Worked example · 2014-02
Mt. Gox exchange collapse — Bitcoin — 2011-09 to 2014-02 (filing); recovery through 2024–2025
Summary
Mt. Gox was, by mid-2013 to early 2014, the largest bitcoin exchange in the world, headquartered in Tokyo and at peak handling on the order of ~70% of all global bitcoin transaction volume. From late 2011 through 2013 the exchange suffered a sustained, undetected drain on its hot-wallet balances driven by compromise of its hot-wallet wallet.dat private-key file. Per the WizSec forensic reconstruction (Kim Nilsson), the initial breach occurred on or about 2011-09-22, when the hot-wallet private keys were exfiltrated as a copied wallet.dat. The attacker then held those keys, and over the following ~21 months progressively swept incoming customer deposits and any spendable hot-wallet balances into attacker-controlled addresses, ultimately accumulating ~630,000 BTC traceable to the compromise on the WizSec analysis. Adjacent operational losses brought the total customer-and-company gap to ~850,000 BTC by the time withdrawals began failing publicly in early 2014. Mt. Gox suspended trading on 2014-02-24 and filed for bankruptcy in Tokyo on 2014-02-28, reporting $65M of liabilities and disclosing ~$473M of missing bitcoin.
The case has three load-bearing characteristics for OAK:
- It is the foundational T11 case. Every subsequent operator-internal hot-wallet compromise — Coincheck 2018, KuCoin 2020, CoinEx 2023, Stake.com 2023, DMM Bitcoin 2024, WazirX 2024 — lives in Mt. Gox's shadow. The structural failure mode (single internet-connected hot wallet holding customer-asset-scale balances, no cold-storage segregation, no multisig at the protocol level even where available, no real-time egress-anomaly detection) was defined by Mt. Gox before any of the post-2014 industry vocabulary for cold/hot separation existed as standard practice. Contributors writing T11 sub-technique pages and adjacent worked examples should treat Mt. Gox as the case the entire T11 pillar's mitigation framing was retro-engineered against.
- The laundering rail is the foundational predecessor of OAK-G03. Vinnik operated BTC-e between 2011 and 2017 as a clearinghouse for criminal proceeds at ~$9B+ aggregate volume across >1M users. The DOJ indictment characterised BTC-e as the laundering venue for proceeds from "computer intrusions and hacking incidents, ransomware scams, identity theft schemes, corrupt public officials, and narcotics distribution rings," with ~300,000 BTC from the Mt. Gox theft laundered through BTC-e specifically. Structurally — a Russia-nexus exchange operating with deliberate KYC/AML defects as a privatised laundering rail for cybercriminal proceeds — BTC-e is the operational template that the post-2017 cluster (Garantex and adjacent venues that anchor much of the current OAK-G03 framing) was built on. Mt. Gox is therefore not only the foundational T11 case; the laundering side of Mt. Gox is the foundational pre-G03 case as well.
- The recovery horizon is structurally unique. Mt. Gox is the only major incident on the public record where civil-rehabilitation proceedings produced creditor distributions a decade after the precipitating event, with creditor outcomes denominated in BTC rather than fiat — meaning creditors received in 2024 the same number of bitcoins they were owed in 2014, at ~10,000% of the at-event price. No other incident in the OAK record has this multi-decade-with-currency-appreciation recovery shape; the case is the canonical reference for it.
