The crypto exchange landscape has changed dramatically since we published our first review on Boxmining back in 2017. Back then, “good” meant: did it not get hacked, did withdrawals work, and were coins somewhat plentiful. In 2026, that bar is no longer enough. Perpetual futures trading volumes now exceed spot by a factor of 4x, MiCAR has standardised crypto-asset service provider (CASP) licensing across the EU, real-world asset (RWA) tokenisation has gone mainstream, and the Bybit hack of February 2025 — $1.5B in ETH stolen by North Korea’s Lazarus Group — has forced every serious exchange to overhaul its wallet infrastructure.
We are updating our review methodology to reflect this new reality. This is the official Boxmining 2026 rating criteria used to score every exchange we cover, from Binance to the long tail of regional CASP-licensed platforms. It is also the scorecard you can apply to exchanges we have not yet reviewed — the rubric below is intentionally self-administered.
Why a 2026 Update Was Needed
Our old methodology treated all volume as equal and assigned “Trustworthiness” almost entirely to whether the exchange hadn’t been hacked recently. After watching Mt. Gox, Quadriga, FTX, and now the Bybit/Lazarus incident play out on loop, four problems became obvious:
- Volume alone is not trust. Aggregate CoinGecko volume can be padded with wash trading; centralised reporting differs from on-chain reality.
- Regulatory regimes have converged. MiCAR is now live in all 27 EU member states, the FATF Travel Rule is enforced in most G20 jurisdictions, and regional licences (FCA, FinCEN, MAS, VARA) increasingly determine which users can actually access a platform.
- The product surface has exploded. Beyond spot, the modern exchange offers perpetuals, options, staking, lending, copy trading, AI strategy bots, tokenised stocks, and on-chain CEX-DEX routing. A 2017-era “coin diversity” metric of 50 vs 200 coins no longer captures differentiation.
- Security has shifted from “is it cold storage” to “can the wallet topology survive a sophisticated state actor.” Multi-sig via Safe{Wallet} is now treated as a liability, not a feature.
The 2026 criteria below answer these points explicitly.
The Five Pillars at a Glance
Every exchange we review is scored on five weighted pillars, each rated 0–100. The weighted average — not a marketing-curated composite — is the Overall Score that appears on every review card and at the top of every review page.
| Pillar | Weight | What it measures |
|---|---|---|
| Trustworthiness | 25% | Solvency, security architecture, incident history, transparency |
| Coin Diversity | 20% | Listing breadth across spot, derivatives, and on-chain pairs |
| Liquidity | 20% | Verified volume, order-book depth, slippage on large orders |
| Regulatory Compliance | 20% | Licences, KYC/AML, Travel Rule, sanctions adherence, jurisdictional stability |
| User Experience | 15% | Interface, support responsiveness, fees, mobile parity, uptime |
| Total | 100% |
Overall Score formula:
OverallScore = (Trustworthiness × 0.25)
+ (CoinDiversity × 0.20)
+ (Liquidity × 0.20)
+ (RegulatorCompliance × 0.20)
+ (UserExperience × 0.15)
The Overall Score is then mapped to a tier:
| Score | Tier | Interpretation |
|---|---|---|
| 90–100 | S+ | Best in class across all five pillars |
| 80–89 | S | Top tier, industry-leading |
| 60–79 | A | Strong, suitable for most users |
| 40–59 | B | Adequate but with notable weaknesses |
| 20–39 | C | Significant risks, use with caution |
| 0–19 | D | Avoid for fund custody |
Every individual exchange review also publishes a Volume-Derived Score on top of this editorial score. That figure is calculated mechanically from CoinGecko 24h spot volume using a logarithmic scale ($1M → 15, $10M → 30, … $100B → 90). It is presented separately from, not mixed into, our editorial rubric — we never want raw volume masquerading as a quality metric.
Pillar 1: Trustworthiness (25%)
Trustworthiness is the heaviest pillar, and rightly so — every other feature is meaningless if user funds are at risk. Our 2026 trustworthiness score blends four sub-components.
1.1 Proof of Reserves & Solvency (35% of pillar)
We no longer accept a single Proof-of-Reserves (PoR) snapshot. Modern trustworthiness requires:
- Merkle-tree PoR published at least monthly, with auditor attestation (Hacken, Armanino, Chainalysis, etc.).
- Independent on-chain verification of the claimed reserves — and we check ourselves using publicly available wallet tags.
