Key Takeaways

  • The loss predated the panic by years. The Department of Justice indictment unsealed in June 2023 alleges attackers first breached the wallet server in September 2011 and drained it gradually until May 2014. The February 2014 withdrawal freeze exposed a hole that had already existed for roughly two and a half years.
  • Mt. Gox's public explanation did not survive scrutiny. It blamed a Bitcoin protocol flaw called transaction malleability. Researchers at ETH Zurich later examined a year of network data and found no widespread use of malleability attacks before the exchange closed.
  • The headline number moved twice. Mt. Gox first reported roughly 850,000 bitcoin missing at its February 2014 bankruptcy filing, then found about 200,000 bitcoin in an old wallet weeks later, revising the loss to roughly 650,000, a figure close to the 647,000 the 2023 indictment separately alleges was stolen.
  • The criminal case against Mark Karpeles was narrower than most people assume. Japan's Tokyo District Court acquitted him of embezzlement in 2019 and convicted him only of manipulating account data, a charge about falsifying records to inflate Mt. Gox's own holdings by roughly $33.5 million, not about the missing customer bitcoin.
  • The legal process reversed itself. Mt. Gox spent 2014 to 2018 in ordinary bankruptcy liquidation, then converted to civil rehabilitation once bitcoin's price rise meant the estate's remaining coins were worth more than creditors' frozen 2014 claims, an outcome the original bankruptcy filing could not have anticipated.
  • The mechanism is the opposite of FTX's. FTX's operators moved customer money to an affiliate on purpose. Mt. Gox's bitcoin was taken by outside attackers the exchange failed to detect for years. Both are custody failures; almost nothing else about them is the same.

What Was Mt. Gox, and How Did It Become Bitcoin's Dominant Exchange?

Mt. Gox began life with a name that has nothing to do with money: Magic: The Gathering Online eXchange, a site programmer Jed McCaleb built to trade cards from a collectible card game. McCaleb repurposed the domain for bitcoin trading in 2010, when Bitcoin itself was barely a year old and had essentially no established exchange infrastructure anywhere. He sold the business in March 2011 to Mark Karpeles, a French software developer living in Tokyo who operated it through his company, Tibanne Co. Ltd.

What followed was less a deliberate rise than an accident of timing. Bitcoin needed somewhere for a buyer and a seller to meet, and for several years Mt. Gox was, for practical purposes, where that happened. By the exchange's own account in its February 2014 bankruptcy filing, it was used overwhelmingly by customers outside Japan, and by early 2014 it was widely regarded as Bitcoin's largest and best-known exchange, a status it had held for roughly three years. A newly listed asset does not automatically get a deep, liquid, trustworthy market. Mt. Gox became the closest thing Bitcoin had to one mostly because it existed first and stayed largest, not because it had built the operational maturity that scale should have demanded.

That gap between market position and operational maturity is the throughline of this entire case. A company that started as a hobbyist card-trading site was, within a few years, holding a large share of the world's bitcoin on behalf of customers across dozens of countries, with a security and accounting apparatus that had not grown to match. Scale arrived faster than the systems needed to justify it, and nobody outside the company could tell the difference between an exchange that had earned its dominance and one that had simply been first.

What Actually Happened Inside Mt. Gox Between 2011 and 2014?

The version of events that reached the public in February 2014 was Mt. Gox's own account: a technical bug had allowed attackers to drain customer bitcoin, and the company had only just discovered the scale of the damage. The version reconstructed later, from a US federal indictment unsealed in June 2023, describes something that started years earlier and had nothing to do with the bug Mt. Gox blamed.

According to that indictment, in or about September 2011, two Russian nationals named Alexey Bilyuchenko and Aleksandr Verner, along with unnamed co-conspirators, gained unauthorized access to the server that held Mt. Gox's cryptocurrency wallets and the private keys needed to move funds out of them. Using that access, the indictment alleges, they caused bitcoin to be fraudulently transferred out of Mt. Gox's wallets to addresses they controlled, and did so repeatedly from September 2011 through at least May 2014, moving at least approximately 647,000 bitcoin in total, the vast majority of what Mt. Gox's customers were owed. These are allegations from an unsealed indictment, not a proven verdict, but they are the most detailed account of the mechanism that exists in any public document, and they line up closely with figures Mt. Gox itself later reported.

The theft's defining feature was not its size. It was its duration. A breach that moves an exchange's entire holdings in one afternoon triggers an immediate crisis, because the exchange cannot process withdrawals it cannot fund. A breach that removes a percentage of holdings at a time, spread across two and a half years, produces almost no immediate symptom, as long as new deposits and ordinary trading volume keep the appearance of liquidity intact. Mt. Gox's own internal ledger could not distinguish a real bitcoin balance from one that existed only on the company's books, which is the central mechanical fact of this collapse: for years, what Mt. Gox reported holding and what it actually held were two different numbers, and nothing in its systems caught the gap.

