Cold storage by default
Client assets are held in air-gapped multi-signature vaults spread across three jurisdictions. Withdrawals from cold storage need quorum approval from separate key holders.
Every exchange says it is safe. This page explains exactly where client assets sit, who can move them, what we publish each month, and what happens if any of it goes wrong.
Client assets are held in air-gapped multi-signature vaults spread across three jurisdictions. Withdrawals from cold storage need quorum approval from separate key holders.
We publish a Merkle-tree attestation every month so you can verify your own balance is included in total reserves, alongside a liabilities report from an independent auditor.
A dedicated fund covers losses from platform failure or a breach of our custody stack, backed by a syndicate policy and an on-chain reserve you can inspect.
Hardware key support, withdrawal allow-lists, per-device session control and a 24-hour hold on any new withdrawal address. No customer account has been drained on our watch.
On the first business day of each month we publish a Merkle tree of every client balance alongside an independent report of what we hold on-chain. Your account page gives you a leaf hash and the path to the root, so you can verify your balance was counted without seeing anyone else's.
| Asset | Held | Owed to clients | Coverage |
|---|---|---|---|
| BTC | 42,118 | 102.2% | |
| ETH | 388,402 | 101.7% | |
| SOL | 1,942,600 | 101.7% | |
| USDC | 612,480,000 | 101.4% | |
| USDT | 418,900,000 | 101.5% |
Figures shown are an illustrative sample of the published report. Coverage above 100% reflects our own capital held alongside client assets.
Client assets are segregated from company funds, are never lent out, and are never used as collateral for anything we do. Moving anything out of cold storage takes several people in several places.
Most losses in this industry start with a compromised account, not a compromised exchange. These controls are free, and we would rather you turned all of them on.
Our bounty programme is open to everyone, has no maximum payout cap for asset-loss reports, and we publish a median triage time of under six hours.
Theft of client assets, remote code execution, authentication bypass
Privilege escalation, order book manipulation, sensitive data exposure
Stored cross-site scripting, broken access control on account data
Rate limit bypass, information leaks with limited impact
Aurex holds registrations in each market it serves, and we do not operate in a jurisdiction before the paperwork is finished.
Registration is not an endorsement, and it does not protect you from market losses. Digital assets are not covered by deposit guarantee schemes in any of the jurisdictions listed above.