Across 81 documented exchange breaches since 2011, only 40% ended with users fully reimbursed, which makes an exchange's ability to absorb a loss the single thing worth checking before you deposit.Across 81 documented exchange breaches since 2011, only 40% ended with users fully reimbursed, which makes an exchange's ability to absorb a loss the single thing worth checking before you deposit.
Learn/Spotlight/Crypto Exch...% Paid Back

Crypto Exchange Hacks: 81 Breaches, $5.1B Stolen, Only 40% Paid Back

Beginner
Sep 1, 2026Sarah Chen
0m
4
4$0.013934-9.09%
Notcoin
NOT$0.0004764+5.49%
Checkmate
CHECK$0.013391-6.06%
Across 81 documented exchange breaches since 2011, only 40% ended with users fully reimbursed, which makes an exchange's ability to absorb a loss the single thing worth checking before you deposit.
MEXC is our top pick on that measure within this comparison: Hacken's independent verification of 10 August 2026 confirmed reserve coverage above 100% on all four in-scope assets, and MEXC's own reserve page puts BTC coverage at 287.53% on the same snapshot.
The full record of all 81 incidents, with the outcome for users in every row, follows below.

Key Takeaways
  • MEXC is our top pick for custody risk in this comparison: Hacken independently verified reserve coverage above 100% on BTC, ETH, USDT and USDC on 10 August 2026, alongside a $100 million Guardian Fund.
  • We have documented 81 centralised exchange hacks across 72 platforms from June 2011 to August 2026, totalling about $5.1 billion at the value of each breach.
  • Users were fully reimbursed in only 32 of those 81 incidents, leaving 44 where someone was left short.
  • Exchanges that made users whole survived at 79%, against 26% for those that did not.
  • Cold wallet and signing failures caused 6% of incidents but 44% of the money lost, averaging about ten times more per event than hot wallet breaches.
  • MEXC is not a licensed exchange in the way Coinbase, Kraken or Gemini are in their home markets, and readers who need a regulated counterparty should weigh that first.

When an exchange is breached, the first question users ask is not how the attackers got in.
It is whether the money is coming back.
That question is surprisingly hard to answer, because almost every published list of exchange hacks records the date and the dollar figure and then stops.
The outcome, which is the part that determines whether a user lost anything at all, gets left in the footnotes or omitted entirely.
So we built the outcome into the table, and the aggregate picture it produces is the reason this page leads with a recommendation rather than ending with one.

Only 40% of Breached Exchanges Paid Users Back

This is the column most public lists leave out, and it produces the least comfortable chart on this page.
Full reimbursement happened in 32 of 81 incidents.
Users were partially reimbursed in 16 cases, received nothing in 14, and are still waiting in 14 more.
Five incidents involved no loss of user funds at all, either because the attack was caught or because it hit corporate rather than customer assets.
The trend is genuinely improving.
Insurance funds, larger balance sheets and the reputational cost of getting it wrong have all pushed in the same direction since 2018.
Even so, a depositor at a randomly chosen breached exchange has had slightly worse than even odds of being made whole.
There is one further correlation worth stating carefully.
Of the 29 exchanges whose incidents all ended in full reimbursement, 23 are still operating today, a survival rate of 79%.
Of the 43 exchanges that left users short in at least one incident, 11 are still operating, a rate of 26%.
Causation runs in both directions here and we are not claiming otherwise: strong platforms can afford to pay, and paying keeps platforms strong.
What the correlation does establish is that an exchange's willingness to absorb a loss is not charity.
It is the same underlying capacity that determines whether it is still there in three years.
The four reimbursement models that actually worked, across 81 incidents, were a pre-funded insurance pool (KuCoin), the company's own cash (Coincheck, which repaid about $440 million to all 260,000 affected customers in early 2018, at a fixed rate below the value at the time of the theft), a debt token redeemed over time (Bitfinex, which first cut every account balance by about 36% and issued BFX tokens, all of which were redeemed in dollars within eight months), and emergency third-party funding followed by independent re-verification (Bybit).
Nothing else has reliably returned money to users.

Why MEXC Is Our Top Pick on Custody Risk

Whether a breached exchange makes users whole has very little to do with how large the loss was.
It has a great deal to do with whether the platform had the balance sheet and the internal controls to absorb one before anything happened.
KuCoin covered $275 million in 2020 because it had an insurance fund already sitting there.
Bybit replenished its reserves within days in 2025 through emergency funding from trading firms, then had Hacken re-verify the position, and withdrawals stayed open throughout.
CoinBene lost a comparable sum in 2019, denied that a breach had happened, and users recovered nothing.
The uncomfortable part for anyone choosing an exchange is that you cannot tell these apart from the outside after the fact.
You have to check before you deposit, and three things are verifiable in advance.


