Размещайте рекламу на KripZen — покажите свой бренд глобальной криптоаудитории.Связаться с нами →

Реестр оценок

Какие биржи могут доказать, что действительно хранят ваши деньги?

Каждая оценка ниже выведена из документов, которые биржа действительно опубликовала: подтверждений резервов, записей в реестрах лицензий, раскрытых страховых фондов и истории инцидентов — по одной взвешенной методике. Чем шире колонка, тем больше её вес.

15 бирж · оценки от A- до D · спонсоры не влияют на оценку

  • Раскрыто
  • Частично или без аудита
  • Не раскрыто
01A-Kraken

Kraken holds a Wyoming SPDI charter, CFTC and SEC registrations and two EU MiCA authorisations, and has published Merkle-tree proof of reserves verified by Armanino LLP since February 2022; it discloses no insurance-fund figure.

  • Доказательство резервов — Merkle-tree proof of reserves verified by third-party accountant Armanino LLP since February 2022, most recently finalised 30 June 2025 across BTC, ETH, SOL, USDC, USDT, XRP and ADA. (соответствует этому фактору)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Wyoming Special Purpose Depository Institution charter, CFTC DCM/DCO/FCM and SEC broker-dealer/RIA registrations, and two EU MiCA CASP authorisations; settled with the CFTC for $1.25m in September 2021 and with the SEC for $30m in February 2023 over its U.S. staking-as-a-service programme, relaunching on-chain U.S. staking in January 2025. (соответствует этому фактору)
  • Страхование — No insurance-fund figure is publicly disclosed. Our research found no SAFU-equivalent named fund, which is a disclosure gap rather than confirmation that none exists. (частично или не проверено)
  • История инцидентов — No confirmed major security incident found in our research; Kraken has operated since 2011 with no reported breach costing customers funds. (соответствует этому фактору)
02B-Binance

Binance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.

  • Доказательство резервов — Publishes Merkle-tree proof of reserves covering 30-plus assets, most recently a 1 January 2026 snapshot of 636,535 BTC, but the reports are self-published rather than independently audited. (частично или не проверено)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Holds an ADGM (UAE) authorisation and, via Binance.US, money-transmitter licences in 30 states (NMLS ID 1906829); pleaded guilty to U.S. Bank Secrecy Act and sanctions violations in November 2023, paying $4.3bn and accepting a five-year DOJ compliance monitorship running to 2028. (частично или не проверено)
  • Страхование — SAFU user-protection fund, established in 2018 and topped up to $1bn in November 2022; it covered the May 2019 hack in full. (соответствует этому фактору)
  • История инцидентов — About 7,000 BTC (roughly $40m at the time) drained from hot wallets on 7 May 2019; the SAFU fund covered the loss in full and no user lost funds. No platform breach of comparable scale has been reported since. (частично или не проверено)
03B+Bitget

Bitget publishes a monthly open-source Merkle-tree proof of reserves showing BTC at 138% and ETH at 181%, and cites a protection fund its own sources size differently; ASIC issued an investor alert in July 2025 over unlicensed high-leverage derivatives.

  • Доказательство резервов — Monthly open-source Merkle-tree proof of reserves published on GitHub, showing BTC reserves at 138%, ETH at 181%, USDC at 107% and USDT at 101%. (соответствует этому фактору)
  • Хранение — Uses multi-signature cold storage, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Lists an AUSTRAC registration, El Salvador CNAD/BSP licences, Argentine CNV and Mexican SAT registrations, a UK FCA Section 21 approver partnership and a Swiss FINMA SRO membership, without registration numbers we could check against public registers. ASIC issued a public investor alert on 28 July 2025 over unlicensed crypto derivatives sold to Australian retail clients at up to 125x leverage, noting Bitget holds no Australian Financial Services licence; its own corporate registration is cited variously as Seychelles, Lithuania or New Zealand. (частично или не проверено)
  • Страхование — A protection fund is disclosed but sized inconsistently across sources — $630m in one, 6,500 BTC (implemented December 2022) in another — so no single figure is confirmed. (частично или не проверено)
  • История инцидентов — No confirmed major security incident found in our research. (соответствует этому фактору)
04B-Bybit

Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46–1.5bn — the largest exchange hack on record — replenishing reserves in full within 72 hours.

  • Доказательство резервов — Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor. (соответствует этому фактору)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax. (частично или не проверено)
  • Страхование — Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed. (частично или не проверено)
  • История инцидентов — About $1.46–1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen. (не соответствует этому фактору)
05BCoinbase

Coinbase is a publicly traded, SEC-reporting U.S. company licensed in 45 states and holding a New York BitLicense, and the SEC's 2023 case against it was dismissed with prejudice in February 2025; it runs no crypto-specific proof-of-reserves programme and its last disclosed crime-insurance figure dates from 2019.