That distinguishes Mt. Gox from most of the exchange failures that came after it. The theft was not a decision anyone at the company made. It was a security failure the company did not detect, allegedly carried out by people entirely outside the organization.

Was the June 2011 Flash Crash the Same Hack That Sank Mt. Gox in 2014?

No, and conflating the two is one of the most common errors in how this case gets retold. Mt. Gox suffered two distinct security incidents roughly three months apart in 2011, and only one of them is the reason the exchange eventually collapsed.

The better-known incident happened first and in public. On 19 June 2011, an attacker used credentials taken from a compromised Mt. Gox auditor account to manipulate the exchange's own order book, driving the displayed bitcoin price down toward essentially zero before using that artificial price to buy bitcoin out of customer accounts. Mt. Gox halted trading, later canceled the transactions executed during the manipulated window, and treated the episode as a contained, one-time breach. It was covered extensively in the small bitcoin press that existed at the time, and it is the incident most people remember when they hear that Mt. Gox was hacked in 2011.

The incident that actually mattered happened separately, roughly three months later, and was never publicly disclosed at the time. That is the wallet-server breach the 2023 Department of Justice indictment describes, beginning in or about September 2011. Unlike the June flash crash, which was loud, visible and resolved within a trading session, the September breach was quiet and ran for years. Mt. Gox's public statements in the run-up to its 2014 collapse never mentioned a second 2011 breach at all. The company's own explanation, when the shortfall could no longer be hidden, pointed at a different cause entirely, covered next.

Why Did Mt. Gox Blame "Transaction Malleability," and Did That Explanation Hold Up?

Transaction malleability is a real property of how Bitcoin transactions were structured in this period: the unique identifier assigned to a transaction could be altered by a third party after it was broadcast but before it was confirmed, without invalidating the sender's signature or the transaction's validity. In practice, that meant someone could intercept a transaction, tweak it slightly, and rebroadcast it under a different transaction ID. If an exchange's software tracked withdrawals by that ID alone, it could conclude a withdrawal had failed and reissue it, even though the original transaction eventually confirmed. It was a genuine software design flaw, and Mt. Gox was not wrong that it existed.

What Mt. Gox claimed was much larger: that transaction malleability was the mechanism by which its bitcoin had disappeared. On 7 February 2014, the exchange suspended all bitcoin withdrawals, and on 10 February it issued a statement attributing the suspension to malleability-related attacks. Two weeks later, on 24 February, it halted trading entirely, and the website went offline hours afterward, replaced by a blank page.

Researchers Christian Decker and Roger Wattenhofer at ETH Zurich tested that explanation directly. Using traces of Bitcoin network activity spanning roughly the year before Mt. Gox's closure, published in a paper titled "Bitcoin Transaction Malleability and MtGox," they found that while the malleability flaw itself was real and exploitable, there was no widespread use of malleability attacks on the network before Mt. Gox shut down. A flaw that can theoretically be exploited is not the same as a flaw that was exploited at a scale sufficient to explain several hundred thousand missing bitcoin.

The distinction matters for how a reader should weigh a company's own explanation for its losses. Transaction malleability could plausibly explain individual customer confusion, a withdrawal that looked stuck or duplicated. It cannot explain a multi-year, multi-hundred-thousand-bitcoin shortfall traced by federal investigators to unauthorized server access. Mt. Gox reached for the explanation that implicated the Bitcoin protocol rather than the explanation that implicated its own security, and for several years that explanation was the only one on the record.

What Happened in the Weeks Before Mt. Gox Went Offline?

Unlike a same-week exchange run, Mt. Gox's visible collapse unfolded over roughly three weeks, and even that understates how long the underlying problem had existed.

Chronology of the visible collapse

Dates as reported by Reuters and The Associated Press at the time, and in the US Department of Justice indictment unsealed in June 2023.

DateWhat happened
September 2011Per the 2023 federal indictment's allegations, attackers gain unauthorized access to the server holding Mt. Gox's cryptocurrency wallets and begin transferring bitcoin out to addresses they control
7 February 2014Mt. Gox suspends all bitcoin withdrawals
10 February 2014Mt. Gox issues a statement attributing the withdrawal suspension to transaction malleability
24 February 2014Mt. Gox halts all trading; the exchange's website goes offline hours later, showing a blank page
28 February 2014Mt. Gox petitions the Tokyo District Court for reorganization protection, reporting roughly 850,000 bitcoin missing and a 2.8 billion yen bank-account discrepancy; Karpeles apologizes at a Tokyo news conference
7 March 2014Mt. Gox reports finding approximately 200,000 bitcoin in an old-format digital wallet it had used before June 2011 and believed held nothing
20 March 2014Mt. Gox publicly confirms the wallet discovery, revising its estimated total loss down to roughly 650,000 bitcoin
Early-to-mid April 2014The Tokyo District Court determines Mt. Gox cannot be rehabilitated and moves the case toward liquidation
24 April 2014Bankruptcy proceedings formally commence; attorney Nobuaki Kobayashi is appointed bankruptcy trustee; a creditors' meeting is scheduled for July 2014
May 2014The period the 2023 federal indictment identifies as the end of the alleged theft from Mt. Gox's wallets

Read against the earlier chronology, the pattern is unusual for a financial collapse: the part the public actually experienced, from the withdrawal freeze to the bankruptcy filing, took about three weeks. The part that caused it, per the federal indictment's allegations, had been running for roughly two and a half years already. Most of this case study's other lessons follow from that gap.

