Forget masked robbers, getaway cars, and elaborate bank vaults. Some of the biggest heists of the modern era have required little more than laptops, stolen credentials, clever code, and an understanding of systems holding billions of dollars in digital assets.
Cryptocurrency has created a new kind of crime story. Hackers have stolen fortunes without ever entering the same country as their victims, negotiated the return of hundreds of millions of dollars through blockchain messages, worked on behalf of hostile governments, and even watched as their victims hacked them back. In some cases, the theft itself was only the beginning of the story.
Here are ten cryptocurrency heists straight out of a Hollywood movie.
Related: Top 10 Things Crypto Was Supposed to Change & What Actually Did
10 The Mt. Gox Collapse
Before cryptocurrency exchanges became a multibillion-dollar industry, Mt. Gox dominated Bitcoin trading. At its peak, the Tokyo-based exchange handled roughly 70% of global Bitcoin trading volume, making it the place where thousands of early investors stored and traded their cryptocurrency.
Then the bitcoins started disappearing.
Security breaches plagued Mt. Gox for years, but users did not grasp the scale of the problem until February 2014, when the exchange suddenly suspended withdrawals. Mt. Gox soon announced that hundreds of thousands of bitcoins belonging to customers and the company were missing and filed for bankruptcy. At the time, the loss was worth hundreds of millions of dollars.
The company initially blamed problems involving Bitcoin’s transaction-malleability vulnerability. Still, later research found that such attacks could account for only a tiny fraction of the missing funds. Whatever had happened, the coins appeared to have been disappearing from Mt. Gox over a much longer period.
Then came another twist: approximately 200,000 bitcoins were later discovered in an old digital wallet. That recovery eventually became part of an extraordinarily complicated bankruptcy and rehabilitation process as former customers fought to recover some of what they had lost.
The story lasted far longer than the exchange itself. In July 2024, more than a decade after Mt. Gox collapsed, creditors finally began receiving Bitcoin and Bitcoin Cash repayments. For some victims, one of cryptocurrency’s earliest great heists took ten years just to reach its final act.[1]
9 The Bitfinex Bitcoin Heist
When nearly 120,000 bitcoins vanished from the Bitfinex cryptocurrency exchange in August 2016, the thief seemed to disappear along with them. At the time, the stolen cryptocurrency was worth around $71 million. As Bitcoin’s price soared over the following years, however, the untouched fortune grew into billions.
The mystery finally broke open in February 2022, when federal investigators arrested a New York couple, Ilya Lichtenstein and Heather Morgan. Morgan immediately attracted attention because she had cultivated an online persona as an eccentric rapper called “Razzlekhan,” complete with surreal music videos and self-described entrepreneurial ambitions.
But the story became considerably stranger after their arrests. Lichtenstein eventually admitted that he—not some still-unidentified hacker—had personally broken into Bitfinex. According to the Justice Department, he fraudulently authorized more than 2,000 transactions that transferred exactly 119,754 bitcoins into a wallet under his control. He later recruited Morgan to help launder the proceeds.
The couple used fictitious identities, darknet markets, cryptocurrency mixers, chain-hopping, and other techniques to obscure the stolen funds. They even converted some of the proceeds into gold coins, which Morgan helped conceal by burying them.
Authorities ultimately recovered billions of dollars in stolen cryptocurrency. Lichtenstein pleaded guilty and was sentenced in November 2024 to five years in federal prison.
A hacker steals a fortune, waits while it becomes worth billions, recruits his aspiring-rapper wife to help launder it, and ends up burying gold along the way. Hollywood would probably be accused of making the story too ridiculous.[2]
8 The Ronin Network Hack
In March 2022, someone pulled off an enormous theft from Ronin Network, the blockchain infrastructure used by the popular online game Axie Infinity. The attackers drained 173,600 ETH and 25.5 million USDC from the Ronin Bridge, with the stolen cryptocurrency valued at roughly $620 million at the time.
The Ronin Bridge existed to allow users to transfer digital assets between different blockchains. The attackers compromised enough of the system’s validator authority to approve fraudulent withdrawals, turning a mechanism designed to connect blockchain economies into the doorway for one of the largest cryptocurrency thefts ever recorded.
What transformed the hack from an enormous cybercrime into an international security story was the identity of the attackers. The FBI formally attributed the theft to Lazarus Group and APT38, hacking organizations associated with the North Korean government. U.S. authorities have repeatedly warned that North Korea uses cryptocurrency theft and other cybercrime to generate revenue for the regime.
In other words, players buying and trading fantasy creatures inside an online game had unwittingly become part of a financial system valuable enough to attract state-backed hackers.
