Exchange Security Checklist 2026

An empty gold-outlined shield stands before three concentric gold arcs on a black background

A structured framework for evaluating any crypto exchange before you send money — covering Proof of Reserves, custody design, regulatory licensing, withdrawal controls, and the operational signals that formal compliance alone cannot capture.

Why This Checklist Exists

Would you hand £10,000 to a stranger without checking their credentials first? That is close to what an unexamined deposit amounts to, and the three collapses documented later on this page put billions of dollars of customer money into insolvency processes, two of which are still running. Industry-wide loss totals circulate freely and almost none of them are traceable to a filing, so the figures in those three case studies come from court filings, trustee notices and regulators rather than from any of those totals. You can avoid the same mistake by running five structured checks before your first deposit, whether you plan to trade tokens, stake assets, or simply hold Bitcoin.

Consider the track record you should know about. Mt. Gox disclosed 850,000 BTC missing when it collapsed in 2014, of which roughly 200,000 were later recovered from an old wallet, leaving a permanent shortfall near 650,000 BTC — tens of billions of dollars at today's prices. QuadrigaCX locked C$250 million behind a dead founder's passwords — your funds would have been permanently inaccessible. FTX commingled $8 billion in customer deposits with a sister trading firm — your money funded someone else's trades. Each failure had warning signs you could have spotted months or years in advance. You simply had no structured way to look for them.

This page gives you that structure. You will learn four concrete checks you can run on any centralised exchange in under an hour, plus a fifth bonus check. Here is what you will verify: does your exchange demonstrably hold what it claims (Proof of Reserves)? How are your funds stored and who controls the keys (custody architecture)? Which jurisdictions can hold your exchange accountable (regulatory licensing)? What account-level protections can you enable (withdrawal controls)? How does your exchange behave when things go wrong (operational signals)?

You should keep two caveats in mind before you begin. First, passing all five checks does not make your exchange safe — it makes it safer than one that fails them. You should treat this framework as a risk reducer, not a risk eliminator. Second, if you have already chosen an exchange and want the full onboarding plan, you should start with our first 30 days on a crypto exchange guide instead. This page is Day 0 — the due diligence you should complete before registration, not after.

Each check below explains what you should look for, how you can verify it independently, which exchanges currently meet our standards, and which red flags should make you reconsider depositing. The three case studies at the end show you what happens when these checks are skipped — with real losses, real timelines, and recoveries measured in years rather than weeks.

Check 1: Proof of Reserves

What Proof of Reserves Actually Proves

How do you know your exchange actually holds your crypto? Proof of Reserves (PoR) is a cryptographic attestation that answers this question for you. You can think of it as a balance sheet audit — your exchange proves it controls at least as many assets as it owes to you and every other customer.

How does this work technically? Your exchange uses a Merkle tree — a data structure built on the same blockchain cryptography that secures cryptocurrency transactions — to let you verify your own balance is included in the total without revealing anyone else's. You can check this yourself on exchanges that provide verification tools. Your exchange publishes its total customer liabilities and then proves, via on-chain wallet addresses and third-party attestation, that it controls at least that amount in your assets — including every token, staking position, and stablecoin balance.

Where did this start? Kraken conducted the first cryptographic PoR audit in March 2014, completed by auditor Stefan Thomas. You should know that since then, PoR has become an industry expectation — but implementation quality varies enormously, so you must evaluate each exchange's approach individually.

What You Should Check in a PoR Report

Not all PoR reports are equal. When you evaluate an exchange's attestation, you should look for these specific elements:

  • Snapshot frequency: Is the report a one-time snapshot or published on a regular schedule? You should prefer monthly reports (such as OKX) over periodic ones. A single snapshot proves solvency at one moment but tells you nothing about the days between reports.
  • Auditor independence: Was your exchange's attestation conducted by an independent third-party auditor, or is it self-attested? You should treat self-attested PoR with significant scepticism — it is like grading your own exam.
  • Asset coverage: Does your report cover only BTC and ETH, or your full range of deposited assets including stablecoins? You should be concerned if the PoR proves BTC reserves while ignoring your USDT liabilities.
  • Liabilities side: Does your exchange's report include customer liabilities, or only asset proof? For example, showing that an exchange controls 100,000 BTC is meaningless without proving that customers are owed less than 100,000 BTC. You must check for this — it is the critical distinction that FTX exploited before its November 2022 collapse.
  • User verification: Can you independently verify that your own balance is included in the Merkle tree? You should test this — OKX and Kraken provide tools that let you check your inclusion proof directly.

How the Major Exchanges Publish Reserves

How do your options compare? Kraken ran the world's first cryptographic PoR audit in 2014 and has published audited reserve reports on a regular cycle since 2022, with tools that let you verify your own balance is included in the total. Binance launched its PoR system in late 2022 and publishes attestations covering BTC, ETH, USDT, and other major assets. A published cadence is a habit rather than a commitment, so read the date printed on the report in front of you: a page that lists reserves reports is not evidence that the most recent one is recent.

OKX publishes monthly PoR reports with Merkle tree verification that you can check yourself. Backing ratios move from report to report, so the figure that matters is the one in the current report rather than any number quoted on a page like this one — check it directly on OKX's Proof of Reserves page before you deposit.

