The comparison
Every exchange we grade, side by side
The same safety grades as the Safety Center, in one table you can re-order β by grade, by name, or down any one of the five checks.
15 exchanges graded Β· A- to D
The comparison
Read it down a column
How many of the graded venues disclose each check at all. The table below answers why one exchange scores what it does; this answers who publishes anything on the question.
Proof of reserves
30%6/15
Disclosed
- Partial or unaudited
- 6
- Not disclosed
- 3
Custody
25%1/15
Disclosed
- Partial or unaudited
- 14
- Not disclosed
- 0
Regulation
20%4/15
Disclosed
- Partial or unaudited
- 9
- Not disclosed
- 2
Insurance
15%2/15
Disclosed
- Partial or unaudited
- 10
- Not disclosed
- 3
Incident history
10%7/15
Disclosed
- Partial or unaudited
- 6
- Not disclosed
- 2
The core question
The full ledger
Tap any row for the factor-by-factor breakdown, or open the full review.
- Disclosed
- Partial or unaudited
- Not disclosed
01A-Kraken
Kraken holds a Wyoming SPDI charter, CFTC and SEC registrations and two EU MiCA authorisations, and has published Merkle-tree proof of reserves verified by Armanino LLP since February 2022; it discloses no insurance-fund figure.
- Proof of reserves β Merkle-tree proof of reserves verified by third-party accountant Armanino LLP since February 2022, most recently finalised 30 June 2025 across BTC, ETH, SOL, USDC, USDT, XRP and ADA. (meets this factor)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β Wyoming Special Purpose Depository Institution charter, CFTC DCM/DCO/FCM and SEC broker-dealer/RIA registrations, and two EU MiCA CASP authorisations; settled with the CFTC for $1.25m in September 2021 and with the SEC for $30m in February 2023 over its U.S. staking-as-a-service programme, relaunching on-chain U.S. staking in January 2025. (meets this factor)
- Insurance β No insurance-fund figure is publicly disclosed. Our research found no SAFU-equivalent named fund, which is a disclosure gap rather than confirmation that none exists. (partial or unverified)
- Incident history β No confirmed major security incident found in our research; Kraken has operated since 2011 with no reported breach costing customers funds. (meets this factor)
02B-Binance
Binance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.
- Proof of reserves β Publishes Merkle-tree proof of reserves covering 30-plus assets, most recently a 1 January 2026 snapshot of 636,535 BTC, but the reports are self-published rather than independently audited. (partial or unverified)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β Holds an ADGM (UAE) authorisation and, via Binance.US, money-transmitter licences in 30 states (NMLS ID 1906829); pleaded guilty to U.S. Bank Secrecy Act and sanctions violations in November 2023, paying $4.3bn and accepting a five-year DOJ compliance monitorship running to 2028. (partial or unverified)
- Insurance β SAFU user-protection fund, established in 2018 and topped up to $1bn in November 2022; it covered the May 2019 hack in full. (meets this factor)
- Incident history β About 7,000 BTC (roughly $40m at the time) drained from hot wallets on 7 May 2019; the SAFU fund covered the loss in full and no user lost funds. No platform breach of comparable scale has been reported since. (partial or unverified)
03B+Bitget
Bitget publishes a monthly open-source Merkle-tree proof of reserves showing BTC at 138% and ETH at 181%, and cites a protection fund its own sources size differently; ASIC issued an investor alert in July 2025 over unlicensed high-leverage derivatives.
- Proof of reserves β Monthly open-source Merkle-tree proof of reserves published on GitHub, showing BTC reserves at 138%, ETH at 181%, USDC at 107% and USDT at 101%. (meets this factor)
- Custody β Uses multi-signature cold storage, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (partial or unverified)
- Regulation β Lists an AUSTRAC registration, El Salvador CNAD/BSP licences, Argentine CNV and Mexican SAT registrations, a UK FCA Section 21 approver partnership and a Swiss FINMA SRO membership, without registration numbers we could check against public registers. ASIC issued a public investor alert on 28 July 2025 over unlicensed crypto derivatives sold to Australian retail clients at up to 125x leverage, noting Bitget holds no Australian Financial Services licence; its own corporate registration is cited variously as Seychelles, Lithuania or New Zealand. (partial or unverified)
- Insurance β A protection fund is disclosed but sized inconsistently across sources β $630m in one, 6,500 BTC (implemented December 2022) in another β so no single figure is confirmed. (partial or unverified)
- Incident history β No confirmed major security incident found in our research. (meets this factor)
04B-Bybit
Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46β1.5bn β the largest exchange hack on record β replenishing reserves in full within 72 hours.
