The Biggest Crypto Hacks and Collapses in History: What Actually Happened
Mt. Gox lost 850,000 Bitcoin in 2014. The DAO hack split Ethereum in two in 2016. Ronin Network lost $620 million in 2022. FTX collapsed with $8.9 billion in missing customer funds the same year. Each of these events changed crypto permanently. Here is what actually happened in each case and what the industry learned from it.
TL;DR: The history of crypto hacks and collapses is not a footnote to the industry's story. It is a central part of it. Every major security failure has directly shaped how exchanges custody assets, how smart contracts are audited, how regulators approach oversight, and how individual users think about self-custody versus exchange trust. This guide covers the ten most consequential incidents: Mt. Gox (2014, 850,000 BTC), The DAO hack (2016, $60 million in ETH), Coincheck (2018, $534 million in NEM), BitFinex (2016, 119,756 BTC), Ronin Network (2022, $620 million), Wormhole Bridge (2022, $320 million), Terra/Luna collapse (2022, $40 billion market cap destruction), Celsius (2022, $4.7 billion in frozen customer funds), FTX (2022, $8.9 billion in missing customer funds), and DMM Bitcoin (2024, $305 million). MediaCrypto note: the pattern across all these incidents is consistent. Concentrated custody without adequate security, algorithmic designs with untested failure modes, fraud enabled by insufficient governance, and cross-chain bridges with inadequate validator security are the recurring vulnerabilities. Understanding them is the most practical crypto security education available.
Crypto's failures have been as defining as its successes. Bitcoin might have died in 2014 if the community had not rebuilt confidence after Mt. Gox. Ethereum might have fragmented permanently after the DAO hack. The 2022 cascade of collapses, from Terra/Luna to Celsius to FTX, produced the regulatory pressure that has now resulted in comprehensive frameworks in the US, EU, and multiple other jurisdictions.
The incidents below are not just historical curiosities. They are the events that shaped every security standard, regulatory requirement, and custody practice that exists in crypto in 2026.
Mt. Gox (2014): 850,000 Bitcoin, the Collapse That Almost Ended Bitcoin
Amount lost: 850,000 Bitcoin (approximately $470 million at 2014 prices, approximately $50 billion at July 2026 prices) Attack type: Long-running exchange hack plus internal mismanagement Year: February 2014
Mt. Gox was, at its peak, the largest Bitcoin exchange in the world, handling approximately 70 to 80 percent of all global Bitcoin transactions. It was founded in 2010 by Jed McCaleb and later sold to Mark Karpelès, a French developer who ran the exchange from Tokyo.
The hack was not a single event. Mt. Gox had been leaking Bitcoin since at least 2011, with hackers exploiting a combination of security vulnerabilities and internal control failures over several years. In February 2014, Mt. Gox suspended trading and filed for bankruptcy, revealing that approximately 850,000 Bitcoin belonging to customers and 100,000 belonging to the exchange had vanished. At 2014 prices, the loss was roughly $470 million. At current prices, those Bitcoin would be worth approximately $50 billion.
The immediate consequence was Bitcoin's price falling from approximately $800 to below $350 within months and remaining depressed for over a year. More significantly, the collapse demonstrated that the infrastructure around Bitcoin, the exchanges and custody services, needed to be rebuilt from scratch with security as a first principle rather than an afterthought.
The recovery and legal process took a decade. Mt. Gox's trustee, Nobuaki Kobayashi, began distributing recovered Bitcoin to creditors in 2024, approximately 10 years after the bankruptcy filing. The approximately 142,000 recovered Bitcoin distributed to creditors has itself been a recurring market overhang narrative, with concern about creditor selling adding periodic bearish pressure to Bitcoin's price.
What changed: Mt. Gox established the baseline case for why exchanges must hold customer assets in segregated cold storage, maintain auditable reserves, and implement multi-signature security for any significant Bitcoin custody. Every exchange custody standard that exists in 2026 traces back in some way to the failures Mt. Gox exposed.
The DAO Hack (2016): $60 Million in ETH and a Community Divided
Amount lost: Approximately $60 million in ETH (approximately 3.6 million ETH at the time) Attack type: Smart contract reentrancy exploit Year: June 2016
The DAO (Decentralized Autonomous Organization) was a venture capital fund built on Ethereum that raised approximately $150 million in ETH through a token sale in May 2016, making it the largest crowdfund in history at the time. The DAO's smart contract allowed token holders to vote on investment proposals.
The exploit used a reentrancy vulnerability, a code pattern where a malicious contract can call back into a function before the initial call completes, allowing it to drain funds repeatedly before the balance is updated. The attacker used this vulnerability to drain approximately 3.6 million ETH, worth about $60 million, into a child DAO they controlled.
