Insights

Risk Management24 September 20267 min read

Crypto Portfolio Risk Management: The Key Factors for Larger Portfolios

By Dominik Schneeberger, Founder & Managing Partner

Bergpanorama zum Artikel über Counterparty Risk Management bei Krypto-Investments
With a larger crypto portfolio, the question changes. It is no longer only about whether Bitcoin, Ethereum or a particular trade might rise. What matters is how much capital is at stake if a decision proves wrong, and how different risks act on the portfolio at the same time.
Professional risk management is therefore not a single stop-loss or a fixed percentage. It is a system of position sizes, exposure, liquidity, correlations, counterparties, operational security and governance. The larger the mandate, the more the interplay between these levels matters.

1. Position size: an opinion is not yet a risk

Position size translates an investment thesis into actual portfolio risk. Two managers can hold the same market view and still take on entirely different risk if one exposes five per cent of the portfolio and the other fifty per cent.
A sensible position size takes into account, among other things, volatility, the invalidation level, the expected holding period, liquidity and the remaining risk budget of the overall portfolio. In crypto markets in particular, size should not be derived from conviction alone. High conviction can be wrong; risk budgets ensure that a single wrong decision does not dominate the entire mandate.

2. Drawdown and the mathematics of recovery

Drawdown describes the loss from the portfolio's previous high to a later low. For investors, this measure is particularly relevant because losses have to be recovered asymmetrically.
After a loss of 10%, a gain of around 11.1% is needed to return to the starting value. After a loss of 25%, it is 33.3%. After a loss of 50%, 100% is required. This arithmetic explains why capital preservation and loss limitation play a central role for larger portfolios.
A strategy does not have to avoid every loss, but it should define which loss paths still lie within the mandate – and at what point exposure is reduced.

3. Market exposure and regime

Risk is not equally attractive in every market phase. In a stable trend with high liquidity, different position sizes can make sense than in a choppy sideways phase with conflicting signals. A market-adaptive approach therefore links the quality of a set-up to the permissible exposure.
When market structure, liquidity and signal quality are weak, reducing risk can be more sensible than forcing new trades. This does not mean that regimes can be reliably predicted. It simply means that risk need not automatically remain constant.

4. Liquidity, slippage and execution

As order sizes grow, execution becomes a risk factor in its own right. A price visible on the screen does not necessarily mean that a large position can be executed in full at that price.
Order book depth, spread, volatility and the timing of a trade influence the actual costs. For highly liquid assets, this effect can be small; in smaller markets or during periods of stress, it can rise considerably. Professional portfolio management should therefore consider, before the trade, how a position can be built up and closed again.

5. Correlation and apparent diversification

Ten different tokens do not automatically make a diversified portfolio. In periods of stress, many crypto assets respond to the same liquidity and risk factors and can be highly correlated with one another.
A portfolio can therefore look diversified on the surface and still, in economic terms, amount to a single large long-risk position. What matters is not only how many positions there are, but which common risk drivers lie behind them. The same applies to several strategies: if they lose money in the same market phases, the diversification effect is smaller than expected.

6. Leverage and derivatives

Derivatives can be useful for hedging, short positioning and efficient use of capital. At the same time, they increase the complexity of risk management.
Leverage amplifies both gains and losses. On top of this come liquidation risks, funding costs and the specific counterparty risks of the platform used. In times of high volatility, price gapping and slippage can even cause a leveraged position to be liquidated despite a stop-loss order being in place. Professional derivatives management therefore does not mean the highest possible leverage, but the controlled use of an additional tool.

7. Counterparty risk

Crypto assets are frequently traded and held via centralised exchanges, brokers, custodians or other service providers. Each of these relationships creates counterparty risk. It breaks down into six dimensions: exchange, custody, wallet, protocol, operational and execution.
A market portfolio can be correctly positioned and still be impaired if a platform halts withdrawals, becomes insolvent or suffers technical problems. Creditworthiness, regulation, operational stability and concentration on individual providers should therefore be taken into account.
Here, redundancy acts first on the size of the damage: if trading exposure is spread evenly across four mutually independent trading venues, an isolated total failure of one counterparty mathematically limits the immediate damage to 25% rather than 100% of the distributed portfolio. This effect holds regardless of the probability of failure. It does, however, require the trading venues to have genuinely independent causes of failure – shared cloud providers, market makers, stablecoins or oracle sources reduce the effect. The quantitative derivation can be found in our research paper on counterparty risk management.

8. Operational security

Access rights, API permissions, two-factor authentication, transfer approvals and internal processes are not purely IT matters. With digital assets, they are part of asset protection.
A professional set-up should follow the principle of least privilege: whoever executes trading decisions does not automatically need the same rights as someone who can transfer assets. Added to this are withdrawal whitelists and limits, hardware-based security keys and documented recovery processes. In addition, unusual activity, changes to permissions and critical transactions should be monitored in a traceable way.

9. Monitoring and escalation

Risk management does not end with the onboarding of an exchange or a custodian. What matters is the ongoing assessment of liquidity, withdrawals, governance, regulation, cybersecurity and technical availability. Proof of reserves can increase transparency, but it is no substitute for an analysis of liabilities and liquidity.
A defined escalation logic helps: from normal operation with regular counterparty assessment, through enhanced monitoring and a reduction of operational liquidity at the counterparty concerned, to migrating new orders to alternative infrastructure and, in the extreme case, a complete exit. A window for reaction may exist, but it is neither guaranteed nor something that can be planned for – a risk framework must not rely on it.

10. Reporting and governance

Risk management is only institutionally robust if it can be communicated in a way others can follow. An investor should understand which risks are permitted in principle and how the actual portfolio moves within that framework. For family offices, risk metrics, drawdowns, exposure and material changes can feed into regular reporting and governance processes.
Governance does not automatically produce better performance. It does, however, reduce the risk of decisions being taken outside the agreed framework or of risks being recognised too late.

Example: a portfolio of CHF 1 million

With a portfolio of CHF 1 million, the starting point should not be the question "How much can this trade earn?", but "How much may this idea lose without placing a disproportionate burden on the overall mandate?".
Suppose a mandate defines a risk budget of 0.5% of the portfolio for a specific position. That corresponds to CHF 5,000. If the technical invalidation lies, for example, five per cent from the entry, a rough starting size of CHF 100,000 in position value would be conceivable, before further factors such as fees, slippage, correlations or leverage are taken into account.
The example is not a recommendation for a specific position size. It merely shows the logic: first the permissible portfolio risk is defined, and the position is derived from it – not the other way round.

Conclusion

For larger crypto portfolios, risk management is not an add-on to the strategy. It is the structure that determines how far a strategy may be implemented at all.
Position sizes, drawdown, market regime, liquidity, correlation, derivatives, counterparties, operational security and governance must be considered together. The larger the mandate, the more important a process becomes that connects these risks systematically – typically within a Segregated Managed Account and a clearly defined Swiss mandate framework.
Dominik Schneeberger, Gründer & Managing Partner der Digital Estate Group AG

Author

Dominik Schneeberger

Founder & Managing Partner

More insights