Leading cryptocurrency exchanges are plagued by high‑risk security weaknesses, according to new analysis from the Business Digital Index, which identified only three platforms as low risk across multiple metrics.
After carrying out external cybersecurity scans of twenty-four crypto exchanges, the BDI’s investigation found evidence of critical gaps that hackers could exploit, from insufficient software patching and poor implementation of encryption protocols to the reuse of employee passwords.
Examining a range of security indicators such as data breach history, web app security, credential hygiene, email security, and hosting infrastructure, the BDI handed out A grades to just three exchanges, Biconomy, Toobit, and Deepcoin, marking them low‑risk overall.
According to the BDI, these three platforms showed barely any externally visible signs of cyber weaknesses, and were the only exchanges for which few company-related credentials could be found in leak databases, compared to most others with over 100 password/email combinations sold on dark web marketplaces.
Other well-known platforms didn’t do so well. Bitstamp, the crypto platform acquired by trading giant Robinhood earlier this year, was assessed as ‘moderate-risk’, barely scraping a C grade in the BDI’s analysis, worrying news for the exchange’s five million users worldwide.
Another poor performer is Coinbase, one of the largest crypto exchanges with over 100 million users, which ranked second-to-last in the BDI’s analysis, scoring a D grade equating to ‘high-risk’.
The BDI said it had found 2,452 corporate credentials linked to Coinbase circulating on the dark web, as well as twenty-four patching vulnerabilities, and 346 less severe SSL configuration issues.
However, these don’t automatically represent exploitable weaknesses, the analysis points out, as Coinbase’s scale, maturity, and strong internal security controls likely mitigate much of the risk of hackers gaining a foothold.
In fact, larger exchanges like Coinbase and Bitstamp posted weaker results due to the complexity of their infrastructure and sprawling systems, which the BDI said heightened the risk of exposure to unpatched gaps, misconfigurations, and stolen employee credentials.
These major platforms are also more vulnerable to the poor cyber hygiene of workers. The BDI found that 63% of companies, 15 out of 24, saw employees reusing passwords across multiple services, an issue that soon becomes endemic when scaled across hundreds or even thousands of staff.
While understanding of the whack-a-mole security issues any large platform faces, the BDI were more scathing of LBank, the only platform to get a failing grade, scoring just 52 out of a possible 100.
Recommended reading
- Comment | The Dark Side of Crypto
- 2025 Is Crypto’s Most Dangerous Year Yet, Chainalysis Warns
- FCA to Gain More Power Over UK’s Booming Crypto Market
The BDI claimed that the Hong Kong-based exchange has not taken previous criticism of its “lacklustre” cybersecurity to heart, still exhibiting many unresolved issues, including 49 unpatched vulnerabilities, eleven of which were flagged as critical and potentially exploitable.
“Historical data breaches and employee password reuse are the primary risk factors across most cryptocurrency exchanges,” concluded the BDI’s analysis.
“One notable exception is LBank, which exhibits more severe security issues. For those who want to err on the side of caution, we recommend choosing to trust companies with the highest security grades in our analysis.”





