toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Is Toobit safe? A complete security review for 2026

2026-08-27 10:25

Toobit

Before depositing crypto on an exchange, users usually want answers to a few basic questions. Who controls the assets? How are they protected? And is there any public evidence behind the platform’s security claims?

So, is Toobit safe? Based on the security measures and records reviewed for this article, the answer leans positive. Toobit combines account-level protection, cold storage, Proof of Reserves, external testing, and formal security governance. Still, using any centralized exchange comes with custodial, operational, and counterparty risk.

Security is never defined by one feature. A strong password cannot compensate for weak custody, just as cold storage cannot protect someone who enters a two-factor authentication code on a phishing site. Audits help, but only within the systems, versions, and dates they cover.

Our approach brings several layers together: two-factor authentication, anti-phishing and withdrawal controls, cold storage, multi-signature approvals, Proof of Reserves, a Shield Fund, ISO/IEC 27001:2022 certification, Hacken testing, and a public bug-bounty program.

This review looks at what those protections do, what the public evidence shows, and which risks users should still consider before keeping funds on Toobit or any other centralized exchange.

Is Toobit safe: the practical answer

No online financial platform can promise complete safety. A better way to evaluate an exchange is to see whether it takes material risks seriously, builds more than one line of defense, and gives users enough information to assess those protections.

Toobit has several positive security signals:

  • Independent testing: Hacken assessments have covered the website, APIs, Android and iOS applications, and reserve verification.

  • Formal security governance: ISO/IEC 27001:2022 certification supports the presence of documented security policies, controls, and review processes.

  • Reserve transparency: Users can view reserve ratios for selected assets and check whether their balances were included in the published Merkle tree.

  • Layered account protection: Available controls address phishing, stolen credentials, unauthorized devices, identity abuse, and suspicious withdrawals.

  • External vulnerability research: A public bug-bounty program allows researchers to report weaknesses through a formal channel.

These protections provide more substance than a general promise that funds are secure. They do not, however, remove every risk.

Proof of Reserves does not disclose every corporate liability, penetration tests only cover their stated scope, and several account protections need to be activated by the user. Third-party exchange ratings may also include liquidity, solvency, transparency, regulation, and trading activity, not just cybersecurity.

Overall, Toobit’s security profile appears reasonably strong for users who understand centralized custody and configure their accounts properly.

Security evidence at a glance

Each security measure answers a different question. An ISO certificate supports security governance but does not guarantee every transaction. A reserve ratio shows asset coverage at a snapshot but is not a complete financial audit.

Security area

Available evidence

What it indicates

Main limitation

Account protection

2FA, anti-phishing, device, identity, and withdrawal controls

Several barriers against account takeover

Some controls require manual activation

Asset custody

Cold storage, multi-signature approval, monitoring, and wallet separation

Reduced exposure to online and single-key attacks

The current wallet allocation is not fully public

Proof of Reserves

Merkle verification and four reserve ratios above 100%

Included balances were backed at the snapshot

Not a complete financial or solvency audit

Shield Fund

Company-funded reserve launched with an initial value of $50 million

Additional resources for eligible platform-related losses

Conditional and not external insurance

Hacken assessments

Seven web, API, mobile, and reserve engagements

Independent testing with documented findings

Results only apply to the tested scope and version

ISO certification

ISO/IEC 27001:2022 for a defined ISMS scope

Formal information-security governance

Does not guarantee individual balances

CoinGecko

Trust Score 9/10 and rank #16 on August 26, 2026

Strong result under a broader exchange methodology

Not a dedicated cybersecurity score

CORE3

CCC grade, PoL 48.42, and rank #14 on August 26, 2026

Strong security inputs but mixed overall risk data

Moderate confidence and incomplete coverage

Compliance

KYC and AML controls alongside registration records

Documented compliance processes

Registration is not the same as licensing

The clearest picture appears when these layers are viewed together: account controls reduce user-level threats, custody procedures limit wallet exposure, audits test specific systems, and reserve disclosures make selected liabilities easier to verify.

