The best cryptocurrency exchange hacks from 2014 to 2025
by
Share and Earn:
For the betterment of investors cryptocurrency exchanges – This is the main way to interact with digital assets, as it allows you to sell, exchange and store cryptocurrencies and, in general, make a significant contribution to the development of the blockchain industry. However, the better the popularity of such platform, the more people want to make illegal profits from the developing industry. Many exchanges store user assets or public and private keys, and this data becomes a target for hackers.
Our editors will talk about best cryptocurrency exchange hacksThese attacks have occurred from the beginning of the industry's development to the present day. Each successful attack damages the reputation of the exchange and, more importantly, investors. But at the same time, hacks contribute to the development of more effective security measures and regulatory standards.
The best cryptocurrency exchange hacks
1. exchange Coincheck, 2018
Hacking the Coincheck exchange
In January, hackers broke into cryptocurrency exchange Coincheck Inc. and stole more than $500 million worth of cryptocurrency, namely NEM coins.
The exchange did not say exactly how the hackers breached its security system, only assuring that it was not an internal crime. The developers admitted that there was a security issue that allowed the attacker to take possession of such a large amount. Customers’ assets were stored in hot wallets, although it is customary to store them in cold wallets, without access to the outside world. In addition, Coincheck also lacked multi-signature protection.
Coincheck has identified and published 11 addresses where all 523 million stolen coins were found. Each address is marked with “coincheck_stolen_funds_do_not_accept_trades” – NEM has created a tool that tracks stolen funds and helps exchanges automatically reject deposits with them. However, hackers can still withdraw them using an exchange or other service that does not collect personal information. For example, convert them to a more anonymous currency.
Theoretically, in such cases, a blockchain fork could help – reverting the network back to the moment of the theft. But this is not an option – the blockchain must remain unchanged, this will be fair to the participants.
2 Mt.Gox, 2014
Hack do Mt.Gox em 2014
At the time, it was the best Bitcoin exchange in existence and many trusted it as an example. But internally, the company turned out to be a mess of inexperience, irresponsibility and mismanagement. The collapse resulted in the theft of US$ 460 million, as well as US$ 27.4 million from bank accounts.
CEO Mark Karpeles confirmed the situation: “We had weaknesses in the system and the bitcoins disappeared. We inconvenienced a lot of people and I deeply regret what happened.” By the way, the previous time Mt. Gox was hacked in 2011 and $8.75 million was stolen.
Soon a shocking internal document appeared on the Internet: it turned out that hackers had been stealing from the company for years. Investigations revealed that the private key of Mt. Gox was decrypted and stolen in 2011.
The event quickly spiraled out of control and by the end of February 2014 the company went bankrupt.
3 Bitgrail Exchange, 2018
Hacked a Bitgrail exchange
A little-known Italian cryptocurrency exchange, BitGrail, lost approximately US$ 195 million in customer cryptocurrencies as a result of a hack and soon declared itself bankrupt.
However, the explanation of a hacker attack did not satisfy many users. Before the event, BitGrail was one of the main trading portals for the Nano cryptocurrency, formerly known as RaiBlocks. BitGrail's founder, Francesco Firano, said that the hackers had stolen 17 million Nano tokens, worth approximately 195 million. But this claim was met with skepticism, mainly due to the suspicious actions of the exchange itself.
Previously, the platform banned deposits and withdrawals of Nano and a few other coins. It then introduced KYC/AML verification for users and started blocking users from Europe – despite the fact that it was not connected to banks or fiat currencies in any way. Even then, some users suspected that the site was heading towards an exit scam; the price of Nano dropped by as much as 20% on the news.
The Bitfinex hack resulted in the disappearance of US$ 60 million in Bitcoin. The large-scale theft caused confusion among users, as there were many incomprehensible aspects. Sources close to the company did not provide detailed assessments. It is known that multisig accounts supported by BitGo were affected. A significant part of the cryptocurrency community was affected.
The direct consequence of the Bitfinex hack can be seen in the price of Bitcoin, which fell almost 20% (to $480) after the news broke, only to recover later.
Given the amount of money involved, many were eager to find someone to blame for the situation. The main culprit was Bitfinex itself, which held two of the three private keys needed to complete the transactions, as well as BitGo, which held the third key. Questions also arise as to why the withdrawal of a huge 120,000 BTC was signed off calmly, without any verification. Also shortly before the event, Bitfinex entered into an agreement with the US Commodity Futures Trading Commission (CFTC) over alleged trading violations. After the hack, some critics blamed the CFTC for enabling the theft by prohibiting Bitfinex from using cold storage.
It is worth noting that in April 2021, the stolen bitcoins were moved (not all, but only 10% of the amount). This happened on the day Coinbase went public on the Nasdaq. Apparently, the attackers expected everyone to focus on the Coinbase listing and not pay attention to the transaction. Earlier, in November 2020, another 5,050 BTC of the stolen amount was transferred.
5 Hacking Zaif exchange, 2018
As a result of the hack of this Japanese cryptocurrency exchange, approximately US$ 60 million in cryptocurrencies were lost. The reason is unauthorized access by hackers to hot wallets.
Of the $60 million, 37.8 million were denominated in BTC. 32% of the stolen funds were Zaif’s own assets, while the rest belonged to clients. Zaif received a 5 billion yen loan to pay back the affected clients. The cases with Zaif and Coincheck have forced the Japanese financial regulator to take a closer look at these trading platforms and introduce stricter requirements for their security.
Also worth mentioning are incidents with exchanges such as:
Conrail 2018. Damage: US$ 37.2 million.
Bithumb 2018. Damages: US$ 30 million.
KuCoin 2020. Damages totaled $281 million, nearly all of which was returned to customers.
Livecoin, 2020. Damages unknown. (Maybe this is a scam on the part of Livecoin itself).
EXMO 2020. Damage: US$4 million.
DeFi protocol Rede Poli 2021. Loss of $610 million, the hacker returned all the money and said he did it for fun and to show developers security issues.
Liquid 2021. Damages: US$ 97 million.
And also many other cases with varying degrees of damage.
How to minimize losses from hackers on exchanges?
Leave only funds that you intend to Trade on the Exchange, the rest store in cold wallets such as safepal
Conclusion
Cryptocurrencies themselves are relatively safe, but the services that support their use can be dangerous. Unfortunately, finding a cryptocurrency exchange that has never been hacked is almost impossible. But there is consolation – over the years, protection becomes more and more reliable, and developers do not repeat previous mistakes. For example, no exchange developer today would think of storing users' funds in hot wallets connected to the Internet. This means that it is not so easy to steal assets.
Additionally, insurance fund systems are being introduced that will cover customers’ losses if something goes wrong. When choosing a cryptocurrency exchange, take a close look at how secure it is – this information should be in the public domain, and hiding it is definitely a red flag.