Curated incidents by year
We group incidents by year. For each one, we highlight user impact and platform response, then pull out a simple lesson you can apply in your own setup, whether you use exchanges, hardware wallets or DeFi protocols.
2026
2026-07-30 · Coldcard (Coinkite)
Coldcard firmware bug and large self-custody losses
A bug introduced in March 2021 reduced seed randomness on some Coldcard devices by falling back to a predictable software random number generator. In 2026, attackers exploited that weakness to brute force keys and drain funds from addresses created on vulnerable firmware.
User impact
Across multiple waves, more than one thousand bitcoins were taken from thousands of wallets, making this one of the largest hardware wallet failures recorded. Only wallets seeded on fixed firmware or other devices were unaffected.
Platform response
Coinkite released patched firmware and urged users to move funds to wallets generated with corrected randomness. However, upgrading firmware could not repair seeds that had already been created under the flawed generator.
Lesson for beginners
The Coldcard incident showed that even specialised hardware can have subtle cryptographic bugs. For large holdings, many users now consider multi-signature setups, diverse vendors and occasional migrations to fresh seeds as part of defence in depth.
2026-08-16 · SafePal and Trezor
SafePal and Trezor customer data exposures and phishing risk
Separate incidents at SafePal and a Trezor shipping provider exposed tens of thousands of customer order records, including names, email addresses and home addresses. The leaks did not reveal recovery phrases or keys but made hardware wallet buyers more visible to attackers.
User impact
Around fifty thousand records were exposed across both companies, raising the risk of targeted phishing, extortion attempts and physical threats against self-custody users.
Platform response
SafePal and Trezor fixed the underlying issues, notified customers and authorities, and worked to remove malicious phishing sites and communications that used the leaked lists.
Lesson for beginners
These incidents showed that privacy around who owns hardware wallets is itself a safety issue. Users benefit from treating any breach-linked email or message as suspect and keeping recovery phrases completely offline.
2026-07-15 · Ostium (Arbitrum perp DEX)
Ostium price signer compromise and vault drain
Ostium, a perpetuals protocol on Arbitrum, suffered an exploit after an attacker compromised its off chain price reporting system. They submitted forged but validly signed oracle prices and routed them through a task scheduler to manufacture artificial trading profits.
User impact
Around 18 to 24 million dollars in stablecoins were drained from the liquidity vault backing trader positions. Trader collateral remained safe, but liquidity providers bore the loss.
Platform response
The protocol paused trading, brought in external investigators, hardened its off chain price signing environment and began to design recovery options for affected liquidity providers.
Lesson for beginners
Ostium’s experience showed that DeFi risk is not limited to smart contracts. Off chain infrastructure such as oracle signers and automation keys must be treated as critical security components.
2025
2025-02-21 · Bybit
Bybit Ethereum wallet compromise and multi-billion dollar loss
Attackers compromised the signing flow for Bybit’s main Ethereum wallet and associated contracts. They tricked signers into approving changes that moved control to a malicious implementation, then drained large holdings of Ether and staked Ether in a short period.
User impact
Reports put the loss at roughly 1.4 to 1.5 billion dollars in Ether and related assets, making it the largest single exchange theft recorded at that time. The incident triggered heavy scrutiny of custody arrangements for large centralised platforms.
Platform response
Bybit processed an intense wave of withdrawals, secured emergency funding and loans, and worked to restore reserves. The platform launched bounty offers and detailed post incident communications while regulators and law enforcement investigated.
Lesson for beginners
Bybit’s loss highlighted that custody risk remains central even for large and well-known exchanges. Users are encouraged to treat platform size and marketing as secondary to technical custody practices and contingency planning.
2023
2023-12-14 · Ledger Connect Kit
Ledger Connect Kit library compromise and DeFi wallet drainer
A former Ledger employee’s credentials were compromised, allowing attackers to push malicious versions of the Ledger Connect Kit JavaScript library to npm. Many DeFi frontends loaded that library directly, and the poisoned versions injected wallet drainer logic into dApps.
User impact
Around 600,000 dollars in crypto was stolen as users connected hardware wallets to compromised DeFi sites and signed transactions that had been silently altered. The incident showed that supply chain risk in Web frontends can undermine even strong hardware wallet practices.
Platform response
Ledger and affected dApps pulled and replaced the malicious library versions, coordinated with WalletConnect to cut off the rogue project, and published technical incident reports and mitigation guidance for developers.
Lesson for beginners
The Connect Kit compromise illustrated that protecting self-custody involves both wallet firmware and the Web applications people use to interact with it. Projects benefit from pinning dependencies, using integrity checks and reacting quickly to upstream compromises.
2022
2022-11-11 · FTX and Alameda Research
FTX and Alameda collapse after secret use of customer assets
From 2019 to 2022, FTX marketed itself as a safe and liquid exchange while its affiliate Alameda Research quietly drew billions of dollars of customer assets via hidden credit lines and bank accounts. Special code paths exempted Alameda from standard risk controls, letting it run a large negative balance backed by user deposits.
User impact
Regulators later alleged that over 8 billion dollars of customer deposits had been misappropriated or lost. When confidence broke in November 2022, withdrawal requests revealed a massive shortfall. FTX and Alameda filed for bankruptcy, leaving millions of users exposed and reshaping trust in centralised platforms.