Account controls and platform protection

Many account compromises begin with something familiar: a reused password, a fake login page, a stolen authentication code, or an unfamiliar device that goes unnoticed.

The Toobit safety hub groups our protections under the Bee-Safe framework. Users can configure several barriers between a stolen password and a completed withdrawal:

  • Two-factor authentication: Adds a second verification step, making a password less useful to an attacker on its own.

  • Anti-phishing code: Places a personal identifier in legitimate emails so impersonation attempts are easier to spot.

  • Device management: Shows which devices and sessions have access to the account.

  • Withdrawal protection: Adds restrictions or checks before funds can be sent to an external wallet.

  • Identity verification: Supports compliance, account recovery, and access-control procedures.

These controls work best together. Two-factor authentication helps if a password is stolen, while an anti-phishing code may stop someone from entering that password on a fake site. Device review can reveal unauthorized access, and withdrawal controls create another checkpoint before funds leave the account.

Several protections require manual setup. Users still need to enable 2FA, create an anti-phishing code, review active devices, and configure withdrawal controls. Those settings should be checked again after changing phones, passwords, email addresses, or recovery methods.

Behind the account interface, the platform uses encryption, access isolation, firewalls, distributed denial-of-service protection, transaction monitoring, and continuous threat detection. Customer assets are also separated from systems used for routine online operations.

External researchers can test the platform through the public HackenProof vulnerability-reward program, which covers the website, API, Android application, and iOS application.

A bug-bounty program does not mean every vulnerability has been found. Its value is that security research continues outside scheduled audit periods, with a clear process for responsible disclosure.

Asset custody, Proof of Reserves, and the Shield Fund

Account controls protect access to a user profile. Asset security covers where funds are stored, how sensitive transactions are approved, whether balances are backed, and what happens after an eligible platform-related loss.

Our framework approaches these questions through three connected layers.

A. Asset custody reduces wallet exposure

Our custody model separates most customer assets from systems used for routine online activity. This reduces the amount directly exposed to internet-based threats while keeping enough liquidity available for normal deposits and withdrawals.

The main custody controls include:

  • Cold storage: Most customer assets are kept away from internet-connected systems.

  • Multi-signature approval: Sensitive wallet transactions require more than one authorization.

  • Wallet separation: Assets used for daily operations are separated from longer-term holdings.

Some assets still need to remain in hot wallets so deposits and withdrawals can function. The exact split between hot and cold wallets is not fully published, nor are all internal approval procedures.

Cold storage and multi-signature approval reduce wallet risk, but they cannot make an operational or custody failure impossible.

B. Proof of Reserves makes balance inclusion verifiable

The public Proof of Reserves dashboard shows whether selected platform assets covered the corresponding user balances at a specific snapshot. Users can also check whether their own balances were included in the recorded liabilities.

The latest displayed snapshot was dated August 1, 2026: 

Asset

Reserve ratio

Bitcoin (BTC)

107%

Ether (ETH)

108%

USD Coin (USDC)

102%

Tether (USDT)

104%

The calculation is:

Reserve ratio = assets held in the relevant wallets ÷ included user-account balances

A ratio above 100% means the disclosed assets exceeded the corresponding user liabilities at that snapshot. It does not mean every token on the platform has the same coverage, and the figures may change after the snapshot date.

Our system uses a Summation Merkle Tree to combine liability data with privacy-preserving balance verification. Users can check their inclusion in three ways:

  1. Run the built-in verification from their Proof of Reserves report.

  2. Copy their Merkle leaf and check it through the verification page.

  3. Download the audit data and run the open-source verifier offline.

The verifier recalculates the user’s leaf hash, follows the path to the published Merkle root, and checks the relevant sibling nodes for negative balances. In practical terms, it allows users to confirm that their balance appeared in the liability dataset instead of relying only on a platform-wide percentage.

The asset side requires separate evidence. Hacken lists a January 2026 Proof-of-Solvency and Reserves engagement, with the report published on April 28, 2026.

The accompanying audit summary reports that roughly 640,000 accounts were examined and that reserve coverage exceeded 100% for BTC, ETH, USDT, and USDC. Evidence connected to institutional custodians was also included in the asset assessment.

