PROOFOFCUSTODY
Scores
Incidents
Learn
About
Get the Report
PROOFOFCUSTODY

The independent scoring system for Bitcoin custody. Every platform scored and ranked.

$1B+ in assets under custody expertise

No spam. Unsubscribe anytime.

PLATFORM SCORES
All ScoresCompareMethodologyIndependence StandardDataCustody Assessment
LEARN
Bitcoin 101Custody GuidesCustody InsuranceIs Your Setup Safe?Custody TimelineIncidentsFAQQuiz
COMPANY
AboutAuthorsEditorial IndependenceChangelogCorrections
RESOURCES
PodcastPressReport
CONNECT
Twitter / XLinkedInYouTubehello@proofofcustody.io
2026 Proof of Custody. Published by Onramp Bitcoin. Editorial Independence.PrivacyTermsproofofcustody.io
Timeline

Fifteen years of losing bitcoin

Every custody model in use today exists because the one before it failed. This is that record: 17 major failures from Mt. Gox to the 2026 entropy defect, what caused each one, and what it should have changed about how people hold bitcoin.

It includes the self-custody side. A registry that records only exchange collapses is an argument for custodians rather than an honest history, and the most recent entry is a hardware wallet.

By Steve L, Editorial Lead·Reviewed by Proof of Custody Editorial
Published Jul 31, 2026
17
Recorded failures
15
Years covered
4
Distinct eras
1
Common root cause

That common root cause: in nearly every entry below, one party could act alone. One company held the keys, one interface decided what got signed, one firmware generated every seed, or one set of terms decided who owned the assets.

17 / 17
2011 to 2016

The Exchange Era

Almost nobody held their own keys. Exchanges were the only usable interface, and the losses were simply the cost of that convenience. The lesson people drew, not your keys not your coins, was correct and incomplete.

Mt. GoxExchange
2011 to 2014~650,000 to 850,000 BTC

Hot-wallet keys were copied in 2011 and theft continued undetected for years against commingled customer assets. The exchange's 2011 on-chain solvency demonstration proved control of coins that were already being drained.

What it changed→
BitfinexExchange
August 2016119,756 BTC

A 2-of-3 multisig arrangement with a third-party co-signer, where the exchange held two of the keys. Attackers compromised admin API credentials, lifted withdrawal limits, and executed over 2,000 unauthorised transactions.

What it changed→
2017 to 2021

The Custodial Boom

Self-custody hardware went mainstream and a new failure surface arrived with it. The threats stopped being only about who held the keys and started being about who knew you held them.

QuadrigaCXExchange
December 2018~C$215M owed

The founder died holding sole control of the cold-wallet keys. Investigation established there was also no meaningful accounting or segregation, and that the platform had operated as a Ponzi scheme.

What it changed→
Ledger customer database breachVendor data
July 2020No direct bitcoin loss

An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived.

What it changed→
2022 to 2023

The Great Unwind

Yield products and regulated wrappers failed in sequence. These were not anonymous offshore exchanges but audited, licensed, household-name institutions, and the losses turned on legal title and segregation rather than on cryptography.

CelsiusLender
June 2022~$4.7B owed to customers

Withdrawals were halted and the company filed for bankruptcy. The court found that the terms of service transferred title of deposited assets to Celsius, making depositors unsecured creditors of the estate.

What it changed→
Voyager DigitalLender
July 2022Hundreds of millions

Marketed as FDIC-insured, which regulators subsequently ordered corrected. Customer USD sat at a partner bank while customers were creditors of Voyager, and lending exposure to a failed fund drove the insolvency.

What it changed→
FTXExchange
November 2022~$8B customer shortfall

Customer assets were commingled with an affiliated trading firm. The exchange had been audited, and the audits did not test segregation or liabilities under stress.

What it changed→
BlockFiLender
November 2022Hundreds of millions

Lending exposure to a failed fund and to FTX, compounded when a rescue facility from FTX defaulted as FTX itself collapsed.

What it changed→
Luke DashjrSelf-custody
January 2023~200 BTC reported

The holder reported that his PGP key was compromised and that bitcoin was taken from systems under his control.

