{"id":37783,"date":"2022-09-16T16:56:07","date_gmt":"2022-09-16T13:56:07","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=37783"},"modified":"2025-08-29T21:28:54","modified_gmt":"2025-08-29T18:28:54","slug":"mt-gox-the-biggest-hack-in-cryptocurrency-history","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/mt-gox-the-biggest-hack-in-cryptocurrency-history\/","title":{"rendered":"Mt. Gox: the biggest hack in cryptocurrency history"},"content":{"rendered":"<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Key points<\/h2>\n<ul class=\"wp-block-list\">\n<li>Mt. Gox was one of the world\u2019s first bitcoin exchanges, launched in 2010. By early 2014 the platform accounted for about 70% of global bitcoin trading.<\/li>\n<li>In 2014 Mt. Gox shut down after a \u201chole\u201d in user balances caused by a hack was discovered. Between 2011 and 2013 attackers quietly siphoned 650,000 BTC \u2014 the largest hack in crypto history.<\/li>\n<li>Since 2018 Mt. Gox has been in civil rehabilitation, which envisages distributing the cryptocurrency remaining on the exchange to victims. Around 25,000 users filed claims.<\/li>\n<li>The organisers and perpetrators of the Mt. Gox hack remain unidentified. In the United States, former BTC\u2011e administrator Alexander Vinnik is on trial for laundering cryptocurrency stolen from Mt. Gox.<\/li>\n<\/ul>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Who founded Mt. Gox, and when<\/h2>\n<p>Mt. Gox\u2019s story did not start with cryptocurrency. In 2007 Jed McCaleb, future co\u2011founder of <a href=\"https:\/\/forklog.com\/en\/news\/what-are-ripple-and-the-cryptocurrency-xrp\">Ripple<\/a> and <a href=\"https:\/\/forklog.com\/en\/news\/what-are-the-stellar-blockchain-and-the-xlm-cryptocurrency\">Stellar<\/a>, registered mtgox.com. He launched a platform called \u201c<strong>M<\/strong>agic: <strong>T<\/strong>he <strong>G<\/strong>athering <strong>O<\/strong>nline E<strong>X<\/strong>change\u201d for trading cards from the popular fantasy game. The shortened name was Mt. Gox.<\/p>\n<p>After McCaleb learned about cryptocurrency in the summer of 2010, he decided to turn Mt. Gox into a bitcoin exchange. A year later he sold it to French developer Mark Karpeles, who lived in Japan, citing a lack of time to grow the project.<\/p>\n<p>According to <a href=\"https:\/\/www.rollingstone.com\/culture\/culture-news\/the-rise-and-fall-of-a-bitcoin-kingpin-43198\/3\/\" target=\"_blank\" rel=\"noreferrer noopener\">Rolling Stone<\/a>, Karpeles effectively acquired Mt. Gox for free. In return he was obliged to pay McCaleb 50% of profits for the first six months of ownership and 12% thereafter.<\/p>\n<p>Meanwhile Mt. Gox quickly gained popularity. In 2011 its user base already numbered tens of thousands, and by 2013 trading volume in bitcoin on the platform <a href=\"https:\/\/www.coindesk.com\/company\/mt-gox\/\" target=\"_blank\" rel=\"noreferrer noopener\">accounted for around 70%<\/a> of the global total.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Early attacks on the exchange<\/h2>\n<p>Security problems began at Mt. Gox even before the sale. As later emerged, in March 2011 Karpeles told McCaleb that about 80,000 BTC in user funds had gone missing. The issue was brushed aside. In 2020 Karpeles said the stolen funds had been moved to a blockchain address controlled by Bitcoin SV creator Craig Wright. Some <a href=\"https:\/\/decrypt.co\/32198\/did-the-mt-gox-bitcoin-hacker-finally-reveal-himself\" target=\"_blank\" rel=\"noreferrer noopener\">suggest<\/a> he was behind the subsequent hack of the platform.<\/p>\n<p>The first publicly recorded attack on Mt. Gox occurred in June 2011. Hackers <a href=\"https:\/\/venturebeat.com\/business\/popular-bitcoin-exchange-mt-gox-hacked-prices-drop-to-pennies\/\" target=\"_blank\" rel=\"noreferrer noopener\">managed to steal<\/a> at least 25,000 BTC, then worth roughly $400,000. The price of bitcoin on Mt. Gox plunged from $17 to almost zero.\u00a0<\/p>\n<p>An internal investigation concluded that attackers had compromised Jed McCaleb\u2019s old administrator account, giving them access to client funds and personal data.<\/p>\n<p>About a week after the attack Mt. Gox resumed operations. Karpeles demonstrated control over the exchange\u2019s wallets by making a confirming <a href=\"https:\/\/www.blockchain.com\/btc\/tx\/3a1b9e330d32fef1ee42f8e86420d2be978bbe0dc5862f17da9027cf9e11f8c4\" target=\"_blank\" rel=\"noreferrer noopener\">transaction<\/a> and reimbursed client losses.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Successes and new problems (2011\u20132013)<\/h2>\n<p>After the first attack, activity on Mt. Gox gradually recovered, and by 2013 it had become the world\u2019s largest venue for bitcoin trading. The company moved its head office to a prestigious Tokyo business district, and Karpeles became a prominent media spokesman for the bitcoin industry.\u00a0<\/p>\n<p>As later became clear, beneath the surface Mt. Gox was struggling. It lacked proper code quality and security controls. There was no financial accounting system to track balances and reserves. In short, no one was monitoring flows of money and cryptocurrency.<\/p>\n<p>Most Mt. Gox users were in the United States, yet the exchange had no licence to operate there. In May 2013 US authorities seized about $5m of the project\u2019s funds held at the payments service Dwolla. Mt. Gox subsequently obtained a money\u2011services licence from FinCEN.\u00a0<\/p>\n<p>In June the exchange halted US\u2011dollar deposits after Japanese bank Mizuho refused to service its accounts. Users began to complain en masse about lengthy cash withdrawals.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">The second hack and Mt. Gox\u2019s shutdown<\/h2>\n<p>In February 2014 Mt. Gox abruptly stopped bitcoin withdrawals. A press release said a bug in bitcoin\u2019s code made it possible effectively to double\u2011spend coins, which attackers used against the exchange\u2019s address. The platform then halted all withdrawals.<\/p>\n<p>By the end of the month the price of bitcoin on Mt. Gox was just 20% of the market average, a clear signal that investors believed the project could not fix its problems. On 24 February all trading was halted; hours later the website went offline. <\/p>\n<p>It later emerged that the team had discovered <a href=\"https:\/\/www.nytimes.com\/2014\/02\/25\/business\/apparent-theft-at-mt-gox-shakes-bitcoin-world.html\" target=\"_blank\" rel=\"noreferrer noopener\">the theft of roughly 750,000 BTC<\/a> from users that had gone unnoticed for years. The platform was insolvent. On 28 February Mt. Gox <a href=\"https:\/\/www.reuters.com\/article\/us-bitcoin-mtgox-bankruptcy\/mt-gox-files-for-bankruptcy-hit-with-lawsuit-idUSBREA1R0FX20140228\" target=\"_blank\" rel=\"noreferrer noopener\">announced<\/a> bankruptcy and closure.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">How many bitcoins were stolen from Mt. Gox<\/h2>\n<p>The bankruptcy filing stated that, in addition to user funds, criminals had stolen 100,000 BTC from the exchange\u2019s reserves. That brought total losses to 850,000 BTC \u2014 about 7% of the cryptocurrency\u2019s supply at the time. <\/p>\n<p>Total losses were estimated at $440m\u2013$480m. As of September 2022, with bitcoin at about $20,000, that is roughly $17bn.\u00a0<\/p>\n<p>In addition to bitcoins, $28m in fiat \u201cdisappeared\u201d from Mt. Gox\u2019s bank accounts in Japan.<\/p>\n<p>In March 2014 Mt. Gox <a href=\"https:\/\/www.reuters.com\/article\/us-bitcoin-mtgox-wallet-idUSBREA2K05N20140321\" target=\"_blank\" rel=\"noreferrer noopener\">reported<\/a> the \u201csudden\u201d discovery of about 200,000 BTC, held at an old\u2011format address used before June 2011. The address had been active only days before it was \u201cfound\u201d. This reduced total cryptocurrency losses to 650,000 BTC, though it did not save Mt. Gox from closure. <\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Details of the Mt. Gox hack<\/h2>\n<p>The second and most extensive hack of Mt. Gox stemmed from poor security and multiple management failures. According to research by WizSec, the second and largest attack began back in 2011. Specialists found that:<\/p>\n<ul class=\"wp-block-list\">\n<li>In September 2011 hackers stole the private key to Mt. Gox\u2019s hot bitcoin wallet. Using it, they gained control over users\u2019 cryptocurrency flows to the exchange;<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>With this private key, the hackers quietly but regularly drained the exchange\u2019s accounts for years;<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>In mid\u20112013, when inflows to the exchange slowed, the hackers withdrew 630,000 BTC from Mt. Gox\u2019s wallet in one go.<\/li>\n<\/ul>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">How Alexander Vinnik\u2019s arrest is linked to Mt. Gox<\/h2>\n<p>Because many Mt. Gox victims were in the United States, authorities there opened an investigation. <\/p>\n<p>In late July 2017, Greek police detained Alexander Vinnik, an administrator of the Russian crypto exchange BTC\u2011e. He was accused of laundering funds stolen from Mt. Gox. According to the US Department of Justice, the criminal organisation involving Vinnik laundered nearly 307,000 BTC of the 850,000 BTC stolen from Mt. Gox via BTC\u2011e.<\/p>\n<p>Extradition requests were sent to Greece by several countries \u2014 the United States, France and Russia. In 2020 he was extradited to France, where he was <a href=\"https:\/\/forklog.com\/en\/news\/alexander-vinnik-sentenced-to-five-years-in-prison-and-a-e100000-fine\">sentenced<\/a> to five years in prison and a \u20ac100,000 fine. In the summer of 2022 Vinnik was extradited to the United States, where he faces up to 55 years in prison.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Investigation and litigation<\/h2>\n<p>In May 2016 Kraken, the Canadian crypto exchange that assisted the investigation, completed the collection and analysis of creditors\u2019 claims. According to Kraken, 24,750 users filed for payouts.<\/p>\n<p>By decision of the Tokyo District Court, which became the main forum for the Mt. Gox case, the compensation process shifted from bankruptcy to civil rehabilitation. Under bankruptcy, creditors would have received compensation equal to assets at the time of the filing; under civil rehabilitation, they would receive \u201cphysical\u201d bitcoins or the fiat equivalent at the time of distribution. <\/p>\n<p>In February 2021 the court <a href=\"https:\/\/forklog.com\/en\/news\/court-approves-mt-gox-creditors-restitution-plan\">approved<\/a> a plan to reimburse creditors in bitcoin, and only in July 2022 did Mt. Gox trustee Nobuaki Kobayashi announce preparations for distributions. As of mid\u2011September 2022, no precise figures or dates had been set.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">What became of Mark Karpeles<\/h2>\n<p>On 1 August 2015 Japanese police arrested former Mt. Gox chief Mark Karpeles. He was charged with fraud, embezzlement and manipulating the exchange\u2019s computer system to inflate account balances.\u00a0<\/p>\n<p>In July 2016 Karpeles was released on bail of about $95,000. In March 2019 he was found guilty of falsifying records and sentenced to two years and six months\u2019 imprisonment, later suspended for four years.\u00a0<\/p>\n<p>In spring 2022 Karpeles announced plans to launch a crypto\u2011ratings agency and distribute NFTs to former Mt. Gox clients.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"819\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/mark_karpeles-min-1024x819.png\" alt=\"Mt. Gox: the biggest hack in cryptocurrency history\" class=\"wp-image-113851\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/mark_karpeles-min-1024x819.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/mark_karpeles-min-300x240.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/mark_karpeles-min-768x614.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/mark_karpeles-min.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Portrait of Mark Karpeles.