Methodology
What the sample measures
exchange.fail reviews official public material from exchanges and custodians. It records what each source actually supports across four migration gates. It does not test private systems or infer unpublished work.
Four gates
- Risk recognition: the source names quantum risk.
- Cryptography inventory: the source describes dependency mapping.
- Custody signer: the source describes signer, HSM, MPC, or recovery migration work.
- Customer migration: the source publishes an asset or customer transition date.
Evidence labels
“Program published” means an official source describes operational work. “Risk acknowledged” means the source recognizes the problem but does not document that gate. “Not in reviewed source” means only that the cited material did not contain the evidence.
Limits
This is a public-disclosure diagnostic, not a penetration test, certification, or claim that an exchange is insecure. The sample can change when stronger official evidence is published.
Return to the diagnostic