ChainBleedv0.1 · open intel
← back to feed·BITCOIPRIVATE-KEY2016-08-03 · 9y ago
Incident · SLOWMIST

Bitfinex

Wallet Stolen
Estimated loss
$900.00M
VERDICT —OUT OF SCOPE
Root cause is private-key / signer compromise — the on-chain contract behaved exactly as written. No pre-deployment source audit or bytecode review reaches the key-custody perimeter; this is operational-security territory (HSM/MPC hygiene, key rotation, hot-wallet isolation). Bytecode would show nothing wrong.
▰ METHOD
PRIVATE KEY
PRIVATE-KEY
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Bitfinex suffered a cyber attack in August 2016. 2,072 Bitcoin transactions were transferred out without Bitfinex's authorization, and then the funds were scattered and stored in 2,072 wallet addresses. Statistics show that Bitfinex lost a total of 119,754.8121 BTC. It was worth about $60 million at the time of the incident, or about $4.5 billion in today's prices. In February 2022, the Department of Justice recovered 94,000 bitcoins for Bitfinex, then valued at $3.6 billion. 34-year-old Ilya Lichtenstein and his wife, Heather Morgan, 31, were arrested in New York and charged with conspiracy to commit money laundering and fraud. on July 7, 2023, Bitfinex recovered more than $312,000 and 6,917 bitcoin cash (approximately $2,000) in stolen assets, which Bitfinex obtained from the U.S. Department of Homeland Security. On July 7, 2023, Bitfinex recovered more than $312,000 and 6.917 Bitcoin cash (approximately $2,000) in stolen funds, and Bitfinex obtained the assets from the U.S. Department of Homeland Security, with the recovered funds to be paid to the owner of the Restoration Rights Token (RRT). Attack method (per SlowMist): Wallet Stolen. Reported loss: $ 900,000,000.

Primary source
https://www.justice.gov/opa/press-release/file/1470186/download
Sourced from
slowmist
Technical record
chain
bitcoin
protocol
Bitfinex
bug_class
private-key
date_occurred
2016-08-03
loss_usd
$900,000,000
source_id
sm:bitfinex::2016-08-03
Related — same bug class· private-key
2026-04-30
1mo ago
MULTI
Wasabi Perps
Admin Key Compromised
private-key
$5.50M
OUT OF SCOPE
2026-04-30
1mo ago
ETH
Wasabi Protocol
Private Key Leakage
private-key
$5.70M
OUT OF SCOPE
2026-04-29
1mo ago
Syndicate Labs
Private Key Leakage
private-key
$380.0K
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vault
Admin Key Compromised
private-key
$3.50M
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vaults
Private Key Leakage
private-key
$3.50M
OUT OF SCOPE
2026-04-16
1mo ago
MULTI
Grinex
Hot wallet hack
private-key
$15.00M
OUT OF SCOPE
ChainBleed — live web3 threat intelligence