OKX Web3 Risk Control Report: H1 2026

Foreword

In the Web3 world, "self-custody" and "decentralization" are often understood as the opposite of compliance: assets are held by users themselves, transactions happen directly onchain, with no account review and no manual risk-control queue. The KYC and AML pipelines that centralized exchanges rely on seem, by nature, not to apply here. This leads to a popular assumption, that decentralized products cannot do real risk control.

OKX's practice offers the opposite answer. Risk control has not disappeared; it has moved from offline manual review to the onchain infrastructure layer. The screening logic is written into the protocol itself, and risk decisions are executed automatically before each transaction is initiated. In the first half of 2026, the OKX risk-control system intercepted, in exactly this way, more than 5.7 million high-risk transactions, spanning hacking and theft, phishing, scams, and transfers from compromised accounts, all accomplished without custodying or freezing user assets.

For OKX, risk management is not homework handed in after a product launches, but a default property written into the architecture from day one. This report sets out to make two things clear: first, how exchange-grade AML capabilities can be built into decentralized infrastructure, protecting users without departing from the principle of self-custody; and second, how "control-first" is genuinely implemented in product design for emerging scenarios such as Exchange OS, Outcomes markets, and RWA. We hope it offers the industry a useful starting point for discussion, and gives users an added measure of confidence.

Chapter 1: The OKX Web3 Risk Control Framework: Building Exchange-Grade AML into Decentralized Infrastructure

To intercept risk before a transaction happens, you essentially need to answer three questions in turn. First, which addresses are dangerous? This requires a risk-intelligence library that is both large enough and accurate enough. Second, how are newly emerging dangerous addresses discovered in time? Hackers move funds at any moment, so the library must be able to grow in real time. Third, how is this intelligence actually put to use before a user sends a transaction? The detection capability must ultimately land on the screening and decisioning of every single transaction.

OKX Web3's onchain risk-control system is built in layers along exactly these three questions: the CT Tag Library accumulates risk intelligence, Tracker expands associated risk addresses in real time, and KYS completes screening before a transaction is initiated. Each is detailed below.

Chain Intelligence Tag Library (CT Tag Library)

  • Number of tags: Over 1.1B (the largest in the industry)

  • Chain coverage: Support for 420+ chains

  • Tag types: Sanctioned addresses, hacker addresses, exchange addresses, mixers, darknet markets, high-risk entities, and more

  • Update mechanism: Real-time synchronization via a dual-track data pipeline with Elliptic

What this means for you: when you are about to transfer or trade, the system already knows in advance whether the counterparty address has a "record," so it can warn you or block the risk before you click confirm, keeping your funds out of harm's way.

Tracker: Real-Time Address Expansion Engine

  • The industry's only real-time expansion capability: average expansion latency of 5 seconds

  • Proprietary graph-analysis algorithms that expand outward from known hacker addresses to associated entities

  • 160K+ newly expanded addresses added in H1 2026

What this means for you: even if an attacker moves stolen funds to a brand-new address that has not yet been publicly exposed, the system has a chance to identify it within a very short time and add it to the risk list, reducing the chance that you mistakenly transfer to a risky address.

KYS (Know Your Signature): Transaction Screening

  • OKX Web3 embeds Elliptic Lens directly into OKX DEX via API, screening the wallet in real time before every transaction is initiated; in institutional bridging or cross-chain scenarios, the receiving address is screened simultaneously.

  • Automated risk decisioning: high-risk wallets are identified and rejected before a transaction proceeds. Because OKX Web3 operates on a non-custodial architecture, it does not freeze user assets directly; risk controls take the form of rejecting the transaction or blocking UI access, consistent with the trust-minimized principles of DeFi.

  • H1 2026 interception data: In the first half of 2026, drawing on a continuously updated threat-intelligence library together with proprietary real-time risk-address detection and expansion capabilities, the OKX risk-control system intercepted a cumulative total of more than 5.7 million high-risk transactions, spanning hacking and theft, phishing, scams, and other categories.

What this means for you: the entire screening runs automatically onchain with no manual review queue. Because OKX Web3 is non-custodial, when a high-risk address is detected, the system rejects the transaction or blocks the relevant UI entry rather than seizing funds – consistent with the basic principle of Web3 self-custody.

H1 2026 Risk-Control Data at a Glance

In the first half of 2026, the OKX Web3 risk-control system blocked over 7.3 million visits to risky websites, involving nearly 40,000 distinct risky sites.

Drawing on a continuously updated threat-intelligence library, together with proprietary real-time risk-address detection and expansion capabilities, it intercepted a cumulative total of more than 5.7 million high-risk transactions, spanning hacking and theft, phishing, scams, account takeover, and blocklisted addresses. The main interception categories and their proportions are shown below:

  • Hacking & Theft (Hack): approximately 2.41 million transactions, 42% of the total and the single largest category. These interceptions primarily targeted transactions flowing to hacker addresses already known from public security incidents, as well as transactions along the movement paths of stolen funds.

