Security and custody

Crypto security and custody at be1crypto.com

Where your coins actually sit, who is able to move them, what our insurance does and does not cover, and the controls only you can switch on.

What be1crypto.com security means in practice

Security at be1crypto.com is not a badge in a footer. It is a set of specific, checkable commitments about where customer assets are stored, how many people it takes to move them, and what happens on the day something goes wrong. This page sets out the custody model in detail, lists the account controls you have to enable yourself, and is deliberately blunt about the two areas where crypto platforms routinely overstate their position: insurance coverage and proof of reserves.

The honest starting point is that custody is a division of responsibility. We are accountable for the keys, the infrastructure and the people with access to both. You are accountable for your credentials, your second factor and the transfers you approve. Most real-world losses in this industry do not come from an exchange being breached. They come from an individual account being taken over, or from a customer being talked into sending funds somewhere themselves. The SEC investor alerts on crypto fraud are worth twenty minutes of reading, whichever platform you use.

Our control framework is mapped to the NIST Cybersecurity Framework and our information security management system follows ISO/IEC 27001. Neither is a guarantee. They are a common vocabulary that makes it possible to audit whether a control exists, whether it runs, and whether anybody checks.

Padlock resting on a laptop keyboard, representing be1crypto.com crypto custody and account security
95% of customer crypto is held offline, across five sites and three jurisdictions.
Custody model

Cold by default, hot by exception

The design goal is simple to state and expensive to build: there should be no single machine, no single site and no single person whose compromise moves customer funds.

Cold storage share
95% of customer crypto, measured daily against total customer balances rather than quoted as a target.
Key material
Generated and held inside FIPS 140-2 Level 3 hardware security modules. Key shares never leave an HSM in plaintext, including during backup.
Geographic split
Five HSM sites across three legal jurisdictions. No single site, and no single jurisdiction, holds enough shares to sign anything.
Signing method
Multi-party computation. The complete private key is never assembled in memory on any machine, at any point, including at signing time.
Withdrawal authorization
A 3-of-5 quorum of custody officers on separate hardware in separate locations. No one person can move funds, and no two can either.
Hot wallet ceiling
A hard 5% cap, enforced in code, with an absolute dollar ceiling that overrides the percentage when balances grow.
Replenishment
Cold-to-hot top-ups run on a fixed schedule with a mandatory delay window, so an attacker cannot drain the hot wallet and trigger an instant refill.

Why multi-party computation instead of multisig

In a conventional setup, a private key exists somewhere in full, at least for the instant it signs. Multi-party computation removes that instant. The key is generated as mathematical shares that are distributed across our HSM sites at creation, and a signature is produced through a protocol run between those shares. The complete key is never reconstructed, not in memory, not on disk, not during backup, not during signing. An attacker who takes total control of one site gets a share, which on its own is useless.

On top of that sits the quorum. Every withdrawal above the automated threshold requires three of five custody officers to approve on separate hardware, in separate locations, against a request they can inspect. The officers are drawn from teams that do not report to one another, so pressuring one person is not a path to anything. If this sounds slow for large withdrawals, it is. That is the trade we chose, and we would rather explain a delay than a loss.

The hot wallet, and why it exists at all

A platform that held 100% of assets offline could not process a withdrawal in under a day. The hot wallet is what makes same-hour withdrawals possible, and it is the honest weak point of every exchange including this one. Ours is capped at 5% of customer assets, enforced in code rather than policy, with an absolute dollar ceiling that takes over when the percentage would allow too large a float. Replenishment from cold storage runs on a fixed schedule with a mandatory delay, which means an attacker who empties the hot wallet cannot trigger an immediate automatic refill and do it again.

Balances that back activity on the trading terminal sit inside that float, which is one reason the terminal settles internally against your ledger balance rather than moving coins on chain for every fill. It is faster, and it keeps on-chain exposure small. Withdrawals leave the float; deposits sweep into cold storage on a schedule.

Insurance

What the policy covers, and what it plainly does not

Insurance is the most misrepresented word in crypto marketing. Here is the version with the limits attached, because the limits are the part that decides whether it ever pays you.

Covered

Our failure, our liability

  • Theft of assets from the hot wallet by an external attacker who breaches our infrastructure.
  • Insider theft, including collusion between employees with custody access.
  • Physical loss, destruction or compromise of key material held at a custody site.
  • Fraudulent transfers executed by someone who compromised our systems rather than your account.
Not covered

Everything outside our control

  • Anyone who signs into your account with your credentials and your 2FA code, however they obtained them.
  • Transfers you authorized yourself, including every transaction sent under the influence of a phishing site or a social engineering call.
  • Market losses. A position that falls 60% is not an insurable event, and no policy anywhere treats it as one.
  • Failure of an asset itself: a stablecoin losing its peg, a chain halting, a smart contract exploit on a token we merely list.
  • Losses on funds you moved into a third-party protocol after withdrawing them from be1crypto.com.
  • Coins sent to a wrong or unsupported address, or to the correct address on the wrong network.

