Exchanges
What happens to your crypto when an exchange fails
“Is this exchange safe” is a question about the future, which is why it has no good answer. The useful version is narrower and answerable: if this venue failed tomorrow, what would determine whether I got my assets back? Four things do, and three of the reassurances people rely on are not among them.
Insurance covers theft, and failure is not theft
Exchanges carry crime and custody policies, and those policies are real. They respond to theft — typically of assets held in hot wallets, the ones a venue keeps online for day-to-day withdrawals, because that is where the insurable risk sits.
What they generally do not respond to is the company becoming insolvent. A business failing is not a theft, so the event that most threatens your balance is the one the policy was not written for. Coverage for insolvency exists only where a policy says so explicitly, and it usually does not.
So “which exchange has the best insurance on deposits” is asking about protection against a scenario that is not the one that has historically cost people money. Worth knowing a venue is insured. Worth knowing more precisely what against.
Deposit insurance covers a bank, not this
The most consequential confusion, and one regulators have had to intervene over.
Schemes like the FDIC in the United States or the FSCS in the United Kingdom protect cash held at an insured bank if that bank fails. They do not cover crypto assets, and they do not cover the failure of a non-bank — an exchange, a custodian, a broker or a wallet provider. The FDIC has published a fact sheet saying exactly this because the implication was being made often enough to need correcting.
Where your fiat balance genuinely sits in an insured bank account, that cash may be covered against the bank’s failure. Your crypto is not, under any circumstances, and no arrangement between you and the exchange changes that.
Segregation is the question that actually decides it
Here is the one that matters, and it is contractual rather than reassuring.
If customer assets are held separately from the company’s own, they are more likely to be treated as yours rather than as property of the estate when administrators arrive. If they sit in an omnibus pool mixed with corporate funds, you are an unsecured creditor with a claim, standing behind secured creditors, in a process measured in years.
Which of those applies is set by the customer agreement and the law where the entity sits — not by the marketing. In the EU it is set by regulation: MiCA requires an authorised provider to hold client crypto-assets separately from its own on the ledger itself, and makes the custodian liable for losses attributable to it. Outside that perimeter, read the terms. The relevant section is usually called something like “title to assets”, and it is short.
“Never been hacked” is a claim about the past
It is also a survivorship claim, which is a different thing from a safety one.
Every venue that has failed could say it had never been hacked, right up until the day it could not. The statement describes a record, not a control, and it gets stronger-sounding the longer a venue operates regardless of whether anything underneath it improved.
The checkable substitutes are dull and better: what is the entity, what is it authorised to do, are client assets segregated, what does the last attestation cover, and how quickly did your own withdrawal actually clear. A reserve attestation is evidence about assets and most of them stop there — which makes it a first question rather than an answer.
What a public listing actually gets you
This is a genuine signal, and it is worth being precise about why.
A listed company files audited financial statements on a schedule, under rules with legal consequences for misstatement, reviewed by an auditor with its own liability. That is a fundamentally different kind of evidence from a self-published attestation: not because listed companies are virtuous, but because the disclosure is compelled, periodic and adversarially checked.
It tells you about the company — its solvency, its revenue, its stated controls. It does not tell you that your particular assets are segregated, and it does not make the entity that serves your country the same one that is listed. Large groups operate through different companies in different regions, and the filing belongs to one of them.
What a wind-down looks like
Worth picturing once, because it shapes every decision above.
Withdrawals stop first, usually without warning and usually while the venue is still saying things are fine. An administrator is appointed. Customers become claimants, the pool of assets is established, and the question of whose property is whose is argued about. Distributions, if any, come in instalments over years, often denominated in a currency amount fixed at the date of failure rather than in the assets you held — so a recovery of most of your claim can still be a fraction of what those coins are worth by the time it arrives.
None of that is unusual or scandalous. It is simply what insolvency is, and it is the thing the word “safe” is standing in front of.
What to do about it
Three things, in order of how much they return.
Run the leaving test before you need it — deposit, buy, sell, withdraw all the way out, at a calm moment, as the comparison piece sets out. Exit behaviour under normal conditions is the best available predictor of exit behaviour under bad ones.
Size the balance to the failure. An exchange is a venue for transacting and a counterparty for holding. What sits there should be what you are actively using plus what you could absorb losing, which is a different number from what is convenient to leave.
Know what you are choosing instead. Exchange or self-custody is not safe versus unsafe — it is recourse against control, and moving assets off a venue trades a counterparty risk for an operational one you now own entirely.