  • Доказательство резервов — Runs no exchange-wide proof-of-reserves programme; reserve assurance rests on its Deloitte-audited filings as an SEC-reporting public company, plus per-asset attestations for wrapped tokens such as cbBTC. (частично или не проверено)
  • Хранение — Coinbase Custody is an NYDFS-regulated qualified custodian, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — New York BitLicense, FinCEN MSB registration, UK FCA registration FRN 900635 and licences in 45 U.S. states; paid a $100m NYDFS consent order in January 2023, and the SEC's 2023 unregistered-exchange suit was dismissed with prejudice on 27 February 2025. (соответствует этому фактору)
  • Страхование — A $255m crime policy covering hot-wallet assets was disclosed in 2019; Coinbase still advertises commercial crime cover for custodied assets but has not confirmed a current figure. (частично или не проверено)
  • История инцидентов — No confirmed platform-level breach of customer funds found in our research. (соответствует этому фактору)
06B-Crypto.com

Crypto.com discloses more than $870m of insurance cover, had its SEC investigation closed with no action in March 2025 and holds a Malta MiCA authorisation; its proof-of-reserves position is contested between our sources, and it reimbursed all users after a January 2022 incident that drained about $34–35m from 483 accounts.

  • Доказательство резервов — Our two sources conflict: one records a published proof-of-reserves portal, the other found no exchange-wide programme. No methodology, auditor or reserve figure was confirmed either way. (частично или не проверено)
  • Хранение — Cold-storage assets sit with custodial partner Ledger Vault, but the cold/hot storage split is not disclosed and we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Malta MFSA MiCA CASP authorisation granted 27 January 2025 covering 6 of the 10 service categories, plus an EU Limited Financial Institution licence from 27 February 2026 for stablecoin services, and licences listed across Singapore, Canada, the UK, Australia, Hong Kong, Brazil and the U.S. without registration numbers we could check against public registers. The SEC closed its investigation with no enforcement action on 27 March 2025. (частично или не проверено)
  • Страхование — More than $870m of disclosed cover: $750m on cold-storage assets through custodial partner Ledger Vault, expanded September 2021, plus $120m of institutional custody insurance arranged through Aon and announced 25 June 2025. U.S. fiat balances are held at FDIC-insured Community Federal Savings Bank. (соответствует этому фактору)
  • История инцидентов — About $34–35m taken from 483 accounts in January 2022 through a 2FA compromise; Crypto.com disclosed the breach publicly and fully reimbursed all affected users. (частично или не проверено)
07BHTX

HTX publishes monthly Merkle-tree proof of reserves that excludes corporate holdings, discloses only a Pakistani no-objection certificate among its authorisations, blocked the entire EU rather than seek MiCA licensing, and faces UK FCA High Court proceedings.

  • Доказательство резервов — Monthly Merkle-tree proof of reserves, a run of 36 consecutive months as of October 2025 and most recently published July 2026; corporate holdings are excluded from the proof. (соответствует этому фактору)
  • Хранение — Cold storage is described by third-party reviewers as air-gapped with hardware security modules and multi-signature controls, but no cold/hot split is disclosed and we could not confirm one from a primary source. (частично или не проверено)
  • Регулирование — Only a Pakistan PVARA no-objection certificate was confirmed among its listed authorisations; it holds no MiCA or UK authorisation and blocked the entire European Union from 1 July 2026 rather than seek one. The UK FCA began High Court proceedings against Huobi Global S.A. on 21 October 2025 over illegal financial promotions. (частично или не проверено)
  • Страхование — No insurance or safety-fund figure is publicly confirmed. That is a disclosure gap rather than confirmation that none exists. (частично или не проверено)
  • История инцидентов — About $7.9–8m (5,000 ETH) stolen in September 2023; roughly 95% was recovered by negotiation with the attacker, with a 5% white-hat bounty paid and no user losses reported. (частично или не проверено)
08B-MEXC

MEXC publishes a proof-of-reserves page stating a reserve-rate methodology and cites a $100m Guardian Fund through a single source; Estonia's financial intelligence unit revoked its VASP licence in November 2023.

  • Доказательство резервов — The proof-of-reserves page states a reserve-rate methodology but publishes no figures we could extract; a June 2026 Hacken-audited snapshot at 114–269% coverage is reported by third parties and could not be confirmed against the primary page. (частично или не проверено)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Holds FinCEN MSB, AUSTRAC, Canadian MSB and Swiss VQF registrations — AML monitoring obligations rather than exchange licences. Estonia's Financial Intelligence Unit revoked MEXC Estonia OÜ's licence in November 2023, and a June 2024 blacklist entry surfaced in our research without a clear issuing body or stated consequence. (частично или не проверено)
  • Страхование — A $100m 'Guardian Fund' is cited by a single third-party source and is not confirmed by any primary MEXC disclosure. (частично или не проверено)
  • История инцидентов — No confirmed major security incident found in our research. (соответствует этому фактору)
09BOKX

OKX publishes monthly zk-STARK proof of reserves with an open-source verification tool and holds Dubai VARA and Malta MiCA authorisations, but its Seychelles operating entity pleaded guilty in the U.S. in February 2025 and paid over $504m.

