Loading market data...

ESMA Launches Crypto Custody Review as Bridge Hack and Exchange Shutdown Raise Alarm

ESMA Launches Crypto Custody Review as Bridge Hack and Exchange Shutdown Raise Alarm

European securities regulator ESMA this week kicked off a coordinated review of crypto firms' operational resilience, with a specific focus on custody. The probe, which runs into 2027 and will end with a public report, comes as a bridge hack drained 24.15 million USDC from an Arbitrum-based platform and as AscendEX ceased operations, leaving users uncertain about withdrawals.

ESMA's year-long probe

ESMA's review, launched in July 2026, targets how crypto firms handle custody — the safekeeping of digital assets. The regulator is examining hot, cold, and qualified custody arrangements. Qualified custody involves a regulated entity with legal segregation and auditability. The review is expected to produce recommendations for the industry by 2027. It's the first EU-wide review of its kind focused on custody, and it covers both hot and cold custody models.

Bridge hack: hot keys compromised

On Arbitrum, a bridge tied to the AFX Trade platform was drained of approximately 24.15 million USDC after attackers compromised hot validator keys. The stolen funds were moved to Ethereum and swapped into ETH, likely to obfuscate the trail. The incident underscores the risks of hot custody, where signing keys remain online to enable instant settlement but expose a larger attack surface. Cold custody, by contrast, keeps keys offline, reducing remote attack risk but slowing workflows.

AscendEX goes dark

AscendEX ceased operations effective July 1, 2026. The exchange paused automated withdrawals, shifted to manual review, and warned it could not assure timing or amounts of withdrawals. Users are left in limbo, with no clear timeline for fund recovery. The shutdown adds to a growing list of exchange failures that regulators are now scrutinizing.

Industry response: Bitcoin Security Consortium

In response to rising security concerns, BlackRock, Coinbase, Fidelity Digital Assets, and others formed the Bitcoin Security Consortium in July 2026. The group pledged $15 million over three years for Bitcoin security research, including post-quantum cryptography. The consortium aims to develop best practices for custody and key management, addressing vulnerabilities exposed by recent incidents. It signals a shift toward industry self-regulation among major players.

Custody basics: hot, cold, qualified

The ESMA review and the recent hacks shows the importance of custody models. Hot custody means signing keys are online, enabling instant settlement but increasing attack surface. Cold custody keeps signing offline, reducing remote attack surface but slowing workflows. Qualified custody involves a regulated entity with legal segregation and auditability. A typical cold-to-hot workflow for a fund involves a portfolio manager request, operations verification, multi-signer approval, offline transaction assembly, and signature production via an air-gapped device or HSM. Each step adds friction but reduces risk.

AscendEX users are still waiting for clarity on whether they will recover their funds, while ESMA's findings are not expected until 2027. The Bitcoin Security Consortium's work is just beginning.