Proof of Reserves has clear limits:

  • It only covers selected assets and liabilities at a particular snapshot.

  • It does not disclose every liability across the wider business.

  • It cannot guarantee immediate liquidity in every market condition.

  • It does not replace a full financial-statement audit.

It gives users useful evidence about selected reserve coverage and balance inclusion, but not an unlimited guarantee of business-wide solvency.

C. The Shield Fund adds conditional protection

The Toobit Shield Fund provides an additional financial resource for certain losses caused by internal security or technical failures. It launched in November 2025 with an initial value of $50 million in company funding.

Each part of the framework serves a different purpose:

  • Custody controls reduce the likelihood of wallet compromise.

  • Proof of Reserves provides evidence about selected asset coverage.

  • The Shield Fund is intended to respond after an eligible platform-related loss.

The fund does not cover personal account compromises, trading losses, market volatility, or incidents outside its published scope. Coverage depends on the terms and circumstances of the event.

It is best described as a company-funded protection reserve, not an external insurance policy. It is also separate from the futures insurance fund used within liquidation and derivatives-market processes.

Hacken testing and ISO security certification

An audit badge only tells part of the story. The useful details are what was tested, when the assessment happened, what was found, and whether the findings were addressed.

The Hacken project page for Toobit listed seven engagements at the time of this review. The available records cover the website, APIs, Android and iOS applications, and reserve verification.

The testing history includes:

  • 2024 web and API penetration test: The assessment found one High-severity KYC integrity issue and two Medium-severity findings. All three were marked as resolved after retesting.

  • 2025 Android assessment: The review reported one Medium and five Low findings. Five were resolved and one was accepted. The Medium-severity root-detection bypass was listed as fixed.

  • 2025 iOS assessment: The results included three Medium and four Low findings. One was fixed and six were accepted, including findings related to stored application data, SSL pinning, and jailbreak detection.

  • 2026 expanded testing: Our security update covers three further assessments of the web platform, API infrastructure, and mobile applications. The update reports no Critical- or High-severity findings and seven Medium-severity findings that were later addressed.

A resolved issue has been remediated and, where stated, retested. An accepted issue has been acknowledged, but some risk remains in the assessed version.

The 2026 update adds to the public testing history, although detailed individual pages for those three assessments were not available for full line-by-line review. The most granular independent findings remain those shown in Hacken’s individual reports.

Security testing also reflects a moment in time. New releases, integrations, dependencies, or configuration changes can alter the risk profile after an assessment. This is why repeated testing and an ongoing bug-bounty program matter.

Toobit Global Pty Ltd also holds ISO/IEC 27001:2022 certification issued by Swiss Approval North America, as documented in a Hacken case study.

The certified Information Security Management System covers exchange and derivatives services, asset storage and management, research and development, infrastructure, compliance, and risk control. The certificate is valid from January 12, 2026, to January 11, 2027, subject to surveillance requirements.

ISO certification looks at how security is managed across the organization. Penetration testing searches for weaknesses in specific systems. Together, they provide two different forms of evidence, though neither guarantees financial solvency or the security of every future software release.

CoinGecko and CORE3 offer different perspectives

CoinGecko and CORE3 both provide third-party information about Toobit, but they are not measuring the same thing. CoinGecko focuses more broadly on exchange quality and market activity, while CORE3 separates security, solvency, and transparency into different parts of its risk model.

That difference explains why Toobit can receive a strong CoinGecko Trust Score and a high CORE3 security score while still receiving a more moderate overall grade from CORE3.

CoinGecko’s perspective: trust and market activity

On CoinGecko’s exchange ranking, Toobit had a Trust Score of 9/10 and ranked #16 when checked on August 26, 2026. Both figures are dynamic and may change as CoinGecko updates its data or the relative position of other exchanges shifts.

The Spot profile also showed approximately $1.61 billion in 24-hour trading volume. The displayed 33.7% decline reflects a change in trading activity over the measured period; it is not, by itself, a security warning.