Coinbase takes a different approach — as a publicly traded company on NASDAQ, you can read its Deloitte-audited annual filings and 10-K reports with the SEC rather than relying on cryptographic attestation.

What PoR Cannot Tell You

Here is the critical limitation you must understand. PoR proves that your cryptocurrency assets exist on-chain at a specific moment, but it cannot tell you whether those assets are pledged as collateral elsewhere, lent to a sister company, or locked in DeFi smart contracts with governance obligations. This is exactly how FTX maintained an appearance of solvency — your deposits sat in wallets FTX controlled, but they were simultaneously committed to cover Alameda Research's trading losses and token positions.

This limitation is why you should treat PoR as necessary but not sufficient. If an exchange refuses to publish any form of PoR, you should consider that a strong red flag. But passing PoR alone does not mean your funds are safe. You need the remaining four checks to build a more complete picture of whether your chosen exchange can be trusted.

Check 2: Custody Architecture

Hot and Cold Storage Ratios

Where are your funds actually stored? Every exchange you use maintains hot wallets (connected to the internet for quick withdrawals) and cold wallets (offline, holding your funds securely). You should look for exchanges that keep the large majority of your assets in cold storage — holding only enough in hot wallets to service withdrawals.

Disclosure practice varies, and what you want to read is what each disclosure actually commits to. Kraken has cited roughly 95% cold storage. Coinbase publishes no current cold-storage percentage at all: what its 2025 annual report gives is a hot-wallet ceiling and an intention, stating that it uses both hot and cold wallets and "generally seek[s] to hold no more than 2% of assets under custody in hot wallets at any given time". Binance, Bybit and OKX describe a "vast majority" in cold storage without publishing a figure. Treat any specific ratio as a claim to verify rather than a guarantee — and remember that the ratio describes where your assets are kept, not who has undertaken to give them back.

Why should you care about this ratio? Because hot wallets are where your funds face the most risk. For example, the 2020 KuCoin hack cost approximately $285 million — KuCoin's own figure, from its chief executive's 2021 letter, covering 154 tokens at the market price of the day — and your funds would have been exposed only if they sat in the internet-connected hot wallet portion. KuCoin recovered 84% of the stolen funds with the help of other exchanges and law enforcement, and covered the rest from its own funds and its insurance fund. If you see your exchange quoting a lower ratio — or declining to disclose the split — you should investigate further before depositing.

Key Management: MPC, Multisig, and Single-Key

How does your exchange manage the private keys that control your cryptocurrency funds? This is as important as where your funds are stored — whether you hold Bitcoin, Ethereum staking positions, DeFi tokens, or NFT assets. You should understand three architectures:

  • Multi-signature (multisig): Your transaction must be authorised by multiple distinct private keys — for example, 3 out of 5 keys held by different people. You should prefer this approach because no single person can move your funds alone, and it is the most battle-tested architecture natively supported on Bitcoin and Ethereum.
  • Multi-party computation (MPC): Your private key is split into encrypted shares across multiple parties, and the shares combine mathematically during signing without ever reconstructing the full key in one place. You should know that MPC can work across more blockchains than multisig, but it is a newer technology with less independent security research behind it.
  • Single-key: One private key controls all your funds — if that key is compromised or lost, you lose everything. You must avoid any exchange still using single-key custody because this is the architecture that caused the Mt. Gox (2014) and QuadrigaCX (2019) disasters.

Third-Party Custody Providers

Some exchanges outsource your cold storage to specialised custody firms like Fireblocks, BitGo, or Copper. Why should this matter to you? Because third-party custody means your exchange cannot unilaterally move your funds — the custody provider must co-sign every transaction from its vaults. You benefit from this separation because it prevents the kind of internal fraud where a rogue executive redirects your deposits.

How can you verify this? First, you should check whether your exchange publicly names its custody provider. Then you should check whether that provider publishes a SOC 2 Type II audit report. What is SOC 2 Type II? You can think of it as an auditing framework that evaluates your provider's security, availability, and privacy controls over a sustained period of 6-12 months — not just at one point in time. If your exchange holds this certification, you can be more confident that your security controls function reliably.

Insurance Coverage

What happens if your exchange's security fails despite good custody? You will meet two different things called insurance here, and only one of them is: a commercial policy underwritten by an insurer, and an operator-funded reserve. Binance's SAFU is the second kind. Binance's SAFU FAQ, updated on 2 February 2026, says that as of February 2026 the fund "holds crypto assets valued at approximately US$1 billion". If its market value falls below US$800 million on Bitcoin price moves, Binance "will rebalance the fund to restore its value to US$1 billion". The same document reserves Binance "full discretion to determine what types of loss and which claims are eligible for recovery". It has drawn on the fund before: after the May 2019 breach Binance said it would use SAFU to cover that incident in full, which is the reason the fund has a reputation at all.

That discretion is the entire distinction. Our guide to what is actually backed, and by whom works through why a fund and a policy behave differently at the moment either is tested; what you need from this page is the habit of asking which of the two you are being shown.

