Real-World Key Compromise Case Studies
Detailed case studies of cryptocurrency lost or compromised through key, password, and seed phrase failures. From Stefan Thomas and James Howells to Quadriga, Mt. Gox key management, SIM swap victories, and the lessons modern holders should take from billions of dollars in permanent losses.
37 min · intermediate · part of Security Mastery: Protecting Your Assets
Why These Stories Matter
Most security education focuses on hypothetical attacks: this is what could go wrong. Case studies are different. They show what has actually gone wrong, in detail, with names, dollar amounts, and traceable consequences. Reading the case studies of major key compromises and losses is one of the most efficient ways to internalize security practices, because the lessons come with emotional weight that abstract advice cannot match.
This lesson is not about scams. Module 23 covers scams, exit fraud, and exchange collapses comprehensively. This lesson is specifically about key management failures: situations where the holder of cryptocurrency lost access to their funds, not because someone deceived them, but because their key, password, or seed phrase was destroyed, forgotten, or stolen through technical compromise. Earlier lessons (security-1 on private keys and seed phrases, security-2 on hardware wallets, security-5 on inheritance) cover the recommended practices. This lesson examines what happens when those practices are not followed, or when they fail.
The dollar figures involved are staggering. Conservative estimates suggest that 2.3 to 3.7 million Bitcoin (roughly 11 to 18 percent of the 21 million cap) are permanently inaccessible. At Bitcoin prices of $80,000 to $130,000 in early 2026, that represents $200 billion to $480 billion of value, simply gone. Most of these losses cannot be recovered, even in principle. The keys are in landfills, in defunct hard drives, in dead memories, in forgotten password managers. The blockchain forever shows the funds; no one can spend them.
By studying the specific stories, you develop intuition about which security failures actually occur in practice and which are exotic. The patterns repeat: forgotten passwords on encrypted hardware, lost backups during life transitions, single points of failure in inheritance, SIM swaps that bypass two-factor authentication, hardware destroyed without proper recovery materials. Real losses come from these specific patterns far more often than from elaborate technical attacks.
Also in this lesson
- Stefan Thomas and the IronKey: ~7,002 BTC
- James Howells and the Newport Landfill: ~7,500 BTC
- Quadriga CX: When the Custodian Dies
- Mt. Gox: The Key Management Lessons
- SIM Swap Case Studies: Terpin and AT&T
- Recent 2024-2025 Compromises and the Aggregate Picture
- Lessons: Cold Storage, Multi-Sig, Inheritance
- For Deeper Reading
Key terms
- IronKey
- A high-security USB device that self-destructs after 10 incorrect password attempts. Used by Stefan Thomas to store ~7,002 BTC; he forgot the password and as of 2026 has 2 attempts remaining before permanent loss.
- Stefan Thomas
- Programmer who received 7,002 BTC for a 2011 explainer video. Stored the bitcoin on an IronKey, lost the paper with the password, used 8 of 10 attempts. As of early 2026, the bitcoin (~$560M-$910M value) remains locked.
- James Howells
- Welsh IT worker who mined ~7,500 BTC in 2009 and lost the hard drive in 2013 when his then-partner threw it in household waste, ending up in the Newport landfill. His £495M lawsuit against the council was dismissed in January 2025.
- Quadriga CX
- Canadian cryptocurrency exchange whose CEO Gerald Cotten died unexpectedly in December 2018 with sole control of cold storage keys. ~$190M USD ($250M CAD) of customer funds were inaccessible; subsequent investigation revealed Quadriga had been operating fraudulently as fractional reserve.
- SIM swap
- Attack where attackers convince a mobile carrier to transfer the victim's phone number to a SIM card they control, enabling interception of SMS-based 2FA codes and password resets. Defeated by hardware security keys and authenticator apps (TOTP).
- Michael Terpin
- Cryptocurrency entrepreneur who lost ~$24M in a January 2018 SIM swap attack. Won $75.8M civil judgment against attacker Nicholas Truglia in 2019. His ongoing case against AT&T was significantly revived by the Ninth Circuit Court of Appeals on September 30, 2024.
- Lost Bitcoin estimates
- Chainalysis and similar firms estimate 2.3-3.7 million BTC are permanently inaccessible (~11-18% of the 21M cap). At early 2026 prices, this represents $200-$480 billion of value lost to forgotten passwords, lost hardware, deceased holders, etc.
- Mt. Gox key management
- The 2014 collapse of Mt. Gox revealed multiple key management failures: excessive hot wallet exposure, inadequate cold storage practices, sole CEO keyholder, no proof-of-reserves. Foundational lessons for all subsequent exchange custody practices.
- Proof-of-reserves
- A practice whereby exchanges cryptographically prove they hold reserves matching customer balances, typically using Merkle tree commitments. Became industry standard after Mt. Gox; major exchanges including Coinbase, Kraken, Binance now publish proof-of-reserves data.
- Hardware security key
- A physical device (YubiKey, Titan Security Key) that provides phishing-resistant authentication via FIDO2/WebAuthn. Defeats SIM swap attacks entirely because the second factor is not derived from the phone number. Major exchanges support hardware keys.
- Supply chain attack (hardware wallets)
- A compromise where an attacker tampers with hardware wallet devices before they reach the user, typically by selling compromised devices through unofficial channels. The defense is to buy hardware wallets only from the manufacturer's official store.
- Cloud backup compromise
- A pattern where attackers compromise a victim's cloud account (often via SIM swap or credential stuffing) and recover seed phrases or wallet files stored in synced services like iCloud, Google Drive, or Notes. Never store cryptographic material in any cloud-synced location.
Continue this lesson — 8 more sections in the CryptoBipto app.
Open lessonEducational only — not financial advice.