  • Доказательство резервов — Monthly zk-STARK v2 proof of reserves — the 44th report covered $22.65bn in primary reserve assets — with an open-source verification tool on GitHub so users can check their own balances against the published Merkle root. (соответствует этому фактору)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Dubai VARA VASP licence VL/23/12/003 and an EU MiCA CASP authorisation via OKX Europe Limited (Malta MFSA, 27 January 2025); operating entity Aux Cayes FinTech Co. Ltd. pleaded guilty in U.S. federal court on 24 February 2025 to running an unlicensed money-transmitting business and paid over $504m. (частично или не проверено)
  • Страхование — No insurance or safety fund is publicly disclosed beyond the proof-of-reserves programme. That is a statement about what OKX discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on. (не соответствует этому фактору)
  • История инцидентов — No confirmed major security incident found in our research. (соответствует этому фактору)
10C-Bitstamp

Bitstamp was the first crypto-asset service provider licensed under MiCA in Luxembourg and has been owned by Robinhood since June 2025; it custodies with BitGo but publishes neither proof of reserves nor an insurance figure, and lost about 19,000 BTC in a 2015 hot-wallet hack.

  • Доказательство резервов — No proof-of-reserves programme was found. Bitstamp reports SOC 2 compliance and annual Big Four accounting audits, but those are not published reserve attestations a user can check. (не соответствует этому фактору)
  • Хранение — Custodies with BitGo since 10 October 2019 and roughly 95% cold storage is reported by third-party reviewers, but Bitstamp publishes no cold/hot split we could confirm from a primary source. (частично или не проверено)
  • Регулирование — Bitstamp Europe S.A. was the first crypto-asset service provider granted a full MiCA licence in Luxembourg, by the CSSF on 16 May 2025 and passported across the EU/EEA, alongside a reported New York BitLicense; since 2 June 2025 it has been owned by Robinhood, an SEC-reporting public company. (соответствует этому фактору)
  • Страхование — No insurance or safety fund is publicly disclosed. Custody sits with BitGo, whose own policy was not shown to extend to Bitstamp balances. That is a statement about what Bitstamp discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on. (не соответствует этому фактору)
  • История инцидентов — About 19,000 BTC stolen from hot wallets in January 2015; Bitstamp recovered and kept operating, and its current BitGo custody architecture postdates the hack by several years. One of our two sources could not re-verify the incident against a primary record. (частично или не проверено)
11CdYdX

dYdX is a non-custodial perpetuals protocol where balances stay in user-controlled wallets and an on-chain insurance fund is financed by a 1% liquidation fee; it holds no exchange licence in any jurisdiction, and a March 2024 attack cost roughly $9m, about 40% of the v3 insurance fund at the time.

  • Доказательство резервов — Non-custodial: balances stay in user-controlled wallets and are verifiable directly on-chain, so no reserve attestation is needed. (соответствует этому фактору)
  • Хранение — Non-custodial protocol — it never takes custody of user funds, so there is no hot/cold split to disclose. (соответствует этому фактору)
  • Регулирование — Holds no exchange licence in any jurisdiction; the v4 protocol runs on its own Cosmos SDK chain under community governance, supported by dYdX Trading Inc. in San Francisco and the dYdX Foundation in Zug. U.S. and Canadian users are blocked at the interface layer rather than by any licensed entity. (не соответствует этому фактору)
  • Страхование — An on-chain insurance fund financed by a 1% fee on liquidations, verifiable on-chain but with no disclosed balance; a March 2024 attack consumed roughly 40% of the v3 fund, and a March 2025 DAO vote moved $10m USDC out of it to cover operating expenses. (частично или не проверено)
  • История инцидентов — Roughly $9m lost in a targeted attack on 5 March 2024, about 40% of the v3 insurance fund at the time; separately, a deposit-proxy vulnerability was exploited by a white hat to rescue about $2m before attackers reached it. One of our two sources recorded no confirmed incident. (частично или не проверено)
12CGate.io

Gate.io holds a Malta MiCA authorisation and an EU payment-services licence, and has published Merkle-tree plus zk-SNARK proof of reserves with Armanino LLP involved since October 2022, though only its U.S. entity's figures come from a primary source.

  • Доказательство резервов — Has published proof of reserves since around May 2020 using a combined Merkle-tree and zk-SNARK method, with third-party involvement from Armanino LLP since 19 October 2022; only the U.S. entity's 100% ratio is primary-sourced, and the global platform's reported 124% ratio comes from third parties. (частично или не проверено)
  • Хранение — Roughly 95% of assets in cold storage is reported by third parties, but Gate publishes no cold/hot split we could confirm from a primary source. (частично или не проверено)
  • Регулирование — Malta MFSA MiCA CASP authorisation granted 29 September 2025 covering 6 of the 10 service categories, and a PSD2 payment-services licence from 26 February 2026, alongside a Gibraltar GFSC DLT licence and a TCSP registration listed on its own licences page without registration numbers we could check; access is restricted from roughly 30–34 countries including the U.S., UK, Canada and most of Western Europe. (частично или не проверено)
  • Страхование — No insurance or safety fund is publicly disclosed. That is a statement about what Gate discloses, not a finding that it is uninsured — but an undisclosed fund is one a user cannot rely on. (не соответствует этому фактору)
  • История инцидентов — No confirmed major security incident found in our research; Gate claims a 13-year record with no platform-level breach, and holds ISO 27001 certification alongside a CER.live AA rating of 88/100. (соответствует этому фактору)
13CGemini

Gemini is a New York-chartered trust company available in all 50 states with $100m of disclosed custody insurance, but publishes no exchange-wide proof of reserves and paid a $37m NYDFS penalty in 2024 over its collapsed Earn programme.