Try to check Coinbase's cover and you find how little of this is normally public. It says it holds a commercial crime policy protecting "a portion" of the digital assets across its storage systems; it names no insurer and publishes no limit, and its 2025 annual report adds that the policy runs one year at a time with no automatic renewal, and that customer assets on the platform are "substantially more than our corporate assets and available insurance". The figure quoted elsewhere reaches you through the funds that use Coinbase as a custodian rather than through Coinbase itself: the iShares Ethereum Trust ETF's Form 10-Q for the quarter ended 30 June 2025 records a Coinbase crime policy of up to $320 million, shared across every customer of Coinbase and its subsidiaries rather than reserved for any one of them, and not every such filing repeats the figure.

Whenever you meet a coverage claim, three things are being run together: the broker who arranges the cover, the insurer who carries the risk, and the market that insurer trades in. If the platform names none of the three, you are being shown a category, not a contract. OKX, separately, operates a Security Fund, or Risk Shield, as a backstop — though OKX itself states this is not an insurance policy or a guarantee against user losses, so you should not treat it as one.

Should you rely on insurance alone? No — it is a last resort rather than a substitute for good custody, and the platforms say so themselves in the pages nobody reads. Coinbase's help centre says it will endeavour to make customers whole after a security event covered by its crime policies, and then immediately adds that "total losses may exceed insurance recoveries so your funds may still be lost". That is the honest shape of crime cover: it is sized to what an insurer will write, not to the balances of everyone who deposited. Check whether your exchange has cover, read what the cover excludes, and do not let its existence be your reason to skip the other four checks.

Custody Red Flags You Should Watch For

  • Your exchange refuses to disclose its hot/cold storage ratio or key management architecture
  • You cannot find a named custody provider or auditor for cold storage
  • You see "trust us" messaging without verifiable technical detail
  • You can identify single-key wallets controlling large balances through on-chain analysis
  • Your exchange discloses no insurance fund or commercial insurance policy

Check 3: Regulatory Licensing

The Regulatory Landscape in 2026

What does "regulated" actually mean for your exchange? The answer depends entirely on the jurisdiction. Some regulatory regimes impose genuine oversight with real consequences for non-compliance. Others offer a licence that amounts to little more than a registration fee. You should understand the difference before trusting any regulatory claim:

  • United States: You can check for FinCEN MSB registration at the federal level, state money transmitter licences, and the New York BitLicense — the most demanding state-level crypto licence you will find globally.
  • European Union: MiCA became fully applicable on 30 December 2024, so you can now verify whether your exchange holds a unified EU licence. MiCA requires capital reserves, client asset segregation, and ongoing compliance reporting — all of which should protect you as a depositor.
  • United Kingdom: You should check the FCA register for cryptoasset firm registration. This covers AML/KYC compliance but does not impose the same capital adequacy requirements as MiCA — so your protection is narrower.
  • Dubai (UAE): VARA grants licences for exchange operations that you can verify on the public register at vara.ae before you deposit.
  • Singapore: MAS regulates crypto services under the Payment Services Act, so you should verify your exchange's MAS registration directly before committing your funds.
  • Japan: The FSA requires exchange registration — one of the earliest national licensing regimes, established after the Mt. Gox collapse specifically to protect customers like you.

Where Can You Verify Major Exchange Licences?

You should check your specific exchange's licences before depositing any of your funds. You can verify that Binance holds a full VARA licence in Dubai (VL/24/04/001, upgraded from MVP in April 2024) and an Abu Dhabi ADGM (FSRA) approval that went operational in January 2026.

Binance's French AMF (DASP) registration lapsed with France's transitional regime on 1 July 2026, and it holds no MiCA authorisation: it withdrew its Greek application and intends to file in another Member State. It announced it would stop onboarding new EU/EEA customers from that date, but enforcement has lagged — treat it as an unlicensed venue you may still be able to join, not a closed door. Check its supported-countries page for your location first.

Kraken should give you the most confidence on regulatory breadth if you value multi-jurisdictional oversight. You can verify its FinCEN MSB registration (US), FCA registration (UK), MiCA authorisation (EU, via Ireland), FINTRAC registration (Canada), AUSTRAC registration (Australia), and VARA licence (Dubai, UAE). You should recognise that this breadth across six demanding jurisdictions is a strong trust signal you can verify independently.

What about OKX and Coinbase? You can verify that OKX operates licensed entities in Malta, Japan, Singapore, and the UAE — each one checkable on the relevant regulator's register. Coinbase is the largest publicly traded exchange on NASDAQ (ticker: COIN) — since Gemini's September 2025 listing it is no longer the only one — which means you can read its Deloitte-audited annual filings and SEC reports yourself, a level of financial transparency that should give you more confidence than any privately held exchange can offer.

How to Independently Verify a Licence

You should never rely on what the exchange claims on its own website. Every major regulator maintains a public register where you can verify whether a specific entity holds a valid, current licence:

  • UK FCA: You can search the Financial Services Register at register.fca.org.uk
  • US FinCEN: You can search the MSB Registrant Search at fincen.gov
  • EU/MiCA: You should check the national competent authority — for example, AMF in France or BaFin in Germany
  • Dubai VARA: You can search the public register at vara.ae
  • Singapore MAS: You should check the Financial Institutions Directory at mas.gov.sg

One important detail you must remember: search for your exchange's legal entity name, not its brand name. For example, you should search for the specific licensed entity — such as Binance FZE (Dubai), which appears on the VARA register — rather than just "Binance." If you cannot find the legal entity on the regulator's register, you should investigate further before depositing your funds — the licence claim may be false or your exchange may operate under a name you do not recognise.

