[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"incident:bitfinex-2016::en":3,"incidents-all::en":15,"exchanges-all::en":176},{"slug":4,"year":5,"date":6,"name":7,"category":8,"amount_label":9,"summary":10,"lesson":11,"published_at":12,"title":7,"meta_title":13,"meta_description":13,"keywords":14},"bitfinex-2016",2016,"August 2016","Bitfinex","hack","~120,000 BTC stolen (publicly reported estimate)","A security breach in Bitfinex's multi-signature wallet setup let attackers drain a large share of customer bitcoin in a single incident. The exchange spread the loss across all users' balances and later repaid affected customers over several years.","Even a widely used, multi-signature custody setup is only as strong as the systems and partners it depends on — 'multi-sig' alone isn't a safety guarantee.","2026-07-19T01:00:17+00:00",null,[],[16,25,34,42,51,58,66,74,82,89,97,105,113,120,127,136,142,151,152,160,168],{"slug":17,"year":18,"date":19,"name":20,"category":8,"amount_label":21,"summary":22,"lesson":23,"published_at":24},"bybit-2025",2025,"February 2025","Bybit","~$1.46B in ETH and staked ETH (publicly reported estimate)","On 21 February 2025 attackers moved roughly $1.46 billion of ether and staked ether out of a Bybit cold wallet by manipulating what signers saw in a Safe multisig interface, so legitimate keyholders approved a transfer that was not what it appeared to be. The FBI attributed the attack to North Korea's Lazarus Group.","No key was stolen — the approval screen lied. Cold storage and multisig only help when every signer can verify, independently of that screen, what they are actually authorising.","2026-08-05T03:45:01+00:00",{"slug":26,"year":27,"date":28,"name":29,"category":8,"amount_label":30,"summary":31,"lesson":32,"published_at":33},"dmm-bitcoin-2024",2024,"May 2024","DMM Bitcoin","4,502.9 BTC (~$300m at the time, company-reported)","On 31 May 2024 DMM Bitcoin, a Japanese exchange registered with the Financial Services Agency, reported an unauthorised outflow of 4,502.9 BTC — worth roughly $300m at the time and one of the largest thefts in the country's history. The company said it would procure the equivalent bitcoin with support from the wider DMM group so that customer holdings were fully covered, and Japan's FSA issued a business improvement order. In December 2024 US and Japanese agencies publicly attributed the theft to North Korea-linked actors, and DMM announced it would cease its crypto business and transfer customer accounts to SBI VC Trade.","Registration and a solvent parent decided how this ended, not whether it happened. Japan's regime is among the strictest anywhere and the coins still left; what the rules and the group balance sheet bought was that customers were repaid rather than queued as creditors. Read a licence as a statement about who absorbs the loss, never as a claim that the loss is prevented — and note that the exchange itself did not survive being made whole.","2026-08-18T03:30:02+00:00",{"slug":35,"year":36,"date":37,"name":38,"category":8,"amount_label":39,"summary":40,"lesson":41,"published_at":24},"htx-2023",2023,"September 2023","HTX (formerly Huobi)","~5,000 ETH (~$8M) taken from a hot wallet (publicly reported estimate)","On 24 September 2023 roughly 5,000 ETH — about $8 million — was taken from a single HTX hot wallet. The exchange identified the attacker, negotiated the return of 95% of the funds and paid the remaining 5% as a white-hat bounty. Customer balances were covered in full.","Negotiating money back worked because the amount was small and the trail was public. That is an outcome, not a security control — no exchange can promise you the next attacker will take the deal.",{"slug":43,"year":44,"date":45,"name":46,"category":47,"amount_label":48,"summary":49,"lesson":50,"published_at":12},"celsius-2022",2022,"June 2022","Celsius Network","insolvency","Withdrawals frozen for roughly $4.7B in customer assets (publicly reported estimate)","The crypto lending platform froze all customer withdrawals during a market downturn and filed for bankruptcy weeks later. Its founder was subsequently charged with, and later pleaded guilty to, fraud for misrepresenting the platform's risk to depositors.","A platform paying yield on deposits is taking risk with your money somewhere. 'Where' and 'how much' are the questions a safety review has to ask before the good times end.",{"slug":52,"year":44,"date":53,"name":54,"category":8,"amount_label":55,"summary":56,"lesson":57,"published_at":24},"crypto-com-2022","January 2022","Crypto.com","~$34M withdrawn from 483 accounts (publicly reported estimate)","On 20 January 2022 roughly $34 million in bitcoin, ether and other assets was withdrawn from 483 Crypto.com customer accounts. The withdrawals were approved without two-factor authentication being properly enforced. The company paused withdrawals, rebuilt the authentication flow, and reimbursed every affected user.","Two-factor authentication only protects you where the platform actually enforces it. The control existed here; the gap in enforcing it on the withdrawal path is what cost money.",{"slug":59,"year":44,"date":60,"name":61,"category":62,"amount_label":63,"summary":64,"lesson":65,"published_at":12},"ftx-2022","November 2022","FTX","fraud","Billions of dollars in customer funds misused (publicly reported estimate)","One of the largest