Cryptocurrency Exchange & Custody Auditing Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Cryptocurrency Exchange & Custody Auditing flashcards as text
What is the primary purpose of a Merkle tree proof in a cryptocurrency exchange proof-of-reserves audit?
Answer: To allow individual users to verify their balance is included in the total reserve without revealing other users' data
A Merkle tree proof lets each customer verify their specific balance is included in the aggregated reserve total while keeping all other users' balances private.
An auditor finds that exchange withdrawal approval requires only a single authorized employee's digital signature. Which control framework principle does this violate?
Answer: Segregation of duties
Requiring only one approver for withdrawals violates segregation of duties, as a single actor can unilaterally move customer assets without independent oversight.
Which type of wallet arrangement presents the highest operational security risk for a cryptocurrency custodian?
Answer: Hot wallet with keys stored on an internet-connected server
Hot wallets with keys on internet-connected servers are the highest risk because network exposure makes private keys vulnerable to remote theft or hacking.
During an exchange audit, the auditor notices customer deposit addresses are reused for multiple clients. What is the primary audit concern?
Answer: It makes it impossible to attribute individual deposits to customers without off-chain ledger records
Reusing deposit addresses across multiple customers means that on-chain data alone cannot identify which customer made a deposit, creating a complete reliance on the exchange's internal records for attribution.
A cryptocurrency exchange's audit reveals a discrepancy between the on-chain wallet balance and the internal customer ledger. What is the auditor's immediate next step?
Answer: Trace all deposits and withdrawals on-chain against ledger entries to identify the source of the discrepancy
The auditor should perform a detailed on-chain trace to reconcile every transaction against the internal ledger to identify whether the discrepancy is a recording error, theft, or fraud.
What is 'rehypothecation risk' in the context of cryptocurrency custody auditing?
Answer: The risk that a custodian pledges or lends customer assets without their knowledge or consent
Rehypothecation risk is the danger that a custodian uses customer-deposited assets as collateral or loans them out, meaning they may not be fully available when customers request withdrawal.