Timeline (UTC unless noted)
| When | Event | OAK ref |
|---|---|---|
| 2010-07 | Mt. Gox launched (originally as a Magic: The Gathering Online Exchange card-trading site, repurposed by founder Jed McCaleb as a bitcoin exchange) | (pre-event) |
| 2011-03 | Mt. Gox sold to Mark Karpelès / Tibanne Co. Ltd. | (pre-event) |
| 2011-06 | Earlier Mt. Gox security incident: account-database compromise and price-manipulation attack; ~25,000 BTC reportedly affected (separate, pre-dates the main multi-year compromise) | (pre-event — distinct incident) |
| 2011-09-22 ~05:30 JST | Per WizSec reconstruction: Mt. Gox hot-wallet wallet.dat file exfiltrated; private keys for the hot wallet's address set fall under attacker control. Beginning of the multi-year drain. |
T11-class entry — operator-internal hot-wallet key compromise (no exact OAK v0.1 match) |
| 2011-09 → 2013 mid | Attacker progressively sweeps spendable balances and incoming deposits from compromised hot-wallet addresses to attacker-controlled wallet(s); per WizSec, traceable cluster ultimately reaches ~630,000 BTC. Bulk of laundering routed through BTC-e (Vinnik). | Sustained extraction |
| 2011 → 2017 | BTC-e operates as Vinnik-controlled laundering venue; ~300,000 BTC of Mt. Gox-theft proceeds laundered through BTC-e per later DOJ indictment | Pre-G03 laundering infrastructure |
| 2013 mid | Spendable balance from compromised keys substantially depleted; drain pace falls off as attacker-controlled keys run out of reachable funds | (steady-state) |
| 2014-02-04 | Internal Mt. Gox tally: 41,390 BTC in "BAD Transaction" status (~$38M at $934/BTC); customer withdrawal complaints accumulating | (operator-side detection, partial) |
| 2014-02-07 | Mt. Gox public statement attributing withdrawal issues to "transaction-malleability" technical problems | (deflection / mis-disclosure) |
| 2014-02-24 | Mt. Gox shuts down its website; trading and withdrawals suspended | (operational halt) |
| 2014-02-28 | Mt. Gox files for bankruptcy in Tokyo; reports ~750,000 customer BTC and |
Filing — disclosure |
| 2014-03-09 | Mt. Gox files Chapter 15 bankruptcy in the United States | (cross-jurisdiction proceeding) |
| 2014-03-20 | Mt. Gox locates 199,999.99 BTC in an old, pre-June-2011 wallet; net unrecoverable reduced from ~850,000 to ~650,000 BTC | Partial recovery — found-not-stolen |
| 2014-04-16 | Mt. Gox abandons rehabilitation plan, requests liquidation | (proceedings) |
| 2015-04 | WizSec publishes initial public conclusion that "most or all of the missing bitcoins were stolen straight out of the Mt. Gox hot cryptocurrency wallet over time, beginning in late 2011" | Forensic-reconstruction milestone |
| 2017-07-25 | Alexander Vinnik arrested in Ouranoupoli, Greece on US warrant for laundering ~$4B through BTC-e | Law-enforcement action — laundering side |
| 2017-07 | DOJ unseals 21-count indictment against Vinnik (operating an unlicensed money-services business and international money-laundering, including for Mt. Gox-theft proceeds) | (DOJ) |
| 2017-07 | WizSec publicly identifies Vinnik as primary suspect for laundering of Mt. Gox-theft proceeds (Breaking open the MtGox case, part 1) | Forensic attribution |
| 2018 | Mt. Gox bankruptcy proceedings transitioned to civil rehabilitation (民事再生) — allowing creditor distributions in BTC rather than at fiat-fixed-rate February-2014 prices | (legal mechanism shift) |
| 2019-03-14 | Tokyo District Court convicts Mark Karpelès of falsifying records (inflating Mt. Gox's reported holdings by ~$33.5M); acquitted of embezzlement and aggravated breach of trust; 30-month suspended sentence | Karpelès legal track — concluded |
| 2020-01 | Vinnik extradited from Greece to France | (Vinnik legal track) |
| 2020-06 | WizSec publishes "The 80,000 stolen MtGox bitcoins" — extending the forensic reconstruction to the March-2011 pre-cursor losses | (forensic) |
| 2020-12-07 | Paris criminal court convicts Vinnik; 5-year prison sentence + €100,000 fine for aggravated organised money-laundering | Vinnik legal track — France |
| 2022-08-04 | Vinnik extradited from France (via Greece) to the United States | (Vinnik legal track) |
| 2024-05 | Vinnik pleads guilty in US to conspiracy to commit money-laundering | Vinnik legal track — US plea |
| 2024-07-05 | Mt. Gox civil-rehabilitation trustee begins BTC and BCH distributions to ~20,000 verified creditors — ~10 years after the bankruptcy filing | Creditor recovery — first distributions |
| 2024-10-10 | Trustee announces most repayments to verified creditors completed; final-distribution deadline extended to 2025-10-31 | (recovery) |