First, reserves that a named third party has checked, on a schedule


A one-off snapshot proves nothing about the month you actually need it.
MEXC publishes proof of reserves monthly, verified independently by the blockchain security firm Hacken, which publishes each report itself rather than submitting it to MEXC for approval.
The verification dated 10 August 2026 covered BTC, ETH, USDT and USDC across 27 networks and confirmed coverage above 100% on all four.


Second, a named fund whose job is to absorb a platform-side loss


MEXC maintains a $100 million Guardian Fund set aside for exactly the kind of event catalogued on this page, separate from the futures insurance fund that covers liquidation shortfalls.
Every platform in this database that covered a loss in full had a funded reserve in place before the incident, not a commitment made afterwards.


Third, the ability to verify your own balance rather than trust a summary


MEXC's Merkle tree implementation lets any user confirm their own balance is included in the reported liabilities, and the validation tool is published as open source so the check does not depend on taking our word for it.
Here is what those reserve figures mean for a deposit, using the numbers from the August 2026 report.
MEXC reported 12,312.75 BTC in verified on-chain reserves against 4,282.20 BTC of user liabilities.
Divide one by the other and every 1 BTC a user held was backed by 2.88 BTC of reserves that Hacken confirmed MEXC controlled, by requiring a signed outgoing transaction from each address.
The USDT figure was 1,939,932,810.71 in reserves against 1,691,925,884.19 in liabilities, or 114.65%.
Both numbers sit on the public proof of reserves page with the wallet addresses attached, so the arithmetic is reproducible by anyone with a calculator.
Two honest limits belong next to that.
Hacken's own report states that a proof of reserves is a point-in-time attestation of on-chain assets and should not be treated as a comprehensive financial audit of a company's liabilities or overall financial position.
That caveat is correct, and it applies to every exchange publishing this kind of report, including ours.
The second limit is that MEXC is not a licensed exchange in the sense that Coinbase, Kraken or Gemini are licensed in their home markets, and readers who want a regulated counterparty above all else should weight that accordingly.
What a monthly independent verification does buy is the thing CoinBene's users did not have: a way to check the position yourself, before you need it.

What Counts as a Crypto Exchange Hack (and Why FTX Does Not)

Most lists of "crypto exchange hacks" quietly mix three different kinds of event, which is why their totals disagree so widely.
Defining the boundary is the first thing this database does.

Category A: centralised exchange custody breaches


An external or internal attacker gained unauthorised control of assets the exchange was holding on behalf of users.
This is the only category recorded in the table below.


Category B: DeFi protocol and decentralised exchange exploits


Ronin, Poly Network, Wormhole, Balancer, and the two largest incidents of 2026 so far, Drift Protocol in April and KelpDAO days later, all belong here.
No custodian held the funds, the failure was in smart contract or bridge logic, and the remedies available afterwards are completely different.
Including them inflates exchange totals by billions and tells a user nothing about the risk of leaving coins on an exchange account.


Category C: collapses, misappropriation and exit scams


FTX is the case that gets miscounted most often.
The roughly $477 million that left FTX wallets in November 2022 happened after the company had already filed for bankruptcy, and the $8.9 billion customer shortfall behind that collapse came from misappropriation rather than intrusion.
Thodex was an exit scam.
Zondacrypto, which stopped honouring withdrawals in 2026 after admitting that the private keys to a cold wallet holding 4,503 BTC had never been handed over during a 2021 ownership change, is a governance failure with no attacker in it at all.
The Coldcard incident of July 2026 sits outside all three categories, since it drained self-custodied wallets rather than an exchange.
Category C events destroyed more user money than most Category A events, so excluding them is not a way of making the numbers look smaller.
It is a way of making them mean something.
A user deciding where to keep trading funds needs to know how often custodians get breached and what happens next, and that question only has an answer if the dataset holds one type of event.
Our guide to proof of reserves and exchange transparency deals with the Zondacrypto case in detail.

The 15 Biggest Crypto Exchange Hacks of All Time, Ranked

Ranked by value at the time of the breach, and restricted to Category A, the largest fifteen look like this.
Rank
Exchange
Date
Reported loss
Outcome for users
1
Bybit
February 2025
$1.46 billion
Fully reimbursed
2
Coincheck
January 2018
$530 million to $547 million
Fully reimbursed
3
Mt. Gox
February 2014
About $460 million
Partially reimbursed, still running
4
DMM Bitcoin
May 2024
$305 million to $320 million
Fully reimbursed, platform wound down
5
KuCoin
September 2020
$275 million to $281 million
Fully reimbursed
6
WazirX
July 2024
$235 million
Partially reimbursed, court-supervised
7
BitMart
December 2021
$150 million to $196 million
Partially reimbursed
8
BitGrail
February 2018
$146 million to $170 million
Partially reimbursed by court order
9
Poloniex
November 2023
$114 million to $126 million
Fully reimbursed
10
Liquid
August 2021
$80 million to $97 million
Fully reimbursed
11
Nobitex
June 2025
$82 million to $90 million
Unresolved
12
AscendEX
December 2021
$78 million to $80 million
Fully reimbursed
13
CoinBene
March 2019
$40 million to $105 million
Not reimbursed
14
Bitfinex
August 2016
$72 million
Fully reimbursed
15
CoinEx
September 2023
$54 million to $70 million
Fully reimbursed
Loss figures are stated at the value on the date of the incident and verified as of 28 August 2026 against mainstream media reporting and maintained blockchain security databases. Where credible sources give materially different figures, both ends of the range are shown.
Those fifteen incidents account for roughly 60% of the total value recorded in this database.
Two patterns in that table are worth pausing on.
The first is that being fully reimbursed does not mean the exchange survived, as DMM Bitcoin demonstrates: it covered the loss, then transferred its accounts to another Japanese operator and wound down anyway.
The second is that Mt. Gox is still not finished.
Twelve years after the collapse, the court-appointed trustee has extended the repayment deadline again, to 31 October 2026, with roughly 19,500 creditors repaid so far.

