-12 / 2019-02 C$169M shortfall not a hack: the founder's fraud CEO-controlled platform with no oversight; false cold-storage claims bankruptcy; about C$46M recovered or identified
Binance 2019-05-07 7,000 BTC (~$40M) user API keys, 2FA codes, hot wallet phishing and malware against users, then withdrawals timed to pass checks (Binance's account, unverified) covered from Binance's own funds (SAFU); no arrests known (unverified)
Ledger customer-data breach 2020-06-25; dumped 2020-12 no coins taken in the breach; 1M emails and ~272,000 names, addresses and phone numbers e-commerce/marketing database (API key); insiders at a Shopify contractor leaked key; insider theft at an outsourced support firm years of phishing, fake devices sent by post, threats and physical attacks on holders
Twitter account takeover 2020-07-15 ~$110,000–118,000 BTC sent by the public Twitter's internal admin tool phone spear-phishing of employees; the attackers got past 2FA 3 charged within 2 weeks; ringleader got 3 years (Florida); a UK man got 5 years (SDNY, 2023)
Coinbase account takeovers Mar–May 2021 ~6,000 customers' funds customer accounts stolen passwords plus a flaw in SMS account recovery customers reimbursed (reported)
FTX 2022-11 billions in customer funds misused; ~$432M stolen on bankruptcy night fraud, not a hack, plus a separate theft misuse of customer funds by insiders; keys stored in plaintext and cloud secrets stores; no cold storage or multisig founder got 25 years (2024); the theft was linked to a SIM-swap ring, three people indicted (2024)
DMM Bitcoin 2024-05 4,502.9 BTC (~$305M) wallet vendor (Ginco) and its transaction process a North Korean fake recruiter compromised a vendor employee exchange closed; FBI and Japan's NPA attributed it to "TraderTraitor"
Coinbase customer-data bribery from 2024-12-26; disclosed 2025-05 data of 69,461 customers; cost to Coinbase up to $400M support-tool data (names, addresses, ID images, balances) bribed overseas support contractors $20M ransom refused; $20M bounty; class actions merged (MDL 3153); an arrest in India reported Dec 2025
Bybit (ETH, not BTC) 2025-02-21 ~$1.5B the multisig signing interface used for cold storage compromise of a third-party wallet tool, so signers approved a disguised transaction (reported) FBI attributed it to North Korea

2. Exchange and custodian incidents

2.1 Mt. Gox, June 2011

  • Date and loss. On 2011-06-19 fraudulent sell orders crashed Mt. Gox's quoted price to one cent. Accounts holding the equivalent of more than $8,750,000 were affected, and Mt. Gox's user database, with hashed passwords, leaked online days earlier (Wikipedia: Mt. Gox).
  • What was compromised. The attacker reportedly used credentials taken from a compromised computer belonging to a Mt. Gox auditor to move bitcoins into his account and sell them (Wikipedia: Mt. Gox).
  • Root cause. A privileged account with no per-account limits or trading sanity checks, accessible from an endpoint that was compromised (Wikipedia: Mt. Gox).
  • Afterwards. Mt. Gox moved 424,242 BTC between its own addresses as public proof that it still held its coins (Wikipedia: Mt. Gox). WizSec later found that hot-wallet losses began only weeks after this, in August to October 2011 (WizSec 2015).
  • Defences that would have helped. Hardware security keys for privileged staff accounts; limits on how much any one account can sell; circuit breakers on price moves; hashing passwords with a slow algorithm and storing them apart from other user data.

2.2 Mt. Gox collapse, 2011–2014

  • Dates. Withdrawals were halted 2014-02-07, trading was suspended 2014-02-24 and civil rehabilitation was filed 2014-02-28 in Tokyo. The case moved to liquidation in April 2014 (Wikipedia: Mt. Gox).
  • Loss. About 750,000 customer bitcoins and about 100,000 of the firm's own (~$473M near filing). On 2014-03-20 Mt. Gox found 199,999.99 BTC in an old wallet, leaving about 650,000 BTC missing (Wikipedia: Mt. Gox).
  • What was compromised and the root cause.
  • WizSec, a Tokyo security firm, matched leaked Mt. Gox data to the blockchain. It concluded that "most or all of the missing bitcoins were stolen straight out of the MtGox hot wallet over time, beginning in late 2011". It found Mt. Gox "technically insolvent since at least 2012" and at least ~300,000 BTC taken in identifiable theft patterns between late 2011 and end-2012 (WizSec 2015).
  • WizSec also reported that Mt. Gox "did not have continuous monitoring of its cold storage". Staff may have kept refilling a leaking hot wallet from pre-generated paper cold wallets without reconciling the amounts. Its lesson: "Always. Monitor. Your. Bitcoins." (WizSec 2015).
  • In February 2014 Mt. Gox blamed transaction malleability, a then-unfixed Bitcoin quirk that let a transaction's ID be altered before confirmation (Wikipedia: Mt. Gox). Decker and Wattenhofer analysed a year of network data and found that "there was no widespread use of malleability attacks before the closure of MtGox" (Decker & Wattenhofer 2014). Contested: Mt. Gox's malleability explanation is generally treated as discredited.
  • In 2016 the bankruptcy trustee reported that he had hired Deloitte Tohmatsu and an accounting firm, with help from Kraken's parent company Payward, to investigate how the BTC disappeared. He said the full picture was hard to establish because information was limited (Trustee report 2016-09-28, Japanese, section 第3).
  • In June 2023 US prosecutors in the Southern District of New York unsealed charges against Russian nationals Alexey Bilyuchenko and Aleksandr Verner. They allegedly gained unauthorised access to a Mt. Gox server holding wallet keys and drained at least 647,000 BTC from 2011 to 2014, laundering much of it through BTC-e (Bitcoin Annotated; Tripwire; DOJ release not fetched, see Gaps). The exact date of the unsealing is unverified.
  • Afterwards.
  • BTC-e operator Alexander Vinnik, named by US authorities as a key figure in laundering the Mt. Gox coins, was arrested in Greece in 2017 and pleaded guilty in the US in May 2024. He was then released to Russia in February 2025 in a prisoner exchange for Marc Fogel (Wikipedia: Alexander Vinnik).
  • CEO Mark Karpelès was arrested in 2015. In March 2019 a Tokyo court convicted him only of falsifying data (30 months, suspended for four years) and acquitted him of embezzlement. None of the charges concerned the missing 650,000 BTC (Wikipedia: Mt. Gox).
  • Creditors. 99% of voting creditors accepted a rehabilitation plan, approved 2021-11-16 (Wikipedia: Mt. Gox). BTC/BCH repayments began 2024-07-05 (Trustee 2024-06-24; Trustee 2024-07-05). On 2025-10-27 the trustee, with the court's permission, moved the repayment deadline from 2025-10-31 to 2026-10-31 because many creditors had not completed the procedures (Trustee 2025-10-27). Creditors are now targeted by fake "MTGOX" websites and emails (Trustee 2025-10-29).
  • Defences that would have helped. Continuous reconciliation of on-chain balances against the internal ledger, with alarms on any gap; cold storage that requires several people (multisig) and is audited independently; keeping the hot wallet small with automatic limits; separating and monitoring the servers that hold keys; regular independent audits.

