Across 81 documented exchange breaches since 2011, only 40% ended with users fully reimbursed, which makes an exchange's ability to absorb a loss the single thing worth checking before you deposit.
MEXC is our top pick on that measure within this comparison: Hacken's independent verification of 10 August 2026 confirmed reserve coverage above 100% on all four in-scope assets, and MEXC's own reserve page puts BTC coverage at 287.53% on the same snapshot.
The full record of all 81 incidents, with the outcome for users in every row, follows below.
Key Takeaways
MEXC is our top pick for custody risk in this comparison: Hacken independently verified reserve coverage above 100% on BTC, ETH, USDT and USDC on 10 August 2026, alongside a $100 million Guardian Fund.
We have documented 81 centralised exchange hacks across 72 platforms from June 2011 to August 2026, totalling about $5.1 billion at the value of each breach.
Users were fully reimbursed in only 32 of those 81 incidents, leaving 44 where someone was left short.
Exchanges that made users whole survived at 79%, against 26% for those that did not.
Cold wallet and signing failures caused 6% of incidents but 44% of the money lost, averaging about ten times more per event than hot wallet breaches.
MEXC is not a licensed exchange in the way Coinbase, Kraken or Gemini are in their home markets, and readers who need a regulated counterparty should weigh that first.
When an exchange is breached, the first question users ask is not how the attackers got in.
It is whether the money is coming back.
That question is surprisingly hard to answer, because almost every published list of exchange hacks records the date and the dollar figure and then stops.
The outcome, which is the part that determines whether a user lost anything at all, gets left in the footnotes or omitted entirely.
So we built the outcome into the table, and the aggregate picture it produces is the reason this page leads with a recommendation rather than ending with one.
This is the column most public lists leave out, and it produces the least comfortable chart on this page.
Full reimbursement happened in 32 of 81 incidents.
Users were partially reimbursed in 16 cases, received nothing in 14, and are still waiting in 14 more.
Five incidents involved no loss of user funds at all, either because the attack was caught or because it hit corporate rather than customer assets.
The trend is genuinely improving.
Insurance funds, larger balance sheets and the reputational cost of getting it wrong have all pushed in the same direction since 2018.
Even so, a depositor at a randomly chosen breached exchange has had slightly worse than even odds of being made whole.
There is one further correlation worth stating carefully.
Of the 29 exchanges whose incidents all ended in full reimbursement, 23 are still operating today, a survival rate of 79%.
Of the 43 exchanges that left users short in at least one incident, 11 are still operating, a rate of 26%.
Causation runs in both directions here and we are not claiming otherwise: strong platforms can afford to pay, and paying keeps platforms strong.
What the correlation does establish is that an exchange's willingness to absorb a loss is not charity.
It is the same underlying capacity that determines whether it is still there in three years.
The four reimbursement models that actually worked, across 81 incidents, were a pre-funded insurance pool (KuCoin), the company's own cash (Coincheck, which repaid about $440 million to all 260,000 affected customers in early 2018, at a fixed rate below the value at the time of the theft), a debt token redeemed over time (Bitfinex, which first cut every account balance by about 36% and issued BFX tokens, all of which were redeemed in dollars within eight months), and emergency third-party funding followed by independent re-verification (Bybit). Nothing else has reliably returned money to users.
Whether a breached exchange makes users whole has very little to do with how large the loss was.
It has a great deal to do with whether the platform had the balance sheet and the internal controls to absorb one before anything happened.
KuCoin covered $275 million in 2020 because it had an insurance fund already sitting there.
Bybit replenished its reserves within days in 2025 through emergency funding from trading firms, then had Hacken re-verify the position, and withdrawals stayed open throughout. CoinBene lost a comparable sum in 2019, denied that a breach had happened, and users recovered nothing.
The uncomfortable part for anyone choosing an exchange is that you cannot tell these apart from the outside after the fact.
You have to check before you deposit, and three things are verifiable in advance.
A one-off snapshot proves nothing about the month you actually need it.
MEXC publishes proof of reserves monthly, verified independently by the blockchain security firm Hacken, which publishes each report itself rather than submitting it to MEXC for approval.
The verification dated 10 August 2026 covered BTC, ETH, USDT and USDC across 27 networks and confirmed coverage above 100% on all four.
