{"@context":"https://schema.org","@type":"Dataset","name":"Proof of Custody — Bitcoin custody failure registry","description":"Dated bitcoin custody failures, each recorded with the custody configurations the failure class could reach, the reported loss and the named source. Self-custody failures are included on the same terms as custodial ones.","url":"https://proofofcustody.io/data/custody-incidents.json","creator":{"@type":"Organization","name":"Proof of Custody","url":"https://proofofcustody.io"},"license":"https://creativecommons.org/licenses/by/4.0/","isAccessibleForFree":true,"inLanguage":"en","dateModified":"2026-09-23T03:54:21.629Z","citation":"Proof of Custody, Bitcoin custody failure registry, https://proofofcustody.io/incidents","editorialIndependence":"https://proofofcustody.io/editorial-independence","publisherDisclosure":"Proof of Custody is published by Onramp Bitcoin. Onramp is scored and recorded by the same methodology as every other platform.","readMe":{"loss":"Loss figures are as reported by the named source. Proof of Custody has not independently reproduced on-chain analysis.","exposedConfigs":"Describes which custody configurations this class of event could reach. It is a failure class, never an accusation about an individual platform.","coverage":"Selected, not exhaustive. Absence from this registry is not evidence that a platform is safe."},"eras":[{"id":"exchange-era","name":"The Exchange Era","range":"2011 to 2016","thesis":"Almost nobody held their own keys. Exchanges were the only usable interface, and the losses were simply the cost of that convenience. The lesson people drew, not your keys not your coins, was correct and incomplete."},{"id":"custodial-boom","name":"The Custodial Boom","range":"2017 to 2021","thesis":"Self-custody hardware went mainstream and a new failure surface arrived with it. The threats stopped being only about who held the keys and started being about who knew you held them."},{"id":"great-unwind","name":"The Great Unwind","range":"2022 to 2023","thesis":"Yield products and regulated wrappers failed in sequence. These were not anonymous offshore exchanges but audited, licensed, household-name institutions, and the losses turned on legal title and segregation rather than on cryptography."},{"id":"infrastructure-era","name":"The Infrastructure Era","range":"2024 to 2026","thesis":"Attackers stopped breaking cryptography and started breaking the operators, the interfaces, and the build pipelines. Then a firmware defect showed that self-custody had a concentration problem of its own."}],"configLabels":{"exchange":"Bitcoin left on an exchange","lender":"Bitcoin lent or earning yield","custodian":"Single qualified custodian","single-sig":"Self-custody, single signature","multisig-one-vendor":"Multisig, devices from one vendor","multisig-multi-vendor":"Multisig, devices from several vendors","collaborative":"Collaborative custody","multi-institution":"Multi-institution custody"},"categoryLabels":{"exchange":"Exchange","lender":"Lender","custodian":"Custodian","hardware":"Hardware wallet","self-custody":"Self-custody","vendor-data":"Vendor data"},"incidents":[{"slug":"mt-gox-2014","name":"Mt. Gox","date":"2011 to 2014","sortDate":"2014-02-01","era":"exchange-era","category":"exchange","loss":"~650,000 to 850,000 BTC","lossNote":"Approximately 850,000 BTC missing at bankruptcy; analysts attribute roughly 650,000 to progressive theft.","rootCause":"Hot-wallet keys were copied in 2011 and theft continued undetected for years against commingled customer assets. The exchange's 2011 on-chain solvency demonstration proved control of coins that were already being drained.","lesson":"A point-in-time proof that coins exist says nothing about who controls them next week. This is the founding case for why attestation is not safekeeping.","exposedConfigs":["exchange"],"sources":"WizSec investigation, bankruptcy filings"},{"slug":"bitfinex-2016","name":"Bitfinex","date":"August 2016","sortDate":"2016-08-02","era":"exchange-era","category":"exchange","loss":"119,756 BTC","lossNote":"~$72M at the time; multi-billion at later valuations.","rootCause":"A 2-of-3 multisig arrangement with a third-party co-signer, where the exchange held two of the keys. Attackers compromised admin API credentials, lifted withdrawal limits, and executed over 2,000 unauthorised transactions.","lesson":"Multisig where one party holds a majority of the keys is not distributed control. The key count was three; the failure domain was one.","exposedConfigs":["exchange"],"sources":"DOJ filings, Ledger Labs / OCCRP reporting"},{"slug":"quadrigacx-2018","name":"QuadrigaCX","date":"December 2018","sortDate":"2018-12-09","era":"custodial-boom","category":"exchange","loss":"~C$215M owed","lossNote":"Ontario Securities Commission later found a C$169M shortfall, most of it attributable to the founder's trading.","rootCause":"The founder died holding sole control of the cold-wallet keys. Investigation established there was also no meaningful accounting or segregation, and that the platform had operated as a