The Day Bitcoin Hit $0.01: Inside the Mt. Gox Flash Crash of June 19, 2011
June 19, 2011 — It was a Sunday morning in Tokyo when the world's largest Bitcoin exchange began to unravel. Within minutes, the price of Bitcoin cratered from $17 to $0.01 — a 99.9% collapse that would have wiped out the entire market if it had been real.
But it wasn't real. It was a hack. And the fallout from that single incident would echo through the cryptocurrency industry for over a decade, culminating in the exchange's catastrophic collapse in 2014, the loss of 850,000 Bitcoins, and the bankruptcy of what was once the center of the Bitcoin universe.
This is the story of how a single stolen auditor password nearly destroyed Bitcoin in its infancy — and the lessons the crypto industry is still learning, fourteen years later.
The Context: Bitcoin in Mid-2011
To understand the gravity of June 19, 2011, you need to understand where Bitcoin was at the time.
Bitcoin was barely two years old. Mt. Gox, founded by programmer Jed McCaleb in July 2010, had rapidly become the dominant exchange, handling the vast majority of Bitcoin trading globally. The exchange name was a holdover from McCaleb's abandoned "Magic: The Gathering Online Exchange" project — he simply repurposed the domain.
By June 2011, Bitcoin had just experienced its first major bull run. The price had surged from under $1 in January to an all-time high of approximately $32 in early June. Then came the pullback. By June 19, Bitcoin had already corrected to around $17 — still a remarkable price for an asset that had been worth pennies just eighteen months earlier.
Mt. Gox was the only game in town for serious Bitcoin trading. There were no Coinbases, no Binances, no regulated custodians. If you wanted to buy or sell Bitcoin, you went to Mt. Gox. McCaleb had already sold the exchange to French developer Mark Karpelès, known online as "MagicalTux," who took over operations in March 2011.
What neither McCaleb nor Karpelès knew was that the exchange was already compromised before the handover was complete.
The Breach: How One Password Crashed an Exchange
The attack on June 19, 2011, was not a sophisticated zero-day exploit. It was a credential compromise made possible by amateur security practices that would be unthinkable today.
Here's what happened, according to blockchain investigator Kim Nilsson of WizSec, who spent years reconstructing the Mt. Gox disaster:
The Auditor Account
Jed McCaleb's original administrator account was still active in the Mt. Gox system when Karpelès took over. The account was kept active to facilitate auditing and verification — a common practice, but one that should have been accompanied by multi-factor authentication, strict access controls, and monitoring.
None of those protections existed.
The Database Leak (Days Earlier)
Just days before the flash crash, on June 17, 2011, an attacker had already breached Mt. Gox's user database. They extracted a table containing 61,016 user accounts with weakly salted password hashes. The database was subsequently posted for sale on Pastebin, a public text-sharing website, where anyone could download it.
This leak wasn't widely reported at the time, but it was devastating. The attackers used the stolen credentials to brute-force passwords, including the password to Jed McCaleb's admin account. Because Mt. Gox's password hashing was weakly salted, modern GPUs of the era could crack large portions of the database in hours.
Creating Bitcoin from Thin Air
Once inside the admin panel, the hacker didn't merely steal existing Bitcoins. They exploited something far more dangerous: the ability to manipulate account balances.
Using McCaleb's compromised admin credentials, the attacker created new accounts and inflated their Bitcoin balances to absurd levels — essentially creating Bitcoin out of thin air within Mt. Gox's internal database. The exchange's trading engine treated these fabricated balances as real.
The attacker then dumped these fake Bitcoins onto the market as fast as possible. At 10:00 AM JST on June 19, the selling began. The market, already thin and illiquid by modern standards, couldn't absorb the tsunami of sell orders. The price collapsed from $17 to $0.01 in minutes.