2.3 Bitstamp, January 2015

  • Date and loss. Service was suspended in January 2015 after a hack in which "less than 19,000 bitcoins" were stolen (Wikipedia: Bitstamp), about $5M (headlines of Fortune 2015-01-05 and ZDNet). The often-quoted figure of 18,866 BTC is unverified.
  • What was compromised and the root cause. A confidential incident report dated 2015-02-20 leaked online. As discussed publicly, it described weeks of targeted phishing of Bitstamp staff by email and Skype, including a Word attachment with a malicious macro. The compromise reached a server holding the hot-wallet file and its passphrase. Only one hot wallet was drained (Hacker News discussion of the leaked report). (unverified): Bitstamp has not confirmed the leaked report, and this note did not read the report itself.
  • Afterwards. Bitstamp resumed service about a week later (NYT DealBook headline, 2015-01-09). No arrests are known (unverified).
  • Defences that would have helped. Keep hot-wallet signing keys in hardware security modules (HSMs) rather than as files with passphrases on general servers; block macros and isolate document opening on administrator machines; separate administrator workstations; train staff on phishing over chat apps, not just email.

2.4 Bitfinex, August 2016

  • Date and loss. In about August 2016 the attacker "fraudulently authorize[d] more than 2,000 transactions" moving about 119,754 BTC (~$71M) to a wallet he controlled (Statement of Offense, ECF 95, ¶14).
  • What was compromised and the root cause.
  • Ilya Lichtenstein admitted researching Bitfinex's infrastructure, compromising its servers outside the US and then reaching further servers. He "ultimately gained access to the keys, or credentials, used to authorize transactions" and afterwards deleted credentials and log files to hide his access (Statement of Offense ¶12–15).
  • Bitfinex used BitGo multi-signature security, yet the theft still succeeded (Wikipedia: Bitfinex). Multisig does not help once an attacker controls enough of the approval path, here the credentials Bitfinex itself used to sign. How the BitGo co-signing limits were bypassed is not described in the documents read here (unverified).
  • Afterwards.
  • Bitfinex cut all customer balances by 36% and issued BFX tokens, redeemed in full by April 2017 (Wikipedia: Bitfinex).
  • In February 2022 investigators decrypted a file of Lichtenstein's that held the wallet keys, seized ~94,000 BTC (then ~$3.6B), and charged Lichtenstein and his wife Heather Morgan with laundering (Wikipedia: 2016 Bitfinex hack).
  • Both pleaded guilty on 2023-08-03. The hacking itself was time-barred, so the convictions were for laundering and conspiracy (Memorandum Opinion 2025-04-04, pp. 2–3).
  • Lichtenstein was sentenced to 60 months and Morgan to 18 months in November 2024 (Wikipedia: 2016 Bitfinex hack).
  • On 2025-04-04 the court awarded $0 restitution to Bitfinex because of competing claims by former account holders. It sent the fate of the forfeited coins to a third-party ancillary proceeding (Memorandum Opinion).
  • Lichtenstein was released early to supervision in January 2026 under the First Step Act (Wikipedia: 2016 Bitfinex hack; CoinDesk 2026-01-02).
  • Defences that would have helped.
  • Sign withdrawals with HSMs and policy engines that apply hard limits by amount, speed and destination. These limits should be held by a party the attacker cannot reach with the same credentials (an independent co-signer that applies its own limits).
  • Separate the networks around signing systems, and send logs off the server in a form that cannot be changed, so that deleting logs does not hide an intrusion.
  • Keep most coins in cold storage, and alert on bulk outflows.

2.5 Coincheck, January 2018 (NEM token)

This was not bitcoin, but it is included because it reshaped how Japanese exchanges, which trade Bitcoin, are regulated.

  • Date and loss. About 500 million NEM tokens (~$530M) were stolen in January 2018, affecting about 260,000 users (Wikipedia: Coincheck). The theft was reported on 2018-01-26 (CNBC headline, 2018-01-26).
  • What was compromised and the root cause.
  • The NEM sat in a hot wallet without multi-signature protection, and the key was stolen after malware reached employees' computers by email (Quadriga Initiative case study, citing contemporary reporting).
  • (unverified) in primary form: Coincheck's own press-conference statements and the FSA order were not fetched.
  • Some reporting attributed the theft to North Korea; that attribution is contested and unverified.
  • Afterwards.
  • Japan's Financial Services Agency ordered Coincheck to improve its security but did not shut it down (Wikipedia: Coincheck; Reuters headline).
  • Coincheck repaid affected users in yen from its own capital. Monex bought it in April 2018 for ¥3.6B (Wikipedia: Coincheck).
  • By February 2021 Tokyo prosecutors had charged 31 people who traded about ¥18.8B of the stolen coins. The original thief was never identified (Wikipedia: Coincheck).
  • Defences that would have helped. Cold storage for most assets, multisig even on hot wallets, separate machines for email and for signing, and blocking email attachments on administrator machines. Japan later required exchanges to keep customer crypto mostly in cold wallets. FTX's post-bankruptcy management (John J. Ray III) noted Japan as the one place FTX used cold storage "where required by regulation" (FTX First Interim Report, report p. 26 / PDF p. 30). The exact Japanese percentage rule is unverified here.

