AMLConsensus · course
Programme · Lesson 11.6
Section 11 · Lesson 11.6 · case study

Mt.Gox: How 850,000 BTC Were Traced Piece by Piece

In 2014 the largest bitcoin exchange on the planet collapsed, taking roughly 850,000 BTC down with it. The trail seemed lost forever. But the blockchain forgets nothing — and what could not be untangled in weeks was untangled by independent researchers over years, coin by coin, transaction by transaction. This is a story about patience that proves stronger than any encryption.

The scene of the crime: the exchange all of bitcoin flowed through

In the early 2010s Mt.Gox was more than just an exchange — the lion's share of the world's entire bitcoin turnover passed through it. The Tokyo-based venue had grown out of a site for swapping cards from a tabletop game (the acronym stood for Magic: The Gathering Online Exchange) into the main gateway through which ordinary people bought and sold the first cryptocurrency. When infrastructure like that falls, the trust of an entire industry falls with it.

In 2014 Mt.Gox collapsed, and roughly 850,000 BTC were lost. Some of the coins belonged to the exchange itself, but most of it was the money of tens of thousands of customers who had entrusted the venue with custody. At the prices of the day this amounted to hundreds of millions of dollars; at later prices, tens of billions. The exchange declared insolvency, and the question "where did the coins go?" hung in the air for years.

Why an ordinary "investigation" didn't work here

When a bank is robbed, the inquiry follows the paperwork: accounts, transfers, requests to other banks. In the Mt.Gox case there was neither a clear point of breach nor a tidy ledger. The coins leaked out gradually, over a long stretch of time, blending in with the exchange's legitimate turnover. The internal bookkeeping was tangled, and some of the movements were disguised as the venue's normal activity. A classic auditor ran straight into a wall here: they could see the money was gone, but not the road it had left by.

And this is where a fundamental property of the blockchain comes onto the stage — the one we have been discussing since the very first section of the course: a public ledger is a permanent record. Every transaction ever made on the bitcoin network is openly accessible and never disappears. The problem is not that the data is missing — on the contrary, there is too much of it. The problem is separating the "thread" of stolen coins from millions of unrelated movements and not losing it at the branch points.

The WizSec method: patience instead of magic

The untangling was carried out not by government agencies armed with warrants, but by independent analysts — the team at WizSec and the researcher Kim Nilsson. They had no access to internal servers, no subpoenas, no way to question witnesses. They had exactly the same tool available to any of us: the open blockchain and a working brain. And yet it was precisely they who, tracing the theft piece by piece over years, managed to reconstruct the picture.

What does that work look like in practice? It is not a single flash of insight but thousands of small steps that add up to a route. The analyst takes the known exchange addresses, finds the moment when the coins start behaving "wrong," and from there follows the chain hop by hop, applying the same techniques you studied in the sections on tracing and patterns.

  1. Clustering. Group together addresses that most likely belong to a single owner (for example, by co-spending inputs within one transaction).
  2. The break-away point. Find the moment when the coins leave the exchange's legitimate perimeter and move into wallets controlled by the attacker.
  3. Tracing the hops. Follow the chain of transfers, marking the nodes of splitting, merging and transit.
  4. Reaching the "cash-out" points. Find the addresses where the dirty flow meets the on- and off-ramps to fiat — that is where the trail turns into a name.
  5. Cross-checking and re-verification. Match the resulting picture against other open data to rule out attribution errors.

The key word here is time. An investigation like this cannot be done over a weekend. It stretches over years, because the dirty flow is deliberately blurred: it is split up, driven through intermediate addresses, mixed with other people's funds. Every such maneuver adds work for the analyst, but not one of them erases the record. A coin that has passed through a hundred addresses still leaves a hundred traces — they simply have to be walked through patiently.

Where the trail led: BTC-e and Alexander Vinnik

Years of tracing did not remain an abstract exercise. The thread of the stolen Mt.Gox coins led the researchers to a specific point of cash-out — the BTC-e exchange, a venue with extremely weak (and effectively absent) KYC procedures that had long raised questions among industry watchers. And behind BTC-e's operations, the investigation eventually reached a specific individual — Alexander Vinnik, who was linked to servicing these flows.

Note the logic of the denouement. The hack took place on the blockchain, where there are no names — only addresses. But to turn bitcoin into usable money, sooner or later you have to pass through a point where crypto meets the real world: an exchange, a bureau de change, a cash-out to fiat. That very point became the weak link. As long as the coins wandered between anonymous addresses, they remained mere numbers. The moment they tried to become "real money," the trail acquired a name.

"Not your keys, not your coins."

— Andreas Antonopoulos, on the importance of self-custody of keys

This phrase echoes twice over in the Mt.Gox case. For the exchange's customers it meant a bitter truth: by entrusting their coins to someone else's venue, they had also entrusted it with the risk of its collapse. And for the investigators it highlights the other side — wherever coins leave self-custody and land on an exchange, a point of control and a point of trace arises. What makes the customer vulnerable makes the attacker vulnerable too.

What this case teaches an AML specialist

The Mt.Gox case is a textbook in patient tracing. It shows that in crypto forensics there are almost no "cold cases": what cannot be untangled today gets untangled a year, two, or five years later, because the underlying data goes nowhere. For a practicing analyst, several practical conclusions follow from this.

What this case teaches. The blockchain is a permanent record, which means time works for the investigators, not the criminal. Patient, long-haul tracing "piece by piece" can reconstruct a route even years after a theft and lead to the real cash-out point — and, with it, to a name. In an AML check this means: never write off an "old" trail as hopeless, and always follow the thread all the way to the point where crypto meets fiat — that is where the truth about the origin of the funds is hiding.

Facts are presented from open sources. This material is for educational purposes.