Historical record
Historical Exchange Incidents
A sourced record of material exchange events relevant to transparency, customer access, and verification. This archive provides historical context; it is not a live allegation or user-claims system.
Research archive
Material incidents and verification events
Event severity and response transparency are recorded separately. Figures reflect cited public reporting and may be revised.
Reported incident damage over time
Explicit USD figures only · ranges use the highest published estimate · logarithmic scale
Hover for details · click to open
36 incidents
Toggle details for Bithumb: BTC promotional-reward miscredit
BithumbReference caseBTC promotional-reward miscredit
Market integrity
Feb 2026
620,000 BTC credited in error
MonitoringHigh
BTC promotional-reward miscredit
Market integrity
Feb 2026
620,000 BTC credited in error
- Incident type
- Internal-ledger miscredit
- Jurisdiction
- South Korea
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Apr 6, 2026
What happened
During a promotional reward distribution, an input error treated Korean-won reward amounts as BTC and credited 620,000 BTC across 695 customer accounts. Bithumb restricted affected trading and withdrawals within 35 minutes, but sales of miscredited balances temporarily distorted its BTC market and contributed to losses for other traders.
Reserve and customer-asset evidence
The credits existed on Bithumb's internal ledger rather than as 620,000 BTC transferred on-chain. Bithumb said customer assets were not lost, reported restoring asset-account consistency, and began compensation for users affected by the resulting market disruption.
Toggle details for Upbit: Solana-network hot-wallet breach
UpbitReference caseSolana-network hot-wallet breach
Security breach
Nov 2025
₩44.5B · ~$30.1M
MonitoringHigh
Solana-network hot-wallet breach
Security breach
Nov 2025
₩44.5B · ~$30.1M
- Incident type
- Hot-wallet breach
- Jurisdiction
- South Korea
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jul 19, 2026
What happened
Upbit detected unauthorized transfers of Solana-network assets to external wallets beginning at 04:42 KST on November 27, 2025. The confirmed loss was revised to ₩44.5 billion. South Korea's Financial Supervisory Service later opened a formal sanctions process concerning the incident; public reporting also raised questions about disclosure timing.
Reserve and customer-asset evidence
Upbit said it would cover the full loss with company assets so customers would not bear the loss. It suspended digital-asset deposits and withdrawals, moved assets to cold wallets, and conducted a broader wallet-security review.
Toggle details for CoinDCX: Internal operational-account breach
CoinDCXReference caseInternal operational-account breach
Security breach
Jul 2025
~$44.2M treasury funds
ResolvedMedium
Internal operational-account breach
Security breach
Jul 2025
~$44.2M treasury funds
- Incident type
- Internal operational-account breach
- Jurisdiction
- India
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jul 21, 2025
What happened
A server-side compromise affected an internal operational account and resulted in a treasury loss. The event is useful for comparing initial disclosure timing with later evidence about customer-asset segregation and withdrawal performance.
Reserve and customer-asset evidence
CoinDCX said the affected account was used for liquidity provisioning, customer wallets were segregated and unaffected, and treasury reserves absorbed the loss. It reported processing all withdrawal requests.
Toggle details for Coinbase: Customer-data theft and extortion
CoinbaseCustomer-data theft and extortion
Security breach
May 2025
$180M–$400M estimated cost
MonitoringHigh
Customer-data theft and extortion
Security breach
May 2025
$180M–$400M estimated cost
- Incident type
- Customer data breach
- Jurisdiction
- United States
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- May 14, 2025
What happened
A threat actor obtained customer-account information and internal documentation after support personnel improperly accessed data, then demanded a $20 million payment. Coinbase disclosed the event in an SEC filing.
Reserve and customer-asset evidence
Coinbase estimated remediation and voluntary reimbursement costs; the event was a customer-data and social-engineering incident rather than a reserve shortfall.
Toggle details for Bitget: VOXELUSDT abnormal trading rollback
BitgetVOXELUSDT abnormal trading rollback
Market integrity
Apr 2025
Affected futures trades
ResolvedMedium
VOXELUSDT abnormal trading rollback
Market integrity
Apr 2025
Affected futures trades
- Incident type
- Abnormal trading and rollback
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Reported
- Last reviewed
- Apr 22, 2025
What happened
Abnormal VOXELUSDT futures volume and price movements triggered account restrictions and rollback of selected trades. Bitget subsequently announced support for affected traders.