2.6 QuadrigaCX, 2018–2019: fraud, not a hack

  • Dates. CEO Gerald Cotten died in India in December 2018. Quadriga announced his death on 2019-01-14 and stopped operating and filed for creditor protection by 2019-02-05 (OSC staff review).
  • Loss. More than 76,000 clients were owed C$215M. Ernst & Young, the trustee, recovered or identified C$46M, leaving a shortfall of at least C$169M (OSC staff review).
  • The popular story versus what investigators found. The popular story was that the money was locked in cold wallets only Cotten could open. The Ontario Securities Commission's staff found the reverse: "most of the $169 million asset shortfall resulted from Cotten's fraudulent conduct" (OSC staff review).
  • About C$115M was lost through fake-funded accounts under aliases that traded against real clients, which in effect ran the platform as a Ponzi scheme.
  • About C$28M was lost in unauthorised trading on other exchanges.
  • Client assets were also misappropriated for his lifestyle.
  • Quadriga's claims of "Cold Storage for the majority of the Bitcoins" and "secure and offline multisignature wallets" were "untrue and misleading". Assets were mostly in hot wallets or on other exchanges. From 2016 Cotten alone controlled them, with "no proper system of oversight or internal controls" (OSC staff review).
  • E&Y found five Quadriga cold-wallet addresses, all empty since April 2018 (Wikipedia: QuadrigaCX).
  • Afterwards. The trustee declared a first interim dividend of about C$40M in March 2023 (Wikipedia: QuadrigaCX). Customers' lawyers asked for Cotten's body to be exhumed. Claims that he faked his death are a fringe theory, unverified (Wikipedia: QuadrigaCX).
  • Defences that would have helped.
  • Require several people to approve any movement of client assets (multisig with independent keyholders).
  • Hold client assets separately, verified by independent audit, with published proof of reserves and liabilities.
  • Register with a regulator.
  • Customers should be wary of any custodian whose storage claims they cannot check (OSC staff review, Regulatory Takeaways).

2.7 Binance, May 2019

  • Date and loss. Around 2019-05-07 hackers took 7,000 BTC (~$40M) using "API keys, two-factor codes and other information". Binance covered the loss from its own funds and resumed trading about a week later (TechCrunch 2019-05-15).
  • Root cause. Binance said the attackers used phishing, viruses and other attacks on users to collect credentials, then withdrew from the hot wallet, which held about 2% of its BTC, in a way that passed its security checks. That account comes from Binance's announcement, which was not fetched (unverified).
  • Afterwards. The loss was covered by Binance's Secure Asset Fund for Users (SAFU) (TechCrunch). No arrests are known (unverified).
  • Defences that would have helped.
  • Users: API keys locked to specific IP addresses with withdrawal permission switched off; hardware security keys instead of codes; withdrawal allow-lists.
  • Exchange: anomaly detection on bulk withdrawals from many accounts; a small hot wallet.

2.8 FTX, November 2022: fraud, with a separate theft

  • What it was. FTX failed because customer money was misused, not because it was hacked. Federal prosecutors called it "one of the biggest financial frauds in American history". Founder Sam Bankman-Fried was convicted on 2023-11-02 on all seven counts (Wikipedia: Bankruptcy of FTX) and sentenced to 25 years on 2024-03-28 (Wikipedia: Sam Bankman-Fried).
  • Wikipedia reports that the Second Circuit affirmed the conviction on 2026-06-12 and that he petitioned the Supreme Court in September 2026 (Wikipedia: Sam Bankman-Fried). This is (unverified against the court record).
  • The separate theft.
  • On the night of the bankruptcy filing (2022-11-11), "a malicious actor had just drained approximately $432 million worth of crypto assets in hours; the FTX Group did not have the controls to detect the compromise, much less to stop it" (FTX First Interim Report).
  • In January 2024 the DOJ indicted three people for a SIM-swap scheme that stole "over $400 million" from an unnamed company on 11–12 November 2022, which Bloomberg's sources identified as FTX (Wikipedia: Bankruptcy of FTX).
  • How those defendants' cases ended is unverified.
  • Control failures found by the new management (the debtors' First Interim Report, filed in court, Doc. 1242-1):
  • "virtually all crypto assets in hot wallets", despite public claims of a standard hot/cold set-up;
  • no multi-signature or multi-party computation (MPC) controls;
  • private keys and seed phrases stored "in plain text and without encryption" on servers. Keys to billions of dollars sat in AWS Secrets Manager or a password vault that many employees could reach;
  • multi-factor authentication not enforced on Google Workspace or 1Password;
  • no written documentation of the key-storage design.
  • Recovery. Customers were projected to recover 118%–142% of their claim values as of the November 2022 petition date (Wikipedia: Bankruptcy of FTX). Claims were valued in dollars at November 2022 prices, so bitcoin holders did not get their bitcoin back.
  • Defences that would have helped.
  • Independent custody of customer assets, segregated from trading.
  • Mostly cold storage with multisig or MPC.
  • Keys held in HSMs, never as plaintext secrets.
  • MFA enforced on every corporate system.
  • Least-privilege access.
  • Audited proof of reserves and liabilities.

