South Africa's Bitcoin specialists. Compliant by design.
Custody & Security · By James Caw · Updated July 2026 · 9 min read

Bitcoin Security: What Has and Has Not Been Hacked

The Bitcoin protocol has never been hacked. Not once in over sixteen years, through more than 880,000 blocks and every crash and hostile government thrown at it. What has been robbed, over and over, is the human scaffolding built around it: the exchanges and the careless wallets. When Mt Gox collapsed in 2014 and roughly 850,000 Bitcoin vanished, the headlines said Bitcoin was hacked. It was not. A company was. That single distinction decides whether your Bitcoin is safe, and it is the thing I spend most of my time explaining to clients.

Key takeaway

The Bitcoin network itself has never been broken. Every famous loss, from Mt Gox to FTX, was an exchange or custodian failing, not the protocol. Confusing the two leads people to fear the wrong thing and trust the wrong thing. Holding your own keys removes the counterparty entirely. Whether your Bitcoin is secure comes down to where you keep it and how carefully.

Most public commentary gets this backwards. It overstates the risk in the protocol, which is close to nil, and understates the risk in the businesses, which is where nearly every rand has actually been lost.

What the network actually is, and why it holds

The Bitcoin blockchain is a public record of every transaction ever made. It is not kept on a server somewhere. It is held simultaneously by tens of thousands of independent computers, called nodes, running in more than a hundred countries, each holding a full copy of the history and each checking every new block against the rules on its own. There is no head office to raid, no master switch to flip and no single machine whose failure takes the rest down. To corrupt the record you would have to corrupt all of them at once, everywhere, in the same instant.

That is a strange kind of fortress, and it is worth sitting with for a moment.

The security rests on two things working together. The first is the cryptography. Bitcoin uses SHA-256, a hashing algorithm that came out of the American National Security Agency, and the numbers involved stop being intuitive very quickly. Guessing a specific private key by chance is roughly the odds of picking one exact number out of a 78-digit range. For scale, a billion has ten digits. You are not going to stumble onto someone's keys, and neither is a supercomputer.

The second is raw computing power. To rewrite a confirmed transaction an attacker would need to out-muscle more than half the network at once, the so-called 51% attack. The network currently runs at over 800 quintillion hashing operations every second, a figure that dwarfs the combined might of the world's largest technology companies and every supercomputer on the planet put together. The people who worry about this often picture a rogue state. Run the numbers and even a coordinated effort by the largest governments on earth would fall short of the hardware needed, never mind that most of them would sooner attack each other. I set out exactly why that attack is a road to nowhere in proof of work explained. The short version is that it would cost billions, take a decade of visible procurement with no shortcut and no cheat code, and the moment it succeeded the price would collapse and leave the attacker holding wrecked machines and a worthless asset. The design does not ask anyone to be honest. It makes honesty the only profitable move.

So a 51% attack has never happened. Ethereum and Solana have both suffered them on their smaller networks. Bitcoin has not, and at its current scale it is not a credible threat.

What has actually been robbed

Mt Gox did not fail because someone broke Bitcoin. It failed because a Tokyo exchange that at its peak handled around 70% of all Bitcoin trades ran its security catastrophically and, by some accounts, was being drained from the inside for years. The roughly 850,000 coins were taken from the exchange's own wallets. The blockchain kept producing a block every ten minutes throughout, and it still holds a perfect record of every one of those coins moving. Creditors waited more than a decade for partial repayment, most of them long past believing the money existed.

Mt Gox was not the first and nowhere near the last. Hackers took 24,000 coins from Bitfloor in 2012 and 19,000 from Bitstamp in 2015. Bitfinex lost close to 120,000 coins in 2016 despite running a multisignature arrangement with a third party. FTX in November 2022 was not a hack in any technical sense at all. The client money was simply not there. It had been spent and gambled away by the people running the exchange, which is fraud of a very old kind wearing new branding. The pattern did not retire either. Bybit suffered one of the largest single-exchange thefts on record in 2025.

Every one of those was an institution failing. Weak internal controls, cost-cutting on security, or an operator who treated other people's coins as his own. None of it touched the protocol. As one writer put it, imagining that a hacked exchange means Bitcoin itself is compromised is like imagining that someone breaking into your online banking now controls every dollar in existence. It is absurd on its face, yet the claim gets made constantly.

South Africa has its own entry in the ledger

You do not need to follow the Tokyo court reports to learn this lesson. It gets taught here in rand.

The BHI Trust scheme took in about R2.9 billion from South Africans and paid old investors with new deposits while the man behind it funded his own lifestyle, a straightforward Ponzi dressed up as an investment house. Alongside the outright frauds there is now a wave of deepfake scams the regulator has flagged, where fabricated videos impersonate real people and real platforms, invite you to deposit and then vanish. People have laid criminal charges against legitimate execution partners whose names were stolen and used as bait. The common thread in all of it is the same as Mt Gox: money handed to a third party who was not what they seemed. Bitcoin held in your own keys sits outside every one of those failure modes.

The distinction that actually decides your risk

Draw the line clearly and everything downstream gets simpler.

If you hold Bitcoin on an exchange, you do not really hold Bitcoin. You hold an entry in a company's database and, in legal terms, you are an unsecured creditor of that company. Your risk is their solvency, their internal controls and the honesty of the people running the place. Your coins are only ever as safe as that firm's weakest point, no matter how strong the protocol underneath happens to be. When something goes wrong the balance in the app stays the same right up to the moment it becomes worthless.