MEXC maintains a $100 million Guardian Fund set aside for exactly the kind of event catalogued on this page, separate from the futures insurance fund that covers liquidation shortfalls.
Every platform in this database that covered a loss in full had a funded reserve in place before the incident, not a commitment made afterwards.
MEXC's Merkle tree implementation lets any user confirm their own balance is included in the reported liabilities, and the validation tool is published as open source so the check does not depend on taking our word for it. Here is what those reserve figures mean for a deposit, using the numbers from the August 2026 report.
MEXC reported 12,312.75 BTC in verified on-chain reserves against 4,282.20 BTC of user liabilities.
Divide one by the other and every 1 BTC a user held was backed by 2.88 BTC of reserves that Hacken confirmed MEXC controlled, by requiring a signed outgoing transaction from each address.
The USDT figure was 1,939,932,810.71 in reserves against 1,691,925,884.19 in liabilities, or 114.65%.
Both numbers sit on the public proof of reserves page with the wallet addresses attached, so the arithmetic is reproducible by anyone with a calculator. Two honest limits belong next to that.
Hacken's own report states that a proof of reserves is a point-in-time attestation of on-chain assets and should not be treated as a comprehensive financial audit of a company's liabilities or overall financial position.
That caveat is correct, and it applies to every exchange publishing this kind of report, including ours.
The second limit is that MEXC is not a licensed exchange in the sense that Coinbase, Kraken or Gemini are licensed in their home markets, and readers who want a regulated counterparty above all else should weight that accordingly.
What a monthly independent verification does buy is the thing CoinBene's users did not have: a way to check the position yourself, before you need it.
Most lists of "crypto exchange hacks" quietly mix three different kinds of event, which is why their totals disagree so widely.
Defining the boundary is the first thing this database does.
An external or internal attacker gained unauthorised control of assets the exchange was holding on behalf of users.
This is the only category recorded in the table below.
No custodian held the funds, the failure was in smart contract or bridge logic, and the remedies available afterwards are completely different.
Including them inflates exchange totals by billions and tells a user nothing about the risk of leaving coins on an exchange account.
FTX is the case that gets miscounted most often.
The roughly $477 million that left FTX wallets in November 2022 happened after the company had already filed for bankruptcy, and the $8.9 billion customer shortfall behind that collapse came from misappropriation rather than intrusion.
Thodex was an exit scam.
Zondacrypto, which stopped honouring withdrawals in 2026 after admitting that the private keys to a cold wallet holding 4,503 BTC had never been handed over during a 2021 ownership change, is a governance failure with no attacker in it at all.
Category C events destroyed more user money than most Category A events, so excluding them is not a way of making the numbers look smaller.
It is a way of making them mean something.
A user deciding where to keep trading funds needs to know how often custodians get breached and what happens next, and that question only has an answer if the dataset holds one type of event.
Ranked by value at the time of the breach, and restricted to Category A, the largest fifteen look like this.
Rank | Exchange | Date | Reported loss | Outcome for users |
1 | Bybit | February 2025 | $1.46 billion | Fully reimbursed |
2 | Coincheck | January 2018 | $530 million to $547 million | Fully reimbursed |
3 | Mt. Gox | February 2014 | About $460 million | Partially reimbursed, still running |
4 | DMM Bitcoin | May 2024 | $305 million to $320 million | Fully reimbursed, platform wound down |
5 | KuCoin | September 2020 | $275 million to $281 million | Fully reimbursed |
6 | WazirX | July 2024 | $235 million | Partially reimbursed, court-supervised |
7 | BitMart | December 2021 | $150 million to $196 million | Partially reimbursed |
8 | BitGrail | February 2018 | $146 million to $170 million | Partially reimbursed by court order |
9 | Poloniex | November 2023 | $114 million to $126 million | Fully reimbursed |
10 | Liquid | August 2021 | $80 million to $97 million | Fully reimbursed |
11 | Nobitex | June 2025 | $82 million to $90 million | Unresolved |
12 | AscendEX | December 2021 | $78 million to $80 million | Fully reimbursed |
13 | CoinBene | March 2019 | $40 million to $105 million | Not reimbursed |
14 | Bitfinex | August 2016 | $72 million | Fully reimbursed |
15 | CoinEx | September 2023 | $54 million to $70 million | Fully reimbursed |
Loss figures are stated at the value on the date of the incident and verified as of 28 August 2026 against mainstream media reporting and maintained blockchain security databases. Where credible sources give materially different figures, both ends of the range are shown.
Those fifteen incidents account for roughly 60% of the total value recorded in this database.
Two patterns in that table are worth pausing on.
The first is that being fully reimbursed does not mean the exchange survived, as DMM Bitcoin demonstrates: it covered the loss, then transferred its accounts to another Japanese operator and wound down anyway.
The second is that Mt. Gox is still not finished.
Every Category A incident we could verify, newest first.
Date | Exchange | Jurisdiction | Reported loss at the time | Same assets today | Attack vector | Outcome for users | Platform status |
15 April 2026 | Grinex | Kyrgyzstan | $13 million to $15 million | n/a | Hot wallet infrastructure (the platform attributed the loss to state actors; analysts have questioned that account) | Unresolved | Closed |
27 November 2025 | Upbit | South Korea | $30 million | n/a | Key-inference vulnerability | Fully reimbursed | Operating |
14 August 2025 | BtcTurk | Turkiye | $38 million to $54 million | n/a | Hot wallet compromise (a further incident was reported in January 2026 but is not recorded in maintained security-firm databases) | Unresolved | Operating |
24 July 2025 | WOO X | Global | $14 million | n/a | Phishing to dev environment | No user funds lost | Operating |
19 July 2025 | CoinDCX | India | $44 million | n/a | Server breach | No user funds lost | Operating |
16 July 2025 | BigONE | Seychelles | $27 million | n/a | Supply chain (CI/CD) | Fully reimbursed | Operating |
18 June 2025 | Nobitex | Iran | $82 million to $90 million | n/a | Key compromise; funds burned | Unresolved | Operating |
8 May 2025 | BitoPro | Taiwan | $12 million | n/a | Malware | Unresolved | Operating |
21 February 2025 | Bybit | UAE | $1.46 billion to $1.50 billion | n/a | Cold-wallet signing compromise | Fully reimbursed | Operating |
23 January 2025 | Phemex | Singapore | $37 million to $85 million | n/a | Hot wallet private key | Fully reimbursed | Operating |
1 January 2025 | NoOnes | Global | $8 million | n/a | Bridge exploit | Unresolved | Operating |
20 September 2024 | BingX | Singapore | $43 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
18 July 2024 | WazirX | India | $235 million | n/a | Third-party multisig custody | Partially reimbursed | Operating |
22 June 2024 | BtcTurk | Turkiye | $54 million to $55 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
19 June 2024 | Kraken | United States | $3 million | n/a | Bug-bounty exploit | No user funds lost | Operating |
31 May 2024 | DMM Bitcoin | Japan | $305 million to $320 million | About $359 million (4,503 BTC) | Unauthorised outflow | Fully reimbursed | Closed |
22 November 2023 | HTX | Global | $30 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
10 November 2023 | Poloniex | Global | $114 million to $126 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
17 October 2023 | | Philippines | $12 million | n/a | Suspected exploit | Unresolved | Operating |
12 September 2023 | CoinEx | Global | $54 million to $70 million | n/a | Hot wallet private key | Fully reimbursed | Operating |
9 April 2023 | GDAC | South Korea | $13 million | n/a | Hot wallet compromise | Unresolved | Closed |
1 November 2022 | Deribit | Global | $28 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
17 January 2022 | | Singapore | $34 million | n/a | 2FA bypass on withdrawals | Fully reimbursed | Operating |
11 December 2021 | AscendEX | Singapore | $78 million to $80 million | n/a | Hot wallet compromise | Fully reimbursed | Closed |
8 December 2021 | LCX | Liechtenstein | $7 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
5 December 2021 | BitMart | Global | $150 million to $196 million | n/a | Hot wallet private key | Partially reimbursed | Closed |
19 August 2021 | Liquid | Japan | $80 million to $97 million | n/a | Warm wallet compromise | Fully reimbursed | Closed |
29 April 2021 | Hotbit | Global | Not disclosed | n/a | Database compromise | No user funds lost | Closed |
1 February 2021 | Cryptopia | New Zealand | $45K | n/a | Breach during liquidation | Unresolved | Closed |
23 December 2020 | Livecoin | Russia | Not disclosed | n/a | Server takeover | Unresolved | Closed |
21 December 2020 | EXMO | United Kingdom | $4 million | n/a | Hot wallet compromise | Partially reimbursed | Operating |
25 September 2020 | KuCoin | Seychelles | $275 million to $281 million | n/a | Hot wallet private key | Fully reimbursed | Operating |
8 September 2020 | Eterbase | Slovakia | $5 million | n/a | Hot wallet compromise | Unresolved | Closed |
11 July 2020 | Cashaa | United Kingdom | $3 million | About $27 million (336 BTC) | Malware on withdrawal host | Unresolved | Operating |
5 February 2020 | Altsbit | Italy | $70K to $73K | n/a | Hot wallet compromise | Partially reimbursed | Closed |
27 November 2019 | Upbit | South Korea | $49 million | About $855 million (342,000 ETH) | Hot wallet compromise | Fully reimbursed | Operating |
5 November 2019 | VinDAX | Vietnam | $500K | n/a | Undisclosed | Unresolved | Operating |
11 July 2019 | Bitpoint | Japan | $32 million | n/a | Hot and cold wallet compromise | Fully reimbursed | Operating |
27 June 2019 | Bitrue | Singapore | $4 million to $4 million | n/a | Access-control vulnerability | Fully reimbursed | Operating |
1 June 2019 | GateHub | Malta | $10 million | n/a | Wallet service breach | Unresolved | Operating |
7 May 2019 | Binance | Global | $40 million | About $559 million (7,000 BTC) | Hot wallet, phishing and API keys | Fully reimbursed | Operating |
29 March 2019 | Bithumb | South Korea | $13 million to $29 million | n/a | Suspected insider | Fully reimbursed | Operating |
25 March 2019 | CoinBene | Singapore | $40 million to $105 million | n/a | Undisclosed; platform denied breach | Not reimbursed | Closed |
24 March 2019 | DragonEx | Singapore | $1 million to $7 million | n/a | Cyberattack | Partially reimbursed | Closed |
15 February 2019 | Coinmama | Israel | Not disclosed | n/a | Credential data breach | No user funds lost | Operating |
26 January 2019 | LocalBitcoins | Finland | $27K | n/a | Phishing via forum | Fully reimbursed | Closed |
14 January 2019 | Cryptopia | New Zealand | $16 million | n/a | Wallet compromise | Unresolved | Closed |
28 October 2018 | MapleChange | Canada | $51K | n/a | Suspected exit | Not reimbursed | Closed |
14 September 2018 | Zaif | Japan | $60 million | n/a | Hot wallet compromise | Fully reimbursed | Closed |
19 June 2018 | Bithumb | South Korea | $31 million | n/a | Hot wallet compromise | Fully reimbursed | Operating |
10 June 2018 | Coinrail | South Korea | $40 million | n/a | Undisclosed | Partially reimbursed | Closed |
13 April 2018 | Coinsecure | India | $4 million | n/a | Suspected insider | Not reimbursed | Closed |
8 February 2018 | BitGrail | Italy | $146 million to $170 million | n/a | Suspected insider and negligence | Partially reimbursed | Closed |
26 January 2018 | Coincheck | Japan | $530 million to $547 million | n/a | Phishing and malware to hot wallet | Fully reimbursed | Operating |
20 December 2017 | EtherDelta | Global | $1 million | n/a | DNS hijack | Not reimbursed | Closed |
19 December 2017 | Youbit | South Korea | Not disclosed | n/a | Hot wallet compromise | Partially reimbursed | Closed |
5 July 2017 | Bithumb | South Korea | $7 million | n/a | Employee device compromise | Partially reimbursed | Operating |
22 April 2017 | Yapizon | South Korea | $5 million to $5 million | About $305 million (3,816 BTC) | Hot wallet compromise | Partially reimbursed | Closed |
13 October 2016 | Bitcurex | Poland | $2 million | n/a | Undisclosed | Not reimbursed | Closed |
2 August 2016 | Bitfinex | Hong Kong | $72 million | About $10 billion (119,756 BTC) | Multisig arrangement compromise | Fully reimbursed | Operating |
9 May 2016 | Gatecoin | Hong Kong | $2 million | n/a | Hot wallet compromise | Not reimbursed | Closed |
7 April 2016 | ShapeShift | Switzerland | $200K to $230K | n/a | Insider | Fully reimbursed | Operating |
14 February 2015 | BTER | China | $2 million | About $572 million (7,170 BTC) | Cold wallet compromise | Partially reimbursed | Closed |
14 February 2015 | KipCoin | China | $728K | n/a | Server compromise | Not reimbursed | Closed |
4 January 2015 | Bitstamp | Luxembourg | $5 million | About $2 billion (19,000 BTC) | Social engineering to hot wallet | Fully reimbursed | Operating |
2 January 2015 | 796 Exchange | China | $270K | n/a | Service compromise | Partially reimbursed | Closed |
14 July 2014 | Cryptsy | United States | $10 million | n/a | Malware backdoor | Not reimbursed | Closed |
13 July 2014 | MintPal | United Kingdom | $2 million to $2 million | n/a | Hot wallet compromise | Not reimbursed | Closed |
4 March 2014 | Poloniex | United States | $50K to $68K | About $6 million (76 BTC) | Withdrawal logic flaw | Fully reimbursed | Operating |
2 March 2014 | Flexcoin | Canada | $600K | About $72 million (896 BTC) | Hot wallet compromise | Not reimbursed | Closed |
24 February 2014 | Mt. Gox | Japan | $460 million | About $68 billion (850,000 BTC) | Multi-year compromise | Partially reimbursed | Closed |
7 February 2014 | Picostocks | Global | $4 million | n/a | Hot and cold wallet compromise | Not reimbursed | Closed |
11 November 2013 | Bitcash.cz | Czech Republic | $100K | n/a | Server compromise | Not reimbursed | Closed |
7 November 2013 | Inputs.io | Australia | $1 million | About $327 million (4,100 BTC) | Hosting account compromise | Not reimbursed | Closed |
1 May 2013 | Vircurex | Global | $352K | n/a | VPS credential compromise | Partially reimbursed | Closed |
12 September 2012 | Bitfloor | United States | $250K | About $2 billion (24,000 BTC) | Unencrypted key backup | Partially reimbursed | Closed |
13 July 2012 | Bitcoinica | Global | $300K | n/a | Third-party account compromise | Fully reimbursed | Closed |
11 May 2012 | Bitcoinica | Global | $87K | n/a | Server and database breach | Partially reimbursed | Closed |
1 March 2012 | Bitcoinica | Global | $228K | About $3 billion (43,554 BTC) | Host provider compromise | Fully reimbursed | Closed |
5 October 2011 | Bitcoin7 | Global | Not disclosed | n/a | Server and user database breach | Not reimbursed | Closed |
19 June 2011 | Mt. Gox | Japan | $9 million | n/a | Auditor credential compromise | Fully reimbursed | Closed |
Data verified as of 28 August 2026 against mainstream media reporting, maintained blockchain security databases and, where available, each platform's own incident disclosure. Figures are stated at the value on the date of the incident. Where credible sources give materially different totals, the range is shown rather than a single chosen figure.
Several widely cited exchange-hack lists still end in mid-2024, which means they miss the largest theft in the industry's history and everything that followed it.
2025 was the worst year on record by value, with roughly $1.8 billion taken across ten incidents.
Bybit alone accounts for about 80% of that, but the other nine matter more for what they say about how attacks changed.
BitoPro lost about $11.5 million in May through malware, in an incident the exchange attributed to North Korean actors.
June brought something new: the roughly $90 million taken from Iran's Nobitex was not laundered but sent to addresses nobody controlled, destroying it as a political gesture rather than stealing it for profit. July produced three incidents in nine days.
CoinDCX lost $44.2 million from an internal operational wallet and absorbed the entire amount from its corporate treasury, leaving customer balances untouched.
WOO X lost $14 million after a phishing attack compromised a team member's device and gave attackers access to a development environment.
August brought BtcTurk's second major breach in fourteen months, and November brought Upbit's second in six years, this time through a vulnerability that allowed private keys to be inferred.
In July 2026 South Korea's Financial Supervisory Service opened a sanctions process against Dunamu over the incident, which is a reminder that covering a loss and satisfying a regulator are two different tests.
2026 has been quieter at exchanges, though not elsewhere in crypto.
The one Category A incident so far is Grinex in April, and it is an unusual entry.
We have recorded it with that caveat attached rather than repeating the platform's account.
The received wisdom, repeated across most write-ups of this topic, is that hot wallet compromises cause the overwhelming majority of exchange losses.
By incident count that is defensible.
By money it is wrong, and the gap between the two is the most useful finding in this dataset.
Hot and warm wallet key compromises are the most common failure at 31 of 81 incidents, and they account for 28% of value lost.
Cold wallet and signing-process failures happened five times.
Those five events account for 44% of every dollar ever taken from a centralised exchange.
The average hot wallet breach costs about $46 million; the average cold wallet or signing failure costs about $450 million, roughly ten times more.
The reason is structural rather than mysterious.
Hot wallets hold operating float, so a compromise drains what was needed for that day's withdrawals.
Cold storage holds the reserve, so when the process guarding it fails the exposure is the whole balance.
Bybit is the clearest example, and it is widely mis-described.
The February 2025 attack did not breach a hot wallet.
Attackers compromised the interface used to review and sign a routine transfer out of cold storage, so the signers approved a transaction that did not do what their screen said it did.
WazirX in 2024 failed the same way through a third-party multisig custody arrangement, and Coincheck in 2018 lost $530 million because it had kept an enormous NEM balance in a single hot wallet with no multisignature protection at all.
The third pattern worth naming is that attacks have moved off-chain.
BigONE's attackers changed server logic without stealing a key.
WOO X's attackers phished a laptop.
CoinDCX's attackers compromised an internal operational account.
None of those required finding a flaw in a blockchain or a smart contract, which is why an exchange's operational security now matters more to a depositor than its cryptography.
Because most early thefts were denominated in bitcoin, the historical loss figures understate what was actually taken by an enormous margin.
Mt. Gox lost about $460 million in 2014.
The same 850,000 BTC would be worth roughly $68 billion today.
Bitfloor's 24,000 BTC was written off as a $250,000 loss in 2012 and would now be about $1.9 billion.
Bitcoinica's March 2012 breach of 43,554 BTC was reported at $228,000 and would now stand at roughly $3.5 billion.
This is not a scoreboard, and it is not an argument that those users were robbed of today's prices.
It is a reminder that custody decisions compound in the same direction as prices do.
Several large exchanges have never disclosed a custody breach, and the marketing language around that fact deserves a closer look than it usually gets.
Kraken is frequently described as never having been hacked, which is close to true but not exactly true.
In June 2024 a security researcher reported a deposit-crediting flaw to Kraken's bug bounty programme, then shared it with two others who withdrew about $3 million from Kraken's own treasury.
Kraken's chief security officer said the parties refused to return the funds and publicly called the demand extortion, the security firm CertiK disputed that account, and the funds were returned days later. No customer lost funds, the bug was patched in 47 minutes, and the incident is in our table because a clean record that quietly omits it is less credible than one that includes it.
Gemini has likewise reported no custody breach, though users of its Earn product lost access to funds through the bankruptcy of a third-party lending partner, which is a Category C event and not a hack.
MEXC belongs in the same paragraph, held to the same standard.
MEXC has operated since 2018 and has not disclosed a comparable custody loss, and as of 28 August 2026 no platform-level custody breach at MEXC has been publicly reported or documented by mainstream media or by the maintained blockchain security databases used to compile this page.
That is a checkable statement rather than a promise, and it is the only form the claim should ever take.
An absence of incidents is evidence about the past.
Coincheck, Bybit and KuCoin all had clean records right up until the morning they did not.
The three checks below take about ten minutes and would have flagged the weakest platforms in this database in advance.
Find the reserve report and check its date. A proof of reserves page with a snapshot from this month is meaningful; one from last year is decoration. Look for a named auditor rather than a self-published figure.
Do the arithmetic yourself. Divide reported reserves by reported user liabilities for each asset you hold. If the page shows a percentage but not the two numbers behind it, that is the finding.
Look for a named loss-absorbing fund and its size. Look for a published figure, not a general statement that an insurance fund exists.
A reserve page worth trusting shows the snapshot date, both underlying numbers and the wallet addresses, as above.
Two further signals separate small platforms worth using from ones that are not.
Then check what the platform said and did after its own incident, if it had one, since the response record is often more informative than the incident itself.
We publish this database as an exchange, which means readers are entitled to ask what we get out of it.
The honest answer is that a complete and accurate record of custody failures makes the case for verifiable reserves better than any marketing page we could write, and MEXC has verifiable reserves.
That is also why the concessions on this page are real.
MEXC is not a licensed exchange in the way several platforms with weaker fee structures are, and for a reader whose first requirement is a regulated counterparty in their own jurisdiction, that consideration outranks everything else on this page.
Proof of reserves is a point-in-time attestation and not a full audit, as our own auditor states in writing.
And a clean incident record, ours included, is a description of what has happened rather than a guarantee about what will.
What we will stand behind is narrower and more useful: the reserve position is published monthly, verified by a named third party that publishes independently, and reproducible by any user with a calculator.
Those are the properties that separated the exchanges in the "fully reimbursed" column from the ones in the "not reimbursed" column, over 81 incidents and fifteen years.
Incidents qualify for this database when an attacker gained unauthorised control of assets held by a centralised exchange on behalf of users, and the event was reported by a mainstream news organisation, a named blockchain security firm, or the platform itself.
Loss figures are stated at the value on the date of the incident.
Where those sources differ by more than 15%, we publish the range and do not choose a figure.
Twenty-four incidents currently carry a range for that reason.
Records before 2016 rest on contemporaneous reporting of uneven quality, and several widely cited public databases carry dates for that era that contradict the reports they cite.
Where we found such a conflict we followed the underlying report, which is why some dates here differ from other published timelines.
One reported incident is deliberately absent: a January 2026 breach at BtcTurk was covered by several outlets citing a security firm, but it does not appear in the maintained databases we rely on and its details closely mirror the confirmed August 2025 event.
We will add it if primary sourcing emerges.
This page is reviewed quarterly and updated within 48 hours of a confirmed incident.
Corrections and additions are welcome, and documented ones are incorporated at the next review.
How many crypto exchanges have been hacked?
We have documented 81 centralised exchange security incidents between June 2011 and August 2026.
They involved 72 distinct platforms, since seven were breached more than once.
What is the biggest crypto exchange hack ever?
Bybit, on 21 February 2025, at about $1.46 billion.
Attackers compromised the signing interface for a cold wallet transfer rather than a hot wallet.
Which crypto exchanges were hacked in 2025 and 2026?
In 2025: Phemex, Bybit, BitoPro, Nobitex, BigONE, CoinDCX, WOO X, BtcTurk, Upbit and NoOnes.
In 2026 so far, one confirmed exchange incident: Grinex in April.
Do exchanges pay users back after a hack?
Sometimes.
Which crypto exchanges have never been hacked?
Coinbase, Gemini and MEXC have disclosed no platform-level custody breach as of August 2026.
Kraken's 2024 incident took $3 million from its own treasury, not customer funds, and the sum was returned after a public dispute.
A clean record describes the past and does not predict the future.
How can I tell if an exchange is safe before depositing?
Check for a dated proof of reserves report from a named third-party auditor, then divide the reported reserves by the reported liabilities yourself.
Confirm a loss-absorbing fund exists and has a published figure attached.
Was FTX a hack?
Not primarily.
About $477 million left FTX wallets after the bankruptcy filing, but the $8.9 billion customer shortfall came from misappropriation, so FTX is excluded from this database.
Are hot wallets or cold wallets the bigger risk?
Hot wallet compromises are far more frequent, at 31 of 81 incidents.
Cold wallet and signing failures are rarer but roughly ten times more expensive per event.
This page is a historical record and is not a security guarantee for any platform named on it, including MEXC.
Holding assets on any centralised exchange means accepting custody risk that self-custody does not carry, and proof of reserves reduces that risk without eliminating it.
This article is informational for readers in the United States and the United Kingdom, where the platforms discussed may not be available or authorised.
Readers in the European Economic Area should note that MEXC is not authorised under MiCA and appears on the European Securities and Markets Authority register of non-compliant entities following a Dutch AFM decision of 24 September 2025.
Readers in Japan should note that MEXC is not registered with the Financial Services Agency and appears on its list of unregistered operators.
Nothing here is investment advice, and reserve figures, fund sizes and platform availability change, so confirm current terms on official pages before trading.
The one habit that separates users who kept their money from users who did not is checking the reserve position before it matters rather than after.