What happens when an exchange is hacked
What happens when a crypto exchange is hacked: how breaches occur, who bears the loss, why deposit insurance rarely applies, and how to limit your exposure.

Quick answer
When an exchange is hacked, attackers usually steal the keys to its wallets or breach its systems, and the coins leave even though your balance still shows a number. Crypto on exchanges is generally not deposit-insured, so recovery depends on the exchange's reserves and solvency. Keep long-term holdings in self-custody to limit exposure.
Key points
- On an exchange, the company holds your keys
- Breaches target the firm systems, not the blockchain
- Crypto on exchanges is generally not deposit-insured
- Recovery depends on the exchange reserves and solvency
- Keep long-term holdings in self-custody
When you keep crypto on a centralised exchange, the exchange holds the private keys — not you. That convenience is the whole risk. If the exchange is hacked, the attacker may be able to move customer funds, and because blockchain transactions are final, recovering them is often impossible. Understanding what actually happens during and after an exchange breach helps you decide how much to trust any custodian.
This is not a prediction about any specific company. It is an explanation of the mechanics, the aftermath, and the practical lessons, so that “not your keys, not your coins” stops being a slogan and becomes something you can reason about.
What “the exchange holds your keys” really means
A centralised exchange works like a custodial bank for crypto. You deposit coins, and internally the exchange credits your account balance in its own database. The actual coins sit in wallets the exchange controls, usually a mix of hot wallets (online, for day-to-day withdrawals) and cold wallets (offline, for the bulk of reserves).
The crucial point: your “balance” on the exchange is an IOU. You are trusting the company to hold the real assets and honour withdrawals. If its keys are stolen, the coins can leave, even though your account still shows a number.
This is worth sitting with, because it is the opposite of how self-custody works. In a wallet you control, you hold the keys and no company can move your coins — but you also carry the full burden of protecting them. On an exchange you outsource that burden, and in exchange you accept that the company’s security, honesty, and solvency now stand between you and your money. Neither model is strictly safer; they simply relocate the risk. The failure explored here is what happens when the party you outsourced to lets you down.
How exchange breaches typically happen
Exchange hacks rarely involve breaking the blockchain’s cryptography. They target the company’s systems and people:
- Hot-wallet key theft. Attackers gain access to the private keys of the online wallets used for withdrawals and drain them.
- Compromised employees or infrastructure. Phishing, malware, or insider access lets attackers reach systems that can authorise transfers. The same social-engineering patterns that target individuals also target staff.
- Software and access-control flaws. Weaknesses in the exchange’s own code or permissions that let funds move without proper authorisation.
- Withdrawal-system abuse. Manipulating the platform’s logic to send out more than an attacker is entitled to.
In almost every case the failure is organisational security, not a broken chain. That is why the strength of the underlying blockchain offers you no protection when a custodian is compromised.
What happens in the immediate aftermath
Once a breach is detected, a fairly consistent sequence tends to follow:
- Withdrawals and trading are frozen to stop further losses and contain the incident. Customers suddenly cannot access their funds.
- The exchange investigates and discloses — sometimes quickly, sometimes slowly — the scope of what was taken.
- Stolen funds are traced on-chain. Because blockchains are public, analysts and the exchange can often follow the coins, and may work with other exchanges to freeze them if the attacker tries to cash out through a regulated venue.
- The shortfall has to be absorbed. This is the decisive question for customers.
Who bears the loss
Here is where reality diverges sharply from a traditional bank. Crypto held on an exchange is generally not covered by government deposit insurance the way insured bank deposits are — regulators including the FDIC in the United States have warned consumers that crypto assets are not FDIC-insured. What happens to your balance after a hack depends entirely on the exchange:
- The exchange covers it from its own capital, an insurance fund, or a reserve set aside for exactly this. Some large exchanges maintain such funds. This is a choice and a capability, not a guarantee.
- Losses are shared across customers (“socialised”), so everyone takes a partial haircut.
- The exchange becomes insolvent and enters bankruptcy, where customers become creditors and may wait years to recover a fraction — as history’s failed exchanges have shown.
