BTC.TedLee.ca
Bitcoin history · losses, failures and lessons

When People Lost Their Bitcoin

From Mt. Gox to FTX and the 2026 Coldcard key-generation flaw: a chronological record of how people lost BTC through failed custodians, fraud, risky lending, weak wallets and missing private keys.

In these cases, the Bitcoin network itself was not hacked.

This page is about Bitcoin only

It does not cover losses of altcoins, tokens, NFTs or DeFi projects. Some failed companies held many types of assets. FTX, Celsius, Voyager and BlockFi appear here only because customers also entrusted Bitcoin to them; organization-wide dollar losses were not necessarily Bitcoin losses.

Bitcoin’s blockchain did what it was designed to do in every incident below. The failures happened around Bitcoin: a company controlled the keys, a criminal gained the keys, a wallet created weak keys, or an owner lost the only backup.

Five ways Bitcoin became lost or inaccessible

“Lost” does not always mean the same thing. Some BTC was stolen forever; some was frozen for years; some customers were repaid; and some coins still exist on-chain but can no longer be spent.

Custodian failure

An exchange held the private keys and failed, froze withdrawals or was hacked.

Fraud

Promoters promised extraordinary investment or mining returns and took victims’ BTC.

Risky lending

Owners gave up control to earn interest and became unsecured creditors.

Weak key creation

A flawed random-number process made supposedly secret keys guessable.

Lost backup

The owner lost or destroyed the private key or seed phrase, leaving no recovery route.

2011–2026

Chronological Bitcoin loss timeline

Figures are approximate. BTC amounts may describe assets stolen, missing, deposited into a scheme or traced through related wallets—not necessarily each victim’s final net loss. Repayments and recoveries are noted where important.

ExchangeFraudLendingWallet flawLost keyCustomers coveredDeveloping
2011–14

Mt. Gox

Japan · Exchange
Trustee notice ↗
Reported missing: about 850,000 BTC; roughly 200,000 BTC was later located.

The world’s dominant early Bitcoin exchange collapsed in February 2014 after years of theft, weak controls and mismanagement. Roughly 650,000 BTC remained unaccounted for after the later discovery. Court-supervised partial repayments in Bitcoin and Bitcoin Cash began in July 2024—more than ten years after the collapse.

2012

Bitcoinica

Online trading platform · Exchange
Contemporary report ↗
Repeated breaches: about 43,554 BTC in March and about 18,547 BTC in May, plus a disputed later incident.

Bitcoinica suffered multiple compromises in only a few months. Confused records, creditor disputes and liquidation made the final customer loss difficult to calculate—a warning that poor accounting can compound a security failure.

2012

Bitcoin Savings & Trust

United States · Ponzi scheme
U.S. SEC ↗
More than 700,000 BTC passed through the scheme.

Trendon Shavers promised returns as high as 7% per week. The SEC described it as a Bitcoin-denominated Ponzi scheme. The large BTC figure measures deposits and flows through the operation, not a one-time wallet theft or a precise final net loss.

2013

James Howells’ discarded hard drive

Wales · Lost private key
Court report ↗
Reportedly 7,500–8,000 BTC became inaccessible.

A hard drive believed to contain the wallet’s private key was accidentally discarded. No thief took the coins; the Bitcoin remains on the ledger but cannot be spent without the key. A court rejected his effort to force access to the landfill.

2013

Inputs.io

Online wallet · Custodial wallet
WIRED report ↗
About 4,100 BTC stolen in two attacks.

The online-wallet service was hacked and did not have enough reserves to make every user whole. The operator offered partial repayment, illustrating the risk of trusting a hosted wallet with the only spendable keys.

2015

Bitstamp hot-wallet hack

European exchange · Exchange Covered
U.S. DOJ ↗
18,866 BTC stolen; Bitstamp said customers would not bear the loss.

A phishing and social-engineering campaign compromised the exchange’s operational wallet. Bitstamp shut down temporarily, rebuilt its systems and covered the loss. It is included as a near-miss for customers, not a permanent customer loss.

2016

Bitfinex

Hong Kong-based exchange · Exchange
U.S. DOJ ↗
119,754 BTC stolen in more than 2,000 unauthorized transactions.

