• Skip to primary navigation
  • Skip to main content
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe

CoinLaw » The Crypto Desk » Crypto Hacks Tracker

Crypto Hacks Tracker

Every major crypto theft we can verify, and what came back. Losses are recorded from the affected project, its regulator or a court filing, never from an aggregator, and the recovery column states whether the stolen value was actually retrieved rather than whether users were reimbursed.

30 incidents tracked · verified through 14 Aug 2026 · last verified 4 Sep 2026 · next review by 12 Nov 2026

Steven Burnett
Maintained By
Steven Burnett
Steven Burnett
Research Analyst • 246 Articles
Steven Burnett has over 15 years of experience across finance, insurance, banking, and compliance-focused industries. Known for his deep res... See full bio
LATEST POSTS:
Federal Tax Revenue by State Statistics 2026: IRS Gross Collections, Top 10 States, Donor vs Recipient
Global Systemically Important Banks Statistics 2026: Bucket Allocation and Capital Surcharges
Tariff Revenue Statistics 2026: Customs Duties and IEEPA Refunds

Incidents
30
Disclosed losses · 27 of 30 incidents
$6.3B
Recovered · where stated
$1.4B
Re-verify cycle
30day
Largest disclosed loss on this page Bybit · $1,500,000,000 (Feb 2025) Largest full recovery Poly Network · $610,000,000 returned

Latest change Coinsbuy now cites the company's own statement directly instead of a news report relaying it. Every row cites a primary. (2 Sep 2026) All changes

All records

30 incidents, newest first. Filter or search below.

What is in scope Incidents where the affected project, a regulator, or a court filing disclosed what was taken. The dollar figure is our conversion at the incident date, never a disclosed number.

30 incidents, $6.3B in disclosed losses converted at each incident date from the units the victim itself published. The most common attack route is Key compromise, in 9 of 21 incidents where the disclosure named one. 27 of 30 disclose an amount; the rest publish none, and this table leaves those cells empty rather than estimating them.

What changed 14 Aug 2026

Coinsbuy joins as the month largest confirmed exchange incident: the platform acknowledged unauthorized withdrawals on 9 August, covered client funds from reserves, and posted a 100,000 dollar bounty, while the independent tally of about 7.9 million dollars stays out of the loss column because the company never confirmed it. The Coldcard entry is re-verified: Coinkite has published its technical backgrounder on the entropy defect, still states no theft figure, and the third-party tallies now disagree with each other, TRM counting 1,816 BTC where Galaxy counts 1,596, which is exactly why this table records only what victims disclose.