Reserve and customer-asset evidence
Bitget said other users and platform funds remained unaffected; the response focused on trade rollback and compensation.
Toggle details for Bybit: Ethereum cold-wallet breach
BybitEthereum cold-wallet breach
Security breach
Feb 2025
~$1.46B
ResolvedHigh
Ethereum cold-wallet breach
Security breach
Feb 2025
~$1.46B
- Incident type
- Cold-wallet breach
- Jurisdiction
- United Arab Emirates
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Feb 26, 2025
What happened
Attackers manipulated a Safe multisignature signing workflow and removed ETH-related assets from a Bybit cold wallet. Bybit continued processing withdrawals, obtained replacement liquidity, and published forensic and reserve updates.
Reserve and customer-asset evidence
An updated third-party PoR reported in-scope assets backed above 100% after Bybit restored its ETH coverage within approximately 72 hours.
Toggle details for Phemex: Multi-chain hot-wallet breach
PhemexReference caseMulti-chain hot-wallet breach
Security breach
Jan 2025
~$69M+
ResolvedHigh
Multi-chain hot-wallet breach
Security breach
Jan 2025
~$69M+
- Incident type
- Multi-chain hot-wallet breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jan 2025
What happened
Phemex detected unusual activity across several hot wallets and temporarily suspended withdrawals. Its timeline documented containment and staged restoration, making it useful for response-transparency analysis.
Reserve and customer-asset evidence
Phemex suspended withdrawals, moved to inspect and rebuild wallet infrastructure, and said cold wallets and customer funds remained secure. Public estimates placed the hot-wallet loss above $69 million.
Toggle details for WazirX: Multisignature-wallet breach and restructuring
WazirXReference caseMultisignature-wallet breach and restructuring
Custody and solvency
Jul 2024
~$230M · ~45% of user funds
MonitoringHigh
Multisignature-wallet breach and restructuring
Custody and solvency
Jul 2024
~$230M · ~45% of user funds
- Incident type
- Security breach and reserve deficit
- Jurisdiction
- India / Singapore
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Oct 2025
What happened
Attackers compromised a multisignature wallet used under a third-party custody arrangement. WazirX stopped withdrawals and later reversed post-halt trades while pursuing a creditor restructuring plan.
Reserve and customer-asset evidence
The loss represented a material share of platform assets and led to prolonged withdrawal restrictions and court-supervised restructuring rather than immediate 1:1 reimbursement.
Toggle details for Kraken: Deposit-crediting vulnerability
KrakenDeposit-crediting vulnerability
Security breach
Jun 2024
~$3M treasury funds
ResolvedMedium
Deposit-crediting vulnerability
Security breach
Jun 2024
~$3M treasury funds
- Incident type
- Platform vulnerability
- Jurisdiction
- United States
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Aug 16, 2024
What happened
Security researchers exploited a deposit-crediting vulnerability and withdrew approximately $3 million, leading to a public dispute over bug-bounty conduct. CertiK later said the funds were returned.
Reserve and customer-asset evidence
Kraken stated that no client assets were affected or at risk and that the exploited funds came from its treasury.
Toggle details for Bitget: PLX token exploit and compensation
BitgetPLX token exploit and compensation
Security breach
Jun–Aug 2024
Affected PLX traders
ResolvedMedium
PLX token exploit and compensation
Security breach
Jun–Aug 2024
Affected PLX traders
- Incident type
- Third-party token exploit
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Reported
- Last reviewed
- Aug 7, 2024
What happened
An exploit allowed abnormal issuance of PLX tokens that were deposited and sold on Bitget. The exchange suspended the pair and pursued a resolution for affected users.
Reserve and customer-asset evidence
The compromised smart contract belonged to the PLEXUS project, not Bitget's core exchange custody system. Bitget announced its own compensation plan.
Toggle details for DMM Bitcoin: Customer bitcoin theft
DMM BitcoinReference caseCustomer bitcoin theft
Custody and solvency
May 2024
4,502.9 BTC · ¥48.2B
ResolvedHigh
Customer bitcoin theft
Custody and solvency
May 2024
4,502.9 BTC · ¥48.2B
- Incident type
- Security breach and closure
- Jurisdiction
- Japan
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Dec 2024
What happened
Customer bitcoin was transmitted outside DMM Bitcoin without authorization. The exchange later chose to discontinue operations and transfer customer accounts and assets to another group platform.
