Bitfinex Hack 2016: The Theft, the Trail and the Recovery
In three hours on August 2, 2016, one attacker drained nearly 120,000 bitcoin from Bitfinex — then the industry watched the coins sit in plain sight on-chain for six years. This is the story of the hack, the 36% haircut every user took, and the five-year investigation that ended with the largest seizure in U.S. Department of Justice history.
12 minutes • 16 illustrated steps • In-depth historical chronology & technical analysis
Editorial Research & Chronological Archive
Independently synthesized and cross-verified by The Blockchain History Editorial Board using primary whitepapers, historical archives, and on-chain records.
What happened in the Bitfinex hack?
On August 2, 2016, an attacker used Bitfinex's own administrator API key to authorize withdrawals and bypass the exchange's 2-of-3 multisig setup with BitGo, draining 119,756 bitcoin (about $72 million then — nearly 1% of all bitcoin in existence) in roughly 2,000 transactions over about three hours. Bitcoin fell more than 20% that day. Bitfinex socialized the loss — every account took a 36.067% haircut — and issued BFX tokens at one per dollar lost, redeeming them all at par within eight months. The coins sat visibly on-chain while their value swelled into the billions; they were laundered through AlphaBay mixing, coinjoins and chain-hopping. The July 2017 seizure of AlphaBay's servers gave investigators the map. In February 2022 the FBI arrested Ilya Lichtenstein and Heather Morgan and seized over 94,000 bitcoin — about $3.6 billion, the largest seizure in DOJ history. Both pleaded guilty in August 2023, Lichtenstein admitting the hack; in November 2024 he was sentenced to 60 months and Morgan to 18 months. Around 80% of the stolen coins have been recovered; a claims process is deciding who gets them.
Key Takeaways
- Bitfinex launched in 2012 as the first exchange designed from the ground up for power traders — peer-to-peer margin lending made it the favorite of high-risk speculators, and one of the largest bitcoin venues in the world by 2016.
- On August 2, 2016, an attacker used an administrator API key held inside Bitfinex to instruct its custody partner BitGo to co-sign withdrawals, draining 119,756 BTC (about $72 million, nearly 1% of all bitcoin then) in 2,000 transactions over roughly three hours.
- The market's reaction was brutal — bitcoin fell more than 20% that day — and Bitfinex spread the pain: every user account, hit or not, took a 36.067% generalized haircut on all assets.
- Customers were repaid with newly issued BFX tokens at one per dollar lost; within eight months Bitfinex redeemed every token at 100 cents or converted it into iFinex equity, and Recovery Right Tokens kept a claim on any coins later recovered.
- For six years the stolen coins sat in plain sight on the public ledger while their value grew into the billions, laundered bit by bit through AlphaBay mixing, coinjoins and chain-hopping — until the dark market's seized server logs gave investigators the map.
- In February 2022 the FBI and IRS arrested couple Ilya Lichtenstein and Heather Morgan and seized 94,000+ bitcoin (~$3.6 billion, the largest seizure in DOJ history); both pleaded guilty in August 2023, and in November 2024 Lichtenstein was sentenced to 60 months and Morgan to 18 months.
August 2016: The Breach
A power-user exchange with a fatal workaround buried in its own custody stack — and the second-biggest theft crypto had seen.
- 1
2012: an exchange built for power traders
Bitfinex went live in 2012, started by Raphael Nicolle — a one-man operation posting under the screen name Uncle Scrooge on the Bitcointalk forum. It was the first exchange designed from the ground up for professional traders: peer-to-peer margin funding, advanced order types, deep books. Everything a high-risk speculator could want. By 2016 it handled enormous daily volume — and its size made it what the video calls the world's most natural bug bounty: break in, steal crypto, mix it well and enjoy life. Less flatteringly, the founder's inexperience running an operation that large attracted exactly the kind of attention an exchange can't afford.