The response divided the Ethereum community. One faction argued that "code is law", the smart contract executed as written and no intervention was appropriate. The other faction argued that returning funds to victims required an intervention. The majority voted for a hard fork that reversed the transactions and returned the funds. A minority rejected the hard fork and continued the original Ethereum chain, which became Ethereum Classic (ETC).
What changed: The DAO hack is the foundational case study for smart contract security. It gave the term reentrancy attack permanent significance in smart contract development and made security audits a standard expectation before deploying any significant DeFi protocol. The community's decision to hard fork also established that Ethereum's governance, while decentralized, could make significant decisions through rough consensus when the stakes were high enough.
Bitfinex (2016): 119,756 Bitcoin Through Multisig Compromise
Amount lost: 119,756 Bitcoin (approximately $72 million at 2016 prices) Attack type: Multi-signature security compromise Year: August 2016
Bitfinex, a major Bitcoin exchange, suffered a hack in August 2016 that stole 119,756 Bitcoin through a compromise of its multi-signature wallet system implemented with BitGo. The hack remains technically unusual because it involved compromising a multi-signature system that theoretically required multiple parties to authorize transactions.
The stolen Bitcoin were recovered in a dramatic development in February 2022, when US law enforcement arrested Ilya Lichtenstein and Heather Morgan for allegedly laundering approximately 119,754 of the stolen Bitcoin. The recovery was one of the largest cryptocurrency seizures in US law enforcement history. Lichtenstein pleaded guilty and cooperated with authorities, receiving a sentence in 2024.
What changed: The Bitfinex hack and the subsequent decade-long recovery case established several precedents. It demonstrated that crypto theft is not inherently untraceable, as blockchain analytics can follow stolen funds across years of attempted obfuscation. It also raised serious questions about multi-signature implementation, specifically whether the security model was actually enforced as intended or whether the Bitcoin remained more vulnerable than the multi-sig architecture implied.
Coincheck (2018): $534 Million in NEM From a Hot Wallet
Amount lost: Approximately $534 million in NEM (XEM) tokens Attack type: Hot wallet compromise Year: January 2018
Coincheck was a Japanese exchange that suffered the largest theft in crypto history at the time of the incident. The attack exploited a straightforward vulnerability: Coincheck held approximately $534 million in NEM tokens in a hot wallet connected to the internet, without using the multi-signature security that NEM's protocol recommended for large holdings.
The Japanese Financial Services Agency moved quickly, issuing a business improvement order to Coincheck and subsequently to other Japanese exchanges that failed security inspections. Rather than failing entirely, Coincheck was eventually acquired by Monex Group and restructured with improved security. It continues to operate in 2026 as one of Japan's FSA-registered exchanges.
What changed: Coincheck established the now-universal standard that exchange hot wallets should hold the minimum required for operational liquidity and that the large majority of customer assets must be in cold storage. Japan's subsequent regulatory tightening after Coincheck directly shaped the custody standards that apply to all FSA-registered exchanges in 2026.
Ronin Network (2022): $620 Million and North Korea
Amount lost: Approximately $620 million (173,600 ETH and $25.5 million USDC) Attack type: Compromised validator nodes Year: March 2022
The Ronin Network hack is the largest single crypto theft in history by dollar value at the time of the incident. Ronin is a blockchain bridge used by Sky Mavis's Axie Infinity game. The attack compromised five of the nine validator nodes required to authorize Ronin transactions, allowing the attacker to approve fraudulent withdrawals.
The US Treasury Department later attributed the attack to North Korea's Lazarus Group, making it one of the most significant state-sponsored crypto thefts ever documented. The Lazarus Group has been responsible for multiple other major crypto thefts, with North Korea using stolen crypto to fund its weapons programs in circumvention of international sanctions.
The Ronin hack was not discovered for six days after the theft occurred, illustrating a monitoring failure that compounded the security failure.
What changed: The Ronin hack made cross-chain bridges one of the most scrutinized security categories in crypto. Bridges that connect different blockchains have become one of the most frequently targeted attack vectors because they often hold large amounts of assets and their security depends on validator sets that may have smaller quorums than the underlying chains. More rigorous validator key management, multi-party computation for validator signatures, and more aggressive monitoring became standard recommendations after Ronin.
Terra/Luna Collapse (2022): $40 Billion in Market Cap Destruction
Amount lost: Approximately $40 billion in market cap across LUNA and UST Attack type: Algorithmic stablecoin design failure Year: May 2022
The Terra/Luna collapse was not a hack. It was a design failure at scale. TerraUSD (UST) was an algorithmic stablecoin designed to maintain its dollar peg through a mint-and-burn relationship with its sister token LUNA, rather than through dollar reserves backing each token.