What "Regulated" Does Not Guarantee

Can you trust a regulated exchange unconditionally? No — and you should understand why. FTX Trading Ltd, the Bahamas-based international exchange, held a licence from the Bahamas Securities Commission, while a separate US entity behind FTX US carried the FinCEN registration — yet the Bahamas-based exchange lost $8 billion in customer funds that could have been yours. You should note that the Bahamian licence came from a small jurisdiction with limited supervisory capacity, so you must weight the quality of the jurisdiction as heavily as the existence of the licence itself.

What should you prioritise when checking your exchange's licences? You should look for an FCA registration or a MiCA licence because these impose ongoing capital requirements, regular audits, and real enforcement consequences that protect you. You should be wary of offshore licences with minimal supervisory infrastructure — these provide legal cover for your exchange, not meaningful protection for your funds. If your exchange is licensed only in jurisdictions without serious banking oversight, you should treat that as a yellow flag at minimum.

Check 4: Withdrawal Controls

Withdrawal Address Whitelisting

What happens if someone gains access to your exchange account? With withdrawal whitelisting enabled, they still cannot steal your funds — because they can only send to addresses you have pre-approved. You should enable this feature immediately after creating your account. None of these controls is switched on for you, and each exchange sets its own waiting period on a newly added address. Coinbase's help article "Add an allowlist address", read on 23 August 2026, says an address "becomes available for sends after 48 hours". Turning allowlisting back off takes 48 hours too, unless you do it within eight hours of activating it.

Binance leaves the period to you: its withdrawal-settings article, last updated 3 March 2025, describes a whitelist withdrawal limit that suspends withdrawals to newly added addresses for 24, 48 or 72 hours. OKX publishes the same idea as a separate advanced setting — its allowlist help article, updated 14 August 2026, says the new address withdrawal lock prevents withdrawals to new allowlist addresses for 24 hours.

How should you set this up? All three file it inside the withdrawal flow rather than the security menu, and each names it differently. On Binance, hover over the profile icon, open Settings, scroll to the Withdrawal section and press Enable next to Withdrawal Whitelist; the same section holds Address Management and the whitelist withdrawal limit. On OKX, go to Assets, then Withdraw, pick the coin and the on-chain route, and the setting sits inside the address book — OKX calls it an allowlist rather than a whitelist, which matters when you are searching their help pages, and Coinbase now uses that word too.

Kraken has the equivalent as well: its own guide to adding a withdrawal address, last updated 4 March 2026, requires you to add and confirm every address before you can send to it, by a link emailed to you unless you are on a device Kraken already trusts.

Why does Kraken's approach deserve your attention? On top of that address list sits the Global Settings Lock — Settings, then Security, then Advanced Settings — which freezes your entire account configuration behind a waiting period you choose. Kraken's help pages, read on 23 August 2026, put the default wait at three days, or 72 hours. An unlock without a Master Key takes a minimum of 24 hours and can be set as long as 30 days, and Kraken warns that its support team cannot expedite it. While the lock is active you cannot add a withdrawal address at all, and Kraken emails you on any attempted unlock — which is what turns the delay into a warning rather than an inconvenience.

Which 2FA Method Should You Use?

Not all 2FA methods protect your account equally. Here is the hierarchy you should follow from weakest to strongest, so you can choose the best option for your situation:

  • SMS (weakest): You should avoid SMS 2FA if possible. SIM-swap attacks — where an attacker convinces your mobile provider to transfer your number to their SIM card — can intercept all your SMS verification codes. SIM swaps have been used to steal millions from individual crypto holders — you must avoid this method.
  • TOTP authenticator apps (strong): A TOTP app is the minimum standard, and the category matters more than the brand. These apps generate codes locally on your device, so they cannot be intercepted remotely. Named recommendations age badly — Twilio shut down the Authy desktop applications in August 2024 and logged those users out — so pick an app your exchange supports, that lets you export your seeds, and that is still actively maintained on the day you set it up. If you lose your phone, you will need the backup codes you recorded during setup, so write those down and store them securely.
  • Hardware security keys (strongest): You should consider a YubiKey or Google Titan key for maximum protection. These use the FIDO2/U2F protocol, which verifies the domain cryptographically to protect you from phishing. Even if you visit a perfect phishing replica, your hardware key refuses to authenticate because the domain does not match. You can use hardware keys on Kraken, Binance, Coinbase, and OKX.

How to Secure Your API Keys and Sub-Accounts

Do you use trading bots or portfolio trackers that connect via API? Then you must verify that your API key has the minimum necessary permissions. Your portfolio tracker should have read-only access only. Your trading bot should have trade permission but nothing more. You should never grant withdrawal permission to either — doing so creates an unnecessary attack surface that could cost you your entire balance if the API key is compromised.

You should also consider sub-account isolation if you trade actively. Sub-accounts on Binance and OKX let you separate funds into independent accounts with their own API keys. If one key is compromised, only that sub-account is exposed — your main account stays safe.

