Changpeng Zhao, better known as CZ, is sounding a sharp warning to crypto exchange operators eyeing acquisitions of smaller platforms. The message is clear: buying a small exchange means taking on its security problems, which often go way beyond what buyers expect.
Risk Factors in Acquiring Smaller Exchanges
CZ points out that an acquisition is not just about increasing user base or market share. It involves inheriting legacy security issues. Smaller exchanges tend to have outdated code, fragile infrastructure, and security measures patched together by lean teams. These weaknesses make them prime targets for hackers, a risk magnified when absorbed by bigger players.
Security isn’t something you just plug in after a takeover. It’s set deep in infrastructure choices made long ago, such as how databases are designed and how cryptographic keys are managed. Fixing these inherited vulnerabilities often costs more than building fresh systems.
Back in February 2020, CZ highlighted that smaller exchanges face higher hacking risks due to weaker defenses compared to larger ones. That gap remains a significant concern amid ongoing merger and acquisition activity in crypto.
Industry Context and Investor Implications
CZ's insights come at a time when he has stepped back from Binance's day-to-day leadership, but his experience remains influential. Since founding Binance in 2017, he witnessed its rapid growth and regulatory hurdles culminating in his 2023 resignation as CEO. His recent book, Freedom of Money, sheds light on these challenges.
For users of exchanges involved in recent acquisitions, CZ’s comments should raise critical questions: Has the acquiring exchange fully audited the security of the new platform? Are user funds migrating onto the acquirer’s secure infrastructure, or dangling on legacy systems longer than they should? Clarity around transition timelines can affect fund safety.
While discussions around CZ often focus on regulatory and futuristic threats like quantum computing, the immediate danger lies in old, unresolved vulnerabilities. Attackers are exploiting these weaknesses today using widely available hacking tools.