How Much Bitcoin Was Actually Missing, and Did Any of It Turn Up?

The number moved twice in Mt. Gox's first month of public failure, and both moves matter for understanding how uncertain the company's own accounting was.

At the 28 February 2014 court filing, Mt. Gox reported that it had lost 750,000 of its customers' bitcoin and 100,000 of its own, about 850,000 bitcoin combined. At the bitcoin price of roughly $565 that Reuters cited from the filing, that came to approximately $480 million, which Mt. Gox itself estimated at around 7 percent of all bitcoin in existence at the time. The filing also disclosed a separate discrepancy of 2.8 billion yen found in the company's bank accounts, and liabilities of 6.5 billion yen against total assets of only 3.84 billion yen. Roughly 127,000 creditors, all but about 1,000 of them outside Japan, were named in the initial bankruptcy filing.

Then, on 7 March 2014, Mt. Gox reported that a rescan of "old-format" digital wallets, a wallet structure the exchange had used before June 2011 and assumed no longer held any funds, had turned up approximately 200,000 bitcoin still sitting in one of them. Mt. Gox confirmed the discovery publicly on 20 March, valuing the recovered coins at roughly $118 million at that day's price, and revised its estimated total loss down to approximately 650,000 bitcoin.

That revised figure, about 650,000 bitcoin, sits close to the 647,000 bitcoin the Department of Justice's 2023 indictment separately alleges was stolen through the server breach, which is why the indictment's account and Mt. Gox's revised 2014 disclosure are treated as broadly consistent rather than describing two different losses. It does not mean every figure in this case is precisely reconciled: creditor and repayment figures from later in the rehabilitation process, covered further down, use different counting methods and reference dates, and this case study treats them as separate numbers rather than forcing a single reconciled total.

How Is Mt. Gox's Collapse Different From the FTX Collapse?

Both are exchange collapses. Both are crypto custody failures. Readers who know Swoopr's case study on the FTX collapse should not assume Mt. Gox is the same story with different names, because the mechanism, the actors and the timeline could hardly be more different.

FTX's failure was a decision. According to the CFTC complaint covered in the FTX case study, FTX executives built features into their own exchange code that let an affiliated trading firm, Alameda Research, borrow customer deposits without a practical limit, and Alameda spent that money. The people who caused the shortfall worked at FTX. The shortfall was, in that sense, chosen.

Mt. Gox's failure was a breach. Per the Department of Justice's 2023 indictment, outside attackers gained unauthorized access to a server and moved bitcoin out over two and a half years without Mt. Gox's knowledge. Nobody at Mt. Gox is alleged to have decided to give the attackers that access, and the criminal case against Mark Karpeles in Japan, covered further down, explicitly did not find him responsible for the theft itself.

The two also failed on entirely different clocks. FTX's public collapse took nine days from a leaked balance sheet to a bankruptcy filing, because its shortfall was created and discovered close together in time. Mt. Gox's public collapse took about three weeks, but the underlying loss had accumulated, undetected, for roughly two and a half years first. A fast collapse and a slow one can look identical once the doors close. They are not the same failure: FTX is a story about where a custodian chooses to put your money, while Mt. Gox is a story about whether a custodian can even tell you accurately what it still holds. Their endings diverge too, covered in detail below.

Which Warning Signs Were Public Before February 2014?

Some warning signs existed. None of them specified an $8 billion-scale server breach running quietly in the background, because that breach was not public information for anyone outside Mt. Gox, and per the 2023 indictment's allegations, not necessarily fully known inside the company either.

What was publicly visible, in the weeks and months before the collapse, included recurring withdrawal delays that predated the formal 7 February 2014 freeze, persistent reports of slow or failed bank transfers to and from the exchange, and the well-known 2011 flash crash, which had already demonstrated the company's security could be breached. Bitcoin's price on Mt. Gox had also begun trading at a discount to prices on other, smaller exchanges in the weeks before the freeze, a signal some market participants were already pricing in withdrawal risk before Mt. Gox said anything publicly.

None of that amounted to knowledge of the actual mechanism or its actual scale. A trader who moved funds off Mt. Gox in January 2014 because withdrawals felt slow was reacting to a real signal and made a good decision in hindsight, but that trader could not have known whether the underlying problem was a temporary bank relationship issue, a liquidity crunch, or a multi-year theft nobody had detected. The signals justified caution. They did not specify the cause, and treating them as if they had is the hindsight bias this case study is built to guard against.

How Did Japan's Bankruptcy Court Handle Mt. Gox?

