Trading venues were robbed repeatedly in early periods, and the practices that emerged in response are now standard.

The early state

Keys held on internet-connected servers, frequently by small teams without security expertise.

Which produced repeated large thefts.

Several venues failed entirely following a single incident.

Cold storage adoption

Holding the majority of assets offline.

Which addressed remote compromise directly.

Ratios between hot and cold storage became a stated policy at serious venues.

Multi-signature arrangements

Requiring multiple keys held by different people in different places.

Which removed the single point of compromise.

Geographic and organisational separation of signers became standard practice.

Withdrawal controls

Allowlisted addresses, delays on new destinations and approval workflows.

Which limit the damage from account compromise.

These are offered to customers and enabled by a minority of them.

Insider risk

Several incidents involved employees rather than external attackers.

Which is why separation of duties and access review matter.

No individual should be able to move funds alone, which is a design requirement.

Insurance

Cover for held assets with defined limits and exclusions.

Which is generally well below total holdings.

Exclusions for client credential compromise are standard.

Proof of reserves

Demonstrating holdings publicly.

Which addresses solvency doubt rather than theft.

Adoption accelerated sharply following a major failure.

Regulatory requirements

Segregation, custody standards and independent assurance are now mandated in several jurisdictions.

Which converted good practice into requirement.

The remaining exposure

Customer-side compromise, which venue security cannot address and which now accounts for a large share of losses.

Hot wallet limits

Caps on how much is held online at any time.

Which bounds the maximum loss from a remote compromise.

Automated replenishment from cold storage with approval controls is standard practice.

Address whitelisting for customers

Restricting withdrawals to pre-approved destinations with a delay on additions.

Which substantially limits account takeover damage.

It is offered widely and used sparingly.

Authentication

Hardware security keys resist phishing where code-based methods do not.

Which matters because phishing dominates account compromise.

Number porting attacks defeated message-based codes repeatedly.

Bug bounty programmes

Venues offering payment for vulnerability disclosure.

Which has identified genuine issues before exploitation.

Payout scale relative to potential exploitation value determines effectiveness.

What customers control

Withdrawal to self-custody, hardware authentication and whitelisted addresses.

Penetration testing and audits

Independent assessment of systems and controls.

Which is standard at regulated venues and variable elsewhere.

Assurance reports covering controls are published by several major custodians.

Incident disclosure

How quickly and how fully a venue discloses a breach.

Which is now partly a legal obligation and partly a reputational choice.

Venues that disclosed promptly and reimbursed users generally survived incidents.

Reimbursement precedent

Several venues covered customer losses from their own resources.

Which established an expectation that not all can meet.

Reserve funds set aside for this purpose exist at some venues.

Key ceremony practice

Documented, witnessed generation and distribution of key material.

Which is borrowed from conventional financial and certificate infrastructure.

What has actually reduced losses

Cold storage ratios, multi-party control and withdrawal delays, more than any single technology.

Where the exposure sits now

Venue-side security has improved substantially through cold storage, multi-party control and regulatory requirement.

Customer-side compromise now accounts for the larger share of losses, and no venue control addresses a user who approves a fraudulent transaction.

Choosing a venue

Authorisation status, custody arrangements, proof of reserves practice, insurance terms and incident history.

All of which are checkable and are checked by very few users.

The customer-side essentials

Hardware authentication, whitelisted withdrawal addresses, and moving assets off the venue when not actively trading.

The long arc

From keys on a web server to multi-party computation, cold storage ratios and regulated custody in roughly fifteen years.

Each step followed a theft large enough to force it, which is the same sequence that produced conventional financial controls over a much longer period.

Regulatory requirements now

Segregation, custody standards, independent assurance and incident reporting.

Which convert what was good practice into obligation at authorised venues.

Unauthorised operators face none of it, which is the practical distinction.

Assessing a venue's history

Past incidents, how they were disclosed and whether users were reimbursed.

Which is public and is the most informative single check available.

A closing note

Every practice described here — cold storage, multi-party control, withdrawal delays, insurance, proof of reserves — exists because a specific venue lost a specific amount of money in a specific way.

The industry learned by paying for the lesson, repeatedly, over fifteen years.

The practical summary

Choose authorised venues with published reserve practices, enable hardware authentication and withdrawal whitelisting, and hold assets elsewhere when not trading.

Which covers the venue-side and the customer-side exposure between them.

The remaining losses are almost entirely on the customer side, where no venue control reaches.

That is the current frontier, and it is a behavioural problem rather than a technical one.