Reserve and customer-asset evidence
DMM Bitcoin said group companies would fund full compensation. Japan's regulator later found material weaknesses in system-risk management and incident response and issued a business-improvement order.
Toggle details for Poloniex: Hot-wallet breach and withdrawal suspension
PoloniexReference caseHot-wallet breach and withdrawal suspension
Security breach
Nov 2023
$100M+ reported
MonitoringHigh
Hot-wallet breach and withdrawal suspension
Security breach
Nov 2023
$100M+ reported
- Incident type
- Hot-wallet breach and withdrawal suspension
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Reported
- Last reviewed
- Nov 2023
What happened
A hot-wallet compromise led Poloniex to suspend deposits and withdrawals. The record remains relevant because the exchange's public solvency assurances were not paired with detailed, independently verified reserve evidence at the time.
Reserve and customer-asset evidence
Poloniex said operating revenue could cover the losses and promised full reimbursement, but its initial notice did not provide a complete loss figure or independent post-event reserve verification.
Toggle details for CoinEx: Multi-chain hot-wallet breach
CoinExReference caseMulti-chain hot-wallet breach
Security breach
Sep 2023
~$70M
ResolvedHigh
Multi-chain hot-wallet breach
Security breach
Sep 2023
~$70M
- Incident type
- Multi-chain hot-wallet breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Sep 22, 2023
What happened
CoinEx detected abnormal withdrawals from several hot wallets used for temporary custody of user assets. It published an evolving response timeline and wallet information.
Reserve and customer-asset evidence
CoinEx suspended deposits and withdrawals, moved remaining assets to new addresses, and said its user-asset security fund would cover affected customer assets.
Toggle details for Binance: Collateral-wallet classification error
BinanceCollateral-wallet classification error
Reserve and verification
Jan 2023
No loss established
ResolvedMedium
Collateral-wallet classification error
Reserve and verification
Jan 2023
No loss established
- Incident type
- Reserve-wallet classification
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jan 25, 2023
What happened
Collateral for some Binance-issued tokens was held in a wallet that also contained other assets. The event affected reserve-wallet clarity but did not by itself establish insolvency or misuse of customer assets.
Reserve and customer-asset evidence
Binance described the shared wallet placement as an operational or labeling error and said assets were being moved to dedicated collateral wallets.
Toggle details for Binance: Mazars PoR verification discontinued
BinanceMazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
MonitoringMedium
Mazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
- Incident type
- Third-party verification discontinued
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Mar 1, 2023
What happened
Mazars stopped providing crypto Proof-of-Reserves work and removed Binance's published report. The discontinuity reduced external assurance but did not establish missing reserves or insolvency.
Reserve and customer-asset evidence
The engagement covered agreed-upon procedures and was narrower than a full financial-statement audit.
Toggle details for Crypto.com: Mazars PoR verification discontinued
Crypto.comMazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
MonitoringMedium
Mazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
- Incident type
- Third-party verification discontinued
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Dec 16, 2022
What happened
Crypto.com published a Mazars agreed-upon-procedures PoR report shortly before Mazars discontinued crypto PoR work. This records a loss of ongoing external verification, not a failed reserve test.
Reserve and customer-asset evidence
The December snapshot reported 1:1 backing for in-scope balances, but the verifier subsequently stopped crypto PoR engagements.
Toggle details for KuCoin: Mazars PoR verification discontinued
KuCoinMazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
MonitoringMedium
Mazars PoR verification discontinued
Reserve and verification
Dec 2022
No reserve loss established
- Incident type
- Third-party verification discontinued
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Dec 16, 2022
What happened
KuCoin was among the crypto exchanges affected by Mazars' decision to stop Proof-of-Reserves work. This is an external-verification discontinuity rather than evidence of insolvency.
Reserve and customer-asset evidence
The external-verification relationship ended when Mazars paused all crypto PoR engagements.
Toggle details for FTX: Customer-fund misuse and collapse
FTXReference caseCustomer-fund misuse and collapse
Custody and solvency
Nov 2022
Billions in customer funds
MonitoringHigh
Customer-fund misuse and collapse
Custody and solvency
Nov 2022
Billions in customer funds
- Incident type
- Customer-fund misuse and fraud
- Jurisdiction
- The Bahamas / United States
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Mar 2024
What happened
FTX collapsed after an undisclosed diversion of customer funds to Alameda Research, preferential platform treatment for Alameda, and public assurances that conflicted with the exchange's actual financial condition. It is a benchmark transparency and liability-disclosure failure.