Crypto Exchange Hack History: All 81 Incidents, 2011 to 2026

Every Category A incident we could verify, newest first.
Date
Exchange
Jurisdiction
Reported loss at the time
Same assets today
Attack vector
Outcome for users
Platform status
15 April 2026
Grinex
Kyrgyzstan
$13 million to $15 million
n/a
Hot wallet infrastructure (the platform attributed the loss to state actors; analysts have questioned that account)
Unresolved
Closed
27 November 2025
Upbit
South Korea
$30 million
n/a
Key-inference vulnerability
Fully reimbursed
Operating
14 August 2025
BtcTurk
Turkiye
$38 million to $54 million
n/a
Hot wallet compromise (a further incident was reported in January 2026 but is not recorded in maintained security-firm databases)
Unresolved
Operating
24 July 2025
WOO X
Global
$14 million
n/a
Phishing to dev environment
No user funds lost
Operating
19 July 2025
CoinDCX
India
$44 million
n/a
Server breach
No user funds lost
Operating
16 July 2025
BigONE
Seychelles
$27 million
n/a
Supply chain (CI/CD)
Fully reimbursed
Operating
18 June 2025
Nobitex
Iran
$82 million to $90 million
n/a
Key compromise; funds burned
Unresolved
Operating
8 May 2025
BitoPro
Taiwan
$12 million
n/a
Malware
Unresolved
Operating
21 February 2025
Bybit
UAE
$1.46 billion to $1.50 billion
n/a
Cold-wallet signing compromise
Fully reimbursed
Operating
23 January 2025
Phemex
Singapore
$37 million to $85 million
n/a
Hot wallet private key
Fully reimbursed
Operating
1 January 2025
NoOnes
Global
$8 million
n/a
Bridge exploit
Unresolved
Operating
20 September 2024
BingX
Singapore
$43 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
18 July 2024
WazirX
India
$235 million
n/a
Third-party multisig custody
Partially reimbursed
Operating
22 June 2024
BtcTurk
Turkiye
$54 million to $55 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
19 June 2024
Kraken
United States
$3 million
n/a
Bug-bounty exploit
No user funds lost
Operating
31 May 2024
DMM Bitcoin
Japan
$305 million to $320 million
About $359 million (4,503 BTC)
Unauthorised outflow
Fully reimbursed
Closed
22 November 2023
HTX
Global
$30 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
10 November 2023
Poloniex
Global
$114 million to $126 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
17 October 2023
Philippines
$12 million
n/a
Suspected exploit
Unresolved
Operating
12 September 2023
CoinEx
Global
$54 million to $70 million
n/a
Hot wallet private key
Fully reimbursed
Operating
9 April 2023
GDAC
South Korea
$13 million
n/a
Hot wallet compromise
Unresolved
Closed
1 November 2022
Deribit
Global
$28 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
17 January 2022
Singapore
$34 million
n/a
2FA bypass on withdrawals
Fully reimbursed
Operating
11 December 2021
AscendEX
Singapore
$78 million to $80 million
n/a
Hot wallet compromise
Fully reimbursed
Closed
8 December 2021
LCX
Liechtenstein
$7 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
5 December 2021
BitMart
Global
$150 million to $196 million
n/a
Hot wallet private key
Partially reimbursed
Closed
19 August 2021
Liquid
Japan
$80 million to $97 million
n/a
Warm wallet compromise
Fully reimbursed
Closed
29 April 2021
Hotbit
Global
Not disclosed
n/a
Database compromise
No user funds lost
Closed
1 February 2021
Cryptopia
New Zealand
$45K
n/a
Breach during liquidation
Unresolved
Closed
23 December 2020
Livecoin
Russia
Not disclosed
n/a
Server takeover
Unresolved
Closed
21 December 2020
EXMO
United Kingdom
$4 million
n/a
Hot wallet compromise
Partially reimbursed
Operating
25 September 2020
KuCoin
Seychelles
$275 million to $281 million
n/a
Hot wallet private key
Fully reimbursed
Operating
8 September 2020
Eterbase
Slovakia
$5 million
n/a
Hot wallet compromise
Unresolved
Closed
11 July 2020
Cashaa
United Kingdom
$3 million
About $27 million (336 BTC)
Malware on withdrawal host
Unresolved
Operating
5 February 2020
Altsbit
Italy
$70K to $73K
n/a
Hot wallet compromise
Partially reimbursed
Closed
27 November 2019
Upbit
South Korea
$49 million
About $855 million (342,000 ETH)
Hot wallet compromise
Fully reimbursed
Operating
5 November 2019
VinDAX
Vietnam
$500K
n/a
Undisclosed
Unresolved
Operating
11 July 2019
Bitpoint
Japan
$32 million
n/a
Hot and cold wallet compromise
Fully reimbursed
Operating
27 June 2019
Bitrue
Singapore
$4 million to $4 million
n/a
Access-control vulnerability
Fully reimbursed
Operating
1 June 2019
GateHub
Malta
$10 million
n/a
Wallet service breach
Unresolved
Operating
7 May 2019
Binance
Global
$40 million
About $559 million (7,000 BTC)
Hot wallet, phishing and API keys
