The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
In 2016 a hacker pulled 119,754 bitcoin out of the Bitfinex exchange, worth about $71 million at the time, and then left most of it sitting in one wallet for more than 5 years.[1][3] When agents finally seized it in 2022, the untouched coins were worth $3.6 billion.[2] This case file covers how the theft happened, how the money was traced, what it cost, and the control that would have stopped it.
What happened
Bitfinex was one of the world's largest bitcoin exchanges, based in Hong Kong. To reassure customers, it kept their bitcoin in separate wallets that needed more than one digital signature to move money, with a security company co-signing transactions.[5][6]
On August 2, 2016, Bitfinex discovered that 119,756 bitcoin had left customer wallets and halted all trading, deposits and withdrawals.[5][6] The figure later used by federal prosecutors was 119,754 bitcoin, moved in more than 2,000 transactions that the intruder authorized himself.[1] Bitcoin's price fell by about 20 percent on the news.[6]
Within days Bitfinex decided to spread the loss across every customer account, cutting balances by about 36 percent, including for customers who held no bitcoin. In place of the missing money, it issued customers IOU tokens that could later be redeemed or swapped for shares in its parent company.[4][5]
Then the trail went quiet. Ilya Lichtenstein, the man who later admitted to the hack, moved only a small slice of the bitcoin over the next 5 years. The rest stayed parked in the wallet that had received it.[2]
How they got in
Prosecutors said Lichtenstein broke into Bitfinex's network using advanced hacking techniques, then used that access to approve the withdrawals as if they were legitimate.[1] Afterward he deleted access credentials and log files from the network to hide his tracks.[1]
The exact route has never been fully explained in public. What was reported at the time is telling: the protections that were supposed to slow a big withdrawal, including two-factor sign-ins and daily limits on how much could be signed for, did not stop it.[6] The co-signing company said it found no sign its own servers were breached.[6] In other words, the second signature existed on paper, but once the intruder controlled the exchange's side, the checks behind it did not catch 2,000 unusual withdrawals.
How it was caught
Bitcoin moves on a public ledger, so every transfer out of the theft wallet could be watched. About 25,000 bitcoin were moved through a web of fake identities, automated transactions, darknet markets, other cryptocurrencies and U.S. business accounts, and some was even turned into gold coins.[1][2] Investigators followed those trails to accounts linked to Lichtenstein and his wife.
Search warrants on online accounts they controlled turned up a file holding the private keys to the theft wallet. With those keys, agents seized more than 94,000 bitcoin, then worth about $3.6 billion, at the time the largest financial seizure in Justice Department history.[2][3] The couple were arrested in Manhattan on February 8, 2022.[2]
What it cost
Lichtenstein pleaded guilty in August 2023 to money laundering conspiracy and admitted to the hack. On November 14, 2024, he was sentenced to 5 years in federal prison.[1] His wife, who also pleaded guilty, received 18 months.[7] Both cooperated with investigators.[8]
Bitfinex customers took the immediate hit through the 36 percent cut in 2016.[4] In January 2025 prosecutors asked the court to return the recovered bitcoin to Bitfinex in kind, since the exchange was the victim of the crimes charged.[7]
The missing control
The missing control: a truly independent second approval on large withdrawals. Money that size should not move unless a separate person or system, outside the reach of whoever made the request, confirms it first.
Bitfinex had a second signature, but it did not act as a real brake. More than 2,000 withdrawals emptying customer wallets in one go is the kind of pattern an independent approver would question. A hard ceiling on how much can leave in a day, enforced somewhere the intruder could not reach, and a human call-back before breaking it, would have capped the loss at a fraction of the total or stopped it outright.[1][6]
What to do in your business
- Require two people for big payments. Set a dollar amount above which any payment, transfer or payout needs approval from a second person who did not start it.
- Use your bank's controls. Most business banks offer dual approval and daily limits for wires and ACH. Turn them on and set the limits low enough to hurt a thief, not you.
- Keep approvals off the same device. The second approval should come from a different login and device, so one stolen account cannot do both.
- Watch for bursts. Ask your bank or payment platform for alerts on unusual volume, such as many transfers in a short window or new payees.
- Protect your logs. Send system and account logs somewhere an intruder cannot delete them, such as a separate cloud account, so you can reconstruct what happened.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- How a fake Google support call stole 4,100 bitcoin from one person
- How the Punjab National Bank fraud hid $1.8 billion outside the bank's own books
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, District of Columbia: Bitfinex hacker sentenced in money laundering conspiracy involving billions in stolen cryptocurrency
- U.S. Department of Justice: Two arrested for alleged conspiracy to launder $4.5 billion in stolen cryptocurrency
- NBC News: Two arrested allegedly trying to launder billions in stolen bitcoin
- Fin24: Hacked bitcoin exchange users lose 36% of deposits
- Fortune: Bitfinex hack and the law for Hong Kong customers
- Help Net Security: $77 million in Bitcoin stolen from Bitfinex exchange
- The Block: US government says stolen bitcoin from 2016 Bitfinex hack should be returned to the exchange in-kind
- Cyber Security News: Bitfinex bitcoin heist sentence