Cold storage for the majority
The target is for at least 95% of customer assets to be held in offline wallets. Their private keys are generated and stored on air-gapped hardware and never exist on an internet-connected machine.
How customer assets are designed to be held, how accounts are protected, how incidents are handled, and what you can do to keep your own account safe.
Zenvorika is in pre-launch and holds no customer assets today. This is the model the platform is being built to, and it will be independently reviewed before launch.
The target is for at least 95% of customer assets to be held in offline wallets. Their private keys are generated and stored on air-gapped hardware and never exist on an internet-connected machine.
A warm tier refills the hot wallet in controlled batches. The hot wallet holds only what is needed for normal withdrawal flow, sized so that its loss would be covered by reserves.
Moving funds out of cold or warm storage requires independent approvals from several key-holders in different locations, using threshold signing. No single employee can move funds alone.
Customer balances are tracked separately from company funds and are not lent, staked or used for operations unless a customer opts into a specific product.
Each control assumes the one before it might fail. A stolen password alone should never be enough to move funds.
Choose a short phrase in your security settings — for example jade-harbour-42. Every genuine email from Zenvorika will include it near the top.
Phishing emails copy logos and wording, but an attacker doesn't know your code. If an email claiming to be from Zenvorika doesn't show it, don't click anything, and forward it to security@zenvorika.com.
Anti-phishing code: jade-harbour-42
This line would appear at the top of every genuine email.
A proof of reserves shows that an exchange holds at least as much of each asset as it owes customers. Customer balances are hashed into a Merkle tree; each customer can check their own leaf is included without seeing anyone else's balance, and the tree's total is compared with wallet balances that can be verified on-chain. It shows assets at one moment in time — it doesn't prove the absence of other liabilities, which is why it works best alongside an independent review.
No system is immune to incidents. What matters is how quickly they are found, how tightly they are contained and how honestly they are reported.
Automated monitoring of wallet flows, login patterns and infrastructure, with alerts routed to an on-call security engineer at all hours.
Affected systems can be isolated and withdrawals paused platform-wide within minutes. Pausing is a deliberate first step, not a failure mode.
Forensic review establishes what happened, which accounts or assets are affected and whether the root cause is closed.
Affected customers are told what happened, what data or assets were involved and what they should do, as soon as facts are confirmed.
Services resume only after verification. A written post-incident review records causes and the changes made to prevent a repeat.
Security researchers who report vulnerabilities responsibly help keep everyone safer. A public bug bounty programme will open alongside the exchange; reports about this website are welcome now.
| Severity | Examples |
|---|---|
| Critical | Theft or unauthorised movement of funds, remote code execution on production, full account takeover without user interaction |
| High | Bypass of 2FA or the withdrawal whitelist, access to other users' personal data, significant authentication flaws |
| Medium | Stored XSS, CSRF on sensitive actions, meaningful information disclosure |
| Low | Issues with limited impact, such as missing security headers with a demonstrable effect |
Most account compromises start outside the exchange. These habits close the common routes in.
Reused passwords are the most common route into accounts. A manager also refuses to fill your password on a look-alike domain.
SIM-swap attacks can intercept SMS codes. A hardware key is the strongest option.
Every genuine Zenvorika email will show the code you chose. No code, or the wrong code, means delete the email.
Not support, not security, not anyone. The same goes for seed phrases of your own wallets.
Type zenvorika.com once, bookmark it and use the bookmark. Ads and search results can be spoofed.
It is the single setting that most limits the damage if someone does get into your account.