Skip to content
Beginner Guides

What “Regulated Exchange” Actually Means

The word "regulated" carries very different weight depending on which regulator, for what, and under which regime. Here is how to read the claim.

Incident Tracker

All incidents →
Disclosed Incident Chain Reported impact Status
Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check
Signing interface compromise · Supply chain
Ethereum approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 Feb 2025) Resolved
WazirX Multisig Compromise, July 2024: What Happened & What to Check
Key compromise · Signing interface compromise
Ethereum approx. US$234.9 million(WazirX, 18 Jul 2024) Contained
DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check
Key compromise
Bitcoin 4,502.9 BTC(DMM Bitcoin, 31 May 2024) Resolved
Ledger Connect Kit Supply Chain Attack, December 2023: What Happened & What to Check
Supply chain · Wallet drainer
Ethereum approx. US$600,000(Ledger, 14 Dec 2023) Resolved
Curve Finance Vyper Compiler Reentrancy, July 2023: What Happened & What to Check
Reentrancy · Toolchain
Ethereum approx. US$70 million across affected pools(Curve Finance, 31 Jul 2023) Resolved
Euler Finance Donation Attack, March 2023: What Happened & What to Check
Business logic · Flash loan
Ethereum approx. US$197 million (substantially all returned)(Euler Labs, 13 Mar 2023) Resolved

Latest

What Conisec covers

Conisec is an independent publication covering crypto security incidents, exploits and regulation. We report on what broke, who it touched, and what the rules now say — across exchanges, protocols, wallets and jurisdictions. We are not a price site, and we do not make market calls.

Every security, incident and regulatory story carries The Ledger: four fixed lines telling you what happened, who's exposed, how to verify it yourself, and what materially changes. The verification line is the point — Conisec never asks to be trusted, it hands you the check. The Ledger is descriptive and procedural. It is not financial, legal, tax or security advice, and it never tells anyone to move funds.

Every row in the Incident Tracker and every field on a jurisdiction page cites a primary document — an official advisory, a post-mortem, a court filing or a regulator notice. If a claim cannot be sourced, it does not publish. How we source, verify and update is written out in full on our methodology page, alongside who we are, our regulation coverage and our security tips.

Frequently asked

What is Conisec?
Conisec is an independent publication covering crypto security incidents, exploits, and regulation. We track what broke, who it affected, and what the rules say — and we cite a primary document for every claim.
What is "The Ledger" on your stories?
The Ledger is a fixed four-line panel on every security, incident and regulatory story: what happened, who's exposed, how to verify it yourself, and what changes. The verification line is the point — we hand you the check rather than asking you to trust us.
Where do your incident details come from?
Primary sources only: official project post-mortems, exchange status pages, security-firm advisories, regulator notices, court filings and on-chain records. Secondary reporting may corroborate a fact but never stands alone for a loss figure, an attribution or a legal characterisation. If it cannot be sourced, it does not publish.
Is anything on Conisec financial, legal or security advice?
No. Everything we publish is for information only. We do not issue buy or sell calls, we do not give legal or tax advice, and we never tell a reader to move funds, revoke an approval or interact with a contract address. We link the official advisory and let the issuer's own instructions stand.
Are your writers real people, and do you use AI?
Every public byline on Conisec is a real, named person. We do not publish under "admin" and we do not invent staff, bios, photos or credentials. Our editorial guidelines state plainly whether and how AI assists our work; a human is accountable for every published claim.
How do I report a correction or a missing incident?
Use our contact page. Corrections are appended and dated on the article itself — never silently rewritten — and logged publicly on our corrections page.