Service
Crypto Exchange Cold Storage Operations — Institutional Custody Procedures
Cold storage holds the majority of customer assets in offline, air-gapped systems. The procedures for accessing cold storage are as important as the technical architecture — both must be documented, tested, and audited.
Air-gapped computers (never connected to internet after key generation). Hardware Security Modules (HSMs) in FIPS 140-2 Level 3 certified offline devices. Dedicated Ledger Enterprise or Trezor hardware wallets for smaller exchanges.
1. Dedicated air-gapped machine — factory reset, never previously connected 2. OS installed from verified ISO, hash verified against official checksum 3. Key generation software run in offline environment 4. Multiple parties present (N-of-M signers) — ceremony must be witnessed 5. Key shares generated and distributed t...
Minimum 3-of-5 multi-signature required for any cold withdrawal. Signers: geographically distributed (different cities, countries for large exchanges). Organizational distribution: 2 signers from exchange, 1 from independent custodian, others from board members or investors. Signer devices: HSM, Ledger Enterprise, or T...
STANDARD COLD WITHDRAWAL PROCEDURE Trigger: Hot wallet balance falls below 2% of total assets Step 1 — Request initiation - Treasury operations creates withdrawal request - Documents: amount, destination (hot wallet address), business justification - Requires sign-off from: CFO or CEO + Compliance Officer - 24-hour wai...
Self-audit (quarterly): - Verify cold wallet balances on-chain against expected amounts - Confirm signer access credentials are current (no departed employees as signers) - Test signing procedure with small test transaction - Verify backup key shares are accessible and decryptable Third-party audit (annual): - Independ...
Common integrations: The Graph, Alchemy/Infura, OpenZeppelin Defender, and popular wallet providers.
Clarify requirements, compliance needs, architecture risks, and launch goals.
Implement core contracts, integrations, product flows, tests, and deployment automation.
Run QA, prepare audit handoff, deploy infrastructure, and support production rollout.
On-chain balance verification: daily (automated, compares expected vs actual balance). Physical signer access verification: quarterly. Full signing procedure test: semi-annually. Third-party proof-of-reserves audit: annually. FTX failed not because cold storage was technically broken but because customer assets were lent out without customer knowledge — on-chain verification alone cannot detect off-chain misuse of hot wallet assets.
Schedule a discovery call and receive a tailored scope and estimate. No commitment required.