How Risky Is Crypto? Seven Separate Dangers, Taken One at a Time
The word "risky" covers price crashes, failed platforms, theft, scams, user error, buggy code and missing insurance. Here is each one with a real, dated case, starting with the $1.5 billion stolen…

TL;DR
- Crypto risk is really seven separate risks: price, platform failure, hacks, scams, your own mistakes, faulty code and the absence of any compensation scheme.
- Price hits every holder alike, and bitcoin fell from about $126,000 in October 2025 to below $60,000 by June 2026 with no hack or fraud involved.
- Coins held by a company share its fate, and FTX customers were repaid on claims fixed at November 2022 prices of $16,871 per bitcoin.
- Neither the UK's FSCS nor the US FDIC covers crypto, so losses from failure, theft or error usually stay where they land.
On 21 February 2025, the people who control Bybit's cold wallet approved what their screens showed as a routine transfer between the exchange's own accounts. The screens had been doctored, and their signatures gave the wallet away. About 401,000 ether and other tokens, roughly $1.5 billion in all, went to hackers the FBI tied to North Korea five days later.
It was the biggest theft from an exchange on record, and it says surprisingly little about whether crypto is dangerous for you. Three days later Bybit said it had replaced all the stolen ether with loans and purchases, and its customers carried on withdrawing.
So "how risky is crypto?" has no single answer. The word covers at least seven separate dangers, and they hit different people in different ways. Some can be shrunk with dull habits, others come with the asset. What follows takes them in turn, with a real case for each. None of it is financial advice.
The price can halve, and recently did
Bitcoin set a record of about $126,000 on 6 October 2025, and by June 2026 it was trading below $60,000. More than half its value went in eight months, and no hack or fraud was needed to make it happen.
It was not a first. Between November 2021 and November 2022 bitcoin fell about 77%, from $69,000 to around $15,500. Ether did worse in the latest slide, dropping from roughly $4,950 in August 2025 to about $1,660 in late June 2026. Price is the one risk that reaches every holder, however carefully the coins are stored.
The main lever is how much you put in. Since October 2023, UK rules have required crypto adverts to carry a warning that opens with "Don't invest unless you're prepared to lose all the money you invest". Borrowing to buy makes a fall worse, because a lender can force a sale at the bottom.
The company holding your coins
Coins that an exchange or lender holds for you are, in practice, a claim on a company. When the company fails, you become one of its creditors.
Mt Gox, once the world's largest bitcoin exchange, stopped withdrawals on 7 February 2014 and filed for bankruptcy protection in Tokyo three weeks later, saying about 850,000 bitcoin were missing. Repayments to creditors started in July 2024. The trustee's deadline for finishing them has been pushed to 31 October 2026, more than twelve years after the collapse.
Celsius, a crypto lender with about 1.7 million users, froze withdrawals on 12 June 2022 and filed for bankruptcy a month later. In January 2023 a New York bankruptcy judge ruled that some $4.2 billion of crypto in its interest-paying Earn accounts belonged to Celsius, because the terms customers had accepted said so.
FTX halted withdrawals on 8 November 2022 and filed three days later, around $8 billion short. By August 2026 its customers had been paid back about 105% of their claims and still lost out, because the claims were fixed in dollars at filing-day prices, which valued a bitcoin at $16,871. When payouts began in February 2025, a bitcoin cost about $95,000.
Two questions are worth asking before leaving coins anywhere: who holds the keys, and what do the terms say you own? Celsius customers got the second answer from a judge.
Theft by hacking, theft by persuasion
Nobody cracked Ethereum to rob Bybit. The attackers broke into one developer's computer at the firm that supplied Bybit's wallet software, and from there they altered what the signers' screens displayed. Almost every big theft works like this: the maths survives, but a laptop, a login or a tired person does not.
Chainalysis put the 2025 total at more than $3.4 billion stolen. Bybit alone was about 44% of that, and North Korean groups took roughly $2 billion across the year. Ordinary holders were hit far more often and for far less each time: 158,000 compromised personal wallets, belonging to 80,000 people, worth about $713 million between them.
Where the coins sit decides whose weak spot matters. On an exchange it is the exchange's, and in your own wallet it is your phone, your laptop and your habits. Unique passwords and app-based two-factor codes shut some doors on an account, and a hardware wallet shuts some on keys you hold yourself. Some stay open whatever you do.
