CryptosBeginner

Security · Incidents timeline

Crypto Exchange and Wallet Security Incidents

This page highlights notable exchange and wallet related incidents. It aims to show where things have gone wrong, how teams responded and what you can learn as a beginner. It is a curated timeline, not a complete record, designed to help you ask better safety questions.

Editor: Alex RiveraPublished: 18 July 2026Last updated: 21 August 2026

How to read this timeline

Each entry summarises what happened, how users were affected, how the platform responded and a simple lesson. Use it together with our safety guides before deciding where and how to store your funds.

Curated incidents by year

We group incidents by year. For each one, we highlight user impact and platform response, then pull out a simple lesson you can apply in your own setup, whether you use exchanges, hardware wallets or DeFi protocols.

2026

2026-07-30 · Coldcard (Coinkite)

Coldcard firmware bug and large self-custody losses

Wallet or self custody exploitHIGH

A bug introduced in March 2021 reduced seed randomness on some Coldcard devices by falling back to a predictable software random number generator. In 2026, attackers exploited that weakness to brute force keys and drain funds from addresses created on vulnerable firmware.

User impact

Across multiple waves, more than one thousand bitcoins were taken from thousands of wallets, making this one of the largest hardware wallet failures recorded. Only wallets seeded on fixed firmware or other devices were unaffected.

Platform response

Coinkite released patched firmware and urged users to move funds to wallets generated with corrected randomness. However, upgrading firmware could not repair seeds that had already been created under the flawed generator.

Lesson for beginners

The Coldcard incident showed that even specialised hardware can have subtle cryptographic bugs. For large holdings, many users now consider multi-signature setups, diverse vendors and occasional migrations to fresh seeds as part of defence in depth.

2026-08-16 · SafePal and Trezor

SafePal and Trezor customer data exposures and phishing risk

Data breachMEDIUM

Separate incidents at SafePal and a Trezor shipping provider exposed tens of thousands of customer order records, including names, email addresses and home addresses. The leaks did not reveal recovery phrases or keys but made hardware wallet buyers more visible to attackers.

User impact

Around fifty thousand records were exposed across both companies, raising the risk of targeted phishing, extortion attempts and physical threats against self-custody users.

Platform response

SafePal and Trezor fixed the underlying issues, notified customers and authorities, and worked to remove malicious phishing sites and communications that used the leaked lists.

Lesson for beginners

These incidents showed that privacy around who owns hardware wallets is itself a safety issue. Users benefit from treating any breach-linked email or message as suspect and keeping recovery phrases completely offline.

2026-07-15 · Ostium (Arbitrum perp DEX)

Ostium price signer compromise and vault drain

Oracle or price feed exploitHIGH

Ostium, a perpetuals protocol on Arbitrum, suffered an exploit after an attacker compromised its off chain price reporting system. They submitted forged but validly signed oracle prices and routed them through a task scheduler to manufacture artificial trading profits.

User impact

Around 18 to 24 million dollars in stablecoins were drained from the liquidity vault backing trader positions. Trader collateral remained safe, but liquidity providers bore the loss.

Platform response

The protocol paused trading, brought in external investigators, hardened its off chain price signing environment and began to design recovery options for affected liquidity providers.

Lesson for beginners

Ostium’s experience showed that DeFi risk is not limited to smart contracts. Off chain infrastructure such as oracle signers and automation keys must be treated as critical security components.

2025

2025-02-21 · Bybit

Bybit Ethereum wallet compromise and multi-billion dollar loss

Exchange hackHIGH

Attackers compromised the signing flow for Bybit’s main Ethereum wallet and associated contracts. They tricked signers into approving changes that moved control to a malicious implementation, then drained large holdings of Ether and staked Ether in a short period.

User impact

Reports put the loss at roughly 1.4 to 1.5 billion dollars in Ether and related assets, making it the largest single exchange theft recorded at that time. The incident triggered heavy scrutiny of custody arrangements for large centralised platforms.