The mechanism worked while confidence in the system held. When large-scale UST redemptions began in early May 2022, possibly coordinated by a large market participant exploiting the mechanism's known theoretical weakness, the system entered a death spiral. LUNA was minted in enormous quantities to absorb UST redemptions, hyperinflating LUNA's supply and collapsing its price. UST lost its peg and traded to near zero within days. Approximately $40 billion in combined LUNA and UST market cap was destroyed in less than two weeks.
Do Kwon, Terra's founder, was arrested in Montenegro in 2023 and faces fraud charges in both South Korea and the United States. The collapse contributed directly to the cryptocurrency market's prolonged bear market through 2022 and into 2023.
What changed: Terra/Luna destroyed confidence in algorithmic stablecoins as a category. Every regulatory framework introduced after 2022, including MiCA, the GENIUS Act, and equivalents in Australia and Singapore, treats algorithmic stablecoins with significant caution or outright prohibition. The incident also established that a stablecoin's peg mechanism must be demonstrated to work under adverse conditions rather than simply theorized.
Celsius (2022): 4.7 Billion in Frozen Customer Funds
Amount lost: Approximately $4.7 billion in customer funds at time of bankruptcy filing Attack type: Not a hack. Mismanagement, undisclosed risks, and liquidity mismatch Year: June to July 2022
Celsius was a crypto lending platform that offered customers yields of up to 18 percent on crypto deposits, funded by lending those deposits to institutional borrowers and deploying them in DeFi strategies. In June 2022, Celsius froze customer withdrawals, citing the need to stabilize liquidity amid market conditions. It filed for bankruptcy in July 2022.
Investigation revealed that Celsius had deployed customer funds in risky strategies that were not adequately disclosed, had suffered significant unreported losses (including from exposure to the Terra/Luna collapse), and had operated with a severe mismatch between the liquidity it offered customers (withdrawals at any time) and the illiquidity of many of its deployed positions (locked in staking or DeFi positions that could not be immediately unwound).
Founder Alex Mashinsky was arrested in July 2023 on fraud charges. The bankruptcy proceedings distributed partial recovery to creditors over the following years.
What changed: Celsius established that the promise of high yields in crypto lending should be treated as a warning sign rather than a feature. The collapse, alongside the simultaneous failures of BlockFi, Voyager, and Genesis through 2022 and 2023, effectively ended the first generation of centralized crypto lending as a retail product and drove regulatory frameworks in every major jurisdiction to require custody segregation, reserve adequacy, and disclosure standards for any entity offering crypto yield products.
FTX (2022): $8.9 Billion and Sam Bankman-Fried
Amount lost: $8.9 billion in customer funds Attack type: Fraud, misappropriation of customer funds, and alleged hack during bankruptcy Year: November 2022
FTX's collapse was the most consequential single event in crypto's history after Mt. Gox, and unlike most other incidents on this list, it was primarily fraud rather than an external hack. FTX, founded by Sam Bankman-Fried in 2019, was at its peak one of the world's largest crypto exchanges, valued at over $32 billion.
The collapse began when CoinDesk published an article in November 2022 revealing that Alameda Research, FTX's affiliated trading firm, held a significant portion of its assets in FTX's own native token FTT. Binance announced it would liquidate its FTT holdings, triggering a bank run on FTX as users rushed to withdraw. FTX halted withdrawals within days, revealing a $8 billion gap in customer funds that Sam Bankman-Fried had allegedly covered by secretly lending customer deposits to Alameda Research to fund its trading and investments.
FTX filed for Chapter 11 bankruptcy on November 11, 2022. The same day, $477 million was drained from FTX's wallets in what the exchange described as unauthorized transfers. Subsequent investigation attributed the theft to a US-based SIM swapping ring that exploited the chaos of the bankruptcy process.
Sam Bankman-Fried was arrested in the Bahamas in December 2022, extradited to the United States, tried, and convicted of fraud and conspiracy charges in November 2023. He received a 25-year prison sentence in March 2024 and was ordered to forfeit $11 billion.
What changed: FTX produced the most sweeping regulatory response in crypto's history. It directly motivated the GENIUS Act's stablecoin provisions requiring reserve segregation, accelerated MiCA's transition deadlines in Europe, drove the SEC's aggressive enforcement posture that led to suits against Coinbase and Binance (subsequently settled), and prompted spot Bitcoin ETF approval as a regulated alternative to exchange custody. The specific protection that customer assets must be legally segregated from company assets in a bankruptcy has become a mandatory requirement in virtually every crypto regulatory framework introduced since FTX's collapse.