<\/figcaption><\/figure>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">How much cryptocurrency remains on Mt. Gox addresses<\/h2>\n<p>Mt. Gox trustee Nobuaki Kobayashi managed to sell part of the BTC and BCH holdings in early 2018, before the shift from bankruptcy to civil rehabilitation. From April to May 2018 Kobayashi <a href=\"https:\/\/bitcoinmagazine.com\/culture\/mt-gox-trustee-confirms-he-sold-230-million-cryptocurrency\" target=\"_blank\" rel=\"noreferrer noopener\">sold<\/a> 24,658 BTC and 25,331 BCH for a total of $406m. <\/p>\n<p>According to <a href=\"https:\/\/www.cryptoground.com\/mtgox-cold-wallet-monitor\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cryptoground<\/a>, which tracks Mt. Gox wallet balances, the exchange holds a total of 137,891 BTC and 137,891 BCH \u2014 worth more than $2.3bn at prices on 15 September 2022.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">What compensation will Mt. Gox clients receive<\/h2>\n<p>Public documents do not give exact figures for bitcoin distributions to creditors. However, in 2021 a CoinLab representative <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-01-15\/coinlab-reaches-deal-with-mt-gox-trustee-over-bitcoin-claims\" target=\"_blank\" rel=\"noreferrer noopener\">said<\/a> users might receive only 0.23 BTC for each bitcoin stolen from them at Mt. Gox.<\/p>\n<p>Specialised firms later emerged offering to buy creditors\u2019 claims. For example, in late 2019 the investment group Fortress sent a letter to Mt. Gox creditors offering to purchase their claims for $5,000 per bitcoin \u2014 allowing immediate payment without waiting for the lengthy court process.<\/p>\n<p>In dollar terms, 0.23 BTC is about $4,600 at a bitcoin price of $20,000 as of 15 September 2022. When the bankruptcy was filed in 2014, the price of bitcoin <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-01-15\/coinlab-reaches-deal-with-mt-gox-trustee-over-bitcoin-claims\" target=\"_blank\" rel=\"noreferrer noopener\">was around $489<\/a>. That implies almost a tenfold gain in dollar terms, despite losing more than three\u2011quarters of bitcoin holdings. <\/p>\n<p>In autumn 2021 a compensation plan was <a href=\"https:\/\/forklog.com\/en\/news\/details-emerge-of-mt-gox-creditors-payouts\">published<\/a> and approved by the court. However, payouts to former Mt. Gox users have yet to begin.<\/p>\n<\/div>\n<div class=\"wp-block-text-wrappers-cards single_card\">\n<h2 class=\"card_label\">Further reading<\/h2>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/how-the-feds-policy-rate-affects-cryptocurrency-prices\">How does the Fed\u2019s rate affect cryptocurrency prices?<\/a><\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/is-bitcoin-digital-gold\">Is bitcoin \u201cdigital gold\u201d?<\/a><\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-bitcoin-improvement-proposal-bip\">What is a Bitcoin Improvement Proposal (BIP)?<\/a><\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/how-to-buy-bitcoin-a-step-by-step-guide-for-beginners\">How to buy bitcoin: a step\u2011by\u2011step guide for beginners<\/a><\/p>\n<p><a href=\"https:\/\/forklog.com\/en\/news\/what-are-fiat-currencies\">What is fiat money?<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Why did Mt. Gox\u2019s administrators fail to spot a years-long breach? How many bitcoins did hackers steal from users? Have the masterminds and perpetrators been found? We retrace Mt. Gox\u2019s rise and collapse in this \u201cCryptorium\u201d overview.<\/p>\n","protected":false},"author":1,"featured_media":37784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"2","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[2113],"tags":[2118,1154,928,136],"class_list":["post-37783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptorium","tag-101-trading-and-investing","tag-crimes","tag-mark-karpeles","tag-mtgox"],"aioseo_notices":[],"amp_enabled":true,"views":"143","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/37783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=37783"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/37783\/revisions"}],"predecessor-version":[{"id":37785,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/37783\/revisions\/37785"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/37784"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=37783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=37783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=37783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}