Biggest Crypto Exchange Hacks Ranked by Amount Stolen

By Dana Kovac · Published 2026-09-28 · Independent review — not affiliated with any exchange

Bottom line

Ranked by dollar value at time of theft, the biggest crypto exchange hacks are Bybit (1.4 to 1.5 billion dollars, February 2025), Ronin Network (615 million), Coincheck (530 to 534 million), and Mt. Gox (450 million). Measured in today's prices instead, older Bitcoin-denominated thefts like Mt. Gox and Bitfinex would rank far higher.

The biggest crypto exchange hacks in history, ranked by the dollar value of assets stolen at the time of the theft, run from Bybit’s roughly 1.4 to 1.5 billion dollar loss in February 2025 down through Mt. Gox, Coincheck, and four other breaches that reshaped how exchanges handle custody. This page is our biggest crypto exchange hacks ranked history, cause, and resolution reference: one comparison table plus a section-by-section breakdown of what happened, why, and whether the exchange made users whole.

Methodology: Why “Biggest” Depends on Which Dollar You Use

Every hack below is ranked by the USD value of the stolen assets at the time of the theft, which is the standard convention used across most crypto-hack reporting. That choice matters more than it sounds. Mt. Gox lost 850,000 BTC in 2014, worth about 450 million dollars then but worth many times that at current Bitcoin prices. Bitfinex’s 120,000 BTC, stolen in 2016 for roughly 70 million dollars, would today be worth billions. If you ranked by today’s value instead of the theft-day value, both of those cases would jump toward the top of the list, and Bitfinex in particular would look nothing like a “smaller” hack. We’re flagging this explicitly rather than picking silently, because a lot of “biggest hack ever” claims quietly switch conventions mid-argument.

The Biggest Crypto Exchange Hacks, Ranked by Amount Stolen

Bar chart ranking the biggest crypto exchange hacks by dollar amount stolen: Bybit, Ronin Network, Coincheck, Mt. Gox, Bitget, DMM Bitcoin, KuCoin, and Bitfinex

RankExchangeDateAmount Stolen (at-the-time USD)Cause CategoryResolution Outcome
1BybitFeb 2025~$1.4–1.5B (ETH)UI/signer spoofing during multisig transferFully self-funded reimbursement, no user losses
2Ronin Network (bridge, not an exchange)Mar 2022~$615M (ETH + USDC)Validator compromise via social engineeringReimbursed over time via funding round
3CoincheckJan 2018~$530–534M (NEM)Hot wallet, single-signature (no multisig)Partial self-funded refund (~$430–443M), later acquired and relicensed
4Mt. GoxDiscovered Feb 2014~$450M (850,000 BTC)Undetected internal leakage since ~2011Bankruptcy; partial repayments still ongoing
5BitgetSept 2026~$351.6MSpoofed internal transaction authorizationCovered in full via User Protection Fund (per Bitget)
6DMM BitcoinMay 2024~$305M (4,502.9 BTC)Compromise linked to wallet-software partnerPaid users in full, then shut down the exchange
7KuCoinSept 2020~$275–285MHot wallet private key compromiseFully reimbursed via recovery efforts and insurance/funds
8BitfinexAug 2016~$70M (120,000 BTC)Multisig co-signing vulnerability with BitGoLoss socialized to all users via debt tokens

1. Bybit — The Largest Crypto Theft in History

Attackers reportedly compromised the UI and transaction-display layer used by Bybit’s cold-wallet signers during what looked like a routine multisig transfer, tricking legitimate signers into approving a transaction that appeared normal but actually redirected funds elsewhere. No private key was stolen; the signers approved something they didn’t realize they were approving. The theft has been attributed to the Lazarus Group, widely linked by investigators to North Korea. Bybit covered the entire loss from its own reserves and bridge financing, and users were made whole without any withdrawal freeze. The exchange has since pursued the stolen funds legally; we’ve covered that pursuit, including the asset-freeze efforts, in more depth in our reporting on Bybit’s lawsuit against North Korea’s Lazarus Group and the follow-up asset-freeze developments. Bybit’s own public statements on the incident are available on its official site.

