Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What happens when a major exchange loses control…
Identity Beyond IAM

What happens when a major exchange loses control of a large share of customer assets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Identity Beyond IAM

When a major exchange loses control of a large share of customer assets, the impact extends beyond the initial theft. Customers may rush to withdraw funds, liquidity pressure can force emergency financing, and market confidence can fall sharply. Recovery becomes a governance and trust problem, not just a technical one, because the organisation must restore operational stability and public credibility.

Why Exchange Asset Loss Becomes a Trust Event, Not Just a Theft Event

A major exchange does not fail in isolation when customer assets are lost. The immediate loss is followed by withdrawal pressure, counterparty uncertainty, and a credibility shock that can outlive the incident itself. That is why the question matters to trading platforms, custody teams, and boards as much as to incident responders. For exchange operators, the control problem is not only whether funds were taken, but whether customers, counterparties, and regulators still believe the platform can safely safeguard and reconcile what remains.

Industry guidance on loss-of-funds handling is fragmented, but the operational pattern is well understood, and the OWASP Non-Human Identity Top 10 is relevant only where the exchange’s custody stack depends on machine-held keys, automated signing paths, or other non-human credentials that materially affect asset control. In practice, many security teams discover the trust failure only after customers begin treating the exchange as a liquidity risk rather than a technology platform.

How Loss of Custody Cascades Through Operations and Markets

Once an exchange loses control of a substantial asset share, the technical event becomes a balance-sheet, liquidity, and governance problem. The first pressure point is often withdrawals: customers seek to move assets before the exchange can demonstrate a complete asset picture, and that behaviour can amplify the shortage even when some reserves remain. If the exchange relies on hot wallets, automated settlement, or internal transfer systems, those functions may need to be paused or restricted while teams verify what is still controlled and what can be reconciled.

That response creates a second-order problem. Pausing normal movement can protect the remaining estate, but it also makes the platform look impaired, which can deepen the run dynamic. Rebuilding confidence usually depends on proving three things at the same time: what was lost, what is still available, and how liabilities will be handled. Without that proof, customers assume the worst-case posture and treat the exchange as if all accessible balances may be at risk.

  • Custody proof matters as much as technical containment because customers judge recoverability, not just compromise scope.
  • Liquidity management becomes a core incident function when withdrawals can accelerate faster than reserves can be stabilised.
  • Reconciliation must separate asset loss, restricted access, and accounting uncertainty, because those are operationally different problems.

Where the exchange depends on automated signing, vendor custody, or delegated control paths, the recovery window can widen quickly because the organisation must validate who or what was authorised to move assets in the first place. This guidance breaks down when the platform cannot produce reliable reserve, ledger, and authorisation evidence quickly enough to distinguish partial compromise from systemic insolvency.

When the Standard Response Stops Working

Tighter containment often increases commercial disruption, so exchanges must balance loss prevention against the need to preserve enough operational continuity to reassure customers. That tradeoff is especially visible when the incident affects a large share of customer assets, because ordinary incident response plays no longer restore confidence on their own.

One variation is partial-control loss, where the exchange still holds some customer assets but cannot prove full segregation or availability. Another is a custody-layer failure, where the exchange’s own systems are intact but a third-party wallet, key-management service, or delegation path has broken trust. There is also a governance edge case: if the exchange cannot rapidly explain whether the issue is theft, accounting mismatch, or internal misuse, the market may react to uncertainty more strongly than to the confirmed loss itself.

Consensus is limited on the exact disclosure sequence across jurisdictions, but practitioners generally agree that delayed clarity increases the chance of a broader confidence event. The hard part is not only stopping further loss, but communicating a defensible asset position before rumours define it for you.

Risk and Threat Considerations

The material risk is systemic exposure: once a major exchange appears unable to control a large customer asset pool, the incident can trigger a run, a funding squeeze, and a collapse in confidence that spreads beyond the original loss. The threat is not limited to the first theft path, because the loss of control itself becomes an exploitable condition for panic, opportunistic abuse, and secondary compromise attempts.

Failure mechanism: Adversaries or accidental failures that defeat custody, key management, or transfer approval can create a control gap where balances cannot be reliably authenticated, moved, or reconciled. That uncertainty is enough to force defensive withdrawal limits, emergency wallet changes, and heightened scrutiny of every remaining transfer path, which can expose additional weak points in hot-wallet handling, internal approvals, or delegated access.

Impact: The exchange may lose the ability to operate normally, secure emergency liquidity, or prove solvency and segregation. Customers may withdraw en masse, counterparties may restrict exposure, and regulators may treat the event as a governance failure rather than a narrow technical incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-1 — Risk Management StrategyAsset loss at an exchange is a governance and enterprise risk problem.
RC.RP-1 — Recovery Plan ExecutionAn exchange must execute recovery actions under liquidity and confidence pressure.
PR.DS-1 — Data-at-Rest ProtectionCustomer assets depend on secure storage and segregation controls around custodial systems.
Recommendation — Use GV.RM-1 to tie custody loss response to enterprise risk decisions and recovery priorities. Use RC.RP-1 to validate that recovery actions preserve custody evidence and operational continuity. Apply PR.DS-1 to harden asset storage and reduce exposure in custody systems.
CIS Controls v86 — Access Control ManagementExchange asset loss often follows compromise or misuse of privileged transfer paths.
Recommendation — Apply Control 6 to restrict and review every path that can move customer assets.
MITRE ATT&CKT1111 — Multi-Factor Authentication InterceptionThe incident may involve adversary abuse of approval or auth pathways before asset transfer.
Recommendation — Map observed abuse of approval chains to T1111 and hunt for stolen-session activity.

Practitioner Guidance

What to prioritise: Establish an immediately defensible asset picture before trying to normalise operations. The first question is not how to restore every service, but whether the exchange can prove what remains under control, what is missing, and what customer balances can still be honoured.

What to verify: Separate custody loss from ledger uncertainty and from temporary access restrictions. Teams should be able to show reserve evidence, transfer-state evidence, and authorisation evidence without relying on informal explanations, because those three signals drive whether the event is viewed as recoverable or existential.

What practitioners underestimate: Communications discipline is part of the control response. If the exchange cannot produce a coherent, evidence-backed account quickly, external stakeholders will assume the worst and react as if the platform’s remaining assets are already impaired.

Practitioner takeaway: A large custody loss is rarely contained by technical recovery alone; the organisation must restore trust in asset control, not just restore systems.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org