The story of Cryptopia, a New Zealand-based cryptocurrency exchange, serves as a stark and protracted warning to the global crypto-interested public. What began as an enthusiast’s project evolved into a massive international trading platform, only to collapse dramatically following a catastrophic hack in January 2019. The exchange’s downfall was not merely a theft of digital funds; it became a multi-year legal saga that defined cryptocurrency as legal property and exposed critical failures in security, regulation, and centralized asset custody. After nearly six years, the eventual partial return of funds to victims in late 2024 underscored the complex and arduous process of digital asset recovery.
CASE SUMMARY: The Rise and Catastrophic Fall of a New Zealand Crypto Giant
Founded in Christchurch, New Zealand, in 2014 by software developers Rob Dawson and Adam Clark, Cryptopia began as a hobby inspired by the negative experiences the founders had on other exchanges. By late 2016, the project became serious enough for the founders to quit their jobs and fully invest their savings. Cryptopia rapidly ascended in prominence, becoming one of the earliest cryptocurrency services in New Zealand. In May 2017, the exchange launched the first stablecoin pegged to the New Zealand dollar, known as NZDT (or NZed token), cementing its pioneering role in the country’s crypto ecosystem.
Cryptopia experienced substantial, even dizzying, growth in 2017. The user base exploded from 30,000 to over 1.4 million by early 2018. At its peak in the late 2010s, Cryptopia was recognized as one of the top 100 cryptocurrency exchanges globally by trading volume. Its trading activity reportedly even outpaced the trade volume of the New Zealand Stock Exchange, with the platform listing up to 900 currencies. At its peak, the exchange employed 100 individuals, including contractors.
However, this rapid expansion masked serious internal vulnerabilities. In January 2019, Cryptopia became the target of a high-profile theft that resulted in the loss of approximately 10% of its cryptocurrency assets. At the time it was taken, the stolen amount was estimated by blockchain infrastructure firm Elementus to be around NZ$24 million (later reported as $16 million USD covering Ethereum and ERC-20 tokens).
Following the devastating security breach, public confidence in the exchange was severely damaged, leading to a substantial drop in trading activity. Despite continuing operations for a few months, Cryptopia ultimately entered formal liquidation in May 2019.
SCAM MECHANISM : The Five-Day Theft and the Crisis of the Centralized Ledger

The catastrophic theft began on January 14, 2019, when a staff member noticed suspicious activity in the company’s hot wallet, signaling that a private key had been compromised. The platform was immediately shut down and placed into maintenance mode. However, the initial shutdown was not enough to stop the bleeding. In the weeks following the initial breach, the theft shockingly continued, with a substantial amount of Ethereum and other ERC-20 tokens being systematically siphoned from 17,000 user accounts.
Analysis conducted by Elementus found that the attackers moved over $16 million worth of Ethereum tokens over a span of five days. Even more concerning, Elementus noted that the hacking continued until January 17, days after police began investigating the incident, apparently happening “right under the authorities’ noses”. This protracted and seemingly calm extraction of funds, unlike typical high-speed digital heists, raised immediate security and technical questions.
The mechanism of the fraud strongly suggested severe security breaches relating to key management. Unlike hacks targeting a smart contract vulnerability, this attack directly compromised more than 76,000 user wallets by obtaining thousands of private user keys from Cryptopia. Elementus suggested this indicated either a “catastrophic and unprecedented security breach” rendering the exchange unable to intervene or that the attack was executed “with inside knowledge”.
The theory of internal sabotage was supported by both co-founders, Rob Dawson and Adam Clark. Clark argued the perpetrator appeared to “know where everything is” and deleted logs. Dawson noted the way the coins were moved was “amateurish,” suggesting the intent might have been to harm the company rather than execute a clean, untraceable theft. This theory was further fueled by the toxic internal atmosphere that had plagued the company in the months leading up to the breach. While some cryptocurrency commentators initially alleged that the incident might have been an exit scam, citing the movement of millions in Ethereum prior to the hack, subsequent investigations by police and the High Tech Crime Unit did not substantiate these wider claims. The FBI, working with New Zealand police, also became involved in the investigation, suggesting the incident had an international dimension.

