CoinGecko updates exchange cybersecurity score with Core3 infrastructure

2 hours ago 17

CoinGecko has swapped out the engine behind its centralized exchange Trust Score, migrating from the old CER.live platform to CORE3, a risk intelligence tool built by blockchain security firm Hacken. The change affects how 166 centralized exchanges are graded on cybersecurity, and the early results paint a pretty unflattering picture of the industry’s security hygiene.

Under CORE3’s expanded evaluation of 193 exchanges, roughly 48% offer zero evidence of proof of reserves, penetration testing, or bug bounty programs. Only about 5.2% of assessed exchanges checked all three boxes.

How the new scoring works

CORE3 introduces what it calls a Probability of Loss (PoL) framework, which is essentially a structured way to estimate how likely it is that an exchange loses your money. The system evaluates exchanges across three pillars: security at 50% weight, solvency at 30%, and transparency at 20%.

That’s a meaningful expansion from CER.live’s narrower focus, which concentrated primarily on pure security metrics. The new model acknowledges something the industry learned the hard way through collapses like FTX: an exchange can have decent technical security and still be insolvent.

The broader CoinGecko Trust Score itself layers CORE3’s cybersecurity assessment into a wider formula. Liquidity carries the heaviest weight at 50%, followed by cybersecurity at 20%, regulation at 15%, incident history at 10%, and proof of reserves at 5%. Updated scores will appear on CoinGecko within 48 hours of any changes.

The path to this update

CoinGecko laid the groundwork across several updates over the past year. The “Basilisk Update” in May 2026 refined the Trust Score methodology, while enhancements to proof-of-reserves tracking rolled out in January 2026.

Guidance documentation for the new system was published on CoinGecko’s support pages on August 6, 2026, with the formal implementation landing on September 2, 2026.

Hacken, the firm behind CORE3, has built its reputation on smart contract audits and blockchain security assessments. Its involvement adds a layer of third-party credibility to the scoring process, with the cybersecurity component now relying on an independent security specialist’s methodology rather than CoinGecko’s own internal rubric.

What the numbers reveal about exchange security

The 48% figure is the one that should make traders pause. Nearly half of the exchanges evaluated by CORE3 couldn’t demonstrate compliance with any of three foundational security practices: proof of reserves, penetration testing, or bug bounty programs.

Proof of reserves is the practice of cryptographically demonstrating that an exchange actually holds the assets it claims to hold. Penetration testing, where hired security professionals attempt to breach an exchange’s systems to find vulnerabilities, is standard practice in traditional finance and enterprise tech. Bug bounty programs pay independent researchers to find and report security flaws.

On the other end of the spectrum, the 5.2% of exchanges that satisfied all three criteria represent a small but growing cohort positioning themselves for institutional-grade trust.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article