Changpeng Zhao, the former Binance CEO widely known as CZ, has issued a stark warning about the dangers embedded in crypto exchange acquisitions. Speaking against the backdrop of BitMEX and BitMart winding down operations, Zhao said buyers often inherit deeply rooted security weaknesses that can turn into devastating financial liabilities.
Hidden risks behind the brand
In his latest commentary, relayed via WuBlockchain, Zhao explained that acquiring a smaller exchange means taking ownership of far more than its user base and trading volume. Buyers also absorb aging codebases, outdated security protocols, and vulnerabilities that may have been known to attackers for years. “Fixing those issues after a deal closes can demand significant time and money,” he stressed, adding that in some cases it is cheaper to rebuild parts of the platform than to patch inherited flaws.
His remarks echoed a position he first outlined in February 2020, when he noted that smaller exchanges are more frequent targets for hackers because they lack the dedicated security staff and budgets of larger competitors.
BitMEX and BitMart closures add urgency
The warning coincides with concrete market events. Derivatives platform BitMEX is set to close on September 23, while BitMart has begun a methodical wind-down. These closures have fueled discussions about the stability of smaller trading venues and the due diligence required when one platform considers absorbing another’s operations or assets. Zhao’s comments suggest that legacy vulnerabilities left by previous management could trigger post-acquisition hacks, making security audits and infrastructure reviews essential before any fund migration.
Implications for the M&A landscape
Zhao’s caution is likely to sharpen scrutiny around crypto M&A. Investors and traders are now being urged to demand clear answers about security audits, migration plans, and the state of legacy systems before trusting an acquired exchange. While Zhao’s recent public discussions have often touched on regulation or future quantum computing risks, he insists that poorly secured systems pose an immediate threat—one that attackers can exploit with widely available tools.