Risk Disclosure
Crypto-assets and related custody, exchange and payment services involve substantial risk. You may lose some or all market value and may temporarily or permanently lose access to assets or funds.
1. Purpose and legal effect
1.1 This Risk Disclosure forms part of the Plumex Multi-Party Terms of Use and explains material risks associated with the Platform, Custody Service, Exchange Service and Fiat Service. It is not exhaustive and does not waive mandatory rights.
1.2 Use a service only after understanding the applicable Terms, Schedules, fees and risks. Crypto-assets and related services may expose you to material or total loss of value and to temporary or permanent loss of access.
2. Provider model and allocation
2.1 Plum Labs provides the Platform; Plum Global provides the Custody Service; IPI is the transaction counterparty/principal for supported exchange/fiat transactions; LMLP provides non-contracting technical verification/routing support. Approved payment, identity-verification, analytics, cloud and infrastructure providers may support those services.
2.2 A failure/restriction/insolvency affecting one provider or critical third party may interrupt other services even though each provider remains responsible only for its allocated obligations.
3. No advice, suitability or guarantee
3.1 No provider gives investment, trading, legal, tax or financial-planning advice through ordinary Platform operation. Availability of an asset/service does not mean it is suitable, safe, recommended or expected to increase in value.
3.2 No provider guarantees profit, preservation of capital, a fixed exchange rate, continuous liquidity, transaction acceptance, processing time, uninterrupted access, recovery of an unsupported transfer or protection from fraud. Public registration of a provider, where applicable, is not an endorsement, insurance or government guarantee.
4. Crypto-asset value and volatility
4.1 Crypto-asset prices may change materially within seconds and may be affected by speculation, market concentration, leverage, news, social media, technology, regulation, macroeconomic events and manipulation. An asset may lose most or all value or become illiquid.
5. Stablecoin, issuer and token-specific risks
5.1 A stablecoin may fail to maintain its reference value because of issuer, reserve, custodian, banking, redemption, liquidity, governance, legal, sanctions or market risks. It is not automatically a bank deposit, electronic money, legal tender or protected claim.
5.2 Token smart contracts may contain vulnerabilities, administrative keys, blacklisting/pausing/upgrade functions. Wrapped/bridged/synthetic assets add dependency on smart contracts, validators, bridges and reserve assets.
6. Custody and private-key-control risks
6.1 The Custody Service is custodial. You do not directly control the private keys or signing process. Key management and signing are performed through Plum Global’s custody operating model and may rely on authorised infrastructure providers.
6.2 Loss, theft, compromise, misuse or unavailability of signing systems, credentials, personnel or infrastructure may cause delay, unauthorised transfer or loss. Security controls can also delay access while checks are completed.
6.3 Insurance, if any, may be limited, subject to exclusions or insufficient. Do not assume insurance unless expressly confirmed in applicable service information.
7. Omnibus wallets, records and insolvency risks
7.1 Plum Global may use client-specific addresses, omnibus wallets or a combination. In an omnibus structure, on-chain records may not identify your individual entitlement; entitlement depends on the internal custody ledger and reconciliation records.
7.2 The legal effectiveness of segregation, the nature of a user’s claim and treatment of custody assets in insolvency depend on the structure, records, governing law, facts and court/insolvency decisions. The Terms do not represent that custody assets are bankruptcy remote.
8. Blockchain, network and protocol risks
8.1 Public blockchains operate independently of providers. Transactions may be delayed, reorganised, censored, duplicated or permanently irreversible. Network congestion, software bugs, consensus failure, validator/miner concentration, cryptographic developments and fee spikes may impair a network or asset.
9. Deposit, withdrawal and transfer risks
9.1 Sending an unsupported asset, using the wrong network/address/tag/memo or sending below a minimum may cause permanent loss. Deposit recognition depends on confirmations, screening, allocation and technical checks.
9.2 Withdrawals may be delayed by authentication, security/compliance review, network congestion, limits or third-party infrastructure. Recovery of an unsupported or incorrectly addressed transfer is not guaranteed.
10. Exchange, pricing, liquidity and execution risks
10.1 Quotes may be indicative/time-limited. Market movement, liquidity, payment confirmation or technical delay may cause expiry, rejection or a new quote. Price may include a spread and differ from other venues.
10.2 Low liquidity, market stress, large orders or provider/venue disruption may cause slippage, delayed/failed execution or inability to execute at a reasonable price.
11. Fiat, vIBAN and payment risks
11.1 A vIBAN or payment reference may be a routing identifier rather than a bank account opened in your name. Fiat funds may pass through banks or payment providers identified in the transaction flow and may be affected by delays, cut-offs, fees, screening, returns, recalls and information requests.
11.2 If a fiat flow is subject to statutory safeguarding or a similar requirement, the responsible payment provider must apply that requirement as applicable. Safeguarding, where applicable, does not eliminate bank, reconciliation, liquidity, fraud, legal or operational risk and is not the same as deposit insurance.