Platform response

Bybit processed an intense wave of withdrawals, secured emergency funding and loans, and worked to restore reserves. The platform launched bounty offers and detailed post incident communications while regulators and law enforcement investigated.

Lesson for beginners

Bybit’s loss highlighted that custody risk remains central even for large and well-known exchanges. Users are encouraged to treat platform size and marketing as secondary to technical custody practices and contingency planning.

2023

2023-12-14 · Ledger Connect Kit

Ledger Connect Kit library compromise and DeFi wallet drainer

Exchange hackMEDIUM

A former Ledger employee’s credentials were compromised, allowing attackers to push malicious versions of the Ledger Connect Kit JavaScript library to npm. Many DeFi frontends loaded that library directly, and the poisoned versions injected wallet drainer logic into dApps.

User impact

Around 600,000 dollars in crypto was stolen as users connected hardware wallets to compromised DeFi sites and signed transactions that had been silently altered. The incident showed that supply chain risk in Web frontends can undermine even strong hardware wallet practices.

Platform response

Ledger and affected dApps pulled and replaced the malicious library versions, coordinated with WalletConnect to cut off the rogue project, and published technical incident reports and mitigation guidance for developers.

Lesson for beginners

The Connect Kit compromise illustrated that protecting self-custody involves both wallet firmware and the Web applications people use to interact with it. Projects benefit from pinning dependencies, using integrity checks and reacting quickly to upstream compromises.

2022

2022-11-11 · FTX and Alameda Research

FTX and Alameda collapse after secret use of customer assets

Misuse of customer fundsHIGH

From 2019 to 2022, FTX marketed itself as a safe and liquid exchange while its affiliate Alameda Research quietly drew billions of dollars of customer assets via hidden credit lines and bank accounts. Special code paths exempted Alameda from standard risk controls, letting it run a large negative balance backed by user deposits.

User impact

Regulators later alleged that over 8 billion dollars of customer deposits had been misappropriated or lost. When confidence broke in November 2022, withdrawal requests revealed a massive shortfall. FTX and Alameda filed for bankruptcy, leaving millions of users exposed and reshaping trust in centralised platforms.

Platform response

New management began forensic work inside the bankruptcy estate. The SEC, CFTC and other regulators filed civil charges, and criminal proceedings targeted the former leadership. Recovery efforts continue, with partial distributions to creditors and detailed public reporting on the scheme.

Lesson for beginners

FTX showed that financial failure can come not only from external hacks but from internal misuse and commingling of funds. Transparent proof of reserves, clear segregation of customer assets and strong governance are critical when choosing an exchange.

2020

2020-09-25 · KuCoin

KuCoin hot wallet compromise and rapid token reissues

Exchange hackHIGH

In September 2020, Singapore-based exchange KuCoin detected unauthorised outflows from its hot wallets. Private keys controlling those wallets had been exposed, allowing attackers to move funds into their own addresses and immediately begin swapping assets on on-chain markets.

User impact

Roughly 281 million dollars worth of assets across Bitcoin, Ether and many ERC 20 tokens were drained from KuCoin hot wallets. Cold wallets remained intact, and later coordination with token issuers allowed a majority of the stolen ERC 20 tokens to be frozen and reissued.

Platform response

KuCoin moved remaining hot wallet funds to new wallets, paused deposits and withdrawals, and launched an investigation with law enforcement and blockchain analytics firms. An insurance fund and issuer support eventually covered most user losses.

Lesson for beginners

KuCoin underlined the importance of strict hot wallet key management and incident response. It also showed how token contracts, on-chain tracing and coordinated reissues can limit damage for some asset types but not for base-layer coins like Bitcoin.

