Real-World Key Compromise Case Studies
Detailed case studies of cryptocurrency lost or compromised through key, password, and seed phrase failures. From Stefan Thomas and James Howells to Quadriga, Mt. Gox key management, SIM swap victories, and the lessons modern holders should take from billions of dollars in permanent losses.
37 min · intermediate · part of Security Mastery: Protecting Your Assets
What you'll learn
- Why These Stories Matter
- Stefan Thomas and the IronKey: ~7,002 BTC
- James Howells and the Newport Landfill: ~7,500 BTC
- Quadriga CX: When the Custodian Dies
- Mt. Gox: The Key Management Lessons
- SIM Swap Case Studies: Terpin and AT&T
- Recent 2024-2025 Compromises and the Aggregate Picture
- Lessons: Cold Storage, Multi-Sig, Inheritance
- For Deeper Reading
Key terms
- IronKey
- A high-security USB device that self-destructs after 10 incorrect password attempts. Used by Stefan Thomas to store ~7,002 BTC; he forgot the password and as of 2026 has 2 attempts remaining before permanent loss.
- Stefan Thomas
- Programmer who received 7,002 BTC for a 2011 explainer video. Stored the bitcoin on an IronKey, lost the paper with the password, used 8 of 10 attempts. As of early 2026, the bitcoin (~$560M-$910M value) remains locked.
- James Howells
- Welsh IT worker who mined ~7,500 BTC in 2009 and lost the hard drive in 2013 when his then-partner threw it in household waste, ending up in the Newport landfill. His £495M lawsuit against the council was dismissed in January 2025.
- Quadriga CX
- Canadian cryptocurrency exchange whose CEO Gerald Cotten died unexpectedly in December 2018 with sole control of cold storage keys. ~$190M USD ($250M CAD) of customer funds were inaccessible; subsequent investigation revealed Quadriga had been operating fraudulently as fractional reserve.
- SIM swap
- Attack where attackers convince a mobile carrier to transfer the victim's phone number to a SIM card they control, enabling interception of SMS-based 2FA codes and password resets. Defeated by hardware security keys and authenticator apps (TOTP).
- Michael Terpin
- Cryptocurrency entrepreneur who lost ~$24M in a January 2018 SIM swap attack. Won $75.8M civil judgment against attacker Nicholas Truglia in 2019. His ongoing case against AT&T was significantly revived by the Ninth Circuit Court of Appeals on September 30, 2024.
- Lost Bitcoin estimates
- Chainalysis and similar firms estimate 2.3-3.7 million BTC are permanently inaccessible (~11-18% of the 21M cap). At early 2026 prices, this represents $200-$480 billion of value lost to forgotten passwords, lost hardware, deceased holders, etc.
- Mt. Gox key management
- The 2014 collapse of Mt. Gox revealed multiple key management failures: excessive hot wallet exposure, inadequate cold storage practices, sole CEO keyholder, no proof-of-reserves. Foundational lessons for all subsequent exchange custody practices.
- Proof-of-reserves
- A practice whereby exchanges cryptographically prove they hold reserves matching customer balances, typically using Merkle tree commitments. Became industry standard after Mt. Gox; major exchanges including Coinbase, Kraken, Binance now publish proof-of-reserves data.
- Hardware security key
- A physical device (YubiKey, Titan Security Key) that provides phishing-resistant authentication via FIDO2/WebAuthn. Defeats SIM swap attacks entirely because the second factor is not derived from the phone number. Major exchanges support hardware keys.
- Supply chain attack (hardware wallets)
- A compromise where an attacker tampers with hardware wallet devices before they reach the user, typically by selling compromised devices through unofficial channels. The defense is to buy hardware wallets only from the manufacturer's official store.
- Cloud backup compromise
- A pattern where attackers compromise a victim's cloud account (often via SIM swap or credential stuffing) and recover seed phrases or wallet files stored in synced services like iCloud, Google Drive, or Notes. Never store cryptographic material in any cloud-synced location.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
