Download Publication

Crypto-Asset Exchange Security Guidelines
Crypto-Asset Exchange Security Guidelines
Who it's for:
 Users, operators, and auditors of crypto-asset exchanges 

Crypto-Asset Exchange Security Guidelines

Release Date: 04/13/2021

Thanks to the blockchain technology that makes them possible, crypto-assets are becoming massively successful. As with any successful industry, a multitude of security questions arise: What risks should cryptocurrency users be aware of? How can they protect themselves? What security controls should operators put in place?

Experts have identified crypto-asset exchanges as a major pain point of crypto security. Exchanges are platforms that mediate crypto-asset transactions between entities. There are several types of attacks that are successful against exchanges. In this document, we give an overview of these attacks, describe an exchange security reference architecture, and then provide a detailed list of crypto-asset exchange security best practices, administrative controls, and physical controls. This is part of an ongoing project by the Blockchain/Distributed Ledger Working Group.

Key Takeaways:
  • The types of attacks that threaten crypto-asset exchanges
  • The details of a centralized exchange reference architecture that applies to a broad spectrum of crypto-asset exchanges
  • Crypto-asset exchange security best practices for end-users, exchange operators, and auditors
  • Crypto-asset exchange administrative and physical security control measures including: legal considerations, risk management, information access management, security awareness and training, workstation security, and more
This publication is part of a larger series on Securing DLT Frameworks for Financial Institutes. If you’re interested in learning more, you can find all the papers in the series here

Help CSA better understand how we can support the cloud community. Answer a couple of questions to download this resource.

In my current job I work in:

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

You’ve made safer cloud computing possible.

Download
Provide feedback on this form

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

Download
Provide feedback on this form

Acknowledgements

Bill Izzo Headshot
Bill Izzo
Bill Izzo

This person does not have a biography listed with CSA.

Ashish Mehta Headshot
Ashish Mehta
Ashish Mehta

Director at Genese Incubation Management Services Pvt, Ltd

Ashish is co-chair of the CSA Blockchain/Distributed Ledger working group, where he leads and supports the group’s peer-reviewed research papers and coordinates educational and networking webinars with various industry players for the wider CSA community and industry participants. He has represented CSA as a speaker at multiple global events and is he...

Read more

Interested in helping develop research with CSA?