The Best Withdrawal Control: Self-Custody

Every control discussed above operates within your exchange's infrastructure — and ultimately depends on the exchange functioning honestly. What is the strongest withdrawal control you can implement? Move your cryptocurrency to a wallet where you hold the private keys directly. A hardware wallet removes the exchange from the equation entirely — your tokens sit on the blockchain, controlled by a key that only you possess, immune to exchange insolvency or governance failures.

You should also consider gas fee costs when planning your withdrawal strategy — moving assets from your exchange to a personal wallet costs you a blockchain transaction fee that varies by network congestion and the token you are transferring. You can learn how to select and configure a hardware wallet in our hardware wallet security guide, which compares Ledger, Trezor, Keystone, and Tangem architectures. Our recommendation: you should keep only the amount you are actively trading on an exchange, and move everything above £1,000 to cold storage.

Withdrawal Control Red Flags

  • You cannot find a withdrawal whitelisting feature on your exchange
  • Your exchange offers SMS-only 2FA with no TOTP or hardware key support
  • You see no API permission granularity — it is all-or-nothing access
  • Your exchange has no cooldown period on new withdrawal address activation
  • You experience unexplained withdrawal delays or sudden limit reductions

Check 5 (Bonus): Operational Security Signals

Why You Need More Than Four Checks

Why should you bother with a fifth check? Because FTX passed the first four formally — it published reserve information, it held regulatory licences, and it offered you withdrawal whitelisting and 2FA. Yet your funds were still at risk because the fraud operated behind these compliant surfaces. You could only detect it through operational behaviour that no compliance checkbox can capture. This fifth check exists because FTX demonstrated that formal compliance alone cannot protect your deposits.

How to Read Incident Response History

How does your exchange respond when something goes wrong? This question should matter more to you than any marketing page. You should compare two contrasting examples to understand what good and bad responses look like for your protection.

In September 2020, KuCoin suffered a hot-wallet breach. The $285 million figure is KuCoin's own, from an open letter its CEO published on 3 February 2021. Chainalysis attributed the attack to North Korea’s Lazarus Group, citing a money-laundering pattern the group had used before, and put the total closer to $275 million. KuCoin itself has never named an attacker.

What did KuCoin do for its customers? They immediately froze deposits and withdrawals to protect your remaining funds, transferred assets to new wallets, and coordinated with other exchanges to freeze stolen cryptocurrency. You can read their detailed post-mortems published throughout the recovery process. KuCoin's own account of the recovery, in a letter from its chief executive published in 2021, splits it three ways: $222 million (78%) recovered with exchange and project partners, $17.45 million (6%) with law enforcement, and the remaining $45.55 million (16%) covered by KuCoin and its insurance fund — so you would not have lost any money as a KuCoin customer.

Now contrast this with how Mt. Gox treated you as a customer. They experienced ongoing thefts from 2011 through early 2014 without telling you about any of them. When the scale of the loss became undeniable in February 2014 — the figure disclosed at the time was 850,000 BTC, and the 200,000 found in an old wallet did not surface until the following month — the exchange simply went offline, giving you no proactive communication, no recovery coordination, and no protection for your funds. Can you see the difference? You should look for exchanges that respond the way KuCoin did in 2020 and avoid those that respond like Mt. Gox.

Note the caveat on that first example: KuCoin pleaded guilty to a US federal charge in January 2025 and left the US market, and a March 2026 CFTC consent order bars US participants unless it registers as a foreign board of trade — so what carries over here is the response pattern rather than the venue.

A third case belongs beside those two, and it should change how you read a cold-storage claim. The FBI attributed the theft of approximately $1.5 billion in virtual assets from Bybit, on or about 21 February 2025, to North Korea. Your funds would not have been in the hot wallet where Check 2 teaches you to expect a loss. The money left a cold multisig wallet, because the people holding the keys approved a transaction whose real contents the signing interface in front of them had misrepresented — our multisig failure-mode case study sets out how the substitution was achieved. The lesson for this check is that a cold wallet moves the attack from the wallet to the signing process, so an exchange that quotes you a cold-storage percentage and cannot describe how its signers verify what they are approving has answered a question you did not ask.

Transparency Indicators You Can Verify

  • Public post-mortems: After any incident, does your exchange publish a detailed timeline and remediation plan? You should be able to find these on their blog.
  • Bug bounty programmes: Can you find active programmes on HackerOne with published payout records? This tells you the exchange invests in proactive security testing rather than reactive crisis management.
  • External audit frequency: Does your exchange conduct SOC 2 Type II audits annually and penetration testing quarterly? You should be able to find summaries of these results.
  • Engineering transparency: Does your exchange maintain a public engineering blog or contribute to open-source projects? For example, Coinbase and Kraken contribute to blockchain node software, and Binance maintains open-source libraries.
  • Team visibility: Can you find the CEO and senior leadership with verifiable professional histories? Do they give interviews and speak at conferences where you can assess their credibility?

Operational Red Flags You Must Not Ignore

  • You cannot identify the founding team — no LinkedIn profiles, no conference appearances, no verifiable history. This should concern you because it was a primary warning sign for QuadrigaCX.
  • You find no public record of any security incidents — this is suspiciously clean. Every exchange that has operated for more than two years has faced attack attempts.
  • You read claims of "we are the safest exchange" without published audits, PoR reports, or named custody providers. You should demand evidence, not assertions.

