CCA Cryptocurrency Exchange & Custody Auditing 1 — Questions and Answers
Question 1: When auditing a cryptocurrency exchange, which control is most critical for verifying that customer assets are properly segregated from exchange operating funds?
- Proof-of-reserves attestation (Correct answer)
- Multi-signature wallet policy review
- KYC documentation review
- Trading volume reconciliation
Correct answer: Proof-of-reserves attestation
Proof-of-reserves attestation cryptographically proves that an exchange holds sufficient assets to cover all customer balances, directly verifying proper asset segregation.
Question 2: A custodian claims to use 'cold storage' for 95% of client assets. Which audit procedure best verifies this claim?
- Review internet connectivity logs for cold wallet addresses (Correct answer)
- Inspect network firewall configurations
- Confirm cold wallet address balances against customer ledger totals
- Review employee access badges to the server room
Correct answer: Review internet connectivity logs for cold wallet addresses
Reviewing internet connectivity logs for the claimed cold wallet addresses verifies they have never been connected online, confirming true air-gapped cold storage.
Question 3: Which risk is most unique to auditing a cryptocurrency exchange compared to a traditional securities exchange?
- Irreversibility of on-chain transactions (Correct answer)
- Front-running by market makers
- Settlement failure risk
- Counterparty credit risk
Correct answer: Irreversibility of on-chain transactions
The irreversibility of confirmed blockchain transactions means unauthorized transfers or errors cannot be reversed, creating a unique and permanent loss risk not found in traditional finance.
Question 4: An exchange uses an omnibus wallet for all customer deposits. What is the primary internal control concern an auditor should flag?
- Inability to individually attribute on-chain balances to specific customers without off-chain records (Correct answer)
- Excessive transaction fees
- Lack of multi-signature approvals
- Slow deposit confirmation times
Correct answer: Inability to individually attribute on-chain balances to specific customers without off-chain records
An omnibus wallet comingles all customer funds in a single address, so accurate individual balances depend entirely on the exchange's internal off-chain ledger, creating a significant reconciliation and fraud risk.
Question 5: During a cryptocurrency custody audit, the auditor discovers that private keys are split using Shamir's Secret Sharing among five key holders requiring three to reconstruct. What does this arrangement primarily address?
- Single point of failure for key compromise (Correct answer)
- Regulatory reporting obligations
- Customer withdrawal speed
- On-chain transaction costs
Correct answer: Single point of failure for key compromise
Shamir's Secret Sharing eliminates a single point of failure by requiring a threshold of key holders to collaborate, preventing any one individual from unilaterally accessing funds.
Question 6: Which metric is most relevant when assessing liquidity risk during an exchange audit?
- Ratio of hot wallet holdings to average daily withdrawal volume (Correct answer)
- Total trading volume over the past 30 days
- Number of listed trading pairs
- Server uptime percentage
Correct answer: Ratio of hot wallet holdings to average daily withdrawal volume
Comparing hot wallet holdings to average daily withdrawal volume shows whether the exchange keeps enough liquid assets readily available to meet normal customer redemption demand.
When auditing a cryptocurrency exchange, which control is most critical for verifying that customer assets are properly segregated from exchange operating funds?