• Hacken
  • Blog
  • Insights
  • TOP-100 EXCHANGES BY CYBERSECURITY SCORE #3 AND COMBINED SCORE (MARCH 2020)

TOP-100 EXCHANGES BY CYBERSECURITY SCORE #3 AND COMBINED SCORE (MARCH 2020)

9 minutes

By Hacken

It is obvious that in the modern economy cyber security is one of the most crucial issues requiring proper maintenance. Especially in the crypto exchanges industry since over $282 million were stolen in 11 hacks from crypto trading platforms in 2019 according to a report by Chainanalysis. Although the total amount stolen is much smaller than in 2018 the number of attacks significantly increased. Therefore CER continues to monitor and assess the cyber security of crypto exchanges.

In the current Analysis CER used the list of 236 spot crypto exchanges from CoinGecko with Trust Score available as of 24.03.2020. 

The initial Cyber Security Score (CSS) methodology was described in the first report and the updates are highlighted in the second report. For the current report the methodology was slightly adjusted by altering weight coefficients of certain parameters and changing the calculation of Password Requirements for more balanced results. 

Statistics

The CSS results from results showed that only 19 crypto exchanges (8%) out of 236 gained “good” scores of over 8 points and higher (see fig 1). 

Fig. 1. Distribution of CSS results by total score.

While the vast part of the sample (148 crypto exchanges, 62.8%) scored moderately (6 to 8 points), 69 crypto exchanges (29.2% out of total) totaled lower than 6 points.

Just like in the previous CSS report the Bug Bounty availability appeared to be weakest parameter again (see fig. 2)

Fig. 2. Bug Bounty 

Missing HTTP headers is the second weakest parameter as 76.7% of exchanges miss 4+ headers out of 7 (see fig. 3)

Fig. 3. Missing  HTTP Headers

And another notable weakness is the presence of captcha during the sign-up and sign-in process on the trading platforms. 97 of exchanges (41.1%) don’t have captcha at all (see fig. 4).

Fig. 4. Captcha

The results for Password Requirements are way better than in the previous report due to altered methodology. Nevertheless some crypto exchanges treat this parameter irresponsibly as 13.56% of them scored 1 or 0 points. And in one particular case the platform allowed to create a 1-symbol password.

New CSS Top-100 Spot Exchanges

Table 1 below provides the list of Top-100 out of 236 sample spot crypto exchanges by CSS total results. It also contains sub-scores for Server Security, User Security, Crowdsourced Security and Historical Cases.

#ExchangeServer SecurityUser SecurityCrowdsourced SecurityHistorical CasesTotal
1btcturk8,509,4710109,02
2otcbtc7,958,4710109,02
3binance_us9,239,471088,91
4bilaxy8,418,125108,76
5bit_z8,118,1510108,66
6kucoin9,148,4710108,65
7btc_alpha8,327,655108,6
8bitsonic7,758,5910108,6
9kraken7,007,651078,56
10binance7,939,47103,58,51
11altilly8,958,005108,47
12coinbase8,147,6510108,46
13hitbtc8,506,7410108,31
14indodax4,959,120108,26
15oceanex7,917,595108,26
16binance_jersey7,619,475108,26
17poloniex10,006,7610108,2
18bigone8,399,740108,07
19txbit8,557,650108
20bitholic8,187,820107,86
21gate8,689,2153,57,82
22kuna6,868,385107,77
23qtrade8,166,855107,77
24bitexlive9,278,090107,69
25bitopro7,508,000107,66
26coinone9,557,125107,6
27bitsdaq9,688,850107,59
28whitebit8,188,060107,58
29bitmax8,238,000107,56
30probit7,598,680107,54
31huobi8,369,210107,54
32coinfloor8,688,590107,54
33mxc8,009,210107,54
34velic7,649,120107,53
35paribu8,116,240107,52
36ftx_spot6,556,180107,5
37bhex5,737,265107,48
38vebitcoin5,349,210107,46
39kkcoin6,689,210107,45
40bitlish7,845,850107,39
41dragonex8,278,5951,57,39
42livecoin7,368,590107,37
43sistemkoin7,827,535107,36
44jex8,736,0010107,34
45gemini7,826,620107,33
46chainex9,417,500107,31
47huobi_japan7,208,470107,31
48bgogo6,506,850107,29
49cbx6,308,940107,28
50graviex8,455,181087,26
51bitflyer5,757,65077,24
52tokenize8,188,380107,2
53huobi_korea8,958,8508,57,19
54quoine8,146,180107,18
55p2pb2b9,457,265107,17
56gdac6,866,910107,16
57exrates8,686,440107,15
58coindeal8,419,120107,12
59cointiger6,868,320107,12
60independent_reserve7,956,760107,12
61coinzo7,897,120107,12
62ooobtc7,916,595107,12
63bitcoin_com7,257,530107,09
64coinbig10,007,530107,08
65bitpanda7,895,795107,07
66bitbay7,485,975107,07
67bitforex7,528,320107,07
68ecxx7,367,120107,06
69dsx10,006,910107,05
70bitstorage6,867,380106,99
71Decoin8,458,740106,99
72bankera7,276,855106,97
73dcoin6,456,245106,96
74luno5,186,910106,95
75btcmarkets6,074,915106,95
76coinflex7,365,97536,95
77c2cx5,147,850106,95
78ovex7,456,940106,94
79bvnex6,577,120106,94
80bihodl8,417,530106,94
81hotbit7,598,0605,56,93
82bithumb_global6,419,0001,56,93
83bitso8,956,35056,92
84bitkub5,646,760106,92
85eToroX9,145,295106,9
86tokok6,687,150106,9
87coss6,328,38076,89
88lbank4,598,320106,88
89omgfin7,955,060106,86
90yobit7,556,240106,84
91daybit7,148,260106,83
92exmarkets5,915,240106,82
93cex8,145,790106,79
94unnamed6,917,350106,78
95coinsuper4,276,265106,78
96okex_korea8,237,6555,56,77
97beaxy4,416,91536,77
98elitex7,207,650106,77
99bit2c7,055,290106,76
100coinex6,326,740106,76