What Happens When Checks Fail: Three Case Studies

Three identical outlined gold vessels, each leaking from one hairline crack at a different height
Three collapses, three different points of failure — which is why one check passed is never the same thing as an exchange being safe.

Mt. Gox (2011-2014): The Original Exchange Collapse

Imagine you had deposited your Bitcoin on the exchange that processed over 70% of all BTC transactions worldwide. That was Mt. Gox — and on 7 February 2014, it halted all withdrawals. Your funds were gone. This was the first demonstration that an exchange could simply vanish along with your money.

What went wrong with your funds? Court documents revealed that attackers systematically siphoned BTC from Mt. Gox hot wallets beginning as early as September 2011. For example, the first breach in June 2011 saw 25,000 BTC stolen from 478 accounts. You should note that Mt. Gox had no Proof of Reserves, no multisig custody, and relied on single-key architecture for your cold storage. If you had checked for these signals, you would have found none of them present.

On 24 February 2014, you would have seen the website go offline. On 28 February, your exchange filed for bankruptcy. Your loss disclosure reported 850,000 BTC missing — though 200,000 BTC were later discovered in a forgotten wallet, reducing your permanent loss to approximately 650,000 BTC — still worth tens of billions of dollars at today's prices.

How long did recovery take? You would have waited over a decade, and the wait is not over. The first BTC repayments to creditors began in July 2024 — more than ten years after the collapse. By March 2025, approximately 19,500 creditors had received partial repayments. The trustee's repayment deadline has been pushed back more than once; when this page was last reviewed, in August 2026, it stood at 31 October 2026, and the only version of that date worth acting on is the one on the trustee's current notice. If you had deposited on Mt. Gox, you would likely never recover the full value of your original deposit.

What would our framework have caught? Check 1 (no PoR) and Check 2 (single-key custody). If you had run these two checks in 2012, you could have discovered the discrepancy between reported balances and actual reserves years before the collapse.

QuadrigaCX (2019): Single Point of Human Failure

QuadrigaCX was Canada's largest crypto exchange when its founder, Gerald Cotten, died on 9 December 2018 in Jaipur, India. Here is why that destroyed your funds if you were a depositor: Cotten was the sole custodian of all cold wallet private keys. When he died, your keys died with him — and C$250 million (approximately US$190 million) in customer funds became permanently inaccessible.

But the Ontario Securities Commission's investigation revealed something worse for you. QuadrigaCX had been operating as what the OSC called "effectively a Ponzi scheme." You should understand what this means: Cotten had created fake accounts, credited them with fictitious balances, and traded against real customers with phantom funds. Ernst & Young identified a C$169 million asset shortfall from Cotten's fraud — your losses existed before his death.

What did you recover? Ernst & Young's May 2023 dividend was interim: 13.094% of proven claims, approximately C$39.5 million to 17,648 creditors. The trustee reserved the remaining funds for later distribution.

What would our framework have caught? Check 2 (single-person custody — no multisig, no third-party custodian) and Check 5 (Cotten was the sole technical operator with no named team). If you had asked "who else can access the keys?" the single-person dependency would have been an obvious existential risk.

FTX (November 2022): When Formal Compliance Masks Fraud

FTX was the third-largest crypto exchange by volume. If you had deposited there, you would have felt safe — the brand sponsored the Miami Heat arena, Major League Baseball, and Formula 1 teams. Sam Bankman-Fried testified before the US Senate. Everything projected compliance and transparency.

What was actually happening with your funds? FTX was funnelling your deposits to Alameda Research — a trading firm also controlled by Bankman-Fried. Your shortfall reached approximately $8 billion. On 2 November 2023, you would have learnt that a jury found Bankman-Fried guilty on all seven counts. On 28 March 2024, he was sentenced to 25 years in prison and ordered to forfeit $11 billion.

How much did you recover if you were a creditor? The bankruptcy estate recovered between $14.7 billion and $16.5 billion through asset liquidation. Five distributions have been paid so far: the fourth, about $2.2 billion, in March 2026, and a fifth of approximately $900 million that the FTX Recovery Trust announced on 17 July 2026 and began paying on 31 July 2026, taking the total returned to creditors close to $10 billion.

Smaller claims under $50,000 were repaid first, in the February 2025 distribution, at approximately 119% of claim value including interest; larger claims were repaid in stages. But you endured years of uncertainty, and your repayment came in fiat — meaning you missed the cryptocurrency appreciation you would have captured in your own wallet.

Why does this case matter most for your framework? Because FTX formally passed Checks 1, 3, and 4. It held licences. It offered you 2FA and withdrawal controls. What could you have spotted? The warning signs were operational: over 130 affiliated entities, no independent board, an unnamed engineering team, and a CEO who discouraged questions about internal controls. You had to know to look for them — which is exactly why you should run Check 5.

What would our framework have caught? Check 2 (commingled funds — no genuine asset segregation) and Check 5 (operational opacity). This is precisely why you should never stop at the first four checks.