What it changed→
Prime TrustCustodian
2023Customer shortfall

A regulated trust company that provided custody rails to multiple platforms lost access to wallets and covered customer withdrawals using other customers' assets before filing for bankruptcy.

What it changed→
2024 to 2026

The Infrastructure Era

Attackers stopped breaking cryptography and started breaking the operators, the interfaces, and the build pipelines. Then a firmware defect showed that self-custody had a concentration problem of its own.

DMM BitcoinExchange
May 20244,502.9 BTC

An employee at the exchange's wallet-infrastructure provider was social-engineered, and stolen session credentials were used to manipulate a legitimate transaction request.

What it changed→
WazirXExchange
July 2024~$230M

Signers on a custody-provider multisig were deceived, partly through a spoofed interface, into approving a malicious contract upgrade.

What it changed→
BybitExchange
February 2025~$1.4 to 1.5B

Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen.

What it changed→
BigONEExchange
July 2025~$27M

A supply-chain compromise of production infrastructure altered withdrawal-approval logic. No private keys were stolen; the system approved fraudulent withdrawals itself.

What it changed→
CoinDCXExchange
July 2025~$44M

Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody.

What it changed→
UpbitExchange
November 2025~$33 to 37M

A hot-wallet breach produced unauthorised withdrawals across several tokens.

What it changed→
Coldcard entropy failureHardware wallet
July 20261,596 BTC confirmed

A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator seeded from guessable values. Keys generated on affected firmware can be reconstructed offline. The defect shipped in March 2021 and sat in public source for roughly five years. Every model proved affected: Coinkite estimates roughly 40 bits of entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128.

What it changed→

What the record actually shows

Read chronologically, the failures look unrelated. An exchange collapse in 2014, a lender in 2022, a firmware defect in 2026. Read structurally, they are the same event repeating with different actors.

The first era taught the wrong lesson too well. Mt. Gox and Bitfinex produced “not your keys, not your coins,” which was correct. It was also incomplete, because it said nothing about what happens when the keys you hold are all generated by the same company, kept in the same place, or understood by only one person.

The middle era proved that regulation is not architecture. Celsius, FTX, and Prime Trust were licensed, audited, and in some cases household names. What failed was legal title and segregation, not cryptography. A clean audit and a custody licence tell you almost nothing about whether one party can move your bitcoin alone.

The current era moved the attack off the cryptography entirely. Bybit, BigONE, WazirX, and DMM were not broken mathematically. Attackers compromised the people, the interfaces, and the build pipelines around the keys. Then the Coldcard defect demonstrated that self-custody carries a concentration risk of exactly the same shape: a multisig wallet built from several units of one device has one firmware and one entropy path.

Independent failure domains

How many separate parties or systems must fail before the bitcoin is at risk. Devices are not domains. Keys that share a manufacturer, a firmware build, or an entropy path all fail together.

Single-sig hardware wallet1 device, 1 vendor
1
2-of-3 multisig, same vendor3 devices, 1 vendor
1
2-of-3 multisig, 3 vendors3 devices, 3 vendors, self-managed
2
Collaborative custodyholder keys + provider key
2
Single qualified custodian1 institution holds all keys
1
Multi-institution custody3 institutions, 2-of-3 quorum
2
Proof of Custody. Domain counts assume a 2-of-3 quorum and no address reuse.

The question that survives all fifteen years is not which product to buy. It is how many independent parties or systems have to fail before your bitcoin is gone, and who is responsible for keeping them independent once you stop paying attention.

We turned that into a published test with four questions you can apply to your own setup, including a setup we have never scored: the Custody Independence Standard. The longer walkthrough of what it means in practice, including why more dice rolls and more hardware wallets do not answer the question, is in Is your custody setup actually safe?

Assess your own setupIncident records
How to cite
Proof of Custody, Bitcoin Custody Failure Timeline, proofofcustody.io/timeline
Frequently asked questions
How much bitcoin has been lost to custody failures?+

Across the failures recorded here, reported losses run from hundreds of thousands of bitcoin at Mt. Gox to billions of dollars at FTX and Bybit. Figures are as reported by courts, regulators, and named on-chain researchers; Proof of Custody has not independently reproduced the on-chain analysis.

