Homework: Hata, Product Analyst
Every MYR pair Hata lists, measured against Luno at the same instant. Four findings that came out of it, including a flat minimum order size that costs a user over 3% round trip in spread alone. Then the Malaysian DAX landscape, each duty in the posting mapped to a plan, and a first 90 days.
Summary
Hata is Malaysia's fifth licensed digital asset exchange, the only one dual-licensed by both the Securities Commission and Labuan FSA, founded by Luno's former APAC general manager and backed by Bybit. The Product Analyst posting asks someone to review payment and settlement workflows, find transaction drop-offs, run UAT, and benchmark Hata against competitors.
Benchmarking is the one duty an outsider can do without access, so I did that one. I pulled Hata's Malaysian order book and Luno's, matched every shared MYR pair at the same instant, and measured spread, depth, volume and price divergence. The result is section ★, and the four product findings that fell out of it are section 03.
The finding I would act on first has nothing to do with liquidity, which Hata cannot fix quickly, and everything to do with a setting that can change this sprint: the minimum order size is a flat RM 10 on every pair regardless of spread, so on the widest books the smallest order a user is allowed to place loses several percent the moment it fills.
- Five years client-facing in crypto-fintech: Technical Support Engineer at BOB, Customer Success at Aztec, Analyst at KIP.
- I already publish a Hata review and a five-operator Malaysian DAX comparison on my own data product.
- Dune Wizard: funnel and drop-off work is query work, and mine is public.
- Runs a live data-API product, so the integrator's seat is familiar.
- Native English and Mandarin, based in KL.
Hata, in context
Recognised Market Operator for Digital Assets from the Securities Commission, Malaysia's fifth DAX, plus a Labuan FSA licence. The only Malaysian exchange holding both.
Led by Bybit, following its USD 4.2m seed participation, earmarked for liquidity, user growth and joint product development. Founded by David Low, formerly Luno's APAC general manager.
209,000+ registered users and RM 1.04 billion of 2025 trading volume, on a book that is now 23 MYR pairs deep.
Two exchanges, one brand, and you can only see it from the API
The most useful structural fact about Hata is not on the website. It runs two separate venues under two regulators, and the split is visible in the API surface.
| Host | Regulator | Book | What it means |
|---|---|---|---|
my-api.hata.io | Securities Commission Malaysia, RMO-DAX | 23 MYR pairs | The real business. Concentrated liquidity, retail Malaysian flow, FPX and e-wallet rails |
api.hata.io | Labuan Financial Services Authority | 6 USD / USDT pairs | A licensed venue carrying listing, surveillance and support cost, and on the day I measured, close to no volume |
The OpenAPI spec confirms the split at the auth layer with /auth/api/v2/my/ and /auth/api/v2/ww/ namespaces. Neither hostname is documented: the spec ships servers: [{url: "/"}] with hideHostname: true.
The Labuan venue is a strategic asset or a maintained cost, and which one it is should be a decision rather than a default. If it is a beachhead being funded deliberately ahead of a global push, that is a good reason to carry a quiet book. If nobody has revisited it since launch, it is six listings, a surveillance obligation and a support surface earning nothing. Asking the question well is more useful than assuming the answer, and it is the kind of question a product analyst should be raising.
The Malaysian DAX map
Five licences, one dominant incumbent, and a regulatory moat that makes this a genuinely small competitive set. Anyone benchmarking Hata is really benchmarking against Luno, because Luno is most of the market.
| Operator | Entity | Position | Where Hata stands against them |
|---|---|---|---|
| Luno | Luno Malaysia Sdn Bhd | The incumbent. 51 MYR pairs, deepest retail liquidity, longest brand history in market | The benchmark. Roughly ten times Hata's volume on shared pairs. Hata quotes tighter on several and lists one Luno does not |
| Hata | Hata Digital Sdn Bhd | Newest DAX, dual-licensed SC and Labuan, Bybit-backed, 23 MYR pairs | Competitive at the top of the book, thin across the tail |
| MX Global | MX Global Sdn Bhd | SC-licensed DAX, smaller retail footprint | Peer rather than the pace-setter |
| SINEGY | SINEGY DAX Sdn Bhd | Penang-based, SC-licensed, focused local operator | Peer |
| Tokenize | Tokenize Technology (M) Sdn Bhd | Renamed in August 2025 to distance itself from Tokenize Xchange Singapore, a separate entity that was under investigation and was never SC-licensed in Malaysia | Reputationally distinct. Worth stating precisely, because most write-ups conflate the two |
Operator list and entity names from the SC's regulated-market register and my own five-operator comparison at malaysia4u.com/crypto-guide. Volume comparison measured directly, see §★.