Red Flags Quick-Scan Checklist

Before you run the full five-check framework, you can eliminate clearly problematic exchanges in under five minutes. Any single red flag does not necessarily condemn an exchange, but if you spot two or more in combination, you should pause before depositing:

  • You cannot find the legal entity name. If you search for the registered company name, jurisdiction of incorporation, and registered address and find nothing, your funds may have no legal protection in a dispute.
  • You see licences only from jurisdictions without banking oversight. A licence from a small island territory with no crypto-specific supervisory capacity protects the exchange, not you.
  • You find no Proof of Reserves. After the FTX collapse, you should treat refusal to publish reserve attestation as a strong negative signal. Self-attested reports without named auditors should also concern you.
  • You can only use SMS for two-factor authentication. If your exchange does not support TOTP or hardware security keys, its security infrastructure is years behind — and your account is exposed to SIM-swap attacks.
  • You cannot identify the CEO or founding team. No LinkedIn profiles, no conference appearances, no verifiable history? This should concern you — QuadrigaCX's minimal team visibility masked the absence of key management oversight.
  • You see "guaranteed yield" or "risk-free" marketing. No legitimate cryptocurrency exchange uses this language because it is legally indefensible. If your exchange's marketing promises what financial markets cannot deliver, you should assume the operation is either reckless or fraudulent.
  • You notice referral bonuses dominating over product marketing. When your exchange prioritises recruiting new depositors over improving its product, you should recognise the structural similarity to schemes that depend on capital inflow to survive.
  • You find no record of any security incidents. Every exchange that has operated for more than two years should have faced attack attempts. A perfectly clean record is more suspicious than a disclosed incident with a good response.
  • You see APY rates far above market. If your exchange offers 20% APY on a stablecoin when the rest of the market offers 3-8%, you should ask where that yield comes from. Legitimate staking rewards are constrained by consensus mechanism economics and validator returns — so your yield must come from somewhere, and that source is often unsustainable risk-taking with your funds through leveraged DeFi positions, dApp farming, or tokenomics that reward early depositors at the expense of later ones.

How We Apply This Framework to Our Partners

We do not recommend exchanges in the abstract — we evaluate every exchange referenced on this site against the same five checks described above, and the result decides the tier we give it. Here is what the classification records for each platform: whether it is regulated in a jurisdiction with real supervisory capacity, whether it publishes Proof of Reserves, whether any third-party insurance sits behind its custody, how long it has run without losing customer funds, whether it holds customer assets at all, and whether its full fee schedule is published. Those six signals resolve into three tiers:

  • Green tier: We classify an exchange as green when it performs strongly across the framework: regulated in at least one major jurisdiction, reserves you can verify (by cryptographic PoR or by audited public filings), a long track record without major customer losses, and fees published in full. Third-party insurance is one of the six signals; an operator-funded fund is not one of them at all, for the reason Check 2 gives.
  • Yellow tier: We use yellow when an exchange has at least one material concern that is partially offset by strength elsewhere. For example, a CeFi platform with custodial risk that is compensated by transparent fees and regulatory compliance.
  • Red tier: We classify exchanges as red when historical failures or critical signals disqualify them from promotion. Most red entries are platforms and funds that failed between 2014 and 2023: Mt. Gox, Celsius, BlockFi, Voyager, FTX, Genesis, Hodlnaut, CoinLoan, Zipmex, Vauld, Three Arrows Capital, Terra and Anchor Protocol. The rest are there for reasons other than a past collapse — a precaution against accidental re-addition, for instance, rather than a ruling that anything failed. None of them can reappear in our recommendations.

How do our current partners score? You can read the full analysis in each review. Kraken holds green tier — you can verify its licences in six jurisdictions, its PoR dating to 2014, and its 13-year breach-free record. Coinbase is green tier — you can read its SEC filings and Deloitte audits, and its US customers' dollar balances sit in pooled custodial accounts at insured banks. Coinbase describes that arrangement as giving it — not you — a claim against pass-through FDIC cover, up to the standard $250,000 limit per depositor, per insured bank. It covers dollars and not crypto, it depends on Coinbase's own record-keeping, and Coinbase states that it applies only to US-based customers of Coinbase, Inc.

Binance scores yellow — it publishes PoR, has transparent fees, and holds genuine licences including Dubai VARA and Abu Dhabi ADGM, but it announced an end to new EU/EEA business (Earn and staking included) from 1 July 2026 after withdrawing its Greek MiCA application, and it is not taking on new UK retail customers. Check whether it can legally serve you before depositing. OKX holds green tier with monthly PoR reports you can verify yourself, transparent fees, and licences in Malta, Japan, Singapore, and the UAE.

We evaluate every partner against these five checks, and our results drive our classification — not the other way around. This is why we do not maintain referral relationships with red-tier exchanges, and why we removed some exchanges that previously appeared on this site during our 2026 content audit when their risk profiles no longer met our minimum threshold for your safety.

CryptoInvesting Team Independent crypto research since 2023. We test every platform we review — no sponsored content, no ads.
Last verified:

From Checklist to Confident First Deposit

You now have a structured way to evaluate any centralised exchange before you commit your funds — whether you plan to trade cryptocurrency, stake tokens through validator delegation, earn mining rewards, or access DeFi through exchange-integrated dApps. The five checks will not guarantee your safety, but they will help you distinguish between exchanges that have invested in verifiable security infrastructure and those that rely on marketing claims you cannot substantiate.