Is self-custody safer than using a custodian?+

The record does not support a simple answer. Custodial failures dominate by total value, but the 2026 Coldcard entropy defect and documented self-custody losses show that holding your own keys concentrates risk differently rather than removing it. What separates durable setups from fragile ones is how many independent parties or systems must fail, not who holds the keys.

What is the most common cause of bitcoin custody failure?+

One party being able to act alone. In nearly every recorded failure, a single company controlled the keys, a single interface decided what got signed, a single firmware generated every seed, or a single set of terms determined who legally owned the assets.

Why does this timeline include hardware wallets?+

Because a record that lists only exchange collapses is an argument for custodians rather than a history. Vendor data breaches that drive years of targeted phishing, and firmware defects that reach every key in a multisig at once, are custody failures with the same structure as an exchange losing customer funds.

Full list of recorded bitcoin custody failures

The Exchange Era (2011 to 2016)

Almost nobody held their own keys. Exchanges were the only usable interface, and the losses were simply the cost of that convenience. The lesson people drew, not your keys not your coins, was correct and incomplete.

  • Mt. Gox (2011 to 2014, Exchange, ~650,000 to 850,000 BTC). Hot-wallet keys were copied in 2011 and theft continued undetected for years against commingled customer assets. The exchange's 2011 on-chain solvency demonstration proved control of coins that were already being drained. What it should change: A point-in-time proof that coins exist says nothing about who controls them next week. This is the founding case for why attestation is not safekeeping. Sources: WizSec investigation, bankruptcy filings
  • Bitfinex (August 2016, Exchange, 119,756 BTC). A 2-of-3 multisig arrangement with a third-party co-signer, where the exchange held two of the keys. Attackers compromised admin API credentials, lifted withdrawal limits, and executed over 2,000 unauthorised transactions. What it should change: Multisig where one party holds a majority of the keys is not distributed control. The key count was three; the failure domain was one. Sources: DOJ filings, Ledger Labs / OCCRP reporting

The Custodial Boom (2017 to 2021)

Self-custody hardware went mainstream and a new failure surface arrived with it. The threats stopped being only about who held the keys and started being about who knew you held them.

  • QuadrigaCX (December 2018, Exchange, ~C$215M owed). The founder died holding sole control of the cold-wallet keys. Investigation established there was also no meaningful accounting or segregation, and that the platform had operated as a Ponzi scheme. What it should change: A custody arrangement only one person can operate fails completely when that person is unavailable. Death is not a risk, it is a certainty with unknown timing. Sources: Ontario Securities Commission report, CCAA filings
  • Ledger customer database breach (July 2020, Vendor data, No direct bitcoin loss). An e-commerce database was breached and published. The records identified people who had bought bitcoin hardware wallets, along with where they lived. What it should change: Buying a hardware wallet is a disclosure that you hold bitcoin. Those records still drive targeted phishing and physical-coercion attempts six years later, and no firmware update can fix a leak of who you are and where you live. Sources: Vendor incident disclosures, published breach data

The Great Unwind (2022 to 2023)

Yield products and regulated wrappers failed in sequence. These were not anonymous offshore exchanges but audited, licensed, household-name institutions, and the losses turned on legal title and segregation rather than on cryptography.