Toobit Spot Trust Score and 24-hour trading volume from CoinGecko, as of August 26, 2026

CoinGecko’s Trust Score methodology is broader than a technical-security audit. It considers several exchange-quality signals, including liquidity, trading activity, cybersecurity, regulatory indicators, incident history, and Proof of Reserves.

From that perspective, the 9/10 score suggests that Toobit performed strongly across CoinGecko’s combined methodology. It should not be read as a 90% probability that funds are safe or as a guarantee that the platform cannot experience a future incident.

The additional information shown on the Spot profile, such as new listings, largest gainers, and short-term volume changes, helps describe the activity taking place on the exchange. These figures may indicate that a market is active, but they do not reveal how customer assets are stored or whether the platform could meet every financial obligation.

CoinGecko’s derivatives perspective: scale and market participation

CoinGecko’s derivatives pages add another perspective by showing the size and breadth of Toobit’s perpetual and futures markets.

The Perpetuals profile displayed:

  • Approximately $16.69 billion in 24-hour trading volume.

  • Approximately $6.11 billion in open interest.

  • 752 listed trading pairs.

  • A 29.7% decrease in 24-hour volume during the captured period.


Toobit perpetuals trading volume, open interest, and listed pairs from CoinGecko, as of August 26, 2026

Open interest represents the value of derivative positions that remain open, while trading volume reflects how much activity took place during the measured period. Large figures can indicate an active derivatives market, although they do not independently prove platform security, reserve coverage, or financial solvency.

The Futures tab displayed the same reported volume, open interest, and pair count in the supplied capture.


Toobit futures trading volume, open interest, and listed pairs from CoinGecko, as of August 26, 2026

Because the two captured tabs show identical numbers, the values should not be added together or presented as separate totals without further verification. The safer interpretation is that CoinGecko was displaying the same derivatives-market dataset across those tabs at the time of capture.

Together, the Spot and derivatives pages show that CoinGecko’s view of Toobit extends beyond cybersecurity. Market activity, liquidity, product coverage, and trading participation all contribute to the broader exchange profile.

CORE3’s perspective: security controls and wider exchange risk

CORE3 approaches the exchange from a different angle. Its exchange methodology gives security 50% of the model, solvency 30%, and transparency 20%.

When checked on August 26, 2026, Toobit’s CORE3 profile showed:

  • Overall rank #14.

  • CCC grade.

  • Probability of Loss score of 48.42.

  • Security score of 86.85 out of 100.

  • Moderate confidence level.

  • 67% data coverage.

The security score was one of the strongest parts of the profile. CORE3 recognized controls across server protection, user-account security, vulnerability reporting, certification, insurance-fund availability, and penetration testing.

Toobit security score and security-control coverage from CORE3, as of August 26, 2026

The profile highlighted several areas:

  • Server protection: SSL/TLS certification, WAF or CDN protection, SPF and DNSSEC, HTTP headers, and no listed spam-database presence.

  • User security: Two-factor authentication, anti-phishing codes, withdrawal allowlisting, CAPTCHA, and device-management controls.

  • Bug bounty: A third-party program operated through HackenProof, with rewards ranging from $50 to $10,000.

  • Security governance: ISO 27001 was marked as present.

  • Incident protection: An insurance fund was marked as present.

  • Penetration testing: CORE3 displayed 100% score coverage for this category.

The “100%” penetration-test figure should be read as coverage within CORE3’s scoring model, not as proof that every Toobit system is free from vulnerabilities. Penetration tests still apply to specific applications, versions, and testing periods.

The same profile did not mark CCSS or SOC 2 as present. That does not cancel out the ISO 27001 certification or the other controls, but it shows why security comparisons should be based on the specific standards and evidence available rather than one general label.

CORE3’s broader result was more mixed. While the security score reached 86.85, the model also showed a solvency score of 10 and a transparency score of 0. Those lower inputs contributed to the CCC grade and PoL score of 48.42.

This does not necessarily mean CORE3 identified an active solvency failure. A low score can also reflect missing, incomplete, or unverified information within the model. The Moderate confidence label and 67% data coverage reinforce that point: CORE3 did not have a complete dataset across every category.