exchanges globally collapsed within days after reporting revealed customer deposits had been comingled with, and lent to, a sister trading firm. Its founder was later convicted on multiple counts of fraud.","Scale, celebrity endorsements and slick branding say nothing about whether customer funds are actually segregated from the company's own trading book.",{"slug":67,"year":44,"date":68,"name":69,"category":8,"amount_label":70,"summary":71,"lesson":72,"published_at":73},"ronin-bridge-2022","March 2022","Ronin Bridge","~$600M in ETH and USDC (publicly reported estimate)","The Ronin bridge, which connected the Axie Infinity game's sidechain to Ethereum, was drained in March 2022 after attackers gained control of a majority of the small validator set whose signatures authorised withdrawals. Nothing was broken in the contract: the withdrawals were validly signed by the keys the system trusted. The loss was only discovered days later, when a user reported being unable to withdraw. US authorities subsequently attributed the theft to the North Korea-linked Lazarus Group.","A bridge is only as decentralised as its signer set. When a handful of keys can authorise every withdrawal, compromising those keys is the whole attack — and if nobody is watching the balance, it can take days for anyone to notice the money has gone.","2026-08-10T03:45:01+00:00",{"slug":75,"year":44,"date":76,"name":77,"category":47,"amount_label":78,"summary":79,"lesson":80,"published_at":81},"terra-luna-2022","May 2022","Terra \u002F LUNA","UST and LUNA lost effectively all of their value","TerraUSD was an algorithmic stablecoin that held its dollar peg not with reserves but with a mint-and-burn link to LUNA, the network's own volatile token: a UST below a dollar could always be exchanged for a dollar of newly created LUNA. In May 2022 the peg slipped and that mechanism worked in reverse — restoring it required minting ever more LUNA, which crushed LUNA's price and destroyed the very value the peg depended on. Both assets collapsed within days, and Terraform Labs and its founder later faced criminal and civil proceedings in the United States and South Korea.","A peg backed by a token the same system issues is circular. It holds while confidence holds and offers nothing to fall back on when confidence goes — which is the moment a stablecoin is supposed to be useful. High advertised yields on a stablecoin are a description of that risk, not a feature.","2026-08-11T03:45:01+00:00",{"slug":83,"year":44,"date":45,"name":84,"category":47,"amount_label":85,"summary":86,"lesson":87,"published_at":88},"three-arrows-capital-2022","Three Arrows Capital","Creditor claims of roughly $3.5B in the liquidation (publicly reported estimate)","Three Arrows Capital was a Singapore-based hedge fund that had become one of the largest borrowers in crypto, funding leveraged positions with loans from centralised lending desks. It held a substantial position in Terra's ecosystem, which lost effectively all of its value in May 2022, and it was exposed to other trades that moved against it as prices fell. When lenders issued margin calls in June 2022 the fund could not meet them. A court in the British Virgin Islands ordered its liquidation at the end of that month, and the liquidators sought recognition in the United States shortly after. The default did not stop at the fund: several of the lending platforms that had extended it credit disclosed losses, and some of them subsequently entered bankruptcy themselves. Singapore's regulator later issued prohibition orders against its founders.","Contagion in crypto is not mystical; it is a lending chain. A platform offering you a yield is lending your deposit to somebody, and the concentration of its loan book is the risk you are actually taking. That book is rarely published, so the question worth asking of any yield product is who the borrower is and what happens to your money if that borrower defaults.","2026-08-13T03:45:01+00:00",{"slug":90,"year":44,"date":91,"name":92,"category":8,"amount_label":93,"summary":94,"lesson":95,"published_at":96},"wormhole-2022","February 2022","Wormhole","~120,000 wrapped ETH (publicly reported estimate)","Wormhole, a bridge issuing wrapped assets across several chains, lost roughly 120,000 wrapped ether in February 2022 when an attacker exploited a flaw in how its Solana-side contract verified the guardian signatures that authorise a mint. The attacker was able to produce a mint that the contract accepted without a matching deposit on Ethereum, leaving the wrapped tokens undercollateralised. Jump Crypto, which backed the project, replaced the missing ether so that holders of the wrapped asset were made whole.","A wrapped token is a claim that something is held elsewhere. When the check that enforces that link is broken, the token keeps circulating and looking normal while the collateral behind it no longer exists — and whether users are made whole comes down to whether somebody with a balance sheet chooses to step in.","2026-08-14T03:45:02+00:00",{"slug":98,"year":99,"date":100,"name":101,"category":8,"amount_label":102,"summary":103,"lesson":104,"published_at":24},"kucoin-2020",2020,"September 2020","KuCoin","~$281M drained from hot wallets (publicly reported estimate)","On 25 September 2020 attackers drained roughly $281 million from KuCoin's hot wallets. About 84% was