What was taken is recorded as the affected project or exchange disclosed it, in the units they stated, and sits in each row’s detail; the dollar column is our own conversion at the incident date, not a disclosed figure, because a token count is fixed while its value moves. Recovery status is as stated by the project or in court filings. A vendor’s estimate never substitutes for a disclosure. Informational only, not investment advice.
Project Date Loss (USD, derived) Vector Recovery Record detail
Coinsbuy CEX 9 Aug 2026 Undisclosed Unknown Partial
What was taken
Ethereum and TRON hot-wallet assets
Amount recovered
None stated
Recovery timeline
Coinsbuy confirmed on 10 August 2026 that unauthorized withdrawals hit several platform wallets the previous day, said all affected client funds were covered from its own reserves, and offered a 100,000 dollar reward. The company neither confirmed nor disputed a total, so the loss stays Undisclosed here. For scale only: the independent investigator SpecterAnalyst tallied about 7.9 million dollars across Ethereum and TRON from three linked addresses, with proceeds moved into Monero via exchanges; ChangeNOW froze a six-figure portion, recorded as partial recovery. Reserve compensation to users is not counted as recovery. The intrusion method has not been described, so the vector stays unknown.
Primary source
Coinsbuy, "Official Statement on the August 9 Security Incident" ↗
Last confirmed
2 Sep 2026
Recent change
Source swapped from a relayed report to Coinsbuy's own statement; facts unchanged (2 Sep 2026).
Coldcard Wallet 30 Jul 2026 Undisclosed Key compromise None disclosed
What was taken
Bitcoin held in self-custody wallets whose seeds were generated on affected COLDCARD firmware
Amount recovered
None stated
Recovery timeline
Coinkite published its Coldcard Security Advisory on 30 July 2026, updated 1 August. A firmware defect present from version 4.0.1 in March 2021 through 4.1.9 inclusive routed seed generation through a predictable software randomizer rather than the hardware entropy source, leaving Mk2 and Mk3 seeds with roughly 40 bits of effective entropy against the 128 expected, which puts the resulting keys within reach of offline enumeration. Seeds made on Mk4, Mk5 and Q before the fixed releases carry about 72 bits. Fixed firmware 4.2.0 corrects new seed generation but cannot repair a seed already created, so Coinkite told affected holders to migrate funds to a newly generated seed. Seeds built with at least 50 fair, independent, private dice rolls are not considered at risk from this defect alone, and a strong unique BIP-39 passphrase adds an independent barrier, though Coinkite advises passphrase users to migrate as well. TAPSIGNER, OPENDIME and SATSCARD are unaffected. Coinkite states no theft figure and says a formal technical review is still to come, so the loss stays Undisclosed here rather than being implied as zero. For scale only, and expressly not as the recorded figure: Galaxy Research, a third-party chain-analytics firm, estimates 1,596 BTC taken from about 7,300 addresses across three confirmed waves plus 14 smaller incidents, worth more than 100 million dollars, and reports that none of the coins from those three waves have moved. This tracker records the figure the affected vendor states, and a chain-analytics estimate never substitutes for a disclosure. Re-verified 14 Aug 2026: Coinkite has published a technical backgrounder attributing the defect to a random-byte fallback introduced during a library migration, with the formal postmortem still to come, and still states no theft figure, so the loss stays Undisclosed. Third-party tallies keep moving and disagree with each other, TRM Labs counting 1,816 BTC from more than 5,200 addresses across four waves while Galaxy counts 1,596 BTC from about 7,300 addresses, which is exactly why an analytics estimate never substitutes for a disclosure here.
Primary source
Coinkite, "Coldcard Security Advisory" ↗
Last confirmed
14 Aug 2026
Bitcoin Depot Other 23 Mar 2026 $3,665,000 Key compromise None disclosed
What was taken
50.903 BTC from company-controlled settlement wallets
Amount recovered
None stated
Recovery timeline
Bitcoin Depot, the crypto ATM operator, discovered on 23 March 2026 that an unauthorized actor had obtained control of credentials for its digital asset settlement accounts and transferred approximately 50.903 Bitcoin from company-controlled wallets. The company determined the incident material on 6 April and filed its 8-K, recording a preliminary loss of approximately 3.665 million dollars, the fair value of the Bitcoin at the incident date, which is the figure stored here per the company own filing. The 8-K states the incident was contained to the corporate environment, with no evidence customer personal information was accessed, and no recovery is reported. Read from the filing text directly, 14 Aug 2026.
Primary source
Bitcoin Depot, Form 8-K (Item 1.05) ↗
Last confirmed
14 Aug 2026
Cetus Protocol DeFi 22 May 2025 $223,000,000unconfirmed Smart-contract bug Partial
What was taken
Liquidity pool assets on Sui, with USDC bridged out via CCTP
Amount recovered
$162,000,000
Recovery timeline
An arithmetic overflow in the liquidity-pool maths let the attacker drain roughly USD 223 million on 22 May 2025. Cetus paused its contracts and, with the Sui Foundation and validators, froze USD 162 million before it could move. A recovery route with no precedent followed: an onchain community vote, carried by validators representing 90.9 per cent of stake, authorised a protocol upgrade reclaiming the frozen funds from the attacker's accounts WITHOUT their signature, into a 4-of-6 multisig trust held by Cetus, the Sui Foundation and OtterSec. About USD 61 million had already been bridged to Ethereum and is treated as lost.
Primary source
Sui Foundation, "Response to the Cetus Incident – Onchain Community Vote" ↗
Last confirmed
4 Sep 2026
Recent change
Cetus own recovery plan calls it only a large amount of tokens; its Q2 report and docs give no figure. The 223m and 162m are not traceable to a primary source.
Bybit CEX 21 Feb 2025 $1,500,000,000 Phishing Partial
What was taken
ETH and staked-ETH derivatives from a cold wallet
Amount recovered
$43,000,000
Recovery timeline
Signers approved a transaction through a manipulated Safe multisig interface, handing control of a cold wallet to the attacker. The FBI attributed the theft to North Korea. mETH Protocol retrieved roughly USD 43 million of cmETH, Tether froze USDT linked to the funds, and a seizure followed in Greece; the LazarusBounty programme continues to pay for traces. Bybit met customer withdrawals from its own reserves and loans, which is not counted as recovery here — the bulk of the stolen value remains with the attacker.
Primary source
FBI, "North Korea Responsible for $1.5 Billion Bybit Hack" ↗
Last confirmed
4 Sep 2026
Recent change
Cross-checked 4 Sep 2026 vs Bybit own LazarusBounty: 1.4bn total, 75.5m frozen, 1.29bn gone dark. Frozen is not recovered. The 43m is the mETH cmETH retrieval, absent from the cited FBI alert.
WazirX CEX 18 Jul 2024 $230,000,000 Phishing None disclosed
What was taken
ETH and ERC-20 tokens from the exchange Ethereum multisig
Amount recovered
None stated
