CoinGecko has swapped out the engine behind its centralized exchange Trust Score, migrating from the old CER.live platform to CORE3, a risk intelligence tool built by blockchain security firm Hacken. The change affects how 166 centralized exchanges are graded on cybersecurity, and the early results paint a pretty unflattering picture of the industry’s security hygiene.

Under CORE3’s expanded evaluation of 193 exchanges, roughly 48% offer zero evidence of proof of reserves, penetration testing, or bug bounty programs. Only about 5.2% of assessed exchanges checked all three boxes.

How the new scoring works

CORE3 introduces what it calls a Probability of Loss (PoL) framework, which is essentially a structured way to estimate how likely it is that an exchange loses your money. The system evaluates exchanges across three pillars: security at 50% weight, solvency at 30%, and transparency at 20%.

That’s a meaningful expansion from CER.live’s narrower focus, which concentrated primarily on pure security metrics. The new model acknowledges something the industry learned the hard way through collapses like FTX: an exchange can have decent technical security and still be insolvent.