- Proof of reserves β Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor. (meets this factor)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax. (partial or unverified)
- Insurance β Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed. (partial or unverified)
- Incident history β About $1.46β1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group β the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen. (does not meet this factor)
05BCoinbase
Coinbase is a publicly traded, SEC-reporting U.S. company licensed in 45 states and holding a New York BitLicense, and the SEC's 2023 case against it was dismissed with prejudice in February 2025; it runs no crypto-specific proof-of-reserves programme and its last disclosed crime-insurance figure dates from 2019.
- Proof of reserves β Runs no exchange-wide proof-of-reserves programme; reserve assurance rests on its Deloitte-audited filings as an SEC-reporting public company, plus per-asset attestations for wrapped tokens such as cbBTC. (partial or unverified)
- Custody β Coinbase Custody is an NYDFS-regulated qualified custodian, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (partial or unverified)
- Regulation β New York BitLicense, FinCEN MSB registration, UK FCA registration FRN 900635 and licences in 45 U.S. states; paid a $100m NYDFS consent order in January 2023, and the SEC's 2023 unregistered-exchange suit was dismissed with prejudice on 27 February 2025. (meets this factor)
- Insurance β A $255m crime policy covering hot-wallet assets was disclosed in 2019; Coinbase still advertises commercial crime cover for custodied assets but has not confirmed a current figure. (partial or unverified)
- Incident history β No confirmed platform-level breach of customer funds found in our research. (meets this factor)
06B-Crypto.com
Crypto.com discloses more than $870m of insurance cover, had its SEC investigation closed with no action in March 2025 and holds a Malta MiCA authorisation; its proof-of-reserves position is contested between our sources, and it reimbursed all users after a January 2022 incident that drained about $34β35m from 483 accounts.
- Proof of reserves β Our two sources conflict: one records a published proof-of-reserves portal, the other found no exchange-wide programme. No methodology, auditor or reserve figure was confirmed either way. (partial or unverified)
- Custody β Cold-storage assets sit with custodial partner Ledger Vault, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (partial or unverified)
- Regulation β Malta MFSA MiCA CASP authorisation granted 27 January 2025 covering 6 of the 10 service categories, plus an EU Limited Financial Institution licence from 27 February 2026 for stablecoin services, and licences listed across Singapore, Canada, the UK, Australia, Hong Kong, Brazil and the U.S. without registration numbers we could check against public registers. The SEC closed its investigation with no enforcement action on 27 March 2025. (partial or unverified)
- Insurance β More than $870m of disclosed cover: $750m on cold-storage assets through custodial partner Ledger Vault, expanded September 2021, plus $120m of institutional custody insurance arranged through Aon and announced 25 June 2025. U.S. fiat balances are held at FDIC-insured Community Federal Savings Bank. (meets this factor)
- Incident history β About $34β35m taken from 483 accounts in January 2022 through a 2FA compromise; Crypto.com disclosed the breach publicly and fully reimbursed all affected users. (partial or unverified)
07BHTX
HTX publishes monthly Merkle-tree proof of reserves that excludes corporate holdings, discloses only a Pakistani no-objection certificate among its authorisations, blocked the entire EU rather than seek MiCA licensing, and faces UK FCA High Court proceedings.
- Proof of reserves β Monthly Merkle-tree proof of reserves, a run of 36 consecutive months as of October 2025 and most recently published July 2026; corporate holdings are excluded from the proof. (meets this factor)
- Custody β Cold storage is described by third-party reviewers as air-gapped with hardware security modules and multi-signature controls, but no cold/hot split is disclosed and we could not confirm one from a primary source. (partial or unverified)
- Regulation β Only a Pakistan PVARA no-objection certificate was confirmed among its listed authorisations; it holds no MiCA or UK authorisation and blocked the entire European Union from 1 July 2026 rather than seek one. The UK FCA began High Court proceedings against Huobi Global S.A. on 21 October 2025 over illegal financial promotions. (partial or unverified)
- Insurance β No insurance or safety-fund figure is publicly confirmed. That is a disclosure gap rather than confirmation that none exists. (partial or unverified)
- Incident history β About $7.9β8m (5,000 ETH) stolen in September 2023; roughly 95% was recovered by negotiation with the attacker, with a 5% white-hat bounty paid and no user losses reported. (partial or unverified)
08B-MEXC
MEXC publishes a proof-of-reserves page stating a reserve-rate methodology and cites a $100m Guardian Fund through a single source; Estonia's financial intelligence unit revoked its VASP licence in November 2023.
