Tokyo, late February 2014. The world's largest bitcoin exchange abruptly halts withdrawals, citing a "technical issue." The site goes dark. The office in central Tokyo, staffed by engineers the day before, turns out to be empty. Within days, an internal document leaks: the exchange cannot account for roughly 850,000 bitcoins — its own and its customers'. At the time that was worth on the order of $450 million. At today's prices, it's tens of billions.
It wasn't the first collapse in the history of money, and it wouldn't be the last in the history of crypto. But it was the first collapse of this scale in a world that still thought of itself as a small experiment run by geeks. The industry got a lesson it would keep having to relearn, under different names on the door: Mt. Gox, then QuadrigaCX, then FTX. Here's how it was built, what actually went wrong, and why the lesson keeps failing to stick.
How an exchange got too big to fail quietly
The name Mt. Gox is an acronym for "Magic: The Gathering Online eXchange." In 2007, programmer Jed McCaleb launched a site for trading cards from the collectible game Magic: The Gathering. It didn't take off, and the domain sat idle — until 2010, when McCaleb repurposed it for something else entirely: trading bitcoin for dollars. At the time, it was nearly the only working venue of its kind, and it quickly became the place where the new currency's price got discovered.
In 2011, McCaleb sold the exchange to Mark Karpelès, a French developer living in Tokyo. By 2013–2014, Mt. Gox had become the dominant player: by various estimates, something on the order of 70% of all bitcoin trades in the world passed through it. That enormous share of the market ran on infrastructure that remained, in essence, a project run by one man and a small team — no bank-grade controls, no independent audit, no separation of duties.
The first warning nobody heard
In June 2011, Mt. Gox had already survived a major hack. An attacker gained access to an account with broad privileges, crashed the exchange's bitcoin price to a single cent within minutes, and tried to drain funds through compromised accounts. Part of the damage got rolled back, trading was suspended, and the exchange survived — and the crypto world filed it away as a scary story from the wild early days, not as a diagnosis.
It was, in fact, a diagnosis. The 2011 hack showed that the exchange had no reliable security architecture, that keys and hot wallets were managed ad hoc, and that incident response was manual and improvised. The hole got patched, not fixed. And, as later became clear, it was around this same period — possibly earlier — that the exchange's wallets began slowly bleeding out, over years.
The hole that grew for years
The technical cause the exchange publicly cited when it froze withdrawals was "transaction malleability" — a quirk of early bitcoin's protocol that let someone slightly alter a transaction's ID so it looked unconfirmed even after the funds had actually moved. With decent bookkeeping, that's an annoyance. With no internal accounting at all, it's a window for fraudulent repeat withdrawals.
But investigations later made clear that malleability explained, at best, a small slice of the losses. The bulk of the missing bitcoin left the exchange's cold and hot wallets over several years — apparently starting around 2011 — gradually, in episodes, with no single day marking the theft. The accounting that would have caught this in time simply didn't exist: the exchange went years without reconciling its actual reserves against what it owed customers. It genuinely did not know how much bitcoin it had left, until the numbers stopped adding up and wouldn't stop not adding up.
Our record. The Scales of Ma'at weigh the heart against the feather — not a promise, but what is actually there. An exchange that takes a deposit hands back, in effect, a receipt: "we're holding your coin." As long as no one asks for the feather, the receipt and the coin look identical. Mt. Gox ran for years on receipts that no longer had coins behind them, and no one held the feather to the scale, because the business kept growing, the price kept climbing, and asking "is it all still there" felt like a hostile thing to do. Isfet rarely looks like villainy in the moment. More often it looks like a comfortable habit of not checking.
The collapse
In early February 2014, Mt. Gox froze bitcoin withdrawals, blaming a transaction-malleability problem it claimed needed fixing before operations could resume. Tens of thousands of customers found themselves locked out — deposits visible in their account dashboards, but nothing withdrawable. For weeks the exchange spoke publicly of "temporary difficulties," until February 24, when the entire trading interface vanished from the site and an internal document — apparently a draft of a crisis plan — leaked online, putting the shortfall at around 850,000 BTC: roughly 750,000 customer coins and about 100,000 belonging to the company itself.
On February 28, 2014, Mt. Gox filed for bankruptcy protection in Tokyo District Court. Karpelès publicly apologized at a press conference, partly in Japanese — a gesture the community read in two different ways, either as genuine remorse or as an attempt to localize the scandal. Some of the missing coins — roughly 200,000 BTC — later turned up in an old-format cold wallet dating to before 2011, one the exchange said it had simply forgotten about. The find didn't change the shape of the story; it only softened the final number a little.
The aftermath: a court case that took a decade
In 2015, Mark Karpelès was arrested in Japan. The charges included embezzlement and manipulating the exchange's server data. The case dragged on for years; in 2019, a Tokyo court delivered its verdict — Karpelès was found guilty of falsifying electronic records and given a suspended sentence, but acquitted on the embezzlement charge for lack of evidence of direct theft. The clean criminal resolution many victims wanted never came.
Getting the money back took even longer. The case first proceeded as a bankruptcy, then was converted into civil rehabilitation proceedings — a mechanism under which creditors receive not cash compensation valued at the moment of collapse, but a share of whatever assets actually remain, including the recovered bitcoin. The rehabilitation plan wasn't approved until 2021, and the first real payouts to victims didn't start reaching people until 2024 — a full decade after that February day. Some creditors died waiting. Others sold their claims to speculators for a fraction of face value, just to get something sooner.
Why the lesson had to be relearned
On paper, Mt. Gox is the story of one badly run company. In substance, it was the first mass demonstration of what happens when an asset engineered to be decentralized and trustless passes through a centralized intermediary that requires trust by default. "Not your keys, not your coins" became a meme after February 2014 not because the phrase was new, but because the cost of ignoring it had, for the first time, been measured in hundreds of millions of dollars and tens of thousands of broken plans.
The industry only half-learned the lesson. Proof-of-reserves demands emerged, cold-storage practices matured, and the malleability bug itself eventually got fixed at the protocol level — the episode was part of what pushed the SegWit upgrade forward. But the structural problem — a large centralized point where other people's assets get commingled under opaque accounting and one-person control — never actually went away. It just moved to new signage, until 2022, when FTX collapsed on nearly the same template: customer liabilities long since written down on paper that no longer matched what the wallets actually held.
Mt. Gox matters less as a horror story from the past than as a measuring instrument. Any time you hand an asset to an intermediary — an exchange, a custodian, a DAO treasury with opaque books — the question worth asking isn't "how big are they" or "how long have they been around." It's simpler: if someone held the feather to their scale right now, what would actually be there. February 2014 is the answer to a question nobody asked for a decade. Asking it on time is the only way to avoid paying, from your own account, for someone else's silence.