ICORating Exchange Security Report
ICORating Exchange Security Report
Exchange
Security Report
ICORating.com Exchange Security Report
Over the years, digital thieves have stolen millions of dollars’ worth of
cryptocurrency from various exchanges. The crypto market attracts a huge number of
investors and everyone hopes to get the highest returns and it doesn’t bother anyone that
once your crypto is stolen, you won’t get the refund, transactions and assets are not
secured in any way, which makes investing in cryptocurrencies really hazardous. The
largest crypto exchanges contain vast amounts of digital cash. These facts are really
attractive for hackers.
Over the past 8 years about 31 crypto exchanges have been hacked and more than a
1 billion dollars (actually, $ 1.3 bn) stolen. Some of the crypto exchanges learned from
their mistakes and managed to recover, the others went bankrupt and several the most
“happy” ones, such as Mt.Gox, Bitcoinica, PicoStocks, Bitcurex, have been attacked even
multiple times.
Today more than 200 crypto-exchanges offer their services and this number is constantly
growing, therefore, the fall or hacking of the one exchange will not lead to a drop in the
market, as it could have been before, furthermore many countries are beginning to
introduce regulatory requirements for crypto-exchanges, but still nobody is fully protected
from the loss of their crypto assets, therefore, invest in reliable assets, diversify your
portfolio and choose good crypto exchanges.
When preparing this security rating, we have assessed security measures against the
following potential vulnerabilities that could negatively impact exchanges and their users.
We selected exchanges whose daily trade value exceeds one million USD; the total number
of exchanges on the list is 100.
1
ICORating.com Exchange Security Report
Console errors
These errors in the code can result in the malfunctioning of some systems that might lead
to problems for their users. This type of vulnerability is usually not critical, however it
should be taken into account as in some instances these errors have resulted in data loss.
● Exchanges that have neither error nor a warning about this type of error: 49%
● Exchanges with no errors: 68%
Conclusion: 32% of exchanges have code errors, which leads to certain defects in
operation.
2
ICORating.com Exchange Security Report
employee owning the domain leaving the company (again, this is a good reason to
use Role Accounts).
5. DNSSEC; DNSSEC eliminates the threat of DNS cache poisoning by authenticating all
DNS queries with cryptographic signatures. Instead of blindly caching DNS records,
DNS servers will reject unauthenticated responses.
There are three possible outcomes for each item: All items above operate correctly (1),
None operate properly (0), warning (0.5). The results of this assessment are as follows:
● Only 2% of exchanges use registry lock
● Only 10% of exchanges use DNSSEC
● There were no exchanges that had problems with all five items
● Only 4
% of exchanges using best practice in 4 out of 5 of these areas.
3
ICORating.com Exchange Security Report
Registrar &
Console Domain Web
Name Errors User Security Security Security Score
1 Coinbase Pro 2/2 4/4 3,5/5 5/5 89
4
ICORating.com Exchange Security Report
15 Bancor Network 1/2 4/4 2/5 4/5 65
5
ICORating.com Exchange Security Report
40 Cryptonex 1/2 2/4 4/5 1/5 48
6
ICORating.com Exchange Security Report
65 itBit 2/2 4/4 1/5 1/5 40
7
ICORating.com Exchange Security Report
90 Trade By Trade 2/2 4/4 1/5 0/5 29
8