Bitfinex in one image: institutional ambition, garage-security reality. - 2
Custody on a 2-of-3 leash
To reassure customers, Bitfinex partnered with BitGo, a Palo Alto provider of insured digital wallets. Customer coins sat in multisig addresses requiring two of three keys: one for Bitfinex, one for BitGo, one for the user. In theory an intrusion at either company couldn't move funds alone. In practice, the system required a Bitfinex administrator to hold a special API key that instructed BitGo to provide its signature on request — which made the whole arrangement decorative. The exchange even ran an announcement crowing that 'the era of commingling customer bitcoin and all of the associated security exposures is over.' An intrusion at Bitfinex would now grant full control of customer funds — precisely what multisig existed to prevent.

Two-of-three keys — unless one party holds the pen that signs for the other. - 3
2,000 withdrawals in three hours
On August 2, 2016, the flaw detonated. Over roughly three hours, about 2,000 separate transactions left customer accounts for a single unknown wallet: 119,756 bitcoin, worth about $72 million at the time — nearly 1% of all bitcoin in existence, and the second-largest exchange theft in crypto history after Mt. Gox. The attacker hadn't defeated BitGo's cryptography; they had simply done what the admin API key was built to do, instructing the signature on thousands of withdrawals before anyone could pull the plug. Come morning, users logging in for another day of margin trading found their accounts empty through no fault of their own.

About $72 million left the exchange before anyone could stop it. - 4
Bitcoin drops more than 20%
The market delivered its verdict the same day: bitcoin's price plunged by more than 20% as the news broke, the CoinDesk chart showing a violent flash crash to the mid-$400s before a partial rebound. Bitfinex halted trading and froze the platform while employees scrambled to work out what had happened. And the timing was cruel: within a year bitcoin's bull run would have valued the stolen stack at more than $2.4 billion, and at the December 2017 peak near $20,000 the haul crossed $4 billion. The victims hadn't just lost coins — they'd lost the bottom tick of the greatest bull market in crypto history.

The flash crash of August 2, 2016, on the day the hack broke.
A 36% Haircut — and a Promise
Bitfinex couldn't identify the thief, so it spread the loss across every user — then paid everyone back with a token it printed itself.
- 5
'No breach' on BitGo's side
The blame game started immediately. BitGo tweeted the same afternoon that its investigation had found no evidence of a breach to any of its servers — pointing squarely back at Bitfinex. Bitfinex commissioned Ledger Labs, a Canadian firm, to produce a detailed report. Its finding confirmed the structural flaw: the admin API key that could invoke BitGo's signature was stored by Bitfinex, and the report traced it to an administrator account — the CFO's, a detail that spawned years of controversy without ever becoming charges. Whoever pulled off the attack had covered their tracks with a data-destruction tool; only a lead from IP analysis pointing toward Poland surfaced, and Bitfinex publicly dismissed even that.

BitGo's servers were clean. The master key lived inside Bitfinex. - 6
Losses generalized: minus 36.067%
With no thief to pursue, Bitfinex made a decision that still divides opinion: it announced that 'losses must be generalized across all accounts and assets.' The stolen coins amounted to 36% of everything held on the platform, so instead of eating the loss itself — and risking ruinous lawsuits from the whales who'd been hit — it applied the same haircut to every account. Users with untouched balances, people who thought they'd dodged the hack, logged in to find their holdings slashed by a generalized 36.067%, in bitcoin and every other asset, whether or not a single coin had left their own account.

Everyone took the same haircut — 36.067 percent, hit or not. - 7
BFX: one token per dollar lost
The compensation was as inventive as it was cheap: Bitfinex credited every affected account with BFX tokens at a rate of one per dollar lost — converting its bitcoin debt into a dollar-denominated IOU, minted on the spot. The hedge was clever: had bitcoin kept falling, the debt would have shrunk; in a bull run it would balloon, which is exactly what happened. Users could hold the token and wait for redemption, or convert BFX into equity in iFinex, the parent company — trading a claim on dollars for a claim on the exchange itself. Not everyone was comforted; many simply asked what had happened to their actual bitcoins.

