Before depositing crypto on an exchange, users usually want answers to a few basic questions. Who controls the assets? How are they protected? And is there any public evidence behind the platform’s security claims?
So, is Toobit safe? Based on the security measures and records reviewed for this article, the answer leans positive. Toobit combines account-level protection, cold storage, Proof of Reserves, external testing, and formal security governance. Still, using any centralized exchange comes with custodial, operational, and counterparty risk.
Security is never defined by one feature. A strong password cannot compensate for weak custody, just as cold storage cannot protect someone who enters a two-factor authentication code on a phishing site. Audits help, but only within the systems, versions, and dates they cover.
Our approach brings several layers together: two-factor authentication, anti-phishing and withdrawal controls, cold storage, multi-signature approvals, Proof of Reserves, a Shield Fund, ISO/IEC 27001:2022 certification, Hacken testing, and a public bug-bounty program.
This review looks at what those protections do, what the public evidence shows, and which risks users should still consider before keeping funds on Toobit or any other centralized exchange.
Is Toobit safe: the practical answer
No online financial platform can promise complete safety. A better way to evaluate an exchange is to see whether it takes material risks seriously, builds more than one line of defense, and gives users enough information to assess those protections.
Toobit has several positive security signals:
-
Independent testing: Hacken assessments have covered the website, APIs, Android and iOS applications, and reserve verification.
-
Formal security governance: ISO/IEC 27001:2022 certification supports the presence of documented security policies, controls, and review processes.
-
Reserve transparency: Users can view reserve ratios for selected assets and check whether their balances were included in the published Merkle tree.
-
Layered account protection: Available controls address phishing, stolen credentials, unauthorized devices, identity abuse, and suspicious withdrawals.
-
External vulnerability research: A public bug-bounty program allows researchers to report weaknesses through a formal channel.
These protections provide more substance than a general promise that funds are secure. They do not, however, remove every risk.
Proof of Reserves does not disclose every corporate liability, penetration tests only cover their stated scope, and several account protections need to be activated by the user. Third-party exchange ratings may also include liquidity, solvency, transparency, regulation, and trading activity, not just cybersecurity.
Overall, Toobit’s security profile appears reasonably strong for users who understand centralized custody and configure their accounts properly.
Security evidence at a glance
Each security measure answers a different question. An ISO certificate supports security governance but does not guarantee every transaction. A reserve ratio shows asset coverage at a snapshot but is not a complete financial audit.
|
Security area |
Available evidence |
What it indicates |
Main limitation |
|
Account protection |
2FA, anti-phishing, device, identity, and withdrawal controls |
Several barriers against account takeover |
Some controls require manual activation |
|
Asset custody |
Cold storage, multi-signature approval, monitoring, and wallet separation |
Reduced exposure to online and single-key attacks |
The current wallet allocation is not fully public |
|
Proof of Reserves |
Merkle verification and four reserve ratios above 100% |
Included balances were backed at the snapshot |
Not a complete financial or solvency audit |
|
Shield Fund |
Company-funded reserve launched with an initial value of $50 million |
Additional resources for eligible platform-related losses |
Conditional and not external insurance |
|
Hacken assessments |
Seven web, API, mobile, and reserve engagements |
Independent testing with documented findings |
Results only apply to the tested scope and version |
|
ISO certification |
ISO/IEC 27001:2022 for a defined ISMS scope |
Formal information-security governance |
Does not guarantee individual balances |
|
CoinGecko |
Trust Score 9/10 and rank #16 on August 26, 2026 |
Strong result under a broader exchange methodology |
Not a dedicated cybersecurity score |
|
CORE3 |
CCC grade, PoL 48.42, and rank #14 on August 26, 2026 |
Strong security inputs but mixed overall risk data |
Moderate confidence and incomplete coverage |
|
Compliance |
KYC and AML controls alongside registration records |
Documented compliance processes |
Registration is not the same as licensing |
The clearest picture appears when these layers are viewed together: account controls reduce user-level threats, custody procedures limit wallet exposure, audits test specific systems, and reserve disclosures make selected liabilities easier to verify.
