Keeping a large balance on an exchange is convenient. Your assets are within reach, a trade takes seconds, and access can be restored through a password or support. That convenience carries a cost that is easy to overlook. The balance in your account reflects the exchange's obligation to you, while the actual coins on the blockchain stay under the platform's control. As long as the sum is modest, the distinction barely registers. Once tens or hundreds of thousands of dollars are involved, every hidden risk starts to cost far more. The sections below break down what that risk actually consists of, drawing on events from 2025 and the first half of 2026.
The Main Risk: The Private Keys Are Not Yours
When cryptocurrency sits on an exchange, the platform holds the private keys to the wallets. The user sees figures in the interface and moves them with buttons in a personal account, but real control over the funds stays with the exchange. The industry captures this with the rule "not your keys, not your coins": while the keys are not in your hands, the coins are not truly yours and remain at the service's disposal.
While everything is fine with the platform, the difference stays invisible: withdrawals work and the balance displays correctly. The situation changes the moment the exchange runs into trouble, whether a hack, a freeze, a legal dispute, or bankruptcy. Access to your money then depends on the state of the company and the decisions of its staff rather than on your own will. This is why experienced holders advise against leaving sums on an exchange that would be painful to lose.
The alternative to exchange storage is a personal wallet where only you control the private keys. That approach comes with its own demands: responsibility for keeping the key and the recovery phrase safe falls entirely on the owner. The choice between different wallet types also has a direct effect on the security of a large sum. We covered how the self-custody options differ and which is more reliable for larger holdings in our article on cold and hot crypto wallets.
The Risk of Hacking and Theft
The blockchains of the major networks run reliably, and a computational break of them remains highly unlikely. What comes under fire is everything built around them: exchanges, hot wallets, employee access, and the interfaces through which operations are signed. The technological reliability of Bitcoin or Ethereum does nothing to protect the money a holder keeps in an exchange account.
The figures from the past year and a half show the scale. In February 2025, the Bybit exchange lost about $1.5 billion in Ethereum, the largest cryptocurrency theft in the market's history, and the FBI linked the attack to the North Korean group Lazarus. Across all of 2025, crypto services lost roughly $3.4 billion to theft, by Chainalysis estimates. The first half of 2026 set a new record for the number of incidents, with more than $1.1 billion in losses across 212 confirmed attacks.
The Bybit story has a sequel: the exchange held on and covered the losses through outside financing, so its clients lost nothing. But no user can know in advance which platform will have that kind of resilience and which will not. A large balance on an exchange leaves the holder dependent on a security system they cannot influence in any way. We collected the history of the biggest attacks from Mt. Gox to Bybit, along with an explanation of why the cause usually lies in the infrastructure around the blockchain rather than in the blockchain itself, in a separate article on the largest crypto hacks.
Bankruptcy and Freezes: When the Money Is There but Out of Reach
You can lose access to your money without any hack at all. It is enough for the exchange to run into financial or legal trouble.
When a platform goes bankrupt, its client becomes an unsecured creditor and joins the general queue for repayment. The FTX case shows how long that process can take. The exchange collapsed in November 2022, and payouts to creditors have stretched across years: a fifth round of roughly $900 million went out at the end of July 2026 and brought total repayments to nearly $10 billion, while no date has yet been set for the next tranche. Many classes have formally recovered 100% of their claims or more, but the repayment is calculated at the exchange rate on the bankruptcy date. Creditors missed out on the market's growth over those years, and their money stayed frozen for more than three years.
A perfectly healthy exchange can restrict access too. Deposits go through AML screening, addresses are checked against sanctions lists, and at any hint of suspicion the platform requests re-verification. Large sums draw the attention of compliance more than ordinary transfers do. Examples are well known: MEXC users complained of account freezes when trying to withdraw large amounts, and South Korea's Upbit suspended deposits and withdrawals in November 2025 after an unauthorized outflow of about $36 million from a hot wallet. At moments like these, the fate of your money is decided by the exchange's staff and algorithms, not by you.
Your Account as a Separate Target
Even when the exchange's own vault is secure, the point of entry stays vulnerable: your personal account. This is where phishing, SIM-swapping, social engineering, and leaks of personal data come into play. Large holders are identified and attacked deliberately, because the effort pays off with one successful login.
Coinbase offered a clear example in May 2025, when news emerged of a data leak. Through the bribery of support staff, attackers obtained the personal data of some clients and then used it for targeted fraud. User losses from the social engineering that followed were estimated at around $45 million, even though the exchange's vault itself was never breached. When an entire large balance sits in a single account, the cost of one mistake at login or transaction confirmation rises sharply.
How to Reduce the Risk
Removing the risks of exchange storage entirely is not possible, but bringing them down to a reasonable level certainly is. The basic rules come down to a few points.
- Split your funds by purpose. Keep only the portion you need for active operations and trading on the exchange, and move the main volume to your own wallet, where only you hold the keys. That way a hack or a freeze at the platform touches only a small share of your assets.
- Protect the account as thoroughly as possible. Two-factor authentication through an app or a hardware key, a whitelist of withdrawal addresses, and an anti-phishing code close off most typical attacks on a personal account. SMS is best avoided as a second factor because of the risk of SIM-swapping.
- Assess the platform's transparency. Publishing proof of reserves helps you see whether the exchange's obligations are backed by real assets. It does not remove the need to trust the exchange, but it reduces the uncertainty around reserves.
- Match the counterparty to the task. For a large operation, a clear and supervised partner with a verifiable legal status matters more than a random intermediary. We looked at the reasoning behind that choice in more detail in our article on why large crypto deals go through licensed platforms.
The Bottom Line
Storing a large sum on an exchange comes down to trading control for convenience. On small balances that trade makes sense, because the cost of a mistake is low. On large volumes the imbalance grows expensive: the holder depends at once on someone else's security system, the solvency of the company, and its internal rules. For large sums it is wiser to store the assets yourself and keep control of the keys, and to bring in an exchange or an exchange service only when you genuinely need to carry out a transaction.
