How to read these grades: each is derived from published, checkable disclosures — proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record — using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.
dYdX
dYdX is a non-custodial perpetuals protocol where balances stay in user-controlled wallets and an on-chain insurance fund is financed by a 1% liquidation fee; it holds no exchange licence in any jurisdiction, and a March 2024 attack cost roughly $9m, about 40% of the v3 insurance fund at the time.
BySafety DeskSenior Exchange Safety Editor
Our dYdX review
dYdX is the only venue here that never holds your money, and the only one with no exchange licence anywhere. Those are the same fact seen from two sides, and the C is what our rubric returns for it.
What checks out
dYdX is a non-custodial perpetuals protocol: balances stay in wallets you control and are verifiable directly on-chain, so no reserve attestation is needed and there is no hot/cold split to disclose. Those are the two heaviest factors on our rubric, and dYdX passes both by architecture rather than by policy — a design where the failure mode of a custodian simply does not apply.
Where the evidence stops
It holds no exchange licence in any jurisdiction. The v4 protocol runs on its own Cosmos SDK chain under community governance, supported by dYdX Trading Inc. in San Francisco and the dYdX Foundation in Zug. U.S. and Canadian users are blocked at the interface layer rather than by any licensed entity — which is a technical restriction, not a supervised one. Under our methodology a failed regulation factor caps the grade at C however well a venue scores elsewhere, and that cap is exactly what is happening here. The on-chain insurance fund is financed by a 1% fee on liquidations and is verifiable on-chain, but no balance is disclosed; a March 2024 attack consumed roughly 40% of the v3 fund, and a March 2025 DAO vote moved $10m USDC out of it to cover operating expenses. That attack cost around $9m on 5 March 2024. Separately, a deposit-proxy vulnerability was exploited by a white hat to rescue about $2m before attackers reached it. One of our two sources recorded no confirmed incident at all.
How to read the grade
The custody risk you take at every other venue on this site is absent here, and it is replaced by smart-contract and governance risk, with nobody licensed to answer for either. That trade is the decision, not the letter.
Grade breakdown
Every KripZen grade comes from the same five weighted checks. Here is how dYdX scores on each.
- Proof of reservesWeight 30%
Non-custodial: balances stay in user-controlled wallets and are verifiable directly on-chain, so no reserve attestation is needed.
What this means → meets this factor - CustodyWeight 25%
Non-custodial protocol — it never takes custody of user funds, so there is no hot/cold split to disclose.
What this means → meets this factor - RegulationWeight 20%
Holds no exchange licence in any jurisdiction; the v4 protocol runs on its own Cosmos SDK chain under community governance, supported by dYdX Trading Inc. in San Francisco and the dYdX Foundation in Zug. U.S. and Canadian users are blocked at the interface layer rather than by any licensed entity.
What this means → does not meet this factor - InsuranceWeight 15%
An on-chain insurance fund financed by a 1% fee on liquidations, verifiable on-chain but with no disclosed balance; a March 2024 attack consumed roughly 40% of the v3 fund, and a March 2025 DAO vote moved $10m USDC out of it to cover operating expenses.
partial or unverified - Incident historyWeight 10%
Roughly $9m lost in a targeted attack on 5 March 2024, about 40% of the v3 insurance fund at the time; separately, a deposit-proxy vulnerability was exploited by a white hat to rescue about $2m before attackers reached it. One of our two sources recorded no confirmed incident.
partial or unverified