An IOU minted on the spot: one BFX for every dollar gone. - 8
Made whole in eight months
Then came the part almost nobody expected: Bitfinex stayed in business and turned a profit. Within eight months it had bought back and destroyed every BFX token at 100 cents on the US dollar — roughly $70 million raised and repaid in the middle of a bear market. Holders who had converted to equity instead received Recovery Right Tokens, a claim on any portion of the stolen coins ever recovered. Bitfinex's own post-mortem FAQ lays it out: 119,755 bitcoin stolen, tokens redeemed at par, all BFX destroyed, RRT distributed to equity converters. The exchange that had lost a third of its assets walked out of 2017 stronger than it entered.

The IOUs were redeemed at par — and RRT kept a claim on recovered coins.
Following the Money
The stolen coins never left the public ledger. Investigators just had to wait six years for them to move — and for one dark-market seizure to hand them the map.
- 9
A black hole called AlphaBay
From January 2017, investigators saw what they'd been waiting for: movement. Small amounts began zigzagging through chains of accounts and landing on AlphaBay, a dark-web marketplace whose mixing protocols made the trail effectively disappear — an information black hole for the online underworld. Everything changed in July 2017, when an international operation seized AlphaBay and its internal transaction logs. Court documents in the eventual case trace the route: stolen coins passing through a BTC-e-linked account, into AlphaBay, then out through nested virtual-currency-exchange sub-accounts. The black hole, suddenly, had lighting.

The wash cycle: victim wallet, mixer, dark market, cash-out accounts. - 10
Coinjoins and chain-hopping
Whoever was cashing out knew the ledger was watching. The two signature techniques of the era: coinjoins, which merge many users' coins into one transaction and split them back out, blurring who owns which output; and chain-hopping, rapidly converting bitcoin into other cryptocurrencies to break the link between addresses. Both work — up to a point. Large amounts stand out no matter how well they're mixed, and each hop leaves its own permanent record. Meanwhile the investigators' side of the arms race industrialized: Chainalysis and other blockchain-analysis firms built the tracing tools that turned 'follow the money' from a metaphor into a query.

Mix the coins and the money gets blurry. It never gets invisible. - 11
2021: the wallets wake up
After years of stillness, the original hack wallets stirred. Over roughly two months in 2020-2021, more than 3,500 of the stolen bitcoin — around $39 million — moved in a deliberate series of transactions, each one flagged in real time by Whale Alert tracking bots for anyone to watch. Headlines followed the money; Bitfinex raised the stakes too, dangling a reward of up to $400 million for information, and even offering the hackers themselves a payout if they returned the funds — a controversial amnesty-style deal that required only a small transfer from the hack wallet to prove good faith. The offer was ignored. More than 80% of the coins stayed put in the original wallet.

3,500 coins started moving — and the whole internet could watch. - 12
The map behind the mixing
The 2021 movements were the last confident step of people who believed the trail was cold. It wasn't. Working through AlphaBay's seized server logs, investigators could see where funds went after they came out the far side of the mixer; cross-referencing those data points surfaced shell companies and bank accounts the cash-outs fed into — accounts that belonged to Ilya Lichtenstein and Heather Morgan. From that point the couple was under watch while the government assembled its case: a privacy-focused wallet startup, an $11,000 pandemic PPP grant, even a $500 Walmart gift card bought with hack-linked bitcoin under Morgan's name. The blockchain had kept every receipt; the seized server had supplied the names.

Return the coins, collect up to $400 million. Nobody took the deal.
2022: The Raid and the Record Seizure
Six years after the breach, a raid on a Wall Street apartment and a warrant for one cloud-storage account ended the mystery.
- 13
Mugshots on Wall Street
On February 8, 2022, FBI and IRS agents raided the couple's luxury Wall Street apartment. Ilya Lichtenstein — Y Combinator alum, Mixrank founder, a man who once wrote on the YC forum that he hadn't done 'black hat stuff in a very long time' — and Heather Morgan: SalesFolk founder, Forbes contributor, self-styled 'Crocodile of Wall Street,' and the rapper Razzlekhan. Morgan tried to buy seconds by chasing her cat, actually going for her phone to lock it; agents stopped her. In hollowed-out books they found fake passports, burner phones and $40,000 in cash — clear signs the pair was preparing to flee, likely for Russia, where Lichtenstein held citizenship. Notably, the charges were for money laundering: at arrest, the government said it had no evidence the couple had committed the hack itself.

