Learn
  • Guides
  • Courses
  • Dictionary
Markets
  • Crypto Prices
  • Stablecoins
  • Blockchains
Research
  • Research & News
  • MiCA Tracker
  • Tokenized Stocks
Compare
  • Exchanges
  • Wallets
  • Crypto Cards
Tools
  • All Tools
  • Cash Out Crypto
  • Trading Tools
News
  • Latest News
  • Market Guides
DealsLog In

Crypto University

Global crypto education, research and decision tools.

Learn

BitcoinEthereumCrypto CoursesGuidesTradingDictionary

Explore

MiCA TrackerBlockchainsStablecoinsTokenized Stocks

Company

Our StoryCommunityAffiliate ProgramGet in Touch

Legal

PrivacyTerms of Use

Connect

Join the Community

Educational content only. Not investment, tax, or legal advice. Verify details with primary sources before making decisions. © 2026 Crypto University.

Go Back to Crypto University Blogs

The Biggest Crypto Exchange Hacks In History: From Mt. Gox To Bybit

Crypto University • 26 September 2026

The Biggest Crypto Exchange Hacks in History: From Mt. Gox to Bybit
Guides

Key Takeaways

  • Most large exchange hacks come from key and signing failures, not broken blockchains. Stolen private keys, manipulated signing screens, and compromised staff devices explain nearly every major incident on this list.

  • Each big hack changed the industry. Mt. Gox and Coincheck pushed Japan toward strict exchange rules, Binance popularized emergency user funds, and Bybit exposed the risk of third-party wallet software.

  • User outcomes vary widely. Some exchanges covered losses within days, others took years, and a few users of failed platforms are still waiting to be repaid.

Why Exchange Hacks Matter

A centralized crypto exchange holds coins on behalf of millions of users. That makes it one of the most attractive targets in finance. When an exchange is hacked, the damage can reach far beyond one company. Prices move, regulators respond, and users learn hard lessons about who really controls their assets.

This guide walks through the most significant exchange hacks on record, from the collapse of Mt. Gox to the record Bybit theft in 2025 and the Bitget incident reported in September 2026. For each one, we explain what happened, how users were affected, and what changed afterward.

Dollar figures below are the widely reported values at the time of each theft. Crypto prices change, so the same coins could be worth far more or less today.

What Counts as a Crypto Exchange Hack?

In this article, an exchange hack means an unauthorized transfer of funds from wallets controlled by a centralized trading platform. That excludes:

  • DeFi protocol exploits, where attackers abuse smart contract code (for example, lending or bridge protocols)

  • Exchange collapses caused by fraud or mismanagement without an external theft, such as FTX in 2022

  • Individual account takeovers, where a single user loses funds to phishing

This distinction matters. A DeFi exploit usually targets code. An exchange hack usually targets people, keys, and internal systems.

The Biggest Exchange Hacks at a Glance

Exchange

Year

Reported Loss (at the time)

Main Cause

Outcome for Users

Bybit

2025

About $1.4 to $1.5 billion in ETH and stETH

Compromised third-party wallet interface

Exchange stayed solvent and restored reserves

Mt. Gox

2011 to 2014

About 850,000 BTC (roughly $350 to $475 million)

Long-running theft and poor accounting

Bankruptcy; repayments still ongoing

Coincheck

2018

About $530 million in NEM

Hot wallet without multisig

Users repaid in yen; company sold

Bitget

2026

About $351.6 million

Backend system fed spoofed transfers (under investigation)

Exchange says protection fund covers loss

DMM Bitcoin

2024

4,502.9 BTC (about $305 million)

Social engineering of a wallet vendor employee

Losses covered; exchange closed

KuCoin

2020

About $281 million

Leaked private keys

About 84% recovered; exchange covered the rest

WazirX

2024

About $230 to $235 million

Multisig wallet manipulation

Restructuring with partial payouts

Bitfinex

2016

119,756 BTC (about $72 million)

Wallet security breach

Losses shared across users, later repaid

Binance

2019

7,000 BTC (about $40 million)

Stolen API keys and 2FA codes

Fully covered by SAFU fund

Bitfinex and Binance are smaller in dollar terms, but both are included because of how much they changed industry practice.