  • Phishing: approximately 1.48 million transactions, 26% of the total. This covers techniques such as impersonation of official channels, malware, and inducement into suspicious transactions – confirming that phishing remains one of the highest-frequency threats on the user side.

  • Scam: approximately 990,000 transactions, 17% of the total. Includes DeFi wallet scams, investment scams, and fraudulent Ponzi-type schemes.

  • Blocklisted Addresses (Blocked): approximately 410,000 transactions. Relating to addresses blacklisted by various stablecoin issuers.

  • Account Takeover (ATO): approximately 410,000 transactions. Intercepting abnormal fund transfers suspected to originate from compromised accounts.

Chapter 2: Security and Risk-Control Design for Emerging Scenarios

Whether it is the open marketplace infrastructure Exchange OS, Outcomes, or RWA (real-world assets), OKX's principle is to put risk management first: introducing an assessment framework at the product-design stage, rather than retrofitting it after launch. Below are several concrete scenarios, and what each of them means for you.

Exchange OS

Exchange OS is an open marketplace infrastructure that OKX has built on X Layer, allowing any deployer to create venues for spot, perpetuals, outcome markets, and more. Open deployment does not mean loss of control. Core risk-control capabilities such as staked accountability, fund isolation, and sanctioned-address screening are built into the protocol layer, providing unified security for all venues. OKX itself also operates a CeDeFi Venue on it as a deployer, applying a higher tier of risk-control standards.

Key risk-control points:

  1. Permissionless deployment with staked accountability. Creating a venue requires no item-by-item approval, but a deployer must stake collateral in advance as a performance guarantee. In cases of oracle manipulation, malicious parameter configuration, non-compliant solicitation, and similar conduct, a decentralized governance committee can rule to slash the stake.

  2. Fund isolation (KYC / non-KYC). KYC venues and non-KYC venues connect to two physically isolated custody contracts, with no onchain fund flow between them, and each has its own independent clearinghouse. This prevents risk from spreading between user groups with different risk-control profiles.

  3. Sanctioned-address controls. The protocol layer maintains a sanctioned- and risk-address library. Matched addresses are restricted from opening new trades across all venues (including third-party deployments) and may only close positions or withdraw. Assets are not unilaterally frozen, balancing sanctions risk control with the principle of self-custody.

Outcome Markets

Outcomes is an event outcomes application that OKX developed on Exchange OS, launched in June 2026, with its first use case being the 2026 World Cup Outcomes campaign.

Region-feature-based access arrangements:

  • The points mode (no capital at stake) is open across a relatively broad global footprint.

  • In regions with strict restrictions on trading event outcomes in any form (for example, Singapore, the UK, and the countries of the European Economic Area), we have fully disabled the relevant features.

  • These access decisions are enforced automatically through system-level feature restrictions and identity verification, currently covering 20+ restricted jurisdictions, with the list continuously updated as local regulations change.

What this means for you: points are distributed free by OKX. You cannot obtain them through deposits or any form of purchase, and participating in outcomes does not involve any capital of your own. This design, on one hand, structurally removes the risk of losing your principal; on the other, it ensures that in regions without the relevant licenses, this kind of product will not be deemed unlicensed derivatives trading. In addition, the Sybil attacks that frequently appeared in past campaigns are hard to hide under continuously iterating risk-control monitoring, so the interests of legitimate participants are not harmed.

Market types have boundaries, and settlement follows rules: the first phase lists only event types with objective, publicly verifiable outcomes, such as sporting events. For sensitive types such as war, terrorism, and political assassination, creation is directly prohibited at the market-creation stage. When each market is listed, an authoritative information source and settlement rules are set in advance, results are verified by an oracle, and a manual-review channel is retained. If a result is disputed, settlement is paused until the review is complete.

Campaign risk control: risk-control capabilities are in place before a campaign opens, used to identify and intercept abnormal cheating behavior; the redemption and withdrawal of points are likewise brought into OKX's unified risk-control system.

RWA: Real-World Assets

OKX does not currently issue RWA assets directly. Instead, it acts as a technology service provider, helping users discover and trade RWA assets and obtain related information. Specifically, this includes:

  • How we screen at the user-access and trading stages: covering primary-market minting and redemption, and identity verification (KYC/KYB, meaning identity checks for individuals and businesses) involved in secondary-market trading, along with regional restrictions, accredited-investor thresholds, wallet permissions, and transfer restrictions, so as to identify the constraints different participants may face at each stage.

  • For core matters that directly affect your rights, such as bankruptcy remoteness, collateral-security interests, and recourse on default, we compile our assessment conclusions and disclose them to you on the product page, making it easier for you to judge for yourself before participating.

