Only publicly settled, dated matters are used. No rumours, unverified figures or open cases: the purpose is pattern, not history.
Four types, and what each one looks like from outside
| Type | What went wrong | What a user could observe beforehand |
|---|---|---|
| Security breach | Assets in connected systems moved out externally | Usually nothing; disclosure follows the event |
| Long-running operational decay | Technical and process weaknesses accumulating over years | Withdrawals gradually slowing, more manual handling |
| Concentrated control | Critical keys held by very few people | Opaque governance, no independent custody arrangement |
| Customer assets misused | Assets and obligations diverging over time | Nearly invisible until concentrated withdrawals |
Two types gave warning; two did not. A strategy based on spotting trouble covers only half the field.
Four cases with settled public records
February 2014. Mt. Gox, then handling a large share of global volume, halted withdrawals and subsequently entered legal proceedings in Japan, with a large quantity of bitcoin undeliverable to users. It was the industry's first large-scale exchange collapse, and creditor proceedings ran for many years afterwards.
January 2018. Coincheck, a Japanese exchange, was attacked and a large amount of the NEM asset was moved out. Contemporary reporting placed the scale in the hundreds of millions of dollars equivalent. The company was later acquired by the Japanese financial group Monex that same year.
January 2019. QuadrigaCX announced that its founder had died in December 2018 and that the platform could not access cold wallet keys, leaving user assets unrecoverable. In June 2020 the Ontario Securities Commission published a review concluding that the operation had involved conduct including trading with client funds, and that the losses were not primarily attributable to external attack.
November 2022. FTX halted withdrawals amid large-scale redemption demand and filed for bankruptcy protection. In November 2023 its founder was found guilty on multiple counts by a US federal jury, and in March 2024 received a custodial sentence. Those proceedings have concluded.
Read across them and the pattern is clearer than any single case. One was an external attack. One was long-accumulated weakness. One was control concentrated in a single person. One was assets and obligations diverging. Different causes, similar outcome for users.
What proof of reserves actually covers
It shows assets exist. It does not show what is owed.
A reserves attestation demonstrates control of assets at a moment in time. Solvency is assets minus liabilities, and liabilities are the half that a reserves-only statement leaves out.
A platform holding a large quantity of assets while owing users more than that would still produce a reserves figure. The number is real; the inference most readers draw from it is not supported by it.
What makes it meaningfully stronger is a liabilities attestation alongside it, ideally one letting users verify their own balance is included. Some platforms publish material in this area — Binance maintains a public proof of reserves page, for instance, and the useful question when reading any of them is always the same: does this address liabilities, or only assets?
Two further limits worth holding. These are point-in-time snapshots, not continuous monitoring. And they say nothing about operational risk, governance, or how a platform behaves under stress.
Three things an ordinary user can actually do
Narrow, and durable across all four failure types
- Do not concentrate everything in one place. The most boring advice here and the only one that works against causes you cannot observe. It applies to a single exchange and equally to a single wallet whose backup you have never tested.
- Know what happens to withdrawals under stress. Historically they slow or stop before any announcement. Anyone waiting for official confirmation is joining a queue that already formed. Not a prediction — a pattern worth having in mind in advance.
- Read reserves disclosures for what they omit. Assets without liabilities is half a statement. Knowing which half you are reading is the entire skill.
What is deliberately not on that list: monitoring news for signs of trouble, or trying to judge which platform is soundest. Two of the four types produce no advance signal at all, so a strategy resting on vigilance covers half the risk while feeling like it covers all of it.
If you do hold assets on a platform, the settings that limit damage from account-level compromise — a different risk from platform failure — are in is a withdrawal whitelist worth turning on and two-factor: SMS, authenticator app, hardware key.
Common questions
Does proof of reserves mean my funds are safe?
No. Proof of reserves demonstrates that assets exist at a point in time. On its own it says nothing about liabilities, so it cannot show that assets exceed what is owed to users. A reserves attestation combined with a liabilities attestation is a much stronger statement than reserves alone.
Can users see these failures coming?
It varies by failure type. Long-running operational decay often shows up as withdrawals becoming slow or requiring manual handling. Misappropriation of customer assets is close to invisible until concentrated withdrawals expose it. A security breach usually has no warning at all.
Is self-custody the answer then?
It moves the risk rather than removing it. Self-custody eliminates platform failure and replaces it with key management, where mistakes are permanent and there is nobody to appeal to. Which is better depends on which failure you are more likely to make.
How much should I keep on an exchange?
We will not give you a figure, because it depends on what you are doing. The durable principle is not concentrating everything in one place — whether that place is one exchange or one wallet whose backup you have never tested.
What actually happens to withdrawals in a crisis?
A withdrawal pause can have several causes: maintenance, network congestion, security response or liquidity stress. A pause by itself does not identify which one applies. Read the platform's official status material, preserve your account records and do not treat the presence or absence of a restoration estimate as proof of solvency.
Primary sources
These four records support the four historical cases above. They come from regulators, a bankruptcy trustee or a prosecuting authority rather than from promoter copy.
- Coincheck: the Japanese Financial Services Agency's official account of the January 2018 unauthorised outflow.
- Mt. Gox: the bankruptcy trustee's 2014 report to the Tokyo District Court.
- QuadrigaCX: the Ontario Securities Commission staff review report.
- FTX: the US Attorney's Office for the Southern District of New York sentencing release.