The growth of digital assets has created unprecedented opportunities in payments, investment, financial inclusion, and asset tokenization. Virtual Asset Service Providers (VASPs), including cryptocurrency exchanges, custodians, brokers, and wallet providers, have become critical components of this ecosystem. Yet, the history of digital assets is also marked by major failures, including exchange collapses, cyberattacks, fraud schemes, money laundering cases, and governance breakdowns that have resulted in billions of dollars in losses.
These incidents demonstrate that while blockchain technology may be innovative, the risks surrounding digital assets are often familiar: poor governance, weak controls, inadequate oversight, and ineffective risk management. For VASPs, the challenge is not only to innovate but also to build a control environment that protects customers, assets, and market integrity.
1. Cybersecurity Risk:
Cybersecurity remains one of the most significant risks in the digital asset industry because digital assets can be transferred almost instantly and often irreversibly. Unlike traditional banking fraud, stolen cryptocurrency can be quickly moved across wallets and jurisdictions, making recovery extremely difficult.
Several high-profile incidents illustrate this risk. In 2014, Mt. Gox, then the world’s largest Bitcoin exchange, collapsed after losing approximately 850,000 Bitcoins through what was believed to be a combination of hacking and operational weaknesses. More recently, the Ronin Network breach in 2022 resulted in over $600 million being stolen after attackers compromised validator nodes supporting the Axie Infinity ecosystem. In 2025, Bybit suffered one of the largest cryptocurrency thefts in history when attackers exploited weaknesses associated with wallet infrastructure and transaction authorization processes.
These incidents demonstrate that sophisticated attackers often target weaknesses in systems, processes, and access controls rather than blockchain technology itself.
To mitigate such risks, VASPs should implement layered cybersecurity controls including multi-factor authentication, privileged access management, network segmentation, continuous security monitoring, penetration testing, and Security Operations Centre (SOC) monitoring. Equally important is a strong incident response capability that enables rapid detection, containment, investigation, and recovery.
2. Custody Risk:
The principle “not your keys, not your crypto” reflects one of the most fundamental risks in digital assets. Ownership of crypto-assets depends entirely on possession and control of private keys.
The collapse of QuadrigaCX in 2019 remains one of the most cited examples of custody risk. Following the death of the founder, the exchange allegedly lost access to wallets containing hundreds of millions of dollars in customer assets because key management processes were concentrated around a single individual. The event exposed severe weaknesses in governance, segregation of duties, and business continuity planning.
VASPs must therefore treat private key management as a critical control function. Best practice includes the use of Hardware Security Modules (HSMs), Multi-Party Computation (MPC), multi-signature wallets, and cold storage solutions. Customer assets should be protected through dual authorization processes, formal key generation ceremonies, secure backup procedures, and periodic independent audits of custody arrangements. No individual should ever have unilateral control over customer assets.
3. Fraud, Money Laundering, and Financial Crime Risk
Digital assets offer speed, accessibility, and pseudonymity, characteristics that can make them attractive to criminals.
The shutdown of the cryptocurrency mixer Tornado Cash highlighted concerns around the use of digital assets to obscure transaction trails and facilitate money laundering. Similarly, several major exchanges have faced enforcement actions for deficiencies in anti-money laundering controls and sanctions screening processes.
Fraud also remains widespread. Numerous rug pulls, Ponzi schemes, and investment scams have exploited investors’ limited understanding of emerging technologies. The collapse of projects such as OneCoin illustrates how weak governance, misleading disclosures, and inadequate investor due diligence can lead to significant consumer harm.
To manage these risks, VASPs need comprehensive Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) frameworks. These should include Know Your Customer (KYC) procedures, sanctions screening, Politically Exposed Person (PEP) monitoring, transaction monitoring systems, blockchain analytics tools, suspicious activity reporting processes, and Travel Rule compliance controls.
Effective financial crime controls should aim not only to satisfy regulators but also to detect unusual patterns before they become major incidents.
4. Governance Risk:
Perhaps no failure better illustrates governance risk than the collapse of FTX in 2022. FTX was once valued at over $30 billion and was considered one of the most influential players in the cryptocurrency industry. However, investigations following its bankruptcy revealed significant governance deficiencies, including weak board oversight, poor record keeping, conflicts of interest, inadequate risk management, and alleged misuse of customer funds. The collapse highlighted that even technologically advanced organizations can fail when governance fundamentals are ignored.
For VASPs, governance controls should include an independent board, clearly defined accountability structures, effective risk committees, conflict-of-interest policies, independent compliance and risk functions, and regular management reporting. A robust Three Lines of Defense model can ensure that business units, risk functions, and independent assurance teams each perform their respective oversight responsibilities. Strong governance often serves as the first line of defense against all other risk categories.
5. Operational and Resilience Risk
Many digital asset failures occur not because of malicious attacks but because of operational weaknesses.
Exchange outages during periods of market volatility have repeatedly prevented customers from executing trades. Such disruptions can result in financial losses, customer complaints, and reputational damage.
Operational risk extends beyond technology failures to include human error, process breakdowns, inadequate change management, and weak third-party oversight.
VASPs should establish comprehensive operational risk frameworks supported by Risk and Control Self-Assessments (RCSAs), Key Risk Indicators (KRIs), incident reporting procedures, root-cause analysis programs, and operational loss databases. Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs) should be tested regularly to ensure that critical services can be restored following disruptions.
As digital asset markets operate continuously, resilience requirements are often more demanding than those of traditional financial institutions.
6. Third-Party Risk:
Most VASPs depend extensively on external service providers for cloud infrastructure, custody solutions, blockchain analytics, payment services, and identity verification.
Failure of a critical vendor can expose a VASP to significant operational and compliance risks. The interconnected nature of the digital asset ecosystem means that a disruption affecting one provider can quickly spread throughout the market.
A robust third-party risk management program should require vendor due diligence, contractual security requirements, ongoing performance monitoring, independent assurance reviews, and contingency arrangements for critical providers. Critical vendors should be subject to the same level of scrutiny as internal operations.
Recommended Controls for VASPs
A mature VASP should implement a control framework built around five core pillars:
1. Governance and Risk Management
- Board Risk Committee oversight
- Enterprise Risk Management framework
- Three Lines of Defense model
- Risk appetite statement
- Independent compliance and internal audit functions
2. Cybersecurity and Asset Protection
- Multi-factor authentication
- Cold storage custody arrangements
- Multi-signature or MPC wallets
- Security Operations Centre monitoring
- Penetration testing and vulnerability management
- Privileged access management
3. Financial Crime Compliance
- KYC and customer due diligence
- Transaction monitoring
- Blockchain analytics
- Sanctions screening
- Travel Rule compliance
- Suspicious transaction reporting
4. Operational Resilience
- Business continuity planning
- Disaster recovery testing
- Incident management procedures
- Change management controls
- Operational risk monitoring
5. Custody and Safeguarding
- Segregation of customer and corporate assets
- Daily reconciliations
- Independent custody audits
- Dual authorization requirements
- Formal key management processes
Conclusion
The digital asset industry has repeatedly shown that technology alone cannot eliminate risk. The failures of Mt. Gox, QuadrigaCX, Ronin Network, and FTX all reveal a common theme: weaknesses in governance, controls, and risk management often matter more than weaknesses in blockchain technology itself.
For VASPs, sustainable success depends on building trust through strong governance, rigorous cybersecurity, effective financial crime controls, resilient operations, and sound custody practices. Organizations that learn from past failures and invest in a comprehensive control environment will be better positioned to protect customers, satisfy regulators, and thrive in an increasingly regulated digital asset ecosystem.

