Join our Newsletter — 33% off our NHI Course

Why do centralized exchanges remain attractive targets for crypto thieves compared with DeFi protocols?

Centralized exchanges concentrate valuable assets, operational trust, and administrative access in one place, which makes them efficient targets for attackers seeking high-value theft. The article shows thieves returning to centralized services as Bitcoin-driven theft rises. When the asset mix and custody model concentrate value, compromise can yield larger payouts than attacking smaller, less liquid venues.

Why Centralized Custody Creates a Bigger Theft Opportunity

Centralized exchanges aggregate custody, settlement, and administrative control into a single operating plane. That concentration creates a larger payout surface than a fragmented DeFi environment because one successful compromise can reach many accounts, many assets, or the exchange’s own reserve and withdrawal paths. The attacker does not need to piece together individual wallet access across a broad protocol landscape.

That is also why exchanges remain attractive even when DeFi is heavily targeted. The theft economics are shaped by concentration and operational leverage: a single breach can convert into outsized value if the attacker can reach hot wallets, internal signing flows, or privileged back-office controls.

How Trust and Administration Change the Attack Economics

Centralized venues depend on administrative privileges, internal workflows, and human-operated recovery processes. Those controls are necessary for customer support, treasury management, and incident response, but they also create high-value trust relationships that thieves can abuse through credential theft, insider misuse, social engineering, or control-plane compromise.

DeFi protocols shift much of the risk into code and on-chain logic, but centralized exchanges still present a simpler route to direct value extraction when the attacker can reach the right operational layer. The target is often not the public trading interface alone, but the administrative path that can move or release assets at scale.

In practice, that means the attacker often benefits more from compromising a small number of privileged workflows than from attempting many separate wallet-level steals. The more the custody model centralizes power, the more efficient the theft path becomes.

Why Liquidity and Operational Concentration Matter More Than Protocol Form

The difference is not just “centralized versus decentralized.” It is how much value is reachable from a single compromise event. Exchanges typically hold assets on behalf of many users, maintain liquid balances for withdrawals and market making, and keep operational access close to those balances. That makes them especially attractive when thieves want immediate, high-confidence monetization rather than complex post-exploit unwinding.

DeFi can absolutely be lucrative for attackers, but the payoff is usually tied to protocol-specific weaknesses, price manipulation, or composable attack paths. A centralized exchange, by contrast, can present a more direct path to pooled funds, which is why it remains a recurring target when thieves look for the highest return per successful intrusion.

If you want a useful comparison point for the custody side of this problem, the exchange risk is often less about the market-facing product and more about NIST Privacy Framework style data and control concentration: the same system that simplifies service delivery also concentrates the consequences of a compromise.

Risk and Threat Considerations

Centralized exchanges create a high-severity target profile because compromise can combine asset concentration, privileged operations, and rapid withdrawal capability. The practical danger is not only theft of customer funds, but also abuse of administrative pathways that can delay detection, weaken recovery, or widen the blast radius.

Failure mechanism: Attackers seek the smallest number of credentials, keys, or privileged workflows that unlock the largest amount of value, then use operational trust to move assets before controls or responders can stop them.

Impact: A single compromise can produce outsized losses, customer harm, and market confidence damage, especially when hot storage, treasury functions, and withdrawal authority are tightly centralized.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.SC-01 — Cybersecurity Supply Chain Risk Management Centralized custody concentrates third-party and operational trust into one attack surface.
Recommendation — Map critical custody dependencies and reduce single-point trust in exchange operations.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Privileged exchange workflows make excessive access a direct theft amplifier.
IA-5 — Authenticator Management Exchange theft often starts with stolen or abused credentials and keys.
AU-6 — Audit Record Review, Analysis, and Reporting Rapid theft depends on delayed detection across high-value operational paths.
Recommendation — Restrict administrative and withdrawal privileges to the minimum required. Harden credential lifecycle, rotation, and revocation for operational access. Review anomalous transfer and admin activity fast enough to interrupt abuse.
CIS Controls v8 CIS-6 — Access Control Management Centralized exchanges rely on tightly governed privileged access paths.
Recommendation — Tighten and review access paths that can move or release assets.

Practitioner Guidance

What to verify: Treat custody concentration as a blast-radius question, not just an architecture choice. Verify which paths can move assets, which people or systems can approve those moves, and whether any one workflow can drain more value than the organisation could absorb in a short response window.

What good looks like: The strongest posture is one where high-value withdrawal or signing actions are bounded, monitored, and independently recoverable, so that an attacker who wins one trust boundary does not automatically win the treasury.

Practitioner takeaway: Centralized exchanges stay attractive because the attacker’s job is easier when value, authority, and execution are concentrated, so the control objective is to reduce what any single compromise can actually reach.