recovered over the following weeks through on-chain tracing, token issuers freezing and reissuing supply, and blacklisting by other exchanges. KuCoin's insurance fund covered the remainder, and users were made whole.","That recovery depended on other people's goodwill — issuers willing to freeze tokens and venues willing to blacklist addresses. Treat it as a favour the industry granted, not a protection you can count on.",{"slug":106,"year":107,"date":108,"name":109,"category":8,"amount_label":110,"summary":111,"lesson":112,"published_at":24},"binance-2019",2019,"May 2019","Binance","~7,000 BTC (~$40M at the time) taken from a hot wallet (publicly reported estimate)","On 7 May 2019 attackers withdrew roughly 7,000 BTC — about $40 million at the time — from a Binance hot wallet in a single transaction, using stolen API keys and phished credentials. Binance covered the entire loss from its Secure Asset Fund for Users, and customer balances were left untouched.","A reserve funded before a breach turns a hack into an accounting entry rather than a customer loss. Check that the fund exists and is disclosed today, not that one is promised afterwards.",{"slug":114,"year":107,"date":115,"name":116,"category":62,"amount_label":117,"summary":118,"lesson":119,"published_at":24},"bitfinex-crypto-capital-2019","2018–2019","Bitfinex \u002F Crypto Capital","~$850M in commingled customer and corporate funds (publicly reported estimate)","Across 2018 and 2019 Bitfinex had roughly $850 million of commingled customer and corporate money sitting with its payment processor, Crypto Capital Corp, whose accounts were seized by authorities in several countries. Affiliated stablecoin issuer Tether's reserves covered the gap; both firms settled with the New York Attorney General for $18.5 million in February 2021 without admitting wrongdoing.","The crypto never moved — the fiat leg did. Ask which outside company actually holds the cash side of an exchange's balance sheet, because that firm's legal problems become yours.",{"slug":121,"year":107,"date":122,"name":123,"category":62,"amount_label":124,"summary":125,"lesson":126,"published_at":12},"quadrigacx-2019","Early 2019","QuadrigaCX","~CA$190M in customer funds inaccessible (publicly reported estimate)","Canada's largest exchange at the time told customers it could no longer access roughly CA$190M in funds after its founder died while allegedly holding sole control of the cold-wallet keys. A later court-appointed investigation found many of the wallets had been empty long before his death, pointing to mismanagement and likely fraud rather than a pure accident.","Single-person key control is a structural failure waiting to happen — deliberate or not. A credible custodian never lets access depend on one individual.",{"slug":128,"year":129,"date":130,"name":131,"category":62,"amount_label":132,"summary":133,"lesson":134,"published_at":135},"bitconnect-2018",2018,"January 2018","BitConnect","~$2.4B taken from investors (figure cited by the US Department of Justice)","BitConnect invited users to exchange bitcoin for its own token and lock it in a lending programme that promised steady returns, said to be generated by a proprietary trading bot nobody outside the company could inspect. A multi-level referral structure paid existing participants to recruit new ones. After state securities regulators in the United States issued cease-and-desist orders, the lending platform was shut down in January 2018 and the token's value collapsed. US authorities later charged the operation as a fraud: a promoter pleaded guilty, and the founder was indicted and reported as a fugitive.","A fixed or guaranteed return in crypto is a claim about the future that nobody can make honestly. When the strategy behind it cannot be inspected and recruitment is rewarded, the returns are being paid by later deposits — which is a structure, not a market view, and it ends when deposits slow.","2026-08-08T03:45:01+00:00",{"slug":137,"year":129,"date":130,"name":138,"category":8,"amount_label":139,"summary":140,"lesson":141,"published_at":12},"coincheck-2018","Coincheck","~$530M in NEM (XEM) stolen (publicly reported estimate)","The Japanese exchange kept a large pool of a single token in an internet-connected hot wallet without a multi-signature setup. Attackers stole hundreds of millions of dollars' worth in one of the largest exchange hacks by value at the time.","Hot-wallet convenience has a price. The safest exchanges keep the large majority of customer funds offline, precisely so one breach can't drain everything.",{"slug":143,"year":144,"date":145,"name":146,"category":8,"amount_label":147,"summary":148,"lesson":149,"published_at":150},"parity-multisig-freeze-2017",2017,"November 2017","Parity Multisig Wallet Freeze","~513,000 ETH rendered permanently inaccessible (publicly reported estimate)","Parity's multi-signature wallets did not each carry their own logic. To save deployment cost, every wallet was a thin contract that delegated its behaviour to one shared library contract on the network. That library had been deployed without being initialised, so its ownership was still unclaimed. In November 2017 a user claimed it and then invoked its self-destruct function, which removed the library's code from the chain. Every wallet that depended on it was left pointing at nothing: the balances still exist