Account controls and platform protection
Many account compromises begin with something familiar: a reused password, a fake login page, a stolen authentication code, or an unfamiliar device that goes unnoticed.
The Toobit safety hub groups our protections under the Bee-Safe framework. Users can configure several barriers between a stolen password and a completed withdrawal:
-
Two-factor authentication: Adds a second verification step, making a password less useful to an attacker on its own.
-
Anti-phishing code: Places a personal identifier in legitimate emails so impersonation attempts are easier to spot.
-
Device management: Shows which devices and sessions have access to the account.
-
Withdrawal protection: Adds restrictions or checks before funds can be sent to an external wallet.
-
Identity verification: Supports compliance, account recovery, and access-control procedures.
These controls work best together. Two-factor authentication helps if a password is stolen, while an anti-phishing code may stop someone from entering that password on a fake site. Device review can reveal unauthorized access, and withdrawal controls create another checkpoint before funds leave the account.
Several protections require manual setup. Users still need to enable 2FA, create an anti-phishing code, review active devices, and configure withdrawal controls. Those settings should be checked again after changing phones, passwords, email addresses, or recovery methods.
Behind the account interface, the platform uses encryption, access isolation, firewalls, distributed denial-of-service protection, transaction monitoring, and continuous threat detection. Customer assets are also separated from systems used for routine online operations.
External researchers can test the platform through the public HackenProof vulnerability-reward program, which covers the website, API, Android application, and iOS application.
A bug-bounty program does not mean every vulnerability has been found. Its value is that security research continues outside scheduled audit periods, with a clear process for responsible disclosure.
Asset custody, Proof of Reserves, and the Shield Fund
Account controls protect access to a user profile. Asset security covers where funds are stored, how sensitive transactions are approved, whether balances are backed, and what happens after an eligible platform-related loss.
Our framework approaches these questions through three connected layers.
A. Asset custody reduces wallet exposure
Our custody model separates most customer assets from systems used for routine online activity. This reduces the amount directly exposed to internet-based threats while keeping enough liquidity available for normal deposits and withdrawals.
The main custody controls include:
-
Cold storage: Most customer assets are kept away from internet-connected systems.
-
Multi-signature approval: Sensitive wallet transactions require more than one authorization.
-
Wallet separation: Assets used for daily operations are separated from longer-term holdings.
Some assets still need to remain in hot wallets so deposits and withdrawals can function. The exact split between hot and cold wallets is not fully published, nor are all internal approval procedures.
Cold storage and multi-signature approval reduce wallet risk, but they cannot make an operational or custody failure impossible.
B. Proof of Reserves makes balance inclusion verifiable
The public Proof of Reserves dashboard shows whether selected platform assets covered the corresponding user balances at a specific snapshot. Users can also check whether their own balances were included in the recorded liabilities.
The latest displayed snapshot was dated August 1, 2026:
|
Asset |
Reserve ratio |
|
Bitcoin (BTC) |
107% |
|
Ether (ETH) |
108% |
|
USD Coin (USDC) |
102% |
|
Tether (USDT) |
104% |
The calculation is:
Reserve ratio = assets held in the relevant wallets ÷ included user-account balances
A ratio above 100% means the disclosed assets exceeded the corresponding user liabilities at that snapshot. It does not mean every token on the platform has the same coverage, and the figures may change after the snapshot date.
Our system uses a Summation Merkle Tree to combine liability data with privacy-preserving balance verification. Users can check their inclusion in three ways:
-
Run the built-in verification from their Proof of Reserves report.
-
Copy their Merkle leaf and check it through the verification page.
-
Download the audit data and run the open-source verifier offline.
The verifier recalculates the user’s leaf hash, follows the path to the published Merkle root, and checks the relevant sibling nodes for negative balances. In practical terms, it allows users to confirm that their balance appeared in the liability dataset instead of relying only on a platform-wide percentage.
The asset side requires separate evidence. Hacken lists a January 2026 Proof-of-Solvency and Reserves engagement, with the report published on April 28, 2026.