You cannot know in advance which outcome you will face, which is the core argument for not leaving more on any exchange than you need.
Proof of reserves and its limits
After several high-profile collapses, many exchanges began publishing proof of reserves — cryptographic evidence that they hold assets matching customer balances. This is a genuine improvement in transparency, and its absence is a fair reason for caution. But it comes with important caveats. A proof of reserves typically shows assets at a moment in time; it does not, on its own, show liabilities or debts the exchange owes elsewhere. An exchange can appear well-funded while being deeply insolvent behind the scenes, and a snapshot can be arranged for the moment of the audit. Treat proof of reserves as one useful signal among several, not as a guarantee that your funds are safe.
What history teaches. The recurring lesson from the industry’s biggest failures is uncomfortable and consistent: size and reputation are not safety. Exchanges that once dominated their era have suffered catastrophic breaches or collapsed into bankruptcy, leaving customers waiting years to recover a fraction of what they were owed. In some cases the damage came from external hackers; in others from internal mismanagement or fraud that a breach merely exposed. From a depositor’s point of view the cause matters less than the outcome — funds you did not control were lost — which is why the practical conclusion has stayed the same across every cycle: minimise how much of your wealth sits with any single custodian.
How to reduce your exposure
You cannot audit an exchange’s internal security, but you can limit how much of your risk depends on it:
- Hold long-term savings in self-custody. Coins in your own wallet cannot be lost in an exchange hack. This is what “not your keys, not your coins” means. See hardware versus software wallets.
- Keep on exchanges only what you are actively trading or about to move.
- Secure the account itself. A strong unique password and app-based or hardware two-factor authentication reduce the far more common risk of your account being taken over, distinct from the exchange being breached.
- Prefer established, regulated venues that publish information about their security and reserves — while remembering that size is not immunity.
- Withdraw to your own wallet for anything you intend to hold.
- Diversify custodians if you must hold large balances on-platform. Spreading funds across more than one reputable venue means a single failure does not take everything, though it multiplies the number of accounts you have to secure.
It is worth being clear that none of this makes an exchange bad or unnecessary. Exchanges do genuinely useful work — converting between currencies, providing liquidity, and giving newcomers an accessible on-ramp — and the convenience is real. The argument is narrower: convenience and custody are a trade, and the sensible response is to use exchanges for what they are good at while keeping only as much on them as that usefulness actually requires. Treat the balance you leave on any platform as money you have chosen to expose to that platform’s fate.
Guard your own login as carefully as the exchange guards its vault; account-takeover via phishing is a threat you control directly.
Bottom line
An exchange hack is fundamentally a custodial failure: the company held the keys, its systems were breached, and the coins left. The blockchain is not at fault and cannot help, deposit insurance generally does not apply, and whether you are made whole depends on the exchange’s own reserves and solvency. The durable lesson is one of proportion — use exchanges for the trading and converting they are good at, secure your account rigorously, and keep meaningful long-term holdings in self-custody where no third party’s breach can reach them.
Sources
Frequently asked questions
If my exchange is hacked, will I get my money back?
It depends entirely on the exchange. Some cover losses from their own reserves or an insurance fund, some socialise losses across customers, and some become insolvent, leaving customers as creditors who may recover only a fraction after years.
Is crypto on an exchange protected like a bank deposit?
Generally no. Regulators such as the FDIC have warned that crypto assets are not government deposit-insured. Recovery after a hack depends on the exchange's own resources, not a deposit-insurance guarantee.
How do I avoid losing crypto in an exchange hack?
Keep only what you are actively trading on the exchange and hold long-term savings in your own self-custody wallet. Coins you control cannot be taken in a breach of the exchange, though you must then secure your own keys.
Related
KYC and AML in crypto, explained
KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the…
Forks: what they are and what happens to your holdings
Crypto forks explained: the difference between soft and hard forks, why chains split, what happens to coins you hold, and…
Token approvals and why they drain wallets
Token approvals explained: how the permissions you sign let contracts move your tokens, why unlimited approvals drain wallets, and how…