2.9 Other incidents worth knowing (briefer)

  • DMM Bitcoin (Japan), May 2024: 4,502.9 BTC (~$305M).
  • The FBI, the Pentagon's DC3 and Japan's National Police Agency said on 2024-12-24 that North Korea's "TraderTraitor" group did it (CoinDesk 2024-12-24).
  • An operative posing as a LinkedIn recruiter gave an employee of the wallet vendor Ginco malicious code dressed up as a "pre-employment test". This gave access to Ginco's systems, and months later the attackers tampered with a real DMM transaction request (CoinDesk).
  • DMM Bitcoin then shut down (CoinDesk). The FBI release itself is listed under Gaps.
  • Defence: treat the wallet vendor as part of your own security boundary; check every transaction independently on a separate device before signing; never run "test" code from recruiters on a work machine.
  • Bybit, 2025-02-21: about $1.5B (mostly ETH).
  • The FBI attributed it to North Korea's TraderTraitor and said some of the stolen assets were converted to bitcoin (FBI PSA I-022625-PSA).
  • Reported cause: a weakness in the third-party multisig tool Safe{Wallet} let attackers get signers to approve a disguised transaction (Wikipedia: Lazarus Group).
  • Wikipedia states that Bybit "was able to recover most of the stolen Ethereum". This is contested/unverified: Bybit restored its reserves mainly by borrowing and buying, not by recovering the stolen coins.
  • Defence: "clear signing", where the hardware wallet shows exactly what is being approved, plus independent verification of the signing interface.
  • LuBian mining pool, December 2020: about 127,000 BTC (contested).
  • In 2025 blockchain analysts (Arkham, per news reports) said this theft had gone unreported for five years and blamed a weak private-key generation method (WebProNews headline; TechRadar headline).
  • China's virus emergency centre (CVERC) alleged that the coins later forfeited by the US in its case against Prince Group's Chen Zhi were the LuBian coins taken by a "state-level" hacker (WebProNews headline). The US describes them as proceeds of fraud.
  • Contested and unverified on both sides. Neither article body could be fetched.

3. Breaches of customer data and accounts

3.1 Ledger, 2020 data breach, and what followed for holders

  • Date and what was taken.
  • On 2020-06-25 an unauthorised party used an API key to reach part of Ledger's e-commerce and marketing database. Ledger first said about 1 million email addresses and 9,500 customers' full contact details were taken. It said that "crypto funds are safe" and the breach had "no link" to its hardware wallets (Ledger, July 2020).
  • In December 2020 the data was dumped publicly. Have I Been Pwned lists 1.1 million email addresses with names, physical addresses and phone numbers (HIBP: Ledger).
  • A court summary describes "over 270,000 pieces of personally identifiable information" (Baton v. Ledger, N.D. Cal., 2021-11-08).
  • Root cause. Two separate failures (Baton v. Ledger, 2021-11-08; 2025-07-07 order): 1. The API-key compromise of Ledger's own database. 2. Between April and June 2020, "rogue" individuals exported Ledger customer records from Shopify's platform. Per Shopify's court declaration, they were contractors of the outsourcing firm TaskUs in the Philippines, who allegedly worked with "a California man". Shopify announced its incident on 2020-09-22.
  • The fallout for holders. The leaked list identified people who probably held crypto, with home addresses.
  • Phishing and extortion. Plaintiffs say they suffered phishing, cyber-attacks, ransom demands and threats (Baton v. Ledger).
  • Fake hardware wallets sent by post. From May 2021 scammers mailed tampered "replacement" Ledger devices to addresses from the leak, with letters urging users to "secure your funds". The devices asked victims for their 24-word recovery phrase (CoinDesk 2021-06-17).
  • Physical danger. Ledger co-founder David Balland and his wife were kidnapped in Vierzon, France, on 2025-01-21; his finger was severed before police (GIGN) rescued them (Lopp list, citing Le Monde). The link between the 2020 leak and specific physical attacks is widely asserted but unverified case by case.
  • Later Ledger-related incidents.
  • Connect Kit, 2023-12-14. A former employee was phished. A token for a JavaScript package account had not been revoked at offboarding, so attackers published a malicious version of Ledger's Connect Kit library. For less than two hours it drained funds from users of other companies' web apps, not hardware wallets. Ledger's fixes: audit access to external tools, tighten code signing, and end "blind signing" (Ledger incident report).
  • Global-e, January 2026. Customer names and contact details were exposed through Ledger's payment processor Global-e. Wallets and keys were not affected (Yahoo, 2026-01-05).
  • Lawsuits. Baton v. Ledger was dismissed in 2021 for lack of jurisdiction. The Ninth Circuit partly reversed in December 2022. In 2025 the remaining claims were still being litigated and an interlocutory appeal was certified (2025-07-07 order).
  • Defences.
  • For individuals: buy hardware wallets direct from the maker; have them delivered to a pickup point or mailbox rather than home; never enter a recovery phrase on anything other than the device itself; treat any unrequested "replacement" device as hostile.
  • For businesses: keep as little customer data as possible and delete it on a schedule; restrict and log contractor access; revoke all external tokens at offboarding.

3.2 Twitter account takeover and Bitcoin "giveaway" scam, July 2020

  • Date and loss.
  • On 2020-07-15 attackers took over 130 high-profile accounts, including Obama, Biden, Musk, Gates, Apple and Coinbase, and posted "double your bitcoin" scams. 45 accounts actually tweeted.
  • One scam address received over 320 deposits worth more than $110,000–118,000.
  • Coinbase blocked over 1,000 attempted transfers worth more than $280,000 (Wikipedia: 2020 Twitter account hijacking).
  • Root cause.
  • A "phone spear phishing attack". Attackers called employees, posed as Twitter IT, and sent them to a fake internal VPN login page. They relayed the stolen credentials and 2FA codes to the real portal in real time.
  • They then used the access to reach staff with rights to the internal admin tool (Wikipedia; Wikipedia: Graham Ivan Clark).
  • As many as 1,500 employees and contractors reportedly had access to that tool (Wikipedia).
  • Afterwards.
  • Three people were charged on 2020-07-31.
  • Graham Ivan Clark, aged 17, pleaded guilty in Florida in March 2021. He was sentenced to 3 years plus 3 years' probation as a youthful offender, and was released 2023-02-16 (Wikipedia: Graham Ivan Clark).
  • UK national Joseph O'Connor ("PlugwalkJoe") was extradited from Spain. He was sentenced in June 2023 to 5 years and forfeiture of at least $794,000. In November 2025 UK prosecutors obtained an order to confiscate 42 BTC (£4.1M) (Wikipedia).
  • The NY Department of Financial Services investigated; its report is listed under Gaps.
  • Twitter then cut admin-tool access, tightened background checks and introduced phishing-resistant security keys for staff (Wikipedia).
  • Defences that would have helped.
  • FIDO2/WebAuthn security keys, which do not work on a look-alike site.
  • Fewer people with access to admin tools, with two-person approval for changing an account's email address.
  • A help-desk rule that IT never asks for credentials by phone.
  • For the public: no genuine giveaway asks you to send bitcoin first.