Mt. Gox's Japanese legal process had two distinct phases, four years apart, and the second phase reversed the first. That reversal is unusual enough that it deserves its own explanation, covered in the next section. This section covers only the first phase.

On 28 February 2014, Mt. Gox petitioned the Tokyo District Court for the Japanese equivalent of reorganization protection, a filing Reuters described at the time as broadly comparable to Chapter 11 in the United States, though under Japanese, not American, law. The petition sought to keep the company operating while it worked out a plan to satisfy creditors, rather than shutting down and liquidating outright.

That plan did not survive contact with the court's own review. Within roughly six weeks, the Tokyo District Court determined that Mt. Gox could not realistically be rehabilitated as a going concern, and the case moved toward liquidation instead. Bankruptcy proceedings formally commenced on 24 April 2014, and the court appointed attorney Nobuaki Kobayashi as bankruptcy trustee, with the authority to investigate the company's affairs, including Karpeles's own conduct, and to sell its remaining assets on creditors' behalf. A creditors' meeting was scheduled for July 2014, and the trustee indicated that Mt. Gox's remaining assets fell well short of what creditors were owed, meaning a full recovery through ordinary bankruptcy liquidation looked unlikely at that point.

For four years, that was the trajectory: an ordinary, if unusually public, bankruptcy liquidation, expected to end with creditors recovering only a fraction of what they had lost, paid out in yen at the depressed values recorded at the 2014 filing. Then bitcoin's price did something the original filing had not anticipated, and the case reversed direction entirely.

What Is Civil Rehabilitation, and Why Did Mt. Gox Switch to It?

Civil rehabilitation is a distinct track under Japanese insolvency law, closer in spirit to a US Chapter 11 reorganization than to a straightforward liquidation, though Mt. Gox used it here for a purpose neither system was originally built around: distributing an appreciated in-kind asset to creditors rather than a fixed cash claim.

The reason the switch happened at all is almost entirely about bitcoin's price. Under ordinary bankruptcy liquidation, creditors' claims are generally fixed in yen, valued at the point the bankruptcy began, and leftover asset value reverts to the company's owners rather than to creditors. Mt. Gox's trustee, Nobuaki Kobayashi, held a substantial quantity of recovered and rediscovered bitcoin on the estate's behalf. As bitcoin's price rose far above where it had traded at the 2014 filing, that holding grew large enough to exceed creditors' original, frozen-in-2014 yen claims, meaning ordinary bankruptcy could have left a large surplus reverting away from the people the case existed to compensate.

In June 2018, the Tokyo District Court moved the case from bankruptcy liquidation to civil rehabilitation, opening the possibility of creditors recovering value tied to bitcoin's current price, potentially in bitcoin itself, rather than a fixed 2014 figure. Kobayashi, who had continued selling portions of the estate's holdings in the run-up to the conversion, reportedly liquidating close to 25,000 bitcoin and a similar quantity of bitcoin cash for roughly $230 million beforehand, paused further sales once rehabilitation began. A plan eventually approved by creditors set aside a fixed pool for distribution: roughly 141,686 bitcoin, approximately 142,846 bitcoin cash, and about 69 billion yen in cash.

The practical effect is that a Mt. Gox creditor with an approved claim could, depending on the option chosen, ultimately receive a share of bitcoin itself rather than only a cash sum frozen at 2014 values, an outcome the original bankruptcy filing gave no indication was possible. It is not, however, a full recovery. The plan covers a defined pool of assets against a defined pool of approved claims, not a guarantee of full restitution for every original loss, and coverage varies by which repayment option a given creditor selected.

What Happened to Mark Karpeles?

Karpeles was arrested in Japan in August 2015, roughly a year and a half after the bankruptcy filing, and held in pretrial detention for nearly a year, a period of incarceration his defense argued was itself excessive given the eventual verdict. He consistently maintained his innocence, telling the court in 2017 that he had "never once improperly used any funds" at Mt. Gox.

On 15 March 2019, the Tokyo District Court delivered a verdict that split sharply between the charges. Karpeles was acquitted of embezzlement and breach of trust, the charges that would have most directly tied him to the missing customer bitcoin, over prosecutors' request for a 10-year sentence. He was convicted on a narrower charge, manipulating electronic financial data, specifically an allegation that he falsified records to inflate Mt. Gox's own recorded holdings by roughly $33.5 million. The court found he had not embezzled funds but had manipulated data in a way that harmed clients and betrayed their trust, and sentenced him to two years and six months, suspended for four years, meaning no additional jail time beyond his pretrial detention. Acquittals of this kind are unusual in Japan's courts, where conviction rates exceed 99 percent, itself a signal the embezzlement case was not considered strong.

The distinction between what Karpeles was convicted of and what many people assume is worth stating plainly, since it is one of this case's most persistent points of confusion. His criminal case in Japan was not a verdict on who stole the roughly 850,000 missing bitcoin. It was a verdict on a specific, separate act of data manipulation involving his own account, a distinction Karpeles himself made in court, saying his case had nothing to do with the hack or recovering the stolen bitcoin. Who actually took the customer funds was addressed in a different country, under a different legal system, years later.