in the ledger, but the code that could authorise a transfer no longer does. Public estimates put the amount stranded at roughly 513,000 ETH. Nobody took the funds, and no exploit moved them; they simply stopped being reachable. Proposals to recover them by protocol change were debated and not adopted. Months earlier, a separate flaw in the same wallet software had allowed an actual theft of around 150,000 ETH by public estimates.","Not every loss involves a thief. Shared code is a shared dependency, and a contract that delegates to a library inherits that library's failure modes without saying so on the tin. It also shows the limit of immutability from the user's side: the same property that stops anyone rewriting your balance stops anyone repairing it, and an unrecoverable mistake can be as expensive as an attack.","2026-08-09T03:45:01+00:00",{"slug":4,"year":5,"date":6,"name":7,"category":8,"amount_label":9,"summary":10,"lesson":11,"published_at":12},{"slug":153,"year":5,"date":154,"name":155,"category":8,"amount_label":156,"summary":157,"lesson":158,"published_at":159},"the-dao-2016","June 2016","The DAO","~3.6M ETH moved out of the contract (publicly reported estimate)","The DAO was an investor-directed fund written entirely as Ethereum smart contracts: token holders would vote on which proposals received funding, with no manager in between. Its 2016 token sale gathered a large fraction of all circulating ether. In June 2016 an attacker exploited a reentrancy flaw in the code that let a participant withdraw their share: the contract sent ether out before it updated the sender's balance, so a malicious contract could call back into the withdrawal repeatedly and be paid again each time on a balance that had not yet been reduced. Roughly 3.6 million ETH was moved into a child contract subject to a holding period written into The DAO's own rules, which is what gave the community weeks to argue about a response. Ethereum's participants ultimately adopted a hard fork that moved the funds to a recovery contract. A minority rejected the fork on the grounds that the ledger should not be rewritten, and continued the original chain as Ethereum Classic.","Code that holds funds is only as good as its ordering. The flaw was not exotic cryptography but a sequence — pay first, update the record after — and that pattern is still what auditors look for first. The aftermath matters as much as the bug: a chain can only reverse a theft if enough of its participants agree to, and that agreement is a political fact about a community, not a technical guarantee you can rely on in advance.","2026-08-12T03:45:01+00:00",{"slug":161,"year":162,"date":163,"name":164,"category":8,"amount_label":165,"summary":166,"lesson":167,"published_at":24},"bitstamp-2015",2015,"January 2015","Bitstamp","~19,000 BTC taken from hot wallets (publicly reported estimate)","In January 2015 roughly 19,000 BTC was taken from Bitstamp's hot wallets following a targeted attack on exchange staff. Bitstamp suspended trading, rebuilt its infrastructure, and afterwards moved to third-party institutional custody with the large majority of customer assets held offline.","What changed Bitstamp's risk profile was the rebuilt custody model, not the apology. Judge an exchange by what it did after an incident, not by how quickly it published a statement.",{"slug":169,"year":170,"date":171,"name":172,"category":8,"amount_label":173,"summary":174,"lesson":175,"published_at":12},"mtgox-2014",2014,"February 2014","Mt. Gox","~850,000 BTC reported missing (publicly reported estimate)","Once the exchange handling the large majority of the world's Bitcoin trades, Mt. Gox abruptly halted withdrawals and filed for bankruptcy in Japan after disclosing that hundreds of thousands of customer and company bitcoins were gone — later attributed to theft that went undetected for years.","Trading volume and market dominance are not safety signals. An exchange can look like the industry's center of gravity and still be hollowed out inside.",[177,201,216,232,247,260,276,290,306,321,335,350,365,379,392],{"slug":178,"name":109,"grade":179,"summary":180,"factors":181,"logo_url":13,"updated_at":199,"has_affiliate":200},"binance","B-","Binance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.",[182,186,189,192,196],{"key":183,"status":184,"note":185},"por","warn","Publishes Merkle-tree proof of reserves covering 30-plus assets, most recently a 1 January 2026 snapshot of 636,535 BTC, but the reports are self-published rather than independently audited.",{"key":187,"status":184,"note":188},"custody","Cold\u002Fhot storage split is not disclosed; we could not confirm it from a primary source.",{"key":190,"status":184,"note":191},"regulation","Holds an ADGM (UAE) authorisation and, via Binance.US, money-transmitter licences in 30 states (NMLS ID 1906829); pleaded guilty to U.S. Bank Secrecy Act and sanctions violations in November 2023, paying $4.3bn and accepting a five-year DOJ compliance monitorship running to 2028.",{"key":193,"status":194,"note":195},"insurance","pass","SAFU user-protection fund, established in 2018 and topped up to $1bn in November 2022; it covered the May 2019 hack in full.",{"key":197,"status":184,"note":198},"incidents","About 7,000 BTC (roughly $40m at the time) drained from hot wallets on 7 May 2019; the SAFU fund covered the loss in full and no user