Reserve and customer-asset evidence
FTX paused customer withdrawals and filed for bankruptcy without sufficient readily available assets to honor customer claims. Court proceedings later established misuse of customer deposits and concealed exposure to Alameda Research.
Toggle details for Deribit: Hot-wallet breach
DeribitReference caseHot-wallet breach
Security breach
Nov 2022
$28M
ResolvedMedium
Hot-wallet breach
Security breach
Nov 2022
$28M
- Incident type
- Hot-wallet breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Nov 7, 2022
What happened
BTC, ETH, and USDC were stolen from a Deribit hot wallet. The exchange published a detailed timeline, identified unaffected asset pools, and described custody changes made after the event.
Reserve and customer-asset evidence
Deribit said company reserves covered the loss and that client assets, cold storage, and its insurance fund were unaffected. Withdrawals resumed after approximately one day.
Toggle details for Crypto.com: Unauthorized account withdrawals
Crypto.comUnauthorized account withdrawals
Security breach
Jan 2022
~$34M · 483 accounts
ResolvedHigh
Unauthorized account withdrawals
Security breach
Jan 2022
~$34M · 483 accounts
- Incident type
- Customer account breach
- Jurisdiction
- Singapore
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jan 20, 2022
What happened
Unauthorized transactions bypassed two-factor authentication on 483 customer accounts, resulting in withdrawals of BTC, ETH, and other funds.
Reserve and customer-asset evidence
Crypto.com said all affected customers were fully reimbursed after withdrawals were paused for approximately 14 hours.
Toggle details for AscendEX: Multi-chain hot-wallet breach
AscendEXReference caseMulti-chain hot-wallet breach
Security breach
Dec 2021
~$70M–$80M
ResolvedHigh
Multi-chain hot-wallet breach
Security breach
Dec 2021
~$70M–$80M
- Incident type
- Multi-chain hot-wallet breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Dec 12, 2021
What happened
Unauthorized transfers affected hot wallets across Ethereum, Polygon, BNB Chain, Litecoin, and Bitcoin Cash. AscendEX publicly discussed the estimated loss and its intended customer coverage.
Reserve and customer-asset evidence
AscendEX said cold wallets were unaffected and promised to reimburse impacted users in full from its own balance sheet.
Toggle details for Coinbase: Delayed cyber-event reporting
CoinbaseDelayed cyber-event reporting
Disclosure and transparency
May–Sep 2021
Five-month reporting delay
ResolvedHigh
Delayed cyber-event reporting
Disclosure and transparency
May–Sep 2021
Five-month reporting delay
- Incident type
- Delayed regulatory disclosure
- Jurisdiction
- United States
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jan 4, 2023
What happened
NYDFS found that Coinbase reported a cyber event to the U.S. Secret Service in May 2021 but did not report it to NYDFS until September despite a 72-hour reporting requirement.
Reserve and customer-asset evidence
Not a reserve-loss finding; the issue was failure to meet a required disclosure deadline.
Toggle details for Coinbase: SMS account-recovery compromise
CoinbaseSMS account-recovery compromise
Security breach
Mar–May 2021
≥6,000 customers
ResolvedHigh
SMS account-recovery compromise
Security breach
Mar–May 2021
≥6,000 customers
- Incident type
- Customer account compromise
- Jurisdiction
- United States
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Sep 24, 2021
What happened
Attackers used separately obtained credentials and exploited a flaw in Coinbase's SMS account-recovery process to access customer accounts and remove funds.
Reserve and customer-asset evidence
Coinbase reported reimbursing affected customers approximately $25.1 million.
Toggle details for OKX: Five-week withdrawal suspension
OKXFive-week withdrawal suspension
Withdrawal and operations
Oct–Nov 2020
Customer access restricted
ResolvedHigh
Five-week withdrawal suspension
Withdrawal and operations
Oct–Nov 2020
Customer access restricted
- Incident type
- Withdrawal interruption
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Nov 19, 2020
What happened
OKX suspended withdrawals because a private-key holder was unavailable during an investigation. The limited initial explanation and extended loss of customer access make this both an operational and disclosure event.
Reserve and customer-asset evidence
OKX said assets remained safe, but it did not publish post-event reserve verification comparable to modern PoR evidence.
