💀
Every Bitcoin exchange that exit scammed, collapsed, defaulted, or was seized since 2011.
Know the history. Keep your own keys.
This is the most important sentence in Bitcoin. It is not a slogan. It is not a preference. It is a technical and legal reality - and every exchange on this page is proof of what happens when people forget it.
When you buy Bitcoin on an exchange and leave it there, you do not own Bitcoin. You own an IOU. A number in a database. A promise from a company that they will give you your Bitcoin back when you ask for it. You are trusting that the exchange is solvent, honest, secure, and that its CEO hasn't secretly been gambling your funds on altcoins from a laptop in a cafรฉ.
Bitcoin was invented specifically so that you would never have to trust a third party with your money. The entire point of the blockchain is that you can hold value without anyone's permission - no bank, no broker, no exchange. The moment you hand custody of your coins to someone else, you are back in the old financial system, with all its risks, none of its protections, and no deposit insurance to bail you out.
Every Bitcoin wallet is controlled by a private key - a secret string of characters that proves ownership and authorises transactions. If you have the private key, you have the Bitcoin. If someone else has it, they have the Bitcoin. It really is that simple, and that absolute.
Self-custody means you hold your own private keys, typically on a hardware wallet (a physical device that stores keys offline). You are the only person who can move your coins. No company can freeze them, steal them, go bankrupt with them, or be hacked out of them. The downside is that if you lose your seed phrase - the 12 or 24 words that back up your keys - the coins are gone forever with no recourse.
Exchange custody means the exchange holds the private keys on your behalf. You log in with a username and password and see a balance, but the exchange actually controls the coins. This is convenient for trading, but it means you are completely exposed to that company's competence, honesty, and security practices - as well as any government that decides to seize or freeze assets.
When you set up a self-custody wallet, it gives you a seed phrase - typically 12 or 24 random words (e.g. witch collapse practice feed shame open despair creek road again ice least). This seed phrase mathematically generates your private keys. Anyone who has it has full, permanent, irrevocable access to every coin in that wallet. Write it down on paper. Store it somewhere fireproof. Never photograph it. Never type it into a website. Never share it with anyone. If someone asks for your seed phrase, they are trying to steal your Bitcoin.
The Bitcoin community's general answer is: only what you are actively trading with. If you bought Bitcoin as a long-term hold, it should be in your own wallet within 24 hours of purchasing. The only coins that make sense to keep on an exchange long-term are ones you intend to trade in the near future - and even then, only on well-established, regulated exchanges with proven track records and transparent proof of reserves.
Self-custody sounds intimidating. It isn't. Millions of people do it every day. Here is the basic process:
The most trusted options are Ledger and Trezor. Buy directly from the manufacturer - never from Amazon or third-party sellers, where devices can be pre-compromised. A hardware wallet stores your private keys on a secure chip that never connects to the internet.
When you first set up the device, it generates your seed phrase and displays it once. Write every word down, in order, on paper. Double-check it. Store it somewhere safe - separate from the device. A fireproof safe is ideal. This is the only backup of your Bitcoin.
Copy your hardware wallet's receiving address. Go to the exchange. Initiate a withdrawal to that address. Start with a small test transaction first to confirm everything works. Once confirmed, withdraw the rest. Your coins now live on the blockchain, under your control.
After withdrawing, test your seed phrase recovery. Reset the device and restore from your seed phrase to confirm it works. This is the only way to be certain your backup is correct. Many people have discovered their seed phrase was wrong only after losing the device.
The hardware wallet itself is PIN-protected. Even if someone steals it, they cannot access the coins without the PIN. But with your seed phrase, they need nothing else - which is why protecting that piece of paper matters more than protecting the device.
Tell someone you trust where your seed phrase is kept, in case something happens to you. Bitcoin held in self-custody has no account recovery, no password reset, no customer service. Make sure it won't be lost forever if you're no longer around to access it.