2020-07-28 · Ledger (e-commerce and marketing data)

Ledger customer contact data breach and leak

Data breachMEDIUM

An attacker gained access to Ledger’s e-commerce and marketing database via a leaked API key. A later incident involving a rogue partner support agent compounded the problem and led to a large set of customer records being exposed online.

User impact

Around one million email addresses and more than 270,000 detailed records, including names, postal addresses and phone numbers, were leaked. Hardware wallets and private keys remained secure, but affected customers faced waves of phishing and extortion attempts.

Platform response

Ledger patched the underlying issues, notified authorities and users, and published several updates explaining what happened. The company increased focus on data minimisation and partner oversight to reduce the impact of similar breaches.

Lesson for beginners

The Ledger breach highlighted that data about who owns hardware wallets can be almost as sensitive as private keys themselves. Users should expect phishing after such breaches and never type recovery phrases into software or forms that claim to be “checking” wallet safety.

2020-09-24 · KuCoin (archive note)

KuCoin laundering trail and token reissues

Exchange hackMEDIUM

Independent incident archives have tracked how attackers moved KuCoin’s stolen funds through decentralised exchanges and mixing services. A large portion of token losses were mitigated by issuer freezes and reissues, while base-layer coins remained irrecoverable.

User impact

The hack settled as one of the largest hot wallet compromises at the time, and its laundering routes helped shape how exchanges and analytics firms monitor abuse on DeFi rails.

Platform response

KuCoin and partners traced flows, coordinated with issuers and gradually reduced the outstanding loss. Insurance funds and reissues helped restore user balances.

Lesson for beginners

This incident reinforced the practical difference between token contracts that can be frozen or reissued and base-layer coins that cannot be rolled back. Both types of assets need careful risk management.

2014

2014-02-28 · Mt. Gox

Mt. Gox collapse after years of undetected hot wallet thefts

Exchange hackHIGH

Launched in 2010, Mt. Gox grew into the dominant Bitcoin exchange before collapsing in early 2014. Later analysis suggested that most of the missing coins had been leaking from its hot wallet since late 2011, far beyond a single one-off hack.

User impact

Around 744,408 customer bitcoins and 100,000 company-held bitcoins were lost. Trading halted, the site was taken offline and the company entered bankruptcy, leaving many early users locked in multi-year recovery proceedings.

Platform response

The company first blamed transaction malleability, then entered civil rehabilitation. Ongoing court-supervised processes aim to redistribute remaining assets to creditors and former customers.

Lesson for beginners

Mt. Gox showed that basic hot-wallet security failures could silently drain an exchange over years. It is one reason modern platforms lean heavily on cold storage, multi-signature controls and external audits.

How we curate and update incidents

We prioritise incidents with clear public documentation from multiple sources. The goal is not to track every minor issue but to build an educational overview of major events and patterns that beginners should know about. Incidents range from early exchange failures like Mt. Gox to more recent wallet bugs and DeFi exploits.

When new, well documented incidents occur, we may add them to this page along with links to our reviews and safety guides. Details here can evolve over time as the crypto ecosystem learns and improves.

FAQ: Exchange and wallet security incidents

Why include both exchanges and wallets on this incidents page?

Beginners face risk from both custodial exchanges and self-custody tools. Seeing incidents side by side helps you understand trade offs between keeping funds on platforms and managing your own keys.

Does one incident mean a platform or wallet is forever unsafe?

Not automatically. The key questions are how the team responded, whether users were made whole, what changed afterwards and whether similar patterns repeat over time.

Is this all of the crypto security incidents that happened?

No. This is a curated educational timeline focusing on notable events with clear public documentation. It is not a complete, real time feed.

How often will this incidents timeline be updated?

It will be updated periodically as significant incidents occur, especially ones that teach new lessons for beginners and long term holders.

This timeline simplifies complex situations and focuses on education. Always read primary sources and consider your own risk tolerance and local regulations before using any platform or hardware wallet.

Spot an error or missing context. Email admin@cryptosbeginner.com so we can review and improve it.