Sponsored

Bybit Cybertruck campaign: trade stocks and crypto for a chance to win.

Incident by Incident: What Happened and What Changed

1. Mt. Gox (2011 to 2014)

What happened: Mt. Gox was once the world's largest Bitcoin exchange. In February 2014 it halted withdrawals and disclosed that about 850,000 BTC were missing, a figure widely reported as close to 7% of all Bitcoin in existence at the time. The theft was not a single event. Coins appear to have been drained over several years without being noticed, because the exchange did not properly reconcile customer balances against its real on-chain holdings.

Mt. Gox publicly blamed a Bitcoin weakness called transaction malleability, which let attackers alter transaction IDs so that withdrawals appeared to fail. That issue was later addressed by the SegWit upgrade in 2017, although how much of the loss it actually explains is still debated. The exchange filed for bankruptcy protection in Tokyo on February 28, 2014, with about 127,000 creditors. It later found about 200,000 BTC in an old wallet, reducing the missing total to roughly 650,000 BTC.

What it changed: Mt. Gox became the reference point for custody failure. Japan began requiring exchanges to register with the government in April 2017, and the case pushed the industry toward regular reserve checks and separation of customer funds. Repayments only began in 2024, and the deadline to finish them has been extended to October 31, 2026.

2. Bitfinex (2016)

What happened: In August 2016, attackers stole 119,756 BTC, worth about $72 million at the time. The breach happened even though Bitfinex was using BitGo's multisignature security, showing that multisig alone is not a complete defense.

What it changed: Instead of leaving only the affected users with losses, Bitfinex reduced every customer balance by about 36% and issued BFX tokens as IOUs. All BFX tokens were redeemed within about eight months. The case also became a landmark for blockchain tracing. In 2022, US authorities seized about 94,643 of the stolen BTC after decrypting files linked to Ilya Lichtenstein, who later admitted to the hack. A court ordered those coins returned to Bitfinex in 2025.

3. Coincheck (2018)

What happened: In January 2018, hackers stole about 523 million NEM tokens, worth roughly $530 million, from Tokyo-based Coincheck. The exchange admitted the coins were kept in an internet-connected hot wallet and that it did not use multisignature protection. Around 260,000 customers were affected.

What it changed: Japan's Financial Services Agency ordered business improvements, raided the company, and announced inspections of all exchanges. Coincheck repaid affected users in yen at a reduced rate per token, and online brokerage Monex acquired the business for about $33.5 million. Coincheck received full registration in January 2019. The episode made cold storage and multisig close to standard expectations for regulated exchanges.

4. Binance (2019)

What happened: In May 2019, attackers withdrew 7,000 BTC, worth about $40 million, from Binance's Bitcoin hot wallet in a single transaction. Binance said the attackers had collected user API keys, 2FA codes, and other data through phishing and malware. The hot wallet held about 2% of the exchange's total BTC.

What it changed: Binance covered the full loss from its Secure Asset Fund for Users (SAFU), an emergency fund created in 2018 and financed with a share of trading fees. The incident made the idea of an exchange-funded user protection reserve popular across the industry. It also showed users that API keys deserve the same care as passwords.

5. KuCoin (2020)

What happened: In September 2020, attackers used leaked private keys to drain about $281 million in Bitcoin, Ethereum-based tokens, and Stellar tokens from KuCoin's hot wallets.

What it changed: KuCoin reported recovering about 84% of the stolen assets within two months. Recovery came from on-chain tracking, token issuers upgrading or redeploying their contracts, blocking attacker addresses, and law enforcement action. It showed that fast industry coordination can reduce losses, especially when stolen tokens have issuers who can freeze or reissue them.