Every exchange on this page showed warning signs before it collapsed. In hindsight they're obvious. Here is what to watch for:
This is the single biggest red flag. A solvent exchange can always process withdrawals. When Mt. Gox suspended Bitcoin withdrawals on February 7, 2014, the exchange was already insolvent - it just took three more weeks for the public to find out. When QuadrigaCX started imposing withdrawal limits in August 2018, the money was already gone. If you cannot withdraw your Bitcoin, your Bitcoin may not exist.
In the final weeks of Mt. Gox, Bitcoin was trading 5-10% cheaper there than everywhere else. Users were panic-selling at a discount just to get something out. This price dislocation is a signal that the market doesn't trust the exchange to deliver actual Bitcoin - and it's usually right.
Exchanges experiencing genuine temporary technical problems communicate clearly and resolve them quickly. Exchanges that are insolvent or hiding something issue vague statements about "security maintenance", "system upgrades", or "transaction malleability bugs" that drag on for weeks. The longer the vague explanation, the worse the reality usually is.
A reputable exchange can prove at any time that it holds customer funds 1:1 - using cryptographic attestations of its wallet balances. If an exchange refuses to publish proof of reserves, or its proof is unaudited and unverifiable, it may be operating fractional - meaning it doesn't actually hold all the Bitcoin it shows in customer balances. This is exactly what QuadrigaCX did for years.
QuadrigaCX's fatal flaw - and the detail that made many investigators suspicious - was that one person, CEO Gerald Cotten, allegedly had sole access to all cold wallets. No legitimate, professionally run exchange gives a single person unchecked control over hundreds of millions in customer funds. Multi-signature wallets, independent audits, and key management procedures exist precisely to prevent this. If an exchange can't explain how its cold storage is secured, that's a problem.
Every exchange below is a real-world consequence of the risks described above. Names, dates, amounts, and what happened to the people responsible.
Mt. Gox stands for "Magic: The Gathering Online eXchange." The domain was originally built in 2007 by programmer Jed McCaleb as a trading platform for Magic: The Gathering cards - the popular fantasy card game. McCaleb abandoned the card idea and in 2010 repurposed the domain as a Bitcoin exchange. He sold it to Mark Karpeles in 2011, who ran it from Tokyo. It grew to handle over 70% of all global Bitcoin trades at its peak. Hackers stole private keys from the hot wallet as early as 2011, slowly draining the exchange for years without anyone noticing. By February 2014, 850,000 BTC were missing. The exchange suspended withdrawals on February 7, went dark on February 24, and filed for bankruptcy in Japan. Around 200,000 BTC were later recovered in an old wallet. Mt. Gox's collapse caused Bitcoin's price to fall 36% and set back mainstream adoption by years. Creditors waited over a decade for repayment, with payouts finally beginning in 2024.
Canada's largest crypto exchange at its peak. CEO Gerald Cotten died in India in December 2018 - allegedly the only person with access to $190M CAD in customer funds locked in cold wallets. Blockchain investigators later found the exchange had been running as a fractional reserve since 2016, using customer deposits to fund Cotten's personal trading and lifestyle. Chainalysis determined the cold wallets were mostly empty. Most of the ~$215M owed to 115,000 customers was never recovered. Many believe Cotten faked his death; a Netflix documentary aired in 2022.
BTC-e was a Russia-linked exchange that processed hundreds of millions in criminal proceeds, including funds from the Mt. Gox hack. The US DOJ and FinCEN seized the exchange in July 2017, fining BTC-e $110 million. Its operator, Russian national Alexander Vinnik, was arrested in Greece, extradited to France, convicted of money laundering, and later extradited to the US. The exchange briefly relaunched as WEX but folded in 2018 when its new operator disappeared with customer funds, making it a double failure.
Once the second-largest US altcoin exchange. In July 2014 a hacker inserted Trojan code into an altcoin called Lucky7Coin listed on the exchange, gaining access to BTC and LTC private keys. CEO Paul Vernon secretly knew about the hack but continued operating the exchange, covering losses with customer funds. The exchange collapsed in January 2016 when it could no longer cover withdrawals. Vernon was later accused of destroying evidence and fleeing to China. Customers were successfully awarded $8.2M in a class action lawsuit, though most funds were never recovered.
