Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

← Back to Safety Scores

How to read these grades: each is derived from published, checkable disclosures — proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record — using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.

B-

Bybit

Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46–1.5bn — the largest exchange hack on record — replenishing reserves in full within 72 hours.

3.3/5
Safety grade

BySafety DeskSenior Exchange Safety Editor

Our Bybit review

Bybit is the venue that lost more money to a single attack than any exchange in history and still paid everybody back. Both halves of that sentence are in the B-.

What checks out

Merkle-tree and proof-of-liabilities audits have run monthly since June 2024 and are published as signed reports by Hacken OU. Hacken is a crypto-security specialist rather than a Big Four financial auditor, which is worth knowing when you read the signature — but a signature from outside the company is still more than most of this corpus offers. On the regulatory side, Bybit EU GmbH holds an EU MiCA licence from the Austrian FMA, granted in May 2025 and covering 5 of the 10 MiCA service categories.

Where the evidence stops

In February 2025 roughly $1.46–1.5bn was taken through a phishing attack on a Safe multisig interface, attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, and only 3.54% of the stolen funds were ever frozen. The insurance fund that backstops derivatives liquidations was drawn on in that response, but its standing balance is not disclosed, so its capacity to absorb a second event is unknown. The cold/hot storage split is also undisclosed. The Dubai VARA approval is provisional and non-operational, not a live licence; the UK FCA issued a public warning in February 2025, and Bybit re-entered the UK in December 2025 through FCA-regulated Archax rather than on its own permission.

How to read the grade

Solvency through the worst attack the sector has seen is real evidence about a balance sheet, and it is not evidence that the attack surface has changed. The B- credits the recovery and refuses to treat it as a security record.

Grade breakdown

Every KripZen grade comes from the same five weighted checks. Here is how Bybit scores on each.

  • Proof of reservesWeight 30%

    Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor.

    What this means → meets this factor
  • CustodyWeight 25%

    Cold/hot storage split is not disclosed; we could not confirm it from a primary source.

    What this means → partial or unverified
  • RegulationWeight 20%

    EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax.

    What this means → partial or unverified
  • InsuranceWeight 15%

    Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed.

    partial or unverified
  • Incident historyWeight 10%

    About $1.46–1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen.

    does not meet this factor

Other exchanges we've graded

A-KrakenKraken holds a Wyoming SPDI charter, CFTC and SEC registrations and two EU MiCA authorisations, and has published Merkle-tree proof of reserves verified by Armanino LLP since February 2022; it discloses no insurance-fund figure.B-BinanceBinance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.B+BitgetBitget publishes a monthly open-source Merkle-tree proof of reserves showing BTC at 138% and ETH at 181%, and cites a protection fund its own sources size differently; ASIC issued an investor alert in July 2025 over unlicensed high-leverage derivatives.BCoinbaseCoinbase is a publicly traded, SEC-reporting U.S. company licensed in 45 states and holding a New York BitLicense, and the SEC's 2023 case against it was dismissed with prejudice in February 2025; it runs no crypto-specific proof-of-reserves programme and its last disclosed crime-insurance figure dates from 2019.B-Crypto.comCrypto.com discloses more than $870m of insurance cover, had its SEC investigation closed with no action in March 2025 and holds a Malta MiCA authorisation; its proof-of-reserves position is contested between our sources, and it reimbursed all users after a January 2022 incident that drained about $34–35m from 483 accounts.BHTXHTX publishes monthly Merkle-tree proof of reserves that excludes corporate holdings, discloses only a Pakistani no-objection certificate among its authorisations, blocked the entire EU rather than seek MiCA licensing, and faces UK FCA High Court proceedings.