What happened at Mt. Gox: the bitcoin that drained out for years before anyone noticed
When the Tokyo bitcoin exchange Mt. Gox collapsed in 2014, about 850,000 bitcoins were missing, and US prosecutors later said most of them had been leaking out since 2011.[1][2] This case file covers how a theft could run for years unnoticed, what happened to the people involved, and the simple check that would have caught it early.
What happened
Mt. Gox was a bitcoin exchange based in Tokyo, a place where people bought, sold and stored the currency.[2] Customers deposited bitcoin and cash, and the exchange showed each of them a balance on its own books.
In 2014 the exchange stopped operating and went into bankruptcy, saying about 850,000 bitcoins had disappeared. At the time they were estimated to be worth about 48 billion yen.[1][2] In March 2014 it reported finding about 200,000 bitcoins in an older wallet it had overlooked, which reduced the gap but did not close it.[3]
Years later, US prosecutors laid out their account of where most of the rest went. In charges announced in 2023, they said 2 Russian nationals gained unauthorized access to the server that held Mt. Gox's cryptocurrency wallets in September 2011, and that about 647,000 bitcoins were taken from then until at least May 2014, most of the bitcoin that belonged to customers.[1]
How it worked
An exchange keeps 2 sets of numbers. One is the ledger: what the exchange says each customer owns. The other is what is actually sitting in its wallets on the blockchain. On a healthy day, the wallets hold at least as much as the ledger promises.
According to prosecutors, once the attackers had access to the wallet server, bitcoin moved out gradually over a long period. They said the coins were then laundered through other online exchanges, through an account on Mt. Gox itself, and through a deal with a New York bitcoin broker disguised as an advertising contract, which moved more than $6.6 million in wire transfers and helped launder more than 300,000 of the stolen bitcoins.[1]
The customer balances on Mt. Gox's own books kept showing what people believed they owned. As long as nobody compared those balances to what was really in the wallets, the gap could keep growing. The 200,000 coins later found in an old wallet show the same weakness from a different angle: the exchange did not have a clear, current picture of what it held.[3]
What it cost
Customers bore the loss. Hundreds of thousands of bitcoins that people thought were safe in their accounts were gone when the exchange shut down, and the bankruptcy turned them into creditors hoping to recover part of what they had.[1][2]
The exchange's chief executive, Mark Karpeles, was prosecuted in Japan. In March 2019 the Tokyo District Court found him guilty of manipulating data and gave him a 2.5-year prison sentence, suspended for 4 years. It found him not guilty of embezzling money through customer accounts, and he was not accused of the theft of the missing bitcoin.[2]
In the US, the 2 Russian nationals were charged in 2023 with conspiracy to commit money laundering, which carries a maximum of 20 years in prison. Prosecutors say they carried out the theft; the charges are allegations.[1]
The missing control
The missing control: daily reconciliation of wallet holdings against the ledger. Every day, the exchange should have compared what its books said customers owned with what was actually in its wallets, and treated any shortfall as an emergency.
That check would have turned a multi-year leak into a problem found within days. According to prosecutors, the theft started in September 2011 and ran until at least May 2014.[1] A daily count would have flagged the first unexplained drop, prompted an investigation of the wallet server, and limited the damage to a small fraction of what was lost. It would also have caught the forgotten 200,000 coins long before a bankruptcy forced a search.
What to do in your business
- Reconcile your bank accounts often. Match your books against bank and card statements at least weekly, and investigate any difference right away instead of carrying it forward.
- Split the counting from the handling. The person who reconciles accounts should not be the same person who moves the money.
- Count your inventory. Do regular spot counts of stock, cash drawers and gift cards against what the system says you have. Slow shrinkage hides in averages.
- Lock down the systems that hold value. Limit who can reach payment, banking and accounting systems, use strong sign-ins, and review access every quarter.
- Know where everything is. Keep a written list of every account, wallet and payment service your business uses, so nothing is forgotten or left unmonitored.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.