INDEPENDENT · PRODUCT BRIEF·Product Analyst

Homework: Hata, Product Analyst

Every MYR pair Hata lists, measured against Luno at the same instant. Four findings that came out of it, including a flat minimum order size that costs a user over 3% round trip in spread alone. Then the Malaysian DAX landscape, each duty in the posting mapped to a plan, and a first 90 days.

~10x
Luno's 24h volume vs Hata, same 22 pairs
91%
of Hata's volume in four pairs
3%+
cost of the minimum order on WLDMYR
EN / 中文
both "preferred" qualifications, KL-based

Summary

Hata is Malaysia's fifth licensed digital asset exchange, the only one dual-licensed by both the Securities Commission and Labuan FSA, founded by Luno's former APAC general manager and backed by Bybit. The Product Analyst posting asks someone to review payment and settlement workflows, find transaction drop-offs, run UAT, and benchmark Hata against competitors.

Benchmarking is the one duty an outsider can do without access, so I did that one. I pulled Hata's Malaysian order book and Luno's, matched every shared MYR pair at the same instant, and measured spread, depth, volume and price divergence. The result is section ★, and the four product findings that fell out of it are section 03.

The finding I would act on first has nothing to do with liquidity, which Hata cannot fix quickly, and everything to do with a setting that can change this sprint: the minimum order size is a flat RM 10 on every pair regardless of spread, so on the widest books the smallest order a user is allowed to place loses several percent the moment it fills.

WHY ME, IN ONE BOX
  • Five years client-facing in crypto-fintech: Technical Support Engineer at BOB, Customer Success at Aztec, Analyst at KIP.
  • I already publish a Hata review and a five-operator Malaysian DAX comparison on my own data product.
  • Dune Wizard: funnel and drop-off work is query work, and mine is public.
  • Runs a live data-API product, so the integrator's seat is familiar.
  • Native English and Mandarin, based in KL.
01

Hata, in context

Two licences
SC Malaysia and Labuan FSA

Recognised Market Operator for Digital Assets from the Securities Commission, Malaysia's fifth DAX, plus a Labuan FSA licence. The only Malaysian exchange holding both.

Bybit-backed
USD 8m Series A, April 2026

Led by Bybit, following its USD 4.2m seed participation, earmarked for liquidity, user growth and joint product development. Founded by David Low, formerly Luno's APAC general manager.

Scale
End-2025

209,000+ registered users and RM 1.04 billion of 2025 trading volume, on a book that is now 23 MYR pairs deep.

Two exchanges, one brand, and you can only see it from the API

The most useful structural fact about Hata is not on the website. It runs two separate venues under two regulators, and the split is visible in the API surface.

HostRegulatorBookWhat it means
my-api.hata.ioSecurities Commission Malaysia, RMO-DAX23 MYR pairsThe real business. Concentrated liquidity, retail Malaysian flow, FPX and e-wallet rails
api.hata.ioLabuan Financial Services Authority6 USD / USDT pairsA licensed venue carrying listing, surveillance and support cost, and on the day I measured, close to no volume

The OpenAPI spec confirms the split at the auth layer with /auth/api/v2/my/ and /auth/api/v2/ww/ namespaces. Neither hostname is documented: the spec ships servers: [{url: "/"}] with hideHostname: true.

THE QUESTION I WOULD TAKE INTO THE ROOM

The Labuan venue is a strategic asset or a maintained cost, and which one it is should be a decision rather than a default. If it is a beachhead being funded deliberately ahead of a global push, that is a good reason to carry a quiet book. If nobody has revisited it since launch, it is six listings, a surveillance obligation and a support surface earning nothing. Asking the question well is more useful than assuming the answer, and it is the kind of question a product analyst should be raising.

02

The Malaysian DAX map

Five licences, one dominant incumbent, and a regulatory moat that makes this a genuinely small competitive set. Anyone benchmarking Hata is really benchmarking against Luno, because Luno is most of the market.

OperatorEntityPositionWhere Hata stands against them
LunoLuno Malaysia Sdn BhdThe incumbent. 51 MYR pairs, deepest retail liquidity, longest brand history in marketThe benchmark. Roughly ten times Hata's volume on shared pairs. Hata quotes tighter on several and lists one Luno does not
HataHata Digital Sdn BhdNewest DAX, dual-licensed SC and Labuan, Bybit-backed, 23 MYR pairsCompetitive at the top of the book, thin across the tail
MX GlobalMX Global Sdn BhdSC-licensed DAX, smaller retail footprintPeer rather than the pace-setter
SINEGYSINEGY DAX Sdn BhdPenang-based, SC-licensed, focused local operatorPeer
TokenizeTokenize Technology (M) Sdn BhdRenamed in August 2025 to distance itself from Tokenize Xchange Singapore, a separate entity that was under investigation and was never SC-licensed in MalaysiaReputationally distinct. Worth stating precisely, because most write-ups conflate the two

Operator list and entity names from the SC's regulated-market register and my own five-operator comparison at malaysia4u.com/crypto-guide. Volume comparison measured directly, see §★.