2. Ronin Network — A Bridge Hack, Not an Exchange Hack

Worth noting up front: Ronin is Axie Infinity’s blockchain bridge, not a centralized exchange. We’re including it because it consistently ranks among the largest crypto thefts in any timeline of cryptocurrency exchange security breaches, and readers researching this topic expect to see it, but the category is genuinely different from the rest of this list. Five of nine validator nodes were reportedly compromised, allegedly through a fake job offer used to socially engineer an employee, in an attack again attributed to the Lazarus Group. Sky Mavis, Ronin’s parent company, raised a funding round and reimbursed affected users over time rather than issuing an immediate full payout.

3. Coincheck, A Hot Wallet Mistake

Coincheck held its NEM (XEM) holdings in a single-signature hot wallet instead of a more secure multi-sig cold storage custody setup, which by 2018 standards was already considered a basic security-architecture failure. The exchange voluntarily refunded users roughly 430 to 443 million dollars from its own corporate funds, a partial but still enormous self-funded reimbursement. Coincheck was later acquired by Monex Group and became a licensed, regulated exchange in Japan, making it one of the industry’s clearer turnaround stories.

4. Mt. Gox, The Original Cautionary Tale

Funds had reportedly been leaking from Mt. Gox since as early as 2011 through a mix of poor security controls and alleged mismanagement, not discovered until the exchange was already critically insolvent. Unlike every other exchange on this list, Mt. Gox went into bankruptcy rather than self-funding a reimbursement. Users have waited over a decade for partial repayment through the Mt. Gox civil rehabilitation creditor process, an exchange bankruptcy fund recovery process that was still distributing partial BTC and cash repayments as of 2024–2025. It remains the sharpest contrast on this list to Coincheck’s and Bybit’s self-funded approach.

5. Bitget, The Most Recent Major Breach

Bitget’s September 2026 incident involved a spoofed internal transaction-authorization exploit, mechanically distinct from the stolen keys and compromised validators seen elsewhere in this list. We covered the mechanism and immediate aftermath in detail separately; see our full breakdown of the Bitget hack rather than a repeat here. Bitget states its User Protection Fund, reported at roughly 5,500 BTC, covers the loss in full, and the exchange has continued operating.

6. DMM Bitcoin, Paid Users Back, Then Shut Down Anyway

Japanese and US authorities attributed the DMM Bitcoin theft to Lazarus Group / TraderTraitor-linked activity, with reporting pointing to a compromise connected to wallet-software partner Ginco rather than a direct breach of DMM’s own primary systems. DMM fully covered the loss from its own balance sheet at the time. But the financial strain proved lasting: DMM ultimately transferred its entire crypto business and customer accounts to SBI VC Trade and shut down the DMM Bitcoin brand by March 2025. It’s a useful nuance for anyone sizing exchange risk: paying users back in full doesn’t guarantee the company survives long term.

7. KuCoin, How a Hack Recovery Should Look

KuCoin’s hot wallet private keys were compromised, and blockchain-forensics work later implicated the Lazarus Group. What followed is widely cited as one of the better-handled recoveries in the industry: KuCoin coordinated with other major exchanges and blockchain-analysis firms to freeze and trace tainted funds, recovered a large share of the stolen assets, and used insurance and its own funds to reimburse remaining user losses in full, without an extended freeze on withdrawals.

8. Bitfinex, The Only Case Where Users Absorbed the Loss

A vulnerability in the multisig co-signing arrangement with security partner BitGo allowed unauthorized withdrawal approval. Rather than absorbing the loss as a company, Bitfinex distributed it proportionally across all user accounts, roughly an 8 to 9 percent haircut applied to every balance, via BFX debt tokens that were redeemed over subsequent years. This is the clearest case on the list where the theft-day-value ranking convention understates the real story: in February 2022, US federal authorities recovered and seized a large portion of the originally stolen bitcoin, by then worth billions due to price appreciation, in a widely covered prosecution of the individuals accused of laundering the funds.