lost funds. No platform breach of comparable scale has been reported since.","2026-08-11T12:26:59+00:00",false,{"slug":202,"name":7,"grade":203,"summary":204,"factors":205,"logo_url":13,"updated_at":199,"has_affiliate":200},"bitfinex","D","Bitfinex is BVI-registered with no public licence register found and publishes no proof of reserves; it lost about 119,756 BTC in the August 2016 hack, and roughly $850m in commingled customer and corporate funds was seized or lost at its payment processor in 2018–19.",[206,209,210,212,214],{"key":183,"status":207,"note":208},"fail","No proof-of-reserves programme was found; both of our sources record none, and neither identified an independent reserve attestation of any kind.",{"key":187,"status":184,"note":188},{"key":190,"status":207,"note":211},"No public licence register was found beyond its British Virgin Islands incorporation, and it blocks U.S. and California residents outright. Settled with the CFTC for $75,000 in 2016 and $1.5m in October 2021, and with the New York Attorney General for $18.5m in February 2021 alongside affiliate Tether.",{"key":193,"status":184,"note":213},"No named insurance fund was identified in our research. That is a disclosure gap rather than confirmation the cover is zero.",{"key":197,"status":207,"note":215},"About 119,756 BTC (roughly $72m at the time) stolen in August 2016, with U.S. authorities recovering $3.6bn from the perpetrators in 2022; separately, roughly $850m in commingled customer and corporate funds was seized or lost at payment processor Crypto Capital in 2018–19 and made good from affiliate Tether's balance sheet.",{"slug":217,"name":218,"grade":219,"summary":220,"factors":221,"logo_url":13,"updated_at":199,"has_affiliate":200},"bitget","Bitget","B+","Bitget publishes a monthly open-source Merkle-tree proof of reserves showing BTC at 138% and ETH at 181%, and cites a protection fund its own sources size differently; ASIC issued an investor alert in July 2025 over unlicensed high-leverage derivatives.",[222,224,226,228,230],{"key":183,"status":194,"note":223},"Monthly open-source Merkle-tree proof of reserves published on GitHub, showing BTC reserves at 138%, ETH at 181%, USDC at 107% and USDT at 101%.",{"key":187,"status":184,"note":225},"Uses multi-signature cold storage, but the cold\u002Fhot storage split is not disclosed and we could not confirm it from a primary source.",{"key":190,"status":184,"note":227},"Lists an AUSTRAC registration, El Salvador CNAD\u002FBSP licences, Argentine CNV and Mexican SAT registrations, a UK FCA Section 21 approver partnership and a Swiss FINMA SRO membership, without registration numbers we could check against public registers. ASIC issued a public investor alert on 28 July 2025 over unlicensed crypto derivatives sold to Australian retail clients at up to 125x leverage, noting Bitget holds no Australian Financial Services licence; its own corporate registration is cited variously as Seychelles, Lithuania or New Zealand.",{"key":193,"status":184,"note":229},"A protection fund is disclosed but sized inconsistently across sources — $630m in one, 6,500 BTC (implemented December 2022) in another — so no single figure is confirmed.",{"key":197,"status":194,"note":231},"No confirmed major security incident found in our research.",{"slug":233,"name":164,"grade":234,"summary":235,"factors":236,"logo_url":13,"updated_at":199,"has_affiliate":200},"bitstamp","C-","Bitstamp was the first crypto-asset service provider licensed under MiCA in Luxembourg and has been owned by Robinhood since June 2025; it custodies with BitGo but publishes neither proof of reserves nor an insurance figure, and lost about 19,000 BTC in a 2015 hot-wallet hack.",[237,239,241,243,245],{"key":183,"status":207,"note":238},"No proof-of-reserves programme was found. Bitstamp reports SOC 2 compliance and annual Big Four accounting audits, but those are not published reserve attestations a user can check.",{"key":187,"status":184,"note":240},"Custodies with BitGo since 10 October 2019 and roughly 95% cold storage is reported by third-party reviewers, but Bitstamp publishes no cold\u002Fhot split we could confirm from a primary source.",{"key":190,"status":194,"note":242},"Bitstamp Europe S.A. was the first crypto-asset service provider granted a full MiCA licence in Luxembourg, by the CSSF on 16 May 2025 and passported across the EU\u002FEEA, alongside a reported New York BitLicense; since 2 June 2025 it has been owned by Robinhood, an SEC-reporting public company.",{"key":193,"status":207,"note":244},"No insurance or safety fund is publicly disclosed. Custody sits with BitGo, whose own policy was not shown to extend to Bitstamp balances. That is a statement about what Bitstamp discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on.",{"key":197,"status":184,"note":246},"About 19,000 BTC stolen from hot wallets in January 2015; Bitstamp recovered and kept operating, and its current BitGo custody architecture postdates the hack by several years. One of our two sources could not re-verify the incident against a primary record.",{"slug":248,"name":20,"grade":179,"summary":249,"factors":250,"logo_url":13,"updated_at":199,"has_affiliate":200},"bybit","Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46–1.5bn — the largest exchange hack on record — replenishing reserves in full within 72 