  • Доказательство резервов — No exchange-wide proof-of-reserves programme was found. Gemini holds SOC 1 Type 2 and SOC 2 Type 2 reports, with Deloitte & Touche involved, but those are controls audits rather than reserve attestations. (не соответствует этому фактору)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — New York limited-purpose trust company charter granted in September 2015, operating in all 50 states; the February 2024 NYDFS consent order over the Gemini Earn programme carried a $37m penalty and more than $1.1bn committed back to users, alongside a $50m New York Attorney General recovery. (соответствует этому фактору)
  • Страхование — Gemini Custody discloses $100m of insurance cover and Gemini operates an in-house Bermuda captive insurer; the cover is scoped to the custody product and we could not confirm it extends to retail exchange balances. (частично или не проверено)
  • История инцидентов — No confirmed breach of Gemini's own systems found in our research; the Earn programme's collapse was a lending-counterparty failure at Genesis, not an attack on the exchange. (соответствует этому фактору)
14C+KuCoin

KuCoin holds an Austrian FMA MiCAR licence passportable across 29 EEA countries but pleaded guilty in the U.S. in March 2024, paying $297m and accepting a ban since made permanent; its proof-of-reserves position is contested between our sources, and it lost roughly $280m in its September 2020 hack, with users made whole.

  • Доказательство резервов — Our two sources conflict: one records Hacken-audited proof of reserves running 32 consecutive months to October 2025 with coverage above 100%, the other found no proof-of-reserves programme at all. Neither could be confirmed against a primary KuCoin disclosure. (частично или не проверено)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — Austrian FMA MiCAR CASP licence passportable across 29 EEA countries; operating entity Peken Global Ltd. pleaded guilty in March 2024 to unlicensed money transmission, paying $297m and accepting a two-year U.S. ban since made permanent by a March 2026 CFTC consent order. Related entities settled with the New York Attorney General for $22m in December 2023 and were permanently banned by the Ontario Securities Commission in June 2022. (частично или не проверено)
  • Страхование — An insurance fund covered the 16% of 2020 hack losses that was not recovered, but its standing balance is not disclosed. (частично или не проверено)
  • История инцидентов — About $280–281m stolen in September 2020; 84% was recovered through on-chain tracing, token reissuance and exchange cooperation, and the remainder covered by the insurance fund, leaving users whole. (частично или не проверено)
15DBitfinex

Bitfinex is BVI-registered with no public licence register found and publishes no proof of reserves; it lost about 119,756 BTC in the August 2016 hack, and roughly $850m in commingled customer and corporate funds was seized or lost at its payment processor in 2018–19.

  • Доказательство резервов — No proof-of-reserves programme was found; both of our sources record none, and neither identified an independent reserve attestation of any kind. (не соответствует этому фактору)
  • Хранение — Cold/hot storage split is not disclosed; we could not confirm it from a primary source. (частично или не проверено)
  • Регулирование — No public licence register was found beyond its British Virgin Islands incorporation, and it blocks U.S. and California residents outright. Settled with the CFTC for $75,000 in 2016 and $1.5m in October 2021, and with the New York Attorney General for $18.5m in February 2021 alongside affiliate Tether. (не соответствует этому фактору)
  • Страхование — No named insurance fund was identified in our research. That is a disclosure gap rather than confirmation the cover is zero. (частично или не проверено)
  • История инцидентов — About 119,756 BTC (roughly $72m at the time) stolen in August 2016, with U.S. authorities recovering $3.6bn from the perpetrators in 2022; separately, roughly $850m in commingled customer and corporate funds was seized or lost at payment processor Crypto Capital in 2018–19 and made good from affiliate Tether's balance sheet. (не соответствует этому фактору)

Как читать эти оценки: каждая выведена из опубликованных и проверяемых раскрытий — аттестаций подтверждения резервов, публичных реестров регуляторов, заявленных страховых фондов и документально подтверждённой истории инцидентов — по весовой методике ниже. Если биржа что-то не раскрывает, мы помечаем это как непроверенное, а не предполагаем. Это не аудит и не инвестиционный совет; оценки отражают опубликованные данные на момент нашей последней проверки.

Начните отсюда

Найдите страницу под ваш настоящий вопрос

Реестр хорошо отвечает на один вопрос: какие площадки могут показать то, что заявляют. Вот остальные вопросы и где на них отвечают.