6. DMM Bitcoin (2024)

What happened: In May 2024, 4,502.9 BTC, worth about $305 million, was stolen from Japanese exchange DMM Bitcoin. The FBI and Japanese police later attributed the theft to TraderTraitor, a North Korea-linked group. According to the FBI, an attacker posed as a recruiter on LinkedIn and sent a malicious "pre-employment test" to an employee at Ginco, the wallet software firm that worked with DMM. That access was later used to manipulate a real transaction request.

What it changed: DMM raised about 55 billion yen to cover customer losses, but decided to close. Accounts and assets moved to SBI VC Trade in March 2025. The case highlighted a growing risk: attackers now target vendors and employees through fake job offers rather than attacking exchange servers directly.

7. WazirX (2024)

What happened: In July 2024, attackers took about $234.9 million from India's WazirX, then one of the country's largest exchanges. The funds sat in a multisig wallet that required signatures from WazirX and from its custody partner, Liminal. Attackers manipulated what signers saw and changed the wallet's smart contract, which gave them control. WazirX blamed Liminal's setup, while Liminal pointed to weaknesses on WazirX's side. The attack has been widely attributed to the Lazarus Group.

What it changed: WazirX used a Singapore court restructuring process to distribute about 85% of claim value, along with recovery tokens for possible future payouts. Singapore's High Court approved the plan on October 13, 2025, after a large majority of creditors voted in favor. The case showed how long and uncertain recovery can be when an exchange cannot cover losses.

8. Bybit (2025): The Largest Crypto Theft on Record

What happened: On February 21, 2025, attackers stole more than 400,000 ETH and stETH, worth roughly $1.4 to $1.5 billion, during a routine transfer from a Bybit cold wallet. The FBI attributed the theft to North Korea's TraderTraitor group, also known as Lazarus. Investigators found that attackers compromised a developer machine at Safe{Wallet}, the multisig platform Bybit used, and injected malicious code into its web interface. Bybit's signers saw what looked like a normal transaction, but actually approved one that handed control of the wallet to the attackers.

What it changed: Bybit stayed solvent, kept processing withdrawals, and restored its ETH reserves. The hack changed how the industry thinks about signing. The key lesson was "verify what you sign": if the screen showing a transaction can be manipulated, even well-protected cold wallets are at risk. It also put a spotlight on supply chain risk from third-party tools.

9. Bitget (2026): A Developing Case

What happened: On September 24, 2026, Bitget said its systems detected unauthorized transfers from some of its hot wallets. The reported loss is about $351.6 million, the largest exchange theft reported so far in 2026. Bitget's CEO said attackers compromised a wallet backend and fed spoofed transfer data into the exchange's authorization process, and that private keys were not compromised. Early on-chain reports also flagged movements from a wallet labeled as cold storage, while Bitget stated that its cold wallets remained secure.

What it changed: It is too early to judge. Bitget said its User Protection Fund, reported at more than $464 million, covers the loss, and it suspended withdrawals pending a security review. A full root cause report had been promised but details were still emerging at the time of writing. Treat all figures in this entry as preliminary.

How Exchange Hacks Have Evolved

Era

Typical Attack

Main Weakness

Industry Response

2011 to 2016

Hot wallet theft, slow draining

Poor accounting, weak key storage

Cold storage, basic reserve checks

2017 to 2020

Stolen keys, phishing, API abuse

Too many funds in hot wallets

Multisig, protection funds, licensing

2021 to 2024

Social engineering, fake recruiters

People and vendors

Staff security training, vendor audits

2025 onward

Supply chain and signing manipulation

What signers see on screen

Independent transaction verification

Blockchain analytics firm Chainalysis estimated that about $3.4 billion in crypto was stolen in 2025, with North Korea-linked groups responsible for about $2.02 billion. The same report found that these groups were linked to a record 76% of service-level compromises, often by placing IT workers inside crypto firms or impersonating executives. In short, the biggest threats now target people and processes more than code.