Bitfinex initially spread the loss across customer accounts and issued compensation tokens, which it later redeemed. U.S. authorities subsequently seized most of the stolen Bitcoin. The case shows that recovery can happen, but may take years.

2018

BitConnect collapse

International · Fraud
U.S. DOJ ↗
About US$2.4 billion obtained from investors across all assets.

Victims transferred Bitcoin into an alleged high-yield lending program. Because the operation revolved around a separate token, this page does not count its headline dollar figure as a Bitcoin-only loss; it is included because Bitcoin was the entry asset many victims surrendered.

2019

QuadrigaCX

Canada · Exchange fraud
Ontario Securities Commission ↗
76,000 clients lost at least C$169 million in cash and mixed digital assets.

Founder Gerald Cotten controlled the platform and used customer assets to cover trading losses and personal spending. The OSC concluded the collapse resulted from fraud—not simply from Cotten dying with the only passwords, as early reports suggested. A BTC-only final loss is not available.

2019

Binance hot-wallet hack

Global exchange · Exchange Covered
Binance notice ↗
7,000 BTC stolen; Binance covered the loss from its emergency fund.

Attackers used phishing, malware and stolen account credentials. Customers did not ultimately bear the theft, so this is another example of a custodian surviving a large breach rather than a permanent client loss.

2019

PlusToken

International · Ponzi scheme
Chainalysis ↗
About 180,000 BTC traced to wallets connected with the operation.

The scheme promised high returns and stopped withdrawals in 2019. It collected multiple asset types, so the traced BTC total is not the same as a final net Bitcoin loss; recovered, transferred and laundered funds complicate the calculation.

2019

BitClub Network

Operated 2014–2019 · Mining fraud
U.S. DOJ case page ↗
At least US$722 million worth of Bitcoin solicited from victims.

Promoters sold supposed shares in Bitcoin mining pools and displayed false mining returns. BitClub was not an exchange hack: it was a fraudulent investment and recruitment scheme that accepted victims’ Bitcoin.

2020

LuBian mining-pool theft

Not publicly identified until 2025 · Weak keys
Arkham findings reported ↗
On-chain analysts attributed the loss of about 127,426 BTC to weak private-key generation.

Arkham Intelligence reported that an attacker apparently derived LuBian’s weak keys and moved the funds in December 2020. LuBian never publicly confirmed the event, so this remains an on-chain analytical conclusion rather than a fully documented company disclosure.

2022

Celsius Network

Crypto lender · Lending collapse
U.S. DOJ ↗
Customers lost access to about US$4.7 billion in mixed assets when withdrawals stopped.

Customers had transferred ownership and control of their BTC and other assets to earn yield. Founder Alex Mashinsky later pleaded guilty and received a 12-year prison sentence. Bankruptcy distributions recovered part of creditor claims, but the headline figure is not BTC-only.

2022

Voyager Digital and BlockFi

Crypto lenders · Bankruptcies
BlockFi distributions ↗
BTC and other customer assets were frozen; later distributions were based on bankruptcy claims.

Both lenders failed during the 2022 credit crisis. BlockFi later announced recovery of the allowed dollar value of eligible customer claims. A dollar-based repayment after Bitcoin’s price changes is not necessarily equivalent to returning the original BTC.

2022

FTX and Sam Bankman-Fried

Bahamas / United States · Exchange fraud
U.S. DOJ ↗
Prosecutors said more than US$8 billion in customer money was stolen across all asset types.

FTX secretly transferred customer deposits to Alameda Research, where they were spent and lost. Bankman-Fried was convicted and sentenced to 25 years. Bankruptcy creditors began receiving dollar-based distributions, but customers who deposited BTC did not necessarily receive the same amount of BTC back.

2024

DMM Bitcoin

Japan · Exchange / wallet compromise
FBI & Japanese police ↗
4,502.9 BTC stolen, worth about US$308 million at the time.

Authorities attributed the theft to North Korean-linked actors. They compromised an employee at a wallet-software provider, stole session information and manipulated a legitimate DMM transaction request.

2026

Coldcard key-generation vulnerability

Hardware wallet · Weak randomness Developing
Official advisory ↗
Initial sweep: about 594 BTC from roughly 500 wallets. Later analysis: about 1,082.65 BTC from 1,196 addresses. The total remains provisional.