- Proof of reserves β The proof-of-reserves page states a reserve-rate methodology but publishes no figures we could extract; a June 2026 Hacken-audited snapshot at 114β269% coverage is reported by third parties and could not be confirmed against the primary page. (partial or unverified)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β Holds FinCEN MSB, AUSTRAC, Canadian MSB and Swiss VQF registrations β AML monitoring obligations rather than exchange licences. Estonia's Financial Intelligence Unit revoked MEXC Estonia OΓ's licence in November 2023, and a June 2024 blacklist entry surfaced in our research without a clear issuing body or stated consequence. (partial or unverified)
- Insurance β A $100m 'Guardian Fund' is cited by a single third-party source and is not confirmed by any primary MEXC disclosure. (partial or unverified)
- Incident history β No confirmed major security incident found in our research. (meets this factor)
09BOKX
OKX publishes monthly zk-STARK proof of reserves with an open-source verification tool and holds Dubai VARA and Malta MiCA authorisations, but its Seychelles operating entity pleaded guilty in the U.S. in February 2025 and paid over $504m.
- Proof of reserves β Monthly zk-STARK v2 proof of reserves β the 44th report covered $22.65bn in primary reserve assets β with an open-source verification tool on GitHub so users can check their own balances against the published Merkle root. (meets this factor)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β Dubai VARA VASP licence VL/23/12/003 and an EU MiCA CASP authorisation via OKX Europe Limited (Malta MFSA, 27 January 2025); operating entity Aux Cayes FinTech Co. Ltd. pleaded guilty in U.S. federal court on 24 February 2025 to running an unlicensed money-transmitting business and paid over $504m. (partial or unverified)
- Insurance β No insurance or safety fund is publicly disclosed beyond the proof-of-reserves programme. That is a statement about what OKX discloses, not a finding that it is uninsured β but an undisclosed fund is one a user cannot rely on. (does not meet this factor)
- Incident history β No confirmed major security incident found in our research. (meets this factor)
10C-Bitstamp
Bitstamp was the first crypto-asset service provider licensed under MiCA in Luxembourg and has been owned by Robinhood since June 2025; it custodies with BitGo but publishes neither proof of reserves nor an insurance figure, and lost about 19,000 BTC in a 2015 hot-wallet hack.
- Proof of reserves β No proof-of-reserves programme was found. Bitstamp reports SOC 2 compliance and annual Big Four accounting audits, but those are not published reserve attestations a user can check. (does not meet this factor)
- Custody β Custodies with BitGo since 10 October 2019 and roughly 95% cold storage is reported by third-party reviewers, but Bitstamp publishes no cold/hot split we could confirm from a primary source. (partial or unverified)
- Regulation β Bitstamp Europe S.A. was the first crypto-asset service provider granted a full MiCA licence in Luxembourg, by the CSSF on 16 May 2025 and passported across the EU/EEA, alongside a reported New York BitLicense; since 2 June 2025 it has been owned by Robinhood, an SEC-reporting public company. (meets this factor)
- Insurance β No insurance or safety fund is publicly disclosed. Custody sits with BitGo, whose own policy was not shown to extend to Bitstamp balances. That is a statement about what Bitstamp discloses, not a finding that it is uninsured β but an undisclosed fund is one a user cannot rely on. (does not meet this factor)
- Incident history β About 19,000 BTC stolen from hot wallets in January 2015; Bitstamp recovered and kept operating, and its current BitGo custody architecture postdates the hack by several years. One of our two sources could not re-verify the incident against a primary record. (partial or unverified)
11CdYdX
dYdX is a non-custodial perpetuals protocol where balances stay in user-controlled wallets and an on-chain insurance fund is financed by a 1% liquidation fee; it holds no exchange licence in any jurisdiction, and a March 2024 attack cost roughly $9m, about 40% of the v3 insurance fund at the time.
