1. Encrypt you users private keys client side with a password only they know. Now I just hold encrypted keys my side.
2. When the user wishes to make an exchange I would create the transaction client side let them sign it and do the exchange.
This way funds are now encrypted by default at rest and if compromise occurs the thief gets encrypted private keys only. Hopefully the users chose passwords secure enough to avoid compromise.
It's not perfect, but can we finally move away from the hot wallet model.
p.s. If you want to build this, and require advice and backing let me know.