When Upbit detected unauthorized withdrawals of roughly $36 million in Solana tokens from a hot wallet on Nov. 27, CEO Oh Kyung-seok went on record within hours. He stated: “The entire amount will be covered by Upbit’s holdings, with no impact on customer assets.” Six years earlier, Upbit said the same thing after losing 342,000 […] The post The trick big crypto exchanges are using to mitigate hacks, yet can still lock up your money appeared first on CryptoSlate.When Upbit detected unauthorized withdrawals of roughly $36 million in Solana tokens from a hot wallet on Nov. 27, CEO Oh Kyung-seok went on record within hours. He stated: “The entire amount will be covered by Upbit’s holdings, with no impact on customer assets.” Six years earlier, Upbit said the same thing after losing 342,000 […] The post The trick big crypto exchanges are using to mitigate hacks, yet can still lock up your money appeared first on CryptoSlate.

The trick big crypto exchanges are using to mitigate hacks, yet can still lock up your money

2025/12/01 23:00
7 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

When Upbit detected unauthorized withdrawals of roughly $36 million in Solana tokens from a hot wallet on Nov. 27, CEO Oh Kyung-seok went on record within hours. He stated:

Six years earlier, Upbit said the same thing after losing 342,000 ETH, worth around $50 million at the time, to North Korea-linked hackers. Both times, customers saw no losses, and both times, the exchange absorbed the hit from its own treasury.

This is the hot wallet insurance model, where exchanges warehouse counterparty risk so that platform-level breaches don’t haircut users.

The system might have three forms: self-insurance from corporate reserves, dedicated emergency funds like Binance’s SAFU, and third-party crime policies with named limits.

The model has become standard practice at Tier 1 centralized exchanges, turning what would have been Mt. Gox-style insolvencies into operational losses that reopen within days.

But “users don’t lose” doesn’t mean markets don’t react. Even when deposits are ultimately safe, immediacy and liquidity are not. Hacks still freeze withdrawals, collapse order-book depth, widen spreads, and trigger reflexive pullbacks by market-makers.

The insurance model changes who eats the loss and how fast platforms can credibly reopen. It doesn’t erase counterparty risk.

Upbit: self-insurance from hacks as a corporate balance sheet

Upbit’s approach is, in effect, self-insurance with no explicit policy limit. The promise depends entirely on the exchange’s solvency and access to capital.

In both the 2019 Ethereum hack and the 2025 Solana breach, Upbit treated hot-wallet losses as operational expenses absorbed by Dunamu, its parent company.

The 2025 incident moved fast. Around 4:42 a.m. local time, roughly 54 billion won in various tokens from the Solana ecosystem tokens drained to an unknown address.

Upbit froze all Solana deposits and withdrawals, shifted remaining assets to cold storage, and froze a portion of the stolen LAYER tokens on-chain.

The exchange said it was working with projects and law enforcement to freeze even more of them, but the core commitment was immediate: no customer losses.

That commitment is credible because Upbit is large and liquid. But it’s not a statutory guarantee. There is no external insurer backstopping the promise, no deposit insurance scheme, and no formal reserve ratio that regulators audit.

The model works until it doesn’t: until a hack is large enough relative to equity that full reimbursement strains or breaks the balance sheet.

Binance and SAFU: a formalized internal fund

Binance created the Secure Asset Fund for Users in July 2018, diverting about 10% of trading fees into dedicated publicly visible cold wallet addresses.

Binance has repeatedly said SAFU is meant for “unexpected extreme cases” such as major hacks. As of press time, the fund was valued at around $1 billion.

When Binance suffered its May 2019 hot wallet breach, resulting in the loss of 7,000 BTC, it paused withdrawals and announced that all affected accounts would be made whole from SAFU, with no user losses.

Internal figures indicate that only about 2% of total exchange funds are in the compromised hot wallet, making it feasible to socialize the loss across the SAFU pool rather than push it to customers.

SAFU is an internal insurance fund: ring-fenced, pre-funded from fees, with an implicit commitment to cover large platform-level hacks, but it’s not a statutory guarantee.

If a breach exceeded the fund balance and Binance’s equity, customers would take losses. But the public visibility of the fund and the fee-funding mechanism make the promise more transparent than Upbit’s balance-sheet approach.

Crypto.com: mixing self-insurance with third-party cover

On Jan. 17, 2022, Crypto.com detected unauthorized withdrawals on a subset of user accounts and halted all withdrawals for about 14 hours.

Later disclosures put the loss at roughly $34 million in BTC, ETH, and other tokens, affecting 483 accounts. The exchange stressed that “no customers experienced a loss of funds” because it either blocked the unauthorized withdrawals in time or fully reimbursed affected users.