Recovery timeline
WazirX own preliminary report, published the day of the attack, states a loss of funds exceeding USD 230 million from a six-signatory multisig run on Liminal custody infrastructure; the stored figure is that stated floor. Signers approved what the interface showed while the actual payload upgraded the wallet to a malicious contract, the same manipulated-signing class as the Bybit theft. No recovery from the attacker; parent Zettai obtained a Singapore moratorium (HC/OA 861/2024) and restructured user claims under a scheme of arrangement, which redistributes the loss rather than recovering it.
Primary source
WazirX, "Preliminary Report: Cyber Attack on WazirX Multisig Wallet" ↗
Last confirmed
3 Sep 2026
DMM Bitcoin CEX 31 May 2024 $308,000,000 Key compromise None disclosed
What was taken
4,502.9 BTC leaked from exchange wallets
Amount recovered
None stated
Recovery timeline
DMM Bitcoin disclosed an unauthorised outflow of 4,502.9 BTC on 31 May 2024 and covered customer balances in full with support from DMM group companies — a reimbursement, not a recovery. None of the stolen bitcoin came back: it was mixed through CoinJoin, moved across bridging services and traced onward to the Huione Guarantee marketplace. Japan's Financial Services Agency issued an administrative action in September 2024, and DMM Bitcoin wound down, transferring accounts to SBI VC Trade by March 2025.
Primary source
DMM Bitcoin, first report on the unauthorised outflow (archived) ↗
Last confirmed
4 Sep 2026
Recent change
Re-sourced to DMM own archived first report: 4,502.9 BTC, about 48.2bn yen. The 308m USD is that at the incident-date rate. Recovery none: customers repaid from group funds, not retrieval.
Orbit Chain Bridge 31 Dec 2023 $81,500,000 Unknown None disclosed
What was taken
ETH, WBTC, USDT, USDC and DAI from the Orbit Bridge Ethereum vault
Amount recovered
None stated
Recovery timeline
Six transactions from 20:52 UTC on 31 December 2023 (1 January 2024, 5:52 a.m. KST) drained about $81.5 million, per Ozys, the bridge's developer. Its statement rules out a smart-contract vulnerability and a validator-key theft and discloses that a departing security officer had weakened firewall policies on 22 November; the cause is otherwise undetermined publicly. Korea's NIS, National Police Agency and KISA investigated. No recovery has been disclosed.
Primary source
Ozys, "Official Statement Regarding 'Orbit Bridge Exploit'" ↗
Last confirmed
2 Sep 2026
KyberSwap DeFi 22 Nov 2023 $55,234,535 Smart-contract bug Partial
What was taken
Elastic pool liquidity: WETH, wstETH, USDC, ARB, cbETH and 30+ tokens across Ethereum, Polygon, Arbitrum, Optimism, Avalanche and Base
Amount recovered
$5,876,336
Recovery timeline
Kyber's post-mortem puts the theft at $55.2 million taken from Elastic pools ($48.7M by the primary exploiter, $6.6M by front-run bots), through a rounding-error defect in the tick-based swap math that audits had missed. Front-run bot operators returned about $5.17M under a 10% bounty agreement and $706K of locked pool assets was recovered; the primary exploiter's takings remain unrecovered. Treasury grants that covered 100% of unrecovered user losses were Kyber's own funds, not recovered assets, and are not counted here.
Primary source
KyberSwap, "KyberSwap Elastic Exploit Post Mortem" ↗
Last confirmed
2 Sep 2026
HTX CEX 22 Nov 2023 $30,000,000 Unknown None disclosed
What was taken
HTX hot-wallet assets; the exchange did not itemize the tokens taken
Amount recovered
None stated
Recovery timeline
HTX's notice of 22 November 2023, 13:38 UTC, put the affected hot-wallet assets at about $30 million and pledged full compensation from the exchange. The same attack hit the Heco Chain bridge gateway; neither HTX nor Heco has published a loss figure for the bridge, so no Heco amount is recorded here. Services resumed from 25 November. No recovery of the stolen funds has been disclosed.
Primary source
HTX, "HTX and HECO Chain Undergo Cyberattack" ↗
Last confirmed
2 Sep 2026
Poloniex CEX 10 Nov 2023 $126,000,000unconfirmed Key compromise Partial
What was taken
Assets across ETH, BTC, TRON and XRP hot wallets
Amount recovered
None stated
Recovery timeline
Hot wallets across several chains were drained on 10 November 2023. Poloniex stated it had identified and frozen a portion of the assets held at the attacker's addresses and offered a 5 per cent white-hat bounty for the return of the rest. The frozen portion has not been quantified publicly, so no recovered figure is recorded. Poloniex separately committed to reimbursing affected users from operating revenue, which is not counted as recovery here.
Primary source
Poloniex, "Announcement on Poloniex Hack Incident" ↗
Last confirmed
4 Sep 2026
Recent change
Poloniex own announcement says only that losses are within manageable limits, and no follow-up exists. The 126m is not traceable to a primary source.
Mixin Network Other 23 Sep 2023 $200,000,000 Unknown None disclosed
What was taken
Mainnet assets held by the network
Amount recovered
None stated
Recovery timeline
Mixin announcement, read at source: in the early morning of 23 September 2023 Hong Kong time the database of the network cloud service provider was attacked, and after initial verification the funds involved are approximately 200 million US dollars, the figure stored here. Deposits and withdrawals were suspended; Google and SlowMist were brought in. Mixin offered a 20 million dollar bounty for return of the funds. The precise mechanism behind the database compromise and the final recovery position were never published, so vector and recovery stay unrecorded.
Primary source
Mixin Kernel announcement, 25 September 2023 ↗
Last confirmed
3 Sep 2026
CoinEx CEX 12 Sep 2023 $44,667,778 Key compromise None disclosed
What was taken
231 BTC, 4,953 ETH, 12.6M XRP, 137.1M TRX, 135,600 SOL, 29,552 BNB and 12 more assets, as itemized by CoinEx
Amount recovered
None stated
Recovery timeline
CoinEx disclosed the leaked hot-wallet private key as the preliminary cause and itemized the stolen assets on 14 September 2023. The dollar figure is our conversion of 16 of the 18 disclosed assets at 12 September 2023 daily closes; 325,430 TON and 229.3M XDAG are excluded for lack of a reliable reference price at that date. Withdrawals resumed from 21 September with new deposit addresses, and the CoinEx User Asset Security Foundation bore user losses. No recovery of the stolen assets has been disclosed.
Primary source
CoinEx, "Latest Progress of the Hacking Attack on Sep 12, 2023" ↗
Last confirmed
2 Sep 2026
Stake.com Other 4 Sep 2023 $41,000,000 Unknown None disclosed
What was taken
Funds on the Ethereum, BSC and Polygon networks, as identified by the FBI
Amount recovered
None stated
Recovery timeline
The FBI confirmed the theft on 6 September 2023, attributed it to the Lazarus Group (APT38) of the DPRK, and published the destination addresses across Ethereum, BSC, Polygon and Bitcoin. No recovery has been disclosed.
Primary source
FBI, "FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $41 Million from Stake.com" ↗
Last confirmed
2 Sep 2026
Curve Finance DeFi 30 Jul 2023 $61,700,000 Smart-contract bug Partial
What was taken
CRV/ETH, alETH, msETH and pETH pool liquidity
Amount recovered