Toggle details for KuCoin: Multi-asset hot-wallet breach
KuCoinMulti-asset hot-wallet breach
Security breach
Sep 2020
~$285M reported
ResolvedHigh
Multi-asset hot-wallet breach
Security breach
Sep 2020
~$285M reported
- Incident type
- Multi-asset hot-wallet breach
- Jurisdiction
- Seychelles
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Feb 3, 2021
What happened
Bitcoin and multiple tokens were removed from KuCoin hot wallets after private keys were compromised. Deposits and withdrawals were suspended while wallets and security systems were replaced.
Reserve and customer-asset evidence
KuCoin said affected users would be covered by the exchange and its insurance fund and later reported substantial asset recovery.
Toggle details for Upbit: Ethereum hot-wallet breach
UpbitReference caseEthereum hot-wallet breach
Security breach
Nov 2019
342,000 ETH · ~$49M
ResolvedHigh
Ethereum hot-wallet breach
Security breach
Nov 2019
342,000 ETH · ~$49M
- Incident type
- Hot-wallet breach
- Jurisdiction
- South Korea
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Nov 27, 2019
What happened
An unauthorized transfer removed 342,000 ETH from Upbit's hot wallet. The incident is useful for evaluating immediate disclosure, withdrawal continuity, and exchange-funded reimbursement.
Reserve and customer-asset evidence
Upbit said it would cover the loss from its own reserves, moved remaining hot-wallet assets into cold storage, and temporarily halted deposits and withdrawals.
Toggle details for Binance: Bitcoin hot-wallet breach
BinanceBitcoin hot-wallet breach
Security breach
May 2019
7,000 BTC
ResolvedHigh
Bitcoin hot-wallet breach
Security breach
May 2019
7,000 BTC
- Incident type
- Hot-wallet breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- May 2019
What happened
Attackers obtained credentials including API keys and two-factor authentication data and withdrew 7,000 BTC from one hot wallet. Binance temporarily suspended deposits and withdrawals.
Reserve and customer-asset evidence
Binance said the affected wallet held about 2% of its BTC and that its SAFU fund would cover the loss.
Toggle details for QuadrigaCX: Customer-asset misuse and collapse
QuadrigaCXReference caseCustomer-asset misuse and collapse
Custody and solvency
Feb 2019
C$169M shortfall
MonitoringHigh
Customer-asset misuse and collapse
Custody and solvency
Feb 2019
C$169M shortfall
- Incident type
- Customer-asset misuse and fraud
- Jurisdiction
- Canada
- Disclosure record
- No exchange response · Corroborated
- Last reviewed
- Jun 11, 2020
What happened
Quadriga claimed customer funds were liquid and withdrawable while its founder used client assets for operating expenses, personal spending, and speculative trading. The resulting shortfall brought down the platform.
Reserve and customer-asset evidence
The Ontario Securities Commission found C$215 million owed to clients against only C$46 million recovered or identified. It found inadequate records, no asset segregation, and extensive misuse of client assets.
Toggle details for Gate.io: Ethereum Classic 51% attack
Gate.ioEthereum Classic 51% attack
Security breach
Jan 2019
$100K in ETC returned
ResolvedMedium
Ethereum Classic 51% attack
Security breach
Jan 2019
$100K in ETC returned
- Incident type
- Network attack
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Reported
- Last reviewed
- Jan 12, 2019
What happened
An Ethereum Classic chain reorganization affected deposits processed by Gate. This was an external network-consensus attack rather than a compromise of Gate's core custody infrastructure.
Reserve and customer-asset evidence
Gate reported that approximately $100,000 of ETC was returned and increased ETC confirmation requirements.
Toggle details for Cryptopia: Multi-asset breach and liquidation
CryptopiaReference caseMulti-asset breach and liquidation
Custody and solvency
Jan–May 2019
~NZ$30M
MonitoringHigh
Multi-asset breach and liquidation
Custody and solvency
Jan–May 2019
~NZ$30M
- Incident type
- Security breach and liquidation
- Jurisdiction
- New Zealand
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- May 2026
What happened
Private keys were used to transfer multiple cryptocurrencies from Cryptopia without authorization. The exchange's subsequent liquidation created a significant customer-asset ownership and recovery case.
Reserve and customer-asset evidence
Court records estimate that 9%–14% of Cryptopia's cryptocurrency was stolen. The exchange briefly resumed operations before entering liquidation, and distributions remain part of a prolonged claims process.