WHAT THE STRUCTURE MEANS FOR PRODUCT

A five-licence market means competition is not really about acquisition cost, because the set of legal alternatives is tiny and every one of them is discoverable. It is about whether a user who arrives actually funds an account and trades. That makes the deposit-to-first-trade funnel the highest-leverage surface in the business, which is exactly what the posting means by "transaction drop-offs", and it is why I would spend the first month there rather than on the roadmap.

Hata versus Luno, measured

Every MYR pair Hata lists, matched to Luno's public ticker at the same instant. Luno reports base-unit volume, so it is converted to ringgit at Luno's own mid at snapshot time. That makes it an estimate of MYR-equivalent turnover rather than a reported figure, and the two venues may also use different 24h windows. Treat the multiple as an order of magnitude. Snapshot of 2026-07-30 14:16 UTC. Pair-level spreads move intraday: across two runs an hour apart the headline multiple moved between 9.3x and 10.0x and individual spreads moved considerably more. Treat the structure as the finding and the console as the current number.

RM 1.01m
Hata, 24h, all 23 pairs
RM 9.29m
Luno, same 22 shared pairs
~10x
Luno's multiple on identical instruments
23 vs 51
MYR pairs listed
PairHata spreadLuno spreadHata 24hLuno 24hRead
ETHMYR12.7 bps1.3 bpsRM 252,969RM 1,221,688Top pair by Hata volume, a fifth of Luno's flow
SOLMYR3.3 bps0.3 bpsRM 252,506RM 342,666Closest to parity on volume
BTCMYR4.4 bps0.0 bpsRM 233,421RM 3,918,149The flagship pair, and the widest volume gap
XRPMYR18.1 bps0.2 bpsRM 141,570RM 2,202,146Tight-ish quote, thin flow
NEARMYR14.8 bps193.3 bpsRM 15,891RM 12,203Hata wins on spread and volume
HBARMYR14.3 bps132.6 bpsRM 13,236RM 22,837Hata quotes tighter
WLDMYR372.0 bpsnot listedRM 10,186n/aHata-only listing, and the widest book on the venue
UNIMYR172.2 bps5.7 bpsRM 6,342RM 384,12030x wider quote, 60x less flow
LINKMYR52.1 bps2.9 bpsRM 250RM 31,852Effectively dormant
SKYMYR55.3 bps4.3 bpsRM 34RM 19,311Thirty-four ringgit in a day

Ten of 23 pairs shown. Full table, every pair, in the console ↗.

THE SHAPE OF IT

ETHMYR, SOLMYR, BTCMYR and XRPMYR are 91% of Hata's entire MYR volume. Those four are also the only pairs where the spread is genuinely competitive. The other 19 pairs share 9% of the flow and carry every wide quote on the venue. That is a concentrated business with a long tail attached, and the tail is where the cost sits.

WHERE HATA GENUINELY WINS

Saying this matters, because a benchmark that only finds problems is advocacy rather than analysis. Hata quotes materially tighter than Luno on NEARMYR (59 vs 318 bps), HBARMYR (40 vs 147), LTCMYR (11 vs 54) and XLMMYR (14 vs 28), does more 24h volume than Luno on NEARMYR, and lists WLDMYR, which Luno does not carry at all. Being more selective at 23 pairs against 51 is also a defensible strategy rather than a shortfall.

03

Four findings

Ranked by how quickly Hata could act on them. The first is a setting, not a market condition, which is why it leads.

ACT FIRSTThe minimum order size is flat, and on wide books it is a trap

min_notional is RM 10 on every one of the 23 pairs, whatever the spread. Spending RM 10 buying and then selling back the exact quantity acquired, what fails to come back is over 3% on WLDMYR and above 1% on six pairs. Spread and slippage only, before any fee.

Why it matters: a wide spread on a quiet pair is nobody's fault. Permitting the platform's own minimum order into it without showing what it costs is a design choice, and the user finds out after the fill. On an SC-licensed venue that becomes a complaints-handling record as well as a support ticket.

What I would ship: tier min_notional by realised spread, or leave the minimum alone and show an estimated round-trip cost at order entry when spread crosses a threshold. The second is one sprint and removes the surprise.

DECIDEThe long tail costs more than it returns

SKYMYR did RM 34 in 24 hours. LINKMYR did RM 147 against Luno's RM 30,408 on the same pair. Each listing carries market surveillance, SC reporting surface, support surface and screen space, and returns close to nothing.