Ponzi scheme.","lesson":"A custody arrangement only one person can operate fails completely when that person is unavailable. Death is not a risk, it is a certainty with unknown timing.","exposedConfigs":["exchange"],"sources":"Ontario Securities Commission report, CCAA filings"},{"slug":"ledger-data-breach-2020","name":"Ledger customer database breach","date":"July 2020","sortDate":"2020-07-01","era":"custodial-boom","category":"vendor-data","loss":"No direct bitcoin loss","lossNote":"~1M email addresses and roughly 272,000 detailed records including names, physical addresses and phone numbers.","rootCause":"An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived.","lesson":"Buying a hardware wallet is a disclosure that you hold bitcoin. Those records still drive targeted phishing and physical-coercion attempts six years later, and no firmware update can fix a leak of who you are and where you live.","exposedConfigs":["single-sig","multisig-one-vendor","multisig-multi-vendor","collaborative"],"sources":"Vendor incident disclosures, published breach data"},{"slug":"celsius-2022","name":"Celsius","date":"June 2022","sortDate":"2022-06-12","era":"great-unwind","category":"lender","loss":"~$4.7B owed to customers","rootCause":"Withdrawals were halted and the company filed for bankruptcy. The court found that the terms of service transferred title of deposited assets to Celsius, making depositors unsecured creditors of the estate.","lesson":"Custody is a legal arrangement before it is a technical one. Read what the terms do to legal title, because a yield rate is priced in the risk you did not read.","exposedConfigs":["lender"],"sources":"Chapter 11 filings, court rulings"},{"slug":"voyager-2022","name":"Voyager Digital","date":"July 2022","sortDate":"2022-07-05","era":"great-unwind","category":"lender","loss":"Hundreds of millions","rootCause":"Marketed as FDIC-insured, which regulators subsequently ordered corrected. Customer USD sat at a partner bank while customers were creditors of Voyager, and lending exposure to a failed fund drove the insolvency.","lesson":"Insurance language is frequently misunderstood and sometimes misused. Verify precisely what is covered, against which event, and for whose benefit.","exposedConfigs":["lender","exchange"],"sources":"FDIC and Federal Reserve joint statement, Chapter 11 filings"},{"slug":"ftx-2022","name":"FTX","date":"November 2022","sortDate":"2022-11-11","era":"great-unwind","category":"exchange","loss":"~$8B customer shortfall","lossNote":"The estate later disclosed the exchange held a small fraction of the bitcoin customers believed it held.","rootCause":"Customer assets were commingled with an affiliated trading firm. The exchange had been audited, and the audits did not test segregation or liabilities under stress.","lesson":"An audit is not a custody control. Segregation and legal title determine what a customer actually owns when the entity fails.","exposedConfigs":["exchange","lender"],"sources":"Chapter 11 filings, CFTC complaint"},{"slug":"blockfi-2022","name":"BlockFi","date":"November 2022","sortDate":"2022-11-28","era":"great-unwind","category":"lender","loss":"Hundreds of millions","rootCause":"Lending exposure to a failed fund and to FTX, compounded when a rescue facility from FTX defaulted as FTX itself collapsed.","lesson":"Counterparty exposure is invisible in any asset-side disclosure. What a platform holds tells you nothing about what it is owed by parties who cannot pay.","exposedConfigs":["lender"],"sources":"Chapter 11 filings"},{"slug":"luke-dashjr-2023","name":"Luke Dashjr","date":"January 2023","sortDate":"2023-01-01","era":"great-unwind","category":"self-custody","loss":"~200 BTC reported","lossNote":"Self-reported by the holder, a long-standing Bitcoin Core contributor. The precise compromise vector remains disputed publicly.","rootCause":"The holder reported that his PGP key was compromised and that bitcoin was taken from systems under his control.","lesson":"Deep technical expertise is not a custody architecture. If one machine's compromise can reach the keys, the setup has one failure domain regardless of who is operating it.","exposedConfigs":["single-sig"],"sources":"Holder's public statements"},{"slug":"prime-trust-2023","name":"Prime Trust","date":"2023","sortDate":"2023-08-01","era":"great-unwind","category":"custodian","loss":"Customer shortfall","rootCause":"A regulated trust company that provided custody rails to multiple platforms lost access to wallets and covered customer withdrawals using other customers' assets before filing for bankruptcy.","lesson":"Qualified custodian is a regulatory status, not a verified security architecture. The licence does not confirm that the keys were competently managed.","exposedConfigs":["custodian","exchange"],"sources":"Nevada regulator filings, Chapter 11 filings"},{"slug":"dmm-bitcoin-2024","name":"DMM Bitcoin","date":"May 2024","sortDate":"2024-05-31","era":"infrastructure-era","category":"exchange","loss":"4,502.9 BTC","lossNote":"~$305 to 308M. The exchange subsequently wound