- Proof of reserves β Non-custodial: balances stay in user-controlled wallets and are verifiable directly on-chain, so no reserve attestation is needed. (meets this factor)
- Custody β Non-custodial protocol β it never takes custody of user funds, so there is no hot/cold split to disclose. (meets this factor)
- Regulation β Holds no exchange licence in any jurisdiction; the v4 protocol runs on its own Cosmos SDK chain under community governance, supported by dYdX Trading Inc. in San Francisco and the dYdX Foundation in Zug. U.S. and Canadian users are blocked at the interface layer rather than by any licensed entity. (does not meet this factor)
- Insurance β An on-chain insurance fund financed by a 1% fee on liquidations, verifiable on-chain but with no disclosed balance; a March 2024 attack consumed roughly 40% of the v3 fund, and a March 2025 DAO vote moved $10m USDC out of it to cover operating expenses. (partial or unverified)
- Incident history β Roughly $9m lost in a targeted attack on 5 March 2024, about 40% of the v3 insurance fund at the time; separately, a deposit-proxy vulnerability was exploited by a white hat to rescue about $2m before attackers reached it. One of our two sources recorded no confirmed incident. (partial or unverified)
12CGate.io
Gate.io holds a Malta MiCA authorisation and an EU payment-services licence, and has published Merkle-tree plus zk-SNARK proof of reserves with Armanino LLP involved since October 2022, though only its U.S. entity's figures come from a primary source.
- Proof of reserves β Has published proof of reserves since around May 2020 using a combined Merkle-tree and zk-SNARK method, with third-party involvement from Armanino LLP since 19 October 2022; only the U.S. entity's 100% ratio is primary-sourced, and the global platform's reported 124% ratio comes from third parties. (partial or unverified)
- Custody β Roughly 95% of assets in cold storage is reported by third parties, but Gate publishes no cold/hot split we could confirm from a primary source. (partial or unverified)
- Regulation β Malta MFSA MiCA CASP authorisation granted 29 September 2025 covering 6 of the 10 service categories, and a PSD2 payment-services licence from 26 February 2026, alongside a Gibraltar GFSC DLT licence and a TCSP registration listed on its own licences page without registration numbers we could check; access is restricted from roughly 30β34 countries including the U.S., UK, Canada and most of Western Europe. (partial or unverified)
- Insurance β No insurance or safety fund is publicly disclosed. That is a statement about what Gate discloses, not a finding that it is uninsured β but an undisclosed fund is one a user cannot rely on. (does not meet this factor)
- Incident history β No confirmed major security incident found in our research; Gate claims a 13-year record with no platform-level breach, and holds ISO 27001 certification alongside a CER.live AA rating of 88/100. (meets this factor)
13CGemini
Gemini is a New York-chartered trust company available in all 50 states with $100m of disclosed custody insurance, but publishes no exchange-wide proof of reserves and paid a $37m NYDFS penalty in 2024 over its collapsed Earn programme.
- Proof of reserves β No exchange-wide proof-of-reserves programme was found. Gemini holds SOC 1 Type 2 and SOC 2 Type 2 reports, with Deloitte & Touche involved, but those are controls audits rather than reserve attestations. (does not meet this factor)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β New York limited-purpose trust company charter granted in September 2015, operating in all 50 states; the February 2024 NYDFS consent order over the Gemini Earn programme carried a $37m penalty and more than $1.1bn committed back to users, alongside a $50m New York Attorney General recovery. (meets this factor)
- Insurance β Gemini Custody discloses $100m of insurance cover and Gemini operates an in-house Bermuda captive insurer; the cover is scoped to the custody product and we could not confirm it extends to retail exchange balances. (partial or unverified)
- Incident history β No confirmed breach of Gemini's own systems found in our research; the Earn programme's collapse was a lending-counterparty failure at Genesis, not an attack on the exchange. (meets this factor)
14C+KuCoin
KuCoin holds an Austrian FMA MiCAR licence passportable across 29 EEA countries but pleaded guilty in the U.S. in March 2024, paying $297m and accepting a ban since made permanent; its proof-of-reserves position is contested between our sources, and it lost roughly $280m in its September 2020 hack, with users made whole.
- Proof of reserves β Our two sources conflict: one records Hacken-audited proof of reserves running 32 consecutive months to October 2025 with coverage above 100%, the other found no proof-of-reserves programme at all. Neither could be confirmed against a primary KuCoin disclosure. (partial or unverified)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β Austrian FMA MiCAR CASP licence passportable across 29 EEA countries; operating entity Peken Global Ltd. pleaded guilty in March 2024 to unlicensed money transmission, paying $297m and accepting a two-year U.S. ban since made permanent by a March 2026 CFTC consent order. Related entities settled with the New York Attorney General for $22m in December 2023 and were permanently banned by the Ontario Securities Commission in June 2022. (partial or unverified)
- Insurance β An insurance fund covered the 16% of 2020 hack losses that was not recovered, but its standing balance is not disclosed. (partial or unverified)
- Incident history β About $280β281m stolen in September 2020; 84% was recovered through on-chain tracing, token reissuance and exchange cooperation, and the remainder covered by the insurance fund, leaving users whole. (partial or unverified)
15DBitfinex
Bitfinex is BVI-registered with no public licence register found and publishes no proof of reserves; it lost about 119,756 BTC in the August 2016 hack, and roughly $850m in commingled customer and corporate funds was seized or lost at its payment processor in 2018β19.