WARNING SIGNS (RED FLAGS): Pre-Hack Instability and Oversight Gaps
Cryptopia’s sudden collapse, while triggered by the hack, was preceded by significant internal and operational instability—a crucial red flag for potential investors.
Management Turmoil and Internal Friction: By early 2018, the exchange’s rapid growth began to cause severe issues, resulting in internal friction among management, resignations, and a publicly alleged toxic workplace culture. Co-founder Adam Clark resigned in February 2018 due to burnout and a deteriorating relationship with co-founder Rob Dawson. Later that year, Dawson himself resigned after feeling forced out by the incoming CEO, Alan Booth, only to return after negotiating Booth out of the company. This instability hinted at a company prioritizing expansion over operational cohesion.
Operational Strain and Capacity Issues: Cryptopia was unable to handle the influx of new trades, forcing the temporary suspension of new account creation and the freezing of trading in assets like Dogecoin and Litecoin. Users complained, and some threatened class action lawsuits, prompting the then-CEO to defend the company. These technical and capacity failures, cited alongside security concerns, should have signaled fundamental architectural weakness.
Regulatory and Banking Caution: The failure of Cryptopia’s NZDT stablecoin project provided an early indication of external regulatory pushback. ASB Bank closed the accounts associated with NZDT due to concerns about regulatory compliance and an inability to verify account identity and activity, forcing customers to withdraw their funds.
Lack of Security Controls and Accountability: The core structural flaw that magnified the hack’s impact was Cryptopia’s failure to segregate client funds properly. While Cryptopia kept track of user ownership via a central, internal ledger, it did not confirm individual ownership on the blockchain, pooling balances in large wallets. This made reconciliation exceptionally difficult post-hack. Furthermore, an employee who later committed unrelated theft in 2020 claimed they had raised security concerns with management between 2018 and 2019. The failure to adhere to basic cybersecurity standards, data protection, and internal controls exposed users to systemic risk, highlighting a significant “lack of proactive security regulation or enforcement”.
CONSEQUENCES & LEGAL STATUS: Defining Digital Property and the Long Road to Restitution

The consequences of the Cryptopia hack were immediate and long-lasting. The company entered liquidation in May 2019, owing NZ$4.2 million to creditors in addition to the stolen crypto assets. The liquidation process, handled by Grant Thornton, has spanned several years and cost millions due to the complexity of international cryptocurrency law. Cryptopia also sought bankruptcy protection in the U.S. under Chapter 15, underscoring the difficulties of coordinating crypto insolvencies across different jurisdictions.
The defining legal outcome was the Ruscoe v. Cryptopia case. In 2020, the New Zealand High Court delivered a landmark ruling, holding that cryptocurrency is a digital asset and a form of property capable of being held in a trust. This decision was pivotal in a Commonwealth country, classifying the customer’s crypto holdings as intangible property held by Cryptopia as a trustee, granting account holders a stronger legal claim and priority over unsecured general corporate creditors during the liquidation process.
Despite this legal clarity, the recovery faced immense practical hurdles. Grant Thornton was forced to reconcile the accounts of approximately 900,000 former users manually. This manual reconciliation was necessary because Cryptopia’s internal records were inconsistent with actual on-chain balances, and the commingling of user funds in large wallets made determining individual ownership using only the wallet keys impossible. Liquidators also had to meet strict legal requirements, including Anti-Money Laundering/Know Your Client (AML/KYC) checks, before assets could be returned.
After years of legal battles, asset tracing (including recovery actions filed in Singapore, Malaysia, and the U.S.), and reconciliation efforts, the first wave of distributions finally began in December 2024. Approximately NZ$400 million (equivalent to about $225 million USD) worth of Dogecoin and Bitcoin was refunded to over 10,000 verified account holders. Many recipients reportedly received 85–90% of their holdings valued at the time of the 2019 hack. Liquidators are planning future “top-up” phases, utilizing funds from accounts where customers have failed to register or complete their claims, potentially allowing verified users to recover up to 100% of their lost holdings.
The complexity of the recovery was further evidenced by secondary issues, such as a former employee stealing Bitcoin in an unrelated incident in 2020 by misusing private keys, and a controversial attempt by a businessman to launch a class action, which resulted in a massive data leak of 900,000 account holders’ details. Cryptopia’s downfall remains a powerful example of the difficulties of handling large-scale cryptocurrency recovery and the weaknesses inherent in centralized platforms.
WRITER’S COMMENTARY: Assessing Failure and Forging a Safer Future
The failure of Cryptopia was not a single event but the predictable result of exponential growth outpacing corporate governance and technical capacity. The core cause assessment reveals that the scam succeeded primarily due to a lethal combination of lax internal security protocols and the dangerous practice of commingling customer assets. Cryptopia was a large but technologically messy operation. The inability to maintain an accurate, auditable, and segregated record of client holdings on the blockchain meant that once the perimeter was breached and private keys compromised, the entire pool of assets became vulnerable to methodical, multi-day extraction. The systemic failure was rooted in treating volatile customer digital assets with the bookkeeping standards of a traditional startup rather than the stringent security required of a major financial custodian. This lack of segregation transformed a security breach into a full-scale insolvency and a multi-year legal disaster.
To prevent future catastrophes of this magnitude and protect the general crypto-interested public, sharp regulatory and technological improvements are necessary:
- Mandatory Asset Segregation and Proof-of-Reserve Audits: Regulation must mandate that centralized exchanges (CEXs) treat customer assets as trust property (building upon the Ruscoe ruling) and require assets to be verifiably segregated on-chain, eliminating the reliance on internal, non-auditable ledgers. Furthermore, independent, frequent, and verifiable Proof-of-Reserve audits must be legally enforced to ensure 1:1 asset backing.
- Harmonized Cross-Border Insolvency Frameworks: Since crypto exchanges inherently operate globally, the drawn-out and costly multi-jurisdictional legal process (New Zealand liquidation, US Chapter 15 protection) highlights the urgent need for international regulatory alignment on handling digital asset insolvency. A unified framework would significantly reduce liquidation costs—which exceeded $20 million in Cryptopia’s case before distributions began—and accelerate compensation.
- Mandatory Security Minimums and Key Management Certification: Exchanges should be required to obtain certification demonstrating adherence to rigorous, standardized security best practices, particularly concerning hot wallet limits, cold storage practices, and private key management. The fact that an insider alleged security concerns were ignored before the hack underscores the need for regulatory enforcement mechanisms beyond mere self-reporting.
Cryptopia’s legacy is a cautionary blueprint: a testament to the risks of entrusting highly volatile, digitally liquid assets to centralized custodians operating outside robust, harmonized financial oversight. The subsequent legal struggle to define cryptocurrency as property, while ultimately beneficial for victims, reveals the institutional unpreparedness that allowed the exchange to run aground in the first place. The return of funds is a silver lining, but the years of waiting serve as a perpetual reminder that in the decentralized world, absolute security often relies on holding your own keys—or, failing that, ensuring that any centralized platform is regulated with the rigor demanded by the stakes involved.
REFERENCES
- Cryptopia liquidator forced to reconcile 900,000 customer data manually
- Cryptopia funds still being drained by hackers while police investigated
- New Zealand Exchange Cryptopia Lost $16 Million in Hack, Not Initially Reported $2.5 Million: Research
- Cryptopia Reviews & News: Investors Can Trace Their Lost Funds (Update Released)
- Cryptopia Users Finally Receive Payouts Years After Devastating Hack
- Cryptopia Hack: Liquidators Distribute $225 Million in Crypto to Victims
- NZ Police issues update on suspicious Cryptopia hack, says “significant amount” stolen