Hacking History of Crypto Exchanges
Centralized custody failures — hot wallets, weak key control, and poor governance drove most major crypto exchange losses.

Crypto exchange hacks kept changing, but the weak point stayed the same: too much customer money under one set of keys.
I’d sum up the full history like this: from Mt. Gox in 2014 to Bybit in February 2025, the biggest losses usually came from hot wallet exposure, poor key control, weak internal checks, and messy crisis handling. The totals make that plain: one study in the article puts crypto hack and scam losses at $22.7 billion across 785 incidents through mid-2025, while exchange-focused trackers list about $4.67 billion across 64 exchange hacks.
If you just want the main points, here they are:
- Centralized custody was the main risk
- When an exchange held user funds, one breach could hit many users at once.
- Hot wallets were hit again and again
- Attackers got more organized over time
- Early thefts were often simpler.
- Later attacks used phishing, malware, API abuse, and linked-wallet drains across many addresses.
- Response quality shaped the damage
- Same-day disclosure, reserve funds, insurance, freezes, and chain tracing often helped limit losses.
- Delays and poor shutdown steps made losses worse, as seen with Cryptopia.
- The market changed after 2022
- Big exchange hacks became less common, while more losses shifted to DeFi, bridges, and smart-contract exploits.
- The biggest lesson is simple
- Exchange security is mostly a custody and governance problem, not just a code problem—which is why using a secure on-ramp provider for direct wallet top-ups can reduce exchange-specific risks.
Here’s the short version of the timeline:
- 2011–2014: Mt. Gox exposed how bad key storage and poor record-keeping could sink an exchange.
- 2016–2019: Bitfinex, Coincheck, Binance, and Cryptopia showed more advanced attack paths and very different recovery plans.
- 2020–2022: KuCoin showed how freezes and cross-chain tracking could recover funds; FTX showed how wallet drains can mix with bankruptcy and internal failure.
- 2023–2025: Fewer giant exchange breaches, but custody pressure stayed; the article ends with Bybit’s roughly $1.46 billion to $1.5 billion loss as the largest case in this period.
Quick Comparison
| Period | What happened | Main weak spot | What changed |
|---|---|---|---|
| 2011–2014 | Mt. Gox collapse | Poor key storage, weak records | First major warning for exchange custody |
| 2016–2019 | Bitfinex, Coincheck, Binance, Cryptopia | Hot wallets, phishing, API misuse | Better public response, but same basic risk |
| 2020–2022 | KuCoin, FTX wallet drain | Compromised wallet access, internal control gaps | More fund recovery tools, more cross-chain tracking |
| 2023–2025 | Fewer giant CEX hacks, more pressure from other parts of crypto | Custody still a weak point | More cold storage, better disclosure, losses shift to DeFi and bridges |
So if you’re reading this to find the core lesson, here it is: the scale got bigger, the tools changed, but the failure pattern stayed mostly the same.
sbb-itb-0796ce6
Timeline of Major Crypto Exchange Hacks
Major Crypto Exchange Hacks: 2011–2025 Timeline & Losses
2011 to 2014: Mt. Gox and the First Large-Scale Warning
The first major exchange collapse laid bare the custody problem that kept showing up in later hacks.
Starting around September 2011, attackers stole Mt. Gox hot-wallet keys, reportedly through an unencrypted wallet.dat file on production servers, and drained Bitcoin for more than two years. Its internal books also failed to line up with its actual reserves.
When Mt. Gox filed for bankruptcy on February 28, 2014, about 850,000 BTC were missing, including roughly 750,000 from customers, worth about $450 million at the time. Later, about 200,000 BTC turned up in an old-format wallet, which brought the confirmed net loss to around 650,000 BTC. Later forensic work found that transaction malleability was not the main cause. The deeper issue was poor key storage and weak reconciliation controls.
At its peak, Mt. Gox handled roughly 70% of global Bitcoin trading volume. So this wasn't just one company going under. It rattled the whole market and gave the industry an early, painful look at what centralized exchange risk can mean.
2016 to 2019: Bitfinex, Coincheck, and Binance

This stretch showed that exchanges had picked up some lessons, but plenty of gaps were still there. The attacks became more technical, and the responses became more organized.