3.3 Coinbase: account takeovers and the 2025 bribery breach

  • 2021 account takeovers.
  • At least 6,000 customers had funds taken between March and May 2021. The attackers already had victims' email addresses, passwords and phone numbers. They then exploited a flaw in Coinbase's SMS account-recovery process that let them receive the recovery code without controlling the victim's phone number.
  • Coinbase said it reimbursed affected customers (Atthacked incident summary, citing Coinbase's notification letter to the California Attorney General).
  • (unverified): the letter was not fetched. The summary itself gives the period as 2020, while contemporary headlines say "this spring" in 2021 (Crypto Briefing headline).
  • Defence: do not let SMS alone recover an account; offer hardware security keys; enforce delays and allow-lists on withdrawals after any security change.
  • 2025 customer-data bribery incident.
  • Date, scale and cause. Starting 2024-12-26, criminals "bribed Coinbase customer support workers" outside the US to pull customer records. 69,461 customers were affected, per Coinbase's filing with Maine's attorney general. The data included names, addresses, phone numbers, emails, government ID images, balances and transaction histories (TechCrunch 2025-05-21).
  • Disclosure. Coinbase learned the scale in May 2025 when it received a $20M ransom demand. It refused to pay and offered a $20M reward for information instead. It disclosed the breach in mid-May 2025 and estimated the cost at up to $400M, including repaying customers who were tricked into sending funds (Wikipedia: Coinbase; TechCrunch). It said no passwords, private keys or funds were taken directly (Wikipedia: Coinbase).
  • How the data was used. Pretending to be Coinbase support and convincing customers to move funds. Coinbase also warned that wealthy customers could be targeted for physical threats (TechCrunch).
  • The outsourcer. An employee of TaskUs in Indore, India, was caught photographing her work screen in January 2025. More than 200 TaskUs staff were later fired. Reuters reported that Coinbase may have known of the incident months before the ransom demand (Yahoo/Reuters 2025-06-02).
  • Lawsuits. On 2025-08-07 the federal panel on multidistrict litigation merged the customer class actions as MDL No. 3153 in the Southern District of New York (JPML transfer order).
  • Arrest. CEO Brian Armstrong announced around 2025-12-26 that a former customer-service agent had been arrested in India (Breitbart, citing Bloomberg). Details are (unverified).
  • Defences that would have helped. Support staff see only the fields they need, with screens masked; alerts on unusual bulk viewing; strict controls on outsourced support, including no phones on the floor and session recording; scheduled deletion of ID images. For customers: assume any call from "support" is a scam and never move funds because someone calls you.

4. Attacks on individuals

4.1 SIM swaps

  • What it is. Criminals get a carrier to move the victim's phone number to a SIM they control. They do this by impersonating the victim, bribing a carrier employee or hacking the carrier. They then receive the victim's SMS codes and password resets (FBI PSA I-020822-PSA; FCC 23-95).
  • Scale.
  • IC3 complaints rose from 320 (2018–2020 combined, ~$12M) to 1,611 in 2021 (~$68M) (FBI PSA).
  • Since then: 1,075 complaints and $48.8M (2023), 982 and $26.0M (2024), 971 and $17.4M (2025) (IC3 2025 report).
  • Cases.
  • Michael Terpin (2018): $24M. A teenager bribed an employee at an AT&T authorised retailer to move Terpin's number. He then used password resets to get into Terpin's OneDrive, where a document in the trash folder held Terpin's cryptocurrency access credentials. In 2024 the Ninth Circuit partly revived Terpin's claims against AT&T (Terpin v. AT&T, 9th Cir. 2024-09-30).
  • SEC's X account (2024-01-09). A SIM swap on the phone of someone with access to the SEC account was used to post a fake approval of Bitcoin ETFs, which briefly moved the price. Eric Council Jr. was sentenced in May 2025 to 14 months (TechCrunch 2025-05-16).
  • FTX bankruptcy-night theft (2022): see §2.8.
  • Rules. On 2023-11-15 the FCC adopted rules requiring US wireless carriers to:
  • use secure ways of verifying a customer before a SIM change or port-out;
  • notify customers immediately;
  • offer account locks against SIM changes and ports;
  • limit employee access to customer data (FCC 23-95).
  • When compliance took effect is unverified.
  • The wider "Com" ecosystem. The FBI says SIM swapping is a core activity of the "Hacker Com" network, which is largely made up of young people. Members steal cryptocurrency, use swatting to distract victims during thefts, and turn to "physical extortion… kidnapping, torture" (FBI PSA I-072325-PSA).
  • Defences.
  • Turn on the carrier's SIM/port-out lock and a carrier PIN.
  • Remove the phone number from crypto and email accounts as a recovery or 2FA method.
  • Use hardware security keys (FIDO2) or at least an authenticator app (CISA).
  • Keep holdings private (FBI PSA).
  • Never store seed phrases or credentials in cloud drives or email (the Terpin lesson).

4.2 Phishing and impersonation

  • What it covers. Fake login pages, fake support calls, fake "update" prompts and impersonation of trustees, exchanges or law enforcement. In 2025 IC3 received 181,565 complaints involving cryptocurrency, with losses of $11.37B (IC3 2025 report):
  • investment fraud: 61,559 complaints, $7.23B;
  • crypto ATM/kiosk fraud: 13,460 complaints, $389M;
  • "recovery" scams that target earlier victims: 10,516 complaints, $1.4B.
  • Examples.
  • The Twitter (§3.2) and Coinbase (§3.3) cases.
  • Fake "MTGOX" sites harvesting creditor logins (Trustee 2025-10-29).
  • Fake law firms offering to "recover" stolen crypto (FBI PSA I-081325-PSA).
  • Why codes do not help. Phishing defeats one-time codes because the victim types the code into the attacker's page. CISA ranks FIDO/WebAuthn and PKI-based MFA as the only phishing-resistant forms and calls them "the gold standard". It rates SMS and voice as the weakest (CISA fact sheet).
  • Defences.
  • Security keys or passkeys on exchange and email accounts.
  • Bookmarks rather than links in messages.
  • A firm personal rule: no legitimate exchange, wallet maker or police force asks for your recovery phrase or asks you to move funds "to safety".

4.3 Clipboard-hijacking malware ("clippers")

  • What it is. Malware watches the clipboard and swaps a copied wallet address for the attacker's. It works because addresses are long and hard to check by eye (Wikipedia: Cryptocurrency and crime).
  • Examples. In February 2019 ESET found the first clipper on Google Play, posing as MetaMask and replacing copied Bitcoin and Ethereum addresses (ESET WeLiveSecurity 2019-02-08). In 2017 Kaspersky reported a Windows clipper, "CryptoShuffler", that had collected about 23 BTC (unverified; source not fetched).
  • Defences.
  • Check the receiving address on the hardware wallet's own screen, comparing several characters at both ends and in the middle.
  • Send a small test payment for large transfers.
  • Use allow-listed addresses on exchanges.
  • Install wallets only from the maker's official site or store listing (ESET).

4.4 Address poisoning

  • What it is. An attacker creates an address that looks like one the victim has used, then plants a small transaction so it appears in the victim's history. The victim later copies the wrong address from that history. One study of Ethereum and BNB Chain found 270 million attack attempts against 17 million victims, and 6,633 incidents costing at least $83.8M (Tsuchiya, Dong, Soska, Christin 2025, Blockchain Address Poisoning).
  • Bitcoin. The technique matters less on Bitcoin, where wallets usually use a new address each time and do not show payee history the same way. It is not impossible there (unverified frequency).
  • Court example. A Dallas company sent 1,698,335 USDC to a poisoned address in February 2024. The FBI traced part of it and the court recommended forfeiture of 86.8684 ETH (US v. 86.8684 ETH, N.D. Tex. 2025-11-12).
  • Defences.
  • Never copy a payee address from transaction history.
  • Use a saved address book or allow-list.
  • Check the full address on the hardware wallet screen.
  • Make a test payment.

4.5 Fake wallet apps, fake updates and tampered devices

  • Fake "investment" apps. The FBI identified 244 victims and about $42.7M in losses to criminals who talked investors into installing apps that copied real US financial firms' names and logos (FBI PIN 20220718-001).
  • Fake Electrum update (December 2018). Malicious Electrum servers showed fake "update" error messages that led users to download a trojaned wallet. Electrum versions 3.3.2 to 3.3.4 stopped servers from showing arbitrary text (Electrum GitHub issue #4968).
  • Tampered hardware wallets sent by post to addresses from the Ledger leak (§3.1) (CoinDesk 2021-06-17).
  • Defences.
  • Download wallets only from the maker's site and verify signatures where offered (Electrum issue).
  • Ignore update prompts that appear inside error messages.
  • Buy devices direct from the maker.
  • Before trusting a new device, check its authenticity with the maker's own process.

4.6 Seed-phrase theft and weak key generation

  • Theft of stored secrets.
  • Terpin's credentials were found in a cloud drive's trash (Terpin).
  • Fake devices and fake support ask victims to type in their phrase (CoinDesk; Ledger).
  • At the institutional level, FTX kept seed phrases and private keys in plaintext on servers (FTX report).
  • Weak randomness when keys were created. No user error is needed; the software made guessable keys.
  • Android, 2013. A flaw in Android's random-number component made "all Android wallets generated to date vulnerable to theft". Users were told to update and move funds to new addresses (bitcoin.org alert 2013-08-11).
  • "Randstorm". Wallets created with the BitcoinJS library between 2011 and 2015 could fall back to weak browser randomness. The advice is to move funds from any possibly affected wallet to "a newly generated wallet created with trusted software" (Unciphered disclosure).
  • "Milk Sad" (CVE-2023-39910). The bx seed command in Libbitcoin Explorer 3.x used a weak random-number generator (Mersenne Twister). Thefts were seen in July 2023 (milksad.info). The size of the losses is unverified.
  • LuBian (2020) was allegedly also a weak key-generation case (contested; §2.9).
  • Defences.
  • Create keys only on dedicated, current hardware wallets or well-reviewed software.
  • Never store a phrase in a photo, cloud drive, email or password manager that syncs.
  • Record it offline, on metal for fire resistance.
  • Consider a BIP-39 passphrase or multisig so that one stolen phrase is not enough.
  • If a wallet was created by software later found to be weak, move the funds to a newly made wallet.