Fully reimbursed
Operating
29 March 2019
Bithumb
South Korea
$13 million to $29 million
n/a
Suspected insider
Fully reimbursed
Operating
25 March 2019
CoinBene
Singapore
$40 million to $105 million
n/a
Undisclosed; platform denied breach
Not reimbursed
Closed
24 March 2019
DragonEx
Singapore
$1 million to $7 million
n/a
Cyberattack
Partially reimbursed
Closed
15 February 2019
Coinmama
Israel
Not disclosed
n/a
Credential data breach
No user funds lost
Operating
26 January 2019
LocalBitcoins
Finland
$27K
n/a
Phishing via forum
Fully reimbursed
Closed
14 January 2019
Cryptopia
New Zealand
$16 million
n/a
Wallet compromise
Unresolved
Closed
28 October 2018
MapleChange
Canada
$51K
n/a
Suspected exit
Not reimbursed
Closed
14 September 2018
Zaif
Japan
$60 million
n/a
Hot wallet compromise
Fully reimbursed
Closed
19 June 2018
Bithumb
South Korea
$31 million
n/a
Hot wallet compromise
Fully reimbursed
Operating
10 June 2018
Coinrail
South Korea
$40 million
n/a
Undisclosed
Partially reimbursed
Closed
13 April 2018
Coinsecure
India
$4 million
n/a
Suspected insider
Not reimbursed
Closed
8 February 2018
BitGrail
Italy
$146 million to $170 million
n/a
Suspected insider and negligence
Partially reimbursed
Closed
26 January 2018
Coincheck
Japan
$530 million to $547 million
n/a
Phishing and malware to hot wallet
Fully reimbursed
Operating
20 December 2017
EtherDelta
Global
$1 million
n/a
DNS hijack
Not reimbursed
Closed
19 December 2017
Youbit
South Korea
Not disclosed
n/a
Hot wallet compromise
Partially reimbursed
Closed
5 July 2017
Bithumb
South Korea
$7 million
n/a
Employee device compromise
Partially reimbursed
Operating
22 April 2017
Yapizon
South Korea
$5 million to $5 million
About $305 million (3,816 BTC)
Hot wallet compromise
Partially reimbursed
Closed
13 October 2016
Bitcurex
Poland
$2 million
n/a
Undisclosed
Not reimbursed
Closed
2 August 2016
Bitfinex
Hong Kong
$72 million
About $10 billion (119,756 BTC)
Multisig arrangement compromise
Fully reimbursed
Operating
9 May 2016
Gatecoin
Hong Kong
$2 million
n/a
Hot wallet compromise
Not reimbursed
Closed
7 April 2016
ShapeShift
Switzerland
$200K to $230K
n/a
Insider
Fully reimbursed
Operating
14 February 2015
BTER
China
$2 million
About $572 million (7,170 BTC)
Cold wallet compromise
Partially reimbursed
Closed
14 February 2015
KipCoin
China
$728K
n/a
Server compromise
Not reimbursed
Closed
4 January 2015
Bitstamp
Luxembourg
$5 million
About $2 billion (19,000 BTC)
Social engineering to hot wallet
Fully reimbursed
Operating
2 January 2015
796 Exchange
China
$270K
n/a
Service compromise
Partially reimbursed
Closed
14 July 2014
Cryptsy
United States
$10 million
n/a
Malware backdoor
Not reimbursed
Closed
13 July 2014
MintPal
United Kingdom
$2 million to $2 million
n/a
Hot wallet compromise
Not reimbursed
Closed
4 March 2014
Poloniex
United States
$50K to $68K
About $6 million (76 BTC)
Withdrawal logic flaw
Fully reimbursed
Operating
2 March 2014
Flexcoin
Canada
$600K
About $72 million (896 BTC)
Hot wallet compromise
Not reimbursed
Closed
24 February 2014
Mt. Gox
Japan
$460 million
About $68 billion (850,000 BTC)
Multi-year compromise
Partially reimbursed
Closed
7 February 2014
Picostocks
Global
$4 million
n/a
Hot and cold wallet compromise
Not reimbursed
Closed
11 November 2013
Bitcash.cz
Czech Republic
$100K
n/a
Server compromise
Not reimbursed
Closed
7 November 2013
Inputs.io
Australia
$1 million
About $327 million (4,100 BTC)
Hosting account compromise
Not reimbursed
Closed
1 May 2013
Vircurex
Global
$352K
n/a
VPS credential compromise
Partially reimbursed
Closed
12 September 2012
Bitfloor
United States
$250K
About $2 billion (24,000 BTC)
Unencrypted key backup
Partially reimbursed
Closed
13 July 2012
Bitcoinica
Global
$300K
n/a
Third-party account compromise
Fully reimbursed
Closed
11 May 2012
Bitcoinica
Global
$87K
n/a
Server and database breach
Partially reimbursed
Closed
1 March 2012
Bitcoinica
Global
$228K
About $3 billion (43,554 BTC)
Host provider compromise
Fully reimbursed
Closed
5 October 2011
Bitcoin7
Global
Not disclosed
n/a
Server and user database breach
Not reimbursed
Closed
19 June 2011
Mt. Gox
Japan
$9 million
n/a
Auditor credential compromise
Fully reimbursed
Closed
Data verified as of 28 August 2026 against mainstream media reporting, maintained blockchain security databases and, where available, each platform's own incident disclosure. Figures are stated at the value on the date of the incident. Where credible sources give materially different totals, the range is shown rather than a single chosen figure.