One of the largest US Bitcoin exchanges of 2012. The operator encrypted wallet keys for transactions but kept an unencrypted backup on the same server. In September 2012, a hacker breached the servers and stole 24,000 BTC - worth around $250,000 at the time. The exchange reported the theft to the FBI and attempted to continue operations, refunding users in USD. However, reserves were exhausted and Bitfloor permanently shut down in April 2013 after US banking partner Signature Bank terminated services.
An early leveraged Bitcoin trading platform. On March 1, 2012, hosting provider Linode was hacked - attackers accessed Bitcoinica's servers and stole 43,000 BTC. A second hack hit in May 2012, stealing 18,548 BTC, this time suspected to have been an inside job. The exchange was already attempting to wind down following the Linode breach when the second attack struck. All customer withdrawals were halted and the platform shut down permanently. Depositors recovered only a fraction of their funds through ongoing legal proceedings.
One of the first Bitcoin wallet services targeting newcomers. In August 2011 the site went offline, with the operator claiming it had been hacked. Users - including prominent Bitcoin community members - lost approximately 154,406 BTC. The operator briefly reappeared claiming 49% of funds had been stolen and offering to return the remainder, but many users never received anything. The true story was never proven: either a hack occurred and the operator vanished with the rest, or it was a full exit scam dressed as a hack. One of Bitcoin's earliest and most costly disasters.
New Zealand-based exchange popular for altcoin trading. In January 2019 hackers exploited a vulnerability to drain over $16M in ETH and ERC-20 tokens, plus some Bitcoin. The exchange attempted to resume operations but was forced into liquidation in May 2019 by Grant Thornton after it became clear the breach had made it unviable. Over 900,000 customers were affected. Legal proceedings regarding the ownership of customer funds (whether they were held in trust) continued for years in NZ courts, setting important legal precedent.
South Korean exchange hacked twice - first as Yapizon in April 2017 (losing 3,816 BTC, ~$5M), then again after rebranding as Youbit in December 2017. The December hack drained 17% of all assets. The exchange declared bankruptcy the same day, offering customers only 75% of the value of their holdings. South Korean authorities attributed both attacks to North Korea's Lazarus Group, making Youbit a notable case of state-sponsored crypto theft.
A popular altcoin exchange acquired by Ryan Kennedy (also known as "Alex Green") in 2014. Kennedy spent weeks draining user balances before disabling all withdrawals and going silent. He was later identified, arrested in the UK, and convicted of theft and rape. Approximately 3,700 BTC belonging to customers were stolen. MintPal is one of the clearest examples of a predatory acquisition used to execute an exit scam.
Poland's third-largest Bitcoin exchange in 2011. During a server restart, the AWS EC2 virtual machine hosting their wallet.dat file was wiped with no backup. All 17,000 BTC in user wallets became permanently inaccessible. Mt. Gox later acquired the insolvent exchange and covered the losses - one of the few cases where affected users didn't ultimately lose funds. A cautionary tale of storing hot wallet files on ephemeral cloud instances with no redundancy.
Japanese exchange operated by the DMM Group. In May 2024, 4,502 BTC (~$320M) was stolen in a sophisticated attack linked to North Korea's Lazarus Group. Despite raising $320M in funding to shore up the exchange and protect customers, DMM Bitcoin was unable to sustain operations. In December 2025 the exchange announced it would shut down and transfer all customer accounts to SBI VC Trade, a subsidiary of financial conglomerate SBI Group, with the transfer completing in March 2025.
A then-minor US altcoin exchange that later grew to dominance. In early 2014 a flaw in the withdrawal code allowed a hacker to initiate multiple simultaneous withdrawals before balances could be updated - a race condition exploit. The exact BTC lost was never disclosed publicly. Poloniex absorbed the losses by reducing all customer balances by 12.3% and paid back the deficit over time. Notably, the exchange survived and became one of the most used altcoin platforms until its later decline under Justin Sun's ownership.
One of the earliest known Bitcoin exchange exit scams. In October 2011, Bitcoin7 posted a message claiming hackers had broken in and stolen all user funds. The site disappeared shortly after. The domain was later found serving cryptocurrency doubling scams - widely believed to be the original operators still running new schemes. No operator was ever identified or charged. The exact BTC stolen was never disclosed.