The accompanying audit summary reports that roughly 640,000 accounts were examined and that reserve coverage exceeded 100% for BTC, ETH, USDT, and USDC. Evidence connected to institutional custodians was also included in the asset assessment.
Proof of Reserves has clear limits:
-
It only covers selected assets and liabilities at a particular snapshot.
-
It does not disclose every liability across the wider business.
-
It cannot guarantee immediate liquidity in every market condition.
-
It does not replace a full financial-statement audit.
It gives users useful evidence about selected reserve coverage and balance inclusion, but not an unlimited guarantee of business-wide solvency.
C. The Shield Fund adds conditional protection
The Toobit Shield Fund provides an additional financial resource for certain losses caused by internal security or technical failures. It launched in November 2025 with an initial value of $50 million in company funding.
Each part of the framework serves a different purpose:
-
Custody controls reduce the likelihood of wallet compromise.
-
Proof of Reserves provides evidence about selected asset coverage.
-
The Shield Fund is intended to respond after an eligible platform-related loss.
The fund does not cover personal account compromises, trading losses, market volatility, or incidents outside its published scope. Coverage depends on the terms and circumstances of the event.
It is best described as a company-funded protection reserve, not an external insurance policy. It is also separate from the futures insurance fund used within liquidation and derivatives-market processes.
Hacken testing and ISO security certification
An audit badge only tells part of the story. The useful details are what was tested, when the assessment happened, what was found, and whether the findings were addressed.
The Hacken project page for Toobit listed seven engagements at the time of this review. The available records cover the website, APIs, Android and iOS applications, and reserve verification.
The testing history includes:
-
2024 web and API penetration test: The assessment found one High-severity KYC integrity issue and two Medium-severity findings. All three were marked as resolved after retesting.
-
2025 Android assessment: The review reported one Medium and five Low findings. Five were resolved and one was accepted. The Medium-severity root-detection bypass was listed as fixed.
-
2025 iOS assessment: The results included three Medium and four Low findings. One was fixed and six were accepted, including findings related to stored application data, SSL pinning, and jailbreak detection.
-
2026 expanded testing: Our security update covers three further assessments of the web platform, API infrastructure, and mobile applications. The update reports no Critical- or High-severity findings and seven Medium-severity findings that were later addressed.
A resolved issue has been remediated and, where stated, retested. An accepted issue has been acknowledged, but some risk remains in the assessed version.
The 2026 update adds to the public testing history, although detailed individual pages for those three assessments were not available for full line-by-line review. The most granular independent findings remain those shown in Hacken’s individual reports.
Security testing also reflects a moment in time. New releases, integrations, dependencies, or configuration changes can alter the risk profile after an assessment. This is why repeated testing and an ongoing bug-bounty program matter.
Toobit Global Pty Ltd also holds ISO/IEC 27001:2022 certification issued by Swiss Approval North America, as documented in a Hacken case study.
The certified Information Security Management System covers exchange and derivatives services, asset storage and management, research and development, infrastructure, compliance, and risk control. The certificate is valid from January 12, 2026, to January 11, 2027, subject to surveillance requirements.
ISO certification looks at how security is managed across the organization. Penetration testing searches for weaknesses in specific systems. Together, they provide two different forms of evidence, though neither guarantees financial solvency or the security of every future software release.
CoinGecko and CORE3 offer different perspectives
CoinGecko and CORE3 both provide third-party information about Toobit, but they are not measuring the same thing. CoinGecko focuses more broadly on exchange quality and market activity, while CORE3 separates security, solvency, and transparency into different parts of its risk model.
That difference explains why Toobit can receive a strong CoinGecko Trust Score and a high CORE3 security score while still receiving a more moderate overall grade from CORE3.
CoinGecko’s perspective: trust and market activity
On CoinGecko’s exchange ranking, Toobit had a Trust Score of 9/10 and ranked #16 when checked on August 26, 2026. Both figures are dynamic and may change as CoinGecko updates its data or the relative position of other exchanges shifts.
The Spot profile also showed approximately $1.61 billion in 24-hour trading volume. The displayed 33.7% decline reflects a change in trading activity over the measured period; it is not, by itself, a security warning.