Firmware generated some seeds with far less randomness than intended, allowing an attacker to reconstruct private keys offline. Coinkite confirms that affected seeds span multiple Coldcard models and firmware tracks. The Bitcoin protocol and its cryptography were not broken; the failure occurred when the wallet created the secret.

Current safety notice · updated August 1, 2026

Coldcard owners: updating alone does not repair an old weak seed

According to Coinkite’s current advisory, seeds created on the following versions may be affected unless at least 50 fair, independent and private dice rolls were added during seed creation:

  • Mk2/Mk3: firmware 4.0.1 through 4.1.9. Fixed in 4.2.0 or later.
  • Mk4/Mk5: before standard 5.6.0 or Edge 6.6.0X.
  • Q: before standard 1.5.0Q or Edge 6.6.0QX.

A firmware update fixes the creation of future seeds; it cannot strengthen a seed already generated. Coinkite advises affected owners to install fixed firmware, create a new seed, verify the backup and receive address, send a small test transaction, and then carefully migrate the remaining balance. A strong, unique BIP-39 passphrase adds protection but does not repair the weak seed. The device PIN is not a BIP-39 passphrase.

Read Coinkite’s complete and continually updated instructions before acting →

What history teaches

Six practical lessons for Bitcoin holders

Self-custody removes the risk of an exchange taking your BTC, but it transfers responsibility to you. There is no completely risk-free storage method.

01

Understand who holds the keys

Bitcoin on an exchange is a claim against a company. Withdrawal to a wallet you control removes that counterparty risk.

02

Do not chase impossible yield

Guaranteed, unusually high or steady returns are classic warning signs. Bitcoin does not naturally pay interest.

03

Verify wallet generation

Use current, authentic firmware and understand how a wallet generates entropy. Never create a seed on a website or connected computer.

04

Back up for real life

Protect against fire, theft, water, memory loss and death. A backup must be readable and recoverable—but not easily found by a thief.

05

Test before trusting

Verify receive addresses on the hardware screen. Practice recovery with a small balance and send a small test before a large transfer.

06

Avoid one point of failure

For meaningful holdings, consider separating funds, devices, locations or signing keys. Complexity also creates risk, so use only a setup you can operate correctly.

Evidence and further reading

Sources

Primary government, regulator, court, trustee and company sources are used where available. Investigative reporting and on-chain analysis are identified as such. External links open in a new tab.

  1. Mt. Gox rehabilitation trustee — commencement of repayments (2024)
  2. Gemini Cryptopedia — Mt. Gox historical overview
  3. Network World — contemporary Bitcoinica report (2012)
  4. U.S. SEC — final judgment against Trendon Shavers
  5. The Guardian — James Howells landfill court ruling (2025)
  6. WIRED — Inputs.io wallet theft (2013)
  7. U.S. DOJ — Bitstamp cybercrime sentencing
  8. U.S. DOJ — Bitfinex guilty pleas and theft facts
  9. U.S. DOJ — BitConnect founder indictment
  10. Ontario Securities Commission — QuadrigaCX report
  11. Binance — May 2019 security-breach announcement
  12. Chainalysis — PlusToken on-chain analysis
  13. U.S. DOJ — BitClub Network case collection
  14. CoinDesk — Arkham’s LuBian on-chain findings
  15. U.S. DOJ — Celsius founder sentencing
  16. U.S. SEC — BlockFi lending order (PDF)
  17. BlockFi bankruptcy distributions
  18. U.S. DOJ — Sam Bankman-Fried sentencing
  19. FBI and Japan NPA — DMM Bitcoin theft attribution
  20. Coinkite — official Coldcard security advisory, updated August 1, 2026
  21. CoinDesk — initial 594 BTC Coldcard sweep report
  22. CoinDesk — later Coldcard scope estimate citing Galaxy Research

Important disclaimer

This independent page is for education and historical discussion only. It is not financial, investment, security, legal or tax advice. Figures are approximate and may change as investigations, court proceedings, recoveries and repayments continue. A company’s inclusion does not mean every customer suffered a permanent loss. Verify current information directly with original sources and seek qualified professional help for decisions involving substantial Bitcoin holdings.

Never share your seed words, private keys, wallet backup or passphrase with anyone. Never enter them into a website.