EntryCrypto

Hacks and collapses

16 major crypto incidents from Mt. Gox to the Bybit hack, $14B+ in losses, and the lesson behind each one. Figures are approximate USD values at the time.

  1. Bybit · · $1.5B · exchange hack

    Attackers attributed to the Lazarus Group compromised the Safe{Wallet} front-end used by Bybit, tricking signers into approving a malicious transaction that drained an Ethereum cold wallet. Largest crypto hack to date. Bybit honored all withdrawals.

    Lesson: Even cold multisigs fail if signers cannot independently verify what they sign. Use hardware wallets that decode transaction data on-device.

  2. WazirX · · $235M · exchange hack

    A multisig wallet managed with custodian Liminal was drained after signers approved a disguised transaction that upgraded the wallet contract.

    Lesson: Blind signing is the root cause of most large custody losses. Verify contract upgrades on-device.

  3. DMM Bitcoin · · $305M · exchange hack

    The Japanese exchange lost 4,502 BTC from a hot wallet. The company was later wound down and customers were transferred to another exchange.

    Lesson: Deposit protection varies by country. Check what happens to your funds if the exchange fails.

  4. Poloniex and HTX · · $150M · exchange hack

    Two Justin Sun-linked exchanges lost hot-wallet funds within weeks of each other due to compromised private keys.

    Lesson: Hot-wallet key management is a recurring weak point. Keep long-term holdings off exchanges.

  5. Mixin Network · · $200M · custodian breach

    Attackers breached the cloud database of Mixin’s service provider and drained user assets.

    Lesson: Custodial wallets carry exchange-like risk without exchange-like disclosure.

  6. Euler Finance · · $197M · DeFi exploit

    A flash-loan attack exploited a bug in a donation function. The attacker later returned almost all funds.

    Lesson: Audits are not guarantees. Diversify across protocols and cap exposure.

  7. FTX · · $8.0B · insolvency or fraud

    FTX collapsed after it emerged that customer deposits had been lent to sister firm Alameda. Roughly $8B in customer funds were missing, and a further $400M+ was drained during the bankruptcy.

    Lesson: Proof-of-reserves and regulated segregation of customer assets matter more than marketing.

  8. BNB Chain Bridge · · $570M · bridge exploit

    A forged proof let an attacker mint 2M BNB on the BSC token hub. The chain was paused to contain the damage.

    Lesson: Bridges concentrate risk. Move only what you need across chains.

  9. Ronin Bridge (Axie Infinity) · · $625M · bridge exploit

    Lazarus Group social-engineered an engineer via a fake job offer, gaining 5 of 9 validator keys and draining the bridge.

    Lesson: Social engineering targets people, not code. Validator sets must be genuinely decentralized.

  10. Wormhole · · $320M · bridge exploit

    A signature verification bug allowed the attacker to mint 120k wrapped ETH on Solana without collateral. Jump Crypto replaced the funds.

    Lesson: A bridge is only as secure as its weakest verification path.

  11. Poly Network · · $611M · bridge exploit

    A cross-chain contract flaw allowed the attacker to change keeper roles. Most funds were returned.

    Lesson: Privileged roles in contracts need multi-party control and monitoring.

  12. KuCoin · · $280M · exchange hack

    Hot-wallet private keys were leaked. KuCoin recovered most funds with help from token projects and covered user losses.

    Lesson: Check whether an exchange has a track record of making users whole.

  13. Binance · · $40M · exchange hack

    Hackers used phished API keys and 2FA codes to withdraw 7,000 BTC in one transaction. Binance covered losses from its SAFU fund.

    Lesson: API keys are credentials. Restrict them by IP and never enable withdrawal permission unless required.

  14. Coincheck · · $530M · exchange hack

    NEM tokens stored in a single hot wallet without multisig were stolen. The incident triggered Japan’s exchange licensing crackdown.

    Lesson: Regulation followed catastrophe. Ask how an exchange stores assets before depositing.

  15. Bitfinex · · $72M · exchange hack

    119,756 BTC were stolen via a flaw in the multisig setup with BitGo. The coins were worth billions when the culprits were arrested in 2022.

    Lesson: Losses compound: coins stolen today are worth more tomorrow. Custody matters.

  16. Mt. Gox · · $450M · insolvency or fraud

    The then-dominant exchange lost about 850,000 BTC over years of undetected theft and filed for bankruptcy. Creditors began receiving repayments only in 2024.

    Lesson: Not your keys, not your coins. Recoveries can take a decade.

Questions

What is the biggest crypto hack in history?
The February 2025 Bybit hack: roughly $1.5 billion in ETH drained from a cold wallet after the Safe{Wallet} signing interface was compromised. Attribution points to the Lazarus Group.
What is the most common cause of exchange hacks?
Compromised private keys for hot wallets and blind signing of multisig transactions. Social engineering of staff is the usual entry point, not a flaw in the blockchain itself.
Do exchanges refund users after a hack?
Sometimes. Binance (2019), KuCoin (2020) and Bybit (2025) covered losses from their own funds. Mt. Gox, FTX and DMM Bitcoin users faced years-long bankruptcy processes or partial recoveries.