New findings on the security and transparency practices of cryptocurrency exchanges have highlighted significant shortcomings in the industry. According to CORE3’s analysis as of September 1, 2026, about half of the 193 centralized crypto exchanges examined lack verified data for key security criteria including Proof of Reserves, penetration testing, and an active bug bounty program.
How Is CoinGecko Evolving Its Security Rating?
CoinGecko has responded to this insight by revising its cybersecurity assessment framework for evaluating centralized exchanges. This update involves transitioning the security component in its Trust Score system from the CER.live platform to the CORE3 system, covering 166 centralized crypto exchanges.
“CoinGecko’s Trust Score system has switched its cybersecurity component to the CORE3 system from the CER.live infrastructure used for nearly six years,” the company stated.
Despite this shift, significant changes to the existing cybersecurity scores of exchanges are not anticipated. The expected variation in individual exchange scores should be limited to approximately two points.
Users will still have access to essential indicators like penetration test status, bug bounty programs, and Proof of Reserves, alongside the exchanges’ cybersecurity scores.
Is Financial Capacity Also Critical?
The upgraded evaluation system considers more than just cybersecurity elements. Exchanges are now assessed under categories of Security, Financial Capacity, and Transparency.
Using this data, a risk indicator known as the “Probability of Loss” (PoL) is generated. This metric aims to assess the risk of loss due to security breaches, financial difficulties, or operational issues.
CORE3 has reported that several exchanges have submitted new documents related to reserves, penetration tests, and bug bounty programs. As a result, the proportion of exchanges without verified criteria might decrease over time.
- Only 24 exchanges, or 12.4%, have verified Proof of Reserves.
- The number of exchanges conducting penetration tests lags at 27.5%.
- Just 10 exchanges meet all three crucial security benchmarks, representing a mere 5.2% of the total dataset.
- A prominent 48.7% of exchanges fail to provide verified evidence for any of the three key security and transparency metrics.
On the operational security front, factors such as private key management and signer infrastructure are also considered in this comprehensive evaluation approach.


