Blockstream

Is Bitcoin safe?

TL;DR: It depends on which risk you mean. Bitcoin's protocol has operated since 2009 without its consensus rules being broken to rewrite history or counterfeit supply. The serious losses people associate with Bitcoin have come from elsewhere: exchanges that failed while holding customer funds, prices that fell sharply, and scams or mistakes at the user level. Each layer carries a different risk, and each has a different mitigation. This article separates them honestly.

"Safe" Covers Four Separate Questions

When someone asks whether Bitcoin is safe, they are usually asking four questions at once, and the questions have different answers:

LayerThe QuestionShort Answer
ProtocolCan the network itself be broken or counterfeited?Its consensus rules have held since 2009. Bugs have been found and patched; settled history has never been rewritten by an attacker.
CustodyIs bitcoin held by an exchange or app safe?Only as safe as the company holding it. Exchange failures are documented and recurring.
PriceWill the value hold?No guarantee. Drawdowns above 70 percent have occurred in past cycles.
UserCan I be scammed or lose access?Yes, and user error causes many real-world losses. Good habits remove most of this risk.

Conflating these layers produces both of the common wrong answers: "Bitcoin is perfectly safe" ignores custody, price, and user risk, while "Bitcoin keeps getting hacked" attributes exchange failures to a protocol that was not the thing compromised. The sections below take the layers one at a time.

Protocol Security: How the Network Itself Holds Up

The Bitcoin network is secured by proof-of-work mining and verified by tens of thousands of independent nodes. Rewriting confirmed transactions would require an attacker to redo the accumulated computational work faster than the entire global hashrate extends the chain, while still producing blocks every node accepts as valid. In more than 17 years of continuous operation, no attacker has accomplished this on Bitcoin: settled history has never been rewritten, and nobody has counterfeited supply that the network accepted as final.

Bitcoin's software has had serious bugs. In August 2010, an integer overflow flaw let someone create a transaction containing 184 billion bitcoin; developers patched the bug within hours and the network abandoned the affected blocks, erasing the exploit's effect. In September 2018, a bug that could have allowed denial-of-service and, in some configurations, inflation was discovered and patched before any exploitation, with the details published in the Bitcoin Core disclosure notice. The accurate claim is narrow and still strong: bugs have existed and may exist again, and the network's record of detecting, patching, and routing around them spans its entire history without a successful theft at the consensus layer.

The economic side of the security model matters as much as the cryptography. Attacking the network requires hardware and electricity at a scale comparable to the global mining industry. Hardware at that scale earns more by mining honestly than an attack would pay. How the incentives, mining, and node validation interlock is covered in How Does Bitcoin Stay Secure?

Custody Risk: When Someone Else Holds Your Keys

Nearly every famous "Bitcoin hack" happened at this layer. An exchange balance is a promise from a company, recorded in that company's internal database. The bitcoin behind that balance sits at an address the exchange controls. If the company is breached, becomes insolvent, or freezes withdrawals, customers discover that what they held was a claim against a business.

The record here is sobering and well documented. Mt. Gox, the largest Bitcoin exchange of its era, suspended withdrawals and entered bankruptcy proceedings in February 2014 after reporting that approximately 850,000 bitcoin belonging to customers and the company were missing; roughly 200,000 were later recovered, and creditor repayments stretched into the 2020s. In November 2022, FTX collapsed into bankruptcy while holding customer assets it was unable to return. Other exchanges have suffered large breaches across the years. The pattern repeats because concentrated funds attract attackers and because a custodian's promises are only as good as its books.

The mitigation is structural rather than hopeful: hold your own keys. Moving bitcoin from an exchange to a self-custodial wallet replaces a claim on a company with direct control, a process explained step by step in How and Why Should I Withdraw My Bitcoin From an Exchange?

Price Volatility Is a Real Risk

A perfectly functioning network does not protect anyone from a falling price. Bitcoin's market value is set by global supply and demand, and it has swung hard in both directions throughout its history. Peak-to-trough drawdowns exceeded 70 percent in multiple past cycles, and steep declines have arrived with little warning.

Volatility is among the most documented properties of the asset, and the structural reasons behind it, from a fixed supply that cannot expand to meet demand surges to a 24/7 global market, are explained in Why Is Bitcoin So Volatile? The practical guidance follows from the data rather than from optimism: position sizes should assume that severe drawdowns can happen again, and money needed on a deadline does not belong in a volatile asset. Many long-term holders reduce timing risk by buying small fixed amounts on a schedule instead of in one lump.

Keep this layer separate from the others in your thinking. The protocol working as designed and the price falling 60 percent can both be true in the same year, and conflating them leads to bad decisions in both directions.

Scams and User Error

The most common way individuals lose bitcoin involves no protocol failure and no exchange collapse. It involves a convincing lie or a careless moment. Because Bitcoin transactions are irreversible by design, an attacker who obtains your keys or tricks you into sending funds does not need to break any cryptography.

