101 · Foundations · lesson 3 of 4

How people actually lose Bitcoin

Before you decide how to protect your Bitcoin, it helps to know what you’re protecting it from. Here’s the honest surprise: most Bitcoin that’s been lost was never stolen by a hacker. It was forgotten, misplaced, or fumbled by its own owner.

The short version

Almost none of the Bitcoin that’s ever been lost was taken by breaking anyone’s security. Over 80% of what gets called “theft” is really a scam or a simple slip — and it’s avoidable. Learn the handful of ways it happens below and you sidestep nearly all of it.

You may have heard that somewhere between 11% and 23% of all Bitcoin is lost forever. The figure is real — but it traces back to Bitcoin’s earliest years: coins worth pennies, held by people who had no idea they’d ever matter, lost to reformatted drives and forgotten passwords. It’s a one-time artifact of that era, not a “one in six of today’s coins are doomed” risk hanging over you now. The single biggest thing separating you from those early losses is simple: you already know what you’re holding. So read the list below not as what’s likely to happen to you, but as the short, knowable set of things to design around.

One idea that ties it all together

There are really only two ways to lose Bitcoin: you can’t get to it (you lost the keys), or someone else can (someone got the keys). The tricky part — and the reason there’s no single “just do this” answer — is that almost every defence against one of those makes the other worse.

Add a secret passphrase to stop a thief, and you’ve added a new way to lock yourself out. Spread your backup across three cities to survive a fire, and you’ve made it harder for you to put it back together. That trade-off is why the next level builds your setup as a ladder — you climb only as far as your real risks require, and no further.

  1. 01

    You lose access to it yourself

    The single most common way. No thief involved — the coins are still there on the blockchain, but you can no longer prove they’re yours. This is where most lost Bitcoin has gone.

    • You never made a backup — or made only one. Your recovery words live in one place, and that place is fragile. A house fire, a flood, a hard drive that dies, ink that fades, or a “safe spot” that gets thrown out during a move or a renovation — and the money is gone with it.
    • “I’ll just remember it.” People memorise a passphrase or invent a clever secret scheme instead of writing it down. Years later the memory has drifted, and nothing they try unlocks the wallet. A secret you can’t reproduce under stress is not a backup.
    • You never tested the backup. A word gets mis-copied when writing it down. You don’t find out until the day you actually need it — and by then it’s too late. A backup you haven’t restored from is a hope, not a backup.
    • You die without leaving a plan. Your family finds a metal plate or a hardware wallet and has no idea what it is or how to use it — so they bin it. The most common version: a hidden passphrase nobody knew about, so heirs restore the words, see an empty wallet, and assume there was nothing there.
    How this guide defends it

    Back up your words on metal, keep a second copy somewhere else, test the restore before you fund it, and leave a plan your family can follow.

    Three lessons take this apart: Backing up a seed phrase and Testing a backup in 103 · Private key creation, then Why Bitcoin doesn’t inherit like money in 104 · The long haul.

  2. 02

    Someone takes it remotely

    A stranger, over the internet, who never touches you or your home. The good news: this almost always requires you to be tricked into helping — so a few simple habits shut most of it down.

    • Phishing and fake “support.” By far the number-one real-world attack. You get an urgent email or text — “suspicious activity,” “verify your account” — that looks exactly like your exchange or wallet company. It sends you to a fake site that steals your words. The rule that beats it: no real company ever contacts you asking for your recovery words. Ever.
    • Address-swapping malware. A virus on your computer silently swaps the payment address you copied for the attacker’s, so your Bitcoin flies off to a stranger. The defence is simple: always check the address on the hardware wallet’s own little screen — that screen can’t be faked by your computer.
    • Fake wallet apps. A phoney app pretending to be a real wallet, sitting in an app store, waiting for you to type your recovery words in to “restore” — and then it steals them. Only ever download wallet software from the maker’s official website.
    • The seed you typed or photographed. The moment your recovery words touch an internet-connected device — a photo that auto-uploads to the cloud, words typed into a phone — they can leak, sometimes years later when that cloud account is breached. Keep the words off anything digital, full stop.
    How this guide defends it

    Never type or photograph your recovery words. Verify every address on the hardware wallet’s screen. Assume any “support” message that wants your words is a scam.

    The scams themselves get a whole lesson — Phishing and everyday safety, in 104 · The long haul. The address check is Sending Bitcoin safely, in 103 · Private key creation.

  3. 03

    Someone takes it physically

    A person in the real world — a burglar, or someone who threatens you in person. Rare, but rising fast, and it works differently than people expect: attackers don’t break the math, they go around it.

    • A found backup. A burglar doesn’t need to “hack” anything if they find your recovery words in a drawer, or your hardware wallet and its passphrase sitting on the same shelf.
    • The “$5 wrench.” The blunt truth: cryptography can’t protect you from someone willing to threaten you until you hand it over. If they know you hold Bitcoin and can reach you, the strong encryption doesn’t matter.
    • Being picked as a target. These attacks are almost never random. It usually starts with a data leak — an exchange gets breached and your name and home address end up on a list — which gets cross-referenced with anything you’ve posted publicly about holding Bitcoin. That’s the pipeline: leak → list → your door.
    How this guide defends it

    The best physical protection isn’t a gadget, it’s a habit: talk about Bitcoin as loudly as you like — never about your Bitcoin. Don’t attach your own name to the fact that you hold and self-custody it, and never attach a number. That includes the people you trust, because they have people they trust too.

    Beyond the habit, the defence is structural: keep backups out of obvious places, and arrange your keys so that no single location — and no single confrontation — holds enough to hand over everything. The setups that make that real, and the backup warning that comes with them, are taught in the lessons named below.

    The habits that keep you off the list are Privacy / OpSec, in 104 · The long haul. The decoy setup itself is a rung on the ladder, in 102 · Wallet configuration.

  4. 04

    You trusted someone else to hold it

    You left your Bitcoin on an exchange or with a company, and that company failed, froze your account, or was hacked. If you don’t hold the keys, you don’t really hold the coins — you hold an IOU.

    • The company goes bankrupt or runs off with it. This is not hypothetical — it’s Bitcoin’s most repeated disaster. Mt. Gox lost about 850,000 coins in 2014. FTX vaporised roughly $8 billion of customer money in 2022. The list of collapsed exchanges is long, and it keeps getting longer.
    • Your account gets frozen. Even a healthy exchange can lock your withdrawals — during a hack, a legal order, or a “review” — and there’s nothing you can do but wait, sometimes forever.
    How this guide defends it

    Move your Bitcoin off the exchange and into your own custody after you buy — that single step is what this whole guide is about. Choosing a buying service you don’t have to live on, and the habit of withdrawing early, are part of the same lesson.

    The very next lesson — Not your keys, not your coins — is this one in full.

  5. 05

    You make a simple send mistake

    A fumble during a transaction. Bitcoin payments can’t be reversed once they go through, so a slip here is permanent — but a couple of habits make it very hard to get wrong.

    • You send to the wrong address. Good news: modern Bitcoin addresses (the ones starting with “bc1”) have a built-in error check that catches almost any typo before it can send. The real risk is malware swapping the address — which is why you verify it on the hardware wallet’s screen — and not doing a test run first.
    • You send more than you meant to. Rushing, tired, or being pressured is when the expensive mistakes happen. There’s no undo button. For anything substantial, slow down — a wallet operation done in a panic is where people lose the most.
    • You send it over the “wrong network.” Some exchanges and apps let you send “Bitcoin” out as a look-alike copy on another blockchain, or ask you to pick a “network” before you withdraw. Choose the wrong one and your coins land somewhere your normal wallet can’t see. The fix is simple: only ever send real, native Bitcoin, and at any network menu choose “Bitcoin.”
    How this guide defends it

    Verify the address on the hardware wallet’s screen, send a tiny test amount first, confirm it arrives, then send the rest — and never do it in a hurry. When withdrawing, make sure you’re sending real Bitcoin on the Bitcoin network.

    All of it lands in one lesson: Sending Bitcoin safely, in 103 · Private key creation.

The one habit that helps against almost everything

Most defences trade one risk for another — but testing your recovery is the rare win-win. Wipe your wallet and restore it from your written words with a tiny amount, before you trust it with savings. You catch a broken backup while it’s still harmless, and you’ll never have to improvise a recovery in a panic. Testing a backup, in 103 · Private key creation, walks the whole rehearsal.

And you don’t need to defend against all five equally. Which of them are really yours depends on how much is at stake, and on how and where you hold it — which is what 102 · Wallet configuration works out.

Check yourself

2 questions on what this lesson just covered. Nothing is scored, recorded or saved — it isn’t sent anywhere and it’s gone when you close the tab.

1Which of these leaves no single failure able to take everything?

2Of all the Bitcoin that has been lost so far, what accounts for the largest share?

You've learned it — here's where the doing lives

That's the concept: the five ways Bitcoin is actually lost, and which defence answers each one. This is the course, and the course teaches — it doesn't set anything up for you. When you want that weighed against your own situation rather than the average holder's, the setup finder walks five plain questions and a short risk assessment — starting from the same base rates this lesson just taught — and names the setup that covers what is actually yours. It's in the Your setup menu, under Find your setup, whenever you want it.

Last verified: August 4, 2026