If you hold the keys yourself, exchange risk drops to zero. Nobody can freeze you, nobody can lend your coins out behind your back and no collapse in Tokyo or the Bahamas can reach you. What changes is that the risk moves onto your own shoulders. Whether your seed phrase is written down and stored off every screen, whether the hardware wallet came genuine from the manufacturer rather than tampered with in the post, whether you have a tested backup and whether you can spot a phishing message before you click it. Those become your problem, and they are solvable problems, but they are yours.

Not your keys, not your coins. It is blunt and it is exactly right.

Self-custody removes the counterparty and hands you the responsibility

Hold your own keys in proper cold storage, a hardware wallet kept offline with the seed backed up somewhere separate, and you become the only person on earth who can move that Bitcoin. No exchange breach anywhere in the world touches you. No lender quietly rehypothecates your coins to prop up its own balance sheet. No regulator freezes a platform you were relying on. That is the whole appeal, and for anyone who watched a South African bank freeze an account first and ask questions later, it is not a paranoid appeal. I walk through the practical mechanics in self-custody in South Africa, and I compare the two models directly in self-custody versus exchange custody.

The price of that freedom is that there is no one to phone. Lose your only key with no backup and the Bitcoin is gone for good, with no appeal. The network does not know who you are and does not care. This is not a flaw that somebody forgot to fix. It is the same property in two directions: the reason nobody can seize your coins is precisely the reason nobody can recover them for you, and any system that added a recovery backdoor would have added a way in for everyone else too.

Which is why the failures in self-custody are almost all self-inflicted and almost all avoidable. People store the seed phrase in a cloud note or a photo, back it up nowhere, or click a link in a message that was engineered to look ordinary. The Lazarus Group famously drained a large sum from a gaming project using nothing more exotic than a fake job interview that got malware onto the right laptop. None of that is a Bitcoin weakness. It is a discipline weakness, and discipline can be taught and checked, which is most of what I do when I sit with a client through a first setup.

What larger holders and institutions do instead

A single key has one honest flaw. It is a single point of failure, and for a meaningful holding that is too much to rest on one device and one piece of paper.

The answer is multisignature. Several keys, generated separately and stored apart, with a rule that any transaction needs a threshold of them before it can move, typically two out of three. Lose one key to fire or theft or simple forgetfulness and the Bitcoin is still safe and still spendable with the other two. No single device, and no single person, can act alone. That structure is what turns key management from a nerve-wracking guess into something an institution can actually govern, with the added benefit that the approvals are recorded on the chain itself as an audit trail rather than buried in some company's private database. I cover how it is built in multi-signature Bitcoin custody.

The SimplB Vault is that principle in managed form. You hold two keys on devices from separate manufacturers, each with its own steel backup, and I hold a third on an air-gapped device purely for recovery and inheritance. Because you hold the majority you can always transact without me, and because I hold only one key I can never move your Bitcoin alone. There is a quiet South African advantage in this too. When you hold the majority of the keys locally, the asset is legally domiciled here, which lets a company secure Bitcoin properly without going to the Reserve Bank for permission to externalise it. That is not a small point for anyone weighing offshore custody against keeping control at home.

Reading the risk the right way round

The people who lost money to Mt Gox were not victims of a broken Bitcoin. They were victims of a badly run business that had taken custody of their coins. The people who lost money to FTX were victims of fraud by named individuals. In both cases the protocol did exactly what it was written to do, on schedule, without a missed beat.

Set Bitcoin's record against the systems we are told to trust instead. Banks get breached, card processors leak and exchanges get robbed with grim regularity. The losses fall on ordinary customers who rarely see the failure coming until the money has already gone. A leaderless network that trusts nothing but mathematics and electricity has a markedly better security record than the intermediaries built on top of it, which is the opposite of the story most people carry in their heads.

So the honest summary is short. The protocol is about as secure as anything humans have built. Everything risky lives in the layer between you and it, and that layer is one you get to choose. Whether your Bitcoin is safe is not really a question about Bitcoin. It is a question about where you decide to keep it, and that decision is entirely yours to get right.

Frequently asked questions

Has Bitcoin ever been hacked?

The protocol itself has never been successfully attacked. In over sixteen years and more than 880,000 blocks, no confirmed transaction has been reversed or altered. What has been hacked are exchanges and custodians, businesses that held Bitcoin on behalf of other people. Mt Gox, Bitstamp, Bitfinex and Bybit were all institutions failing, not the network.

What is a 51% attack and is it a real risk?

A 51% attack means controlling more than half of Bitcoin's mining power to rewrite recent history. At current scale the network runs at over 800 quintillion operations a second, more than the world's largest tech firms and supercomputers combined, so the attack would cost billions, take years and crash the very asset it targeted. Bitcoin has never suffered one.

Is it safe to leave Bitcoin on an exchange?

Holding Bitcoin on an exchange means holding a claim in a company's database, not the coins themselves, which makes you an unsecured creditor of that firm. Your security depends on its solvency, controls and honesty. Mt Gox, FTX and many others show what happens when that trust fails. For anything beyond short-term trading, move it to self-custody or a regulated multisig custodian.

What happens if I lose my Bitcoin seed phrase?

If you lose your only seed phrase with no backup, the Bitcoin is gone for good. There is no recovery line and no backdoor. That is deliberate: the same property that stops anyone seizing your coins is what stops anyone recovering them. It is why a written and tested backup, stored off every screen, is not optional, and why larger holdings belong in a multisig setup where one lost key is survivable.

Move your Bitcoin to proper self-custody.

SimplB helps South Africans secure Bitcoin in cold storage and multi-signature custody, as a Juristic Representative of CAEP Asset Managers (FSP 33933).

Book a custody review