What I would bring to the table: a listing scorecard with an explicit review trigger, so pairs are delisted or given market-maker support by a written rule rather than by whoever notices. The recommendation itself is a management decision; the analysis and the rule are the analyst's job.

MONITORPrice divergence on the thin pairs

Mid against Luno's mid at the same instant: HBARMYR -292 bps, XLMMYR -204, NEARMYR -188, DOTMYR -126. Entirely expected on a thin book, and still worth an automated cross-venue reference check, because a user who compares two Malaysian venues and sees a 3% gap will ask, and a regulated venue should have the answer ready before they do.

CONTRIBUTEThe public API is half-public, and the docs do not say so

Three things a partner integrating with Hata will hit, offered as a contribution rather than a complaint:

  • Neither my-api.hata.io nor api.hata.io appears in the docs, so copying the documented pair_name=BTCMYR example against the obvious host fails, because that host carries no MYR pairs.
  • The API returns 403 to a default scripted user-agent and to any request carrying an Origin header, and sends no CORS header. So no browser tool can call it, and a partner's backend breaks on a header nothing documents.
  • The OpenAPI changelog is currently catching spelling and type slips by hand (user_Id, reciepient, borrowing typed bool). A schema lint in CI catches that class automatically.

All three are small, and the first is the reason the console ships a stamped snapshot rather than a live read.

04

Each duty in the posting, my plan

The posting saysWhat I would actually doEvidence I can do itShown in
Review payment gateway performance, settlement cycles and wallet operations against targetsInstrument the funnel end to end before touching anything: FPX, bank transfer and e-wallet deposit success rates by rail and by hour, time-to-credit distribution rather than an average, and withdrawal rejection reasons grouped by cause. Averages hide the tail, and the tail is the complaint.Runs a live data-API product on scheduled jobs; Python eval harnesses at KIP§05
Map end-to-end user journeys and fund flows to find automation opportunitiesOne diagram per rail, from bank debit to tradable balance, with every state a transaction can be stuck in and who owns each. The automation candidates fall out of that map rather than out of a brainstorm.Wrote BOB's support knowledge base and process from nothing§05
Detect operational bottlenecks and transaction drop-offs in deposit and withdrawal patternsThe single number I would want on day one: registered to KYC-passed to funded to first-trade. With 209k registered users against RM 1bn of annual volume, the gap between registered and funded is almost certainly the largest addressable number in the business.Dune Wizard, published on-chain SQL; funnel work at KIP§05
Assist with requirement gathering, PRDs and user-flow mappingWrite the PRD from the measured problem, not from the request. Every one opens with the number it moves and how we will know it moved.Ships product end to end solo; specs, builds and maintains it§06
Lead User Acceptance Testing for back-office tools and payment integrationsTest the failure paths, because the happy path always works. A written matrix per rail: timeout, partial credit, duplicate reference, name mismatch, limit breach, cutoff boundary. Plus the API contract checks in §03 running in CI.Built the nine-assertion contract suite for a regulated issuer this month§03
Benchmark Hata's features against regional and global competitorsAlready done and running. Not a one-off deck: the console re-measures, so the comparison is a standing instrument rather than a slide that ages.§★ and the console§07
Maintain product documentation aligned with regulatory requirementsKeep the SC-facing documentation and the internal runbook as one source, because two drift. Learn what an RMO-DAX actually owes the Commission early rather than discovering it at a deadline.CompTIA Security+; regulated-issuer research at MAS-licensed Paxos this month§06
05

How I would run the analysis

The funnel first, because everything else is downstream of it.

Registered
209k+
KYC passed
Sumsub, drop reasons
Deposit attempted
FPX, transfer, e-wallet
Funded
time-to-credit
First trade
which pair, what size
Retained
30-day repeat
METRICS WORTH RUNNING
  • Time-to-credit as a distribution, never an average. The 95th percentile is the ticket.
  • Deposit failure by rail and by hour. Bank cutoffs and holidays make this a clock problem, not a volume problem.
  • Withdrawal rejections grouped by cause, with name-mismatch separated out, because that one is fixable in the UI.
  • First-trade pair mix. If new users land on a wide-spread pair, finding 1 is costing acquisitions as well as support time.
  • Cost-to-trade by pair, tracked over time. The benchmark in §★ as a standing number.
HOW I WOULD WORK
  • Measure before proposing. Every recommendation opens with the number it moves.
  • Deliver in whatever form gets used. If the company runs on spreadsheets, the answer is a spreadsheet.
  • Separate what I found from what I recommend, so management can disagree with one without discarding the other.
  • Write the rule, not the one-off. A listing scorecard beats a listing opinion.
  • Say when a number is a snapshot and when it is a trend. One day is never a trend.
06

First 90 days

Days 1 to 30 · Get the funnel on one page

Map every deposit and withdrawal rail end to end with the states a transaction can be stuck in. Get the registered-to-funded-to-first-trade numbers, which probably do not exist as a single view today. Read the SC reporting obligations that land on product so I am not surprised by a deadline. Ship the estimated-cost warning from finding 1, because it is small, it is measurable, and it proves the loop works.