4.7 Physical coercion ("wrench attacks")

  • Scale.
  • Jameson Lopp's public list of known physical attacks on crypto holders (public domain) has, by this note's count of dated entries, roughly 32 (2021), 36 (2022), 24 (2023), 41 (2024), 86 (2025) and 62 in 2026 up to 2026-10-09 (Lopp list, snapshot). The list says it "is not comprehensive; many attacks are not publicly reported". The yearly counts are this note's tally, not Lopp's.
  • France has become a centre of such attacks. Headlines in 2026 give differing tallies, for example "41 cases in 2026" and "77 crypto kidnappings and extortions since January" (Yahoo headline; Yahoo headline). These are (unverified; article bodies not read).
  • Examples (Lopp list, citing press reports):
  • Ledger co-founder kidnapped, finger severed (France, 2025-01-21).
  • Father of a crypto entrepreneur abducted for a €5M ransom, finger severed (Paris, 2025-05-01).
  • Attempted abduction of the daughter of a French exchange CEO (Paris, 2025-05-13).
  • A man held and tortured for weeks in a Manhattan apartment (New York, May 2025).
  • Home invasions in which victims were forced to transfer crypto (e.g., Durham, North Carolina, 2023).
  • What drives it.
  • Leaked customer lists that tie names to home addresses (Ledger 2020; Coinbase 2025, where Coinbase itself warned of physical threats (TechCrunch)).
  • Holders posting about their wealth. One 2025 case followed a streamer showing a large BTC balance (Lopp list).
  • The FBI says a "violence as a service" market grew out of the SIM-swapping community, with contracts for kidnappings, armed robbery and assault advertised online (FBI PSA I-072325-2-PSA).
  • Contested: Pavel Durov alleged that leaks from French tax-authority data feed kidnappings in France. This is an allegation (unverified) (Cointelegraph headline).
  • Defences (principles only).
  • Do not disclose holdings; keep the link between your identity and your home address to a minimum (deliveries, KYC data).
  • Arrange custody so that no one person can move large sums alone or quickly: multisig with keys held in other places or by other people, and time-delayed vaults. Then coercing one person does not work, and it helps if this is publicly known.
  • Keep only small "spending" amounts on a phone.
  • Plan home security and with family.
  • Businesses should treat executives' home addresses and family details as sensitive data.
  • Lopp's list links his talks on physical security for holders (Lopp list).

5. Patterns across the incidents

  1. The weak point is usually people and processes, not Bitcoin's cryptography. None of these losses came from breaking Bitcoin's signatures or proof-of-work. They came from: - phishing: Bitstamp, Twitter, Binance users, DMM/Ginco, Ledger Connect Kit; - insiders and contractors: Shopify/TaskUs for Ledger, TaskUs for Coinbase, the AT&T retailer in Terpin; - keys left reachable: Mt. Gox, Bitfinex, Coincheck, FTX; - outright fraud: QuadrigaCX, FTX.

The rare exception is key-generation flaws in wallet software: Android 2013, Randstorm, Milk Sad. 2. Unmonitored balances let theft go on for years (Mt. Gox), and a lack of oversight let fraud do the same (QuadrigaCX, FTX). 3. Multisig only works if the signers are truly independent. Bitfinex was breached despite multisig. Bybit's signers approved a transaction they could not properly see. 4. SMS is not a security factor for anything holding money (Coinbase 2021, Terpin, the SEC's X account, FTX bankruptcy night). 5. Leaked customer data does lasting harm. Ledger's 2020 leak was still driving phishing, fake devices and, reportedly, physical targeting years later. 6. Laundering takes time, which gives investigators a chance. The Bitfinex coins were mostly recovered six years later. Mt. Gox coins were traced through BTC-e. But recovery seldom makes victims whole quickly, or in bitcoin.


6. Defences

6.1 For individuals

Risk Defence
Exchange failure, hack or fraud (Mt. Gox, QuadrigaCX, FTX) Keep long-term holdings in self-custody on a hardware wallet. Use exchanges for trading, not storage. Prefer regulated custodians with audited segregation of customer assets (OSC; FTX report).
One stolen or coerced key Multisig (e.g., 2-of-3 with keys stored in different places), or a BIP-39 passphrase on top of the seed. For larger sums, time-delayed or collaborative custody.
Phishing and account takeover Hardware security keys (FIDO2/WebAuthn) or passkeys on exchange and email accounts. Never SMS (CISA; FBI SIM PSA). Use a separate email address for financial accounts. Use bookmarks, not links.
SIM swap Carrier SIM/port-out lock and PIN (now required to be offered in the US: FCC 23-95). Remove the phone number as a recovery method.
Wrong address: clippers, poisoning, tampered apps Verify the address on the hardware wallet's screen. Use exchange withdrawal allow-lists with a waiting period for new addresses. Send a test transaction. Never copy addresses from history (ESET; address-poisoning study).
Fake apps, devices or updates Install only from the maker, and verify signatures. Buy hardware direct. Ignore "update" prompts in error messages (Electrum; FBI PIN).
Seed-phrase theft Never type a seed into a phone or computer. Never photograph it or store it in the cloud. Keep it offline (metal backup) and separate from the device (Terpin; CoinDesk).
Weak wallet software Move funds out of wallets created by software later found to be weak (bitcoin.org; Randstorm; Milk Sad).
Physical coercion Privacy about holdings; deliveries not to home; custody that one person cannot unlock quickly; only small amounts on a phone (Lopp list; FBI IRL Com PSA).
"Recovery" scams after a loss Report to IC3 and police. Never pay anyone who offers to recover funds for an upfront fee (FBI PSA I-081325-PSA).
Inheritance and single points of failure Write down how heirs can reach funds without any one person being essential, the lesson of QuadrigaCX's "only the CEO had the keys" story (Wikipedia: QuadrigaCX).

