Trading venues were robbed repeatedly in early periods, and the practices that emerged in response are now standard.
The early state
Keys held on internet-connected servers, frequently by small teams without security expertise.
Which produced repeated large thefts.
Several venues failed entirely following a single incident.
Cold storage adoption
Holding the majority of assets offline.
Which addressed remote compromise directly.
Ratios between hot and cold storage became a stated policy at serious venues.
Multi-signature arrangements
Requiring multiple keys held by different people in different places.
Which removed the single point of compromise.
Geographic and organisational separation of signers became standard practice.
Withdrawal controls
Allowlisted addresses, delays on new destinations and approval workflows.
Which limit the damage from account compromise.
These are offered to customers and enabled by a minority of them.
Insider risk
Several incidents involved employees rather than external attackers.
Which is why separation of duties and access review matter.
No individual should be able to move funds alone, which is a design requirement.
Insurance
Cover for held assets with defined limits and exclusions.
Which is generally well below total holdings.
Exclusions for client credential compromise are standard.
Proof of reserves
Demonstrating holdings publicly.
Which addresses solvency doubt rather than theft.
Adoption accelerated sharply following a major failure.
Regulatory requirements
Segregation, custody standards and independent assurance are now mandated in several jurisdictions.
Which converted good practice into requirement.
The remaining exposure
Customer-side compromise, which venue security cannot address and which now accounts for a large share of losses.
Hot wallet limits
Caps on how much is held online at any time.
Which bounds the maximum loss from a remote compromise.
Automated replenishment from cold storage with approval controls is standard practice.
Address whitelisting for customers
Restricting withdrawals to pre-approved destinations with a delay on additions.
Which substantially limits account takeover damage.
It is offered widely and used sparingly.
Authentication
Hardware security keys resist phishing where code-based methods do not.
Which matters because phishing dominates account compromise.
Number porting attacks defeated message-based codes repeatedly.
Bug bounty programmes
Venues offering payment for vulnerability disclosure.
Which has identified genuine issues before exploitation.
Payout scale relative to potential exploitation value determines effectiveness.
What customers control
Withdrawal to self-custody, hardware authentication and whitelisted addresses.
Penetration testing and audits
Independent assessment of systems and controls.
Which is standard at regulated venues and variable elsewhere.
Assurance reports covering controls are published by several major custodians.
Incident disclosure
How quickly and how fully a venue discloses a breach.
Which is now partly a legal obligation and partly a reputational choice.
Venues that disclosed promptly and reimbursed users generally survived incidents.
Reimbursement precedent
Several venues covered customer losses from their own resources.
Which established an expectation that not all can meet.
Reserve funds set aside for this purpose exist at some venues.
Key ceremony practice
Documented, witnessed generation and distribution of key material.
Which is borrowed from conventional financial and certificate infrastructure.
What has actually reduced losses
Cold storage ratios, multi-party control and withdrawal delays, more than any single technology.
Where the exposure sits now
Venue-side security has improved substantially through cold storage, multi-party control and regulatory requirement.
Customer-side compromise now accounts for the larger share of losses, and no venue control addresses a user who approves a fraudulent transaction.
Choosing a venue
Authorisation status, custody arrangements, proof of reserves practice, insurance terms and incident history.
All of which are checkable and are checked by very few users.
The customer-side essentials
Hardware authentication, whitelisted withdrawal addresses, and moving assets off the venue when not actively trading.
The long arc
From keys on a web server to multi-party computation, cold storage ratios and regulated custody in roughly fifteen years.
Each step followed a theft large enough to force it, which is the same sequence that produced conventional financial controls over a much longer period.
Regulatory requirements now
Segregation, custody standards, independent assurance and incident reporting.
Which convert what was good practice into obligation at authorised venues.
Unauthorised operators face none of it, which is the practical distinction.
Assessing a venue's history
Past incidents, how they were disclosed and whether users were reimbursed.
Which is public and is the most informative single check available.
A closing note
Every practice described here — cold storage, multi-party control, withdrawal delays, insurance, proof of reserves — exists because a specific venue lost a specific amount of money in a specific way.
The industry learned by paying for the lesson, repeatedly, over fifteen years.
The practical summary
Choose authorised venues with published reserve practices, enable hardware authentication and withdrawal whitelisting, and hold assets elsewhere when not trading.
Which covers the venue-side and the customer-side exposure between them.
The remaining losses are almost entirely on the customer side, where no venue control reaches.
That is the current frontier, and it is a behavioural problem rather than a technical one.