Пять проверок

Что мы на самом деле проверяем

Каждая оценка на этом сайте сводится к этим пяти факторам с указанными весами. Никаких скрытых критериев.

  • Доказательство резервов

    Может ли биржа показать — а не просто заявить — что она держит то, что должна клиентам, в идеале с независимым подтверждением?

  • Хранение

    Хранится ли большинство средств клиентов офлайн в холодном хранилище, с публично раскрытым распределением?

  • Регулирование

    Лицензирована ли она признанным регулятором на рынках, где работает, или только зарегистрирована как компания по денежным услугам?

  • Страхование

    Есть ли раскрытый страховой фонд или сторонняя защита от кражи и взломов?

  • История инцидентов

    Избегала ли она крупных инцидентов безопасности — или справилась с одним прозрачно и возместила клиентам ущерб?

Как мы оцениваем

Критерий, стоящий за каждой оценкой безопасности на этом сайте, и почему платное партнёрство не может купить лучшую.

Каждая биржа, которую мы освещаем — спонсор или нет — оценивается по одним и тем же пяти факторам, с одинаковым весом. Платное партнёрство может ускорить попадание биржи в список. Оно не может купить лучшую оценку.

Доказательство резервов
30%
Хранение
25%
Регулирование
20%
Страхование
15%
История инцидентов
10%

Эта оценка безопасности — более узкое и быстрое прочтение, чем наш полный обзор биржи, который также охватывает комиссии, монеты и поддержку. Читать нашу полную редакционную политику →

Шкала A–F

  • A

    Соответствует каждому фактору по высокой планке: независимо проверенные резервы, раскрытое холодное хранение, реальное лицензирование, страхование и чистая история.

  • B

    Сильна по большинству факторов, с хотя бы одним пробелом — обычно самозаявленные резервы или регистрация вместо полного лицензирования.

  • C

    Средне. Есть некоторое раскрытие, но несколько факторов слабы, самозаявлены или непроверяемы.

  • D

    Несколько реальных пробелов — нераскрытое хранение, нет регулирования, нет страхования — даже без известного инцидента.

  • F

    Либо подтверждённая история крупных инцидентов, либо достаточно структурных тревожных сигналов, чтобы мы не могли ответственно её рекомендовать.

Хроника

Уроки из худших крахов криптобирж

Шесть самых значимых крахов бирж из истории, в том порядке, в котором они произошли.

Вся хроника →

Даты и цифры — это широко публиковавшиеся публичные оценки из освещения того времени, а не собственные проаудированные данные KripZen.

  1. 2014

    Mt. Gox

    ВзломFebruary 2014

    Once the exchange handling the large majority of the world's Bitcoin trades, Mt. Gox abruptly halted withdrawals and filed for bankruptcy in Japan after disclosing that hundreds of thousands of customer and company bitcoins were gone — later attributed to theft that went undetected for years.

    Урок — Trading volume and market dominance are not safety signals. An exchange can look like the industry's center of gravity and still be hollowed out inside.

    ~850,000 BTC reported missing (publicly reported estimate)

  2. 2015

    Bitstamp

    ВзломJanuary 2015

    В январе 2015 года из горячих кошельков Bitstamp было выведено около 19 000 BTC после целенаправленной атаки на сотрудников биржи. Bitstamp приостановила торги, перестроила инфраструктуру и позже перешла на институциональное хранение у стороннего провайдера, где основная часть средств клиентов держится офлайн.

    Урок — Профиль риска Bitstamp изменила перестроенная модель хранения, а не извинения. Оценивайте биржу по тому, что она сделала после инцидента, а не по скорости выпуска заявления.

    ~19,000 BTC taken from hot wallets (publicly reported estimate)

  3. 2016

    Bitfinex

    ВзломAugust 2016

    A security breach in Bitfinex's multi-signature wallet setup let attackers drain a large share of customer bitcoin in a single incident. The exchange spread the loss across all users' balances and later repaid affected customers over several years.

    Урок — Even a widely used, multi-signature custody setup is only as strong as the systems and partners it depends on — 'multi-sig' alone isn't a safety guarantee.

    ~120,000 BTC stolen (publicly reported estimate)

  4. 2016

    The DAO

    ВзломJune 2016

    The DAO был фондом, управляемым инвесторами и целиком написанным в виде смарт-контрактов Ethereum: держатели токенов голосовали за финансирование заявок, без управляющего посередине. Токенсейл 2016 года собрал значительную часть всего обращающегося эфира. В июне 2016 года атакующий использовал уязвимость повторного входа в коде, позволявшем участнику забрать свою долю: контракт отправлял эфир до того, как обновлял баланс отправителя, поэтому вредоносный контракт мог повторно вызывать вывод и каждый раз получать выплату по ещё не уменьшенному балансу. Около 3,6 млн ETH было переведено в дочерний контракт с периодом ожидания, прописанным в правилах самого The DAO, — это и дало сообществу несколько недель на спор о реакции. В итоге участники Ethereum приняли хардфорк, переместивший средства в контракт для возврата. Меньшинство отвергло форк, считая, что переписывать реестр нельзя, и продолжило исходную цепь как Ethereum Classic.

