Exchange risk is the possibility that a platform or one of its dependencies prevents a user from using, transferring, or recovering assets and money, degrades execution quality, or interrupts service. It is not one risk: it combines contract, custody, balance sheet, technology, conflicts, and market.
In plain terms — A balance on the screen does not answer three decisive questions: who must return it, where the assets are, and what happens if withdrawals stop or the company fails.
1. Which entity owes an obligation to the client?
A brand and app may be shared by several companies. Identify the contractual entity, country, service, and applicable law for trading, custody, fiat, derivatives, and staking. A licence or registration should be read within its actual perimeter: the authority, authorised activities, and listed entity.
“Regulated” does not mean risk-free. It means that particular obligations and controls apply within a defined scope. It does not guarantee price, future solvency, or immediate return of assets in every crisis.
2. Who controls the assets, and which rights remain?
A CEX may record the balance in an internal ledger and control assets through omnibus wallets, custodians, or sub-custodians. Contract and law determine whether assets remain the client's property, are held in custody, may be reused, or create a claim against the intermediary.
Segregation separates records or holdings under defined rules, but does not by itself ensure immediate return or identical treatment in every insolvency. Reconciliations, access to keys, the sub-custody chain, procedures, and applicable law are also required.
3. Proof of reserves, audits, and solvency
A proof of reserves may show that an entity controlled specified assets at a point in time and within a stated perimeter. It does not necessarily prove complete liabilities, unencumbered assets, off-balance-sheet exposure, the quality of controls, or clients' legal rights.
A financial-statement audit, a reserves attestation, and a custody reconciliation have different objectives. Even a solvent balance sheet is a snapshot: liquidity, concentration, leverage, and maturities can change. The right question is not “does it have a PoR?”, but which claim does it verify, at what date, and with which exclusions?
4. Withdrawals and operational continuity
Downtime, a cyberattack, a wallet error, congestion, maintenance, or a supplier problem can stop orders and withdrawals. A working API and a reachable website do not prove that settlement and custody are operational.
The review considers incident history, communications, actual withdrawal times, limits, allowlists, manual procedures, business continuity, disaster recovery, and dependencies on cloud providers, custodians, and networks. A small test can confirm one route at one moment; it cannot guarantee that the route remains available under stress.
5. Conflicts and market integrity
A crypto intermediary may combine a trading platform, brokerage, custody, lending, staking, market making, token issuance, and proprietary trading. This concentration can create conflicts, cross-use of collateral, opaque prices, and transmission of losses between activities.
Matching, market surveillance, asset admission, management of affiliated tokens, order priority, and the role of affiliates should be distinguished. CEX, DEX, and OTC separates venue model, price mechanism, custody, and settlement.
Risk is not removed by distributing balances blindly
Using several venues can reduce one concentration but adds accounts, keys, APIs, entities, and procedures. Two brands may depend on the same custodian, group, or liquidity source. Self-custody reduces some intermediary exposure but transfers key, backup, signing, and succession risks to the user.
There is no universal percentage. Operating capital depends on strategy, liquidity, transfer times, and the ability to stop. Each limit should have a rationale, be monitored, and connect to a workable exit plan.
Signals to investigate
Unexplained withdrawal delays or changing rules, unclear entities, undescribed liabilities, returns inconsistent with observable flows, proprietary tokens used as collateral, and incomplete communications require investigation. Divergent spreads, mark prices, or liquidations across markets can also signal stress, but no single signal proves insolvency.
Compare independent sources and retain the date and perimeter. The absence of a visible red flag is not evidence of safety.
Exit and continuity plan
- Identify the entity, service, jurisdiction, and applicable contract.
- Document custody, sub-custody, segregation, reuse, and insolvency rights.
- Compare reserves with liabilities, assurance, reconciliations, and the reference date.
- Test withdrawals, authorised addresses, and support routes before an emergency.
- Prepare how to reduce positions, hedges, and orders if the API or market stops.
- Keep an inventory of balances, assets, networks, keys, contacts, and shared dependencies.
Professional level: monitoring claims, not labels
Professional due diligence links each piece of evidence to a precise claim: existence of assets, completeness of liabilities, ownership, segregation, internal control, resilience, or market integrity. It keeps versioned copies of terms, authorisations, financial statements, attestations, incidents, and changes to limits.
Scenarios include insolvency, cyberattack, loss of a custodian, collateral depeg, a network freeze, liquidation cascades, a bank closure, and conflict with an affiliated company. The plan must still work when promised transferability is unavailable.
Sources
- ESMA — MiCA, Article 68 — governance, resilience, continuity, and controls within the EU perimeter.
- ESMA — MiCA, Article 70 — safeguarding and segregation of clients' funds and crypto-assets.
- ESMA — MiCA, Article 72 — identification, prevention, and disclosure of conflicts.
- ESMA — MiCA, Article 75 — custody, records, sub-custody, return, and liability.
- IOSCO — Policy Recommendations for Crypto and Digital Asset Markets — Recommendations 12–17 on client assets, segregation, assurance, and operational risk.
- FSB — Multifunction Crypto-asset Intermediaries — concentration of functions, interdependencies, and conflicts.
- BIS–FSI — Cryptoasset service providers as financial intermediaries — custody, title to assets, intermediation, and risk channels.
Links
Digital assets and crypto markets · CEX, DEX, and OTC · Exchange and broker · Broker risk · Operational risk · Self-custody
Gold path — Execution module. Index: Gold path.