Table 1. Top-100 crypto exchanges by CSS results

Combined Score

Cyber Security is one of the most important parameters one should consider while evaluating crypto exchanges. But Cyber Security alone doesn’t give the full view of the trading platform’s grade. For more balanced evaluation other parameters should be assessed. Therefore CER calculated the Combined Score by adding CSS and CoinGecko’s  Trust Score equally weighted. Fig. 5 shows the distribution by Combined Score results. 

Fig. 5. Distribution of Combined Score.

In the table 2 below one can find the list of Top-100 crypto exchanges by Combined Score.

#ExchangeCSSCoinGecko Trust
Score
CSS + GC
1binance_us8,91109,46
2kucoin8,65109,33
3kraken8,56109,28
4binance8,51109,26
5coinbase8,46109,23
6poloniex8,2109,10
7bitflyer7,24108,62
8gate7,8298,41
9bithumb6,64108,32
10coinone7,698,30
11bitfinex6,6108,30
12huobi7,5498,27
13ftx_spot7,598,25
14bittrex6,43108,22
15gemini7,3398,17
16bigone8,0788,04
17probit7,5487,77
18paribu7,5287,76
19bitstamp5,35107,68
20hitbtc8,3177,66
21indodax8,2677,63
22oceanex8,2677,63
23tokenize7,287,60
24quoine7,1887,59
25coindeal7,1287,56
26bitbank6,0797,54
27luno6,9587,48
28btcmarkets6,9587,48
29bitso6,9287,46
30bitkub6,9287,46
31coss6,8987,45
32cex6,7987,40
33floatsv6,6987,35
34bitopro7,6677,33
35max_maicoin6,6487,32
36btc_alpha8,667,30
37bitsdaq7,5977,30
38bitmax7,5677,28
39bitlish7,3977,20
40livecoin7,3777,19
41upbit6,2487,12
42cointiger7,1277,06
43independent_reserve7,1277,06
44bitpanda7,0777,04
45bitbay7,0777,04
46dsx7,0577,03
47exmo6,0487,02
48dcoin6,9676,98
49hotbit6,9376,97
50bithumb_global6,9376,97
51eToroX6,976,95
52omgfin6,8676,93
53kuna7,7766,89
54okex_korea6,7776,89
55bitexlive7,6966,85
56gopax6,6876,84
57bit_z8,6656,83
58coinsbit6,6476,82
59coinfloor7,5466,77
60dragonex7,3966,70
61therocktrading6,3176,66
62digifinex6,376,65
63graviex7,2666,63
64bw6,2376,62
65zb6,2176,61
66btse6,1976,60
67p2pb2b7,1766,59
68coinzo7,1266,56
69bitforex7,0766,54
70bkex6,0576,53
71bankera6,9766,49
72coinflex6,9566,48
73ovex6,9466,47
74coincheck5,9176,46
75aex5,9176,46
76itbit5,976,45
77coinsuper6,7866,39
78qtrade7,7756,39
79elitex6,7766,39
80bilaxy8,7646,38
81okex6,7366,37
82bibox6,7266,36
83bitsonic8,646,30
84eterbase6,5366,27
85bhex7,4856,24
86vebitcoin7,4656,23
87bitmart6,4666,23
88kkcoin7,4556,23
89korbit6,466,20
90latoken6,3866,19
91crex246,3666,18
92okcoin6,3166,16
93shortex6,1466,07
94btcturk9,0236,01
95txbit846,00
96bitstorage6,9956,00
97Decoin6,9956,00
98bvnex6,9455,97
99zbg4,8875,94
100lbank6,8855,94

Table 2. Top-100 crypto exchanges by Combined Score 

Conclusions

As apparent from CSS results only 8% of trading platforms scored favorably (8 points and higher) and over 29.2% of them received fair results (below 6 points). These figures are once more highlighting the need for cyber security enhancement in the industry.As an answer on a demand for complex versatile ranking of crypto exchanges CER integrated CSS and CoinGecko’s Trust Score. The Combined Score provides a more comprehensive and multifaceted rating of cryptocurrency trading platforms. We believe that the approach of combining different assessment methodologies will help users to better evaluate the grade of crypto exchanges. Exchanges representatives can get details about their exchange rating by leaving a request in our contact form.

Subscribe
to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img

Table of contents

  • Statistics
  • New CSS Top-100 Spot Exchanges
  • Combined Score
  • Conclusions

Tell us about your project

Follow Us

Read next:

More related
  • Blog image
    Protecting Web3: Q3 2023 Security Insights Report

    2 min read

    Discover

  • Blog image
  • Blog image
More related →

Trusted Web3 Security Partner