Ronin later reimbursed affected users and rebuilt its bridge with additional security protections. But the central image remains hard to improve on: North Korean cybercriminals stealing hundreds of millions of real dollars from the economy surrounding a game about cartoon monsters.[3]
7 The Poly Network Exploit
On August 10, 2021, an anonymous hacker exploited a vulnerability in Poly Network, a platform that allowed users to move cryptocurrency between different blockchains. By the time the attack ended, more than $610 million in digital assets had disappeared.
Then the thief started talking.
Because messages can be embedded in blockchain transactions, the hacker began publicly explaining the attack and claimed the theft was done “for fun” and to expose Poly Network’s weaknesses. Whether that had really been the plan all along was impossible to prove. Laundering more than half a billion dollars in publicly traceable cryptocurrency was also becoming extremely difficult.
Within days, the hacker began returning the money. Poly Network responded in an equally bizarre fashion, dubbing the thief “Mr. White Hat” and thanking the person for exposing its security flaws. The company even offered a $500,000 bug bounty as the stolen assets came back.
Eventually, almost all of the recoverable funds were returned.
Plenty of heist stories involve a thief who gets cold feet and gives back the loot. Few involve someone stealing more than $600 million, publicly chatting with the victim while returning it, and then being offered half a million dollars for pointing out how the robbery was possible.[4]
6 The Coincheck Hack
In January 2018, Japanese cryptocurrency exchange Coincheck discovered that hackers had drained roughly ¥58 billion—about $530 million at the time—in NEM cryptocurrency from the platform.
The stolen coins had been kept in a “hot wallet,” meaning the wallet remained connected to the internet rather than being stored offline. The enormous loss immediately focused attention on the security practices of cryptocurrency exchanges, and Japan’s Financial Services Agency ordered Coincheck to improve its operations while expanding scrutiny of other exchanges.
Coincheck’s response was almost as remarkable as the theft. Instead of simply telling customers that their cryptocurrency was gone, the company announced that it would reimburse roughly 260,000 affected users from its own funds. The eventual repayment totaled about ¥46 billion, or more than $400 million.
Meanwhile, efforts were made to track the stolen NEM as it moved through the cryptocurrency ecosystem. Unlike a suitcase full of cash, hundreds of millions of dollars in blockchain assets leave a public trail—even when nobody knows who controls the wallets at the end of it.
Coincheck survived, reimbursed its customers, tightened its controls, and later continued operating under new ownership. The hackers vanished with an enormous haul, but the victim exchange somehow lived through a theft that might have destroyed almost any conventional financial business.[5]
5 The Wormhole Bridge Hack
On February 2, 2022, an attacker found a flaw in Wormhole, a bridge that allowed cryptocurrency to move between blockchains such as Solana and Ethereum. By exploiting the bridge’s verification process, the hacker minted 120,000 unbacked wrapped Ether and walked away with cryptocurrency worth roughly $320 million at the time.
Wormhole’s backer, Jump Crypto, responded by buying 120,000 ETH on the open market and replacing the missing assets, restoring the bridge’s backing. The hacker, meanwhile, kept the stolen cryptocurrency and later began putting some of it to work in decentralized-finance protocols rather than simply letting the fortune sit untouched.
Then, about a year after the original theft, the story took an extraordinary turn. Some of the hacker’s assets had been deposited in vaults operated through the Oasis platform. After white-hat hackers discovered a way to access those positions, the High Court of England and Wales ordered Oasis to use the vulnerability to recover the funds.
Oasis complied, effectively counter-exploiting its own software and seizing cryptocurrency worth around $140 million from positions tied to the Wormhole hacker before returning the assets to an authorized third party.
The Wormhole thief had successfully exploited one of the world’s biggest cryptocurrency bridges. A year later, the victim’s side essentially hacked the hacker back.[6]
4 The BSC Token Hub Exploit
In October 2022, an attacker targeted the BSC Token Hub, the bridge connecting BNB Beacon Chain and BNB Smart Chain. Rather than stealing cryptocurrency already belonging to customers, the hacker exploited a flaw in the bridge’s proof-verification system to create approximately two million new BNB, worth nearly $570 million.
The attacker quickly moved some of the newly minted assets onto other blockchains. BNB Chain faced an uncomfortable decision: allow the transfers to continue while validators followed normal operations, or coordinate an emergency shutdown.
They chose the latter.
BNB Smart Chain validators contacted one another and synchronized a temporary pause, preventing much of the fraudulent BNB from escaping. BNB Chain later estimated that more than $100 million remained unrecovered. At the same time, the majority of the newly created assets stayed under control. The blockchain itself was not rolled back, and BNB Chain said ordinary users were not directly affected.