$5,400,000
Recovery timeline
A malfunctioning reentrancy lock from Vyper compiler versions 0.2.15-0.3.0 - a compiler flaw, not Curve's own contracts - let attackers drain the pETH/ETH, msETH/ETH, alETH/ETH and CRV/ETH pools on 30 July 2023. The dollar figure sums the per-pool takings itemized by Curve DAO's risk team at exploit-time prices, about $61.7 million. The whitehat c0ffeebabe.eth returned 2,879.65 ETH (about $5.4M) the same day, and Curve stated on 11 August 2023 that 70 percent of affected funds had been recovered. An earlier version of this row carried $70M lost and $52.3M recovered from an aggregator's tally; both now follow the project's own statements.
Primary source
LlamaRisk (Curve DAO risk team), "Curve Pool Reentrancy Exploit Postmortem July 30th, 2023" ↗
Last confirmed
3 Sep 2026
Recent change
Cited postmortem states 2,879.65 ETH (about 5.4m USD) from the CRV/ETH pool was returned to Curve by c0ffeebabe.eth. Stays partial: the other affected pools are not reported as returned.
Multichain Bridge 7 Jul 2023 $127,000,000 Unknown None disclosed
What was taken
wETH, wBTC and USDC, with close to USD 120 million from the Fantom bridge alone
Amount recovered
None stated
Recovery timeline
Assets left Multichain's bridge wallet on 7 July 2023 with no exploit transaction to point to. The Singapore High Court records that over US$127 million worth of assets were moved out into other wallets, and that the CEO - taken into custody by Chinese police in May 2023, per the team, which also said it had lost access to the MPC keys - had ultimate privileges and control over the assets, contrary to the user agreement's claim of decentralized MPC control. Multichain ceased operations; the vector stays unknown because no exploit mechanism has been determined. Nothing was returned. An earlier version of this row carried $126M dated 6 July from an aggregator's tally.
Primary source
Singapore High Court, "Fantom Foundation Ltd v Multichain Foundation Ltd [2024] SGHC 173" ↗
Last confirmed
2 Sep 2026
Recent change
Re-sourced from an aggregator to the Singapore High Court judgment; loss restated $126M to $127M, date 6 to 7 July (2 Sep 2026).
Atomic Wallet Wallet 2 Jun 2023 $100,000,000 Unknown None disclosed
What was taken
User funds drained from non-custodial wallets across multiple chains
Amount recovered
None stated
Recovery timeline
Users of the non-custodial wallet reported drained balances on 2 June 2023. Atomic Wallet said fewer than 0.1 percent of active users were affected and never published its own loss total; the USD 100 million figure and the date come from the FBI, whose August 2023 press release attributes the theft to DPRK TraderTraitor actors, the group also behind Harmony Horizon and Ronin. The company has announced no reimbursement and no recovery of the stolen funds; the attack mechanism was never officially established.
Primary source
FBI, "FBI Identifies Cryptocurrency Funds Stolen by DPRK" ↗
Last confirmed
3 Sep 2026
Euler Finance DeFi 13 Mar 2023 $197,000,000 Smart-contract bug Recovered
What was taken
DAI, WBTC, stETH and USDC drawn from the lending pools
Amount recovered
$240,000,000
Recovery timeline
Flash-loan assisted exploit of the donation and liquidation logic on 13 March 2023. The exploiter returned assets in tranches through late March following negotiation with Euler Labs, and Euler recorded all recoverable funds returned on 3 April 2023. Value returned to the protocol by the exploiter; this was not an operator reimbursement.
Primary source
Euler Finance, "War & Peace: Behind the Scenes of Euler's $240M Exploit Recovery" ↗
Last confirmed
3 Sep 2026
FTX CEX 11 Nov 2022 $413,000,000 Unknown None disclosed
What was taken
Mixed digital assets drained from FTX.com and FTX US wallets
Amount recovered
None stated
Recovery timeline
Funds drained from both exchanges the night the company filed for Chapter 11. The stored figure is the debtors own accounting from their 17 January 2023 statement: 323 million dollars of FTX.com assets and 90 million of FTX US assets were subject to unauthorized third-party transfers post-petition. The attack mechanism was never officially established by the debtors, and the recovery position of those specific funds was never cleanly separated from the estate recoveries, so both stay unrecorded here rather than guessed.
Primary source
FTX Debtors, "FTX Debtors Provide Additional Information to Customers and Other Stakeholders" ↗
Last confirmed
3 Sep 2026
Mango Markets DeFi 11 Oct 2022 $110,000,000 Smart-contract bug Partial
What was taken
USDC, SOL and other collateral drawn against inflated MNGO positions
Amount recovered
$67,000,000
Recovery timeline
Avraham Eisenberg pumped MNGO across three venues so the oracle price rose more than thirteen-fold in half an hour, then borrowed against the inflated collateral. He returned roughly USD 67 million in USDC and SOL under a governance proposal the Mango DAO approved on 13 October 2022, keeping USD 47 million as a claimed bug bounty in exchange for the DAO agreeing not to pursue him. Mango added USD 25 million from its own treasury to compensate users, which is not counted as recovery here. The CFTC, SEC and Department of Justice each brought charges regardless of the DAO vote.
Primary source
CFTC, "CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 million from Ma ↗
Last confirmed
3 Sep 2026
Nomad Bridge Bridge 1 Aug 2022 $190,000,000unconfirmed Bridge exploit Partial
What was taken
WBTC, WETH, USDC and other bridged assets
Amount recovered
$37,000,000
Recovery timeline
A botched initialisation let any message prove valid, and the exploit turned into a free-for-all: over 300 addresses drained the bridge by copying the original transaction. Nomad published a recovery address and offered up to a 10 per cent bounty, treating anyone returning at least 90 per cent of what they took as a white hat. More than USD 37 million, about a fifth, came back that way.
Primary source
Nomad, "The Road to Recovery" ↗
Last confirmed
4 Sep 2026
Recent change
Cited Nomad post says the bridge was hacked for more than 186m USD and never states 190m, so the loss is marked unconfirmed. The 37m recovered IS stated by that same post.
Harmony Horizon Bridge Bridge 24 Jun 2022 $100,000,000 Key compromise None disclosed
What was taken
ETH, USDC, WBTC and other bridged assets
Amount recovered
None stated
Recovery timeline
The FBI confirmed in January 2023 that Lazarus Group actors were responsible for the theft reported on 24 June 2022. The proceeds were laundered through Tornado Cash and later through RAILGUN, and the FBI has continued to track the assets in North Korean-controlled wallets. Nothing has been returned. A Harmony proposal to mint ONE to compensate holders was rejected by its community, so there was no reimbursement either.
Primary source
FBI, "FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft" ↗
Last confirmed
3 Sep 2026
Beanstalk DeFi 17 Apr 2022 $77,000,000 Smart-contract bug None disclosed
What was taken
Non-Beanstalk user assets drained from protocol liquidity pools
Amount recovered
None stated
Recovery timeline