A hash-power marketplace, not a traditional exchange, but widely used by Bitcoin miners to sell their hashing power for BTC. In December 2017, hackers compromised the payment system and drained the entire NiceHash Bitcoin wallet - 4,736 BTC worth ~$78M at the time. NiceHash suspended operations for 24 hours, confirmed the theft, and began a years-long repayment program. By 2020, the company had repaid approximately 80% of stolen funds from profits, eventually completing the repayment. One of the few platforms that fully made users whole after a hack.
One of Poland's largest cryptocurrency exchanges. In July 2019, the exchange suddenly shut down with no warning, posting only a brief notice stating it had lost its liquidity. Co-founder Tobiasz Niemiro was found dead days later in an apparent suicide. Approximately 2,300 BTC and millions in PLN owed to customers remained frozen. Polish prosecutors launched an investigation but recovery was minimal. The lack of any public explanation and the founder's death left customers with little recourse.
Every notable exchange failure, sorted chronologically. An enduring reminder that custody risk never goes away.
| Year | Exchange | Type | BTC Lost | USD at Time | Outcome |
|---|---|---|---|---|---|
| 2011 | Bitcoin7 | Exit | Unknown | Unknown | Vanished |
| 2011 | MyBitcoin | Exit Scam | 154,406 BTC | ~$1.2M | Never resolved |
| 2011 | Bitomat.pl | Accident | 17,000 BTC | ~$220K | Covered by Mt. Gox |
| 2012 | Bitcoinica | Hack | ~61,000 BTC | ~$500K | Shutdown |
| 2012 | Bitfloor | Hack | 24,000 BTC | ~$250K | Shutdown |
| 2014 | Mt. Gox | Hack | 650,000 BTC | ~$390M | Bankrupt |
| 2014 | Poloniex | Hack | ~12.3% holdings | Undisclosed | Survived - repaid |
| 2014 | Cryptsy | Hack + Fraud | 13,000 BTC | ~$9M | Bankrupt 2016 |
| 2014 | MintPal | Exit | ~3,700 BTC | ~$1.3M | Operator convicted |
| 2017 | BTC-e | Seized | ~66,000 BTC | ~$120M | Operator imprisoned |
| 2017 | Youbit | Hack ร2 | ~3,800 BTC | ~$72M | Bankrupt |
| 2017 | NiceHash | Hack | 4,736 BTC | ~$78M | Survived - repaid |
| 2019 | QuadrigaCX | Fraud | ~76,000 BTC | ~$190M | Bankrupt |
| 2019 | Cryptopia | Hack | ~$16M (mixed) | ~$16M | Liquidated |
| 2019 | Bitmarket.pl | Insolvency | ~2,300 BTC | ~$23M | Shutdown |
| 2024 | DMM Bitcoin | Hack | 4,502 BTC | ~$320M | Closed, users transferred |
Every exchange on this page failed while holding customer funds. When you leave BTC on an exchange you are an unsecured creditor, not the owner. Hardware wallets exist for a reason.
Delayed withdrawals, vague security "issues", premium prices over other exchanges, and sudden maintenance windows are all red flags. Mt. Gox, QuadrigaCX, and Cryptsy all showed these signals weeks before collapse.
Reputable exchanges now publish cryptographic proof-of-reserves. If an exchange cannot or will not prove it holds 1:1 customer funds, it may be running fractional - exactly what QuadrigaCX did for years.
BTC-e and Mt. Gox operated in regulatory grey zones. Post-Mt. Gox regulation in Japan and post-QuadrigaCX in Canada improved standards. But regulation alone doesn't prevent insider fraud.
Youbit, NiceHash, and DMM Bitcoin were all linked to North Korea's Lazarus Group. Nation-state adversaries specifically target crypto exchanges. Security budgets need to reflect this threat level.
In every case on this page, blockchain analysis revealed the truth before courts did. QuadrigaCX's fraud, Mt. Gox's slow drain, BTC-e's laundering - all visible on-chain, if you know how to look.