2025 and 2026: The Post-Bybit Years


Several widely cited exchange-hack lists still end in mid-2024, which means they miss the largest theft in the industry's history and everything that followed it.
2025 was the worst year on record by value, with roughly $1.8 billion taken across ten incidents.
Bybit alone accounts for about 80% of that, but the other nine matter more for what they say about how attacks changed.
BitoPro lost about $11.5 million in May through malware, in an incident the exchange attributed to North Korean actors.
June brought something new: the roughly $90 million taken from Iran's Nobitex was not laundered but sent to addresses nobody controlled, destroying it as a political gesture rather than stealing it for profit.
July produced three incidents in nine days.
BigONE lost $27 million to a supply chain attack that altered server logic without touching a private key, then committed to covering user losses in full and restored trading the same day.
CoinDCX lost $44.2 million from an internal operational wallet and absorbed the entire amount from its corporate treasury, leaving customer balances untouched.
WOO X lost $14 million after a phishing attack compromised a team member's device and gave attackers access to a development environment.
August brought BtcTurk's second major breach in fourteen months, and November brought Upbit's second in six years, this time through a vulnerability that allowed private keys to be inferred.
Upbit's operator Dunamu covered the loss, froze part of the stolen funds, and restored deposits and withdrawals on 6 December.
In July 2026 South Korea's Financial Supervisory Service opened a sanctions process against Dunamu over the incident, which is a reminder that covering a loss and satisfying a regulator are two different tests.
2026 has been quieter at exchanges, though not elsewhere in crypto.
The one Category A incident so far is Grinex in April, and it is an unusual entry.
We have recorded it with that caveat attached rather than repeating the platform's account.

Attack Methods, Ranked by What They Actually Cost

The received wisdom, repeated across most write-ups of this topic, is that hot wallet compromises cause the overwhelming majority of exchange losses.
By incident count that is defensible.
By money it is wrong, and the gap between the two is the most useful finding in this dataset.
Hot and warm wallet key compromises are the most common failure at 31 of 81 incidents, and they account for 28% of value lost.
Cold wallet and signing-process failures happened five times.
Those five events account for 44% of every dollar ever taken from a centralised exchange.
The average hot wallet breach costs about $46 million; the average cold wallet or signing failure costs about $450 million, roughly ten times more.
The reason is structural rather than mysterious.
Hot wallets hold operating float, so a compromise drains what was needed for that day's withdrawals.
Cold storage holds the reserve, so when the process guarding it fails the exposure is the whole balance.
Bybit is the clearest example, and it is widely mis-described.
The February 2025 attack did not breach a hot wallet.
Attackers compromised the interface used to review and sign a routine transfer out of cold storage, so the signers approved a transaction that did not do what their screen said it did.
WazirX in 2024 failed the same way through a third-party multisig custody arrangement, and Coincheck in 2018 lost $530 million because it had kept an enormous NEM balance in a single hot wallet with no multisignature protection at all.
The third pattern worth naming is that attacks have moved off-chain.
BigONE's attackers changed server logic without stealing a key.
WOO X's attackers phished a laptop.
CoinDCX's attackers compromised an internal operational account.
None of those required finding a flaw in a blockchain or a smart contract, which is why an exchange's operational security now matters more to a depositor than its cryptography.

