How safe is Crypto.com,
really?
Instead of a vague 'trusted' badge, we grade Crypto.com on five concrete, checkable criteria — each with sources. Here's exactly how it scores.
Criterion by criterion, with sources
- ✓
Regulation
Broadly licensed — Singapore MAS (Major Payment Institution), EU MiCA via Malta MFSA (2025), UK FCA (EMI + cryptoasset registration), US FinCEN MSB with state money-transmitter licences, plus Canada FINTRAC and Australia AUSTRAC. Source 1 → Source 2 →
- ✗
Proof-of-Reserves
A Merkle-tree reserves portal exists, but the last independent attestation (Mazars, 101–106% coverage) was December 2022; Mazars then exited crypto and no current independent auditor has been named. Source 1 → Source 2 →
- ✓
Flexible withdrawal
Flexible-term Crypto Earn can be withdrawn at any time with no lock-up; rewards accrue daily and pay out weekly. Lock-up only applies to fixed-term products. Source →
- ✗
Insurance Fund
Insurance exists and is named, but nothing current covers the retail account. Crypto.com has published two policies, four years apart, for two different things. June 2025: "USD $120 million total of crime and specie insurance coverage for digital assets custodied by Crypto.com Custody Trust Company" — arranged by Aon through Lloyd's, split $100M cold storage and $20M crime — and that entity is, in their words, "Crypto.com's U.S.-based custody solution for all North American digital assets and eligible North American institutions", not the retail app. September 2021: $750M led by Arch Underwriting at Lloyd's Syndicate 2012, covering "cold storage assets on Ledger Vault, the company's custodial partner" — that one did cover retail, but the policy is dated "effective 6 September 2021", has had no published renewal since, and Ledger has wound the Vault product down. Crypto.com's own security page today mentions no crypto insurance at all. The widely quoted "$870M" is those two sums added together by someone else; Crypto.com has never published that figure. Source 1 → Source 2 → Source 3 →
- ✓
Track record (2+ years incident-free)
Operating since 2016. A January-2022 hack drained ~$34M from 483 accounts via a 2FA bypass — all affected users were fully reimbursed from company funds, and no comparable incident has occurred since. Source →
Incidents we count
Known incidents
1- January 2022 Attackers bypassed 2FA and withdrew ~$34M (444 BTC, 4,836 ETH + other) from 483 accounts. Crypto.com paused withdrawals, audited security, added a 24h delay for new withdrawal addresses, and fully reimbursed affected users. Source →