Who Were the Hackers, and Where Did the Stolen Bitcoin Go?

For nine years after Mt. Gox's collapse, no public document identified who was actually behind the theft. That changed on 9 June 2023, when the US Department of Justice unsealed an indictment in the Southern District of New York charging Russian nationals Alexey Bilyuchenko, 43, and Aleksandr Verner, 29, with conspiracy to launder approximately 647,000 bitcoin taken from the 2011 hack of Mt. Gox.

According to the indictment's allegations, Bilyuchenko, Verner and unnamed co-conspirators used the unauthorized server access described earlier in this case study to move stolen bitcoin to addresses they controlled, then laundered the bulk of it through accounts at two other online bitcoin exchanges and through a specific account on Mt. Gox itself. In one specific scheme described in the indictment, the pair allegedly entered a fraudulent advertising contract in April 2012 with a bitcoin brokerage service based in New York, using it as cover to have the broker wire more than $6.6 million to offshore accounts, including shell-company accounts, in exchange for credit on one of the two exchanges through which the group is alleged to have laundered more than 300,000 of the stolen bitcoin.

Bilyuchenko was also separately charged, in the Northern District of California, with conspiring with a third Russian national, Alexander Vinnik, to operate the BTC-e cryptocurrency exchange from 2011 until law enforcement shut it down in July 2017. A civil penalty the Financial Crimes Enforcement Network assessed against BTC-e in July 2017, $110,003,314 against the exchange and a further $12 million against Vinnik personally, found that BTC-e had processed over 300,000 bitcoin in transactions traceable to the Mt. Gox theft, alongside funds tied to ransomware, dark-net drug markets and other criminal proceeds. Vinnik was arrested in Greece the same week that penalty was announced.

What happened to each man afterward differs sharply. Vinnik was eventually extradited to the United States and, on 3 May 2024, pleaded guilty in federal court to conspiracy to commit money laundering, admitting BTC-e had enabled the laundering of at least $121 million in criminal proceeds and facing a maximum sentence of 20 years. He never reached sentencing. In February 2025, before a scheduled June 2025 sentencing date, Vinnik was released from US custody and sent to Russia as part of a prisoner exchange for an American citizen who had been detained there, forfeiting more than $100 million as a condition of the deal. As of this writing, the public record does not indicate Bilyuchenko or Verner have been apprehended, and their indictment remains, in legal terms, only a set of allegations.

Read together, this is the plainest fact this case study can offer about accountability: no one has served a US prison sentence for the theft of Mt. Gox's bitcoin. Karpeles received a suspended sentence in Japan for a narrower, separate offense. Vinnik pleaded guilty to a related laundering charge and left US custody before sentencing. The men the 2023 indictment names as the alleged hackers have not, as far as the public record shows, faced trial.

Are Mt. Gox Creditors Actually Getting Their Bitcoin Back?

Yes, in meaningful volume, though the process has been unusually slow even by the standards of complex bankruptcies, and it is still not finished as of this writing.

Under the civil rehabilitation plan described above, more than 20,000 creditors with approved claims became eligible for distributions drawn from the roughly 141,686 bitcoin and 142,846 bitcoin cash the trustee set aside, alongside a cash portion in yen. The trustee designated a small group of partner exchanges, including Kraken, Bitstamp, Bitbank, SBI VC Trade and BitGo, to receive bulk transfers of cryptocurrency on behalf of their customers among the creditor pool and handle onward distribution.

Those distributions began in July 2024, a full decade after the original collapse. Kraken and Bitbank together served roughly 13,000 of the eligible creditors, with Kraken announcing it had completed distribution of the bitcoin and bitcoin cash owed to its Mt. Gox creditor customers later that month, while Bitstamp began its own distributions to customers later in July after receiving its allocation from the trustee. Distribution timelines varied meaningfully by exchange, from as little as roughly two weeks at some partner exchanges to as long as ninety days at others, reflecting each exchange's own compliance and processing requirements rather than any single fixed schedule set by the trustee.

The process remains open. As of this writing, the rehabilitation trustee's official site indicates the deadline for base repayment, early lump-sum repayment and intermediate repayment has been extended from 31 October 2025 to 31 October 2026, a deadline that has already moved once since the plan's approval and could move again before every eligible creditor has been paid. Readers checking on the status of a specific claim should treat the trustee's own site as the current source, not any date printed in secondary coverage of the case, including this one.

The unusual part of this outcome deserves to be stated without spin. A Mt. Gox creditor repaid in bitcoin today is being repaid in an asset worth far more, in dollar terms, than the equivalent cash claim would have been in 2014. That is not typical of bankruptcy outcomes, and it happened only because of the specific legal mechanism, civil rehabilitation rather than ordinary liquidation, combined with bitcoin's price trajectory over the following decade. Neither was something a 2014 creditor could have counted on.

Did the Mt. Gox Collapse Damage the Wider Bitcoin Market?