Three qualifications matter more than the headline. First, the crime policy is an aggregate limit held by be1crypto.com, not a per-customer allocation. A single large event can consume it, and there is no scenario in which every customer is individually insured for their full balance. Second, it insures the pooled hot wallet, not the consequences of your own account being accessed. Third, and this applies to every crypto platform operating in the United States: crypto assets are not FDIC or SIPC insured. Uninvested US dollar balances may be held at partner banks with pass-through FDIC coverage up to the standard $250,000 per depositor, subject to the terms set by those banks. Your Bitcoin is not covered by any government scheme, anywhere.

The practical reading: insurance is a backstop against our institutional failure, not a replacement for your own security hygiene, and not a promise that any loss you experience will be made whole. Anyone telling you their platform is fully insured is either being loose with language or hoping you will not read the policy. Our full liability position is written out in the terms and conditions, and the risk framing for products that pay yield sits on the earn page.

Your half of the job

Six account controls worth twenty minutes of your time

Cold storage protects the platform. These protect you. An account takeover bypasses every custody control described above, because the withdrawal looks legitimate to us.

Account security controls available on be1crypto.com, why each one matters and how to enable it
Control Why it matters How to enable
Hardware security key A FIDO2 key checks the website domain before it releases a signature, so a fake login page gets nothing even if you type your password into it. It is the only widely available second factor that resists phishing outright. Security settings, Add security key. Register two and keep the spare somewhere separate from your laptop bag.
Authenticator app (TOTP) Better than SMS and immune to SIM swaps, but still phishable: a convincing fake page can collect the six digits and relay them to the real site within the 30-second window. Security settings, Add authenticator. Store the recovery seed offline, on paper, not in the same password manager.
Withdrawal address allowlist Limits outbound transfers to addresses you added in advance. An attacker inside your session cannot send to an address that is not on the list, which converts a total loss into a failed attempt. Withdrawal settings, Enable allowlist. New entries sit under a 24-hour cooldown before they can receive anything.
Anti-phishing code A short phrase you choose that appears in every genuine email we send. Its absence is a reliable signal that a message did not come from us, and it costs an attacker nothing to be wrong about. Security settings, Set anti-phishing code. Pick something you will recognize at a glance and never post it publicly.
Device and session management Shows every active session with its device, approximate location and last activity time. Sessions are where account takeovers actually live, long after a password has been changed. Security settings, Active sessions. Revoke anything you do not recognize, then rotate your password and re-pair your 2FA.
API key IP allowlisting Binds a key to specific source addresses. A leaked key that only works from your own server is close to worthless to whoever steals it, which is why leaked-key incidents almost always involve unrestricted keys. API management. Set the IP list, grant the narrowest scope the strategy needs, and leave withdrawal permission off unless you genuinely need it.

Why we push hardware keys over SMS codes

SMS is the weakest second factor in common use, and the reasons are concrete rather than theoretical. A SIM swap needs no technical skill at all: an attacker calls your mobile carrier, impersonates you with details scraped from a data breach, and has your number ported to a SIM in their hand. Every code then arrives on their phone. Separately, the SS7 signaling network that routes messages between carriers was designed in an era of trusted operators and can be abused to intercept texts in transit. And even when delivery is clean, an SMS code is a short string you can be talked into typing somewhere. A convincing fake login page collects it and replays it to the real site inside the validity window.

A FIDO2 hardware key fails all three attacks. It is bound to the origin, so it simply will not produce a signature for a domain that is not ours. There is no code to read out, no number to port, and nothing useful to intercept. If a key is not practical for you, an authenticator app is a clear improvement on SMS. We still support SMS as a last resort, because no second factor at all is worse than a weak one, but we do not recommend it and we will keep saying so. If you are setting up a new account, work through how the platform works first, then harden the account before you fund it.

Organizational controls

The controls that apply to our own people

Technology is the easy half. Most catastrophic exchange failures were governance failures first, where one person had access nobody was reviewing.

SOC 2 Type II

Audited annually against the security, availability and confidentiality criteria. Type II matters because it tests whether controls operated over a period, typically twelve months, rather than whether they existed on the day the auditor visited. The report is available to institutional clients under NDA.

Two penetration tests a year

Commissioned from two different independent firms so neither gets comfortable with our architecture. Scope covers the web platform, the mobile apps, the API surface and the internal network. Critical and high findings are remediated before the engagement closes.

Bug bounty, $250 to $120,000

Paid by severity, with the top band reserved for anything touching customer funds or the custody path. Researchers get a safe harbor commitment in writing. We publish anonymized summaries of paid reports so the program is visible rather than decorative.

Least privilege and access reviews

Engineers get the narrowest production access their role requires, time-bound and logged. Every entitlement is re-certified quarterly by the system owner, and anything not actively defended in that review is removed rather than renewed by default.