The recurring patterns are worth knowing by name:

  • Phishing sites and fake wallet apps that imitate real services to capture credentials or recovery phrases.
  • Fake support staff who contact users after a real problem and ask for the recovery phrase "to restore the wallet". No legitimate company ever asks for it.
  • Giveaway and impersonation scams promising to double whatever is sent.
  • Investment platforms showing fabricated returns until the victim tries to withdraw.
  • Clipboard malware that swaps a copied address for the attacker's at paste time.

Simple habits defeat nearly all of this: never enter a recovery phrase anywhere except the wallet it belongs to, verify addresses on a trusted screen before sending, treat unsolicited contact about your bitcoin as hostile, and assume any promised return is fraudulent. A fuller catalog of failure modes and how to avoid them is in What Are Bitcoin Mistakes to Avoid? and What Can Actually Go Wrong in Bitcoin?

How Self-Custody Changes the Risk

Self-custody removes the custodian from the risk model and puts you in their place. That trade is worth stating plainly, because it cuts both ways: no exchange can lose your bitcoin, and no support desk can recover it if you lose your own backup.

The core responsibility is the recovery phrase, the human-readable backup from which a wallet's keys can be regenerated. Written on paper or stamped into steel and stored offline, it survives lost phones and dead hard drives. Typed into a website or photographed to the cloud, it becomes the single thing an attacker needs. Everything else in self-custody practice is detail around that fact.

Hardware raises the bar further. A hardware wallet such as Jade Plus keeps keys on a dedicated offline device and signs transactions without exposing them, so malware on a computer or phone cannot reach the keys, an approach known as cold storage. Paired with a self-custodial software wallet like the Blockstream app for day-to-day use, the setup covers both convenience and deep storage. Full practices, including backup testing and inheritance planning, are in How Do I Safely Store My Bitcoin?

A Practical Security Checklist

Condensed to the actions that matter most:

  • Hold long-term savings in a self-custodial wallet, with keys on a hardware device for meaningful amounts.
  • Write the recovery phrase on paper or steel, store it offline, and never share it with anyone for any reason.
  • Test the backup by restoring a wallet with small funds before trusting it with large ones.
  • Verify receiving addresses character by character, or on a hardware wallet screen, before sending.
  • Treat unsolicited messages about your bitcoin, however official they look, as attacks.
  • Size holdings so that a severe drawdown would be survivable.

Putting the Layers Together

The protocol has a 17-year record of resisting attack at the consensus level, with bugs found and fixed along the way and no settled history ever rewritten. Custodians fail often enough that leaving bitcoin on an exchange is a documented, recurring source of loss. The price can fall far and fast, and has. Users who guard their recovery phrase and verify what they sign face very little residual risk; users who do neither supply most of the loss statistics.

Safety in Bitcoin is less a property of the asset and more a set of decisions: where the keys live, how the backup is protected, and how much exposure a budget can absorb. The protocol's job is keeping the ledger honest, and it has done that since 2009; the decisions above belong to the holder.

Has Bitcoin ever been hacked?

Bitcoin's consensus rules have never been broken to rewrite settled history or counterfeit supply. Software bugs have been found over the years, including a 2010 inflation bug that was exploited and corrected within hours, and a 2018 bug patched before exploitation. Headlines about hacks almost always describe exchanges or wallets, which are custody failures rather than protocol failures.

Is it safe to keep bitcoin on an exchange?

It carries real counterparty risk. Bitcoin on an exchange is an entry in the company's database, exposed to its security, solvency, and policies. Mt. Gox in 2014 and FTX in 2022 left customers waiting years in bankruptcy proceedings. Withdrawing to a self-custodial wallet removes that dependence on any company.

Can I lose my bitcoin?

Yes, through avoidable mistakes: losing the recovery phrase that backs up your wallet, sending funds to a wrong address, falling for phishing or fake support staff, or trusting a custodian that fails. Bitcoin transactions cannot be reversed, so prevention is the only protection. Careful backups and verification habits eliminate most of these risks.

Is bitcoin a safe investment?

Bitcoin's price is volatile, with peak-to-trough drawdowns that have exceeded 70 percent in past cycles. Nothing guarantees future returns, and anyone treating bitcoin as a guaranteed gain is misinformed. Network security and price risk are separate questions: the protocol can work flawlessly while the price falls. Only commit money whose loss would be tolerable.

What happens if I lose my recovery phrase?

If the wallet itself is also lost or destroyed, the bitcoin becomes permanently unspendable. No company can restore a recovery phrase, and no support line can regenerate it. While the wallet still works, a new backup can be made or funds moved to a fresh wallet. Test backups with small amounts before relying on them.

Share:

Copied!