| 2025-02 | Vinnik released from US custody as part of Russia–US prisoner-exchange (for Marc Fogel) | (post-recovery legal disposition) |
| 2025-10-31 | Trustee final deadline for completion of all creditor distributions | (recovery) |
What defenders observed and learned
- Cold-storage / hot-wallet separation at exchange scale was not industry-standard practice before Mt. Gox. The entire post-2014 exchange-custody paradigm — segregate the bulk of customer assets into cold storage; minimise hot-wallet float to operational-liquidity needs; use multisig where the asset's protocol supports it; treat the hot-wallet
wallet.dat(or its protocol-equivalent) as a single point of failure that will eventually be compromised — was crystallised industry-wide in the years immediately after Mt. Gox. The Coincheck 2018 example documents what happens when an exchange in 2018 still runs a single-hot-wallet design at exchange scale; the Mt. Gox 2014 example is why the post-Mt. Gox baseline exists at all. Defenders writing exchange-custody runbooks should treat the cold/hot separation as the directly-attributable Mt. Gox lesson. - A multi-month-to-multi-year undetected hot-wallet drain is a structural failure mode, not a one-off event. The most consequential property of Mt. Gox is not the magnitude of the loss but the duration of the undetected compromise (~21 months from initial
wallet.datexfiltration to operationally-visible failure). Modern hot-wallet operations runbooks treat continuous cryptographic-balance reconciliation against expected hot-wallet state as a core control precisely because Mt. Gox demonstrated, at industry-defining scale, what happens when reconciliation is absent or merely accounting-driven. The post-2018 industry baseline of "any hot-wallet egress that is not matched by a customer-withdrawal-or-rebalance event must alert within minutes" is a direct retro-fit against the Mt. Gox failure pattern. - The fiat-denominated recovery that did not happen is itself a defender lesson. Mt. Gox is the canonical reference for how civil-rehabilitation-style proceedings, where creditors retain a denominated-in-the-asset claim through the recovery process, produce structurally different outcomes than US-style fiat-fixed-rate bankruptcy claims. The 2018 transition from Japanese bankruptcy to civil rehabilitation is the legal mechanism that allowed creditors to recover their claims in BTC at 2024 prices rather than at February-2014 prices. Defenders advising on jurisdiction-of-incorporation choices for exchanges, custodians, and DAO treasuries should treat the Japanese civil-rehabilitation regime — and its ability to preserve in-kind asset claims through multi-year recovery — as a real and case-tested option, with Mt. Gox as the singular precedent.
- The laundering side of an exchange-scale theft can drive the long-tail law-enforcement story more than the theft itself. The Mt. Gox theft was not solved on the entry-vector side — Karpelès was tried and convicted in Japan only for falsification of records, not for the underlying compromise, and there is no Japanese conviction tying anyone to the original 2011-09 hot-wallet breach. The Mt. Gox legal accountability story is overwhelmingly the Vinnik laundering story, traced over a decade across Greek arrest (2017), French conviction (2020), US extradition (2022), and US plea (2024). Defenders writing law-enforcement-cooperation runbooks for exchange-incident response should treat the Vinnik track as the model for how the long-tail accountability story actually runs: not via the original-jurisdiction prosecution of the entry-vector compromise, but via downstream prosecution of laundering infrastructure across multiple jurisdictions over multiple years.
What this example tells contributors writing future Technique pages
- Mt. Gox is THE foundational T11 case. Every operator-internal-custody-compromise example after it lives in its shadow. Contributors writing T11 sub-technique pages, T11 worked examples, or any custody-and-signing-family analysis should treat Mt. Gox as the anchor and explicitly cross-reference the 2011–2014 timeline. The cases that matter as derivatives of Mt. Gox include Coincheck 2018, KuCoin 2020, CoinEx 2023, Stake.com 2023, DMM Bitcoin 2024, and WazirX 2024 — each documented in the OAK examples set, each fitting into the same operator-internal-hot-wallet-compromise gap that Mt. Gox first defined. The T11 pillar's Technique-set was retro-engineered against the failure shape Mt. Gox revealed; contributors should not treat the T11 sub-techniques as "the framework" and Mt. Gox as "an example of the framework," but rather treat Mt. Gox as the historical fact the framework was retro-fit to describe.