Common Patterns Behind the Biggest Hacks

  • Hot wallets are the front line. Funds kept online for fast withdrawals are the easiest to steal.

  • Multisig is not a guarantee. Bitfinex, WazirX, and Bybit all used some form of multisig. Attackers beat the process around it.

  • Third parties add risk. DMM Bitcoin, WazirX, and Bybit were all breached through or around partner systems.

  • North Korea is the dominant actor. Investigators have linked many of the largest recent thefts to Lazarus-related groups.

  • Recovery depends on reserves. Exchanges with strong balance sheets or emergency funds covered losses quickly. Weaker ones restructured or closed.

Sponsored

Crypto University and OKX: spend crypto with the OKX Card. Zero fees.

How Users Can Think About Exchange Risk

This section is educational and is not financial advice. Every user's situation is different.

  1. Understand custody. Coins on an exchange are held by the exchange. You rely on its security and solvency.

  2. Check public transparency. Look for proof of reserves reports, licensing in your country, and whether the exchange has a user protection fund.

  3. Secure your own account. Use app-based 2FA or a hardware security key, unique passwords, and withdrawal address whitelists.

  4. Protect API keys. Only grant the permissions a tool needs, and never enable withdrawals on keys used by third-party apps.

  5. Consider self-custody for long-term holdings. Many users move funds they are not trading to a wallet they control, while accepting the responsibility of protecting their own recovery phrase.

Frequently Asked Questions

What is the biggest crypto exchange hack in history?

The Bybit hack of February 2025 is the largest on record, with roughly $1.4 to $1.5 billion in ETH and stETH stolen. The FBI attributed it to North Korea-linked hackers.

How much Bitcoin was lost in the Mt. Gox hack?

About 850,000 BTC was reported missing in 2014. Around 200,000 BTC was later found in an old wallet, and about 140,000 BTC is being returned to creditors through a repayment process that is still ongoing.

Who is behind most large crypto exchange hacks?

Many of the largest recent thefts, including Bybit, DMM Bitcoin, and WazirX, have been linked by investigators to North Korea's Lazarus Group and related units such as TraderTraitor.

Do exchanges repay users after a hack?

Sometimes. Binance and Bybit covered losses from their own funds. Coincheck repaid users in yen. Others, such as Mt. Gox and WazirX, went through long legal processes that returned only part of the original value or took years.

Are cold wallets completely safe?

No storage method is completely safe. Cold wallets keep keys offline, which reduces risk, but the Bybit case showed that attackers can still steal cold wallet funds by manipulating the transaction approval process.

Related Terms

  • Multisig Wallet: A wallet that requires approval from several separate keys before funds can move.

  • Hot Wallet: A crypto wallet connected to the internet, used for quick and frequent transactions.

  • Cold Wallet: A crypto wallet kept offline to reduce exposure to online attacks.

  • Private Key: A secret code that gives full control over the crypto held at a wallet address.

  • Proof of Reserves: An audit-style report showing that an exchange holds assets to match customer balances.

Disclaimer: This content is for educational and informational purposes only and is not  financial, investment, legal, or tax advice. Nothing here is a recommendation to buy or sell any asset or use any platform. Do your own research and manage your risk.

Sources

  • FBI Internet Crime Complaint Center, "North Korea Responsible for $1.5 Billion Bybit Hack" (PSA, February 26, 2025): https://www.ic3.gov/PSA/2025/PSA250226

  • BleepingComputer, "Lazarus hacked Bybit via breached Safe{Wallet} developer machine": https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/

  • Decrypt, "Mt. Gox Bitcoin Billions Are Being Repaid: How We Got Here": https://decrypt.co/239720/mt-gox-bitcoin-billions-repaid-how-we-got-here

  • Koinly, "Mt. Gox: What Happened?": https://koinly.io/blog/mt-gox/

  • Fortune / Reuters, "Japan Seeks to Clean Up Cryptocurrency Markets After $530 Million Coincheck Heist": https://fortune.com/2018/01/29/japan-coincheck-cryptocurrency-hack