What the Same Coins Would Be Worth Now

Because most early thefts were denominated in bitcoin, the historical loss figures understate what was actually taken by an enormous margin.
Mt. Gox lost about $460 million in 2014.
The same 850,000 BTC would be worth roughly $68 billion today.
Bitfloor's 24,000 BTC was written off as a $250,000 loss in 2012 and would now be about $1.9 billion.
Bitcoinica's March 2012 breach of 43,554 BTC was reported at $228,000 and would now stand at roughly $3.5 billion.
This is not a scoreboard, and it is not an argument that those users were robbed of today's prices.
It is a reminder that custody decisions compound in the same direction as prices do.

Which Exchanges Have Never Been Hacked? What That Claim Is Worth

Several large exchanges have never disclosed a custody breach, and the marketing language around that fact deserves a closer look than it usually gets.
Coinbase has operated since 2012 without a reported platform-level theft of customer assets, though it disclosed a customer data breach in May 2025 involving bribed overseas support contractors.
Kraken is frequently described as never having been hacked, which is close to true but not exactly true.
In June 2024 a security researcher reported a deposit-crediting flaw to Kraken's bug bounty programme, then shared it with two others who withdrew about $3 million from Kraken's own treasury.
Kraken's chief security officer said the parties refused to return the funds and publicly called the demand extortion, the security firm CertiK disputed that account, and the funds were returned days later.
No customer lost funds, the bug was patched in 47 minutes, and the incident is in our table because a clean record that quietly omits it is less credible than one that includes it.
Gemini has likewise reported no custody breach, though users of its Earn product lost access to funds through the bankruptcy of a third-party lending partner, which is a Category C event and not a hack.
MEXC belongs in the same paragraph, held to the same standard.
MEXC has operated since 2018 and has not disclosed a comparable custody loss, and as of 28 August 2026 no platform-level custody breach at MEXC has been publicly reported or documented by mainstream media or by the maintained blockchain security databases used to compile this page.
That is a checkable statement rather than a promise, and it is the only form the claim should ever take.
An absence of incidents is evidence about the past.
Coincheck, Bybit and KuCoin all had clean records right up until the morning they did not.


How to Check an Exchange Before You Deposit

The three checks below take about ten minutes and would have flagged the weakest platforms in this database in advance.
  1. Find the reserve report and check its date. A proof of reserves page with a snapshot from this month is meaningful; one from last year is decoration. Look for a named auditor rather than a self-published figure.
  2. Do the arithmetic yourself. Divide reported reserves by reported user liabilities for each asset you hold. If the page shows a percentage but not the two numbers behind it, that is the finding.
  3. Look for a named loss-absorbing fund and its size. Look for a published figure, not a general statement that an insurance fund exists.
A reserve page worth trusting shows the snapshot date, both underlying numbers and the wallet addresses, as above.
Two further signals separate small platforms worth using from ones that are not.
Check whether an independent tracker covers the exchange at all, because a venue no third party has assessed cannot be checked by any method available to a retail user, a problem examined in our guides to vetting an untracked exchange and to platforms operating after a regulator has issued an alert.
Then check what the platform said and did after its own incident, if it had one, since the response record is often more informative than the incident itself.
Our review of BigONE and its alternatives works through exactly that comparison for a platform that was breached and then paid.

Our View: Why an Exchange Publishes a Hack Database

We publish this database as an exchange, which means readers are entitled to ask what we get out of it.
The honest answer is that a complete and accurate record of custody failures makes the case for verifiable reserves better than any marketing page we could write, and MEXC has verifiable reserves.
That is also why the concessions on this page are real.
MEXC is not a licensed exchange in the way several platforms with weaker fee structures are, and for a reader whose first requirement is a regulated counterparty in their own jurisdiction, that consideration outranks everything else on this page.
Proof of reserves is a point-in-time attestation and not a full audit, as our own auditor states in writing.
And a clean incident record, ours included, is a description of what has happened rather than a guarantee about what will.
What we will stand behind is narrower and more useful: the reserve position is published monthly, verified by a named third party that publishes independently, and reproducible by any user with a calculator.
Those are the properties that separated the exchanges in the "fully reimbursed" column from the ones in the "not reimbursed" column, over 81 incidents and fifteen years.


