CryptoExID

Security · Reviewed Aug 19, 2026 · 9 min read

What Actually Happens When an Exchange Gets Hacked

A decade of exchange hacks shows who eats the loss, who gets repaid, and who disappears.

Reviewed by CryptoExID Editorial · Aug 19, 2026 · Editorial policy · how we make money

The first 48 hours

The pattern rarely varies. Withdrawals pause, usually blamed on maintenance. On-chain analysts spot large unusual transfers before any announcement. Then a statement arrives calling it a security incident, and the real number emerges days later, almost always bigger than the first admission.

During this window the exchange races the attacker. Stolen tokens get flagged with other venues and stablecoin issuers, who can freeze assets that touch their systems. Tokens with centralized control can be frozen or forked outright. Bitcoin and monero, effectively, cannot. What was stolen matters as much as how much.

Mt. Gox: the worst case

Mt. Gox handled most of the world's bitcoin trading when it collapsed in February 2014, admitting roughly 850,000 BTC was gone, siphoned over years through compromised keys while internal books showed balances that did not exist. Customers waited about a decade for partial repayment through Japanese civil rehabilitation.

Gox set the template for everything customers now fear: no insurance, no segregation, no way to see the hole until it swallowed the company. Every security practice we score today, from proof of reserves to cold storage policy, is in some sense a reaction to Gox.

Coincheck and KuCoin: two recoveries

Coincheck lost about $530 million in NEM tokens in January 2018 from a hot wallet with no multisig. The saves were corporate: Coincheck repaid customers from its own balance sheet, was acquired by the Monex Group, and kept operating. Japanese regulators responded with much tighter custody rules.

KuCoin's 2020 breach took roughly $280 million, but most of it came back. Stolen tokens were frozen by issuers, some were recovered through project-level forks, and negotiations reportedly recovered more. KuCoin covered the rest through insurance funds and partners. Full customer reimbursement, remarkable for a hack that size.

BitMart and FTX: the other endings

BitMart lost about $196 million in December 2021 when a hot wallet private key was compromised. The exchange pledged to compensate users from its own capital, but reimbursement was slow and communication thin. BitMart still operates, and that incident still weighs on its security score in our model today. A hack is not just an event, it is a permanent data point.

FTX in November 2022 was not a hack at all, though a mysterious $400 million drain occurred mid-collapse. Customer funds had been commingled and spent. The lesson: outside attackers have stolen billions, but the largest customer losses in crypto history came from the inside.

Who eats the loss

Reimbursement depends on whether the loss is smaller than the exchange's will and ability to pay. Coincheck and KuCoin repaid in full because the parent had capital or recovery went well. Mt. Gox and FTX customers became bankruptcy creditors, waiting years for partial recovery, often paid at petition-date prices far below later market value.

Corporate insurance and pledge funds help but are capped, and no policy covers insolvency. In bankruptcy, your terms of service decide whether you are an owner or an unsecured creditor, and that clause was written long before the hack.

What this history changes in our scores

Incident history is the hardest security signal we have, so we weight it hard. Security carries 20% in our base ranking and about 30% on the safest-exchanges page, with a bonus for venues that have never been hacked. Kraken, clean since 2011, benefits. BitMart carries a penalty that will take years of clean operation to work off.

We also credit how a venue handled its incident. KuCoin's recovery and full reimbursement counts in its favor. Slow, vague communication counts against. The breach reveals the architecture; the response reveals the management.

FAQ

Do customers get their money back after an exchange hack?

Sometimes. Coincheck and KuCoin repaid customers in full from corporate funds and recoveries. Mt. Gox and FTX customers waited years in bankruptcy for partial repayment. The deciding factor is whether the exchange stays solvent.

What was the biggest exchange hack ever?

Mt. Gox in 2014 remains the benchmark at roughly 850,000 BTC. In dollar terms at today's prices nothing else comes close, though Coincheck's $530M NEM loss was the largest single theft at the time it happened.

Why did KuCoin recover most of its stolen funds?

Most stolen assets were tokens whose issuers could freeze or fork them, and coordination happened fast. Combined with insurance funds and negotiations, KuCoin covered customers fully. A bitcoin-heavy theft would have been far harder to claw back.

Was FTX a hack?

No. FTX collapsed because customer funds were commingled and spent by insiders. An unexplained $400M drain did occur during the bankruptcy, but the core loss was misappropriation, not intrusion.

Does a past hack mean I should avoid an exchange?

Not automatically, but it is a permanent data point. We still discount BitMart's security score for its 2021 breach. What matters most is whether users were made whole and what changed afterward.

Can stolen crypto be frozen?

Centralized tokens and major stablecoins can be frozen by their issuers, and exchanges can blacklist deposit addresses. Bitcoin and privacy coins effectively cannot be frozen, only tracked.