    Урок — Код, который держит средства, надёжен ровно настолько, насколько верен порядок действий. Уязвимость была не в экзотической криптографии, а в последовательности — сначала выплата, потом обновление записи, — и именно этот шаблон аудиторы ищут первым. Последствия важны не меньше самой ошибки: сеть способна отменить кражу, только если на это согласится достаточная часть её участников, а такое согласие — политический факт о сообществе, а не техническая гарантия, на которую можно рассчитывать заранее.

    ~3.6M ETH moved out of the contract (publicly reported estimate)

  5. 2017

    Parity Multisig Wallet Freeze

    ВзломNovember 2017

    Мультиподписные кошельки Parity не несли собственную логику. Ради экономии на развёртывании каждый кошелёк был тонким контрактом, делегировавшим поведение одному общему библиотечному контракту в сети. Эта библиотека была развёрнута без инициализации, поэтому права владения на неё оставались никем не заявленными. В ноябре 2017 года пользователь заявил их, а затем вызвал функцию самоуничтожения, удалившую код библиотеки из цепи. Каждый зависевший от неё кошелёк остался указывать в пустоту: балансы по-прежнему существуют в реестре, но кода, способного санкционировать перевод, больше нет. По публичным оценкам, заблокированной оказалась сумма около 513 000 ETH. Средства никто не забрал, и никакой эксплойт их не перемещал — они просто перестали быть доступными. Предложения вернуть их изменением протокола обсуждались и не были приняты. Несколькими месяцами ранее другая уязвимость того же кошелькового ПО позволила совершить реальную кражу, по публичным оценкам около 150 000 ETH.

    Урок — Не всякая потеря связана с вором. Общий код — это общая зависимость, и контракт, делегирующий работу библиотеке, наследует её сценарии отказа, ничего об этом не сообщая. Случай показывает и обратную сторону неизменяемости для пользователя: то же свойство, что не даёт никому переписать ваш баланс, не даёт никому и исправить его, а непоправимая ошибка может обойтись не дешевле атаки.

    ~513,000 ETH rendered permanently inaccessible (publicly reported estimate)

  6. 2018

    BitConnect

    МошенничествоJanuary 2018

    BitConnect предлагал обменять биткоин на собственный токен и заблокировать его в «кредитной программе» с обещанием стабильного дохода, который якобы приносил закрытый торговый бот, недоступный для проверки со стороны. Многоуровневая реферальная схема платила участникам за привлечение новых. После предписаний от регуляторов ценных бумаг штатов США кредитную платформу закрыли в январе 2018 года, и стоимость токена рухнула. Позже американские власти квалифицировали проект как мошенничество: один из промоутеров признал вину, а основателю предъявили обвинение, и, по сообщениям, он скрывается.

    Урок — Фиксированная или гарантированная доходность в крипте — это утверждение о будущем, которое никто не может сделать честно. Когда стратегию нельзя проверить, а за привлечение людей платят, доход выплачивается из более поздних взносов: это структура, а не рыночная идея, и она заканчивается, как только приток замедляется.

    ~$2.4B taken from investors (figure cited by the US Department of Justice)

  7. 2018

    Coincheck

    ВзломJanuary 2018

    The Japanese exchange kept a large pool of a single token in an internet-connected hot wallet without a multi-signature setup. Attackers stole hundreds of millions of dollars' worth in one of the largest exchange hacks by value at the time.

    Урок — Hot-wallet convenience has a price. The safest exchanges keep the large majority of customer funds offline, precisely so one breach can't drain everything.

    ~$530M in NEM (XEM) stolen (publicly reported estimate)

  8. 2019

    Binance

    ВзломMay 2019

    7 мая 2019 года злоумышленники одной транзакцией вывели из горячего кошелька Binance около 7000 BTC — примерно 40 млн долларов по курсу того времени, использовав украденные API-ключи и добытые фишингом учётные данные. Убыток полностью покрыл фонд SAFU, балансы клиентов остались нетронутыми.

    Урок — Резерв, наполненный до взлома, превращает атаку в бухгалтерскую проводку, а не в потерю клиента. Проверяйте, что фонд существует и раскрыт сегодня, а не обещан задним числом.

    ~7,000 BTC (~$40M at the time) taken from a hot wallet (publicly reported estimate)

  9. 2019

    Bitfinex / Crypto Capital

    Мошенничество2018–2019

    В 2018–2019 годах у платёжного процессора Bitfinex, компании Crypto Capital Corp, находилось около 850 млн долларов смешанных клиентских и корпоративных средств; счета процессора были арестованы властями нескольких стран. Разрыв закрыли резервы аффилированного эмитента стейблкоина Tether, а в феврале 2021 года обе компании урегулировали дело с генпрокуратурой Нью-Йорка за 18,5 млн долларов без признания вины.

    Урок — Криптовалюта никуда не двигалась — двигалась фиатная часть. Выясняйте, какая сторонняя компания реально держит денежное плечо биржи: её юридические проблемы становятся вашими.