The response stopped an enormous theft from becoming even larger, but it raised an awkward philosophical question. A blockchain promoted as decentralized had just demonstrated that, in a sufficiently serious emergency, a relatively small group of validators could coordinate to stop it.
The attacker created hundreds of millions of dollars from nothing. The defenders responded by doing something blockchains supposedly aren’t designed to do: hitting pause.[7]
3 The KuCoin Hack
In September 2020, cryptocurrency exchange KuCoin detected abnormal withdrawals from several of its hot wallets. By the time the damage was understood, hackers had stolen approximately $285 million across 154 different cryptocurrencies and tokens.
KuCoin later said the attackers had spent considerable time inside its systems, eventually obtaining private keys for several hot wallets and bypassing security controls. The company immediately replaced the affected wallets and began working with exchanges, blockchain projects, security companies, and law enforcement to track the stolen assets.
What happened next demonstrated something unusual about cryptocurrency theft.
Some token issuers and blockchain projects were able to freeze, recover, or replace stolen assets, preventing the hackers from freely cashing out everything they had taken. KuCoin ultimately reported recovering about $222 million, or 78%, through cooperation with exchanges and cryptocurrency projects, plus another $17.45 million, or 6%, through law enforcement and security efforts. KuCoin and its insurance fund covered the remaining losses so customers did not bear them.
In total, about 84% of the stolen assets were recovered through outside cooperation. The thieves had successfully taken hundreds of millions of dollars, only to discover that some of their digital loot could effectively be frozen or replaced by the organizations behind it.
It was a heist in which the stolen money itself could suddenly stop cooperating with the thieves.[8]
2 The Bybit Heist
On February 21, 2025, Bybit employees prepared what appeared to be a routine transfer from an Ethereum cold wallet to a warm wallet. Multiple authorized signers reviewed the transaction through the Safe{Wallet} interface and approved it.
What they saw was not what they signed.
A forensic investigation completed by cybersecurity firm Sygnia in 2026 found that the attackers had spent nearly three weeks preparing the operation. They first compromised a Safe{Wallet} developer’s computer through social engineering, gained access to cloud infrastructure, and eventually injected malicious JavaScript into the wallet’s web interface.
When Bybit’s employees reviewed the transfer, the screen displayed apparently legitimate transaction details. Behind the scenes, however, the malicious code altered what was actually being signed. The resulting transaction gave the attackers control of the cold wallet.
Within minutes, roughly $1.5 billion in Ethereum assets had vanished. Sygnia attributed the operation to Lazarus Group, the North Korean state-linked hacking organization, making the attack both the largest documented cryptocurrency theft and another example of cybercrime intersecting with geopolitics.
The attackers quickly removed the malicious code afterward, attempting to erase evidence of how they had done it. Bybit, meanwhile, kept withdrawals operating while scrambling to secure enough liquidity to reassure customers and cover the loss.
There were no drills, explosives, or getaway cars. Employees simply looked at one transaction, unknowingly signed another, and watched $1.5 billion disappear.[9]
1 The DAO Exploit
In 2016, Ethereum was still young when one of its most ambitious projects promised to demonstrate what decentralized finance might become. The DAO was essentially an investor-controlled venture fund built entirely through smart contracts. Investors poured roughly $150 million worth of Ether into it.
Then someone discovered a flaw in the code.
The attacker exploited a recursive-call vulnerability that allowed Ether to be withdrawn repeatedly before the smart contract properly updated the account balance. More than 3.6 million ETH was drained into a separate “child DAO.” Ethereum itself was not hacked; the vulnerable application running on it was.
There was one crucial complication. The DAO’s rules prevented the attacker from immediately withdrawing the stolen Ether, giving the Ethereum community several weeks to decide what to do.
That decision triggered a philosophical crisis. Blockchains were supposed to be immutable. If the code had executed exactly as written—even disastrously—should anyone intervene?
Ethereum holders voted on a controversial hard fork designed to recover the assets. More than 85% of the votes cast supported intervention. At block 1,920,000, the fork performed an irregular state change that transferred affected DAO balances into a recovery contract so investors could reclaim their Ether. It did not erase the earlier blocks or simply reverse the offending transactions.
Not everyone agreed. Some miners and users refused to adopt the fork and continued running the original chain. Their blockchain became Ethereum Classic, while the forked version retained the name Ethereum.
Most heists leave behind police reports, court cases, and missing money. The DAO exploit left behind two blockchains.[10]