hours.",[251,253,254,256,258],{"key":183,"status":194,"note":252},"Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor.",{"key":187,"status":184,"note":188},{"key":190,"status":184,"note":255},"EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax.",{"key":193,"status":184,"note":257},"Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed.",{"key":197,"status":207,"note":259},"About $1.46–1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen.",{"slug":261,"name":262,"grade":263,"summary":264,"factors":265,"logo_url":13,"updated_at":199,"has_affiliate":200},"coinbase","Coinbase","B","Coinbase is a publicly traded, SEC-reporting U.S. company licensed in 45 states and holding a New York BitLicense, and the SEC's 2023 case against it was dismissed with prejudice in February 2025; it runs no crypto-specific proof-of-reserves programme and its last disclosed crime-insurance figure dates from 2019.",[266,268,270,272,274],{"key":183,"status":184,"note":267},"Runs no exchange-wide proof-of-reserves programme; reserve assurance rests on its Deloitte-audited filings as an SEC-reporting public company, plus per-asset attestations for wrapped tokens such as cbBTC.",{"key":187,"status":184,"note":269},"Coinbase Custody is an NYDFS-regulated qualified custodian, but the cold\u002Fhot storage split is not disclosed and we could not confirm it from a primary source.",{"key":190,"status":194,"note":271},"New York BitLicense, FinCEN MSB registration, UK FCA registration FRN 900635 and licences in 45 U.S. states; paid a $100m NYDFS consent order in January 2023, and the SEC's 2023 unregistered-exchange suit was dismissed with prejudice on 27 February 2025.",{"key":193,"status":184,"note":273},"A $255m crime policy covering hot-wallet assets was disclosed in 2019; Coinbase still advertises commercial crime cover for custodied assets but has not confirmed a current figure.",{"key":197,"status":194,"note":275},"No confirmed platform-level breach of customer funds found in our research.",{"slug":277,"name":54,"grade":179,"summary":278,"factors":279,"logo_url":13,"updated_at":199,"has_affiliate":200},"crypto-com","Crypto.com discloses more than $870m of insurance cover, had its SEC investigation closed with no action in March 2025 and holds a Malta MiCA authorisation; its proof-of-reserves position is contested between our sources, and it reimbursed all users after a January 2022 incident that drained about $34–35m from 483 accounts.",[280,282,284,286,288],{"key":183,"status":184,"note":281},"Our two sources conflict: one records a published proof-of-reserves portal, the other found no exchange-wide programme. No methodology, auditor or reserve figure was confirmed either way.",{"key":187,"status":184,"note":283},"Cold-storage assets sit with custodial partner Ledger Vault, but the cold\u002Fhot storage split is not disclosed and we could not confirm it from a primary source.",{"key":190,"status":184,"note":285},"Malta MFSA MiCA CASP authorisation granted 27 January 2025 covering 6 of the 10 service categories, plus an EU Limited Financial Institution licence from 27 February 2026 for stablecoin services, and licences listed across Singapore, Canada, the UK, Australia, Hong Kong, Brazil and the U.S. without registration numbers we could check against public registers. The SEC closed its investigation with no enforcement action on 27 March 2025.",{"key":193,"status":194,"note":287},"More than $870m of disclosed cover: $750m on cold-storage assets through custodial partner Ledger Vault, expanded September 2021, plus $120m of institutional custody insurance arranged through Aon and announced 25 June 2025. U.S. fiat balances are held at FDIC-insured Community Federal Savings Bank.",{"key":197,"status":184,"note":289},"About $34–35m taken from 483 accounts in January 2022 through a 2FA compromise; Crypto.com disclosed the breach publicly and fully reimbursed all affected users.",{"slug":291,"name":292,"grade":293,"summary":294,"factors":295,"logo_url":13,"updated_at":199,"has_affiliate":200},"dydx","dYdX","C","dYdX is a non-custodial perpetuals protocol where balances stay in user-controlled wallets and an on-chain insurance fund is financed by a 1% liquidation fee; it holds no exchange licence in any jurisdiction, and a March 2024 attack cost roughly $9m, about 40% of the v3 insurance fund at the time.",[296,298,300,302,304],{"key":183,"status":194,"note":297},"Non-custodial: balances stay in user-controlled wallets and are verifiable directly on-chain, so no reserve attestation is needed.",{"key":187,"status":194,"note":299},"Non-custodial protocol — it never takes custody of user funds, so there is no hot\u002Fcold split to disclose.",{"key":190,"status":207,"note":301},"Holds no exchange licence in any jurisdiction; the v4 protocol runs on its own Cosmos SDK chain under community governance, supported by dYdX Trading Inc. in San Francisco and the dYdX Foundation in Zug. U.S. and Canadian users are blocked at the interface layer rather than by any licensed entity.",{"key":193,"status":184,"note":303},"An on-chain insurance fund financed by a 1% fee on liquidations, verifiable on-chain but with no disclosed balance; a March 2024 attack consumed roughly 40% of the v3 fund, and a March 2025 DAO vote moved $10m USDC out of it to cover operating expenses.",{"key":197,"status":184,"note":305},"Roughly $9m lost in a targeted attack on 5 