Bitfinex: what actually recovered the bitcoin, and why nobody repeats it

2026-08-01 · Illicit Finance The story everybody tells about the largest financial seizure in United States history at the time is that a $500 Walmart gift card brought it down. The affidavit says something duller, and the dull version is the one worth reading. Case file…


01 / 01 Sections Sections

2026-08-01 · Illicit Finance

The story everybody tells about the largest financial seizure in United States history at the time is that a $500 Walmart gift card brought it down. The affidavit says something duller, and the dull version is the one worth reading.

Case file

Field Value
Matter United States v. Ilya Lichtenstein and Heather Rhiannon Morgan
Court D.D.C., Judge Colleen Kollar-Kotelly
Docket 1:23-cr-00239 (CKK). Arrest complaint 1:22-mj-00022 (RMM), 7 February 2022
Affiant Special Agent Christopher Janczewski
Breach August 2016. Over 2,000 unauthorised transactions, 119,754 BTC out of the exchange
Value Approx. $71 million at the time. Over $4.5 billion as of February 2022
Recovery 31 January 2022, by decrypting a file in a cloud storage account obtained under warrant
What the file held A list of 2,000 addresses and their private keys
Lichtenstein conviction Guilty plea to one count, 18 U.S.C. § 1956(h), money laundering conspiracy. Not the hack
Sentences Lichtenstein 60 months plus 36 months supervised release. Morgan 18 months
Judgments 3 December 2024 and 11 December 2024
Posture as of 1 August 2026 Both convicted and sentenced. No appeal on the dockets read

What the record shows

In or around August 2016, a hacker breached the security systems of a virtual currency exchange, referred to throughout the complaint as the Victim VCE and publicly known to be Bitfinex. Inside the network, the hacker initiated over 2,000 unauthorised bitcoin transactions, moving approximately 119,754 BTC out of the exchange’s wallets into a single outside wallet the affidavit calls Wallet 1CGA4s.

At the time of the breach that was worth approximately $71 million. By February 2022, when the complaint was filed, the same coins were worth over $4.5 billion.

Figure disagreement, printed. Coverage of this case routinely gives the 2016 value as $72 million. The affidavit says approximately $71 million. Where they differ, this article follows the affidavit.

The tracing chain

The complaint sets out the route the funds took in five steps. From Wallet 1CGA4s, where the coins sat dormant until January 2017. Then to accounts at AlphaBay, at the time one of the largest darknet markets. Then to seven interconnected accounts at a United States exchange, plus accounts at three others. Then to various unhosted wallets. Then to accounts at six further exchanges held by Lichtenstein and Morgan.

The affidavit also itemises the laundering techniques, and the list is a compact education in what serious effort looks like: accounts opened with fictitious identities; funds moved in a long series of small amounts rather than in large chunks, totalling thousands of transactions; computer programs used to automate those transactions; layering through exchanges and darknet markets so the trail breaks; chain hopping into anonymity-enhanced currencies; and United States business accounts used to make the activity look legitimate.

That went on for roughly five and a half years.

The Walmart gift card

The gift card is real and it is in the affidavit, at paragraph 47.

On or about 3 May 2020, a cluster of addresses tied to the defendants sent approximately 0.057 BTC to a business that sells prepaid gift cards for bitcoin. The vendor’s records showed the transaction bought a $500 gift card to Walmart. The purchasing account was registered with an email address hosted by a provider in Russia, and the purchase was made from an IP address resolving to a New York City cloud service provider. The cloud provider’s records showed the IP address was leased by an account in Lichtenstein’s name.

Read that again for what it is. It is an identity link. It connects a cluster of addresses to a named human being through two subpoenaed business records. It is one of many such links in a twenty-page document, and the affidavit gives it a paragraph and a chart.

It recovered nothing.

What actually recovered $3.6 billion

Paragraph 6, fifteen pages earlier:

On January 31, 2022, law enforcement gained access to Wallet 1CGA4s by decrypting a file saved to LICHTENSTEIN’s cloud storage account, which had been obtained pursuant to a search warrant. The file contained a list of 2,000 virtual currency addresses, along with corresponding private keys.

Blockchain analysis then confirmed that almost all of those addresses were directly linked to the hack. Between 31 January and 1 February 2022, the government moved the coins.

A warrant. A cloud account. A file. That is the whole recovery.

What each of them was convicted of

This matters and it is widely got wrong. Lichtenstein pleaded guilty to one count: money laundering conspiracy under 18 U.S.C. § 1956(h), with the offence ending 28 February 2022. He was sentenced on 14 November 2024 to 60 months, with credit for time served from 8 February 2022 and 36 months of supervised release. Judgment was entered 3 December 2024.

Morgan was sentenced to 18 months on counts two and three, running concurrently, with credit for the week she was held in February 2022. Judgment was entered 11 December 2024.

Neither was convicted of the 2016 breach. The conviction on the docket is for laundering the proceeds. Any account of this case that says Lichtenstein was convicted of hacking Bitfinex is describing something that did not happen in this court.

What I think happened

The gift card detail survives in retellings of the Bitfinex case because it is a better story than the truth, and better in a specific way: it flatters the reader.

In the gift card version, Ilya Lichtenstein and Heather Morgan ran a five-year laundering operation of real technical sophistication and were undone by a moment of stupidity. It has a shape. It has a punchline. It invites you to think that the difference between them and you is care, and that you would not have bought the gift card. Everything about it is comfortable.

The cloud storage version has no punchline. Lichtenstein and Morgan did almost everything else right and kept the private keys to roughly $4.5 billion of bitcoin stolen from Bitfinex in 2016 in a file, in an account, with a password. That is the detail the February 2022 seizure turned on, and the reason it does not circulate is that it does not flatter anybody. Most people reading this have key material somewhere similar. A screenshot in a photo library. A note in a password manager whose recovery email still points at a university address. A text file in a folder called crypto. The gift card is a story about them. The cloud file is a story about you.

The second thing the Bitfinex case settles, and I have not seen it put plainly anywhere, is what blockchain forensics actually does.

The tracing in the Lichtenstein and Morgan investigation is genuinely impressive. Five hops, thousands of transactions, chain hopping into privacy coins, fictitious identities, automated layering, and the analysts held the thread across five and a half years, from the 2016 Bitfinex hack to the February 2022 arrests, and came out the other side pointing at two named people in New York. That is the strongest advertisement for chain analysis in the public record.

And that tracing did not recover a single satoshi.

Tracing tells you where the money went and who moved it. It does not get it back. Getting the Bitfinex bitcoin back required the keys, and the keys came from a search warrant executed against a consumer cloud service. The blockchain half of the case identified Lichtenstein and Morgan. The boring half, the half that looks like every other financial investigation since the invention of the filing cabinet, is the half that produced the $3.6 billion the government seized in February 2022.

I would hold that thought against the way seizures get reported. When you read that authorities “seized” cryptocurrency, the interesting question is never how they traced it. It is how they came to control the keys. Sometimes it is a warrant on a cloud account, as here. Sometimes it is a defendant handing them over under threat of detention, which is what happened in the Helix case. Sometimes, as in that same case, they cannot get them at all and the coins simply leave.

The third thing is smaller and worth saying because the record in the Bitfinex case is unusually clear about it. The affidavit’s list of laundering techniques is the best short description I have read of what deliberate obfuscation involves. It is not one clever trick. It is six mundane ones applied consistently for years: false identities, small amounts, automation, layering, chain hopping, and a legitimate-looking business front. Every one of those is boring. The sophistication was in the persistence, not the ideas.

Which is also why the tidy morality of the gift card story is wrong on the facts. Lichtenstein and Morgan were not caught because they got sloppy for one afternoon. They were caught because a five-year laundering operation generates thousands of small contacts with the regulated financial system, and a subpoena to any one of them can name you. The gift card was simply the contact the affidavit chose to draw a chart of.

What would have changed the outcome

The Bitfinex case ends with no product attached, because the failure sits several steps upstream of anything a reader would buy.

What the case actually demonstrates is that where your key material lives determines who can reach it, and that the answer is usually broader than people think. A file in a cloud account is reachable by a search warrant. It is also reachable by anyone who compromises the account, and by anyone who can complete its password reset. Those are three different threat models sharing one weakness, and only one of them applies to a criminal.

Worth doing, in the next ten minutes rather than in principle:

  • List every place key material exists. Not where you think it should be. Where it is. Include photo libraries, note apps, password managers, email drafts, and anything you sent to yourself once to move it between devices.
  • Assume anything synced is reachable. If it reaches your phone automatically, it is on somebody else’s server, and the security of your coins is now the security of that account and its recovery path.
  • Check the recovery path, not the password. An account with a strong password and a recovery email you no longer control is a weak account. This is the failure people miss, because the password feels like the door.
  • Prefer material that cannot be copied at a distance. Something on paper or steel in a physical location has a narrower set of people who can reach it than something in an account, and the set is one you can actually name.

The related question of who is able to move assets, as opposed to who can reach the key material, is the subject of the Helix passphrase case, and the succession question of what happens when the person who knows is unavailable is covered in the QuadrigaCX record. Between them those three cases cover most of what goes wrong with keys, and none of it is exotic.

Sources

  • United States v. Ilya Lichtenstein and Heather Rhiannon Morgan, No. 1:22-mj-00022 (RMM) (D.D.C.). Sealed Complaint and Statement of Facts, ECF 1-1, filed 7 February 2022, 20 pages, Special Agent Christopher Janczewski. Statement of Facts, PDF · Docket
  • United States v. Lichtenstein, No. 1:23-cr-00239 (CKK) (D.D.C.). Judgment as to Lichtenstein, ECF 195, entered 3 December 2024. Judgment as to Morgan, ECF 198, entered 11 December 2024. Docket

Disclosure. Max Avery is affiliated with Digital Ascension Group (DAG). Investment advisory services are offered through DAG Wealth, an SEC-registered investment adviser (CRD No. 328627). Registration does not imply a certain level of skill or training. DAG is not a law firm and does not provide legal or tax advice. Custody arrangements with third-party independent qualified custodians reduce certain risks but do not eliminate them. Nothing here is investment, legal, or tax advice, or a recommendation to buy or sell any asset. This article describes matters of public record; charges are allegations and defendants are presumed innocent unless and until proven guilty.


More from the journal

Continue reading.