The Numbers
According to Mt. Gox's own statements and Nilsson's blockchain analysis:
- Fake Bitcoins sold: Approximately 500,000 BTC in fake trades over one hour
- Price bottom: $0.01 per Bitcoin (a 99.9% crash from $17)
- Real Bitcoins stolen: Approximately 2,000 BTC that were actually withdrawn from the exchange
- User accounts compromised: 61,016 accounts exposed in the database leak
- Exchange market share: Mt. Gox handled approximately 70% of global Bitcoin trading
The attacker also attempted to withdraw funds during the chaos. Some accounts with legitimate balances at $0.01 attempted to withdraw, but Karpelès shut down the servers before significant outflows could occur.
The Rollback: Crypto's First Major Controversy
Karpelès acted quickly. He saw the crash unfolding, realized the admin panel had been compromised, and immediately shut down Mt. Gox's servers. The exchange went dark.
Then came the most controversial decision in early Bitcoin history: the rollback.
Mt. Gox announced that all trades executed during the crash period would be reversed. The exchange would restore Bitcoin prices to approximately $17.50 and nullify every transaction that occurred during the hack. Users who had legitimately sold Bitcoin at $17 would keep their trades. But anyone who had "bought" Bitcoin at $0.01 — including some users who saw the crash and genuinely attempted to purchase — would have those trades undone.
The exchange posted a statement: "Huge Bitcoin sell off due to a compromised account — rollback. The bitcoin will be back to around 17.5$/BTC after we rollback all trades."
The community reaction was split. Some praised Karpelès for preventing what would have been a catastrophic, potentially fatal blow to Bitcoin. Others criticized the rollback as centralized intervention in a system that was supposed to be trustless. The irony was not lost on early Bitcoiners: a supposedly decentralized currency had just been saved by a single administrator unilaterally reversing transactions on a centralized exchange.
What the Hack Revealed About Mt. Gox's Security
The June 2011 hack was not an isolated incident. It was the first visible symptom of an exchange built on quicksand.
Pre-Existing Insolvency
Kim Nilsson's investigation, published years later, revealed that Mt. Gox was already technically insolvent when Karpelès took over. Before the June 2011 hack, approximately 80,000 Bitcoins had been stolen from the exchange's hot wallet — a theft that occurred during McCaleb's ownership but wasn't detected until after the handover. These Bitcoins were transferred to an address where they remain, untouched, to this day.
Additional Breaches in 2011
The June 19 hack was just the beginning. Later in 2011, additional breaches occurred:
- September 2011: Another database breach allowed attackers to alter account balances directly, resulting in the theft of approximately 80,000 additional Bitcoins.
- October 2011: Mt. Gox's hot wallet file (wallet.dat) was stolen. This would become the big one — the thief maintained access to the wallet for nearly two years, siphoning approximately 650,000 Bitcoins before the theft was detected in 2013.
By the time the 2014 collapse occurred, Mt. Gox had lost approximately 850,000 Bitcoins to various hacks and thefts — the vast majority of which happened under Karpelès's management.
The Unsecured Admin Panel
Perhaps the most shocking revelation was that the Mt. Gox admin panel — a page that allowed operators to manipulate account balances, view private user data, and control the exchange — was protected by nothing more than a single password. There was no two-factor authentication, no IP whitelisting, no access logging, no approval workflows for large balance changes.
In an era when cryptocurrency exchanges now employ dedicated security teams, hardware security modules (HSMs), multi-signature cold wallets, and SOC 2 compliance, the Mt. Gox infrastructure was little more than a web application run by a handful of developers.
The User Database: What Was Exposed
The Pastebin leak of June 2011 was a data breach that would have triggered massive regulatory fines today. The leaked database contained:
- User IDs
- Usernames
- Email addresses
- Password hashes (weakly salted, vulnerable to rainbow table attacks)
- Account balance information (for some records)
The weakly salted hashes meant that dedicated attackers could crack a significant portion of the passwords using precomputed tables. For users who had reused their Mt. Gox password on other services, the leak created a cascading security risk.
The full database was eventually distributed widely enough that it became part of the public record of early Bitcoin history. Today, the leaked database is still analyzed by researchers studying the demographics and behavior of early Bitcoin adopters.