Toobit Spot Trust Score and 24-hour trading volume from CoinGecko, as of August 26, 2026
CoinGecko’s Trust Score methodology is broader than a technical-security audit. It considers several exchange-quality signals, including liquidity, trading activity, cybersecurity, regulatory indicators, incident history, and Proof of Reserves.
From that perspective, the 9/10 score suggests that Toobit performed strongly across CoinGecko’s combined methodology. It should not be read as a 90% probability that funds are safe or as a guarantee that the platform cannot experience a future incident.
The additional information shown on the Spot profile, such as new listings, largest gainers, and short-term volume changes, helps describe the activity taking place on the exchange. These figures may indicate that a market is active, but they do not reveal how customer assets are stored or whether the platform could meet every financial obligation.
CoinGecko’s derivatives perspective: scale and market participation
CoinGecko’s derivatives pages add another perspective by showing the size and breadth of Toobit’s perpetual and futures markets.
The Perpetuals profile displayed:
-
Approximately $16.69 billion in 24-hour trading volume.
-
Approximately $6.11 billion in open interest.
-
752 listed trading pairs.
-
A 29.7% decrease in 24-hour volume during the captured period.
Toobit perpetuals trading volume, open interest, and listed pairs from CoinGecko, as of August 26, 2026
Open interest represents the value of derivative positions that remain open, while trading volume reflects how much activity took place during the measured period. Large figures can indicate an active derivatives market, although they do not independently prove platform security, reserve coverage, or financial solvency.
The Futures tab displayed the same reported volume, open interest, and pair count in the supplied capture.
Toobit futures trading volume, open interest, and listed pairs from CoinGecko, as of August 26, 2026
Because the two captured tabs show identical numbers, the values should not be added together or presented as separate totals without further verification. The safer interpretation is that CoinGecko was displaying the same derivatives-market dataset across those tabs at the time of capture.
Together, the Spot and derivatives pages show that CoinGecko’s view of Toobit extends beyond cybersecurity. Market activity, liquidity, product coverage, and trading participation all contribute to the broader exchange profile.
CORE3’s perspective: security controls and wider exchange risk
CORE3 approaches the exchange from a different angle. Its exchange methodology gives security 50% of the model, solvency 30%, and transparency 20%.
When checked on August 26, 2026, Toobit’s CORE3 profile showed:
-
Overall rank #14.
-
CCC grade.
-
Probability of Loss score of 48.42.
-
Security score of 86.85 out of 100.
-
Moderate confidence level.
-
67% data coverage.
The security score was one of the strongest parts of the profile. CORE3 recognized controls across server protection, user-account security, vulnerability reporting, certification, insurance-fund availability, and penetration testing.
Toobit security score and security-control coverage from CORE3, as of August 26, 2026
The profile highlighted several areas:
-
Server protection: SSL/TLS certification, WAF or CDN protection, SPF and DNSSEC, HTTP headers, and no listed spam-database presence.
-
User security: Two-factor authentication, anti-phishing codes, withdrawal allowlisting, CAPTCHA, and device-management controls.
-
Bug bounty: A third-party program operated through HackenProof, with rewards ranging from $50 to $10,000.
-
Security governance: ISO 27001 was marked as present.
-
Incident protection: An insurance fund was marked as present.
-
Penetration testing: CORE3 displayed 100% score coverage for this category.
The “100%” penetration-test figure should be read as coverage within CORE3’s scoring model, not as proof that every Toobit system is free from vulnerabilities. Penetration tests still apply to specific applications, versions, and testing periods.
The same profile did not mark CCSS or SOC 2 as present. That does not cancel out the ISO 27001 certification or the other controls, but it shows why security comparisons should be based on the specific standards and evidence available rather than one general label.
CORE3’s broader result was more mixed. While the security score reached 86.85, the model also showed a solvency score of 10 and a transparency score of 0. Those lower inputs contributed to the CCC grade and PoL score of 48.42.
This does not necessarily mean CORE3 identified an active solvency failure. A low score can also reflect missing, incomplete, or unverified information within the model. The Moderate confidence label and 67% data coverage reinforce that point: CORE3 did not have a complete dataset across every category.