What Happens When an Exchange Gets Hacked? Three Outcomes, Not One

Looking at all eight cases together, there are really three distinct outcomes, not one generic “the exchange gets hacked and users lose money” script. Bybit, Coincheck, KuCoin, and Bitget all self-funded a full or near-full reimbursement, drawing on reserves or a dedicated protection fund rather than passing the loss to depositors. Bitfinex is the outlier that socialized the loss across every account instead. And Mt. Gox, plus DMM Bitcoin’s eventual shutdown despite paying users back, show that self-funded compensation and long-term survival are two separate questions entirely. An exchange can make every user whole and still not make it as a business.

How Do You Check Whether an Exchange Can Survive a Hack?

None of this is meant as an alarmist takeaway. Hacks happen across the industry regardless of size or reputation, and the more useful exercise for a trader is evaluating how a given platform’s custody setup, protection fund, and disclosure practices compare before you deposit, not after. Our guide on how to check exchange security before depositing walks through the specific things worth verifying, and if you’re newer to this, the beginner learning path covers custody and account-security fundamentals from scratch. For traders weighing options with a clean incident-response track record to date, our BYDFi exchange review is worth a look, and BYDFi’s own site is at bydfi.com.

▶ How to Use Bank Transfer (App) | BYDFi Tutorial · BYDFi Official (YouTube)

Frequently asked questions

How do I verify if a crypto exchange is secure and regulated in 2026?

Check for published proof-of-reserves audits, a licensed operating entity in a named jurisdiction, and a public incident-response history rather than marketing claims alone. Our guide on how to check exchange security before depositing walks through the specific documents and disclosures worth looking for. Regulatory status and self-reported audits are not the same thing, so verify both separately.

What security measures do crypto exchanges use to protect customer funds?

Most large exchanges combine multi-signature cold storage for the bulk of reserves, a smaller hot wallet for daily withdrawals, and internal transaction-approval workflows requiring multiple signers. Some also maintain insurance or protection funds funded from company revenue. The hacks in this article show that the weak point is usually the human approval process around these systems, not the cryptography itself.

What happens to my funds if a crypto exchange gets hacked?

It depends entirely on whether the exchange can absorb the loss. In several cases covered here, including Bybit, Coincheck, and KuCoin, the exchange reimbursed users from its own funds. In Mt. Gox's case, the exchange instead entered bankruptcy, and creditors are still receiving partial repayments more than a decade later through Japan's civil rehabilitation process.

Which major crypto exchanges have experienced security breaches and what was the outcome?

Bybit, Coincheck, Mt. Gox, DMM Bitcoin, KuCoin, Bitfinex, and Bitget have all suffered breaches ranked among the largest in industry history, alongside the Ronin Network bridge hack. Outcomes ranged from full self-funded reimbursement to bankruptcy to losses spread across all user accounts. The full comparison table below breaks down cause and resolution for each one.

What insurance or protection do crypto exchanges offer against hacks and theft?

Some exchanges maintain a dedicated protection or insurance fund built from trading fee revenue, which can be used to cover user losses without needing outside funding. Bitget has pointed to its User Protection Fund as the source covering its 2026 incident in full. Not every exchange discloses the size or terms of such a fund publicly, so it is worth confirming before assuming coverage exists.

How do exchanges implement KYC compliance and custody security standards?

KYC verification and custody security are handled separately: KYC confirms who is trading, while custody standards like multi-sig cold storage protect where the assets sit. Some platforms position themselves around lighter KYC requirements, which is a separate question from how well they secure reserves. Our roundup of no-KYC exchanges covers that trade-off in more depth.

Which crypto exchange hack was the biggest in history?

By dollar value at the time of the theft, the Bybit hack in February 2025 is the largest, at roughly 1.4 to 1.5 billion dollars in stolen ETH. If you instead value older thefts like Mt. Gox's 850,000 BTC at today's Bitcoin price, that ranking changes dramatically, which is why the convention used matters.

Is Mt. Gox still paying back creditors as of 2026?

Yes. The Mt. Gox civil rehabilitation process has been distributing partial BTC and cash repayments to creditors, with distributions continuing into 2024 and 2025 more than a decade after the 2014 collapse. It remains the clearest example in this list of what happens when an exchange cannot cover a loss itself.

Dana Kovac — Covers trading tools, bots and market structure. Spent four years on a prop trading desk before going independent.