Methodology and Update Policy

Incidents qualify for this database when an attacker gained unauthorised control of assets held by a centralised exchange on behalf of users, and the event was reported by a mainstream news organisation, a named blockchain security firm, or the platform itself.
Loss figures are stated at the value on the date of the incident.
Source priority runs from the exchange's own post-incident disclosure, to maintained databases from named security firms including SlowMist, Elliptic, Chainalysis and TRM Labs, to mainstream reporting citing named on-chain analysts.
Where those sources differ by more than 15%, we publish the range and do not choose a figure.
Twenty-four incidents currently carry a range for that reason.
Records before 2016 rest on contemporaneous reporting of uneven quality, and several widely cited public databases carry dates for that era that contradict the reports they cite.
Where we found such a conflict we followed the underlying report, which is why some dates here differ from other published timelines.
One reported incident is deliberately absent: a January 2026 breach at BtcTurk was covered by several outlets citing a security firm, but it does not appear in the maintained databases we rely on and its details closely mirror the confirmed August 2025 event.
We will add it if primary sourcing emerges.
This page is reviewed quarterly and updated within 48 hours of a confirmed incident.
Corrections and additions are welcome, and documented ones are incorporated at the next review.

Frequently Asked Questions

How many crypto exchanges have been hacked?
We have documented 81 centralised exchange security incidents between June 2011 and August 2026.
They involved 72 distinct platforms, since seven were breached more than once.


What is the biggest crypto exchange hack ever?
Bybit, on 21 February 2025, at about $1.46 billion.
Attackers compromised the signing interface for a cold wallet transfer rather than a hot wallet.


Which crypto exchanges were hacked in 2025 and 2026?
In 2025: Phemex, Bybit, BitoPro, Nobitex, BigONE, CoinDCX, WOO X, BtcTurk, Upbit and NoOnes.
In 2026 so far, one confirmed exchange incident: Grinex in April.


Do exchanges pay users back after a hack?
Sometimes.
Users were fully reimbursed in 32 of 81 incidents, so it is closer to a coin flip than most people assume, and you can check an exchange's reserve position before finding out.


Which crypto exchanges have never been hacked?
Coinbase, Gemini and MEXC have disclosed no platform-level custody breach as of August 2026.
Kraken's 2024 incident took $3 million from its own treasury, not customer funds, and the sum was returned after a public dispute.
A clean record describes the past and does not predict the future.


How can I tell if an exchange is safe before depositing?
Check for a dated proof of reserves report from a named third-party auditor, then divide the reported reserves by the reported liabilities yourself.
Confirm a loss-absorbing fund exists and has a published figure attached.


Was FTX a hack?
Not primarily.
About $477 million left FTX wallets after the bankruptcy filing, but the $8.9 billion customer shortfall came from misappropriation, so FTX is excluded from this database.


Are hot wallets or cold wallets the bigger risk?
Hot wallet compromises are far more frequent, at 31 of 81 incidents.
Cold wallet and signing failures are rarer but roughly ten times more expensive per event.


Risk Warning and Regional Notice

This page is a historical record and is not a security guarantee for any platform named on it, including MEXC.
Holding assets on any centralised exchange means accepting custody risk that self-custody does not carry, and proof of reserves reduces that risk without eliminating it.
This article is informational for readers in the United States and the United Kingdom, where the platforms discussed may not be available or authorised.
Readers in the European Economic Area should note that MEXC is not authorised under MiCA and appears on the European Securities and Markets Authority register of non-compliant entities following a Dutch AFM decision of 24 September 2025.
Readers in Japan should note that MEXC is not registered with the Financial Services Agency and appears on its list of unregistered operators.
Nothing here is investment advice, and reserve figures, fund sizes and platform availability change, so confirm current terms on official pages before trading.

Verify Before You Deposit

The one habit that separates users who kept their money from users who did not is checking the reserve position before it matters rather than after.
Market Opportunity
4 Logo
4 Price(4)
$0.013934
$0.013934$0.013934
-12.73%
USD
4 (4) Live Price Chart
This article is provided by Sarah Chen for informational purposes only and does not constitute financial or investment advice. Cryptocurrency markets involve significant risk. Please conduct independent research or consult a qualified professional before making any investment decisions. The views expressed do not necessarily represent those of MEXC or its affiliates.

Popular Articles

View More
Nebius Customer Commitments Explained: $40B+ Commitments, RPO and Customer Prepayments

Nebius Customer Commitments Explained: $40B+ Commitments, RPO and Customer Prepayments

Summary Nebius now has several numbers that are large enough to be easily confused. $582.3 million $37.5 billion more than $40 billion billions of dollars of customer prepayments They are not

How to DCA Into NBISON on MEXC: A Step-by-Step Spot DCA Guide

How to DCA Into NBISON on MEXC: A Step-by-Step Spot DCA Guide

Summary Nebius presents a classic DCA dilemma. The company is growing extremely fast. Q2 2026 group revenue increased 454% year over year, and AI Cloud revenue increased 514%. At the same time,

MEXC Global Card vs MEXC Card (APAC) vs MEXC Ether.Fi Card: Which Crypto Visa Card Is Right for You?

MEXC Global Card vs MEXC Card (APAC) vs MEXC Ether.Fi Card: Which Crypto Visa Card Is Right for You?

