Live security feed + exchange risk lab
Security Alerts & Exchange Risk Lab
Tvijo AIOS relays security advisories and turns them into practical risk signals for crypto users: scams, exchange failures, copytrading drift, bot drawdowns, and high-leverage liquidation traps.
MEXC
Gate.io
Bybit
OKX
Copytrading
x100 / x200 / x500
Auto-refresh every 5 minutes. No blockchain RPC calls yet; on-chain anomalies are a placeholder.
Wondering how the platform itself is secured? Read our Platform Security statement.
Why deposits disappear
Most losses are not hacks. They are missing limits.
This risk lens follows the failure modes users actually meet on exchanges: copied traders changing risk, bots averaging into liquidation, API keys with too much power, and leverage bands where a tiny move can erase margin.
Bybit
Copytrading drift
Follower entry price, margin mode, and master-trader hedge can diverge.
OKX
Bot guardrails
Grid/DCA bots need hard daily loss caps, position caps, and kill switches.
Gate.io
Listing and liquidity risk
Thin books, delistings, and transfer network mistakes can trap capital.
MEXC
Extreme leverage
Very high leverage turns normal volatility, fees, and slippage into liquidation.
Copytrading
Follower risk is not master risk
Users can enter later, receive different fills, copy a larger effective position, or miss the master trader's hedge. A profitable leader can still liquidate followers.
- Show copied leverage before follow.
- Block martingale-style size jumps.
- Stop copying when drawdown exceeds the user's cap.
Exchange bots
Automation without a hard stop drains slowly, then suddenly
Grid, DCA, and signal bots can keep adding exposure after the thesis breaks. Without loss limits, one bad regime can consume the full deposit.
- No withdrawal permission on API keys.
- Daily loss, max orders, and max notional ceilings.
- Emergency pause after repeated failed exits.
High leverage
x100 / x200 / x500 is a liquidation product
At extreme leverage, ordinary candle noise, funding, spread, and liquidation fees can erase margin before a human has time to react.
- Default to low leverage; require friction above the cap.
- Separate isolated margin from cross-collateral.
- Show liquidation distance in price, not only percent.
Operational risk
The loss can start outside the trade
Wrong deposit networks, fake support links, compromised sessions, stale API keys, delistings, or disabled withdrawals can convert a normal action into a capital lock.
- Warn before network and memo mismatches.
- Score exchange incidents and withdrawal friction.
- Surface phishing and support impersonation alerts.
Risk budget first
Position size, max daily loss, max open orders, and exchange exposure are set before any bot or copy strategy can run.
API permissions audit
Trade-only keys are isolated per exchange. Withdrawal rights, stale keys, and broad account scopes are treated as critical risk.
Leverage ceiling
Strategies are blocked or downgraded when leverage, liquidation distance, or cross-margin exposure breaks the user's safety profile.
Copytrader drift check
Follower fills, master leverage, drawdown, symbol changes, and hidden averaging are monitored as live risk, not marketing performance.
Public /security
Live advisories, token checks, wallet screening, exchange risk education, and user-facing warnings.
GOGA Lab
Strategy safety scoring, bot drawdown simulation, copytrading anomaly review, and liquidation-distance analysis.
Admin App
Collector health, cron status, provider failures, source freshness, risk taxonomy, and release readiness.
Sources in this snapshot:
hn (46), github_security (14).
Counts are computed from the live normalized feed only — nothing is hand-curated.
Active filter:
category = breach
— sections below show matching alerts only. Reset.
Points: 1 | Comments: 1
Points: 3 | Comments: 0
Points: 2 | Comments: 0
No scam warnings in the current feed.
GoPlus token risk snapshot for contract-level checks: honeypot, proxy, mint rights, ownership changes.
Paste a token contract address to render the latest normalized risk snapshot.
OpenSanctions wallet screening against sanctions datasets. This is a public read-only relay, not a compliance decision engine.
Paste a wallet address to run the cached/live screening relay.
Points: 1 | Comments: 1
Points: 3 | Comments: 0
Points: 2 | Comments: 0
Points: 1 | Comments: 1
Points: 3 | Comments: 0
Points: 2 | Comments: 0
This page tracks external market threats. For how BibaMoney / Tvijo AIOS itself is protected, read the full statement:
- Non-custodial: no funds held, no withdrawal access, ever.
- Exchange keys sealed with AES-256-GCM; fail-closed vault, never shown or logged.
- Read-only public surface: no write path from public pages to the database.
- Strict CSP (no inline scripts), clickjacking and MIME-sniffing protection.
Platform Security statement
Chainabuse/abuse-report normalization is not wired into this public surface yet. Once the collector lands, this section should list newly flagged wallets and campaign notes.