Mt. Gox and Bitcoin's First Big Collapse
Book: Crypto Wars: Faked Deaths, Missing Billions and Industry Disruption
Author: Erica Stanford
ISBN: 9781398600683
Previous: Previous: QuadrigaCX, the Faked Death, and Missing Millions
Next: Next: Crypto Mining Scams and Cloud Hashrate Fraud
Before Quadriga faked a death to dodge creditors, Mt. Gox taught the world what happens when the biggest bitcoin exchange runs on vibes, untested code, and a CEO who would rather perfect quiche than check the vault.
Stanford is clear: Mt. Gox was not a planned scam like Bitconnect or OneCoin. It was something almost worse in its own way. A pile of hacks, accounting failures, legal blunders, and slow-motion theft that nobody noticed until one million bitcoin on the books became zero.
If you were in crypto before 2014, you probably had money on Mt. Gox. That is how dominant it was.
From Magic cards to magic money
Mt. Gox did not start as a crypto company. The name means Magic: The Gathering Online Exchange. Founder Jed McCaleb built it for trading playing cards, then rewrote the site in 2010 into a bitcoin exchange while keeping the domain.
Timing was perfect. Bitcoin was a year old and buying it elsewhere was painful. Mt. Gox was clunky, but slightly less clunky than the competition. Orders snowballed. Jed wanted out. Mark Karpeles, an enthusiastic hacker known online as MagicalTux, took over for basically nothing beyond a profit share for Jed.
Karpeles inherited legal uncertainty he did not take seriously. He would later answer “no” on US forms asking whether Mt. Gox exchanged currency or transmitted money. Spoiler: it did both.
Hack after hack, and a CEO who went missing on weekends
The first major hack hit in June 2011. An attacker used Jed’s old admin credentials, crashed bitcoin’s price on the exchange from $17 to one cent, bought 2,000 coins cheap, and sold them back at market rate. Panic spread. Volunteers flew in from around the world to help rebuild systems over a weekend. Karpeles, according to Stanford, was absent until Monday and then worked on unrelated tasks.
That was only the beginning. Six hacks hit in 2011 alone, plus bugs that sent tens of thousands of bitcoin to wrong accounts or broken wallet addresses.
Security that would have cost a fraction of the losses was never treated as urgent. Meanwhile deposits kept arriving faster than bitcoin leaked out, so the books looked fine. Nobody reconciled what they should have held versus what was actually there.
That pattern is the scariest part to me. The exchange was bleeding for years and still looked alive because new money kept walking in the door.
The slow drain: 850,000 bitcoin gone
By February 2014, Mt. Gox handled over 80 percent of global bitcoin trades. Then withdrawals stopped. Users who had waited months for cash got silence. Bitcoin priced on Mt. Gox traded at less than half the market rate. On February 24, the exchange shut down. A leaked document revealed the truth: they should have had one million bitcoin. They had none.
Investigators later pieced together a three-year bleed. Starting from the 2011 breach, an attacker copied Mt. Gox’s private keys and set automations to siphon coins gradually. About nine out of ten incoming deposits were stolen as they arrived. The thief could have taken everything at once, but that would have crashed bitcoin’s thin liquidity and attracted instant law enforcement heat. Slow draining was smarter.
Total loss: 850,000 bitcoin. Roughly 740,000 belonged to customers. At bitcoin’s later peak near $48,000, Stanford notes that stack would have been worth over $40 billion.
Karpeles later found 200,000 bitcoin sitting in an old forgotten wallet, which was luck, not competence. That still left 650,000 missing.
Willy, Markus, and market manipulation
After collapse, a leaked trading database exposed two suspicious automated buyers later nicknamed Willy and Markus.
Willy bought 10 to 20 bitcoin every five to ten minutes in round dollar amounts, only buying, never selling, using fresh accounts, and somehow trading even when the exchange was closed. Markus showed weirder fiat amounts and worked alongside Willy. Together they bought around 250,000 bitcoin and may have pushed wider market prices up.
Karpeles admitted running Willy as part of an “obligation exchange” to simulate volume and keep the exchange alive after the 2011 shortfall. He called it for the good of the company. Courts did not entirely agree, but Stanford’s framing matters here: the bots were a bandage on a gunshot wound, not the original crime.
BTC-e, Alexander Vinnik, and the puzzle solver
Swedish engineer Kim Nilsson spent years tracing coins on the public blockchain. He linked about 630,000 stolen bitcoin to wallets tied to a Mt. Gox account called WME, which pointed to Alexander Vinnik, operator of shady Russian exchange BTC-e. Vinnik was arrested in Greece in 2017 for laundering billions, including Mt. Gox proceeds.
Protests, Ponzi comparisons, and a cruel legal twist
Outside Mt. Gox’s Tokyo office, a protester stood for two weeks with a sign: “MT GOX WHERE IS OUR MONEY?” Karpeles hid in his penthouse doing database archaeology while lawyers compared the final months to Bernie Madoff, using new deposits to pay older withdrawal demands.
Karpeles was convicted in 2019 of falsifying financial records but acquitted of embezzlement, receiving a suspended sentence. Stanford argues he was incompetent and in over his head, not a mastermind thief. I tend to agree with her read. Negligence at industrial scale can ruin as many lives as malice.
The final irony is brutal. Under Japanese bankruptcy law, creditors may be repaid at bitcoin’s dollar value when Mt. Gox failed, around $489 per coin. The remaining 200,000 bitcoin could repay everyone several times over in fiat today, yet lawsuits and legal delays have stretched the saga for years. Hackers who sold early reportedly made around $20 million, while victims lost far more.
Mt. Gox did not need a fake death or a cryptoqueen on the run. It just needed someone to count the coins before they were all gone.