Skip to content
buybitcoinsmart

Bitstamp security record

Our rating
4.3
Events
12
Adverse
3
Since
2014
Review updated
2026-08-12

Our record for Bitstamp holds 12 dated events since 2014, 3 of them a breach, enforcement action, insolvency or outage. The most recent, on 2026-02-06: Virtual asset service provider registration in the British Virgin Islands. Every event below carries its source.

By kind

Breach
1
Enforcement
1
Outage
1
Licence
6
Audit
1
Proof of reserves
2

The record, year by year

Newest first. Good news and bad news sit in the same list, in order.

2026

  1. Licence

    Virtual asset service provider registration in the British Virgin Islands

    Bitstamp Global Ltd was registered as a virtual asset service provider by the British Virgin Islands Financial Services Commission, announced on 6 February 2026. The entity and its BVI supervision appear in the footer of Bitstamp's own site alongside the EU, UK, US and Singapore entities. It is an offshore registration for a separate group company and does not extend the EU or UK regimes to the customers it serves.

    Bitstamp by Robinhood: BVI VASP registration

2025

  1. Licence

    Major payment institution licence granted by the Monetary Authority of Singapore

    The Monetary Authority of Singapore licensed Bitstamp Asia Pte Ltd as a major payment institution, announced on 3 July 2025 under licence number PS20200667. The same entity and licence number appear in the footer of Bitstamp's own site. It is the group's first full operating licence in Asia and came shortly after Robinhood's acquisition of Bitstamp, the exchange now trading as Bitstamp by Robinhood.

    Bitstamp: globally trusted and now licensed in Singapore

  2. Enforcement

    French appeal court holds Bitstamp Europe liable for serving France without AMF registration

    The Court of Appeal of Grenoble ruled on 26 June 2025 that Bitstamp Europe was civilly liable to a customer for having provided a digital asset service in France without registering with the Autorite des marches financiers by the PACTE Act deadline of 19 December 2020. The court ordered Bitstamp to pay 27,950 euros, the value of crypto assets stolen from that customer's account, plus 3,000 euros toward legal costs. The reasoning matters beyond the sum: the court treated the missing registration as a civil fault directly causing the loss, so the customer did not have to prove the exchange had been operationally negligent about the theft.

    Goodwin: liability of crypto asset service providers for failure to register with the AMF

  3. Licence

    MiCA crypto asset service provider licence issued by the Luxembourg CSSF

    The Commission de Surveillance du Secteur Financier authorised Bitstamp Europe S.A. as a crypto asset service provider under the EU Markets in Crypto Assets regulation, announced on 16 May 2025. It covers operating the trading platform, executing client orders and custody of crypto assets, and passports across the European Economic Area. CASP licence number N00000003 appears in the footer of Bitstamp's own site. MiCA brings custody, capital and disclosure obligations that the earlier payment institution licence did not impose on the crypto side of the business.

    Bitstamp: secures CASP licence under MiCA

2023

  1. Licence

    Registered as a cryptoasset business by the UK Financial Conduct Authority

    Bitstamp UK Ltd was entered on the FCA cryptoasset register on 13 June 2023 under firm reference number 978690, covering custody of cryptoassets, buying and selling cryptoassets for legal tender, and crypto to crypto trading. The firm reference number appears in the footer of Bitstamp's own site. Read the scope carefully: this register is anti money laundering supervision only. It is not FCA authorisation of how the exchange treats customers, and crypto held at a registered firm is not protected by the Financial Services Compensation Scheme.

    Bitstamp: registered as a cryptoasset business by the FCA

2022

  1. Proof of reserves

    Proof of reserves audit described as an aim, not an existing practice

    On 18 November 2022, weeks after FTX failed, Bitstamp published its position on reserves. It said its group and legal entities had been audited by a big four accounting firm annually since 2016, pointed to its ISO 27001 and SOC 2 Type 2 certifications, and stated that its aim was to release a proof of reserves audit. That was a stated intention rather than something already in place. Bitstamp does not name the audit firm and does not publish the reports, and there is no Merkle tree proof that lets an individual customer check their own balance is included in a stated total.

    Bitstamp: proof of reserves and transparency, the Bitstamp way

  2. Audit

    SOC 2 Type 2 attestation and ISO/IEC 27001 certification obtained, reports not published

    Bitstamp announced on 18 March 2022 that it had obtained a SOC 2 Type 2 attestation, which tests whether security controls actually operated over a period rather than merely existing on paper, and ISO/IEC 27001 certification of its information security management system. The same post says Bitstamp is audited by one of the Big Four but does not name the firm. Neither report is published, so the findings cannot be checked from outside.

    Bitstamp: two new certifications

2019

  1. Licence

    New York BitLicense granted to Bitstamp USA

    The New York State Department of Financial Services granted Bitstamp a virtual currency licence on 9 April 2019. US customers are served by Bitstamp USA, Inc., which the site's own footer states is licensed by NYDFS to engage in virtual currency business activity and separately licensed by NYDFS as a money transmitter, under NMLS number 1905429. New York is the only US state that reviews crypto firms this way, so the licence is a supervisory check rather than a self declaration.