March 2024, about 40% of the v3 insurance fund at the time; separately, a deposit-proxy vulnerability was exploited by a white hat to rescue about $2m before attackers reached it. One of our two sources recorded no confirmed incident.",{"slug":307,"name":308,"grade":293,"summary":309,"factors":310,"logo_url":13,"updated_at":199,"has_affiliate":200},"gate-io","Gate.io","Gate.io holds a Malta MiCA authorisation and an EU payment-services licence, and has published Merkle-tree plus zk-SNARK proof of reserves with Armanino LLP involved since October 2022, though only its U.S. entity's figures come from a primary source.",[311,313,315,317,319],{"key":183,"status":184,"note":312},"Has published proof of reserves since around May 2020 using a combined Merkle-tree and zk-SNARK method, with third-party involvement from Armanino LLP since 19 October 2022; only the U.S. entity's 100% ratio is primary-sourced, and the global platform's reported 124% ratio comes from third parties.",{"key":187,"status":184,"note":314},"Roughly 95% of assets in cold storage is reported by third parties, but Gate publishes no cold\u002Fhot split we could confirm from a primary source.",{"key":190,"status":184,"note":316},"Malta MFSA MiCA CASP authorisation granted 29 September 2025 covering 6 of the 10 service categories, and a PSD2 payment-services licence from 26 February 2026, alongside a Gibraltar GFSC DLT licence and a TCSP registration listed on its own licences page without registration numbers we could check; access is restricted from roughly 30–34 countries including the U.S., UK, Canada and most of Western Europe.",{"key":193,"status":207,"note":318},"No insurance or safety fund is publicly disclosed. That is a statement about what Gate discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on.",{"key":197,"status":194,"note":320},"No confirmed major security incident found in our research; Gate claims a 13-year record with no platform-level breach, and holds ISO 27001 certification alongside a CER.live AA rating of 88\u002F100.",{"slug":322,"name":323,"grade":293,"summary":324,"factors":325,"logo_url":13,"updated_at":199,"has_affiliate":200},"gemini","Gemini","Gemini is a New York-chartered trust company available in all 50 states with $100m of disclosed custody insurance, but publishes no exchange-wide proof of reserves and paid a $37m NYDFS penalty in 2024 over its collapsed Earn programme.",[326,328,329,331,333],{"key":183,"status":207,"note":327},"No exchange-wide proof-of-reserves programme was found. Gemini holds SOC 1 Type 2 and SOC 2 Type 2 reports, with Deloitte & Touche involved, but those are controls audits rather than reserve attestations.",{"key":187,"status":184,"note":188},{"key":190,"status":194,"note":330},"New York limited-purpose trust company charter granted in September 2015, operating in all 50 states; the February 2024 NYDFS consent order over the Gemini Earn programme carried a $37m penalty and more than $1.1bn committed back to users, alongside a $50m New York Attorney General recovery.",{"key":193,"status":184,"note":332},"Gemini Custody discloses $100m of insurance cover and Gemini operates an in-house Bermuda captive insurer; the cover is scoped to the custody product and we could not confirm it extends to retail exchange balances.",{"key":197,"status":194,"note":334},"No confirmed breach of Gemini's own systems found in our research; the Earn programme's collapse was a lending-counterparty failure at Genesis, not an attack on the exchange.",{"slug":336,"name":337,"grade":263,"summary":338,"factors":339,"logo_url":13,"updated_at":199,"has_affiliate":200},"htx","HTX","HTX publishes monthly Merkle-tree proof of reserves that excludes corporate holdings, discloses only a Pakistani no-objection certificate among its authorisations, blocked the entire EU rather than seek MiCA licensing, and faces UK FCA High Court proceedings.",[340,342,344,346,348],{"key":183,"status":194,"note":341},"Monthly Merkle-tree proof of reserves, a run of 36 consecutive months as of October 2025 and most recently published July 2026; corporate holdings are excluded from the proof.",{"key":187,"status":184,"note":343},"Cold storage is described by third-party reviewers as air-gapped with hardware security modules and multi-signature controls, but no cold\u002Fhot split is disclosed and we could not confirm one from a primary source.",{"key":190,"status":184,"note":345},"Only a Pakistan PVARA no-objection certificate was confirmed among its listed authorisations; it holds no MiCA or UK authorisation and blocked the entire European Union from 1 July 2026 rather than seek one. The UK FCA began High Court proceedings against Huobi Global S.A. on 21 October 2025 over illegal financial promotions.",{"key":193,"status":184,"note":347},"No insurance or safety-fund figure is publicly confirmed. That is a disclosure gap rather than confirmation that none exists.",{"key":197,"status":184,"note":349},"About $7.9–8m (5,000 ETH) stolen in September 2023; roughly 95% was recovered by negotiation with the attacker, with a 5% white-hat bounty paid and no user losses reported.",{"slug":351,"name":352,"grade":353,"summary":354,"factors":355,"logo_url":13,"updated_at":199,"has_affiliate":200},"kraken","Kraken","A-","Kraken holds a Wyoming SPDI charter, CFTC and SEC registrations and two EU MiCA authorisations, and has published