On October 10 last year, the traders being liquidated and the traders trying to stop it had one thing in common. Neither group could reach the exchange.

Binance and Coinbase both had outages as the volume hit. API rate limits on the major centralized venues stopped people from adjusting positions in the middle of a $19.3 billion liquidation cascade. A stop-loss doesn't do anything if the order never arrives.

Every backtest I've ever run contains an assumption nobody writes down. The fills happen. The API answers. The venue is still solvent on the day you want your money back.

Break any one of those and the equity curve you tested has nothing to do with the money you actually keep.

An exchange isn't infrastructure the way a power grid is infrastructure. It's a private company holding your collateral, matching your orders, and deciding under stress — unilaterally, in the middle of the worst hour — what happens to your position. That makes it a counterparty. Counterparties fail.

FTX is the obvious example. Customer deposits were commingled with Alameda Research, the shortfall came to roughly $8 billion, and the whole thing was gone within days once withdrawals spiked. The dangerous part wasn't the fraud itself. It's that hundreds of thousands of people treated a website they logged into daily as a place, when it was a balance sheet.

Most traders now believe proof of reserves closed this hole. It didn't. Proof of reserves shows what an exchange holds; solvency is about what it owes, and four years on, most published attestations still cover the assets without covering the liabilities.

The professionals haven't been reassured either. In one survey of the crypto derivatives market, 47% named counterparty risk as a top concern against 31% for operational risk, and 64% said they were still uneasy about the quality of proof-of-reserves disclosures from most exchanges.

Solvency isn't even where most of the damage happens, though. It's the ten minutes when nothing loads. On October 10, Hyperliquid cleared $10.1 billion in liquidations without downtime, while traders on venues that did go down sat frozen in positions they had perfectly good rules for and no way to execute. Uptime is a risk parameter, and almost nobody sizes it.

Self-custody is the obvious objection, and it only half solves this. You can hold spot in your own wallet. You can't run a leveraged position without posting collateral on somebody's venue, which means every derivative you hold is a claim on someone else's balance sheet. The choice was never whether to take counterparty risk — only how much of it, and for how long.

So treat the exchange like a position, because that's what it is. It has a size, you chose that size, and right now you probably can't say what it is out loud.

Here's the question worth answering tonight. What percentage of your total capital is sitting on one venue at this moment, and would you accept losing that number to a freeze or a fraud you had no way to forecast? If the answer is uncomfortable, the fix isn't a better exchange. It's a smaller number.

Mine is written down. Trading capital stays on the venue, everything else lives off it, and the sweep runs on a schedule rather than when I remember to do it. I also keep a one-page plan for the day the API stops answering: which position I close first, what I can actually reach from a phone, and which backup venue I trade from if the primary is dark for a day.

None of that improves a single entry. It just decides whether four good years survive one bad afternoon.

That's the part systematic trading forces you to confront, because a strategy has to survive its venue before it gets to survive the market. The risk rules behind our BTC strategy, along with six years of backtest data and the TradingView verification scripts, are at v33systematic.com.