The 'Crocodile of Wall Street' and her husband, booked in February 2022. - 14
The largest seizure in DOJ history
The breakthrough came from a search warrant on Lichtenstein's cloud-storage account. Inside: a list of the hack-linked wallets — with their passwords. Using them, investigators opened a wallet holding the bulk of the remaining haul, about 94,000 bitcoin, worth roughly $3.6 billion, and took the funds: the largest financial seizure in the Department of Justice's history, announced by Deputy Attorney General Lisa Monaco. The pair was charged with conspiracy to commit money laundering and conspiracy to defraud the United States — because, as the case file put it, taxes are due even on illicit gains — facing up to 25 years. Lichtenstein was held as a flight risk; Morgan was released on $3 million bond secured by her parents' home.

94,000 coins, unlocked with the suspect's own passwords.
Pleas, Sentences and Recovery
The case closed with confessions, prison terms — and one last argument over who the recovered coins belong to.
- 15
Guilty — and the hack admitted
In July 2023 the couple agreed to plead, and on August 3, 2023 the pleas were entered in federal court in Washington. Lichtenstein admitted everything: he pleaded guilty to money-laundering conspiracy and confessed to hacking Bitfinex in 2016 and stealing the roughly 120,000 bitcoin — resolving the question that had hung over the case since the arrest. Morgan pleaded guilty to one count of money laundering and one count of conspiracy to defraud the United States. Sentencing came in November 2024: Lichtenstein received 60 months in federal prison; Morgan received 18 months — a gap that reflected who did what. The 'Razzlekhan' saga, which had begun with terrible rap videos, ended in a courtroom.

The plea ended the whodunit: Lichtenstein admitted the hack itself. - 16
Who gets the coins back?
That left the money. Chain analysis — the same public-ledger transparency that let the couple watch their coins appreciate — is what undid them: of the roughly 119,756 bitcoin stolen, more than 94,000 were seized, about 80% of the haul, with the DOJ calling it the largest recovery of its kind. Now comes the argument: Bitfinex claims the coins as its own; users who took the 36% haircut — especially BFX holders who converted to equity and RRT — claim their share was always theirs. The DOJ has set up a claims process for alleged victims, and the likely outcome is distribution to creditors who can document their losses. Either way, the case reset industry expectations: multisig on paper means nothing if one party holds the pen, commingling is a liability, and every coin is traceable forever.

The blockchain kept the receipts; the courts now divide them.
Frequently Asked Questions
How much bitcoin was stolen in the Bitfinex hack?
Did Bitfinex customers get their money back?
Who actually hacked Bitfinex?
How were the Bitfinex hackers caught?
What sentences did the Bitfinex hackers receive?
How much of the stolen bitcoin was recovered?
Continue the Story
Mt. Gox Collapse: The Complete Timeline
The record Bitfinex's hack broke: 850,000 missing BTC, a decade of waiting — and repayments that finally arrived.
The BTC-e Story
The exchange that appears in the Bitfinex fund-flow chart — and the arrest that linked it to the dark web's banker.
QuadrigaCX Collapse: The Crypto King Who Took the Keys
The other custody horror story: an exchange whose cold-wallet keys left the planet with one man.
The Biggest Crypto Scams in History, Case by Case
Where exchange hacks sit in the larger lineup of cons, collapses and outright thefts.
The Genesis Block
The first block that started the public ledger — the very property that made this six-year manhunt possible.
The Cypherpunk Movement
Where the 'don't trust, verify' ethos that both the hackers and the investigators relied on came from.
All Blockchain History Guides
Every illustrated guide in the series, from the genesis block to the latest collapse.
References
Extended Multimedia Reference
Visual sequences and chronologies in this guide cross-reference video documentation “The Rapper Behind The $4.5 Billion Bitfinex Hack” by Crumb.
This illustrated guide is maintained strictly for educational, research, and historical documentation purposes. None of the materials constitute investment, financial, legal, or trading advice. Historical crisis and market events are documented from public archives. Digital assets involve significant risks.