Poolin's Bankruptcy: The $173M Lesson in Custodial Mining Pool Failure
When a mining pool that once commanded 14% of Bitcoin's hashrate files for Chapter 11, the market shrugs. That shrug conceals a fundamental truth about the economics of trust. On July 22, 2025, Poolin’s holding company Lonestar Dream Inc. and subsidiary Taproot Inc. entered bankruptcy protection in New Jersey. The petition revealed a debt structure that functioned less like a balance sheet and more like a Ponzi contract with a missing return statement. Total liabilities: $173 million. Unsecured customer IOU tokens: $163.7 million. Asset sale proceeds from two Texas mining facilities: $52 million. The math is brutal: a recovery ratio of 0.3:1 before legal fees, and the trend only worsens.
Context is critical. Poolin was once a titan of Bitcoin mining infrastructure. At its peak in 2019, it commanded 14% of global hashrate, operating a mining pool and a custodial wallet product. Users could deposit BTC, ETH, and other assets into Poolin Wallet, earning mining rewards or simply storing funds. Then the 2022 bear market hit. Bitcoin dropped below $20,000. Poolin, like many overleveraged miners, had borrowed heavily. It owed Antalpha (a Bitmain affiliate) $213 million, secured against mining equipment and customer assets. By late 2022, Poolin froze all withdrawals. To placate users, it issued IOU tokens—pBTC, pETH, etc.—essentially promissory notes redeemable only if the company recovered. Recovery never came.
The Texas expansion was the final straw. Poolin had secured power capacity for 600 MW across two sites in Pyote and Tarbush. Actual operational capacity: 100 MW. The gap was due to the Chinese mining ban and underestimated grid constraints. The failed expansion bloated debt without producing revenue. From 2023 to 2025, the company reported $8.8 million in losses, accumulating $45.9 million in total deficits. By early 2025, it had stopped all mining operations. The only remaining asset of value was the partially developed Texas land and power infrastructure.
Here is where the technical analysis begins. The IOU tokens issued to 11,700 wallet users are not a novel DeFi primitive; they are a distress signal. Each pBTC and pETH token represents an unsecured claim against a pool that had already been drained by operational losses. The asset-liability mismatch is not just a financial failure—it is a protocol failure. A custodial wallet with no proof-of-reserves, no on-chain verification, and no escape hatch for users is a smart contract with a single, unaccountable administrator. In my 2021 audit of Lido’s stETH-Aave composability, I identified a similar centralization vector: when a single entity controls both staking operations and derivative issuance, the risk of misappropriation becomes structural, not stochastic. Poolin’s case is identical. The mining pool and the wallet shared the same balance sheet. User deposits were fungible with operating capital. When Antalpha demanded repayment, Poolin transferred collateral from the collective pool, not from segregated accounts. That is not a bug; it is an architectural assumption that trust is infinite.
Code is law, but bugs are reality. The IOU token mechanism itself is a perfect example of debt tokenization—a concept that sounds sophisticated until you realize its only function is to delay insolvency. Unlike collateralized debt positions (CDPs) on MakerDAO, these IOUs have no liquidation mechanism, no price oracle, and no overcollateralization ratio. They are simply is a promise written in a smart contract that anyone can deploy, but that only the issuer can resolve. And when the issuer becomes insolvent, the token becomes a zombie. I spent four months during the 2022 bear market implementing a Rust-based groth16 prover. That work taught me something fundamental about cryptographic promises: zero-knowledge isn’t mathematics wearing a mask; it’s a proof of state. Poolin’s IOUs offered no proof of state. They were a black box where the only verification was the trust that the CEO would do the right thing. That trust turned out to be a single point of failure.
Now for the contrarian angle. The market narrative frames Poolin’s collapse as another casualty of the crypto winter—a predictable outcome of falling BTC prices and rising energy costs. That narrative is convenient, but it misses the real blind spot. The failure is not macroeconomic; it is structural. Poolin’s architecture lacked orthogonality between custody and operations. Every mining pool that offers a custodial wallet with co-mingled funds inherits this vulnerability. The proof-of-reserves trend that emerged after FTX has not yet penetrated the mining industry. Most pools still operate on a trust model: users send hash to the pool, the pool credits balances, and only periodic audits (often unaudited) confirm solvency. But as I saw in my analysis of Celestia’s Data Availability Sampling, trustless verification requires redundant sampling. A single audit every quarter is not redundancy; it is theater. Poolin’s books were never independently verified on-chain. The result is a $163.7 million hole that creditors are now trying to fill with $52 million of real estate.
The asset sale itself reveals another blind spot. The stalking horse bidder, Thor CALAP LLC, is paying for facilities that originally cost tens of millions to develop. The buyer is reported to be an AI/HPC operator, not a mining firm. This signals a fundamental shift: mining-grade power infrastructure is now being repurposed for AI compute. Poolin’s Texas assets may be worth more to an AI hyperscaler than to another miner. That is a market signal that the mining industry itself is commoditizing its own resource. The mining pool business model, based on selling hashrate, is being replaced by a model of selling power contracts. But that transition is irrelevant to Poolin’s 10,001 to 25,000 creditors, who will likely see recovery rates below 15%. In my experience auditing the zkEVM trusted setup, I learned that the difference between a theoretical maximum and practical reality is often several orders of magnitude. Here, the theoretical recovery is 30% based on asset value; the practical recovery will be cut by legal fees, administrative costs, and the seniority of secured creditors like Antalpha.
The takeaway is not about Poolin specifically. It is about the vulnerability of centralized mining infrastructure. Every mining pool that operates a custodial wallet without transparent, auditable on-chain reserves is a ticking smart contract with a single administrator key. The next bear market will flush out more such entities. The solution is not regulation; it is protocol design. Mining pools should implement non-custodial payout mechanisms, on-chain proof-of-reserves, and decentralized governance of pooled funds. Until then, the market should treat every IOU token as a speculative debt instrument, not a stable claim on hashrate. Protocols don’t die; they are murdered by debt. And the biggest bug in Poolin’s code was its accounting.