Advisory · 24 August 2026

Nested exchange cybersecurity

Securing the operator-host chain.

A nested exchange arrangement lets a customer-facing operator provide virtual asset trading or related services through an account, subaccount or API at another exchange. The model can expand access and reduce infrastructure cost, but it also divides control and evidence between organisations; where assets or activity are pooled, one compromised credential, privileged role or master account can affect many customers at once.

Zanarc’s Nested Exchange Cybersecurity Advisory examines the risks across the complete operator-host chain. It provides practical guidance on host access and execution authority, API credentials, pooled custody, reconciliation and forensic evidence, customer applications and domains, monitoring, incident response, and continuity and exit readiness.

Download the advisory to assess the cybersecurity considerations relevant to your nested service arrangement. Nested operators, host exchanges and their supervisors may also contact Zanarc to request a confidential briefing on selected findings from the research behind the advisory.

Register your email address to download the advisory.

Register to download

What the advisory covers

Written for boards, executives, regulators, host exchanges, nested operators, auditors and security teams. Inside the advisory:

Zanarc advisory: Nested Exchange Cybersecurity, securing the operator-host chain. Advisory, 24 August 2026, 30 pages.

A three-party control chain

How authority and evidence divide across customers, the nested operator and the host exchange, and why ordinary failures can amplify.

Nine risk domains

From pooled custody and API credentials to privileged access, reconciliation, host dependency and recursive nesting.

Incident lessons

Control lessons from published incidents at 3Commas, Curve, Bybit and Coinbase, mapped to the nested service model.

Control priorities

Host access and execution authority, an independent ledger, application and supplier security, monitoring, incident response and exit readiness.

Minimum control baseline

Ten control objectives, each with the minimum expectation and the evidence to retain.

Assurance and oversight

What an assessment should cover, with questions for boards, regulators and host exchanges.

Frequently asked questions

About the advisory, the registration process, and Zanarc.

Who is the advisory written for?

Boards, executives, regulators, host exchanges, nested operators, auditors and security teams. Section 6 sets out the questions most relevant to boards and senior management, and to regulators and host exchanges.

Is the advisory free?

Yes. Register your email address and your copy of the 30-page PDF will be sent to your inbox.

How will my email address be used?

To deliver the advisory and, where you have opted in, occasional updates from Zanarc on digital asset cybersecurity. You can unsubscribe at any time.

What is a nested exchange?

A nested exchange arrangement allows a customer-facing operator to provide virtual asset trading or related services through an account, subaccount, API or technology connection at another exchange. The host may provide execution, custody, liquidity, settlement or platform functions while the operator manages the customer relationship and its own internal records. The term describes a service arrangement, not a legal classification.

Does the advisory replace NIST, ISO/IEC, or OWASP guidance?

No. Existing standards and regulatory rulebooks cover parts of a nested arrangement, and the advisory sets out what each contributes and where it stops. No single source assesses the complete operator-host transaction path across the accounts, interfaces, permissions, suppliers and recovery procedures actually used; the advisory addresses that gap.

Who is Zanarc?

Zanarc is a specialist blockchain and digital asset cybersecurity consultancy. It advises virtual asset platforms and their supervisors, conducts CryptoCurrency Security Standard (CCSS) readiness assessments and audits, and assesses cybersecurity risks arising from artificial intelligence, real-world asset tokenisation and nested exchange arrangements.

Register to download the advisory

A nested service divides control and evidence between the operator and the host, and a licence or certification alone does not prove the complete transaction path is secure. The advisory sets out where failures amplify, and the controls nested operators, host exchanges and their supervisors should put in place.