How to read these grades: each is derived from published, checkable disclosures — proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record — using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.
Bitstamp
Bitstamp was the first crypto-asset service provider licensed under MiCA in Luxembourg and has been owned by Robinhood since June 2025; it custodies with BitGo but publishes neither proof of reserves nor an insurance figure, and lost about 19,000 BTC in a 2015 hot-wallet hack.
BySafety DeskSenior Exchange Safety Editor
Our Bitstamp review
Bitstamp was the first crypto-asset service provider in Europe to be granted a full MiCA licence, and it publishes less about its own reserves than almost any venue in this corpus. The C- is the arithmetic of one very strong factor against three weak ones.
What checks out
Bitstamp Europe S.A. received a full MiCA licence from Luxembourg's CSSF on 16 May 2025 — the first such grant anywhere — and passported it across the EU and EEA. A New York BitLicense is also reported. Since 2 June 2025 Bitstamp has been owned by Robinhood, an SEC-reporting public company, which adds a layer of external financial reporting that did not previously exist above it. Custody has sat with BitGo since 10 October 2019.
Where the evidence stops
There is no proof-of-reserves programme. Bitstamp reports SOC 2 compliance and annual Big Four accounting audits, but neither is a published reserve attestation you can check your own balance against. Third-party reviewers put roughly 95% of assets in cold storage; Bitstamp itself publishes no split we could confirm. No insurance or safety fund is disclosed, and while custody sits with BitGo, BitGo's own policy was not shown to extend to Bitstamp balances. About 19,000 BTC was stolen from hot wallets in January 2015 — one of our two sources could not re-verify that against a primary record, and the BitGo custody architecture postdates the hack by several years.
How to read the grade
A first-in-Europe licence is a real, dated, checkable thing, and it tells you who supervises Bitstamp rather than what Bitstamp holds. On the second question this venue is close to silent, and the grade says so.
Grade breakdown
Every KripZen grade comes from the same five weighted checks. Here is how Bitstamp scores on each.
- Proof of reservesWeight 30%
No proof-of-reserves programme was found. Bitstamp reports SOC 2 compliance and annual Big Four accounting audits, but those are not published reserve attestations a user can check.
What this means → does not meet this factor - CustodyWeight 25%
Custodies with BitGo since 10 October 2019 and roughly 95% cold storage is reported by third-party reviewers, but Bitstamp publishes no cold/hot split we could confirm from a primary source.
What this means → partial or unverified - RegulationWeight 20%
Bitstamp Europe S.A. was the first crypto-asset service provider granted a full MiCA licence in Luxembourg, by the CSSF on 16 May 2025 and passported across the EU/EEA, alongside a reported New York BitLicense; since 2 June 2025 it has been owned by Robinhood, an SEC-reporting public company.
What this means → meets this factor - InsuranceWeight 15%
No insurance or safety fund is publicly disclosed. Custody sits with BitGo, whose own policy was not shown to extend to Bitstamp balances. That is a statement about what Bitstamp discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on.
does not meet this factor - Incident historyWeight 10%
About 19,000 BTC stolen from hot wallets in January 2015; Bitstamp recovered and kept operating, and its current BitGo custody architecture postdates the hack by several years. One of our two sources could not re-verify the incident against a primary record.
partial or unverified