Toggle details for Gate.io: StatCounter supply-chain attack
Gate.ioStatCounter supply-chain attack
Security breach
Nov 2018
No confirmed loss
ResolvedLow
StatCounter supply-chain attack
Security breach
Nov 2018
No confirmed loss
- Incident type
- Attempted security breach
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Nov 2018
What happened
Attackers compromised third-party StatCounter analytics code and targeted Gate.io users' Bitcoin withdrawal flow. The malicious code was identified and removed, with no confirmed customer loss reported.
Reserve and customer-asset evidence
No customer-asset shortfall was publicly identified.
Toggle details for Gate.io: RLC/USDT abnormal trading
Gate.ioRLC/USDT abnormal trading
Security breach
May 2018
~1.5M USDT trading volume
ResolvedMedium
RLC/USDT abnormal trading
Security breach
May 2018
~1.5M USDT trading volume
- Incident type
- Platform vulnerability
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Reported
- Last reviewed
- May 28, 2018
What happened
Malicious code injected through a chat feature caused abnormal RLC/USDT orders. Gate rolled back the affected 15-minute trading window and repaired the vulnerability.
Reserve and customer-asset evidence
Gate said suspicious accounts were frozen, no funds were lost from the platform, and affected users would be compensated.
Toggle details for Coincheck: NEM hot-wallet breach
CoincheckReference caseNEM hot-wallet breach
Security breach
Jan 2018
523M XEM · ~¥58B
ResolvedHigh
NEM hot-wallet breach
Security breach
Jan 2018
523M XEM · ~¥58B
- Incident type
- Hot-wallet breach
- Jurisdiction
- Japan
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Mar 2018
What happened
Attackers transferred customer NEM from a Coincheck hot wallet. The scale of the loss and the custody controls identified afterward made the event a major test of reimbursement capacity and regulatory transparency.
Reserve and customer-asset evidence
Coincheck announced reimbursement for affected customers. Japan's FSA conducted an onsite inspection and required improvements to security and operational controls.
Toggle details for Bitfinex: Bitcoin custody breach and recapitalization
BitfinexReference caseBitcoin custody breach and recapitalization
Custody and solvency
Aug 2016
~119,754 BTC
ResolvedHigh
Bitcoin custody breach and recapitalization
Custody and solvency
Aug 2016
~119,754 BTC
- Incident type
- Security breach and recapitalization
- Jurisdiction
- Global
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Nov 2024
What happened
A compromise of Bitfinex's multisignature custody arrangement resulted in the theft of nearly 120,000 BTC. The exchange halted operations and implemented a recovery-token structure to address the resulting customer-asset deficit.
Reserve and customer-asset evidence
Bitfinex socialized losses across customer balances and issued BFX recovery tokens, which it later reported as fully redeemed. The event is a major example of post-loss recapitalization rather than immediate 1:1 reimbursement.
Toggle details for Bitstamp: Hot-wallet breach
BitstampHot-wallet breach
Security breach
Jan 2015
18,866 BTC
ResolvedHigh
Hot-wallet breach
Security breach
Jan 2015
18,866 BTC
- Incident type
- Hot-wallet breach
- Jurisdiction
- Luxembourg
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jan 12, 2015
What happened
Attackers stole bitcoin from an operational hot wallet. Bitstamp suspended service and warned customers not to deposit to previously issued addresses while it investigated and rebuilt the platform.
Reserve and customer-asset evidence
Bitstamp said customer balances would be honored in full and relaunched after rebuilding its systems.
Toggle details for Mt. Gox: Exchange collapse and missing bitcoin
Mt. GoxReference caseExchange collapse and missing bitcoin
Custody and solvency
Feb 2014
850,000 BTC initially reported missing
MonitoringHigh
Exchange collapse and missing bitcoin
Custody and solvency
Feb 2014
850,000 BTC initially reported missing
- Incident type
- Custody failure and insolvency
- Jurisdiction
- Japan
- Disclosure record
- Exchange responded · Corroborated
- Last reviewed
- Jul 2024
What happened
Mt. Gox halted withdrawals and ceased operations before filing for bankruptcy. The prolonged, previously undetected loss and the gap between customer claims and recoverable assets made the collapse a defining custody and transparency failure.
Reserve and customer-asset evidence
Mt. Gox initially reported 850,000 BTC missing, later located 200,000 BTC, and entered bankruptcy and civil rehabilitation. Creditor repayments began more than a decade after the collapse.
Historical inclusion does not by itself establish present exchange risk, insolvency, or misconduct. Records are maintained for research context and may be corrected when stronger evidence becomes available.