Bitcoin coins and charts illustrating exchange hack recovery data

Exchange Hacks: What Actually Gets Recovered

Will the money come back?

Every exchange hack ends with the same question. Will the funds be recovered?

We stopped guessing and built a dataset. Nine major exchange hacks, from 2014 to 2025, plus two fraud collapses for comparison. Every number below traces to a primary source: DOJ filings, trustee reports, a securities regulator, or the companies themselves.

Headline result: about $4.4 billion stolen, about $1.1 billion recovered. A recovery rate of roughly 25%.

But averages lie. The median hack in this dataset returned about 6%. Two spectacular recoveries do most of the heavy lifting. In most cases, the thieves keep nearly everything.

The full dataset

Exchange hacks: what was stolen vs. what came back

ExchangeYearStolen (at the time)RecoveredRecovery rateCustomers made whole?
Mt. Gox2014850,000 BTC (~$470M)141,686 BTC distributed to creditors16.7%Partially, a decade later
Bitfinex2016119,754 BTC (~$72M)94,643 BTC seized by DOJ, court-ordered back79%Yes, within 8 months
NiceHash20174,640 BTC (~$55M)0 from the thieves0%Yes, from company profits
Coincheck2018523M XEM (~$530M)~0 from the thieves~0%~80%, from company funds
KuCoin2020$281M$236M84%Yes
Poly Network2021$611M~$611M returned by the hacker~100%Yes
Ronin2022$625M~$35.8M seized5.7%Yes, by Sky Mavis
DMM Bitcoin20244,502.9 BTC (~$305M)~0~0%Yes, company guaranteed
Bybit2025401,347 ETH (~$1.46B)~$80M frozen or recovered5.5%Yes, exchange absorbed it

Fraud collapses, for comparison

ExchangeYearOwedRecoveredRecovery rateCustomers made whole?
FTX2022~$11.2B in claims$14.7-16.5B119% of petition-date claimsIn Nov 2022 dollars, yes
QuadrigaCX2019$215M (per OSC)$46M identified or recovered~21% of owed; ~13% of filed claimsNo

Five patterns in the data

1. The thief usually keeps the money

In 5 of the 9 hacks, under 6% of stolen funds were ever recovered from the attackers. NiceHash, Coincheck, and DMM Bitcoin recovered essentially zero from the thieves. Ronin and Bybit, both tied to North Korean hacking crews, sit at about 6% each. When a professional crew steals the coins, assume they are gone.

2. The outliers are weird

The three best recovery rates all came from strange situations. Poly Network’s hacker returned nearly everything voluntarily and called it white hat behavior. KuCoin clawed back 84% by freezing tokens, upgrading smart contracts, and working with law enforcement before the funds could be laundered. Bitfinex’s 79% arrived six years later, when the FBI decrypted a cloud storage file holding over 2,000 private keys. None of these is a strategy you can count on.

3. Customers usually get paid anyway, by the exchange

Here is the twist. In 7 of the 9 hacks, customers were made whole or nearly whole. Not because the thieves were caught. Because the exchange absorbed the loss from its own pocket. Bitfinex imposed a 36% haircut, then redeemed every BFX token within 8 months. NiceHash diverted its profits to users for three years until every bitcoin was repaid. Coincheck paid out of its own capital. Ronin, DMM, Bybit, and KuCoin all covered user balances. The lesson is not that hacks are safe. It is that you are betting on the exchange’s balance sheet, not on justice.

4. Bitcoin going up distorts everything

Mt. Gox lost 850,000 BTC worth about $470 million in 2014. Creditors are receiving 141,686 BTC, a 16.7% recovery in bitcoin terms. Priced in 2024 dollars, that is over $8 billion returned on a $470 million loss. Bitfinex’s seized 94,643 BTC was worth about $3.6 billion at seizure, against a $72 million theft. Recovery math in crypto is meaningless unless you fix the unit. We used native units throughout this dataset.

5. Fraud pays worse than hacking, for victims

FTX creditors are set to receive 119% of their claims, but priced in dollars at November 2022, the bottom of the bear market. Anyone holding BTC or SOL on FTX missed the entire bull run. QuadrigaCX victims got about 13 cents on the dollar of their filed claims. When the exchange itself is the thief, there is no hacker to catch and no balance sheet to bill.

Methodology

  • Dataset: 9 exchange hacks (2014-2025), selected for size and documentation quality, plus FTX and QuadrigaCX as fraud comparisons.
  • Recovery rate means funds recovered or returned divided by funds stolen, measured in native units: BTC for BTC thefts, USD at time of theft for mixed-asset thefts.
  • The weighted aggregate converts BTC-denominated cases at the theft-time BTC price. All figures are rounded.
  • “Customers made whole” counts any case where users got their balances back, regardless of who paid for it.
  • Sources: DOJ court filings, the Mt. Gox rehabilitation trustee, the Ontario Securities Commission, company statements, and the press reports linked below.

What we cannot know

  • Small hacks and quiet reimbursements never make the news. This dataset skews toward the biggest, most public cases.
  • Frozen is not returned. Some counted recoveries sit in government wallets for years before victims see anything.
  • Attribution is uncertain in several cases. We only named North Korean crews where the FBI or investigators did.
  • Self-reported figures, like KuCoin’s 84%, cannot be independently audited.
  • The true denominator of crypto theft is unknowable. On-chain analytics only sees reported flows.

The takeaway for your coins

Two numbers matter. About 6% is the typical recovery when thieves steal exchange funds. And nearly every customer who got paid was paid by the exchange, not by justice.

Both numbers say the same thing. Once your coins leave your keys, your outcome depends on other people’s money and other people’s mistakes. Cold storage exists so you never roll those dice. Coincheck kept its NEM in a hot wallet. NiceHash lost its entire wallet to a phished employee. A hardware wallet holding your keys offline has no hot wallet to drain.

QuadrigaCX is the darkest version of this story: one man held all the keys, and he was the thief. Seed words alone are not enough when a single person is the whole security model. That is the case for multisig: no one key, no one person, no single point of failure. Bitfinex ran a multisig setup in 2016 and still got drained through a flawed integration, which is why the setup matters more than the label.

Not sure what fits you? The wizard walks you through it, and the compatibility checker shows which hardware wallets work with your software before you buy.

Sources

Publications similaires

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *