Skip to content
Beginner Guides

What Happens to Your Crypto When an Exchange Fails

Whether you own the assets or merely have a claim against the company is decided by paperwork written long before the failure — not by a balance on a screen.

Incident Tracker

All incidents →
Disclosed Incident Chain Reported impact Status
Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check
Signing interface compromise · Supply chain
Ethereum approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 Feb 2025) Resolved
Radiant Capital Signing Compromise, October 2024: What Happened & What to Check
Key compromise · Signing interface compromise
Arbitrum, BNB Chain approx. US$50 million(Radiant Capital, 17 Oct 2024) Contained
WazirX Multisig Compromise, July 2024: What Happened & What to Check
Key compromise · Signing interface compromise
Ethereum approx. US$234.9 million(WazirX, 18 Jul 2024) Contained
DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check
Key compromise
Bitcoin 4,502.9 BTC(DMM Bitcoin, 31 May 2024) Resolved
Munchables Insider Key Compromise, March 2024: What Happened & What to Check
Access control · Insider access
Blast approx. US$62 million (returned)(Munchables, 26 Mar 2024) Resolved
Orbit Chain Bridge Compromise, December 2023: What Happened & What to Check
Bridge exploit · Key compromise
Ethereum, Orbit Chain approx. US$81.5 million(Orbit Chain, 1 Jan 2024) Contained

Regulation watch

All jurisdictions →

China

The prohibition has been accompanied by separate work on the state digital yuan, which is a central bank currency and not a crypto-asset in the sense used elsewhere on this site.

Mexico

The practical position has been shaped less by prohibition than by Banxico limiting the virtual assets institutions may offer to the public, which has kept regulated retail access narrow.

Thailand

The SEC has continued to adjust rules on custody, advertising and retail access, and Thailand publishes a register of licensed operators.

Malaysia

The SC has periodically acted against unregistered platforms operating into Malaysia, and publishes an investor alert list naming them.

Latest

Guides & security tips

All guides →
Newsletter

The weekly security digest

The week's incidents and rule changes, each with its primary source and the check worth running. Free, short, no price calls.

About the digest

Frequently asked

What is Conisec?
Conisec is an independent publication covering crypto security incidents, exploits, and regulation. We track what broke, who it affected, and what the rules say — and we cite a primary document for every claim.
What is "The Ledger" on your stories?
The Ledger is a fixed four-line panel on every security, incident and regulatory story: what happened, who's exposed, how to verify it yourself, and what changes. The verification line is the point — we hand you the check rather than asking you to trust us.
Where do your incident details come from?
Primary sources only: official project post-mortems, exchange status pages, security-firm advisories, regulator notices, court filings and on-chain records. Secondary reporting may corroborate a fact but never stands alone for a loss figure, an attribution or a legal characterisation. If it cannot be sourced, it does not publish.
Is anything on Conisec financial, legal or security advice?
No. Everything we publish is for information only. We do not issue buy or sell calls, we do not give legal or tax advice, and we never tell a reader to move funds, revoke an approval or interact with a contract address. We link the official advisory and let the issuer's own instructions stand.
Are your writers real people, and do you use AI?
Every public byline on Conisec is a real, named person. We do not publish under "admin" and we do not invent staff, bios, photos or credentials. Our editorial guidelines state plainly whether and how AI assists our work; a human is accountable for every published claim.
How do I report a correction or a missing incident?
Use our contact page. Corrections are appended and dated on the article itself — never silently rewritten — and logged publicly on our corrections page.