The two ratings answer different questions

CoinGecko and CORE3 are most useful when their results are read side by side rather than treated as competing verdicts.

Perspective

CoinGecko

CORE3

Main focus

Exchange trust, liquidity, trading activity, cybersecurity, regulation, and reserves

Security, solvency, transparency, and estimated loss risk

Toobit result

Trust Score 9/10 and rank #16

Security 86.85/100, CCC grade, PoL 48.42, and rank #14

Strongest signal

Broad exchange quality and active Spot and derivatives markets

Strong technical-security and account-control coverage

Main limitation

Not a dedicated security or solvency audit

Moderate confidence and 67% data coverage

Best use

Comparing overall exchange quality and market participation

Examining security controls and identifying gaps in available risk data

CoinGecko’s result suggests that Toobit performs strongly across a broad exchange-quality framework. CORE3 provides a more segmented view: the technical-security score is strong, while its solvency and transparency assessments are limited or unfavorable.

There is also some overlap between the sources. CORE3 and Hacken are connected through the HAI Group ecosystem, as disclosed in Hacken’s 2025 year-end update. CORE3’s security profile also identifies HackenProof as Toobit’s third-party bug-bounty provider. Their findings remain relevant, but they should not be treated as completely unrelated validation.

The practical takeaway is simple: CoinGecko provides useful context about trust, liquidity, and market participation, while CORE3 offers a closer look at technical controls and broader risk categories. Neither rating should be used on its own to decide whether an exchange is safe. They are most useful when combined with Proof of Reserves, Hacken reports, certification records, incident history, and the user’s own custody preferences.

Compliance records require context

Security controls and regulatory status should be evaluated separately. KYC and Anti-Money Laundering processes can support compliance obligations, but they do not automatically give an exchange a license in every jurisdiction.

We use KYC and AML processes alongside external services for identity checks, blockchain monitoring, and Travel Rule workflows. Elliptic has confirmed its blockchain-screening partnership with Toobit.

The available records show:

  • The FinCEN MSB registry returned a record for Hopeful Technology Co., Ltd., a contracting entity associated with Toobit.

  • FinCEN explains that MSB registration is self-reported and does not amount to licensing, certification, approval, or government endorsement.

  • A Polish VASP registration forms part of the compliance record, but Poland’s official guidance states that legacy registration does not automatically authorize Crypto-Asset Service Provider activity under MiCA.

  • The ESMA MiCA register did not show an authorization for Toobit or its related European entity during this review.

Registration, licensing, and authorization are different legal concepts. Descriptions such as “KNF-licensed”, “MiCA-authorized”, or broadly “EU-regulated” would go beyond the evidence available at the research cutoff.

Availability and verification requirements may also differ by location. Users should review the current Toobit Terms of Use and the rules that apply in their jurisdiction.

Documented incidents and operational issues

Not every incident is a hack. A compromised social-media account, a pricing deviation, and a breach of core exchange wallets involve different systems and consequences.

No verified major compromise of Toobit’s core wallets was identified in the public sources reviewed for this article. Public research cannot, however, rule out events that were never disclosed.

Two types of incidents were documented:

  • February 2025 communication-channel compromise: Our official X account was compromised after an employee entered login credentials and a 2FA code on a phishing page. Unauthorized content appeared before access was restored. The trading platform and user assets were not affected.

  • Operational market events: Public notices covered a May 2025 mark-price deviation and a December 2025 market-data irregularity. Review or compensation processes followed.

The X incident shows how phishing can defeat authentication when a valid user enters both their credentials and 2FA code on a fraudulent page.

The market events were operational rather than confirmed cyberattacks, but they still matter. Pricing feeds, liquidation systems, APIs, and market data can affect user positions even when no wallet has been breached.

Risks that remain on a centralized exchange

Toobit operates a custodial model. The platform controls the wallets and private keys connected to balances held on the exchange, giving users convenient access to trading, liquidity, and account recovery.

That convenience also creates dependence on the exchange.

The main risks include:

  • Custodial risk: Users rely on the exchange to protect private keys and process withdrawals.