At the time, Mt. Gox was not one exchange among many with a comparable share of the market. Its own bankruptcy filing estimated the missing 850,000 bitcoin at approximately 7 percent of the entire bitcoin supply then in existence, and for years it had functioned as the primary venue where a Bitcoin price was actually discovered through trading. Removing both a meaningful share of circulating supply's certainty and the dominant price-discovery venue at once is a different kind of shock than a single company's stock losing most of its value, because there was no equally deep alternative market ready to absorb the disruption.

Bitcoin's price fell sharply around the February 2014 collapse and remained depressed for an extended period afterward, a pattern consistent with a market that had lost a large trading venue and a meaningful amount of confidence at once. This case study deliberately does not publish a specific before-and-after price figure for that decline: no primary or institutional source consulted this session supplied a bitcoin price series this case study could verify and attribute with confidence, and inventing a number to fill that gap would be a worse defect than describing the direction without one.

What is better documented is that the damage stayed largely confined to confidence in centralized bitcoin exchanges, rather than triggering a broader freeze in unrelated financial markets. Bitcoin in 2014 had nowhere near the interconnection with traditional finance that crypto assets would develop by the time of later episodes covered elsewhere in this library, including the DAO hack and the FTX collapse.

Could a Mt. Gox-Style Collapse Happen on a Modern Exchange?

The exact mechanism is harder to repeat unnoticed today, though not impossible, and the reasons why are worth separating from a false sense that custody risk itself has gone away.

What has genuinely changed since 2011 makes a multi-year, undetected wallet theft less likely to run as long before discovery. On-chain analytics firms now track large wallet movements across major exchanges in close to real time. Proof-of-reserves attestations, whatever their limits, at least give outside observers a periodic snapshot of what an exchange claims to hold, something that did not exist as a market practice in 2011. Regulatory licensing regimes in multiple jurisdictions now impose security and operational requirements that simply did not apply to an exchange like Mt. Gox at the time. A theft on the scale the 2023 indictment alleges, run for two and a half years with no external party noticing, would be considerably harder to sustain against today's monitoring infrastructure.

None of that eliminates custody risk. It shifts where the risk is most likely to concentrate. A proof-of-reserves attestation, as Swoopr's own explainer on proof of reserves covers, shows assets an exchange controls at one point in time. It says nothing about whether that exchange has also taken on offsetting liabilities, deliberately or otherwise, which is a closer description of how FTX failed than how Mt. Gox did. Today's better-defended exchanges are, if anything, more exposed to an FTX-style deliberate misuse of customer funds than to a Mt. Gox-style silent external breach, precisely because the defenses built after 2014 target external attackers more directly than they target an exchange's own operators.

The generalizable lesson, then, is narrower than "this specific thing won't happen again," and more durable because of it. Any custodian holding an asset on a customer's behalf is, functionally, a claim on that custodian's own security, competence and honesty. Bitcoin's blockchain can prove a transaction happened. It cannot prove that the company holding your balance has not lost it, lent it out, or simply never had it, and readers who understand that distinction are better positioned against the next custody failure, whatever specific form it takes, than readers who only learned to watch for one particular attack.

Common Myths About the Mt. Gox Collapse

"A software bug caused the losses." That was Mt. Gox's own explanation at the time, and it does not hold up. Researchers at ETH Zurich found no widespread use of transaction malleability attacks before Mt. Gox closed. The Department of Justice's 2023 indictment instead alleges a server breach and years-long theft by outside attackers, a mechanism that has nothing to do with the malleability flaw Mt. Gox publicly blamed.

"Mark Karpeles was convicted of stealing the bitcoin." He was not. The Tokyo District Court acquitted him of embezzlement in 2019 and convicted him only of manipulating his own account's data, a much narrower offense. Karpeles himself told the court his case had nothing to do with the hack or the missing bitcoin.

"This was basically the same failure as FTX." The mechanisms are close to opposites. FTX's shortfall came from a deliberate internal decision to lend customer deposits to an affiliate. Mt. Gox's shortfall came from an external breach the company did not detect for years. Both are custody failures; the similarity mostly ends there.

"Mt. Gox creditors lost everything." Most did not, and the outcome is unusually favorable by bankruptcy standards, though it took a decade to arrive. A 2018 conversion from bankruptcy liquidation to civil rehabilitation, driven by bitcoin's price appreciation, let creditors begin receiving bitcoin itself starting in 2024 rather than only a cash sum frozen at 2014 values.

"Someone went to prison for this." As of this writing, no one has served a US prison sentence for the theft. Karpeles received a suspended sentence in Japan for a separate, narrower offense. Alexander Vinnik pleaded guilty to a related money-laundering charge in the United States but was released to Russia in a prisoner exchange before sentencing. The two men the 2023 indictment names as the alleged hackers have not, as far as the public record shows, faced trial.

"The 2011 hack is what destroyed Mt. Gox." The well-known June 2011 flash crash was a real, disclosed security incident, but it was contained and the affected trades were reversed. The breach that actually destroyed the exchange, per the 2023 federal indictment, began separately in September 2011 and was never disclosed until the indictment was unsealed nine years after the collapse.

