How to read these grades: each is derived from published, checkable disclosures — proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record — using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.
Binance
Binance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.
BySafety DeskSenior Exchange Safety Editor
Our Binance review
Binance earns a B- on our five-factor rubric. It discloses more than most venues of its size, and the two things it does not disclose are the two that matter most on the day an exchange gets into trouble.
What checks out
The SAFU user-protection fund is the strongest single item on the record. Set up in 2018 and topped up to $1bn in November 2022, it covered the May 2019 hot-wallet theft in full — a fund tested in public, rather than one described in a policy document. Binance also publishes Merkle-tree proof of reserves across more than 30 assets; the most recent snapshot we recorded, dated 1 January 2026, covers 636,535 BTC.
Where the evidence stops
Those reserve reports are self-published. No independent accountant signs them, which makes them a claim you can inspect rather than one somebody else has checked — proof of reserves is not an audit, and here it is not even attested. The cold/hot storage split is not disclosed at all, and we could not confirm it from a primary source. On licensing, Binance holds an ADGM authorisation in the UAE and, through Binance.US, money-transmitter licences in 30 states under NMLS ID 1906829. It also pleaded guilty in November 2023 to U.S. Bank Secrecy Act and sanctions violations, paid $4.3bn, and accepted a five-year DOJ compliance monitorship that runs to 2028.
How to read the grade
A monitored exchange is not the same as an unwatched one: the monitorship exists because the failures were established, and it also means somebody is now checking. The B- describes a venue with real, tested loss cover and a real enforcement history, whose reserve and custody disclosures still rest on its own word. About 7,000 BTC left its hot wallets in May 2019 and no user lost money, because the fund paid. That is the shape of the risk here.
Grade breakdown
Every KripZen grade comes from the same five weighted checks. Here is how Binance scores on each.
- Proof of reservesWeight 30%
Publishes Merkle-tree proof of reserves covering 30-plus assets, most recently a 1 January 2026 snapshot of 636,535 BTC, but the reports are self-published rather than independently audited.
What this means → partial or unverified - CustodyWeight 25%
Cold/hot storage split is not disclosed; we could not confirm it from a primary source.
What this means → partial or unverified - RegulationWeight 20%
Holds an ADGM (UAE) authorisation and, via Binance.US, money-transmitter licences in 30 states (NMLS ID 1906829); pleaded guilty to U.S. Bank Secrecy Act and sanctions violations in November 2023, paying $4.3bn and accepting a five-year DOJ compliance monitorship running to 2028.
What this means → partial or unverified - InsuranceWeight 15%
SAFU user-protection fund, established in 2018 and topped up to $1bn in November 2022; it covered the May 2019 hack in full.
meets this factor - Incident historyWeight 10%
About 7,000 BTC (roughly $40m at the time) drained from hot wallets on 7 May 2019; the SAFU fund covered the loss in full and no user lost funds. No platform breach of comparable scale has been reported since.
partial or unverified