  • Counterparty risk: Proof of Reserves does not reveal every liability or guarantee that the wider business can meet all obligations during severe stress.

  • Account risk: Phishing, password reuse, malware, and stolen verification codes can bypass platform controls through the user’s account.

  • Operational risk: Pricing systems, APIs, withdrawal infrastructure, and internal processes can fail without a cyberattack.

  • Technology risk: New code or configuration changes can introduce weaknesses after testing.

  • Transparency risk: Reserve snapshots and public security reports do not provide a complete real-time view of the business.

Market risk is separate. An account can remain secure while its owner loses money through volatility, a poor trade, or leveraged liquidation.

How much someone keeps on an exchange should depend on their trading needs, withdrawal habits, risk tolerance, and ability to manage self-custody safely.

Practical steps for securing a Toobit account

Account protections should be configured before depositing meaningful funds:

  1. Enable app-based two-factor authentication. Never enter a code on a page opened through an unverified message.

  2. Use a long, unique password. Do not reuse one from email, social media, or another exchange.

  3. Set an anti-phishing code. Treat emails with a missing or incorrect code as suspicious.

  4. Verify websites and communication channels. Use the official verification tool before trusting an unfamiliar website or account.

  5. Review active devices and sessions. Remove anything you no longer use or recognize.

  6. Configure withdrawal controls. Use the available allowlist or related restrictions.

  7. Keep authentication information private. Never share passwords, 2FA codes, backup codes, recovery phrases, or remote-screen access.

  8. Test a small withdrawal first. Confirm the network, address, memo or tag, and security settings before moving a larger amount.

These steps cannot remove platform-level risk, but they can reduce common threats such as phishing, stolen credentials, and unauthorized withdrawals.

Final assessment of Toobit security

Based on the evidence available in August 2026, Toobit has a reasonably strong security profile for users who understand centralized-custody risks and protect their accounts properly.

The positive case rests on Hacken testing, documented remediation, ISO/IEC 27001:2022 certification, user-verifiable reserve data, cold-storage and multi-signature controls, an active bug-bounty program, and practical account protections.

The answer is not absolute. Proof of Reserves is narrower than a full financial audit, the Shield Fund contains exclusions, some audit findings were accepted rather than fixed, and the regulatory picture is less straightforward than the technical-security record.

So, is Toobit safe? The available evidence supports a qualified yes. The platform has several layers of protection and makes a meaningful amount of security information public. Users should still decide how much capital they are comfortable leaving with any custodian.

For more information, visit the Toobit safety hub and review the latest Proof of Reserves.

Common questions about Toobit security

Is Toobit safe for everyday use?

The available evidence supports a qualified positive assessment, provided users activate the available security controls and understand the risks of centralized custody.

Has Toobit experienced a major wallet breach?

No verified major compromise of Toobit’s core exchange wallets was identified in the reviewed public sources. A phishing incident affected the official X account in February 2025, but the trading platform and user assets were not affected.

Does Toobit publish Proof of Reserves?

Yes. The August 1, 2026 snapshot showed ratios of 107% for BTC, 108% for ETH, 102% for USDC, and 104% for USDT. Users can also verify their inclusion through the Merkle-based system.

What has Hacken tested?

Hacken has listed seven engagements covering the website, APIs, mobile applications, and reserve verification. Each assessment applies to its stated scope and testing period.

Which security settings should users enable?

Users should enable app-based 2FA, use a unique password, set an anti-phishing code, review active devices, configure withdrawal protection, and verify official communication channels.

This article is for informational purposes only and does not constitute financial advice. Always do your own research (DYOR) before making any decisions.

About Toobit

Toobit is where the future of crypto trading unfolds. The award-winning cryptocurrency derivatives exchange provides zero-fee spot trading, AI trading tools, and high leverage for both crypto and TradFi markets. Built for those who thrive on exploring new frontiers, Toobit maintains a fair, secure, and transparent environment for traders to navigate digital asset markets.

For more information about Toobit, visit: Website | X | Telegram | LinkedIn | Discord | Instagram

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.