On August 2, 2016, Bitfinex lost roughly 119,756 BTC, or about $72 million at the time, after attackers compromised about 2,000 multisig wallets with BitGo. Bitfinex disclosed the breach fast and issued BFX tokens to spread losses across users, then later redeemed them.
In January 2018, Coincheck lost about 523 million XEM (NEM) tokens worth around $530 million from a single hot wallet that had no cold-storage separation. Japan’s Financial Services Agency issued operational improvement orders, and the NEM Foundation helped trace the stolen funds on-chain. Coincheck said it would repay affected users in yen, though many immediately questioned whether it could actually cover that promise.
Then came Binance on May 7, 2019. Attackers mixed phishing, malware, and API abuse to steal 7,000 BTC, roughly $40 million, from a hot wallet holding about 2% of Binance’s BTC reserves. Binance disclosed the incident the same day and covered the loss through its SAFU fund. There was also a short-lived internal discussion about asking for a Bitcoin reorganization to reverse the transactions, but that idea was later dropped.
2020 to 2022: KuCoin and the FTX Wallet Drain

By 2020, the response playbook around major exchange hacks looked more coordinated.
When KuCoin detected unauthorized withdrawals in the early hours of September 26, 2020, attackers had already moved roughly $281 million across multiple token types by exploiting compromised hot-wallet private keys. Token issuers froze assets and upgraded contracts while investigators tracked the flow across chains and exchanges. By November 11, KuCoin had recovered about 84% of the stolen funds, and the remaining 16% was covered by its insurance fund. Hackers also routed tokens through decentralized exchanges.
The FTX wallet drain in November 2022 looked different. Soon after FTX filed for bankruptcy, large unauthorized outflows started moving from FTX-controlled wallets under conditions that were never fully cleared up. It remained disputed whether the transfers came from an outside attacker or someone with internal access. The case showed how an exchange breach can blur into bankruptcy and governance collapse.
2023 to 2025: Fewer Large Exchange Breaches, Continued Custody Pressure
After 2022, the pace of headline exchange breaches slowed, but custody risk never went away.
Major exchange mega-breaches became less common as exchanges moved toward stronger cold storage, hardware security modules, threshold signature schemes, and faster disclosure. Aggregate data from 2011 through mid-2025 puts total crypto losses from hacks and scams at roughly $22.7 billion across 785 incidents. But more of the damage shifted away from exchange hot wallets and toward DeFi protocols, cross-chain bridges, and smart-contract exploits.
Better incident reporting changed the picture too. Problems that might once have stayed hidden until a full collapse were now more likely to come out fast. The pattern moved from repeat exchange drains toward tighter custody controls and quicker disclosure.
What the Data Shows About Losses and Attack Methods
How Losses and Incident Frequency Changed Over Time
The timeline shows the incidents. The data shows the pattern.
Across the major cases above, losses were packed into a small number of breaches instead of being spread evenly over time. In plain English, a handful of attacks did most of the damage. That points to a hard truth: centralized custody puts both money and risk in one place, highlighting the need for secure crypto purchases.
Many smaller breaches still mattered. They often led to days of follow-on withdrawals after the first hit. Cryptopia is a clear example. Its losses didn’t stop with the initial theft. Attackers kept draining funds for days through compromised wallets.
That long tail matters. Once attackers get control, they often keep moving stolen assets through other venues to make tracking harder. In Cryptopia’s case, hackers used other exchanges and trading venues to launder stolen assets.
The Most Common Attack Methods in Exchange Breaches
Most exchange breaches begin the same way: attackers compromise a hot wallet, an account, or another central access point. From there, they move into related wallets. The shared weak spot is centralized control over hot wallets and user access.
Phishing and domain spoofing also stayed common. By the late 2010s, the pattern had shifted. Attackers were no longer just looking for a quick hit. They often kept access long enough to drain linked wallets and move stolen assets across other platforms.
Those patterns shaped how exchanges and regulators responded.
How Exchanges and Regulators Responded
Incident Response Patterns After Major Hacks
Exchanges reacted to breaches in very different ways, and those choices often shaped what happened next.
Mt. Gox went into civil rehabilitation under trustee Nobuaki Kobayashi, who sold off remaining assets to repay creditors.
