Back to Blog

Case study: KuCoin holds #1 by the lowest Probability of Loss on CORE3 without submitting anything

by Dmytro Zap
3m

Which data KuCoin submitted?

KuCoin got there without sending CORE3 a single new document. In fact, it achieved rank 1 by already being transparent on the metrics that make up the score, with one catch.

Six of the seven tracked metrics were public before CORE3 ever looked at them. That list runs to proof of reserves audit, disclosed wallets with verified ownership, bug bounty programme, ISO and CCSS certification, user security controls, and server security. CORE3's researchers found and verified every one of them independently, without asking KuCoin for anything.

The only metric that wasn't public is the penetration test, which CORE3 inherited from what KuCoin submitted years earlier to CER.live.

Which metrics carry the weight?

KuCoin introduces well-rounded coverage across all metrics from CEX Probability of Loss methodology.

Metric

Points

Why

Proof of reserves audit21Hacken confirms that KuCoin holds enough assets to cover what it owes depositors at a point in time. 
Disclosed wallets, verified ownership20KuCoin has published the on-chain wallets it holds reserves in, with a signed proof that it controls them.
Penetration test12.5Third party has attempted to break into KuCoin's systems and documented what it found.
Bug bounty programme12.5A standing, public offer to pay third-party researchers for vulnerabilities they find hosted on Bugcrowd.
ISO and CCSS certification10Two independent security-management standards, one general (ISO 27001) and one crypto-specific (CCSS), both requiring a formal audit to obtain and maintain.
User security controls7.5Account-level protections such as two-factor authentication and withdrawal whitelisting.
Server security6Infrastructure-level hardening: response headers, cookie flags, and similar signals visible from the outside.

What is Probability of Loss?

The Probability of Loss (PoL) is an unbiased, data-based numerical index (0–100) that estimates the likelihood that a project will fail or that users will incur losses. The metric was designed to create a unified risk language on the digital asset market, suitable for investors, builders, and institutions. 

 

For more information, refer to the CEX methodology.

What does transparency provide as an upside?

Proof of reserves audit, disclosed reserve wallets, and the bug bounty page. Together they're 53.5 of the 89.5 points listed above, and none of them required direct data submission. A published PoR report, a signed wallet attestation, and a live bug bounty URL are each checkable in minutes by anyone who knows where to look. And this has a lot of benefits to offer a transparent party:

Start with the buyer's side, because that's where the gap costs someone money. Institutions that currently have nothing to underwrite are sitting out of crypto entirely, not because the risk is unacceptable, but because it isn't visible enough to price. Once it's quantified, that changes the question they can ask. 

None of that is a one-off credit, either, because CORE3 tracks the risk record on an ongoing basis. Regulators and counterparties get a live health signal instead of a single approval snapshot, which favours projects that stay in good standing over time. A clean multi-year track record becomes an asset, instead of something the market ignores in favour of the newest narrative.

Put together, disclosure itself becomes the differentiator. Projects that publish and disclose can prove they're safer than the market otherwise assumes; the ones that don't just look like the rest of the pack.

Conclusion

The programme behind KuCoin's score took years and plenty of budget allocation: the audits, the certifications, the bounty, and the custody controls. But keeping it public costs them nothing, while bringing plenty of benefits. 

If you've already spent that budget, the rating is unclaimed. If you haven't, "Improve Score" on your CORE3 listing is where that conversation starts.