CZ Warns Crypto Exchange Acquisitions May Carry Legacy Security Risks
Key Takeaways
- •Zhao warned that acquiring a crypto exchange can transfer hidden security weaknesses to the buyer.
- •Legacy systems may include outdated code, aging infrastructure, and weaknesses affecting customer accounts or stored assets.
- •He said technical due diligence should examine infrastructure before customer funds are moved to an acquired platform.
- •Zhao previously noted that smaller exchanges are often more vulnerable because they typically have fewer security resources than larger rivals.
- •The warning comes amid continued mergers and acquisitions across the digital asset sector.

Changpeng Zhao, widely known as CZ, has warned that crypto exchange acquisitions can bring inherited security weaknesses that create significant risks for buyers and users.
Buying a trading platform may appear to be a fast way to gain customers, liquidity, and market share. However, Zhao said security should be a central concern in any takeover because serious vulnerabilities can remain hidden beneath an exchange’s public brand and operating history. In his view, security problems inherited from a smaller exchange can become costly liabilities for the acquiring company.
Legacy Systems May Become a Major Liability in Exchange M&A
CZ argued that acquiring an exchange involves taking ownership of more than customer accounts and trading activity. Buyers may also inherit aging infrastructure, outdated codebases, and security weaknesses that have accumulated over several years of operation.
Those risks are especially important in crypto because exchanges often manage account access, wallet infrastructure, private-key controls, and transaction systems that directly affect customer assets. Weaknesses in any of those layers can remain difficult for outside users to evaluate, making technical due diligence a central part of any acquisition process.
Addressing those problems after a transaction closes can require substantial time, staff, and financial resources. In some cases, Zhao suggested, rebuilding parts of a platform may be less expensive and more practical than trying to repair the existing infrastructure.
His latest comments are consistent with earlier remarks. In February 2020, Zhao said hackers often target smaller exchanges because they generally do not have the same level of protection as larger competitors. Larger platforms can allocate more personnel and funding to security, while smaller operators often work with tighter budgets and fewer specialized staff.
Poorly Secured Platforms Can Transfer Cyber Risk to New Owners
Several areas require close attention during any crypto exchange takeover. Legacy software may contain flaws that attackers already know how to exploit. Older security practices can expose customer accounts and stored assets. Delays in migration can leave acquired systems operating longer than intended. Security reviews should also examine infrastructure before customer funds are transferred.
For acquirers, the issue is not limited to whether an exchange is operational at the time of purchase. Past design choices, undocumented systems, third-party integrations, and incomplete migration work can all affect how safely a platform can be absorbed into a larger business. These concerns can also matter to customers who may not know when backend systems are being replaced or consolidated.
Zhao’s comments come as mergers and acquisitions continue across the digital asset sector. Binance, which launched in 2017, grew into the world’s largest crypto exchange. Zhao later stepped down as chief executive in 2023 amid increasing regulatory pressure. His memoir, Freedom of Money, published on April 8, 2026, discusses Binance’s rapid expansion and the legal challenges that followed.
Exchange acquisition announcements can raise questions about security audits, migration plans, and legacy systems before assets are moved. While recent discussions involving Zhao have often centered on regulation and future quantum computing risks, he has argued that inherited security flaws deserve more immediate attention. Unlike distant technological threats, poorly secured systems can become targets for attackers using tools that are already widely available.