← Back to Attack Methods

Cryptocurrency Exchange Hacks: What Happens to Your Funds

Exchange hacks are fundamentally different from wallet theft. The attacker didn't take your keys — the platform that held your funds on your behalf was compromised. That distinction changes every option available to you.

When a centralized exchange is hacked, users who held funds on that platform become creditors of a company in crisis. You did not lose your private keys — you never had them. You held a claim against the exchange, and now that claim is harder to collect. Understanding how these events unfold determines whether you can recover anything, and through what channel.

How Exchange Hacks Differ From Direct Wallet Theft

In a direct wallet theft, an attacker gains access to your private keys or approvals and drains your wallet. The transaction is visible on-chain immediately, and the tracing path starts at your wallet address.

In an exchange hack, the attacker compromises the exchange's hot wallets — the operational wallets the platform uses to process withdrawals. Your funds were pooled with thousands of other users' funds in those wallets. The thief didn't target you specifically. They targeted the exchange.

This creates a different set of problems:

  • You are an unsecured creditor of the exchange, not the direct victim of a traceable on-chain theft from your personal address.
  • Your claim depends on the exchange's solvency and whether it carries insurance, reserves, or can raise recovery capital.
  • The theft transactions are the exchange's to trace, not yours — though an independent investigator can still document what happened.

What Actually Happens During a Major Exchange Hack

The sequence is consistent across most large exchange incidents:

  1. Hot wallet compromise — Attackers gain access to private keys for the exchange's operational wallets, typically through compromised employee credentials, supply chain attacks on software dependencies, or direct infrastructure breaches.
  2. Rapid drain — Funds move out of exchange wallets in bulk transactions, often structured to avoid automatic circuit-breakers. This phase can complete in under an hour on fast networks.
  3. Laundering begins immediately — Stolen funds are split across dozens of wallets, bridged across chains, and routed through mixers. Professional forensic firms can often trace significant portions before they disappear into deep privacy infrastructure.
  4. Exchange suspends withdrawals — The platform freezes operations, often triggering a bank-run dynamic where users who still have funds rush to withdraw, worsening the liquidity crisis.
  5. Public disclosure — Exchanges are generally required to notify users, though the timing and completeness of disclosure varies widely.

Historical Scale

The Mt. Gox hack (2014) resulted in the loss of approximately 850,000 BTC. The Bybit hack (2025) involved roughly $1.5 billion in ETH stolen in a single operation. The Bitfinex hack (2016) recovered $3.6 billion in BTC in 2022 — six years later — through a federal law enforcement operation. Scale matters: larger hacks attract more investigative resources and international coordination.

Your Recovery Options After an Exchange Hack

Exchange Insurance or Reserve Funds

Some exchanges maintain insurance coverage (Coinbase holds FDIC insurance on USD balances, not crypto) or self-insured reserve funds (Binance's SAFU fund). Whether you receive any payout depends entirely on the exchange's financial position, the size of the hack relative to those reserves, and your account status at the time of the incident.

Insolvency and Bankruptcy Proceedings

If the exchange files for bankruptcy protection, you become a creditor in that proceeding. The FTX collapse is the most prominent recent example: creditors were eventually paid a significant percentage of their claims, but the process took over two years. Filing a proof of claim in the bankruptcy is typically required to participate in any distribution — missing this deadline bars your recovery entirely.

Class Action Litigation

Exchange hacks frequently generate class action lawsuits by affected users against the platform, its executives, and in some cases its auditors or security vendors. These suits can result in settlements but move slowly. Joining a class action costs nothing and preserves your options.

Law Enforcement and Civil Asset Recovery

If the stolen funds are traced to identifiable actors — which happens more often than the public assumes — law enforcement can seize and return assets. The DOJ's recovery of Bitfinex funds demonstrated that even cold-stored stolen crypto can be recovered years later. These recoveries depend on the quality of blockchain forensic evidence and the jurisdiction of the actors involved. See law enforcement vs civil lawsuit to understand your options, and when recovery is realistic for a broader breakdown.

What Blockchain Forensics Can Do in an Exchange Hack

An independent forensic investigation of an exchange hack serves different purposes than a direct theft investigation, but it is not useless:

  • Document your account balance at the time of the hack — a written forensic record is useful evidence in bankruptcy proceedings, class actions, and regulatory complaints.
  • Trace where the stolen funds went — even if you cannot personally enforce recovery, evidence that the funds reached a specific exchange or jurisdiction can support law enforcement referrals.
  • Identify whether the exchange's disclosures are accurate — on-chain data does not lie. An investigator can verify whether the exchange's stated hack amount and timeline match what the blockchain shows.

What to Do Immediately

If your exchange announces a hack or freeze: (1) Screenshot your account balance and all transaction history immediately, before any UI changes. (2) Download CSV exports of all transactions if the platform still allows it. (3) Record the exact date and time you learned of the incident. This documentation is your claim basis — courts and bankruptcy administrators require it.

How Exchange Hacks Differ by Platform Type

Centralized Exchanges (CEX)

You held a balance claim against the company. You have creditor rights in bankruptcy, potential insurance claims, and standing in class action litigation. The exchange had custody of your funds.

Decentralized Exchanges (DEX)

If a DEX protocol is exploited, the smart contract holding user funds is drained directly. There is no company to file a claim against. Recovery depends entirely on whether the protocol's treasury funds a reimbursement (as Wormhole did in 2022), or whether on-chain governance votes to support affected users.

DeFi Protocols and Bridges

Cross-chain bridge exploits are the largest category of DeFi hack by dollar value. Ronin Network ($625M, 2022), Nomad Bridge ($190M, 2022), and Poly Network ($611M, 2021) are prominent examples. These follow the DEX pattern: no company entity, recovery depends on the protocol's own response.

The Difference Between "Exchange Hack" and "Exchange Exit Scam"

Not every exchange disappearance is a hack. Some are deliberate fraud: the exchange was never solvent, the hack story is fabricated, and the operators have simply taken the money. The on-chain evidence distinguishes these cases. In a genuine hack, funds move in a pattern consistent with an external attacker racing to launder. In an exit scam, funds move in a controlled, unhurried pattern consistent with insiders managing a withdrawal.

This distinction matters legally because an exit scam creates personal criminal liability for the exchange operators — which is a stronger recovery path than a legitimate hack against a bankrupt entity.