    ~$850M in commingled customer and corporate funds (publicly reported estimate)

  10. 2019

    QuadrigaCX

    МошенничествоEarly 2019

    Canada's largest exchange at the time told customers it could no longer access roughly CA$190M in funds after its founder died while allegedly holding sole control of the cold-wallet keys. A later court-appointed investigation found many of the wallets had been empty long before his death, pointing to mismanagement and likely fraud rather than a pure accident.

    Урок — Single-person key control is a structural failure waiting to happen — deliberate or not. A credible custodian never lets access depend on one individual.

    ~CA$190M in customer funds inaccessible (publicly reported estimate)

  11. 2020

    KuCoin

    ВзломSeptember 2020

    25 сентября 2020 года злоумышленники вывели из горячих кошельков KuCoin около 281 млн долларов. Примерно 84% удалось вернуть в последующие недели за счёт ончейн-отслеживания, заморозки и повторного выпуска токенов их эмитентами, а также блокировок на других биржах. Остаток покрыл страховой фонд KuCoin, и клиенты не пострадали.

    Урок — Возврат держался на доброй воле посторонних: эмитенты согласились заморозить токены, площадки — заблокировать адреса. Это одолжение отрасли, а не защита, на которую можно рассчитывать.

    ~$281M drained from hot wallets (publicly reported estimate)

  12. 2022

    Celsius Network

    НеплатёжеспособностьJune 2022

    The crypto lending platform froze all customer withdrawals during a market downturn and filed for bankruptcy weeks later. Its founder was subsequently charged with, and later pleaded guilty to, fraud for misrepresenting the platform's risk to depositors.

    Урок — A platform paying yield on deposits is taking risk with your money somewhere. 'Where' and 'how much' are the questions a safety review has to ask before the good times end.

    Withdrawals frozen for roughly $4.7B in customer assets (publicly reported estimate)

  13. 2022

    Crypto.com

    ВзломJanuary 2022

    20 января 2022 года с 483 клиентских счетов Crypto.com было выведено около 34 млн долларов в биткоине, эфире и других активах. Выводы прошли без надлежащей проверки второго фактора. Компания приостановила вывод средств, перестроила механизм аутентификации и возместила потери всем пострадавшим.

    Урок — Двухфакторная защита работает лишь там, где площадка действительно её проверяет. Механизм здесь был — денег стоила именно дыра в его применении на пути вывода средств.

    ~$34M withdrawn from 483 accounts (publicly reported estimate)

  14. 2022

    FTX

    МошенничествоNovember 2022

    One of the largest exchanges globally collapsed within days after reporting revealed customer deposits had been comingled with, and lent to, a sister trading firm. Its founder was later convicted on multiple counts of fraud.

    Урок — Scale, celebrity endorsements and slick branding say nothing about whether customer funds are actually segregated from the company's own trading book.

    Billions of dollars in customer funds misused (publicly reported estimate)

  15. 2022

    Ronin Bridge

    ВзломMarch 2022

    Мост Ronin, соединявший сайдчейн игры Axie Infinity с Ethereum, был опустошён в марте 2022 года после того, как злоумышленники получили контроль над большинством небольшого набора валидаторов, чьи подписи разрешали вывод. В контракте ничего не ломали: выводы были корректно подписаны ключами, которым система доверяла. Потерю обнаружили лишь несколько дней спустя, когда пользователь пожаловался, что не может вывести средства. Позднее власти США приписали кражу связанной с КНДР группе Lazarus.

    Урок — Мост децентрализован ровно настолько, насколько децентрализован его набор подписантов. Если вывод санкционирует горстка ключей, то компрометация этих ключей и есть вся атака, — а когда за балансом никто не следит, пропажу денег могут не замечать днями.

    ~$600M in ETH and USDC (publicly reported estimate)

  16. 2022

    Terra / LUNA

    НеплатёжеспособностьMay 2022

    TerraUSD был алгоритмическим стейблкоином, удерживавшим привязку к доллару не резервами, а связью выпуска и сжигания с LUNA — собственным волатильным токеном сети: UST дешевле доллара всегда можно было обменять на доллар вновь созданной LUNA. В мае 2022 года привязка поплыла, и механизм сработал в обратную сторону: чтобы её восстановить, приходилось выпускать всё больше LUNA, что обрушило её цену и уничтожило ту самую стоимость, на которой держалась привязка. Оба актива рухнули за несколько дней, а Terraform Labs и её основатель позже стали фигурантами уголовных и гражданских дел в США и Южной Корее.

    Урок — Привязка, обеспеченная токеном, который выпускает та же система, замкнута сама на себя. Она держится, пока держится доверие, и не оставляет опоры, когда доверие уходит, — то есть ровно в тот момент, когда стейблкоин и должен быть полезен. Высокая обещанная доходность по стейблкоину описывает этот риск, а не является преимуществом.