What happens if you skip these checks? The three case studies show you the cost. Mt. Gox depositors waited over a decade for partial recovery. QuadrigaCX customers have recovered 13% so far. FTX creditors endured years of uncertainty and received fiat repayments that missed the crypto appreciation they would have captured in their own wallets. You can avoid these outcomes by spending one hour on due diligence before your first deposit.

Once your chosen exchange passes these checks, what should you do next? Register, complete KYC, and make your first trade. Our first 30 days on a crypto exchange guide walks you through Week 1 foundation setup through Week 4 security hardening — treating this security checklist as your Day 0.

And remember the most important lesson from all three case studies: you should not trust any exchange indefinitely with your long-term savings. For any amount above £1,000, your safest position is self-custody in a hardware wallet — where the only key holder is you.

Should you re-run these checks periodically? Yes — you should review your exchange against all five checks at least quarterly. Reserves reports appear on schedules that vary by exchange and can lapse without notice, regulatory status can change when an exchange gains or loses a licence, and operational signals like executive departures or withdrawal delays can appear at any time. Set a calendar reminder every three months and re-run the red flags quick-scan before making any large new deposit to protect your funds over the long term.

Sources and References

Frequently Asked Questions

Is Proof of Reserves enough to trust an exchange?
No. Proof of Reserves confirms that an exchange holds enough assets to cover customer balances at a specific point in time, but it does not reveal internal liabilities, off-balance-sheet obligations, or commingled funds. FTX passed a form of reserve attestation while secretly funnelling customer deposits to Alameda Research. PoR is one essential check, but it must be combined with custody architecture review, regulatory licensing verification, and operational transparency assessment before you can form a reasonable confidence picture.
What is the difference between MPC and multisig custody?
Multi-signature custody requires multiple distinct private keys (for example, 3 out of 5) to authorise a transaction. Multi-party computation splits a single private key into encrypted shares distributed across multiple parties, and the shares are combined mathematically during signing without reconstructing the full key. MPC works across blockchains that lack native multisig support, making it more flexible for enterprise custody — but it is a newer technology with a smaller body of independent security research than traditional multisig.
Does a regulated exchange guarantee that funds are safe?
No. Regulation reduces risk but does not eliminate it. FTX Trading Ltd, the Bahamas-based international exchange, held a licence from the Bahamas Securities Commission, while a separate US entity behind FTX US carried the FinCEN registration — yet the Bahamas-based exchange lost over $8 billion in customer funds. The quality of the regulatory jurisdiction matters: an FCA registration in the UK or a MiCA licence in the EU imposes stronger oversight than an offshore licence with minimal supervisory capacity. A licence means the exchange passed an initial compliance review and submits to ongoing scrutiny — not that your funds are guaranteed.
How often should an exchange be re-checked against this framework?
At least quarterly. Publication schedules differ from one exchange to the next and none of them is a commitment, so read the date printed on the latest reserves report instead of assuming a cadence. Regulatory status can change when an exchange gains or loses a licence. Operational signals — executive departures, withdrawal delays, sudden changes to terms of service — can appear at any time. Set a calendar reminder every three months and re-run the red flags quick-scan before making any large new deposit.
What two-factor authentication method is safest for exchange accounts?
Hardware security keys (YubiKey, Google Titan) provide the strongest protection because they require physical possession and verify the domain cryptographically — making them immune to both SIM swaps and phishing. TOTP authenticator apps are the next safest option; pick one your exchange supports that is still actively maintained, because named recommendations date quickly — Twilio shut down the Authy desktop applications in August 2024. SMS-based 2FA is the weakest because it is vulnerable to SIM-swap attacks where an attacker convinces your mobile provider to transfer your number to their SIM card.
If an exchange passes all five checks, is deposited money completely safe?
No. These five checks reduce your exposure to the most common and historically destructive failure modes, but they cannot protect against novel risks: a zero-day infrastructure exploit, a government asset seizure, or a fraud scheme that evades all public-facing indicators. The framework helps you make an informed decision, not a risk-free one. For holdings above £1,000, the safest approach is to keep only actively traded amounts on any exchange and withdraw the rest to a hardware wallet.
Should crypto be kept on an exchange or in a hardware wallet?
Both, for different purposes. Keep amounts you are actively trading or earning yield on in your exchange account — protected by 2FA, withdrawal whitelisting, and the security infrastructure described in this checklist. Move long-term holdings above £1,000 to a hardware wallet where you control the private keys directly. This split limits your exposure to exchange-specific risk (insolvency, hacks, regulatory freezes) while maintaining liquidity for active positions.

Back to Crypto Investing Blog Index

Financial Disclaimer

This content is not financial advice. All information provided is for educational purposes only. Cryptocurrency investments carry significant investment risk, and past performance does not guarantee future results. Always do your own research and consult a qualified financial advisor before making investment decisions.

Our Review Methodology

CryptoInvesting Team maintains funded accounts on every platform we review. Each review includes a full registration and KYC cycle, a real deposit and withdrawal test, and a hands-on evaluation of the trading or earning interface. Fee data, APY rates, and supported assets are verified against the platform directly — not sourced from aggregators. We re-check published figures quarterly and update pages when terms change. Referral partnerships never influence editorial ratings or recommendations.