  • Celsius (June 2022, Lender, ~$4.7B owed to customers). Withdrawals were halted and the company filed for bankruptcy. The court found that the terms of service transferred title of deposited assets to Celsius, making depositors unsecured creditors of the estate. What it should change: Custody is a legal arrangement before it is a technical one. Read what the terms do to legal title, because a yield rate is priced in the risk you did not read. Sources: Chapter 11 filings, court rulings
  • Voyager Digital (July 2022, Lender, Hundreds of millions). Marketed as FDIC-insured, which regulators subsequently ordered corrected. Customer USD sat at a partner bank while customers were creditors of Voyager, and lending exposure to a failed fund drove the insolvency. What it should change: Insurance language is frequently misunderstood and sometimes misused. Verify precisely what is covered, against which event, and for whose benefit. Sources: FDIC and Federal Reserve joint statement, Chapter 11 filings
  • FTX (November 2022, Exchange, ~$8B customer shortfall). Customer assets were commingled with an affiliated trading firm. The exchange had been audited, and the audits did not test segregation or liabilities under stress. What it should change: An audit is not a custody control. Segregation and legal title determine what a customer actually owns when the entity fails. Sources: Chapter 11 filings, CFTC complaint
  • BlockFi (November 2022, Lender, Hundreds of millions). Lending exposure to a failed fund and to FTX, compounded when a rescue facility from FTX defaulted as FTX itself collapsed. What it should change: Counterparty exposure is invisible in any asset-side disclosure. What a platform holds tells you nothing about what it is owed by parties who cannot pay. Sources: Chapter 11 filings
  • Luke Dashjr (January 2023, Self-custody, ~200 BTC reported). The holder reported that his PGP key was compromised and that bitcoin was taken from systems under his control. What it should change: Deep technical expertise is not a custody architecture. If one machine's compromise can reach the keys, the setup has one failure domain regardless of who is operating it. Sources: Holder's public statements
  • Prime Trust (2023, Custodian, Customer shortfall). A regulated trust company that provided custody rails to multiple platforms lost access to wallets and covered customer withdrawals using other customers' assets before filing for bankruptcy. What it should change: Qualified custodian is a regulatory status, not a verified security architecture. The licence does not confirm that the keys were competently managed. Sources: Nevada regulator filings, Chapter 11 filings

The Infrastructure Era (2024 to 2026)

Attackers stopped breaking cryptography and started breaking the operators, the interfaces, and the build pipelines. Then a firmware defect showed that self-custody had a concentration problem of its own.

  • DMM Bitcoin (May 2024, Exchange, 4,502.9 BTC). An employee at the exchange's wallet-infrastructure provider was social-engineered, and stolen session credentials were used to manipulate a legitimate transaction request. What it should change: Your custody is only as strong as every vendor in the signing path, including the ones you have never heard of. Sources: FBI, DC3 and Japan NPA joint advisory
  • WazirX (July 2024, Exchange, ~$230M). Signers on a custody-provider multisig were deceived, partly through a spoofed interface, into approving a malicious contract upgrade. What it should change: When every signer approves through the same interface, that interface is a single point of failure no matter how many keys exist. Sources: Exchange and custody-provider post-mortems
  • Bybit (February 2025, Exchange, ~$1.4 to 1.5B). Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen. What it should change: A proof-of-reserves attestation published days earlier was accurate and irrelevant. It described what was held, not whether the signing workflow could be subverted. Sources: FBI advisory, exchange post-mortem, NCC Group analysis
  • BigONE (July 2025, Exchange, ~$27M). A supply-chain compromise of production infrastructure altered withdrawal-approval logic. No private keys were stolen; the system approved fraudulent withdrawals itself. What it should change: Controlling what gets signed is sufficient. Key custody is not the only control that matters. Sources: Exchange disclosure, third-party incident analysis
  • CoinDCX (July 2025, Exchange, ~$44M). Social engineering of an employee laptop gave server-side access to an internal operational wallet, which was segregated from customer custody. What it should change: Segregation worked exactly as intended and contained the blast radius. The lost funds also sat outside the scope of any reserve attestation, which is worth understanding about what attestations cover. Sources: Exchange incident report
  • Upbit (November 2025, Exchange, ~$33 to 37M). A hot-wallet breach produced unauthorised withdrawals across several tokens. What it should change: Reserves and insurance made customers whole, which is the system working. Neither prevented the theft, which is the distinction between compensation and prevention. Sources: Exchange disclosure, Korean regulatory reporting
  • Coldcard entropy failure (July 2026, Hardware wallet, 1,596 BTC confirmed). A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator seeded from guessable values. Keys generated on affected firmware can be reconstructed offline. The defect shipped in March 2021 and sat in public source for roughly five years. Every model proved affected: Coinkite estimates roughly 40 bits of entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128. What it should change: Self-custody has a concentration problem too. Multisig wallets built from several units of one device shared a single firmware and a single entropy path, so one defect reached every key at once. Sources: Block engineering analysis, Coinkite advisory. Sources disagree on current models.