CoinW says it has expanded its internal security operations around a Zero Trust model, proprietary wallet infrastructure and continuous testing, placing cybersecurity at the center of its exchange operations as digital-asset platforms face increasingly sophisticated theft and phishing campaigns.
The exchange, founded in 2017, appointed cybersecurity specialist Michael Liu as chief security consultant in 2022. CoinW says its security unit now protects digital assets for tens of millions of users, with a team of engineers supported by an internal red team that attempts to identify weaknesses through ongoing penetration testing.
Liu’s appointment brought experience spanning traditional banking software and cybersecurity research. According to CoinW, Liu began security research in 2007 after working in banking software development and earned a PhD in cybersecurity nearly two decades ago. His more recent academic interests include the security of AI algorithms, threats associated with AI agents and blockchain security.
CER.live, an independent cybersecurity ratings platform, currently assigns CoinW an AAA rating under its exchange assessment methodology. Such ratings offer one external indication of a platform’s disclosed security posture, though they do not remove the operational risks that exchanges and their users face from software flaws, credential theft and social-engineering attacks.
Wallet controls and internal infrastructure
CoinW’s approach places particular emphasis on controlling core systems internally rather than relying extensively on outside providers. The company says it develops key components including its wallet systems and data infrastructure in-house, a choice intended to reduce supply-chain exposure from external code, software dependencies or integrations.
Supply-chain risk has become a persistent concern for centralized platforms. A vulnerability in a third-party component, a compromised software update or insecure integration can provide attackers a route into systems that otherwise appear well protected. Liu has identified this category of risk as a common issue for centralized services.
The exchange says it uses multi-person authorization for sensitive actions, a structure designed to prevent a single employee or compromised account from controlling critical asset movements. It also reports separating hot-wallet and cold-wallet environments.
Hot wallets remain connected to online systems to support withdrawals and trading operations, making their security procedures particularly consequential for day-to-day exchange activity. Cold wallets are designed for storage outside those online environments. CoinW says its cold-wallet assets are secured with hardware security modules, or HSMs, and secure chips, hardware designed to protect cryptographic keys against unauthorized extraction or use.
CoinW also says it operates an in-house multiparty computation, or MPC, wallet. MPC divides the control required to authorize a transaction among separate parties or systems, rather than relying on one private key held in one location. The arrangement can reduce the damage from a single compromised credential, though its effectiveness depends on how the wallet’s authorization rules and operational procedures are implemented.
Testing extends beyond internal teams
CoinW says its defenses are also reviewed by outside security firms. The company has used Hacken for penetration testing and CertiK for wallet-system audits, according to CoinW. It also maintains a bug bounty program that allows independent security researchers to report vulnerabilities.
External testing provides a separate challenge to internal engineering assumptions, particularly where systems have grown across wallets, web applications, mobile interfaces, application programming interfaces and custody operations. Bug bounties can widen that review by giving independent researchers a channel to disclose flaws before criminals find and exploit them.
The company’s internal red team serves a related but different role. Rather than conducting one-off reviews, red teams simulate attacker behavior against systems over time, testing whether security controls work together under realistic conditions. That can include attempts to exploit misconfigured access controls, exposed services, employee-targeted phishing and weaknesses introduced through software changes.
CoinW says security training begins when employees join the company and is repeated regularly. The firm also conducts monthly simulated phishing exercises. These tests are designed to measure whether staff can identify deceptive messages seeking passwords, account access or other sensitive information.
Phishing remains a practical threat even for platforms with extensive technical controls because attackers often target people rather than encryption systems. A convincing message, cloned website or fraudulent support request can seek to capture credentials that allow intruders to bypass normal account protections. Employee access makes internal awareness training relevant to asset security, customer data protection and incident response alike.
AI creates a defensive and offensive race
CoinW is developing AI-driven security agents that it says will analyze large volumes of internal log data for anomalies and automate parts of detection and response. Log data records activity across systems, such as account access attempts, administrative actions, software events and network connections. Detecting unusual patterns in that volume of information can help security teams investigate possible intrusions faster.
Liu has also warned that AI tools can strengthen attackers. He has said AI can be used to scan APIs and identify infrastructure weaknesses more quickly than manual methods. APIs are software interfaces that enable applications and services to communicate with each other; poorly secured APIs can expose account functions, data or administrative capabilities.
That dual use creates pressure on exchanges to pair automated detection with disciplined controls over code deployment, wallet access and employee permissions. AI can help surface suspicious activity, but it can also accelerate reconnaissance and phishing operations by reducing the time attackers need to identify targets and tailor deceptive messages.
User habits remain part of the security equation
CoinW’s security program addresses risks inside the platform, while users retain responsibility for securing their own accounts and long-term holdings. Hardware-based offline storage can reduce exposure for assets that do not need to be readily available for trading, though users must protect recovery information and understand the operational risks of self-custody.
Account holders can also reduce phishing exposure by navigating directly to verified platform addresses, checking domain names carefully and treating unsolicited support messages with caution. Attackers commonly imitate exchange branding and create counterfeit login pages intended to collect passwords, two-factor authentication codes or wallet approvals.
CoinW’s combination of internal development, multi-person controls, testing and planned AI monitoring reflects an effort to make a successful intrusion harder to execute and contain its effects if one occurs. The remaining challenge is operational: security protections must keep pace with new software dependencies, evolving attack methods and the human errors that technical systems alone cannot eliminate.
Strengthen your defenses against phishing and theft—explore Toobit’s guide on crypto safety standards every exchange user needs to follow.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