A five-licence market means competition is not really about acquisition cost, because the set of legal alternatives is tiny and every one of them is discoverable. It is about whether a user who arrives actually funds an account and trades. That makes the deposit-to-first-trade funnel the highest-leverage surface in the business, which is exactly what the posting means by "transaction drop-offs", and it is why I would spend the first month there rather than on the roadmap.
Hata versus Luno, measured
Every MYR pair Hata lists, matched to Luno's public ticker at the same instant. Luno reports base-unit volume, so it is converted to ringgit at Luno's own mid at snapshot time. That makes it an estimate of MYR-equivalent turnover rather than a reported figure, and the two venues may also use different 24h windows. Treat the multiple as an order of magnitude. Snapshot of 2026-07-30 14:16 UTC. Pair-level spreads move intraday: across two runs an hour apart the headline multiple moved between 9.3x and 10.0x and individual spreads moved considerably more. Treat the structure as the finding and the console as the current number.
| Pair | Hata spread | Luno spread | Hata 24h | Luno 24h | Read |
|---|---|---|---|---|---|
| ETHMYR | 12.7 bps | 1.3 bps | RM 252,969 | RM 1,221,688 | Top pair by Hata volume, a fifth of Luno's flow |
| SOLMYR | 3.3 bps | 0.3 bps | RM 252,506 | RM 342,666 | Closest to parity on volume |
| BTCMYR | 4.4 bps | 0.0 bps | RM 233,421 | RM 3,918,149 | The flagship pair, and the widest volume gap |
| XRPMYR | 18.1 bps | 0.2 bps | RM 141,570 | RM 2,202,146 | Tight-ish quote, thin flow |
| NEARMYR | 14.8 bps | 193.3 bps | RM 15,891 | RM 12,203 | Hata wins on spread and volume |
| HBARMYR | 14.3 bps | 132.6 bps | RM 13,236 | RM 22,837 | Hata quotes tighter |
| WLDMYR | 372.0 bps | not listed | RM 10,186 | n/a | Hata-only listing, and the widest book on the venue |
| UNIMYR | 172.2 bps | 5.7 bps | RM 6,342 | RM 384,120 | 30x wider quote, 60x less flow |
| LINKMYR | 52.1 bps | 2.9 bps | RM 250 | RM 31,852 | Effectively dormant |
| SKYMYR | 55.3 bps | 4.3 bps | RM 34 | RM 19,311 | Thirty-four ringgit in a day |
Ten of 23 pairs shown. Full table, every pair, in the console ↗.
ETHMYR, SOLMYR, BTCMYR and XRPMYR are 91% of Hata's entire MYR volume. Those four are also the only pairs where the spread is genuinely competitive. The other 19 pairs share 9% of the flow and carry every wide quote on the venue. That is a concentrated business with a long tail attached, and the tail is where the cost sits.
Saying this matters, because a benchmark that only finds problems is advocacy rather than analysis. Hata quotes materially tighter than Luno on NEARMYR (59 vs 318 bps), HBARMYR (40 vs 147), LTCMYR (11 vs 54) and XLMMYR (14 vs 28), does more 24h volume than Luno on NEARMYR, and lists WLDMYR, which Luno does not carry at all. Being more selective at 23 pairs against 51 is also a defensible strategy rather than a shortfall.
Four findings
Ranked by how quickly Hata could act on them. The first is a setting, not a market condition, which is why it leads.
min_notional is RM 10 on every one of the 23 pairs, whatever the spread. Spending RM 10 buying and then selling back the exact quantity acquired, what fails to come back is over 3% on WLDMYR and above 1% on six pairs. Spread and slippage only, before any fee.
Why it matters: a wide spread on a quiet pair is nobody's fault. Permitting the platform's own minimum order into it without showing what it costs is a design choice, and the user finds out after the fill. On an SC-licensed venue that becomes a complaints-handling record as well as a support ticket.
What I would ship: tier min_notional by realised spread, or leave the minimum alone and show an estimated round-trip cost at order entry when spread crosses a threshold. The second is one sprint and removes the surprise.