- Mt. Gox sits in the same OAK v0.1 taxonomy gap as KuCoin and Coincheck — but predates the G01 attribution scaffolding entirely. The entry-vector class — operator-internal hot-wallet
wallet.dat/ private-key compromise — has no exact T11.001 / T11.002 / T11.003 sub-technique. A future v0.x update should consider adding a T11.x sub-technique covering this entry-vector class, with Mt. Gox as the founding case and Coincheck / KuCoin / DMM Bitcoin / WazirX as the lineage. Contributors should not attempt to retro-attribute Mt. Gox to OAK-G01 (DPRK / Lazarus); the WizSec attribution and the DOJ indictment trace the laundering to Vinnik / BTC-e, which is structurally and politically distinct from the post-2017 DPRK cluster. Mt. Gox is the case that demonstrates that the T11 entry-vector class exists and produces industry-defining losses independently of any G-cluster attribution. - BTC-e under Vinnik is a foundational pre-G03 case. Contributors writing the OAK-G03 Russia-nexus laundering-infrastructure pages, or worked examples that touch the Garantex / adjacent-venue cluster, should treat BTC-e (2011–2017) as the operational template that the post-2017 cluster inherited. The structural pattern — a Russia-nexus exchange operating with deliberate KYC/AML defects as a privatised laundering rail for cybercriminal proceeds; multi-billion-dollar aggregate volume; cross-jurisdiction operator with Cyprus / Bulgaria / Greece operational footprint; eventual law-enforcement disruption — is the BTC-e template, and the Garantex-era cluster is its iteration. Mt. Gox is therefore the foundational worked example for the BTC-e → G03 lineage on the laundering side, in the same way it is the foundational example for T11 on the entry-vector side.
- Karpelès and Vinnik are separate criminal tracks, and the OAK record must keep them separate. Karpelès was tried in Japan for record-falsification specific to Mt. Gox accounting; he was not charged in Japan with the underlying 2011–2013 compromise, and the public-record verdict (2019-03-14) acquitted him of embezzlement and aggravated breach of trust. Vinnik was tried across France (conviction 2020), the United States (plea 2024), and pre-trial Greek-detention proceedings (2017–2020) for laundering the Mt. Gox-theft proceeds and other proceeds through BTC-e — not for the underlying entry-vector compromise. Contributors writing future operator-accountability or laundering-infrastructure worked examples should treat the Mt. Gox case as the canonical reference for how the entry-vector criminal track and the laundering criminal track diverge in jurisdiction, timeline, and standard of proof. The two are not interchangeable, and the OAK record's value depends on documenting them as the structurally distinct accountability mechanisms they are.
- Preserve the at-the-time / at-current-prices dual loss numbers and the BTC-denominated claim notation. Mt. Gox's gross loss at filing was ~$473M (the figure disclosed in the bankruptcy filing); after the March 2014 recovery of ~200,000 BTC the net unrecoverable balance was
650,000 BTC ($373M at the February 2014 price, ~$50B+ at 2024–2026 prices). Each figure is correct only with its qualifier — gross-vs-net and at-time-vs-at-current must travel together. Worked examples that involve in-kind BTC creditor claims — a class Mt. Gox effectively defines — should record the BTC-denominated claim as the primary number, with the fiat-equivalents-at-times noted secondarily; this notation convention is the right default for in-kind-denominated recovery cases.
Public references
[wizsecmtgox2017]— Nilsson, K. Breaking open the MtGox case, part 1. WizSec blog, 2017-07. Forensic reconstruction of the 2011-09 hot-walletwallet.datexfiltration and the multi-year drain through 2013; primary-source attribution of laundering proceeds to Vinnik / BTC-e.[wizsecmtgox2015]— Nilsson, K. The missing MtGox bitcoins. WizSec blog, 2015-04. Earlier WizSec public conclusion that the bulk of missing bitcoins were drained from the hot wallet over time beginning in late 2011.[wizsecmtgox2020]— Nilsson, K. The 80,000 stolen MtGox bitcoins. WizSec blog, 2020-06. Forensic reconstruction extending the analysis to the March-2011 pre-cursor losses.[dojvinnik2017]— US Department of Justice. Russian National and Bitcoin Exchange Charged in 21-Count Indictment for Operating Alleged International Money-Laundering Scheme and Allegedly Laundering Funds from Hack of Mt. Gox. DOJ press release, 2017-07-26 (ICE archived release referenced).[dojvinnik2024plea]— US Department of Justice. Operator of BTC-e Pleads Guilty to Money-Laundering Conspiracy. 2024-05. Vinnik US plea; cross-referenced for the conclusion of the US criminal track.[karpelesjapan2019]— Tokyo District Court verdict, People v. Karpelès, 2019-03-14. Conviction for falsification of records (suspended 30-month sentence); acquittal on embezzlement and aggravated breach of trust.[mtgoxbankruptcy2014]— Mt. Gox Co., Ltd. bankruptcy filing, Tokyo District Court, 2014-02-28. Primary-source disclosure of ~750,000 customer BTC and ~100,000 company BTC missing.[mtgoxtrustee2024]— Mt. Gox Rehabilitation Trustee. Notice on Repayments, 2024-06-24 and 2024-07-05 announcements. Civil-rehabilitation distributions to creditors.[paristribunalvinnik2020]— Paris Criminal Court verdict, Procureur c. Vinnik, 2020-12-07. 5-year prison sentence + €100,000 fine for aggravated organised money-laundering.[chainalysis2024dprk]— referenced for companion historical context on cross-period laundering-infrastructure analysis (Mt. Gox falls outside the DPRK / G01-attributed cumulative figures Chainalysis tracks; this reference is included to disambiguate Mt. Gox from the G01 totals contributors might otherwise conflate).
