PROOFOFCUSTODY
Scores
Incidents
Learn
About
Get the Report
PROOFOFCUSTODY

The independent scoring system for Bitcoin custody. Every platform scored and ranked.

$1B+ in assets under custody expertise

No spam. Unsubscribe anytime.

PLATFORM SCORES
All ScoresCompareMethodologyIndependence StandardDataCustody Assessment
LEARN
Bitcoin 101Custody GuidesCustody InsuranceIs Your Setup Safe?Custody TimelineIncidentsFAQQuiz
COMPANY
AboutAuthorsEditorial IndependenceChangelogCorrections
RESOURCES
PodcastPressReport
CONNECT
Twitter / XLinkedInYouTubehello@proofofcustody.io
2026 Proof of Custody. Published by Onramp Bitcoin. Editorial Independence.PrivacyTermsproofofcustody.io
Registry

Bitcoin custody incident registry

A dated record of 17 major custody failures, the architecture that allowed each one, and what it should change about how holders evaluate custody. Nearly every entry was preventable by structure rather than by vigilance, which is the point of keeping the list.

This is the reference view. For the same record told as a history, grouped into eras, see the timeline.

Coldcard entropy failure

Hardware wallet
July 20261,596 BTC confirmed

A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator seeded from guessable values. Keys generated on affected firmware can be reconstructed offline. The defect shipped in March 2021 and sat in public source for roughly five years. Every model proved affected: Coinkite estimates roughly 40 bits of entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128.

What it should changeSelf-custody has a concentration problem too. Multisig wallets built from several units of one device shared a single firmware and a single entropy path, so one defect reached every key at once.

Full incident record→

Upbit

Exchange
November 2025~$33 to 37M

A hot-wallet breach produced unauthorised withdrawals across several tokens.

What it should changeReserves and insurance made customers whole, which is the system working. Neither prevented the theft, which is the distinction between compensation and prevention.

Full incident record→

CoinDCX

Exchange
July 2025~$44M

Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody.

What it should changeSegregation worked exactly as intended and contained the blast radius. The lost funds also sat outside the scope of any reserve attestation, which is worth understanding about what attestations cover.

Full incident record→

BigONE

Exchange
July 2025~$27M

A supply-chain compromise of production infrastructure altered withdrawal-approval logic. No private keys were stolen; the system approved fraudulent withdrawals itself.

What it should changeControlling what gets signed is sufficient. Key custody is not the only control that matters.

Full incident record→

Bybit

Exchange
February 2025~$1.4 to 1.5B

Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen.

What it should changeA proof-of-reserves attestation published days earlier was accurate and irrelevant. It described what was held, not whether the signing workflow could be subverted.

Full incident record→

WazirX

Exchange
July 2024~$230M

Signers on a custody-provider multisig were deceived, partly through a spoofed interface, into approving a malicious contract upgrade.

What it should changeWhen every signer approves through the same interface, that interface is a single point of failure no matter how many keys exist.

Full incident record→

DMM Bitcoin

Exchange
May 20244,502.9 BTC

An employee at the exchange's wallet-infrastructure provider was social-engineered, and stolen session credentials were used to manipulate a legitimate transaction request.

What it should changeYour custody is only as strong as every vendor in the signing path, including the ones you have never heard of.

Full incident record→

Prime Trust

Custodian
2023Customer shortfall

A regulated trust company that provided custody rails to multiple platforms lost access to wallets and covered customer withdrawals using other customers' assets before filing for bankruptcy.

What it should changeQualified custodian is a regulatory status, not a verified security architecture. The licence does not confirm that the keys were competently managed.

Full incident record→

Luke Dashjr

Self-custody
January 2023~200 BTC reported

The holder reported that his PGP key was compromised and that bitcoin was taken from systems under his control.

What it should changeDeep technical expertise is not a custody architecture. If one machine's compromise can reach the keys, the setup has one failure domain regardless of who is operating it.

Full incident record→

BlockFi

Lender
November 2022Hundreds of millions

Lending exposure to a failed fund and to FTX, compounded when a rescue facility from FTX defaulted as FTX itself collapsed.

What it should changeCounterparty exposure is invisible in any asset-side disclosure. What a platform holds tells you nothing about what it is owed by parties who cannot pay.

Full incident record→

FTX

Exchange
November 2022~$8B customer shortfall

Customer assets were commingled with an affiliated trading firm. The exchange had been audited, and the audits did not test segregation or liabilities under stress.

What it should changeAn audit is not a custody control. Segregation and legal title determine what a customer actually owns when the entity fails.

Full incident record→

Voyager Digital

Lender
July 2022Hundreds of millions

Marketed as FDIC-insured, which regulators subsequently ordered corrected. Customer USD sat at a partner bank while customers were creditors of Voyager, and lending exposure to a failed fund drove the insolvency.

What it should changeInsurance language is frequently misunderstood and sometimes misused. Verify precisely what is covered, against which event, and for whose benefit.

Full incident record→

Celsius

Lender
June 2022~$4.7B owed to customers

Withdrawals were halted and the company filed for bankruptcy. The court found that the terms of service transferred title of deposited assets to Celsius, making depositors unsecured creditors of the estate.

What it should changeCustody is a legal arrangement before it is a technical one. Read what the terms do to legal title, because a yield rate is priced in the risk you did not read.

Full incident record→

Ledger customer database breach

Vendor data
July 2020No direct bitcoin loss

An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived.

What it should changeBuying a hardware wallet is a disclosure that you hold bitcoin. Those records still drive targeted phishing and physical-coercion attempts six years later, and no firmware update can fix a leak of who you are and where you live.

Full incident record→

QuadrigaCX

Exchange
December 2018~C$215M owed

The founder died holding sole control of the cold-wallet keys. Investigation established there was also no meaningful accounting or segregation, and that the platform had operated as a Ponzi scheme.

What it should changeA custody arrangement only one person can operate fails completely when that person is unavailable. Death is not a risk, it is a certainty with unknown timing.

Full incident record→

Bitfinex

Exchange
August 2016119,756 BTC

A 2-of-3 multisig arrangement with a third-party co-signer, where the exchange held two of the keys. Attackers compromised admin API credentials, lifted withdrawal limits, and executed over 2,000 unauthorised transactions.

What it should changeMultisig where one party holds a majority of the keys is not distributed control. The key count was three; the failure domain was one.

Full incident record→

Mt. Gox

Exchange
2011 to 2014~650,000 to 850,000 BTC

Hot-wallet keys were copied in 2011 and theft continued undetected for years against commingled customer assets. The exchange's 2011 on-chain solvency demonstration proved control of coins that were already being drained.

What it should changeA point-in-time proof that coins exist says nothing about who controls them next week. This is the founding case for why attestation is not safekeeping.

Full incident record→

The pattern

Read the registry as a whole and the same shape repeats. In almost every case, one party could act alone: one company controlled the keys, one interface decided what got signed, one firmware generated every seed, or one set of terms determined who owned the assets. The losses were not failures of vigilance. They were failures of structure.

That is what the Custody Independence Standard tests for, and why our scoring weights custody architecture above every other dimension.

How to cite
Proof of Custody, Bitcoin Custody Incident Registry, proofofcustody.io/incidents