SKYMYR did RM 34 in 24 hours. LINKMYR did RM 147 against Luno's RM 30,408 on the same pair. Each listing carries market surveillance, SC reporting surface, support surface and screen space, and returns close to nothing.
What I would bring to the table: a listing scorecard with an explicit review trigger, so pairs are delisted or given market-maker support by a written rule rather than by whoever notices. The recommendation itself is a management decision; the analysis and the rule are the analyst's job.
Mid against Luno's mid at the same instant: HBARMYR -292 bps, XLMMYR -204, NEARMYR -188, DOTMYR -126. Entirely expected on a thin book, and still worth an automated cross-venue reference check, because a user who compares two Malaysian venues and sees a 3% gap will ask, and a regulated venue should have the answer ready before they do.
Three things a partner integrating with Hata will hit, offered as a contribution rather than a complaint:
- Neither
my-api.hata.ionorapi.hata.ioappears in the docs, so copying the documentedpair_name=BTCMYRexample against the obvious host fails, because that host carries no MYR pairs. - The API returns
403to a default scripted user-agent and to any request carrying anOriginheader, and sends no CORS header. So no browser tool can call it, and a partner's backend breaks on a header nothing documents. - The OpenAPI changelog is currently catching spelling and type slips by hand (
user_Id,reciepient,borrowingtypedbool). A schema lint in CI catches that class automatically.
All three are small, and the first is the reason the console ships a stamped snapshot rather than a live read.
Each duty in the posting, my plan
| The posting says | What I would actually do | Evidence I can do it | Shown in |
|---|---|---|---|
| Review payment gateway performance, settlement cycles and wallet operations against targets | Instrument the funnel end to end before touching anything: FPX, bank transfer and e-wallet deposit success rates by rail and by hour, time-to-credit distribution rather than an average, and withdrawal rejection reasons grouped by cause. Averages hide the tail, and the tail is the complaint. | Runs a live data-API product on scheduled jobs; Python eval harnesses at KIP | §05 |
| Map end-to-end user journeys and fund flows to find automation opportunities | One diagram per rail, from bank debit to tradable balance, with every state a transaction can be stuck in and who owns each. The automation candidates fall out of that map rather than out of a brainstorm. | Wrote BOB's support knowledge base and process from nothing | §05 |
| Detect operational bottlenecks and transaction drop-offs in deposit and withdrawal patterns | The single number I would want on day one: registered to KYC-passed to funded to first-trade. With 209k registered users against RM 1bn of annual volume, the gap between registered and funded is almost certainly the largest addressable number in the business. | Dune Wizard, published on-chain SQL; funnel work at KIP | §05 |
| Assist with requirement gathering, PRDs and user-flow mapping | Write the PRD from the measured problem, not from the request. Every one opens with the number it moves and how we will know it moved. | Ships product end to end solo; specs, builds and maintains it | §06 |
| Lead User Acceptance Testing for back-office tools and payment integrations | Test the failure paths, because the happy path always works. A written matrix per rail: timeout, partial credit, duplicate reference, name mismatch, limit breach, cutoff boundary. Plus the API contract checks in §03 running in CI. | Built the nine-assertion contract suite for a regulated issuer this month | §03 |
| Benchmark Hata's features against regional and global competitors | Already done and running. Not a one-off deck: the console re-measures, so the comparison is a standing instrument rather than a slide that ages. | §★ and the console | §07 |
| Maintain product documentation aligned with regulatory requirements | Keep the SC-facing documentation and the internal runbook as one source, because two drift. Learn what an RMO-DAX actually owes the Commission early rather than discovering it at a deadline. | CompTIA Security+; regulated-issuer research at MAS-licensed Paxos this month | §06 |
How I would run the analysis
The funnel first, because everything else is downstream of it.
- Time-to-credit as a distribution, never an average. The 95th percentile is the ticket.
- Deposit failure by rail and by hour. Bank cutoffs and holidays make this a clock problem, not a volume problem.
- Withdrawal rejections grouped by cause, with name-mismatch separated out, because that one is fixable in the UI.
- First-trade pair mix. If new users land on a wide-spread pair, finding 1 is costing acquisitions as well as support time.
- Cost-to-trade by pair, tracked over time. The benchmark in §★ as a standing number.
- Measure before proposing. Every recommendation opens with the number it moves.
- Deliver in whatever form gets used. If the company runs on spreadsheets, the answer is a spreadsheet.
- Separate what I found from what I recommend, so management can disagree with one without discarding the other.
- Write the rule, not the one-off. A listing scorecard beats a listing opinion.
- Say when a number is a snapshot and when it is a trend. One day is never a trend.
First 90 days
Map every deposit and withdrawal rail end to end with the states a transaction can be stuck in. Get the registered-to-funded-to-first-trade numbers, which probably do not exist as a single view today. Read the SC reporting obligations that land on product so I am not surprised by a deadline. Ship the estimated-cost warning from finding 1, because it is small, it is measurable, and it proves the loop works.
Listing scorecard with a written review trigger, taken to whoever owns the listing decision. Cross-venue reference monitoring on the thin pairs. UAT failure-path matrix per rail, and the API contract checks from finding 4 running in CI. Start the withdrawal-rejection breakdown, because name-mismatch rejections are usually a UI fix wearing a compliance costume.
The Hata-versus-Luno comparison running on a schedule with the numbers going to whoever sets pricing and listings, so it informs decisions instead of decorating a deck. First quarterly product-operations review: what the funnel did, what we shipped, what moved, what is still open.
Read access to the warehouse or a read replica. Without it this role is forwarding questions to engineering and waiting, and every number above stays limited to what a public endpoint will tell an outsider. Also clarity on who owns the listing decision and who owns pricing, because findings 1 and 2 both land on someone and it is better to know who on day one.
The benchmark console
Everything in §★ and §03, working, with the method visible. Read-only, unauthenticated, public endpoints only.
All 23 Hata MYR pairs against Luno: spread, ringgit volume both sides, relative volume bars, price divergence and book depth. Pairs where Hata quotes tighter are marked, because a benchmark that only finds problems is not a benchmark.
Open ↗Spends RM 10 buying on every pair, sells back the quantity acquired, and reports what fails to come back in percent and in ringgit, with a verdict per pair. This is finding 1, made concrete.
Open ↗The Malaysian book against the Labuan book, side by side, with the global venue's six pairs listed out.
Open ↗Six assertions against the live API, each with the real response, the client impact and a proposed fix. Two pass.
Open ↗The console serves a stamped snapshot rather than a live read, and the reason is finding 4: Hata's API rejects any request carrying an Origin header and any default user-agent, and both hosts sit behind Cloudflare so an edge proxy fails with error 1042. The only way to read the data is a plain server-side process, which is refresh.py in the repository, run by hand and timestamped. In production it would be a scheduled job. Saying that plainly is better than implying the page is live. This also reads public market data only, so it says nothing about Hata's internal funnel, which is the part I would actually be hired to fix.
Method & sources
Method
- Read the posting (public job posting, 2026), then worked out what the job is from what the business actually operates.
- Pulled Hata's Malaysian book from
my-api.hata.io:/orderbook/api/v2/exchange-infofor all 23 pairs, then/orderbook/api/orderbook?pair_name=for full depth on each. The global book fromapi.hata.io. 26 calls per refresh. - Matched against Luno's public tickers, converting base-unit volume to ringgit at Luno's own mid so both sides are comparable notional. Luno quotes Bitcoin as XBT, mapped accordingly.
- Cost of the minimum order is a true round trip: spend RM 10 walking the asks, then sell the exact quantity acquired back into the bids. Two fixed notionals would overstate it on an asymmetric book. Spread and slippage only, before fees; it excludes taker fees, latency, replenishment and hidden liquidity.
- Read the OpenAPI spec at
developers.hata.io, including its changelog, for the documentation findings. - Every figure is stamped and reproducible. One day is a snapshot, not a trend, and it is labelled as such throughout.
Sources
my-api.hata.ioandapi.hata.io, public market data, probed 30 July 2026.- developers.hata.io, OpenAPI 1.0.0, changelog last updated 2026-07-03.
- api.luno.com/api/1/tickers, 51 MYR pairs, same timestamp.
- SC Malaysia regulated-market register for the five licensed DAX operators; Labuan FSA for the second licence.
- Bybit-led USD 8m Series A (April 2026) and the earlier USD 4.2m seed; 209k registered users and RM 1.04bn 2025 volume, from contemporaneous coverage.
- Sumsub published case study for the KYC stack.
- My own Hata review and five-operator Malaysian DAX comparison, which predate this application.
Independent work by Edward Tay for the Hata Product Analyst application. Not affiliated with Hata or Luno, and not their code. edwardtay.com · benchmark console ↗