What a Reader Can Actually Carry Forward

Mt. Gox is not a useful template for spotting the next hidden exchange breach, because the specific failure, a years-long undetected server compromise at a single company with almost no external monitoring, describes an infrastructure environment that mostly no longer exists. It is useful for a narrower, more durable question: what can you actually verify about a place that holds your assets, and what are you simply trusting?

What generalizes

  • A company's own explanation for its losses is a claim, not a finding. Mt. Gox's transaction-malleability explanation was wrong, and it took outside researchers analyzing public network data, not regulators or auditors, to demonstrate that. Weigh a custodian's account of its own failure the way you would weigh any other interested party's account of events that make it look less culpable.
  • Undetected loss can persist for years before it becomes visible. The gap between Mt. Gox's actual and reported holdings existed for roughly two and a half years before withdrawal problems forced it into the open. A custodian solvent for years is not thereby proven solvent today; it has only been proven not to have failed loudly yet.
  • Legal outcomes can move in directions no one at the start expected. Mt. Gox's creditors went from an expected partial cash recovery under 2014-era bankruptcy liquidation to a far larger, partly in-kind recovery under 2018 civil rehabilitation, entirely because of a price move nobody could have priced into the original filing.
  • A criminal verdict answers a narrower question than the headline suggests. Karpeles's acquittal on embezzlement did not mean nobody stole the bitcoin, and his conviction on data manipulation did not mean he did. Read what a court actually decided, not what the case became shorthand for afterward.

What does not generalize

  • The specific mechanism. A silent, multi-year wallet-server compromise at a single centralized exchange with minimal external monitoring describes 2011 to 2014 far better than it describes the more heavily monitored exchange environment that exists today.
  • The recovery outcome. Mt. Gox creditors benefited from an asset-price move of a scale that is not a reasonable baseline expectation for any future custody failure.
  • The decade-long timeline. Mt. Gox took roughly a decade from collapse to meaningful creditor distributions. Other custody failures in this library, including FTX, resolved on considerably shorter timelines; neither pace is the norm.

The one question worth asking now

For every exchange, broker or custodian currently holding an asset on your behalf, ask what you could actually verify about its solvency today, using only information available to you as an outside party, not information the custodian has simply told you. A proof-of-reserves attestation, a licensing status, a track record without a public incident: each is evidence, and none of them, on its own, is proof. Mt. Gox operated for roughly two and a half years with a real shortfall that no external party could see, because no external party had a way to look. If your honest answer is that you are relying entirely on the custodian's own word, that is worth knowing before a withdrawal freeze forces the question. Our guides to the Scam & Security Center and crypto exchange custody risk cover how to think through that exposure in more detail.

References

Every figure on this page was verified against the following sources, each retrieved on 28 August 2026:

Figures deliberately not stated. This page gives no specific bitcoin price series or percentage decline for the period immediately following the February 2014 collapse, and no current dollar valuation of the bitcoin and bitcoin cash still to be distributed under the rehabilitation plan. No primary or institutional source consulted this session supplied those figures on a basis this case study could verify and attribute with confidence, so the direction and mechanism are described and the number is left out rather than estimated. The precise number of bitcoin the Department of Justice's 2023 indictment alleges was stolen, at least approximately 647,000, is described as an allegation throughout this page, not as an established fact, because the underlying case had not gone to trial as of this writing.

Method note: figures from the unsealed 2023 federal indictment are identified as allegations throughout this page, consistent with the presumption of innocence; the defendants named have not been convicted of the charges described here. Facts about Mt. Gox's own February 2014 disclosures and the Tokyo District Court's 2014 and 2018 to 2019 proceedings are drawn from contemporaneous wire-service reporting where no English-language primary court filing was accessible; Swoopr Investment's own interpretive framing, including the comparison to the FTX collapse, is labeled as such in the text.

This is educational content about a historical episode. It is not investment advice, it is not a forecast, and nothing here should be read as a claim about how any future exchange failure will behave.

Frequently Asked Questions

What caused the Mt. Gox collapse?

An indictment unsealed by the US Department of Justice in June 2023 alleges that in or about September 2011, two Russian nationals and unnamed co-conspirators gained unauthorized access to the server holding Mt. Gox's cryptocurrency wallets and used that access to steal at least approximately 647,000 bitcoins over the following two and a half years. The theft went undetected because Mt. Gox's own accounting could not distinguish a stolen balance from a real one, so the exchange kept operating, and kept accepting new deposits, on top of a hole that had already opened. Withdrawal problems in February 2014 did not create the shortfall. They exposed one that had existed for years.

How much bitcoin did Mt. Gox actually lose?