- Proof of reserves β No proof-of-reserves programme was found; both of our sources record none, and neither identified an independent reserve attestation of any kind. (does not meet this factor)
- Custody β Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (partial or unverified)
- Regulation β No public licence register was found beyond its British Virgin Islands incorporation, and it blocks U.S. and California residents outright. Settled with the CFTC for $75,000 in 2016 and $1.5m in October 2021, and with the New York Attorney General for $18.5m in February 2021 alongside affiliate Tether. (does not meet this factor)
- Insurance β No named insurance fund was identified in our research. That is a disclosure gap rather than confirmation the cover is zero. (partial or unverified)
- Incident history β About 119,756 BTC (roughly $72m at the time) stolen in August 2016, with U.S. authorities recovering $3.6bn from the perpetrators in 2022; separately, roughly $850m in commingled customer and corporate funds was seized or lost at payment processor Crypto Capital in 2018β19 and made good from affiliate Tether's balance sheet. (does not meet this factor)
How to read these grades: each is derived from published, checkable disclosures β proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record β using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.
Head to head
The written matchups
Two venues, five checks, and the rows where they actually differ. Each comparison is written by hand, never generated β only the matchups worth a page exist.
No pay-to-play
How we grade
The rubric behind every Safety Grade on this site, and why a paid partnership can't buy a better one.
Every exchange we ever cover β sponsor or not β is scored against the same five factors, weighted the same way. A paid partnership can get an exchange listed faster. It cannot buy a better grade.
- Proof of reserves
- 30%
- Custody
- 25%
- Regulation
- 20%
- Insurance
- 15%
- Incident history
- 10%
This Safety Grade is a narrower, faster read than our full exchange review, which also covers fees, coins and support. Read our full editorial policy β
The AβF scale
- A
Meets every factor at a high bar: independently verified reserves, disclosed cold-storage custody, real licensing, insurance, and a clean record.
- B
Strong on most factors, with at least one gap β usually self-attested reserves or registration instead of full licensing.
- C
Average. Some disclosure, but several factors are thin, self-reported, or unverifiable.
- D
Multiple real gaps β undisclosed custody, no regulation, no insurance β even without a known incident.
- F
Either a confirmed history of major incidents, or enough structural red flags that we can't responsibly recommend it.
No pay-to-play
Questions this table does not answer on its face
Five things readers ask about the ledger, including the two we cannot answer.
Which is the safest crypto exchange?
There is no risk-free venue, and the top of this table is not one. The grade measures what a venue can show β reserve attestations, custody disclosure, licences on a public register, loss cover, incident record β so the highest grade belongs to whoever discloses the most, which is a narrower claim than βsafestβ. Read the five checks for the two or three you would actually use, then decide how much you keep there at all.
Is proof of reserves enough on its own?
No. It is the heaviest of our five checks at 30% and the one most venues publish, which is exactly why it needs reading closely. A snapshot shows assets at a moment; it does not show liabilities, and a self-published report with no accountant behind it is a claim you can inspect rather than one somebody else has checked. Most reserve disclosures in this table are graded warn for that reason, not fail.
Which exchange has the lowest fees?
We do not know, and we do not hold a fee figure for any venue in this table, so we will not rank on one. Published fees change by market, tier, promotion and interface, and a rate we copied down once would be wrong within weeks while the page kept looking current. Use the fee calculator with your own trade size and volume tier instead.
Why does a large, well-known exchange grade below a smaller one?
Because the grade measures disclosure, not size, brand or volume. A venue that publishes an independently attested reserve report, its cold-storage split and a licence number you can check against a register outscores a larger one that publishes none of those β regardless of how long it has been trading or how much passes through it.
Can I use these exchanges where I live?
Each venue decides that in its own terms, and it changes. Our regulation notes carry the licences and enforcement history we could verify against public registers, which is a different thing from a statement that a venue will accept you: a licence in one jurisdiction is not access in yours. Check the venue's own terms, and do not try to work around a restriction you find there.
Next
Where to go from here
How the grades are built, and the failures that made these checks necessary.