At Its Peak, 70% of the World's Bitcoin Moved Through a Magic Card Trading Site
August 5, 2026 · 5 min read
The most consequential cryptocurrency exchange in history began as a website for trading fantasy cards.
In 2007, a programmer named Jed McCaleb registered mtgox.com — Magic: The Gathering Online eXchange — intending to build an eBay for collectible card players. It never took off. The domain sat idle, one more abandoned side project.
Then Bitcoin appeared, McCaleb repurposed the domain into a currency exchange, and within a few years that repurposed card-trading site was handling something on the order of seventy percent of all Bitcoin transactions on earth.
In February 2014 it stopped, having lost approximately 850,000 bitcoin belonging to its customers. At the exchange rates of the day, roughly half a billion dollars. At later valuations, an amount that has repeatedly made Mt. Gox creditors' claims worth more than the entire company ever was.
The interesting thing about the loss is that nobody can point to the day it happened.
There Was No Heist
The mental image is a break-in: alarms, a bad night, a discovered breach. That is not what occurred.
The coins left gradually — withdrawal by withdrawal, transaction by transaction, over a period of months and probably years. There was no single moment of crisis, because a slow leak does not produce one. By the time the scale became undeniable, the vaults were effectively empty and had been for a long while.
The technical mechanism most associated with the theft is transaction malleability, a quirk in how Bitcoin worked at the time. Every Bitcoin transaction has an identifier — a hash of the transaction data. It turned out that a third party could alter certain parts of a transaction's signature data without changing what the transaction actually did, and the result was a valid transaction that moved the same coins to the same place under a different identifier.
Harmless on the network. Catastrophic if your accounting system tracks withdrawals by transaction ID and treats "I can't find that ID on the blockchain" as "the withdrawal failed."
Because then a customer could request a withdrawal, receive their coins, alter the transaction ID, and tell support the withdrawal never arrived. Mt. Gox would look for the original ID, fail to find it, conclude the transfer had failed, and send the coins again.
Malleability was known and documented. It was discussed on Bitcoin developer forums years before the collapse. It was a problem for any exchange that built its withdrawal logic naively — and the fix, on the exchange side, was to verify against the actual movement of coins rather than trusting an identifier that was known not to be reliable.
Whether malleability accounts for all 850,000 coins is genuinely disputed; subsequent analysis suggests it explains a portion, with insider access and simple long-running compromise of the exchange's wallets accounting for much of the rest. What is not disputed is that the exchange had no reliable idea how many coins it held.
Nobody Was Reconciling Anything
This is the part that generalizes beyond cryptocurrency.
Mt. Gox did not have the internal controls of a financial institution because it had never intended to be one. It had grown from a hobby project into custody of a significant fraction of a new asset class in about three years, and the engineering, accounting, and governance never caught up with the responsibility.
The Mt. Gox Collapse
There was no regular reconciliation of coins held against coins owed. That single practice — count what you have, compare it to what you owe customers, investigate the difference — is the foundational control of every custody business that has ever existed, and it is precisely the control that would have caught a slow drain in its first month. There was no meaningful segregation of duties. There was no independent audit. The codebase was reportedly maintained without version control for a long stretch, with a single person able to push changes to production.
Mark Karpelès, who took over the exchange from McCaleb in 2011, was by most accounts a capable programmer who liked solving technical problems and had no interest in running a regulated financial business. He was, at the end, personally the bottleneck for a large share of the company's engineering.
And when the shortfall became clear internally, the exchange did what troubled institutions do: it kept operating, kept accepting deposits, and presented balances it could not honor. Withdrawals slowed. The public explanation cited technical difficulties. Then withdrawals stopped entirely, the site went dark, and a leaked internal document put the number at 850,000 coins.
The Aftermath Ran a Decade
Mt. Gox filed for bankruptcy protection in Japan in February 2014. Shortly afterward, 200,000 bitcoin turned up in an old wallet format that had been forgotten — which is either reassuring or alarming depending on how you feel about an institution that could misplace, and then find, two hundred thousand bitcoin.
Karpelès was arrested and prosecuted in Japan. He was ultimately convicted of falsifying financial records and acquitted of embezzlement, receiving a suspended sentence. Whether he was a thief, a man in far over his head, or both, has been argued for over a decade.
The creditors waited more than ten years. The recovered coins appreciated enormously during the proceedings, producing the surreal situation in which a bankruptcy estate became worth vastly more than the losses it was meant to compensate — while the people owed money spent a decade unable to touch any of it. Distributions did not begin in earnest until 2024.
The Lesson That Did Not Take
Mt. Gox is usually filed as a cautionary tale about cryptocurrency. That reading is too narrow and too comfortable.
The failure was custody. Mt. Gox held other people's assets without the controls that holding other people's assets requires, and the specific asset being Bitcoin only determined how fast the shortfall could grow and how permanently it could be moved. Everything else — no reconciliation, no segregation of duties, no audit, a single point of technical control, and continued operation after insolvency was known internally — is a pattern with a very long history in finance.
"Not your keys, not your coins" entered the vocabulary because of this collapse. It is good advice and it was not learned. The years since have produced repeated exchange failures on the same structural template, with the same explanations, culminating in collapses far larger than Mt. Gox.
The card-trading site that became a bank never once counted what was in the vault. That is the whole story, and it did not require a new technology to be possible.
The Mt. Gox Collapse: Bitcoin's First Crisis covers the whole arc — McCaleb's abandoned domain, Karpelès and the rise, the malleability exploit, the slow drain, the faked solvency, the bankruptcy, the criminal case, and the creditors' decade-long wait.