The two ratings answer different questions
CoinGecko and CORE3 are most useful when their results are read side by side rather than treated as competing verdicts.
|
Perspective |
CoinGecko |
CORE3 |
|
Main focus |
Exchange trust, liquidity, trading activity, cybersecurity, regulation, and reserves |
Security, solvency, transparency, and estimated loss risk |
|
Toobit result |
Trust Score 9/10 and rank #16 |
Security 86.85/100, CCC grade, PoL 48.42, and rank #14 |
|
Strongest signal |
Broad exchange quality and active Spot and derivatives markets |
Strong technical-security and account-control coverage |
|
Main limitation |
Not a dedicated security or solvency audit |
Moderate confidence and 67% data coverage |
|
Best use |
Comparing overall exchange quality and market participation |
Examining security controls and identifying gaps in available risk data |
CoinGecko’s result suggests that Toobit performs strongly across a broad exchange-quality framework. CORE3 provides a more segmented view: the technical-security score is strong, while its solvency and transparency assessments are limited or unfavorable.
There is also some overlap between the sources. CORE3 and Hacken are connected through the HAI Group ecosystem, as disclosed in Hacken’s 2025 year-end update. CORE3’s security profile also identifies HackenProof as Toobit’s third-party bug-bounty provider. Their findings remain relevant, but they should not be treated as completely unrelated validation.
The practical takeaway is simple: CoinGecko provides useful context about trust, liquidity, and market participation, while CORE3 offers a closer look at technical controls and broader risk categories. Neither rating should be used on its own to decide whether an exchange is safe. They are most useful when combined with Proof of Reserves, Hacken reports, certification records, incident history, and the user’s own custody preferences.
Compliance records require context
Security controls and regulatory status should be evaluated separately. KYC and Anti-Money Laundering processes can support compliance obligations, but they do not automatically give an exchange a license in every jurisdiction.
We use KYC and AML processes alongside external services for identity checks, blockchain monitoring, and Travel Rule workflows. Elliptic has confirmed its blockchain-screening partnership with Toobit.
The available records show:
-
The FinCEN MSB registry returned a record for Hopeful Technology Co., Ltd., a contracting entity associated with Toobit.
-
FinCEN explains that MSB registration is self-reported and does not amount to licensing, certification, approval, or government endorsement.
-
A Polish VASP registration forms part of the compliance record, but Poland’s official guidance states that legacy registration does not automatically authorize Crypto-Asset Service Provider activity under MiCA.
-
The ESMA MiCA register did not show an authorization for Toobit or its related European entity during this review.
Registration, licensing, and authorization are different legal concepts. Descriptions such as “KNF-licensed”, “MiCA-authorized”, or broadly “EU-regulated” would go beyond the evidence available at the research cutoff.
Availability and verification requirements may also differ by location. Users should review the current Toobit Terms of Use and the rules that apply in their jurisdiction.
Documented incidents and operational issues
Not every incident is a hack. A compromised social-media account, a pricing deviation, and a breach of core exchange wallets involve different systems and consequences.
No verified major compromise of Toobit’s core wallets was identified in the public sources reviewed for this article. Public research cannot, however, rule out events that were never disclosed.
Two types of incidents were documented:
-
February 2025 communication-channel compromise: Our official X account was compromised after an employee entered login credentials and a 2FA code on a phishing page. Unauthorized content appeared before access was restored. The trading platform and user assets were not affected.
-
Operational market events: Public notices covered a May 2025 mark-price deviation and a December 2025 market-data irregularity. Review or compensation processes followed.
The X incident shows how phishing can defeat authentication when a valid user enters both their credentials and 2FA code on a fraudulent page.
The market events were operational rather than confirmed cyberattacks, but they still matter. Pricing feeds, liquidation systems, APIs, and market data can affect user positions even when no wallet has been breached.
Risks that remain on a centralized exchange
Toobit operates a custodial model. The platform controls the wallets and private keys connected to balances held on the exchange, giving users convenient access to trading, liquidity, and account recovery.
That convenience also creates dependence on the exchange.