Bitfinex took a very different path. It spread the losses across user balances and issued BFX tokens equal to the stolen amount. Users could redeem those tokens for cash or swap them for shares in iFinex Inc. By April 2017, only eight months later, every BFX token had been redeemed or converted. Bitfinex also worked with U.S. law enforcement. In February 2019, authorities returned 27.66 BTC tied to the original theft, and that amount was distributed to Recovery Right Token (RRT) holders.
Cryptopia’s January 2019 response shows how much damage can grow when early steps go wrong. After the first breach, the exchange did not disable compromised deposit addresses. So users kept sending funds to wallets the exchange no longer controlled. Two weeks after the first attack, hackers pulled another 1,675 ETH from 17,000 wallets because deposits were still coming in. Total losses climbed to about $16.1 million. The New Zealand Police, led by Detective Greg Marton, later carried out physical office searches.
These cases pushed exchanges to move faster on freezes, communicate more clearly, and tighten custody controls. Some socialized losses with token plans. Others used reserve funds. Some ended up in court-led recovery. But one pattern keeps showing up: fast disclosure and strong controls already in place helped limit the damage.
Security, Governance, and Regulatory Lessons
After these breaches, exchanges faced more pressure to prove they had solid controls in place. Cybersecurity rating firms such as CER and Hacken started grading exchanges on items like TLS, port monitoring, 2FA, and stricter password rules.
By 2019, Kraken scored 9/10. Coincheck and Zaif, both of which had suffered breaches, scored 5/10.
Regulators also tightened rules around customer asset protection and AML/KYC. But that came with a tradeoff. Stricter KYC created another risk: stolen user data being sold on darknet markets.
Conclusion: The Main Patterns in Exchange Hacking History
Look across these cases as a group, and one pattern keeps showing up. From 2011 to 2025, exchange hacks got bigger and more sophisticated. But centralized custody kept producing the same weak spots. Hot wallet exposure, poor key management, and weak governance showed up again and again.
The numbers back that up. One longitudinal study estimated $22.7 billion lost across 785 incidents from 2011 to mid-2025. Exchange-focused trackers list 64 hacking events totaling about $4.67 billion, which shows how much of the damage sits in this one part of the market.
The scale changed. The failure modes didn’t. The first major hack in 2011 cost about $8.75 million. By February 2025, the Bybit breach had reached an estimated $1.46–$1.5 billion, making it the largest recorded exchange hack in this period. More money flowed into centralized custody, and the same old weak spots carried a much bigger price tag.
Key Takeaways From 2011 to 2025
Mt. Gox showed that custody failures can threaten the life of an exchange. Coincheck showed how hot-wallet concentration can blow past stated policy. Binance showed that fast disclosure and reserve funds can help hold user trust after a breach.
The broader crypto data points in the same direction. A scientific review of 220 major CEX and DEX incidents found that repeated attack vectors, especially key compromise and server exploits, made up 82.7% of incidents and 65% of total losses. That pattern helped push regulators in Japan, the U.S., and the EU toward segregated custody, mandatory reporting, stronger capital buffers, and better governance standards.
The core lesson is simple: exchange security is a custody and governance problem first, and a software problem second.
FAQs
Why are hot wallets hacked so often?
Hot wallets get hacked so often for a simple reason: they stay connected to the internet all the time. That always-on connection makes instant transactions and balance checks easy, but it also leaves the door open for attackers.
Cybercriminals can go after weak software libraries, pretend to be legitimate users, and use advanced tactics to get around protections like multi-signature protocols. Because of that, it’s smart to keep most funds in offline cold storage, especially for long-term holding.
How does centralized custody increase exchange risk?
Centralized custody comes with more risk because users hand control of their private keys to someone else. And when an exchange holds funds for a large number of people, it becomes a prime target for hackers trying to exploit weak points in hot wallets, internal systems, and smart contracts.
There’s also counterparty risk. That can mean insolvency, account freezes, or major losses after a security breach. If a platform holds your keys, your assets depend on that platform’s security and day-to-day stability.
What should I check before trusting an exchange?
Before you trust a cryptocurrency exchange, make sure it clearly shows its licensing and regulatory status and follows KYC and AML rules.
Then look at security. A good exchange should use encryption, multi-signature wallets, and mandatory 2FA. It should also be upfront about fees and show signs that it takes risk seriously, like regular third-party audits, bug bounty programs, and asset segregation so customer funds stay separate from company assets.