Discussion
Mt. Gox is the OAK record's foundational case for two distinct things at once: the T11 entry-vector pillar (operator-internal hot-wallet compromise) and the pre-G03 laundering-infrastructure cluster (BTC-e under Vinnik as the operational template that later Russia-nexus laundering venues iterated on). No other single case in the OAK examples set anchors two distinct framework pillars simultaneously. Contributors should treat this dual-anchor role as a structural feature of the case, not a categorisation accident: the same multi-year compromise produced both a record-defining T11 loss and the laundering rail that became the prototype for the post-2017 Russia-nexus cluster, and the historical fact that one operator-internal compromise produced both is what makes Mt. Gox distinct from every later T11 case where the laundering side and the entry-vector side typically attach to different actor clusters.
The BTC-e → G03 lineage observation deserves to be stated carefully. BTC-e is not itself an OAK-G03 venue; G03 as currently framed in OAK references the post-2017 Russia-nexus laundering cluster of which Garantex is the canonical present-day reference. But the structural pattern G03 names — a Russia-nexus exchange operating with deliberate KYC/AML defects as a privatised laundering rail for cybercriminal proceeds, run by an identifiable Russia-nationality operator across a multi-jurisdiction operational footprint, eventually disrupted by a multi-jurisdiction law-enforcement action — is the BTC-e pattern. Vinnik is the prototype operator; Garantex (and adjacent venues) are the iterated descendants. Contributors writing the G03 actor page or G03-attributed worked examples should explicitly cross-reference Mt. Gox / BTC-e as the prototype case, not as a separate G-cluster, and should treat the historical lineage as the strongest argument for why the G03 cluster is a coherent attribution category at all.
The Karpelès-versus-Vinnik separate-criminal-tracks observation matters for how OAK records operator-accountability across the broader examples set. The instinct to collapse "the Mt. Gox case" into a single legal narrative is wrong: the operator (Karpelès) was held legally accountable in Japan only for record-falsification, not for the underlying compromise; the laundering-infrastructure operator (Vinnik) was held legally accountable across France, the US, and pre-trial Greek detention, not for the underlying entry-vector compromise. There is no public-record criminal verdict against any party for the original 2011-09 hot-wallet exfiltration itself — eleven years on. Defenders and contributors writing operator-accountability or law-enforcement-cooperation analyses should treat this entry-vector-criminal-track absence as the typical, not exceptional, outcome for sustained T11-class compromises. The accountability story runs through the laundering side and through the corporate-governance / record-falsification side; the entry-vector-side accountability story typically does not run at all.
Finally, the multi-decade legal-to-recovery pipeline is a unique feature of this case and worth flagging as a precedent. From 2014-02 (filing) to 2024-07 (first creditor BTC distribution) to 2025-10-31 (final-distribution deadline) is a >11-year span, with the Vinnik laundering criminal track running in approximate parallel from 2017 (Greek arrest) through 2024 (US plea) to 2025 (US release in prisoner-exchange). No other OAK-record case has this shape — most exchange-incident cases resolve, in either direction, within ~5 years. Contributors writing recovery-and-accountability worked examples that may take similarly long horizons (notably any large-scale T11 case where in-kind asset claims survive multi-year proceedings) should treat Mt. Gox as the only fully-worked-out precedent for what a decade-plus civil-rehabilitation-with-in-kind-distribution arc actually looks like end-to-end.