Early users lost substantial holdings to causes that are now addressed by standard practice, and the history explains why the practices exist.
Discarded storage
Keys held in files on ordinary computers, deleted or lost with hardware.
Which produced permanent losses that are documented and occasionally famous.
The absence of any recovery mechanism was not widely understood at the time.
Weak passphrases
Keys derived from memorable phrases chosen by people.
Which have far less entropy than assumed and were swept systematically by automated systems.
The practice was recommended in early guidance and was subsequently and comprehensively discredited.
Random number generation failures
Weak entropy sources producing predictable keys.
Which affected specific wallet implementations and platforms.
Funds in affected addresses were drained by anyone reproducing the flaw.
Exchange storage by default
Leaving assets on trading venues because it was easier.
Which produced losses at every major exchange failure.
The self-custody principle emerged directly from this experience.
The standardisation response
Deterministic wallets generating unlimited addresses from one backup.
Word-list encoded recovery phrases with checksums.
Which made backup practical and portable between implementations.
Hardware wallets
Dedicated devices keeping keys away from general-purpose computers.
Which addressed malware extraction specifically.
Screen verification on the device addressed the substituted-address attack.
What replaced the old failures
Phishing, malicious signature requests and approval abuse.
Which are now the dominant loss categories.
The technical failures were solved; the human ones were not.
The pattern across the history
Each generation of protection produced a new dominant attack targeting whatever remained unprotected.
Paper wallets
Keys printed and stored physically.
Which addressed digital compromise and introduced generation and handling risks.
Generating them on internet-connected computers or with online tools defeated the purpose entirely.
Backup redundancy
Single backups lost to fire, flood and misplacement.
Which led to metal backups and geographic distribution.
Split-secret schemes distributing shares with a recovery threshold address single-point loss.
Inheritance
Assets inaccessible after the holder's death.
Which accounts for a meaningful share of permanently lost holdings.
Arrangements exist and require deliberate setup that most people never do.
Testing recovery
Backups assumed to work and never verified.
Which fails at exactly the moment it is needed.
Restoring to a spare device before funding is the practice that catches this.
The current threat picture
Signature phishing, approval abuse and address substitution dominate reported losses now.
Standardisation of recovery phrases
A defined word list with checksum encoding.
Which made backups human-transcribable and portable between wallets.
This single standard removed an enormous category of error.
Derivation path standards
Conventions for how addresses are generated from a seed.
Which allow a phrase to be imported into different software.
Inconsistent early implementations produced the apparently-missing-funds problem that still occurs.
Passphrase features
An additional secret producing an entirely separate set of accounts.
Which provides deniability and creates an unrecoverable failure mode if forgotten.
It is not stored anywhere and cannot be recovered by any means.
Multi-signature for individuals
Arrangements removing single points of failure.
Which are increasingly accessible through consumer tooling.
The unchanged constant
The recovery phrase is the whole of the security, and everything else is a convenience around it.
The pattern across two decades
Each generation of security improvement closed one category of loss and left the next one exposed.
Software vulnerabilities gave way to malware, malware gave way to hardware wallets, and hardware wallets gave way to phishing and signature abuse.
The consistent element is that the remaining attack surface is always the human one.
What to do now
Record the wallet software, the derivation path and whether a passphrase is used, alongside the phrase itself.
Test recovery on a spare device before funding anything substantial.
Store backups where fire, flood and theft are all considered separately.
The persistent truth
Every generation of users learns this the same way, and it is entirely avoidable.
The one-line summary
The technical failures were solved by standards and hardware; the remaining losses are people approving things they did not read.
Institutional practice
Key ceremonies, multi-party control and tested recovery procedures.
Which developed in parallel with consumer practice and are considerably more rigorous.
Individuals can adopt scaled-down versions of the same controls.
The persistent gap
Most people still hold a single phrase, written once, never tested, in one location.
Which is precisely the arrangement that produced the losses this history describes.
A closing note
Two decades of standards, hardware and tooling have made key management genuinely solvable for anyone willing to spend an hour on it.
The losses that continue are overwhelmingly people signing things they did not read, which no amount of engineering addresses.
The hour worth spending
Record the software, path and passphrase status, test a recovery on a spare device, and store backups in two places that would not burn down together.
That is the whole of it, and most losses in this history came from skipping it.