6.2 For businesses (exchanges, custodians, merchants)

  • Custody design
  • Keep the large majority of client assets in cold storage, with only working balances hot (FTX report).
  • Use multisig or MPC with keyholders who are independent in people, sites and systems.
  • Keep keys in HSMs, never in plaintext, cloud secret stores or password vaults (FTX report).
  • Back up keys and document them (FTX report).
  • Transaction policy
  • Limits by amount and speed, plus destination allow-lists, enforced by a signer the attacker cannot reach with the same credentials (Bitfinex).
  • "Clear signing" on trusted displays, never blind signing (Ledger Connect Kit; Bybit) (Ledger report).
  • Independent checking of every transaction request that comes through a vendor (DMM) (CoinDesk).
  • Monitoring and reconciliation
  • Continuously reconcile on-chain holdings against customer liabilities, with alerts on any drift (WizSec).
  • Send logs off-host in a form that cannot be altered (Bitfinex's intruder deleted logs: Statement of Offense ¶15).
  • Watch for bulk-withdrawal anomalies (Binance).
  • Identity and access
  • Phishing-resistant MFA for all staff (CISA).
  • MFA enforced on email and password managers (FTX report).
  • Least-privilege access to signing and admin tools (FTX report; Twitter).
  • Two-person approval for account-recovery changes (Twitter).
  • Revoke all external tokens and API keys at offboarding (Ledger report).
  • Staff, contractor and insider controls
  • Screen and supervise support staff, including outsourced ones.
  • Show support staff only the data fields they need, with masking.
  • Alert on unusual record viewing.
  • Ban personal devices on support floors (Coinbase/TaskUs; Shopify/TaskUs) (Reuters via Yahoo; Baton v. Ledger).
  • Train staff against phone and chat phishing (Twitter; Bitstamp).
  • Data minimisation
  • Collect and keep less customer PII.
  • Delete ID images and addresses on a schedule.
  • Assume a customer list of crypto holders is a target and a physical-safety risk (Ledger; Coinbase).
  • Customer-facing protections
  • Offer and encourage security keys.
  • Do not allow SMS-only account recovery (Coinbase 2021).
  • Withdrawal allow-lists with cool-off periods.
  • Warnings and delays after any change of security settings.
  • Software supply chain
  • Signed releases.
  • Scoped, short-lived publishing tokens.
  • Code review before deployment (Ledger report; Electrum).
  • Governance
  • Independent directors and audits.
  • No single person in control of client assets.
  • Honest public statements about storage (OSC).
  • Incident response
  • A pre-planned process to freeze withdrawals, contact blockchain-analytics firms and law enforcement, and notify customers and regulators (FBI Bybit PSA).

7. Contested, fringe or unverified claims collected here

  • Mt. Gox's "transaction malleability" explanation: research says malleability attacks were not widespread before the collapse (Decker & Wattenhofer).
  • North Korea as the Coincheck thief: reported suspicion, unverified.
  • Bybit "recovered most" of the stolen ETH (Wikipedia wording): doubtful; Bybit replaced reserves rather than recovering the coins (unverified).
  • LuBian 2020 theft and China's CVERC claim that the US government took the coins: contested allegation; the US calls them fraud proceeds.
  • Gerald Cotten faked his death: fringe theory, no evidence in the OSC review.
  • Pavel Durov's claim that French tax-data leaks fuel kidnappings: allegation.
  • SBF appeal outcome (affirmed 2026-06-12) and cert petition: from Wikipedia, not checked against the court record.
  • Coinbase 2021 takeover window (2021 vs 2020) and its reimbursement: secondary sources disagree on the year.
  • Bitstamp attack details: from a leaked, unconfirmed report.

8. Gaps: blocked or not fetched (open in Chrome)

  • DOJ press releases (justice.gov returned a bot challenge):
  • Mt. Gox hack charges against Bilyuchenko and Verner: https://www.justice.gov/usao-sdny/pr/russian-nationals-charged-hacking-one-cryptocurrency-exchange-and-illicitly-operating-another
  • Vinnik/BTC-e 2017 indictment: https://www.justice.gov/usao-ndca/pr/russian-national-and-bitcoin-exchange-charged-21-count-indictment-operating-alleged
  • Bitfinex sentencing: https://www.justice.gov/usao-dc/pr/bitfinex-hacker-sentenced-money-laundering-conspiracy-involving-billions-stolen
  • Bitfinex arrests (2022): https://www.justice.gov/archives/opa/pr/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency
  • Bitfinex case page: https://www.justice.gov/usao-dc/2016-bitfinex-hack
  • Twitter charges (2020), O'Connor sentencing (2023), SBF sentencing (2024), the FTX SIM-swap indictment (Jan 2024) and the SEC X sentencing (2025): DOJ pages not located because of the block.
  • FBI/DC3/NPA statement on DMM Bitcoin (fbi.gov, Cloudflare block): https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom
  • NY DFS Twitter investigation report (403): https://www.dfs.ny.gov/system/files/documents/2020/10/Report-Public_Version_Twitter_Investigation_10.14.2020.pdf
  • Binance 2019 breach announcement (blocked): https://www.binance.com/en/support/announcement/360028031711
  • Coinbase "Standing up to extortionists" blog (403): https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists. Its May 2025 SEC 8-K was not fetched, because EDGAR requires a contact address in the request header.
  • Coinbase 2021 breach notice to the California AG, and the Maine AG notice for the 2025 breach (not located).
  • Japan FSA business-improvement orders to Coincheck (2018); Tokyo District Court judgment on Karpelès (2019); Japan NPA's DMM statement (not located on fsa.go.jp / npa.go.jp).
  • Reuters (Coincheck; Vinnik exchange), The Verge, CNBC and CNN Binance articles, Business Insider and Crypto Briefing on Coinbase 2021, and the techmeme/WebProNews pages on the Coinbase arrest and LuBian: blocked or not readable.
  • CourtListener docket pages (their robots.txt disallows crawling). Individual court PDFs were taken from its file store and govinfo instead. The FTX SIM-swap (Powell et al.) and Council dockets were not found.
  • Kaspersky's CryptoShuffler report (2017) and the leaked Bitstamp report (Scribd; also not freely licensed).

Source list

Each tag in the text resolves to one of these.


Spark run on this topic (pointer added by the completeness check, 2026-10-09)

The local Spark run 20261009-143852--what-were-the-major-bitcoin-exchange-hacks-and-thefts-mt-gox finished on 2026-10-09. Its findings are not merged into this note yet. Its CONTESTED and UNDOCUMENTED answers, the claims its verifier rejected or found only partly supported, the facts it dropped, and the pages it refused or skipped are all listed and flagged in RESEARCH-STATUS-2026-10-09.md § 6, as the editor asked (include everything the Spark rejects, labelled). It labels the cause of the 2020 Ledger breach UNDOCUMENTED. This note documents it in § 3.1.