From August 31, 2026, MEXC's card lineup has three Visa cards, not two: two issued by MEXC and one co-branded card issued through ether.fi. The MEXC Global Card and the MEXC Card (APAC) are custodial

Sberbank Crypto Explained: Russia's Largest Bank Sees a $46 Billion First-Year Trading Market

Sberbank Crypto Explained: Russia's Largest Bank Sees a $46 Billion First-Year Trading Market

Russia's new regulated crypto market is beginning to take shape, and one of its most important participants may be a traditional bank. Sberbank, Russia's largest lender, expects cryptocurrency

Hot Crypto Updates

View More
Why Is Robinhood Stock Up? Agentic Trading, Banking Growth and a Mystery Product Teaser

Why Is Robinhood Stock Up? Agentic Trading, Banking Growth and a Mystery Product Teaser

Overview Retail financial technology and brokerage platform Robinhood (NASDAQ: HOOD) experienced notable upward momentum during overnight trading sessions, jumping nearly 3% before consolidating

What Is the BLAKE2b Bitcoin Fork? Everything You Need to Know

What Is the BLAKE2b Bitcoin Fork? Everything You Need to Know

If you’ve seen headlines this week about a “new Bitcoin fork” and felt a jolt of panic, or maybe excitement about free coins, take a breath first. A group of developers is attempting to launch a

Will the Fed Hike Rates in September? What It Means for Bitcoin?

Will the Fed Hike Rates in September? What It Means for Bitcoin?

On August 28, new Fed Chair Kevin Warsh gave a speech that sounded nothing like his predecessor. No forward commitments, no soft guidance, just a hard inflation benchmark the current data hasn't met

MEXC Alpha Trader – Industry Daily (September 1, 2026)

MEXC Alpha Trader – Industry Daily (September 1, 2026)

I. Macro & Market Sentiment (Market Data) · BTC Price: $78,381 (24h +0.94%) · Funding Rate: +0.0073% · Fear & Greed Index: 75 (Greed) (Key Event Preview) · This Friday (September 5), the U.S. will

Trending News

View More
Coldcard Mk3 Warning Follows $38M Bitcoin Sweep, but Cause Remains Unconfirmed

Coldcard Mk3 Warning Follows $38M Bitcoin Sweep, but Cause Remains Unconfirmed

Bitcoin hardware wallet maker Coinkite has warned users about a seed-generation issue affecting Coldcard devices, including every Mk3 firmware version from 4.0.1 onward. The warning emerged as securit

BIP-110 Bitcoin fork stalls after two blocks

BIP-110 Bitcoin fork stalls after two blocks

The BIP-110 Bitcoin fork began at block 961,632 after nodes enforcing the proposal started rejecting blocks that did not signal support through version bit 4. This rule divergence produced a minority

Grayscale Zcash Trust Seeks NYSE Arca Listing

Grayscale Zcash Trust Seeks NYSE Arca Listing

Grayscale Investments has advanced its effort to move the Grayscale Zcash Trust toward an exchange-listed structure, filing Amendment No. 4 to its Form S-3 registration statement on August 18, 2026. T

Pons Trading Volume Passes $4 Billion on Robinhood Chain

Pons Trading Volume Passes $4 Billion on Robinhood Chain

Pons has passed $4 billion in cumulative trading volume on Robinhood Chain, but fee revenue and repeat activity matter more for PONS.

Related Articles

View More
Best OKX Alternatives Compared: 8 Platforms, 6 Verified Numbers, One Answer

Best OKX Alternatives Compared: 8 Platforms, 6 Verified Numbers, One Answer

For traders outside the European Union, United Kingdom and United States, MEXC is our top pick among the OKX alternatives in this comparison, on two verified numbers: 0.0000% spot maker fees against O

Best Coinbase Alternatives: 9 Exchanges Ranked by Published Fees

Best Coinbase Alternatives: 9 Exchanges Ranked by Published Fees

MEXC is our top pick among Coinbase alternatives in this comparison, on two measures you can check yourself: a published spot rate of 0.0000% maker and 0.0500% taker, and roughly four times as many li

Best Crypto.com Alternatives 2026: Which Platform Actually Costs Less Per Trade?

Best Crypto.com Alternatives 2026: Which Platform Actually Costs Less Per Trade?

MEXC is our top pick among Crypto.com alternatives in this comparison, on the one axis you can check before opening any account: published spot trading cost, at 0.0000% maker and 0.0000% to 0.0500% ta

Best Bybit Alternatives 2026: 6 Derivatives Platforms Ranked on Fees, Contracts and Reserves

Best Bybit Alternatives 2026: 6 Derivatives Platforms Ranked on Fees, Contracts and Reserves

MEXC is our top pick as a Bybit alternative for perpetual futures within this comparison, on two measures: 0.020% taker on BTCUSDT against Bybit's 0.055% on its own published schedule, and more than 1

Sign Up on MEXC
Sign Up & Receive Up to 10,000 USDT Bonus
Find Your Ideal MEXC Card
Find Your Ideal MEXC CardFind Your Ideal MEXC Card
Global for travel. APAC for daily. ether.fi to HODL.