Scams skip the break-in and get you to send the coins yourself. For 2025 the FBI's internet crime report, published in April 2026, logged 181,565 crypto-related complaints and $11.4 billion of losses, a record and 22% more than the year before. Fake investment schemes accounted for over $7 billion of it, and people aged 60 and over reported losing $4.4 billion.
The script is monotonous. First contact comes from a stranger, returns are promised, then something becomes urgent, and eventually you are asked for your recovery phrase or for a "release fee" before your supposed profits can be withdrawn. No legitimate company, exchange or wallet ever needs that phrase.
Your own mistakes
There is no undo button, and no helpline that can press one for you. On 10 November 2025 somebody moved about $10 of bitcoin and attached a fee of 0.9999 BTC, worth around $105,000 that day. The network did precisely what the signed transaction told it to. The fee went to the mining pool that confirmed the block, and getting any of it back depended entirely on that pool's goodwill.
Lost keys do the same damage slowly. In 2020 Chainalysis estimated that about 3.7 million bitcoin, roughly a fifth of all the coins then in existence, had sat untouched for five years or more and were probably gone for good. A coin sent over the wrong network, or to an address pasted from the wrong window, usually ends up in the same place.
The habits that prevent this are boring. Send a small test first and wait for it to arrive. Check the network with the same care as the address. Write the recovery phrase down, keep it offline, and put it somewhere a spring clean will not throw it away.
The code itself
Bitcoin's ledger has run since January 2009, and its most famous failure came on 15 August 2010, when a transaction appeared that created more than 184 billion bitcoin out of nothing by overflowing a sum. A fix was out within about five hours. By the next day the corrected chain had overtaken the bad one, and the phantom coins no longer existed.
Code built on top of blockchains is younger and has failed far more often. In June 2016 an attacker used a flaw in The DAO, an investment fund run by smart contracts on Ethereum, to drain about 3.6 million ether, a third of its money. Ethereum answered with a hard fork on 20 July that put the ether back within its owners' reach, and the minority who refused the change kept the old chain, now Ethereum Classic.
The 2010 bug had a cousin fifteen years later. On 22 May 2025 a faulty overflow check in Cetus, a trading protocol on the Sui blockchain, let an attacker take about $223 million, of which Sui's validators froze around $162 million. Every extra protocol your coins pass through is more code that has to be right.
Who pays when it goes wrong
Usually nobody.
The UK's Financial Services Compensation Scheme protects bank deposits up to £120,000, but its own leaflet lists cryptoassets among the things it does not cover, and it says it cannot help if a crypto platform goes out of business. In the US, the FDIC says its insurance does not cover crypto assets and does not protect against the failure of crypto exchanges, custodians or wallet providers.
When a UK bank fails, the FSCS normally repays savers within seven days. A failed crypto firm goes through the courts instead, which is how Mt Gox creditors came to wait ten years for their first coins.
The UK warning quoted earlier has a second sentence: "This is a high-risk investment and you should not expect to be protected if something goes wrong". It means exactly what it says.
Frequently Asked Questions
Yes, in several unrelated ways. Prices can lose more than half their value within months, as bitcoin did between October 2025 and June 2026. A platform holding your coins can fail, thieves can target exchanges or your own wallet, and a single wrong transaction cannot be reversed. How exposed you are depends on how much you hold and where it sits.
Generally not in the way a bank deposit is. The UK's FSCS lists cryptoassets among the products it does not cover, and the US FDIC says its insurance does not protect against the failure of crypto exchanges or custodians. Customers of a failed platform usually become creditors in a bankruptcy that can run for years: Mt Gox repayments began a decade after its 2014 collapse.
Not in the way the headlines suggest. The large thefts, such as the $1.5 billion taken from Bybit in 2025, broke into exchanges, apps and personal wallets while the underlying ledgers kept working as designed. The software has had serious bugs, though: in August 2010 one transaction created over 184 billion bitcoin through an overflow error, and a fix plus a corrected chain erased them within about a day.
In the US alone, the FBI recorded about $11.4 billion in crypto-linked losses for 2025, from more than 181,000 complaints and 22% higher than in 2024. Fake investment schemes accounted for over $7 billion of that total, and people aged 60 and over reported the largest losses of any age group, around $4.4 billion.
Usually not. Once confirmed, a transaction cannot be reversed by the network, a bank or a card company. Getting it back depends on whoever controls the receiving address choosing to return it, which is plausible if that address belongs to an exchange that can trace the error and unlikely otherwise. Sending a small test amount first is the standard precaution.