  • CNBC, "Japanese regulators raid Coincheck in wake of crypto heist": https://www.cnbc.com/2018/02/02/japanese-regulators-raid-coincheck-in-wake-of-crypto-heist.html

  • Wikipedia, "2016 Bitfinex hack": https://en.wikipedia.org/wiki/2016_Bitfinex_hack

  • Cointelegraph, "US government says funds from 2016 hack should return to Bitfinex": https://cointelegraph.com/news/us-government-funds-bitfinex-hack-returned

  • IG, "Binance exchange says it has been hacked, US$40 million worth": https://ig.com/en-ch/news-and-trade-ideas/other-news/binance-exchange-says-it-has-been-hacked-us-40-million-worth-of--190508

  • The Block, "KuCoin has recovered 84% of affected funds in $280M hack": https://www.theblock.co/post/84248/kucoin-280m-stolen-recovered

  • The Block, "Japanese exchange DMM Bitcoin to shut down, transfer assets to SBI Group unit": https://www.theblock.co/post/328890/japanese-exchange-dmm-bitcoin-to-shut-down-transfer-assets-to-sbi-group-unit-after-300-million-hack

  • FBI, "FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com": https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom

  • Wikipedia, "2024 WazirX hack": https://en.wikipedia.org/wiki/2024_WazirX_hack

  • Business Standard, "Singapore court approves crypto exchange WazirX's scheme of arrangement": https://www.business-standard.com/companies/news/singapore-court-approves-crypto-exchange-wazirx-s-scheme-of-arrangement-125101301118_1.html

  • Bitget Support Center, "Security Notice: Bitget Hot Wallet Incident, September 24, 2026": https://www.bitget.com/support/articles/12560603896024

  • CoinDesk, "Bitget's $352 million hack happened via spoofed transfers, not private keys": https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says

  • Decrypt, "North Korean Hackers Have Stolen $2 Billion in Crypto This Year: Report" (Chainalysis data): https://decrypt.co/352775/north-korean-hackers-stolen-2-billion-crypto-2025-report

More Reading

Bitget Hot Wallet Hack Explained: What It Teaches About Exchange Security

How to Check Whether a Transaction Was Replaced

How RugCheck Works: A Beginner's Guide to Checking Solana Tokens

How to Spot a Crypto Recovery Scam

How to Identify Fake Investment Platforms

Share Posts

Copy Link

cryptouniversity.networkblog/bigges...

$30,000 Deposit Blast-Off campaign artwork
Limited-Time

$30,000 Deposit Blast-Off

Stand to earn the biggest reward in any crypto exchange! Bybit is offering up to 30,000 USDT in deposit rewards! Spread the word now!

Bybit logo

Bybit

Claim OfferTerms apply.
Ends Dec 31, 202695 days remaining
Brazil's $10,000 Self-Custody Crypto Reporting Rule Explained
Crypto University•28 September 2026

Brazil's $10,000 Self-Custody Crypto Reporting Rule Explained

Brazil will report crypto transfers of $10,000 or more to or from self-custody wallets from October 1. Here is how it works.

Crypto News
Emerging Crypto Exchanges 2026: MEXC, Bitunix & Fameex Altcoin Guide
Cryptouniversity Research•27 September 2026

Emerging Crypto Exchanges 2026: MEXC, Bitunix & Fameex Altcoin Guide

Master early-stage altcoin investing in 2026. Learn to find micro-cap alpha on MEXC, Bitunix, and Fameex while avoiding liquidity traps and FDV pitfalls.

CryptocurrencyExchange
Bitget Hot Wallet Hack Explained: What It Teaches About Exchange Security
Crypto University•25 September 2026

Bitget Hot Wallet Hack Explained: What It Teaches About Exchange Security

Bitget lost about $351.6M from hot and warm wallets in September 2026. Learn what happened and how exchange wallet security works.

Crypto News