    Bitstamp: Bitstamp obtains BitLicense

2016

  1. Licence

    Luxembourg payment institution licence, passportable across the EU

    Luxembourg's financial regulator signed Bitstamp Europe S.A.'s payment institution licence on 25 April 2016, to take effect on 1 July 2016 when its Luxembourg headquarters became operational. The application ran close to two years and included security reviews and an audit by Ernst and Young. The licence passported into what were then 28 EU member states. Bitstamp still holds it: CSSF payment institution licence number Z00000012 appears in the footer of its own site.

    Finance Magnates: Bitstamp gets payment institution licence in Luxembourg

2015

  1. Breach

    18,866 BTC drained from the hot wallet, worth 5.26 million dollars, customers repaid in full

    Attackers phished six Bitstamp employees between 4 November and 19 December 2014, using emails and Skype messages carrying Word attachments that ran an obfuscated VBA script and pulled down a remote access trojan. One employee opened a file named UPE_application_form.doc, which gave the attacker his laptop and, through it, a VPN route into Bitstamp's data centre. On 29 December 2014 the attacker took the wallet.dat file from one server and its passphrase from another. On 4 January 2015 the hot wallet was drained of 18,866 BTC, worth 5,263,614 dollars at Bitstamp's clearing price of 279 dollars per bitcoin. Bitstamp suspended the service at 09:00 UTC on 5 January, rebuilt the platform from a clean backup onto entirely new hardware on AWS, and reopened on 9 January 2015 with BitGo multisignature wallets integrated. All balances held before the suspension were honoured in full and the loss was absorbed by the company, not by customers.

    Bitstamp incident report, 20 February 2015

2014

  1. Proof of reserves

    Cold storage of 183,497 BTC proven by a send to self, observed by a bitcoin developer

    On 24 May 2014 Bitstamp moved its cold wallet balance in a send to self transaction with bitcoin developer Mike Hearn observing, proving control of 183,497 BTC. Bitstamp said the reserves covered customer bitcoin held both on the exchange and on the Ripple network, and that a financial statement audit was under way at the time. It was a one off exercise and was not repeated on a schedule.

    Bitstamp: BTC proof of reserves, May 2014

  2. Outage

    Bitcoin withdrawals suspended for four days by a transaction malleability attack

    Bitstamp stopped processing bitcoin withdrawals on 11 February 2014 after a denial of service attack exploited transaction malleability and made its bitcoind wallet report inconsistent results. Failed withdrawal attempts from 10 and 11 February were cancelled and credited back to accounts. Bitstamp said no funds were lost and none were at risk, and announced on 15 February 2014 that fully automated bitcoin withdrawal processing had been restored after testing. Mt. Gox halted withdrawals in the same month citing the same class of attack and collapsed weeks later.

    Bitstamp: bitcoin withdrawal processing suspended

Compared with the alternatives

The same counts for every alternative the Bitstamp review names. A platform with no dated record is one we have not researched to this depth, not one with a clean history.

Dated security events on our record for Bitstamp and its alternatives.
ExchangeEventsAdverseLatestRecord
Bitstamp1232026-02-06
Kraken1062026-06-30Record
Coinbase1082026-05-07Record
Bitvavo842025-06-27Record
BitpandaNo dated record

Compared: Kraken, Coinbase, Bitvavo and Bitpanda.

Frequently asked questions

Has Bitstamp been hacked?

Our record lists 1 breach event: 2015, 18,866 BTC drained from the hot wallet, worth 5.26 million dollars, customers repaid in full. Whether customer funds were lost is stated per event above.

Has Bitstamp faced regulatory action?

Yes, 1 enforcement action on our record: 2025, french appeal court holds Bitstamp Europe liable for serving France without AMF registration.

Does Bitstamp publish proof of reserves?

Yes. 2022, proof of reserves audit described as an aim, not an existing practice; 2014, cold storage of 183,497 BTC proven by a send to self, observed by a bitcoin developer. A proof of reserves shows assets held against client balances at one moment; it is not an audit of liabilities.

Is Bitstamp licensed?

6 licence or authorisation events on our record: 2026, virtual asset service provider registration in the British Virgin Islands; 2025, major payment institution licence granted by the Monetary Authority of Singapore; 2025, miCA crypto asset service provider licence issued by the Luxembourg CSSF; 2023, registered as a cryptoasset business by the UK Financial Conduct Authority; 2019, new York BitLicense granted to Bitstamp USA; 2016, luxembourg payment institution licence, passportable across the EU. A licence covers the entity and activities it names, which the event text states.

Is Bitstamp safe?

Safety is not a field on our record; dated events are. Since 2014 we have sourced 12 events for Bitstamp, 3 of them adverse, the latest on 2026-02-06. Weigh the list above, and keep coins you are not trading in your own wallet whichever platform you use.