Beanstalk Farms own postmortem, read at source: the credit-based stablecoin protocol was attacked at 12:24 UTC on 17 April 2022, with approximately 77 million dollars of non-Beanstalk user assets stolen from its liquidity pools, the figure stored here. The attacker used a flash loan to pass a malicious governance proposal and send the funds to their own wallet; the team shut off governance, paused the protocol, and burned the remaining Beans in the exploiter contract. Larger figures circulated for total protocol impact, but the tracker records the victim stated theft. The protocol later relaunched through a community recapitalization, which is funding, not recovery.
Primary source
Beanstalk Farms, "Beanstalk Governance Exploit" ↗
Last confirmed
3 Sep 2026
Ronin Bridge Bridge 23 Mar 2022 $564,031,504 Key compromise Partial
What was taken
173,600 ETH and 25.5m USDC drained from the bridge
Amount recovered
None stated
Recovery timeline
Five of nine validator keys were compromised — four Sky Mavis validators plus the Axie DAO validator, reached through a gas-free RPC backdoor left allowlisted — letting the attacker forge withdrawals of 173,600 ETH and 25.5M USDC on 23 March 2022, undiscovered until 29 March. The FBI attributed the theft to the Lazarus Group. The dollar cell is our conversion at the 23 March close ($3,102.14 per ETH); the widely cited $625M priced the loss at the disclosure date instead. Norway's Økokrim announced in February 2023 the seizure of about NOK 60 million (roughly $5.9M) linked to the theft, and US authorities have seized further amounts; a combined recovered total exists only as an analytics-firm tally, so none is recorded. Sky Mavis reimbursed users from a $150M funding round plus balance-sheet funds — reimbursement is not counted as recovery.
Primary source
Sky Mavis / Ronin Network, "Community Alert: Ronin Validators Compromised" (archived) ↗
Last confirmed
2 Sep 2026
Recent change
Re-sourced to Ronin's own alert; loss restated $625M to $564M at the incident-date close; the $30M recovery tally (analytics firm) withdrawn (2 Sep 2026).
Wormhole Bridge 2 Feb 2022 $321,680,400 Smart-contract bug None disclosed
What was taken
120,000 wETH minted on Solana without collateral
Amount recovered
None stated
Recovery timeline
A signature-verification flaw let the attacker mint 120,000 wETH on Solana without posting collateral; Wormhole itself stated the 120k wETH figure the same day. The dollar cell is our conversion at the 2 February 2022 close ($2,680.67 per ETH). Jump Crypto replaced the full amount within roughly a day so the protocol stayed solvent, and a $10 million bounty offer to the attacker went unanswered. None of the stolen value has been recovered: users were made whole, the theft was not reversed. An earlier version of this row carried $326M cited to an aggregator.
Primary source
Wormhole, X statement of 3 February 2022 ("The wormhole network was exploited for 120k wETH") ↗
Last confirmed
2 Sep 2026
Recent change
Re-sourced to Wormhole's own statement; loss restated $326M to $321.7M at the incident-date close (2 Sep 2026).
BitMart CEX 4 Dec 2021 $150,000,000 Key compromise None disclosed
What was taken
ETH and BSC hot-wallet assets across many tokens
Amount recovered
None stated
Recovery timeline
BitMart own breach notice, read at source: a large-scale security breach on 4 December 2021 hit one ETH and one BSC hot wallet, with hackers withdrawing assets of approximately 150 million US dollars, the figure stored here; the company later attributed the breach to a stolen private key that compromised both wallets. Third-party analysts put the total nearer 196 million, but the tracker records what the victim disclosed. BitMart compensated affected users from its own funding, which is not counted as recovery; nothing is recorded as recovered from the attacker.
Primary source
BitMart, "BitMart Security Breach Update" (archived) ↗
Last confirmed
4 Sep 2026
Recent change
Re-sourced to the archived BitMart notice, which states hackers withdrew approximately 150 million USD. Recovery stays none: BitMart covered it from its own funding, which is reimbursement.
BadgerDAO DeFi 2 Dec 2021 $116,300,000 Phishing Partial
What was taken
2017 BTC, 53 DIGG, 26.56 ETH, 730 CVX
Amount recovered
$9,123,000
Recovery timeline
A malicious snippet injected into the front end via an unauthorised Cloudflare API key prompted users to grant unlimited token approvals, which the attacker then drew on. Badger paused all contracts, stranding assets the attacker had taken but not yet withdrawn. BIP 76 and 77 recovered those to a DAO multisig and BIP 78 returned them to the wallets they came from: $9.123M, which Badger states is 7% of funds lost and left 40% of affected users whole. The remaining ~$121M has not been recovered from the attacker. Treasury-funded restitution under BIP 79/80 is reimbursement, not recovery, and is excluded here.
Primary source
BadgerDAO Recovery Phase (project statement, archived) ↗
Last confirmed
3 Sep 2026
Poly Network Bridge 10 Aug 2021 $610,000,000 Bridge exploit Recovered
What was taken
ETH, BSC and Polygon assets across the cross-chain pools
Amount recovered
$610,000,000
Recovery timeline
The attacker, who used the moniker Mr. White Hat, began returning assets voluntarily the day after the exploit. Tether released 33,431,200 USDT frozen during the attack on 25 August 2021. Poly Network stated recovery of all affected user assets complete on 26 August 2021. Value returned to the protocol; this was not an operator reimbursement.
Primary source
Poly Network, "Asset Recovery Complete" ↗
Last confirmed
3 Sep 2026
KuCoin CEX 25 Sep 2020 $281,000,000unconfirmed Key compromise Partial
What was taken
BTC, ETH and a long tail of ERC-20 tokens from hot wallets
Amount recovered
$204,000,000
Recovery timeline
Hot-wallet private keys were compromised and the FBI later attributed the theft to the Lazarus Group. KuCoin put recovery at about 84 per cent, roughly USD 204 million, achieved largely by token issuers freezing or reissuing affected contracts and by exchanges blocking the laundering routes. Value returned to KuCoin rather than paid out of its own pocket, so it is counted here.
Primary source
KuCoin, "The Latest Updates About the KuCoin Security Incident" ↗
Last confirmed
4 Sep 2026
Recent change
KuCoin cited page itemises freezes, returns and disabled transfers that are not commensurable and never totals them. The 281m and 204m are not traceable to a primary source.
Coincheck CEX 26 Jan 2018 Undisclosed Unknown None disclosed
What was taken
Customer-held NEM (XEM), sent externally from the exchange
Amount recovered
None stated
Recovery timeline
The largest exchange theft of its era, recorded here on the regulator own words: Japan FSA bulletins state that on 26 January 2018 virtual currency (NEM) held by Coincheck was illicitly transmitted externally following unauthorized access, and that business-improvement orders and on-site inspections followed across the industry. Every loss and compensation figure Coincheck published was denominated in yen and XEM, and the company notices from the period are no longer online, so this row records no US dollar loss rather than a converted or second-hand one. The episode led directly to Japan revised crypto exchange regulation.
Primary source
Japan FSA, Access FSA No. 176 (administrative actions, virtual currency exchangers) ↗
Last confirmed
3 Sep 2026