Subsequent communications highlighted a new protection program offering coverage of up to $250,000 per account in the event of certain third-party breaches.

Public reporting notes that exchanges like Crypto.com and Coinbase carry crime policies that pay out if the platform itself is hacked, but not if an individual loses funds due to their own credential compromise.

The distinction matters. Crime policies typically cover platform-wide breaches, insider theft, or fraudulent transfers involving the exchange’s own systems. They do not cover phishing, SIM-swaps, or users losing private keys.

Coverage is finite and conditional, with named limits and exclusions that can leave customers exposed if a breach falls outside policy terms or exceeds the limit.

Third-party policies and captive structures for hacks

Coinbase has long disclosed a crime insurance policy with a $255 million limit on its hot wallet balances, placed through Aon with Lloyd’s syndicates.

The policy is designed to cover platform-wide breaches but explicitly excludes losses from someone compromising an individual user’s login.

Gemini took the captive route, launching “Nakamoto Ltd.” in Bermuda to provide $200 million in coverage for Gemini Custody, topping up what the commercial market would offer.

Newer regulated exchanges now market “100% hot wallet insurance” as a selling point. HashKey Global says user assets are protected by comprehensive insurance, including 100% hot wallet insurance, with 90% kept in cold storage.

The spectrum runs from implicit promises backed only by equity and retained earnings, to ring-fenced internal funds, to formal insurance contracts with named limits and exclusions.

The market is maturing: recent research estimates the crypto exchange hot wallet insurance segment at about $1.4 billion in 2024, with projected growth to roughly $12 billion by 2033 as exchanges, custodians, and regulators push for more formalized loss mitigation.

Markets still react when users don’t lose

Even when users are made whole, hacks change how traders price counterparty risk. Bybit’s February 2025 $1.5 billion hack illustrates this perfectly.

Bitcoin market depth on Bybit collapsed from normal levels to about $100,000 immediately after the incident, then recovered to roughly $13 million by the end of the first quarter, in line with pre-hack conditions.

Spreads widened across BTC and the top 30 altcoins, only to tighten again over several weeks as market-makers returned.

Coinlaw data from November 2025 noted that even a technical KRW transfer suspension on Upbit coincided with an estimated 70% drop in liquidity and a sharp fall in Upbit’s share of global top 10 volumes, highlighting how quickly capital can step back from a single venue.

The pattern is consistent: frozen withdrawals, wider spreads, thinner depth, and a reflexive liquidity provider pullback. Even when deposits are ultimately safe, immediacy is not.

Traders who need to move capital or hedge positions face hours or days of illiquidity. Market-makers who provide depth pull back until they are confident the platform is stable.

What the model does and doesn’t solve

Hot wallet insurance greatly reduces the odds that a single exchange hack wipes out customer coins. It changes who eats the loss and how fast platforms can credibly reopen.

Upbit, Binance, and Crypto.com all absorbed platform-level breaches from reserves or internal funds and reopened within days, avoiding the years-long insolvency proceedings that followed Mt. Gox.

But coverage is finite and conditional. It often applies only to platform-level breaches, not to phishing or SIM swaps.

A sovereign guarantee doesn’t back it, the way bank deposits are. And it does nothing to stop the short-term fallout that actually moves markets: frozen withdrawals, wider spreads, thinner depth, and a reflexive pullback of liquidity.

The lesson is that hot wallet insurance is real and functional, but it’s not deposit insurance. It depends on the exchange’s solvency and liquidity, the adequacy of internal funds or external policies, and the platform’s willingness to honor promises when reserves are tested.

For users, the model means counterparty risk is lower than it was in the Mt. Gox era, but it’s not zero. For markets, it means hacks still dominate headlines and price action even when every customer ends up whole.

The post The trick big crypto exchanges are using to mitigate hacks, yet can still lock up your money appeared first on CryptoSlate.

Market Opportunity
Swarm Network Logo
Swarm Network Price(TRUTH)
$0.009503
$0.009503$0.009503
+1.14%
USD
Swarm Network (TRUTH) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
BitcoinEthereumNews2025/09/18 01:33
Tether Engages Big Four for First Full Audit – Crypto News Bitcoin News

Tether Engages Big Four for First Full Audit – Crypto News Bitcoin News

The post Tether Engages Big Four for First Full Audit – Crypto News Bitcoin News appeared on BitcoinEthereumNews.com. New Transparency Push for Tether With Major
Share
BitcoinEthereumNews2026/03/25 04:39
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23