Platform response
New management began forensic work inside the bankruptcy estate. The SEC, CFTC and other regulators filed civil charges, and criminal proceedings targeted the former leadership. Recovery efforts continue, with partial distributions to creditors and detailed public reporting on the scheme.
Lesson for beginners
FTX showed that financial failure can come not only from external hacks but from internal misuse and commingling of funds. Transparent proof of reserves, clear segregation of customer assets and strong governance are critical when choosing an exchange.
2020
2020-09-25 · KuCoin
KuCoin hot wallet compromise and rapid token reissues
In September 2020, Singapore-based exchange KuCoin detected unauthorised outflows from its hot wallets. Private keys controlling those wallets had been exposed, allowing attackers to move funds into their own addresses and immediately begin swapping assets on on-chain markets.
User impact
Roughly 281 million dollars worth of assets across Bitcoin, Ether and many ERC 20 tokens were drained from KuCoin hot wallets. Cold wallets remained intact, and later coordination with token issuers allowed a majority of the stolen ERC 20 tokens to be frozen and reissued.
Platform response
KuCoin moved remaining hot wallet funds to new wallets, paused deposits and withdrawals, and launched an investigation with law enforcement and blockchain analytics firms. An insurance fund and issuer support eventually covered most user losses.
Lesson for beginners
KuCoin underlined the importance of strict hot wallet key management and incident response. It also showed how token contracts, on-chain tracing and coordinated reissues can limit damage for some asset types but not for base-layer coins like Bitcoin.
2020-07-28 · Ledger (e-commerce and marketing data)
Ledger customer contact data breach and leak
An attacker gained access to Ledger’s e-commerce and marketing database via a leaked API key. A later incident involving a rogue partner support agent compounded the problem and led to a large set of customer records being exposed online.
User impact
Around one million email addresses and more than 270,000 detailed records, including names, postal addresses and phone numbers, were leaked. Hardware wallets and private keys remained secure, but affected customers faced waves of phishing and extortion attempts.
Platform response
Ledger patched the underlying issues, notified authorities and users, and published several updates explaining what happened. The company increased focus on data minimisation and partner oversight to reduce the impact of similar breaches.
Lesson for beginners
The Ledger breach highlighted that data about who owns hardware wallets can be almost as sensitive as private keys themselves. Users should expect phishing after such breaches and never type recovery phrases into software or forms that claim to be “checking” wallet safety.
2020-09-24 · KuCoin (archive note)
KuCoin laundering trail and token reissues
Independent incident archives have tracked how attackers moved KuCoin’s stolen funds through decentralised exchanges and mixing services. A large portion of token losses were mitigated by issuer freezes and reissues, while base-layer coins remained irrecoverable.
User impact
The hack settled as one of the largest hot wallet compromises at the time, and its laundering routes helped shape how exchanges and analytics firms monitor abuse on DeFi rails.
Platform response
KuCoin and partners traced flows, coordinated with issuers and gradually reduced the outstanding loss. Insurance funds and reissues helped restore user balances.
Lesson for beginners
This incident reinforced the practical difference between token contracts that can be frozen or reissued and base-layer coins that cannot be rolled back. Both types of assets need careful risk management.
2014
2014-02-28 · Mt. Gox
Mt. Gox collapse after years of undetected hot wallet thefts
Launched in 2010, Mt. Gox grew into the dominant Bitcoin exchange before collapsing in early 2014. Later analysis suggested that most of the missing coins had been leaking from its hot wallet since late 2011, far beyond a single one-off hack.
User impact
Around 744,408 customer bitcoins and 100,000 company-held bitcoins were lost. Trading halted, the site was taken offline and the company entered bankruptcy, leaving many early users locked in multi-year recovery proceedings.
Platform response
The company first blamed transaction malleability, then entered civil rehabilitation. Ongoing court-supervised processes aim to redistribute remaining assets to creditors and former customers.
Lesson for beginners
Mt. Gox showed that basic hot-wallet security failures could silently drain an exchange over years. It is one reason modern platforms lean heavily on cold storage, multi-signature controls and external audits.
How we curate and update incidents
We prioritise incidents with clear public documentation from multiple sources. The goal is not to track every minor issue but to build an educational overview of major events and patterns that beginners should know about. Incidents range from early exchange failures like Mt. Gox to more recent wallet bugs and DeFi exploits.
When new, well documented incidents occur, we may add them to this page along with links to our reviews and safety guides. Details here can evolve over time as the crypto ecosystem learns and improves.
FAQ: Exchange and wallet security incidents
Why include both exchanges and wallets on this incidents page?
Beginners face risk from both custodial exchanges and self-custody tools. Seeing incidents side by side helps you understand trade offs between keeping funds on platforms and managing your own keys.
Does one incident mean a platform or wallet is forever unsafe?
Not automatically. The key questions are how the team responded, whether users were made whole, what changed afterwards and whether similar patterns repeat over time.
Is this all of the crypto security incidents that happened?
No. This is a curated educational timeline focusing on notable events with clear public documentation. It is not a complete, real time feed.
How often will this incidents timeline be updated?
It will be updated periodically as significant incidents occur, especially ones that teach new lessons for beginners and long term holders.
This timeline simplifies complex situations and focuses on education. Always read primary sources and consider your own risk tolerance and local regulations before using any platform or hardware wallet.
Spot an error or missing context. Email admin@cryptosbeginner.com so we can review and improve it.