
Mt. Gox aftermath - the effect in the ecosystem
Hack attempts are a tale as old as crypto itself. Exchanges were always prime targets, as they’re a massive honeypot for hackers. While breaching such systems requires a high level of skill, the potential rewards are enormous. Recently, on our blog, we explored the details of the Mt Gox hack and subsequent creditor repayment. In this blog we will go through other significant exchange hacks, continuing from the Mt Gox breach.
The Bitfinex hack
Back in 2016, Bitfinex suffered a hack that was somewhat comparable to the one Mt. Gox went through (we've gone through that Mt. Gox aftermath on a previous blog). Around 120k BTC were stolen, from approximately 2000 users. The vast majority of these funds were since recovered by authorities, after being tracked through Dark Web marketplaces. The seizure of AlphaBay specifically leading into the perpetrators. A New York couple eventually pleaded guilty to money laundering. One of them admitted to the hack and assisting with unlocking the stolen assets.
While only funds from a few accounts were stolen, Bitfinex strangely decided to socialise the losses, citing legal reasons to do so. With this, they’ve effectively put all their customers in a 36% loss, and issued them BFX tokens at a 1$ rate as an IOU.
Remarkably, Bitfinex reimbursed all those BFX tokens out of their own pocket less than a year after the incident, using their profits to do so. They’ve effectively made their customers whole in dollar terms.
Early on, Bitfinex also allowed users to trade these losses, represented by the BFX token, into what’s called RRT’s. In short, you could either keep BFX and wait for the reimbursement that eventually happened, or trade those BFX into RRT’s and make yourself eligible to be paid out with funds recovered from the hack, if they were to be recovered.
RRT holders already received two distributions of just over 30 BTC, a larger portion of it having been from funds sent from law enforcement to Bitfinex, and the smaller one with funds that eventually ended up at Poloniex. This is obviously a very small portion of the stolen assets. With the majority of them having been recovered, it is extremely odd that law enforcement opted to only return a very tiny portion of it after all this time, further delaying distribution to RRT holders. In addition to this, authorities have also sent cash and BCH assets to Bitfinex, who promptly distributed them to RRT holders. The only people left to be made whole, as of the time of writing, are the RRT holders, who have hopes of receiving a share of the funds recovered by law enforcement.
The Coincheck hack
In early 2018, Japanese exchange Coincheck was hacked out of more than 500M NEM, worth about 40000 BTC at the time. The breach occurred after hackers sent malware via email, allowing them to infiltrate the system undetected. The breach occurred after hackers sent malware via email, allowing them to infiltrate the system undetected.
Shockingly, these coins were stored in a simple hot wallet, with minimal security measures in place.
Nevertheless, the exchange took the responsible route of refunding users. They did so in JPY, with the token’s valuation at the time of the hack, and with the community’s support.

The Binance hack
On May 7th 2019, Binance suffered a significant breach, in which they lost 7000 BTC. According to Binance, the attack was highly sophisticated, with the hackers managing to compromise user API keys and 2FA codes. The hack was executed in a very timely manner and the attackers were able to evade the withdrawal checks. However, the withdrawal did ring the alarm over at Binance, prompting them to investigate and close withdrawals.
Although the loss amounted to a substantial sum, it represented only 2% of Binance’s total BTC holdings at the time. This exchange is also renowned for its “SAFU” fund, which currently holds 1 billion USDC and can be used to reimburse users in case of a hack. This allowed for Binance to make users whole fairly easily.

Key takeaways
All these exploits through time served as crucial learning experiences for exchanges, both those affected and those who were not. They stand as stark reminders that, regardless of how large or well-structured an organization might be, it remains vulnerable to catastrophic hacks. These events were a turning point, prompting the entire industry to take significant strides in improving security practices. The advancements made since then are not only remarkable, but also vital in ensuring the continued growth and resilience of the crypto ecosystem.