No records match the current filters.

What the data shows

Every figure below comes from the verified table above, redrawn as the trends and comparisons a table cannot show.

Disclosed losses by yearSum of losses as each affected project disclosed them. Years with no verified disclosure are absent, not zero.0500M1B1.5B2B2020: $281M$281M20202021: $876M$876M20212022: $1.78B$1.78B20222023: $1.06B$1.06B20232024: $538M$538M20242025: $1.72B$1.72B20252026: $4M$4M2026
Largest incidentsLoss at disclosure, as each affected project stated it.0500M1B1.5BBybitBybit: $1.5B$1.5BPoly NetworkPoly Network: $610M$610MRonin BridgeRonin Bridge: $564M$564MFTXFTX: $413M$413MWormholeWormhole: $322M$322MDMM BitcoinDMM Bitcoin: $308M$308MKuCoinKuCoin: $281M$281MWazirXWazirX: $230M$230MCetus ProtocolCetus Protocol: $223M$223MMixin NetworkMixin Network: $200M$200M
Attack vectorsHow the funds were taken, per incident post-mortems.Unknown: 9Unknown 9Key compromise: 9Key compromise 9Smart-contract bug: 7Smart-contract bug 7Phishing: 3Phishing 3Bridge exploit: 2Bridge exploit 2
Recovery outcomesWhether anything came back, per incident.None disclosed: 17None disclosed 17Partial: 11Partial 11Recovered: 2Recovered 2
Recovered vs lost, by yearSplit by what was actually retrieved. An incident whose recovery has never been quantified sits whole in the third band rather than being guessed at, and one whose loss no primary source states sits in the fourth. Nothing is dropped, and nothing unverified is folded into a total.0500M1B1.5B2BRecovered · 2020Not recovered · 2020Recovery not established · 2020Loss not confirmed · 20202020Recovered · 2021: $0.6B$0.6BNot recovered · 2021Recovery not established · 2021Loss not confirmed · 20212021Recovered · 2022: $0.1BNot recovered · 2022Recovery not established · 2022Loss not confirmed · 20222022Recovered · 2023: $0.2B$0.2BNot recovered · 2023Recovery not established · 2023Loss not confirmed · 20232023Recovered · 2024Not recovered · 2024Recovery not established · 2024Loss not confirmed · 20242024Recovered · 2025: $0.0BNot recovered · 2025Recovery not established · 2025Loss not confirmed · 20252025Recovered · 2026Not recovered · 2026Recovery not established · 2026Loss not confirmed · 20262026RecoveredNot recoveredRecovery not establishedLoss not confirmed