DMM Bitcoin (2024): $305 Million and Japan's Second Major Exchange Failure
Amount lost: Approximately $305 million (4,502.9 Bitcoin) Attack type: Private key compromise Year: May 2024
DMM Bitcoin, a Japanese cryptocurrency exchange, suffered a hack in May 2024 that resulted in the theft of 4,502.9 Bitcoin valued at approximately $305 million, making it the largest Japanese exchange theft since Coincheck in 2018. The stolen Bitcoin were drained in a single transaction, suggesting compromise of the private keys controlling a significant wallet.
DMM Bitcoin announced in December 2024 that it would wind down operations, transferring customer accounts to SBI VC Trade. The collapse was the second significant Japanese exchange failure and came after years of strengthened FSA oversight following Coincheck, raising questions about whether Japan's enhanced regulatory requirements were being applied consistently across all registered exchanges.
What changed: DMM Bitcoin reinforced that private key security remains the foundational vulnerability regardless of regulatory oversight. It also demonstrated that regulatory registration does not guarantee security, a distinction that regulators in Japan and elsewhere have been explicit about.
The Pattern Across All These Incidents
Looking across all ten incidents, several consistent patterns emerge.
Concentrated custody without adequate security is responsible for Mt. Gox, Coincheck, and DMM Bitcoin. Massive amounts of customer assets in inadequately secured hot wallets or with insufficient internal controls created targets that attackers exploited. The cold storage mandates now required by Singapore (90 percent minimum), Japan, and most other developed regulatory frameworks exist directly because of these incidents.
Algorithmic designs with untested failure modes produced the Terra/Luna collapse. A mechanism that worked in normal conditions had a known theoretical weakness that was never adequately stress-tested against adversarial conditions at scale. The stablecoin reserve requirements now mandatory under MiCA and the GENIUS Act exist because of Terra/Luna.
Fraud enabled by insufficient governance and customer protection explains Celsius, FTX, and arguably parts of the Bitfinex situation. Customer assets treated as operational capital, yield promises backed by undisclosed risks, and absence of meaningful separation between customer funds and company activities. Custody segregation requirements now mandatory in virtually every regulatory framework exist because of these incidents.
Cross-chain bridge vulnerabilities explain Ronin and Wormhole. Bridges that connect different blockchains have emerged as one of the highest-risk categories in crypto, because they hold large assets and their security depends on validator sets and smart contract code with limited time for stress testing before deployment at scale.
About the Author
This article was researched and written by the MediaCrypto editorial team. MediaCrypto is a cryptocurrency news and market analysis publication covering Bitcoin, Ethereum, altcoins, regulatory developments, and market trends. Follow us on X at @MediaCrypto_AI and on Instagram.
FAQ — Biggest Crypto Hacks and Collapses
What is the biggest crypto hack in history? The Ronin Network hack in March 2022, attributed to North Korea's Lazarus Group, stole approximately $620 million (173,600 ETH and $25.5 million USDC), making it the largest single crypto theft by dollar value at time of incident.
What happened to Mt. Gox? Mt. Gox, once the world's largest Bitcoin exchange handling 70 to 80 percent of global transactions, collapsed in February 2014 after revealing that 850,000 Bitcoin (approximately $470 million at 2014 prices) had been stolen through years of security failures and mismanagement. Its bankruptcy trustee began distributing approximately 142,000 recovered Bitcoin to creditors in 2024, a decade after the collapse.
How much did FTX steal from customers? FTX, under founder Sam Bankman-Fried, had an $8.9 billion gap in customer funds caused by secretly lending customer deposits to affiliated trading firm Alameda Research. Bankman-Fried was convicted of fraud and conspiracy and sentenced to 25 years in prison in March 2024.
What was the Terra/Luna collapse? TerraUSD (UST) was an algorithmic stablecoin that maintained its dollar peg through a mint-and-burn mechanism with LUNA rather than through dollar reserves. In May 2022, large-scale UST redemptions triggered a death spiral that destroyed approximately $40 billion in combined market cap within days. The collapse ended confidence in algorithmic stablecoins and directly influenced every stablecoin regulatory framework introduced since.
What did these hacks change about crypto? Each major incident produced lasting changes. Mt. Gox established cold storage custody standards. The DAO hack created the smart contract security audit industry. Coincheck produced Japan's strict custody regulations. Ronin made bridge security a primary concern. FTX produced mandatory customer fund segregation requirements in virtually every regulatory framework introduced since 2022.
For live crypto prices and market data see https://mediacrypto.ai/market
Read also: How to Keep Your Crypto Safe From Hackers in 2026 — https://mediacrypto.ai/news/how-to-keep-your-crypto-safe-from-hackers-in-2026
Read also: What Is a Smart Contract A Simple Explanation for Beginners — https://mediacrypto.ai/news/what-is-a-smart-contract-a-simple-explanation-for-beginners
This article is for informational purposes only and does not constitute financial advice. Always do your own research before making investment decisions.