Merkle-tree proof of reserves verified by Armanino LLP since February 2022; it discloses no insurance-fund figure.",[356,358,359,361,363],{"key":183,"status":194,"note":357},"Merkle-tree proof of reserves verified by third-party accountant Armanino LLP since February 2022, most recently finalised 30 June 2025 across BTC, ETH, SOL, USDC, USDT, XRP and ADA.",{"key":187,"status":184,"note":188},{"key":190,"status":194,"note":360},"Wyoming Special Purpose Depository Institution charter, CFTC DCM\u002FDCO\u002FFCM and SEC broker-dealer\u002FRIA registrations, and two EU MiCA CASP authorisations; settled with the CFTC for $1.25m in September 2021 and with the SEC for $30m in February 2023 over its U.S. staking-as-a-service programme, relaunching on-chain U.S. staking in January 2025.",{"key":193,"status":184,"note":362},"No insurance-fund figure is publicly disclosed. Our research found no SAFU-equivalent named fund, which is a disclosure gap rather than confirmation that none exists.",{"key":197,"status":194,"note":364},"No confirmed major security incident found in our research; Kraken has operated since 2011 with no reported breach costing customers funds.",{"slug":366,"name":101,"grade":367,"summary":368,"factors":369,"logo_url":13,"updated_at":199,"has_affiliate":200},"kucoin","C+","KuCoin holds an Austrian FMA MiCAR licence passportable across 29 EEA countries but pleaded guilty in the U.S. in March 2024, paying $297m and accepting a ban since made permanent; its proof-of-reserves position is contested between our sources, and it lost roughly $280m in its September 2020 hack, with users made whole.",[370,372,373,375,377],{"key":183,"status":184,"note":371},"Our two sources conflict: one records Hacken-audited proof of reserves running 32 consecutive months to October 2025 with coverage above 100%, the other found no proof-of-reserves programme at all. Neither could be confirmed against a primary KuCoin disclosure.",{"key":187,"status":184,"note":188},{"key":190,"status":184,"note":374},"Austrian FMA MiCAR CASP licence passportable across 29 EEA countries; operating entity Peken Global Ltd. pleaded guilty in March 2024 to unlicensed money transmission, paying $297m and accepting a two-year U.S. ban since made permanent by a March 2026 CFTC consent order. Related entities settled with the New York Attorney General for $22m in December 2023 and were permanently banned by the Ontario Securities Commission in June 2022.",{"key":193,"status":184,"note":376},"An insurance fund covered the 16% of 2020 hack losses that was not recovered, but its standing balance is not disclosed.",{"key":197,"status":184,"note":378},"About $280–281m stolen in September 2020; 84% was recovered through on-chain tracing, token reissuance and exchange cooperation, and the remainder covered by the insurance fund, leaving users whole.",{"slug":380,"name":381,"grade":179,"summary":382,"factors":383,"logo_url":13,"updated_at":199,"has_affiliate":200},"mexc","MEXC","MEXC publishes a proof-of-reserves page stating a reserve-rate methodology and cites a $100m Guardian Fund through a single source; Estonia's financial intelligence unit revoked its VASP licence in November 2023.",[384,386,387,389,391],{"key":183,"status":184,"note":385},"The proof-of-reserves page states a reserve-rate methodology but publishes no figures we could extract; a June 2026 Hacken-audited snapshot at 114–269% coverage is reported by third parties and could not be confirmed against the primary page.",{"key":187,"status":184,"note":188},{"key":190,"status":184,"note":388},"Holds FinCEN MSB, AUSTRAC, Canadian MSB and Swiss VQF registrations — AML monitoring obligations rather than exchange licences. Estonia's Financial Intelligence Unit revoked MEXC Estonia OÜ's licence in November 2023, and a June 2024 blacklist entry surfaced in our research without a clear issuing body or stated consequence.",{"key":193,"status":184,"note":390},"A $100m 'Guardian Fund' is cited by a single third-party source and is not confirmed by any primary MEXC disclosure.",{"key":197,"status":194,"note":231},{"slug":393,"name":394,"grade":263,"summary":395,"factors":396,"logo_url":13,"updated_at":199,"has_affiliate":200},"okx","OKX","OKX publishes monthly zk-STARK proof of reserves with an open-source verification tool and holds Dubai VARA and Malta MiCA authorisations, but its Seychelles operating entity pleaded guilty in the U.S. in February 2025 and paid over $504m.",[397,399,400,402,404],{"key":183,"status":194,"note":398},"Monthly zk-STARK v2 proof of reserves — the 44th report covered $22.65bn in primary reserve assets — with an open-source verification tool on GitHub so users can check their own balances against the published Merkle root.",{"key":187,"status":184,"note":188},{"key":190,"status":184,"note":401},"Dubai VARA VASP licence VL\u002F23\u002F12\u002F003 and an EU MiCA CASP authorisation via OKX Europe Limited (Malta MFSA, 27 January 2025); operating entity Aux Cayes FinTech Co. Ltd. pleaded guilty in U.S. federal court on 24 February 2025 to running an unlicensed money-transmitting business and paid over $504m.",{"key":193,"status":207,"note":403},"No insurance or safety fund is publicly disclosed beyond the proof-of-reserves programme. That is a statement about what OKX discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on.",{"key":197,"status":194,"note":231}]