Verification ledger

5 most recent of 10 logged updates
  • Coinsbuy now cites the company's own statement directly instead of a news report relaying it. Every row cites a primary. 2 Sep 2026
  • Wormhole and Ronin Bridge re-sourced to the projects' own statements; both dollar figures restated to incident-date conversions ($321.7M and $564M) and Ronin's analytics-firm recovery tally withdrawn. No aggregator-cited rows remain. 2 Sep 2026
  • Curve Finance and Multichain re-sourced from an aggregator to primaries: Curve now cites its DAO risk team's postmortem (loss restated to the $61.7M it itemizes) and Multichain the Singapore High Court judgment [2024] SGHC 173 (over $127M, 7 July 2023). 2 Sep 2026
  • Five 2023 incidents added from primary disclosures: Stake.com (FBI attribution), CoinEx, HTX, KyberSwap and Orbit Chain. The tracker now holds 30 records. 2 Sep 2026
  • Bitcoin Depot backfilled from its 6 Apr 8-K: 50.903 BTC (about 3.67 million dollars, the company own recorded fair value) taken from corporate settlement wallets via compromised credentials on 23 Mar. Surfaced while triaging the breach tracker drafts; it was filed there, but no personal data was taken, so it belongs here. 14 Aug 2026

How this tracker is maintained

Every incident passes the same checks before it appears, and recovery stays under review after.

  1. 01

    Sourced

    The loss figure is the one the affected project, exchange, or court filing states, linked on every row. A chain-analytics estimate never substitutes for a disclosure. Where no figure was disclosed, the row says Undisclosed.

  2. 02

    Dated

    Each row carries the incident date as disclosed and the date we last confirmed it.

  3. 03

    Re-checked

    Recovery status is re-verified on a 90-day cycle, because recoveries unfold for years after the headlines stop. Each status change lands in the ledger.

Where do these come from?
Project statements, exchange notices, post-mortems, and court records only, linked on every row. An absent loss figure renders as Undisclosed rather than zero, because absence is a real answer.
Why track recovery?
Most coverage ends at the loss headline. Whether funds came back, fully or partly or not at all, is the part readers rarely find, so recovery is a first-class column here, sourced from the project’s own statements and court filings.
Which incidents qualify?
Major incidents from January 2024 onward, plus canonical earlier cases kept for reference depth. Inclusion is editorial; the tracker accepts no submissions and no payment.

This is informational content and does not constitute investment advice. Loss and recovery figures reflect what the affected parties disclosed as of the stated dates and can be revised. Confirm with the linked primary source before relying on a figure.

Quoting a figure with a link to this page needs no permission. Cite it as you would any source. Reuse of the compiled dataset itself is licensed under CC BY 4.0: credit CoinLaw and link back.

Sources

  • BadgerDAO Recovery Phase (project statement, archived)
  • Beanstalk Farms, "Beanstalk Governance Exploit"
  • BitMart, "BitMart Security Breach Update" (archived)
  • Bitcoin Depot, Form 8-K (Item 1.05)
  • CFTC, "CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 million from Ma
  • CoinEx, "Latest Progress of the Hacking Attack on Sep 12, 2023"
  • Coinkite, "Coldcard Security Advisory"
  • Coinsbuy, "Official Statement on the August 9 Security Incident"
  • DMM Bitcoin, first report on the unauthorised outflow (archived)
  • Euler Finance, "War & Peace: Behind the Scenes of Euler's $240M Exploit Recovery"
  • FBI, "FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft"
  • FBI, "FBI Identifies Cryptocurrency Funds Stolen by DPRK"
  • FBI, "FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $41 Million from Stake.com"
  • FBI, "North Korea Responsible for $1.5 Billion Bybit Hack"
  • FTX Debtors, "FTX Debtors Provide Additional Information to Customers and Other Stakeholders"
  • HTX, "HTX and HECO Chain Undergo Cyberattack"
  • Japan FSA, Access FSA No. 176 (administrative actions, virtual currency exchangers)
  • KuCoin, "The Latest Updates About the KuCoin Security Incident"
  • KyberSwap, "KyberSwap Elastic Exploit Post Mortem"
  • LlamaRisk (Curve DAO risk team), "Curve Pool Reentrancy Exploit Postmortem July 30th, 2023"
  • Mixin Kernel announcement, 25 September 2023
  • Nomad, "The Road to Recovery"
  • Ozys, "Official Statement Regarding 'Orbit Bridge Exploit'"
  • Poloniex, "Announcement on Poloniex Hack Incident"
  • Poly Network, "Asset Recovery Complete"
  • Singapore High Court, "Fantom Foundation Ltd v Multichain Foundation Ltd [2024] SGHC 173"
  • Sky Mavis / Ronin Network, "Community Alert: Ronin Validators Compromised" (archived)
  • Sui Foundation, "Response to the Cetus Incident – Onchain Community Vote"
  • WazirX, "Preliminary Report: Cyber Attack on WazirX Multisig Wallet"
  • Wormhole, X statement of 3 February 2022 ("The wormhole network was exploited for 120k wETH")

