In June 2018, a tech millionaire named John McAfee put his name on a $120 hardware wallet, called it “the world’s first un-hackable storage for cryptocurrency & digital assets,” and backed the claim with a bounty that grew to $250,000 for anyone who could prove him wrong. A fifteen-year-old broke it playing a video game. That part is almost funny. What it accidentally proves is not: last year, $3.4 billion was stolen from crypto — including about $8,900, on average, taken from each of roughly 80,000 individual people — and not one dollar of it came from Bitcoin itself failing.
Underwriting mortgages for most of two decades taught me to be suspicious of one word: “guaranteed.” Somebody is always the one doing the guaranteeing, and that somebody can have a bad day, a careless employee, or a line of bad code. So when a product’s box says “unhackable,” my first question isn’t excitement, it’s: who’s promising that, and what happens to my money if they’re wrong? In 2018, the answer showed up in about six weeks.
The $250,000 bet John McAfee lost
The device was the Bitfi — a stripped-down Android phone, $120 at launch, built mainly to hold Bitcoin and marketed as impossible to breach. McAfee, its executive chairman, backed that claim with a bounty: $100,000 at first, raised to $250,000 once the smaller number failed to draw serious researchers.
It took a fifteen-year-old researcher named Saleem Rashid about six weeks to get root access to the device and get it running a video game — proof the “secure” hardware wasn’t secure at all. McAfee argued the goalposts instead of conceding: playing a game on it wasn’t a hack, he said, because nobody had taken any coins yet. Weeks later, a British security firm did exactly that — intercepted the connection between the device and its dashboard and pulled a user’s secret recovery words straight off it, meeting the company’s own published bounty conditions.
The security world gave Bitfi an award for that response — “Lamest Vendor Response,” handed out the same week at the same Las Vegas conference where the hack was presented. It’s a punchline. The number underneath it is not.
$1.7 billion, then $3.4 billion
The year Bitfi launched, $1.7 billion was stolen across the entire crypto industry — tracked by the blockchain-forensics firm CipherTrace, roughly triple what was stolen the year before. Last year, that number was $3.4 billion, according to Chainalysis. Nearly half of it — about $1.5 billion — came out of a single exchange, Bybit, hacked in February. Another $713 million came from roughly 80,000 individual people’s own wallets: phishing links, fake apps, cloned websites. Real savings, gone one person at a time.
Here’s the sentence that’s easy to lose inside numbers that large: every one of those thefts happened to an exchange, a company, an app, or a person’s device. Not one of them happened to the Bitcoin ledger itself — the actual public record of who owns which coin. Nobody has ever hacked that. What keeps getting hacked, year after year, is whatever stands between a person and it.
The mailbox isn’t the post office
Picture it this way. The postal system — the trucks, the sorting, the rule that a letter with the right address gets delivered — is one thing. Your mailbox at the end of your driveway is a completely different thing, bolted on by a different company, and it can be pried open by anyone with a crowbar and ten quiet minutes. When a mailbox gets robbed, nobody says the postal system is broken. They say somebody needed a better mailbox, or a locked one.
Every crypto theft on record is a mailbox story. Bitfi was a mailbox. Bybit was a mailbox — a very large one, run by professionals, robbed anyway. The 80,000 individual wallets drained last year were mailboxes too, opened one at a time. The Bitcoin ledger — the actual record of who owns what, running since January 2009 — has never once had a coin moved off it without the real key. Sixteen years, constantly attacked, in public, for money.
There’s exactly one honest exception, and leaving it out would be dishonest. In August 2010, a flaw in the software let someone create 184 billion Bitcoin out of nothing in a single transaction — a bug, not a theft. It was caught, patched, and reversed within hours. Nobody who exploited it kept a coin. In sixteen years of Bitcoin being a public, constantly-attacked financial ledger, that is the one crack anyone has ever found in the post office itself. Everything else — all $3.4 billion of it last year — was a mailbox.
Every mailbox has an owner. The post office doesn’t.
This is where it stops being a story about hackers and starts being a story about everything you own. A hardware wallet has a manufacturer who can ship bad firmware. An exchange has a company that can get robbed, freeze your account, or go bankrupt with your coins still on its books — ask anyone who had money on Mt. Gox in 2014 (roughly 850,000 Bitcoin, most of it never recovered) or FTX in 2022 (more than a million customers still waiting in bankruptcy court). A Bitcoin ETF has one custodian holding the actual coins on your behalf, and you cannot call them and ask for your coins back — you own a line on a brokerage statement, not a key.
Widen the lens further and the same shape shows up in everything they’re building right now. A tokenized bond has an issuer. A tokenized house has a registry and a clerk. A stablecoin has a company that can freeze your balance. A future digital dollar has a central bank that decides what you’re allowed to do with it. Every one of those is a mailbox with somebody’s name on it — a person or an institution who can be hacked, sued, subpoenaed, or simply make a mistake at two in the morning. Bitcoin, the protocol itself, is the only thing being built into that future with nobody’s name on the box at all.
The door out
Twenty-one million Bitcoin will ever exist. More than 94% are already mined, and the count isn’t kept by a company you have to take on faith — anyone running the software can verify the current supply themselves, in about ten seconds, for free. No CEO to pressure. No emergency board meeting. No firmware update that quietly changes the rules. That’s not a marketing claim. It’s arithmetic every computer on the network checks independently, roughly every ten minutes, whether anyone’s watching or not.
Probability, never prophecy: none of this means Bitcoin can’t fall hard, or that holding it yourself makes you smarter than the people who lost money at Bybit, Bitfi, or Mt. Gox. Self-custody done carelessly is its own way to lose everything — a lost seed phrase is exactly as final as a hacked exchange. What eight years of theft statistics actually show is narrower than a prediction: the failures keep happening to the boxes, never to the post office. That’s a fact you can check yourself tonight, not a story you have to take on faith.
Watch the full breakdown — the bounty, the six weeks, and what $3.4 billion actually proves, on camera.
Watch: Bitcoin vs. Everything Else — Why Only One Asset Has No ‘Man’ Behind It →
See the live Bitcoin, gold and dollar numbers on the same free screen used in this piece. No card, two minutes.
The invitation, never the shove. Nobody needs to take my word for any of this — the CipherTrace and Chainalysis numbers are public, the Bitfi story is public, and the Bitcoin ledger itself is public, twenty-four hours a day, to anyone who wants to check it. That’s the whole difference between an asset with a man behind it and one without: one asks you to trust the box. The other lets you verify the post office yourself.
Sources: TechCrunch, “A hacker says he can break Bitfi’s ‘unhackable’ crypto wallet — and the company won’t pay up” (Aug 14, 2018); Tom’s Hardware, coverage of the Bitfi bounty program (2018); Yahoo/CCN, Bitfi launch and bounty reporting (2018); The Register, Pwnie Awards 2018 “Lamest Vendor Response”; CipherTrace 2018 Cryptocurrency Anti-Money Laundering Report via CNBC (Jan 29, 2019); Chainalysis 2025 Crypto Crime Update via The Block; Bitcoin value-overflow incident, Aug 15, 2010 (CVE-2010-5139); Mt. Gox and FTX bankruptcy proceedings. Tim Talks Finance, “Bitcoin vs. Everything Else: Why Only One Asset Has No ‘Man’ Behind It.” Educational content only, not financial advice. Bitcoin is volatile and can lose some or all of its value; self-custody carries its own risks, including permanent loss from a lost seed phrase. Do your own research and consult a qualified professional before making any decision. One coin only: Bitcoin, the protocol.
Keep going: Bitcoin Self-Custody Explained · Bitcoin ETF Fees Explained · Free Macro Command Center