    UST and LUNA lost effectively all of their value

  17. 2022

    Three Arrows Capital

    НеплатёжеспособностьJune 2022

    Three Arrows Capital был хедж-фондом из Сингапура, ставшим одним из крупнейших заёмщиков в крипте: он финансировал позиции с плечом за счёт займов у централизованных кредитных площадок. Фонд держал значительную позицию в экосистеме Terra, которая в мае 2022 года потеряла практически всю стоимость, и был экспонирован к другим сделкам, шедшим против него по мере падения цен. Когда в июне 2022 года кредиторы выставили маржин-коллы, фонд не смог их исполнить. В конце того же месяца суд Британских Виргинских островов вынес решение о ликвидации, а вскоре ликвидаторы обратились за признанием процедуры в США. Дефолт не остановился на самом фонде: несколько кредитных платформ, выдававших ему займы, раскрыли убытки, и часть из них впоследствии сама вошла в процедуру банкротства. Позже регулятор Сингапура вынес запретительные предписания в отношении основателей фонда.

    Урок — Эффект домино в крипте не мистика, а кредитная цепь. Площадка, предлагающая вам доходность, кому-то отдаёт ваш депозит в долг, и концентрация её кредитного портфеля — это и есть риск, который вы на самом деле берёте. Портфель почти никогда не публикуется, поэтому к любому доходному продукту стоит задавать вопрос: кто заёмщик и что произойдёт с вашими деньгами, если он объявит дефолт.

    Creditor claims of roughly $3.5B in the liquidation (publicly reported estimate)

  18. 2022

    Wormhole

    ВзломFebruary 2022

    Мост Wormhole, выпускающий обёрнутые активы в нескольких сетях, в феврале 2022 года потерял около 120 000 обёрнутых эфиров: атакующий использовал изъян в том, как контракт на стороне Solana проверял подписи «стражей», разрешающие чеканку. Он смог сформировать выпуск, который контракт принял без соответствующего депозита в Ethereum, и обёрнутые токены остались без полного обеспечения. Компания Jump Crypto, стоявшая за проектом, возместила недостающий эфир, поэтому держатели обёрнутого актива не пострадали.

    Урок — Обёрнутый токен — это утверждение, что где-то лежит обеспечение. Когда проверка, скрепляющая эту связь, ломается, токен продолжает обращаться и выглядит нормальным, хотя обеспечения за ним уже нет, — а возместят ли потери, зависит от того, найдётся ли тот, кто закроет дыру собственным балансом.

    ~120,000 wrapped ETH (publicly reported estimate)

  19. 2023

    HTX (formerly Huobi)

    ВзломSeptember 2023

    24 сентября 2023 года из одного горячего кошелька HTX было выведено около 5000 ETH — примерно 8 млн долларов. Биржа установила личность атакующего, договорилась о возврате 95% средств и выплатила оставшиеся 5% как премию «белому» хакеру. Балансы клиентов были покрыты полностью.

    Урок — Договориться о возврате удалось потому, что сумма была небольшой, а след — публичным. Это исход, а не мера защиты: никакая биржа не пообещает, что следующий атакующий согласится на сделку.

    ~5,000 ETH (~$8M) taken from a hot wallet (publicly reported estimate)

  20. 2024

    DMM Bitcoin

    ВзломMay 2024

    31 мая 2024 года DMM Bitcoin, японская биржа, зарегистрированная в Агентстве финансовых услуг, сообщила о несанкционированном выводе 4502,9 BTC — на тот момент около 300 млн долларов и одна из крупнейших краж в истории страны. Компания заявила, что приобретёт эквивалентное количество биткоина при поддержке группы DMM, чтобы средства клиентов были покрыты полностью, а японское FSA выдало предписание об улучшении деятельности. В декабре 2024 года ведомства США и Японии публично связали кражу с субъектами, связанными с Северной Кореей, и DMM объявила о прекращении криптобизнеса с передачей клиентских счетов в SBI VC Trade.

    Урок — Регистрация и платёжеспособный материнский холдинг определили, чем это кончилось, а не то, случится ли это вообще. Японский режим — один из строжайших в мире, и монеты всё равно ушли; правила и баланс группы купили лишь то, что клиентам вернули деньги, а не поставили их в очередь кредиторов. Читайте лицензию как утверждение о том, кто поглотит убыток, но никогда как обещание, что убытка не будет, — и заметьте, что сама биржа возмещения не пережила.

    4,502.9 BTC (~$300m at the time, company-reported)

  21. 2025

    Bybit

    ВзломFebruary 2025

    21 февраля 2025 года злоумышленники вывели из холодного кошелька Bybit около 1,46 млрд долларов в эфире и стейкнутом эфире, подменив то, что видели подписанты в интерфейсе мультиподписи Safe: законные держатели ключей одобрили перевод, который выглядел совсем не тем, чем был. ФБР приписало атаку северокорейской группе Lazarus.

    Урок — Ключи не крали — солгал экран подтверждения. Холодное хранение и мультиподпись помогают лишь тогда, когда каждый подписант может проверить содержание операции независимо от этого экрана.

    ~$1.46B in ETH and staked ETH (publicly reported estimate)