down.","rootCause":"An employee at the exchange's wallet-infrastructure provider was social-engineered, and stolen session credentials were used to manipulate a legitimate transaction request.","lesson":"Your custody is only as strong as every vendor in the signing path, including the ones you have never heard of.","exposedConfigs":["exchange"],"sources":"FBI, DC3 and Japan NPA joint advisory"},{"slug":"wazirx-2024","name":"WazirX","date":"July 2024","sortDate":"2024-07-18","era":"infrastructure-era","category":"exchange","loss":"~$230M","lossNote":"Roughly 45% of the reserves attested a month earlier.","rootCause":"Signers on a custody-provider multisig were deceived, partly through a spoofed interface, into approving a malicious contract upgrade.","lesson":"When every signer approves through the same interface, that interface is a single point of failure no matter how many keys exist.","exposedConfigs":["exchange"],"sources":"Exchange and custody-provider post-mortems"},{"slug":"bybit-2025","name":"Bybit","date":"February 2025","sortDate":"2025-02-21","era":"infrastructure-era","category":"exchange","loss":"~$1.4 to 1.5B","lossNote":"The largest single crypto theft on record at the time.","rootCause":"Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen.","lesson":"A proof-of-reserves attestation published days earlier was accurate and irrelevant. It described what was held, not whether the signing workflow could be subverted.","exposedConfigs":["exchange"],"sources":"FBI advisory, exchange post-mortem, NCC Group analysis"},{"slug":"bigone-2025","name":"BigONE","date":"July 2025","sortDate":"2025-07-16","era":"infrastructure-era","category":"exchange","loss":"~$27M","rootCause":"A supply-chain compromise of production infrastructure altered withdrawal-approval logic. No private keys were stolen; the system approved fraudulent withdrawals itself.","lesson":"Controlling what gets signed is sufficient. Key custody is not the only control that matters.","exposedConfigs":["exchange"],"sources":"Exchange disclosure, third-party incident analysis"},{"slug":"coindcx-2025","name":"CoinDCX","date":"July 2025","sortDate":"2025-07-19","era":"infrastructure-era","category":"exchange","loss":"~$44M","lossNote":"Customer funds were unaffected. The exchange absorbed the loss from its own treasury.","rootCause":"Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody.","lesson":"Segregation worked exactly as intended and contained the blast radius. The lost funds also sat outside the scope of any reserve attestation, which is worth understanding about what attestations cover.","exposedConfigs":["exchange"],"sources":"Exchange incident report"},{"slug":"upbit-2025","name":"Upbit","date":"November 2025","sortDate":"2025-11-27","era":"infrastructure-era","category":"exchange","loss":"~$33 to 37M","lossNote":"Customers were fully reimbursed from reserves and insurance.","rootCause":"A hot-wallet breach produced unauthorised withdrawals across several tokens.","lesson":"Reserves and insurance made customers whole, which is the system working. Neither prevented the theft, which is the distinction between compensation and prevention.","exposedConfigs":["exchange"],"sources":"Exchange disclosure, Korean regulatory reporting"},{"slug":"coldcard-entropy-2026","name":"Coldcard entropy failure","date":"July 2026","sortDate":"2026-07-30","era":"infrastructure-era","category":"hardware","loss":"1,789 BTC confirmed","lossNote":"Galaxy Research puts high-confidence losses at 1,789.28 BTC, about $114.7M at the prices when the coins moved, from 8,865 addresses, held with high confidence on 221 victim reports and on-chain analysis. Roughly 1,824 BTC including medium-confidence cases. On September 21, 2026, white-hat operators moved 52.37 BTC into an address presented as a recovery trust; the claims process is unpublished.","rootCause":"A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator seeded from guessable values. Keys generated on affected firmware can be reconstructed offline. The defect shipped in March 2021 and sat in public source for roughly five years. Every model proved affected: Coinkite estimates roughly 40 bits of entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128.","lesson":"Self-custody has a concentration problem too. Multisig wallets built from several units of one device shared a single firmware and a single entropy path, so one defect reached every key at once.","exposedConfigs":["single-sig","multisig-one-vendor"],"sources":"Block engineering analysis, Coinkite advisory. Sources disagree on current models."}],"liveIncidents":[{"slug":"coldcard-entropy-2026","title":"Coldcard entropy failure","status":"Developing","firstReported":"2026-07-29","updatedAt":"2026-09-23T03:00:00.000Z","summary":"A firmware defect caused affected Coldcard hardware wallets to skip their hardware random number generator and fall back to a predictable software generator. Keys generated on affected firmware can be reconstructed offline. Coinkite's advisory, updated August 1, confirms every model is affected: Mk2 and Mk3 at roughly 40 bits of effective entropy and Mk4, Q and Mk5 at roughly 72 bits, against an intended 128. Galaxy Research's latest tally puts high-confidence losses at 1,789.28 BTC from 8,865 addresses, about $114.7M at the prices when the coins moved, rising to roughly 1,824 BTC once medium-confidence cases are included. On September 21 white-hat operators moved 52.37 BTC, about 3% of the total, into an address presented as a recovery trust. The exploit remains active.","url":"https://proofofcustody.io/incidents/coldcard-entropy-2026","keyFacts":[{"label":"Root cause","value":"A check tested whether a configuration setting existed rather than whether it was enabled. The check passed, the hardware random number generator was bypassed, and the firmware fell back to a software generator seeded from guessable values. On newer models a secure-element reseed exists but retains only four bytes. Coinkite added on August 4 that the defect sat at a boundary between two unrelated submodules, \"not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews\", and that because the flag check looked correct it went unnoticed while its impact grew with every release. Its own disclosure record attributes the random-byte fallback to a library migration.","source":"Block engineering analysis, Coinkite technical backgrounder and Aug 4 update"},{"label":"Every model is affected, at different magnitudes","value":"Coinkite's advisory, updated August 1, states that seeds generated on Mk4, Q and Mk5 before the fixed releases are also affected, with about 72 bits of entropy rather than the expected 128. Mk2 and Mk3 are estimated at about 40 bits. Block quantifies the newer-model weakness differently, reporting that the reseed contributes at most 32 bits. Both agree on scope; they differ on magnitude.","source":"Coinkite advisory (updated Aug 1), Block engineering (Jul 30)"},{"label":"When it shipped","value":"The affected range begins at firmware v4.0.1, released March 2021, and the defect remained in publicly readable open-source code for roughly five years.","source":"Coinkite advisory, Block engineering analysis"},{"label":"Confirmed losses","value":"Galaxy Research's August 24 update puts high-confidence losses at 1,789.28 BTC across 8,865 addresses, about $114.7M at the prices when the coins moved. 221 victims have come forward reporting 790.72 BTC between them. Read \"confirmed\" as one firm's assessment corroborated by victim reports, not as audited or adjudicated: 221 reports anchor a pattern across 8,865 addresses rather than validating each one. Earlier snapshots of roughly 1,367 BTC, 1,596 BTC and 1,816 BTC were accurate when published and are superseded.","source":"Alex Thorn, Galaxy Research, Aug 24, via The Crypto Times"},{"label":"Medium-confidence cases on top of the headline figure","value":"Including medium-confidence cases takes the total to roughly 1,824 BTC, about $140M at the prices when the coins moved. Galaxy keeps these outside its headline number because no victim has confirmed them. An earlier projection of about 2,055 BTC for a suspected fourth wave does not appear in Galaxy's August 24 update; treat it as superseded by the tally above rather than as a separate outstanding claim. The exploit remains active.","source":"Alex Thorn, Galaxy Research, Aug 24, via The Crypto Times"},{"label":"Almost none of the stolen bitcoin has moved","value":"Galaxy reports that roughly 90% of the stolen coins remain unmoved, including all of the coins taken in waves one to three. Galaxy offers two readings: the operator is waiting for scrutiny to fade, or has no viable way to launder a sum this visible. Separately, on-chain analyst Willy Woo puts the odds of partial recovery at 20 to 40%, likely taking years.","source":"Galaxy Research via The Block; Willy Woo via news.bitcoin.com"},{"label":"A small share has been recovered, into a trust nobody can yet reach","value":"On September 21, 2026, white-hat operators swept 52.37 BTC out of attacker-controlled addresses before the attacker could move it, including 40.71 BTC, about $3.31M, in a single transaction confirmed in block 967,948. Proof of Custody verified that block exists and was mined at 05:45 UTC on September 21; we have not independently traced the coins. The destination is presented as the Crypto Recovery Trust, described in Galaxy's account as a Wyoming statutory trust, and the transaction carries an OP_RETURN reading \"claim:cryptorecoverytrust dot com\". How an owner proves title, on what deadline, and at what cost are not stated on-chain, and cryptorecoverytrust.com returned a server error each time we checked it on September 22 and 23. This is roughly 3% of the stolen total. Treat it as a reported recovery, not as funds returned.","source":"Alex Thorn, Galaxy Research, Sept 21; CoinDesk and Decrypt, Sept 22; block 967,948 checked against mempool.space"},{"label":"Fourth-wave transactions signal replace-by-fee","value":"Unlike the earlier waves, sweeps in the suspected fourth wave signal replace-by-fee. A holder who sees their own address being swept in the mempool has a short window to broadcast a competing transaction at a higher fee and move the funds first. This is a narrow escape hatch, not a defence, and it only helps someone already watching.","source":"Galaxy Research via CoinDesk, Aug 3"},{"label":"AI-assisted code review did not catch it","value":"Coinkite states it ran AI-assisted review against its critical codebases in the weeks before the exploit and that it \"did not catch this vulnerability\". After the incident it re-tested against frontier models, naming Kimi K3, Claude Fable and Codex 5.6, and reports that none of them caught it either. Its own disclosure record logs an enterprise AI firmware review on June 26, 2026, roughly a month before the theft began, that produced 85 candidate findings without surfacing this one. Coinkite recommends that teams relying on AI review of security-critical code test it specifically against build and submodule boundaries. This is the vendor's own account of its process and Proof of Custody has not verified it, but it is a rare public data point on where automated review currently fails: at the seams between components rather than inside the cryptography.","source":"Coinkite, Adding to the Public Record, Aug 4; Coinkite historical disclosures"},{"label":"Coinkite has published a historical disclosure record","value":"Alongside the August 4 update Coinkite published a page recording known public security research, coordinated disclosures, professional audits, internal findings and advisories affecting Coldcard devices: 23 events from 2019 to August 2026, of which 12 show public evidence of coordinated disclosure. It is vendor-maintained and therefore self-selected, but it is a real primary artifact and more than most hardware vendors publish. We are treating it as a research source rather than as an independent audit.","source":"coinkite.com/historical-disclosures, published Aug 4"},{"label":"Patched firmware does not repair an existing seed","value":"Coinkite states that the patched firmware prevents the issue for newly generated seeds and does not repair or restore security to a seed already generated on vulnerable firmware. Affected holders must generate a new seed on fixed firmware and move funds to it.","source":"Coinkite update, Aug 2"},{"label":"Dice-generated seeds are the documented exception","value":"Coinkite states that funds are at risk if the seed was created without at least 50 independent, private dice rolls and the wallet is not protected by a strong, unique BIP-39 passphrase. Fifty fair rolls contribute at least 128 bits on their own, which is why that path is treated differently.","source":"Coinkite advisory (updated Aug 1)"},{"label":"Vendor response","value":"Coinkite destroyed its remaining inventory manufactured with the vulnerable firmware and halted shipment when the vulnerability was confirmed. It states that its legal team will coordinate as warranted with law enforcement across multiple jurisdictions, which is a conditional commitment rather than confirmation of an active investigation. Galaxy Research has referred roughly 600 suspected attacker addresses to US federal investigators, exchanges and compliance firms; no indictment, seizure or agency statement has followed. It has also pointed users to alternative devices while they decide next steps, naming Bitkey, Ledger, Trezor, Jade and BitBox. Bitkey is made by Block, the company that published the competing engineering analysis.","source":"Coinkite update, Aug 2"}],"openQuestions":["Magnitude on current models. Coinkite estimates about 72 bits of effective search space for Mk4, Q and Mk5; Block reports the secure-element reseed contributes at most 32 bits. Neither has publicly reconciled the difference.","Block has flagged a fail-open boot path in which an exception before the reseed executes would leave the device at a known public state with no added entropy, and says this should be treated separately from the proven 32-bit weakness. Coinkite's advisory does not address it.","Block's analysis still carries only its July 30 date and has not been updated to reflect Coinkite's August 1 advisory.","Whether the Crypto Recovery Trust is reachable and how a victim claims. The trust is named only in an on-chain message and in Galaxy's account of it; its website did not respond when we checked, and no trustee, law firm, deadline or fee schedule has been published. Until that exists, the 52.37 BTC is out of the attacker's reach rather than back with its owners.","The disclosure timeline is still unpublished. Coinkite has not stated when it first learned of the defect, when it confirmed it, or how long it held the finding before warning users. Its August 4 update defers this to a post-mortem, citing the active investigation. Critics have alleged a delay of days; no primary source establishes the timeline either way, so we record the gap rather than the allegation.","No reimbursement, compensation or insurance position has been stated. Coinkite says it is supporting affected customers directly, which is not the same as a remediation commitment."]}]}