Days 31 to 60 · Turn findings into rules

Listing scorecard with a written review trigger, taken to whoever owns the listing decision. Cross-venue reference monitoring on the thin pairs. UAT failure-path matrix per rail, and the API contract checks from finding 4 running in CI. Start the withdrawal-rejection breakdown, because name-mismatch rejections are usually a UI fix wearing a compliance costume.

Days 61 to 90 · Make the benchmark standing

The Hata-versus-Luno comparison running on a schedule with the numbers going to whoever sets pricing and listings, so it informs decisions instead of decorating a deck. First quarterly product-operations review: what the funnel did, what we shipped, what moved, what is still open.

WHAT I WOULD NEED

Read access to the warehouse or a read replica. Without it this role is forwarding questions to engineering and waiting, and every number above stays limited to what a public endpoint will tell an outsider. Also clarity on who owns the listing decision and who owns pricing, because findings 1 and 2 both land on someone and it is better to know who on day one.

07

The benchmark console

Everything in §★ and §03, working, with the method visible. Read-only, unauthenticated, public endpoints only.

Head to head

All 23 Hata MYR pairs against Luno: spread, ringgit volume both sides, relative volume bars, price divergence and book depth. Pairs where Hata quotes tighter are marked, because a benchmark that only finds problems is not a benchmark.

Open ↗
Cost of the minimum order

Spends RM 10 buying on every pair, sells back the quantity acquired, and reports what fails to come back in percent and in ringgit, with a verdict per pair. This is finding 1, made concrete.

Open ↗
Two venues, one brand

The Malaysian book against the Labuan book, side by side, with the global venue's six pairs listed out.

Open ↗
Docs and contract checks

Six assertions against the live API, each with the real response, the client impact and a proposed fix. Two pass.

Open ↗
HONEST LIMITS

The console serves a stamped snapshot rather than a live read, and the reason is finding 4: Hata's API rejects any request carrying an Origin header and any default user-agent, and both hosts sit behind Cloudflare so an edge proxy fails with error 1042. The only way to read the data is a plain server-side process, which is refresh.py in the repository, run by hand and timestamped. In production it would be a scheduled job. Saying that plainly is better than implying the page is live. This also reads public market data only, so it says nothing about Hata's internal funnel, which is the part I would actually be hired to fix.

08

Method & sources

Method

  • Read the posting (public job posting, 2026), then worked out what the job is from what the business actually operates.
  • Pulled Hata's Malaysian book from my-api.hata.io: /orderbook/api/v2/exchange-info for all 23 pairs, then /orderbook/api/orderbook?pair_name= for full depth on each. The global book from api.hata.io. 26 calls per refresh.
  • Matched against Luno's public tickers, converting base-unit volume to ringgit at Luno's own mid so both sides are comparable notional. Luno quotes Bitcoin as XBT, mapped accordingly.
  • Cost of the minimum order is a true round trip: spend RM 10 walking the asks, then sell the exact quantity acquired back into the bids. Two fixed notionals would overstate it on an asymmetric book. Spread and slippage only, before fees; it excludes taker fees, latency, replenishment and hidden liquidity.
  • Read the OpenAPI spec at developers.hata.io, including its changelog, for the documentation findings.
  • Every figure is stamped and reproducible. One day is a snapshot, not a trend, and it is labelled as such throughout.

Sources

  • my-api.hata.io and api.hata.io, public market data, probed 30 July 2026.
  • developers.hata.io, OpenAPI 1.0.0, changelog last updated 2026-07-03.
  • api.luno.com/api/1/tickers, 51 MYR pairs, same timestamp.
  • SC Malaysia regulated-market register for the five licensed DAX operators; Labuan FSA for the second licence.
  • Bybit-led USD 8m Series A (April 2026) and the earlier USD 4.2m seed; 209k registered users and RM 1.04bn 2025 volume, from contemporaneous coverage.
  • Sumsub published case study for the KYC stack.
  • My own Hata review and five-operator Malaysian DAX comparison, which predate this application.

Independent work by Edward Tay for the Hata Product Analyst application. Not affiliated with Hata or Luno, and not their code. edwardtay.com · benchmark console ↗