The Price Impact: A 99.9% Crash That Lasted Minutes
The June 19, 2011 flash crash was the first major Bitcoin price collapse, and it set a pattern that would repeat throughout the decade.
Bitcoin's price had peaked near $32 on June 8, 2011. By June 19, it had already corrected to $17. The flash crash to $0.01 represented a 99.9% drop from the pre-crash price and a 99.97% drop from the all-time high just eleven days earlier.
But here's what makes the incident remarkable: Bitcoin survived. The exchange reopened. The price recovered. Within weeks, Bitcoin was trading back above $15. The ecosystem didn't collapse because it was so small that the damage, while devastating to Mt. Gox, was containable for the broader market.
Contrast this with the 2014 Mt. Gox collapse, which caused a two-year bear market. In 2011, Bitcoin was still tiny enough to absorb catastrophic exchange failures. By 2014, it was big enough that the failure of its largest exchange could drag the entire market down.
Long-Term Impact: Lessons That Took Years to Learn
The June 2011 Mt. Gox hack taught the crypto industry painful lessons that took years to fully implement:
1. Exchange Security is Not Optional
Mt. Gox proved that running an exchange with minimal security was a ticking time bomb. Modern exchanges now invest heavily in security infrastructure, bug bounty programs, and regular audits. The notion that a single stolen password could crash a 70% market share exchange is now unthinkable.
2. Proof of Reserves Matters
The 2011 hack — and the subsequent 2014 collapse — demonstrated that users had no way to verify that exchanges actually held the funds they claimed. The concept of "proof of reserves," now implemented by several major exchanges, emerged directly from the Mt. Gox disaster.
3. Rollbacks Undermine Trust
The controversial rollback of June 2011 established a precedent that centralized exchanges could reverse transactions. This tension between exchange autonomy and blockchain immutability remains unresolved today. It also helped drive interest in decentralized exchanges (DEXs) that operate without central administrators who can reverse trades.
4. The Database Leak Problem
The Pastebin leak of 61,000 user accounts highlighted the risks of centralized data collection. In an industry where privacy is often a core value, the Mt. Gox database leak demonstrated that exchanges had become honeypots of sensitive personal information. This has driven interest in non-custodial solutions and decentralized identity systems.
5. Hot Wallet Vulnerabilities
The repeated theft of hot wallet files from Mt. Gox led to the industry-wide adoption of cold storage practices. Today, major exchanges keep 95%+ of funds in offline cold wallets, with only a small operational float in hot wallets. Multi-signature schemes, geographic distribution of keys, and hardware security modules are now standard.
6. Exit Scams and Insolvency Detection
The 2011 hack revealed that Mt. Gox was already missing funds when Karpelès took over. This pattern — of new owners inheriting insolvent exchanges and attempting to trade their way back to profitability — became a recurring theme in crypto. It led to the development of on-chain analytics tools that can detect unusual exchange reserve movements, providing early warning of potential insolvency.
The 2023 Connection: Justice Department Charges
In June 2023, the U.S. Department of Justice unsealed charges against Russian nationals Alexey Bilyuchenko and Aleksandr Verner, alleging they were responsible for the 2011 hack of Mt. Gox. According to the indictment, the defendants operated the illicit BTC-e exchange, which was used to launder funds stolen from Mt. Gox and other hacked exchanges.
The charges confirmed what blockchain investigators had long suspected: the 2011 hack was not an isolated amateur attack but part of a larger criminal operation targeting cryptocurrency exchanges. The stolen funds from the 2011 hack were traced through complex laundering schemes, eventually flowing into the BTC-e exchange, which operated from 2011 to 2017.
This revelation added a new dimension to the Mt. Gox story: the exchange wasn't just a victim of poor security practices. It was targeted by organized cybercriminals who systematically exploited vulnerabilities across the entire early cryptocurrency ecosystem.
What Happened to the Lost Bitcoins?
One of the most fascinating footnotes of the Mt. Gox saga involves the stolen Bitcoins themselves.