Mt. Gox told the Tokyo District Court on 28 February 2014 that it had lost 750,000 of its customers' bitcoins and 100,000 of its own, about 850,000 bitcoin in total, which it valued at roughly $480 million at the bitcoin price of the day. On 20 March 2014, Mt. Gox said a rescan of old-format wallets it had used before June 2011 turned up approximately 200,000 bitcoin it had not known it still held, revising the missing total down to about 650,000 bitcoin. The Department of Justice's 2023 indictment separately alleges at least approximately 647,000 bitcoin were stolen through the hack, a figure that lines up closely with the revised loss.

Was Mt. Gox's collapse the same kind of failure as FTX?

No, and the difference is the central lesson of comparing the two. FTX's customer deposits were deliberately lent to an affiliated trading firm and spent, a decision made by people who worked at FTX. Mt. Gox's bitcoin was taken by outside attackers who breached its systems, according to the Department of Justice indictment, and the exchange did not detect the theft for years. FTX is a story about where a custodian chooses to put your assets. Mt. Gox is a story about whether a custodian can tell you it still has them.

Did transaction malleability really cause Mt. Gox to lose customer bitcoin?

Mt. Gox said so at the time, but the claim did not hold up. Researchers Christian Decker and Roger Wattenhofer at ETH Zurich analyzed a year of Bitcoin network traffic preceding Mt. Gox's closure and found that while the transaction malleability flaw was real, there was no widespread use of malleability attacks before Mt. Gox shut down. Transaction malleability could make a withdrawal look like it failed when it had actually gone through, which explains customer confusion about missing withdrawals. It cannot explain how several hundred thousand bitcoins left wallets Mt. Gox controlled over nearly three years, which is what the Department of Justice's indictment describes as a server breach and theft.

What happened to Mark Karpeles?

Karpeles was arrested in Japan in August 2015 and held for almost a year before trial. On 15 March 2019 the Tokyo District Court found him guilty of manipulating electronic data and acquitted him of embezzlement and breach of trust, the more serious charges prosecutors had sought a 10-year sentence for. He received a two-year, six-month prison sentence suspended for four years, meaning no jail time. The data-manipulation conviction concerned an allegation that he falsified data to inflate Mt. Gox's own recorded holdings by about $33.5 million, a narrower charge than the mass theft of customer bitcoin, which the verdict did not attribute to him.

Who was actually charged with stealing the Mt. Gox bitcoin?

In June 2023 the US Department of Justice unsealed an indictment charging Russian nationals Alexey Bilyuchenko and Aleksandr Verner with conspiring to launder approximately 647,000 bitcoin stolen from Mt. Gox beginning in September 2011. Bilyuchenko was separately charged with conspiring with Alexander Vinnik to operate the BTC-e exchange, which a Financial Crimes Enforcement Network penalty found had processed over 300,000 bitcoin traceable to the Mt. Gox theft. Vinnik pleaded guilty in May 2024 to conspiracy to commit money laundering and faced up to 20 years in prison, but in February 2025 he was released from US custody before sentencing and sent to Russia as part of a prisoner exchange for an American citizen. As of this writing, no one has served a US prison sentence for the Mt. Gox theft itself.

Are Mt. Gox creditors getting their bitcoin back?

Many are, in bitcoin rather than cash, which is unusual for a decade-old bankruptcy. In June 2018 the Tokyo District Court moved Mt. Gox from bankruptcy liquidation into civil rehabilitation after the estate's remaining bitcoin holdings, revalued at the current market price, turned out to be worth far more than creditors' original yen-denominated claims. A rehabilitation plan approved by creditors set aside roughly 141,686 bitcoin and 142,846 bitcoin cash for distribution. The trustee began sending cryptocurrency to exchanges including Kraken, Bitstamp and Bitbank for onward distribution to more than 20,000 creditors starting in July 2024. As of this writing, the trustee has extended the deadline for base, early lump-sum and intermediate repayments to 31 October 2026, a date that has already moved once and can move again.

Did the Mt. Gox collapse crash the wider bitcoin market?

Mt. Gox's own bankruptcy filing estimated its missing 850,000 bitcoin at about 7 percent of all bitcoin then in existence, and the exchange had been the dominant venue for trading it, so the collapse removed both a large share of supply-side certainty and the market's main price-discovery venue at once. Bitcoin's price fell sharply around the February 2014 collapse and stayed depressed for an extended period afterward. This case study does not publish a specific before-and-after price figure because no primary or institutional source consulted supplied one on a comparable basis; the mechanism and direction are described instead of an unverified number.

Could a Mt. Gox-style collapse happen on a modern exchange?

The specific mechanism, a years-long undetected theft from a single company-run wallet server with no real-time proof of solvency, is harder to repeat unnoticed today because proof-of-reserves attestations, on-chain analytics firms and larger compliance teams now exist that did not in 2011. None of that makes custody risk obsolete. An attestation shows assets an exchange controls at one moment; it does not prove the exchange has not also taken on offsetting liabilities, which is closer to how FTX failed than how Mt. Gox did. The generalizable lesson is narrower than the headline: any custodian holding assets on your behalf is a claim on that custodian's own security, competence and honesty, not a claim on the asset itself, whatever the underlying blockchain can prove.