Security is one of those things that works best when nobody has to think about it.
Unfortunately, crypto has spent the past few years giving everyone plenty of reasons to think about it.
CoinGecko recently published its 2026 State of Crypto Security Report, examining how attacks are changing and what exchanges are doing in response. Toobit is featured in the report as part of its look at centralized exchange security, including our Bee-Safe framework, cold wallet custody, Proof of Reserves, real-time monitoring, and Toobit Shield Fund.
We are glad to be included. More importantly, the report gets at something we believe strongly: security is not one feature. It is a stack of safeguards that need to work together.
One lock is not enough
There is no magic security button.
Our Bee-Safe framework starts at the account level with protections including two-factor authentication, anti-phishing verification, withdrawal address allowlisting, and additional safeguards around newly added withdrawal addresses.
Then there is custody. More than 90% of assets held on Toobit are stored offline in multi-signature cold wallets, reducing the amount of capital exposed to internet-connected systems.
Behind that sits another layer of infrastructure protection, including data encryption, DDoS protection, multi-cloud architecture, real-time risk monitoring, and ongoing security assessments.
And because testing your own homework only gets you so far, we bring in outside eyes too.
In August 2026, Hacken completed expanded penetration testing across our web and API infrastructure as well as our iOS and Android applications. The assessments recorded no Critical or High-severity findings, and all seven Medium-severity findings identified during testing were resolved.
Security is a process. Preferably a repetitive one.
Trust is better with receipts
Protecting assets is one side of exchange security. Showing that those assets are actually there is another.
Toobit maintains 1:1+ Proof of Reserves, with reserve ratios for BTC, ETH, USDT, and USDC above 100%. Through Merkle-tree verification, traders can independently confirm that their balances are included in our reserves.
That distinction matters. "Trust us" has never been a particularly convincing security model. Verification gives traders something better: the ability to check for themselves.
The same principle applies to our Shield Fund.
We launched the Toobit Shield Fund in October 2025 with an initial value of $50 million to cover eligible losses resulting from technical or security incidents originating from the exchange.
There is no application process based on how large your account is or how much you trade. Protection applies automatically to eligible traders.
The assets behind the fund are also held across four dedicated public wallets, so anyone can monitor their composition and value on-chain in real time.
Again, receipts.
The threats are not getting simpler
There is a reason the industry keeps adding more layers.
CoinGecko recorded $3.63 billion in losses across 245 security incidents between January 2025 and July 2026. More than 72% of those losses came from just the 10 largest incidents.
TRM Labs found another interesting imbalance. It recorded 207 hacks during the first half of 2026, the highest number it has observed in any six-month period. Infrastructure and operational compromises represented only around 15% of incidents but accounted for roughly 76% of the $972 million lost.
In other words, attackers do not need to win often if the wins are big enough.
That changes how exchanges need to think about security. Protecting individual accounts matters, but so do custody systems, private keys, infrastructure, operational controls, monitoring, external testing, reserves, and contingency funds.
No single safeguard covers all of that.
Security should be built to last
CoinGecko featuring Toobit in its 2026 report is welcome recognition of the work happening behind the trading screen.
But security is not something we consider finished because it appeared in a report.
Threats change. Systems change. Attackers change tactics. The safeguards around them have to keep moving too.
So we will keep testing our infrastructure, monitoring activity, maintaining transparent reserves, and adding layers where they are needed.
Because when security is doing its job properly, there should not be much drama.
We are perfectly happy with that.