The 80,000 BTC Hot Wallet Theft
The approximately 80,000 Bitcoins stolen from the hot wallet before Karpelès took over were transferred to a specific Bitcoin address. They have never moved. As of June 2026, fourteen years later, they remain in that address — a frozen monument to the earliest major Bitcoin theft. Speculation about why they haven't moved ranges from lost private keys to the thief's death to strategic patience.
The 650,000 BTC Wallet.dat Theft
The larger theft — the 650,000 Bitcoins siphoned from the stolen wallet.dat file between 2011 and 2013 — was partially traced. Some of these funds were eventually recovered through the Mt. Gox bankruptcy proceedings, and creditors have been receiving distributions since 2024. The recovered funds represent a small fraction of the total stolen, but they have provided some closure to the victims of history's largest cryptocurrency exchange failure.
Historical Parallels: Why June 19, 2011 Still Matters
Fourteen years after the Mt. Gox flash crash, similar vulnerabilities still plague parts of the cryptocurrency industry:
- Centralized exchanges remain the primary targets for hackers, with billions stolen annually across the industry
- Admin panel compromises continue to cause catastrophic losses, most notably in the 2022 Ronin Network hack ($620M) where compromised validator keys enabled the theft
- Database leaks remain common, with exchange user data regularly appearing on dark web markets
- Flash crashes still occur, though modern circuit breakers and market maker protections have reduced their severity
The difference today is scale. A 99.9% flash crash on a major exchange in 2026 would wipe out trillions in market value, trigger regulatory investigations across multiple jurisdictions, and potentially cause systemic contagion across DeFi protocols, lending platforms, and institutional positions.
Bitcoin in 2011 was an experiment that could afford to fail. Bitcoin in 2026 is a global financial asset that cannot.
The Human Element: Mark Karpelès and the Burden of a Broken Exchange
Mark Karpelès is a controversial figure in Bitcoin history. He took over an exchange that was already missing funds. He presided over multiple breaches that cost users hundreds of thousands of Bitcoins. He was arrested in 2015, convicted of falsifying financial records in 2019, and served a suspended sentence in Japan.
But it's worth noting that Karpelès also tried to save Mt. Gox. The June 2011 rollback, however controversial, prevented a potential death blow to Bitcoin. He kept the exchange running for nearly three years after the first hack, attempting to trade his way back to solvency. He was in over his head — running a global financial exchange with minimal staff, no formal financial training, and software that was never designed for the scale it reached.
The Mt. Gox story is not simply a tale of criminal hackers and incompetent administrators. It is the story of an entire industry learning, in real-time, how to build secure financial infrastructure for a technology that had never existed before. The lessons were learned through catastrophic failures, and the tuition was paid by Mt. Gox's users.
Conclusion: The Month Crypto Learned Exchanges Could Fail
June 2011 was the month the cryptocurrency industry learned that exchanges could fail. Before the Mt. Gox hack, the community operated with a naive optimism — the Bitcoin protocol itself was secure, therefore the ecosystem built around it must be secure too. The flash crash to $0.01 shattered that illusion.
The hack demonstrated that Bitcoin's security model ends at the protocol layer. Exchanges, wallets, and custodial services are centralized points of failure that introduce vulnerabilities the blockchain cannot protect against. This understanding drove the development of hardware wallets, multi-signature schemes, decentralized exchanges, and the "not your keys, not your coins" philosophy that defines crypto security culture today.
Fourteen years later, Bitcoin trades at prices that would have been unimaginable in 2011. Mt. Gox is a historical footnote, a cautionary tale told to newcomers. But the lessons of June 19, 2011, remain as relevant as ever: in a trustless system, trust is the most dangerous vulnerability.
The hacker who crashed Bitcoin to a penny with a single password taught the industry that decentralized money requires centralized security — and that when those centers fail, the damage can be catastrophic.
Track real-time Bitcoin volatility, exchange security incidents, and market structure analysis at LiveVolatile.com.
Disclaimer: This article is for educational and historical purposes. It does not constitute financial advice. Cryptocurrency investments carry significant risk. Always conduct your own research and use secure, reputable exchanges.