Background checks and separation of duties

Criminal, employment and sanctions screening before any role with production or custody exposure. No individual can both initiate and approve a movement of customer assets, and the custody quorum is drawn from people who do not report to each other.

Monitoring that a human reads

Withdrawal patterns, login anomalies and infrastructure telemetry feed a security operations rota with 24/7 coverage. Alerting is tuned so that a page at 3am means something, because a team that ignores its own alerts has monitoring in name only.

Rows of server racks in a data center supporting be1crypto.com infrastructure security
Production infrastructure runs in tier III+ facilities with segmented networks, hardware two-factor authentication for every operator and full audit logging of privileged sessions.
Proof of reserves

Proof of reserves, and the limitation nobody advertises

Each quarter we publish a reserves attestation at a fixed block height. It contains the on-chain addresses we control, with signed messages proving control, and a Merkle tree of customer balances. Your account page shows your leaf hash and the path to the published root, so you can verify that your own balance was included in the total the auditor checked. That verification takes about a minute and does not require you to trust us for the arithmetic.

Here is what it does not prove

A proof of reserves demonstrates assets. It says nothing about liabilities. A platform can hold visible coins at a snapshot and still owe far more than it holds, because obligations to lenders, counterparties and other customers do not appear on chain. It is also a point-in-time measurement: coins can be borrowed for the snapshot block and returned the following day, a maneuver that has been observed in this industry more than once. A reserves proof on its own is compatible with insolvency.

It becomes meaningful only when paired with an independent liability attestation: an accounting firm verifying that total customer liabilities are no greater than the verified reserves, under an agreed-upon-procedures engagement with its scope published. We commission that liability side alongside the asset side, and we publish both together with the engagement scope attached, because the asset half alone is closer to marketing than to assurance. If a platform shows you a reserves number and no liability figure, the correct response is to ask why, not to feel reassured. You can independently sanity check reported balances against public chain explorers and aggregate data on CoinGecko.

Incident response

What happens when something goes wrong

Every platform has incidents. The difference is whether there is a rehearsed procedure and whether you hear about it from the company or from a stranger on social media.

  1. Detect and contain

    Automated detection or a human report opens an incident. The first action is containment: freeze the affected withdrawal path, rotate credentials, isolate the host. Availability is sacrificed for containment every time, which is why you may occasionally see withdrawals paused with no explanation yet.

  2. Assess scope

    A named incident commander establishes what was reached, what was taken and which accounts are affected. Nothing is communicated as fact until it has been verified against logs, because a wrong first statement is worse than a slow one.

  3. Notify

    For any confirmed incident that materially affects customer assets or personal data, a public notice goes out within 24 hours of confirmation. Personal data breaches are additionally reported to the relevant supervisory authority within 72 hours, as described in our privacy policy.

  4. Publish the post-mortem

    A written post-mortem within 14 days: the root cause, the timeline, what we fixed and what we got wrong. We commit to not quietly patching a customer-affecting incident and never mentioning it. That commitment is worth checking us on.

Suspect your account is compromised? Do not wait for a reply before acting. Revoke your active sessions, then contact us through the channels on the contact page, which lists our verified support routes. How we handle the personal data involved in an investigation is documented in the privacy policy.

Phishing defense

Eight red flags that mean stop

Phishing is the single most common way people lose crypto. It does not require any weakness in the platform, which is exactly why it works.

  • Any message telling you to move funds to a "secure wallet" or a "recovery address". We will never ask you to move your assets anywhere, under any circumstance, for any reason.
  • An email missing your anti-phishing code. Set the code so that its absence becomes information.
  • A domain that is not exactly be1crypto.com. Watch for be1crypto-support.com, be1crypto.io, secure-be1crypto.com, and lookalikes built from Cyrillic or accented characters that render almost identically.
  • Support asking for your password, your 2FA code, your recovery seed or your screen. Our staff cannot use those and will never request them.
  • Live chat or a helpline you reached through a search advertisement. Paid search results are a standard delivery channel for support scams. Navigate to the site directly.
  • Urgency: a deadline, a frozen account, a countdown, a threat of liquidation. Pressure exists to stop you from checking.
  • A phone call claiming to be from be1crypto.com about a withdrawal. We do not make outbound calls about withdrawals.
  • A browser extension or wallet prompt asking you to sign a transaction you did not initiate. Read what you are signing, especially unlimited token approvals.

One habit covers most of this: never reach be1crypto.com through a link. Type the domain or use your own bookmark, every time, including when the email looks perfect. Attackers are patient, their pages are good copies, and the deciding factor is almost never whether you could spot a fake. It is whether you gave yourself the chance to. If something looks wrong, stop and verify it with us before you touch anything. Nothing on this platform is so urgent that it cannot survive a two-minute check.

Harden your be1crypto.com account in twenty minutes

Register a hardware key, set an anti-phishing code and turn on withdrawal allowlisting. Three settings that neutralize the attacks that actually happen.