The main risks include:
-
Custodial risk: Users rely on the exchange to protect private keys and process withdrawals.
-
Counterparty risk: Proof of Reserves does not reveal every liability or guarantee that the wider business can meet all obligations during severe stress.
-
Account risk: Phishing, password reuse, malware, and stolen verification codes can bypass platform controls through the user’s account.
-
Operational risk: Pricing systems, APIs, withdrawal infrastructure, and internal processes can fail without a cyberattack.
-
Technology risk: New code or configuration changes can introduce weaknesses after testing.
-
Transparency risk: Reserve snapshots and public security reports do not provide a complete real-time view of the business.
Market risk is separate. An account can remain secure while its owner loses money through volatility, a poor trade, or leveraged liquidation.
How much someone keeps on an exchange should depend on their trading needs, withdrawal habits, risk tolerance, and ability to manage self-custody safely.
Practical steps for securing a Toobit account
Account protections should be configured before depositing meaningful funds:
-
Enable app-based two-factor authentication. Never enter a code on a page opened through an unverified message.
-
Use a long, unique password. Do not reuse one from email, social media, or another exchange.
-
Set an anti-phishing code. Treat emails with a missing or incorrect code as suspicious.
-
Verify websites and communication channels. Use the official verification tool before trusting an unfamiliar website or account.
-
Review active devices and sessions. Remove anything you no longer use or recognize.
-
Configure withdrawal controls. Use the available allowlist or related restrictions.
-
Keep authentication information private. Never share passwords, 2FA codes, backup codes, recovery phrases, or remote-screen access.
-
Test a small withdrawal first. Confirm the network, address, memo or tag, and security settings before moving a larger amount.
These steps cannot remove platform-level risk, but they can reduce common threats such as phishing, stolen credentials, and unauthorized withdrawals.
Final assessment of Toobit security
Based on the evidence available in August 2026, Toobit has a reasonably strong security profile for users who understand centralized-custody risks and protect their accounts properly.
The positive case rests on Hacken testing, documented remediation, ISO/IEC 27001:2022 certification, user-verifiable reserve data, cold-storage and multi-signature controls, an active bug-bounty program, and practical account protections.
The answer is not absolute. Proof of Reserves is narrower than a full financial audit, the Shield Fund contains exclusions, some audit findings were accepted rather than fixed, and the regulatory picture is less straightforward than the technical-security record.
So, is Toobit safe? The available evidence supports a qualified yes. The platform has several layers of protection and makes a meaningful amount of security information public. Users should still decide how much capital they are comfortable leaving with any custodian.
For more information, visit the Toobit safety hub and review the latest Proof of Reserves.
Common questions about Toobit security
Is Toobit safe for everyday use?
The available evidence supports a qualified positive assessment, provided users activate the available security controls and understand the risks of centralized custody.
Has Toobit experienced a major wallet breach?
No verified major compromise of Toobit’s core exchange wallets was identified in the reviewed public sources. A phishing incident affected the official X account in February 2025, but the trading platform and user assets were not affected.
Does Toobit publish Proof of Reserves?
Yes. The August 1, 2026 snapshot showed ratios of 107% for BTC, 108% for ETH, 102% for USDC, and 104% for USDT. Users can also verify their inclusion through the Merkle-based system.
What has Hacken tested?
Hacken has listed seven engagements covering the website, APIs, mobile applications, and reserve verification. Each assessment applies to its stated scope and testing period.
Which security settings should users enable?
Users should enable app-based 2FA, use a unique password, set an anti-phishing code, review active devices, configure withdrawal protection, and verify official communication channels.
This article is for informational purposes only and does not constitute financial advice. Always do your own research (DYOR) before making any decisions.
About Toobit
Toobit is where the future of crypto trading unfolds. The award-winning cryptocurrency derivatives exchange provides zero-fee spot trading, AI trading tools, and high leverage for both crypto and TradFi markets. Built for those who thrive on exploring new frontiers, Toobit maintains a fair, secure, and transparent environment for traders to navigate digital asset markets.
For more information about Toobit, visit: Website | X | Telegram | LinkedIn | Discord | Instagram




