Canada Introduces New Crypto Custody Rules to Protect Investors After QuadrigaCX Collapse

TheNewsCrypto2026-02-04 tarihinde yayınlandı2026-02-04 tarihinde güncellendi

Özet

Following the QuadrigaCX collapse in 2019, which resulted in the loss of $123 million in customer funds, Canada’s Investment Regulatory Organization (CIRO) has introduced new crypto custody rules for exchanges. The regulations aim to protect investors by enforcing stronger custody arrangements, improved internal controls, and clear separation of client assets from company funds. The framework adopts a risk-based approach, requiring higher-risk firms to meet stricter standards while allowing flexibility for lower-risk platforms. CIRO will actively update the rules as new threats emerge and has the authority to investigate misconduct and impose penalties. The move reflects Canada’s protective regulatory stance, bringing crypto custody under existing securities laws.

The Canadian Investment Regulatory Organization (CIRO) has announced that Canada has introduced new crypto custody rules for the exchanges to reduce the risk of investor losses and prevent failures, as the QuadrigaCX collapse happened in 2019.

This move immediately takes effect after the direct response to the past crypto failure, like the QuadrigaCX collapse. QuadrigaCX was one of the canada’s largest crypto exchanges. After its CEO died, it has missed about $123 million of customer funds. Investigations later found that this was caused by its poor controls, weak governance, and serious custody failures.

What CIRO’S new crypto rules do

CIRO’S Digital Asset Custody Framework used a risk-based approach, which sets clear standards for protecting investors from hacking, fraud, weak controls, and poor governance. The firms which higher risk activities should meet the stronger custody standards, and the lower-risk firms get more flexibility but still need the protections.

After the new rules, crypto platforms in Canada should use stronger custody arrangements and improve the internal controls and oversight with clear separation of customer assets from the company funds. CIRO says many platforms are already following a similar structure, and any transitions to the new rules will be handled case by case without disrupting the firms suddenly.

Canada’s approach towards crypto custody

CIRO says that it will actively monitor the new risk, and the regulators will update the new rules if they seem to have any new custody threats and repeated problems across the firms. This shows that the framework still needs to be fixed and will evolve as per the crypto market changes.

Canada has taken a protective approach towards crypto regulations and is bringing crypto custody platforms under the existing securities laws. CIRO has the authority to investigate the misconduct, impose fines, and suspend the firms, which shows a strong focus on the custody and increased attention on stablecoins.

Highlighted Crypto News:

Ethereum Eyes Frame Transactions as Hegota Headliner

TagsCanadaCryptocurrency

İlgili Sorular

QWhat event prompted Canada to introduce new crypto custody rules?

AThe collapse of QuadrigaCX in 2019, which resulted in the loss of approximately $123 million in customer funds due to poor controls, weak governance, and custody failures.

QWhich organization announced Canada's new crypto custody rules?

AThe Canadian Investment Regulatory Organization (CIRO) announced the new crypto custody rules.

QWhat is the main approach of CIRO's Digital Asset Custody Framework?

AIt uses a risk-based approach, setting clear standards for protecting investors from hacking, fraud, weak controls, and poor governance, with higher-risk firms facing stronger custody requirements.

QHow do the new rules require crypto platforms to handle customer assets?

APlatforms must use stronger custody arrangements with clear separation of customer assets from company funds and improve internal controls and oversight.

QWhat regulatory powers does CIRO have under the new framework?

ACIRO has the authority to investigate misconduct, impose fines, and suspend firms, showing a strong focus on custody and increased attention on stablecoins.

İlgili Okumalar

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru55 dk önce

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru55 dk önce

İşlemler

Spot
活动图片