12. Third-party, outsourcing and concentration risks
12.1 Services depend on payment providers, banks, liquidity providers, blockchain nodes, cloud services, identity verification, analytics, telecommunications, app stores and other third parties. Outage, termination, cyber incident, regulatory restriction, insolvency or policy change may interrupt service.
13. Cybersecurity, fraud and account-takeover risks
13.1 Crypto services are frequent targets for phishing, malware, SIM swapping, impersonation, remote-access scams, investment/romance scams, invoice fraud and address substitution. Transactions authorised under deception may be irreversible.
13.2 Secure your email/device and authentication methods. No provider will request your private key, seed phrase, password or one-time authentication code for ordinary support.
14. Availability and operational risks
14.1 Services may be unavailable/degraded due to maintenance, software defects, cyber incidents, power/telecom failure, network congestion, banking hours, liquidity, human error, provider outage, natural disaster, war or emergency measures. No provider guarantees no downtime or fixed completion time.
15. Compliance, sanctions and legal-hold risks
15.1 Providers may conduct identity, residence/location, sanctions/PEP, source-of-funds/wealth, wallet-control, fraud and blockchain-risk checks before and during the relationship.
15.2 A transaction/service may be delayed, rejected, frozen, returned, reported, restricted or terminated because of applicable law, sanctions, court/authority orders, suspicious activity, provider policy, payment-provider requirements or proportionate risk controls. Screening may produce false positives and require human review.
16. Legal, territorial, regulatory and enforcement risks
16.1 Crypto, custody, exchange, payment, tax, sanctions, consumer and data-protection laws are developing and may change rapidly. A change may prohibit a service, require additional verification, restrict transfers, require reporting, delist an asset or require an orderly exit.
16.2 The Ukraine Service Route excludes users resident or located in the EU/EEA and other unsupported jurisdictions. Providers are located in different countries; cross-border complaints, insolvency and enforcement may be slower, more expensive or less effective.
16.3 A Panamanian corporation does not by itself confer authorisation or a regulatory passport in another jurisdiction. The law of the user’s location and the place where a service is provided may apply independently.
17. Forks, airdrops and unsupported features
17.1 Providers may decide which chain/asset to support after a fork or upgrade. You have no entitlement through the services to airdrops, forked assets, staking rewards or governance distributions unless expressly supported.
17.2 Staking, lending, yield, derivatives, leverage, margin and decentralised-finance features are not included in the Ukraine Service Route unless separately introduced under specific terms/disclosures.
18. Tax, accounting and reporting risks
18.1 Buying, selling, exchanging, transferring, receiving or holding crypto-assets may create tax/reporting/accounting obligations. Providers do not determine your tax liability; maintain records and obtain independent advice where needed.
19. Privacy, identity and public-blockchain risks
19.1 Verification/compliance may require sensitive personal data, biometrics, financial records, wallet addresses and transaction information. Data may be transferred internationally among providers and approved vendors.
19.2 Public blockchain transactions are persistent, visible and difficult/impossible to erase. Combining chain data with other information may identify or profile a user.
20. Provider change, termination, migration and exit risks
20.1 A provider, payment rail, supported asset or operating structure may change, which may require service suspension, new verification, updated terms, changed payment/deposit details, withdrawal, return or migration.
20.2 Migration can create delay, reconciliation error, address error, duplicate/missing records, technical incompatibility and temporary loss of access.
21. Practical risk-reduction measures
• Use only assets, networks, currencies and payment details shown for the specific service and transaction; independently verify destination/network/tag/memo.
• Enable multi-factor authentication, secure your email/device, keep software updated and never share passwords, one-time codes, private keys or seed phrases.
• Use a small test transaction where appropriate and keep independent records of confirmations, bank references and transaction hashes.
• Do not act under pressure, follow unsolicited investment instructions, grant remote access or send assets to “support”, “recovery”, “tax” or “verification” wallets.
22. Acknowledgement, support and language
22.1 By using a service after this Disclosure is presented, you acknowledge an opportunity to read it and understand that crypto/custody/exchange/payment services involve risk of delay, restriction and loss, including possible total loss of market value. This acknowledgement does not waive mandatory rights.
22.2 General support: support@plumex.io. Complaints: complaints@plumex.io. This Disclosure may be published in English and Ukrainian; for the Ukraine Service Route, the Ukrainian version prevails unless mandatory law requires otherwise.
23. Definitions
“Custody Service” means the receipt, holding, recording and authorised withdrawal/transfer of supported crypto-assets by Plum Global. “Exchange Service” and “Fiat Service” mean supported transactions provided by IPI under applicable terms. “Stablecoin” means a crypto-asset designed or represented as seeking to maintain a reference value without any guarantee that it will do so. Other capitalised terms have the meanings given in the Multi-Party Terms of Use.