  • Access thresholds for asset providers: for projects where legal rights are unclear, risk-response mechanisms are insufficient, the underlying assets are weakly liquid, or the issuer, custodian, or counterparty carries higher risk, we will in principle not integrate them, or will only consider integrating them once the risks have been further verified and effectively mitigated. We also pay close attention to the liquidity depth of the underlying market, the secondary-market liquidity of the token, market-making stability, and minting/redemption capacity, in order to reduce the risk that you later want to exit but cannot, or that the token price diverges significantly from the value of the underlying asset.

Why some RWA products are not visible in certain regions: RWA assets may carry securities-like characteristics, and different regions vary widely in how they classify such products and in their marketing and solicitation rules. Our regional controls are mainly not about whether you can trade, but about whether the platform proactively displays and recommends these products in different regions. The legal team, taking into account local business realities and regulatory requirements, judges whether products may be proactively recommended to local users. In regions where doing so could be deemed active solicitation or marketing of securities-like products, we remove the relevant assets from proactively exposed placements such as rankings, featured recommendations, and marketing campaigns. This is done to ensure that users in each region participate in these products in compliance with local regulations, rather than simply limiting your choices.

Closing

After reading through these mechanisms, the tag library, the screening engine, the slashing committee, the regional-access rules, you might think: isn't this all just the platform doing "compliance"? What does it have to do with me?

That is exactly the perspective this report wants to share. Risk control is not only protection for the platform; more importantly, it adds a layer of protection for users. Risk control is not a constraint. It is the first line of defense for the safety of user assets.

When the system stops a transfer to a scam address, a phishing contract, or a hacker address before it is even initiated, what gets kept is often your money. That deserves to be seen.

When your wallet stays clear of "dirty money" thanks to upfront risk screening, you are also less likely to be mistakenly flagged or restricted later by other platforms or stablecoin issuers. This line of defense stands in front of the problem, rather than scrambling to fix things after your assets are already in trouble.

In the past 30 days, Tether froze 250 million USDT across 472 addresses. Source: BlockSec

When a new product works out, before launch, what risks users might face and what the regional rules allow, every usable feature you see has had someone clear the mines for you in advance.

The word "compliance" can sometimes sound like it serves the platform's own interests, but broken down, it does a few very concrete things: stopping you before you send money to the wrong place, shielding your assets before they get caught up in risk, and clearing the mines before you try a new feature. Most of the time you don't feel this work, because when it is done well, precisely nothing happens.

We will keep refining these mechanisms and making them more transparent, and we welcome you to treat this report as a starting point for understanding how these protections actually work.You just trade, and OKX will do everything it can to safeguard your assets.

Disclaimer: This report is for industry reference only and does not constitute any investment, legal, or compliance advice.

Дисклеймер
Материалы предоставлены исключительно в ознакомительных целях и могут включать информацию о продуктах, которые недоступны в вашем регионе. Они не являются инвестиционным советом или рекомендацией, предложением или приглашением к покупке, продаже или удержанию криптовалюты / цифровых активов, советом в финансовой, бухгалтерской, юридической или налоговой сфере. Криптовалюты / цифровые активы, в том числе стейблкоины и NFT, сопряжены с высокой степенью риска и их курсы могут сильно колебаться. Оцените свое финансовое состояние и тщательно обдумайте, подходит ли вам торговля криптовалютой / цифровыми активами и их хранение. По вопросам, связанным с конкретными обстоятельствами, проконсультируйтесь со специалистом в юридической, налоговой или инвестиционной сфере. Информация, представленная на этой странице (включая рыночные и статистические данные, если таковые имеются), предназначена исключительно для ознакомления. Часть контента может быть создана с использованием инструментов искусственного интеллекта (ИИ). При подготовке статьи были приняты все меры предосторожности, однако автор не несет ответственности за фактические ошибки и упущения. Web3-кошелек OKX и вспомогательные сервисы не предлагаются биржей OKX и на них распространяются Условия использования Web3-экосистемы OKX.

Похожие статьи

Показать еще
Web3 Security Report H1 2026 Thumb

OKX Web3 Security Report: H1 2026

Jointly produced by the OKX Web3 Security Team, SlowMist, and OtterSec Foreword In the first half of 2026, if you looked only at publicly disclosed lo
24 июл. 2026 г.
30 10 Bằng chứng dự trữ, kỷ niệm 3 năm Blog Thumb

Kỷ niệm 3 năm Proof of Reserves - Bằng chứng dự trữ: 35,4 Tỷ USD tài sản bảo chứng, tăng 75% so với cùng kỳ

OKX chính thức đánh dấu 3 năm triển khai chương trình Proof of Reserves - Bằng chứng dự trữ (PoR). Tính đến hiện tại, OKX đang bảo chứng 35,4 tỷ USD
30 окт. 2025 г.
Показать еще