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
  • Crypto Regulation Tracker
  • ETF Flow Tracker
  • Exchange Listings Tracker
  • Crypto Treasuries Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
  • Accessibility Statement
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Banking
  • Finance
  • Insurance
Cryptocurrency
AI Trading Bot Statistics
AI Trading Bot Statistics 2026: Market, Platforms and MEV Data
BMNR Stock Statistics
BMNR BitMine Stock Statistics 2026: ETH Treasury, Shares, ATM
Hyperliquid Statistics
Hyperliquid Statistics 2026: Perp DEX, TVL, and HYPE Token Data
Crypto Ownership By Generation Statistics
Crypto Ownership by Generation Statistics 2026: Gen Z vs Millennials
How Many Cryptocurrencies Are There Statistics
How Many Cryptocurrencies Are There Statistics 2026: Crypto Boom
How Many Bitcoins Are There
How Many Bitcoins Are There 2026: Growth and Circulating Supply
Payments
Remittances By Country Statistics
Remittances by Country Statistics 2026: Inflows and Cost
Cash App vs Zelle Statistics
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Venmo vs. PayPal Statistics
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Toast Statistics
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Banking
Global Systemically Important Banks Statistics
Global Systemically Important Banks Statistics 2026: Bucket Allocation and Capital Surcharges
Bank Failures Statistics
Bank Failures Statistics 2026: FDIC Data, DIF Costs, and Recent Trends
The 15 Largest Banks in the US
The 15 Largest Banks in the US in 2026: By Assets, Deposits, and Branches
N26 Statistics
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Finance
Federal Tax Revenue By State Statistics
Federal Tax Revenue by State Statistics 2026: IRS Gross Collections, Top 10 States, Donor vs Recipient
Tariff Revenue Statistics
Tariff Revenue Statistics 2026: Customs Duties and IEEPA Refunds
Emergency Fund Statistics
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain In Supply Chain Finance Statistics
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Insurance
Lemonade Insurance Statistics
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Fintech
  • Compliance
  • Finance
Cryptocurrency
Robinhood Chain Halts Block Production Outage
Robinhood Chain Halts Block Production in 14-Minute Outage
Bybit Pay Mesh Partnership
Bybit Pay Brings Direct Crypto Payments via Mesh Network
Polymarket Launches Perps With Up To 20x Leverage
Polymarket Launches Perps With Up to 20x Leverage
Sofi Kraken Payward Partnership
SoFi Partners With Payward to Link Banking, Crypto
Bybit Announces Hot Wallet Infrastructure Upgrade
Bybit Announces Hot Wallet Infrastructure Upgrade from 4th Sept
Hashkey Joins Dtcc Panel
HashKey Takes First Asian Seat on DTCC Tokenization Panel
Investments
Dag Wealth Xrp Parataxis Capital Custody
DAG Wealth Puts Client XRP to Work Without Moving Custody
Strategy Strc Dividend Rate
Strategy Confirms 12% STRC Rate in Major Dividend Update
Cantor Opens Kalshi Block Trading To 3 000 Institutions
Cantor Opens Kalshi Block Trading to 3,000 Institutions
Nvidia Eyes 500 Billion Ai War Chest With Wall Street
Nvidia Eyes $500 Billion AI War Chest With Wall Street
Bitdeer Q2 2026 Results Stock Drop
Bitdeer Stock Drops 16.82% Despite Q2 Bitcoin Output Surge
Coinhako Sbi Holdings Acquisition
SBI Holdings Acquires Coinhako Crypto Exchange
Fintech
World Launches Provekit For Zk Proofs
World Launches ProveKit for On-Device Zero-Knowledge Proofs
Kraken Lseg Tokenized Stocks Deal
LSEG and Kraken Forge Major Deal for Tokenized Shares
World ID Comes to peaqOS Robots Without Sharing Identity
World ID Comes to peaqOS Robots Without Sharing Identity
K Lab Names Nasdaq Veteran Jay Heller U S CEO
K Lab Names Nasdaq Veteran Jay Heller U.S. CEO
Citi Bitcoin Custody
Citi Launches Custody+ With Real-Time Asset Servicing, Bitcoin Ahead
Kalshi And Apex Fintech Open Predictions Market
Apex and Kalshi Open Prediction Markets to More Firms
Compliance
Bitpanda Mica Austria Fine
Bitpanda Fined €70,000 in First Austrian MiCA Penalty
Wintermute Wins Us Broker Dealer Status
Wintermute Enters US Markets With Broker-Dealer Status
Taiwan Targets Crypto Transfers Travel Rules
Taiwan’s Crypto Crackdown Raises Compliance Stakes
Bybit Lead Global Compliance Robert Loo
Bybit Poaches VARA’s Ex-Counsel to Lead Global Compliance
Robinhood Wins Uk Fca License
Robinhood Lands Key FCA Registration Before UK Crypto Rules
Circle Clears Nydfs Trust Charter
Circle Clears NYDFS Trust Charter After Decade Under BitLicense
Finance
Polymarket Seeks 20b Usd Valuation
Polymarket Targets $20B Valuation in Bold $1B Funding Push
Lsg To Operate 24 7 For Etps
London Stock Exchange Plans Overnight Trading by 2027
Avax One Regains Nasdaq Listing Compliance
AVAX One Regains Nasdaq Listing Compliance
Kraken Lets Traders Post Tokenized Stocks As Collateral
Kraken Lets Traders Post Tokenized Stocks as Collateral
Kalshi Targets Ipo After Massive Valuation
Kalshi Targets IPO After Massive Growth and $22B Valuation
Coinbase To Launch Tokenized Us Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks