Loading live prices…

Exchange Security Basics

What custodial holding means, what proof of reserves does and does not show, and the account practices that reduce your exposure — without naming or rating any venue.

Last updated: 2026-09-01

The core fact

An asset held on a custodial exchange is a claim on that exchange. The venue holds the keys; your balance is an entry in their ledger. That arrangement is not a flaw — it is what makes fast trading possible — but it means your access depends on the venue remaining solvent, operational and willing.

This is covered in depth in custody and exchange risk.

What to look for, and how to read it

Published security practices

Venues that take this seriously usually publish something concrete: cold storage policy, key management approach, third-party audits, penetration testing cadence, bug bounty programme. The presence of a page is not evidence; the specificity of it is.

Vague assurances — "bank-grade security", "military-grade encryption" — are marketing copy. They describe nothing checkable.

Incident history

A venue that has had an incident and published a full account of what happened, what was lost and what changed is telling you more than a venue with no public history. Look for the venue's own post-incident disclosures, not only news coverage.

Proof of reserves

An attestation that the venue controlled certain assets at a point in time. Useful, and frequently over-read.

Solvency is assets minus liabilities. An attestation covering only the asset side cannot establish it. Stronger implementations commit to the liability side using cryptographic techniques that let an individual customer verify their own balance is included in the total. Even then it is a snapshot, not a continuous guarantee.

Regulatory registrations

Registrations the venue itself publishes are checkable against the regulator's own register — and worth checking, because claimed registrations are sometimes for a different entity, a different jurisdiction, or a different activity than the one you are about to undertake.

Practices on your side

These reduce your exposure regardless of which venue you use:

  • Hardware or app-based two-factor authentication, not SMS. SIM-swap attacks are common and effective.
  • A withdrawal address allowlist, where supported.
  • A unique, long password stored in a password manager.
  • Keep on the venue only what you are actively trading.
  • Hardware wallet for longer-term holdings, with the recovery phrase on physical media — never a photo, never cloud storage, never email.
  • Test any new withdrawal route with a small amount first.
  • API keys, if you use them, scoped to the minimum permissions and never granted withdrawal rights.

The rule with no exceptions

No legitimate party ever needs your seed phrase or private key. Not support, not a wallet provider, not a regulator, not a recovery service.

Anyone who asks is attempting theft — including convincing websites, plausible support agents who contacted you first, and messages that arrive at exactly the moment you have a real problem. That timing is not coincidence; attackers monitor public support channels.

This site will never ask for a seed phrase, private key, exchange password or API trading key, and no tool here requires one.