- Third-party custodian disclosure. Where the platform uses a qualified custodian (Fireblocks, Anchorage, Coinbase Custody, BitGo), it is a positive signal; reliance on a self-custodied “Safe{Wallet}” multi-sig alone is no longer sufficient.
- Liability matching. A platform holding $10B in BTC but unable to demonstrate 1:1 customer liability matching is downgraded. This was the FTX failure mode.
1.2 Security Architecture & Custody (30% of pillar)
Specifically evaluated:
- Hot/cold wallet ratio. Industry best practice is <5% hot wallet exposure; we flag anything above 15%.
- Wallet topology. After the Bybit hack, single-vendor multi-sig (e.g. all signers behind Safe{Wallet}) is treated as a meaningful risk. Geographic and operational segregation of signers is rewarded.
- Withdrawal protection. Mandatory 2FA, anti-phishing codes, allow-listed withdrawal addresses, and time-locked large withdrawals.
- Bug bounty programme. Active bounties on Immunefi, HackerOne, or Bugcrowd with disclosed payouts >$100k.
- Penetration test & SOC 2 / ISO 27001 audits dated within the last 12 months.
1.3 Incident History (20% of pillar)
We construct a five-year incident log per exchange. Severity is graded:
- Catastrophic (–40 points): Total loss of customer funds or insolvency (Mt. Gox, FTX, Quadriga, Bybit Feb 2025).
- Major (–20 points): Significant hot-wallet drain with partial recovery.
- Moderate (–5 points): Phishing campaign or isolated user compromise traced to platform.
- Minor (0 points): DDoS, brief outage with no fund loss.
Crucially, a catastrophic incident is not permanent disqualification. The exchange is judged on its response: transparency, reimbursement, architectural remediation, and time-to-recovery. Bybit recovered customer reserves within 72 hours and shipped segregated signer infrastructure within six months — those are trust-positive actions that partially offset the original event.
1.4 Transparency & Disclosure (15% of pillar)
- Publicly named executive team and board.
- Disclosed jurisdiction of incorporation, headquarters, and regulatory home.
- Published trading fees, withdrawal fees, and any spread markups.
- Active response to researcher inquiries.
Pillar 2: Coin Diversity (20%)
“Coin diversity” in 2026 is no longer about raw spot-pair count — it is about what product surfaces an exchange makes accessible across asset classes.
2.1 Spot Coverage (40% of pillar)
- Total spot pairs (logarithmic scoring: 50 pairs = 30, 200 pairs = 60, 500+ pairs = 80, 1000+ pairs = 95).
- Coverage of major coins (BTC, ETH, SOL, top 20 by market cap): full credit if all 20 listed.
- Coverage of mid-cap and emerging narratives: AI tokens, RWA tokens, modular blockchain tokens, gaming, DePIN.
- Stablecoin support: USDT, USDC, USDS, DAI, USDG, PYUSD.
2.2 Derivatives Breadth (35% of pillar)
For derivatives-led exchanges, this pillar category matters more. We look at:
- Perpetual futures pairs (VIP-eligible volume counts as a tiebreaker).
- Quarterly / dated futures.
- Options support (BTC, ETH at minimum for full marks).
- Inverse vs USDT-margined contracts.
- Leverage ceiling (without rewarding recklessness — exchanges offering >125x with weak risk systems are penalised elsewhere).
2.3 On-Chain & Tokenised Markets (15% of pillar)
- Tokenised US stocks (xStocks, Robinhood-equivalent integrations).
- Tokenised treasuries and money-market funds.
- Pre-market / pre-listing derivatives.
- On-chain CEX-DEX aggregations (DEX-as-a-feature).
2.4 Quality of Listings (10% of pillar)
Listing count alone can be inflated via microcaps. We reward:
- Time-to-listing for top-50 by market cap (faster = better).
- Drop of delisted/rug-prone tokens.
- Rigorous listing review process.
- Refusal of wash-trading-favourable tokenomics.
Pillar 3: Liquidity (20%)
Liquidity is the single biggest differentiator between a real exchange and a token-laundering front. Our 2026 methodology refuses to take volume at face value.
3.1 Verified 24h Volume (30% of pillar)
- Source: CoinGecko + CoinMarketCap 24h spot volume (averaged, deduplicated against known wash-trading patterns).
- Verified against the exchange’s own published API volume: if claimed > reported by >15%, deduction.
- Liquid markets list (“A-grade liquidity pairs”) counted separately.
3.2 Order-Book Depth (30% of pillar)
We pull the top-20 order books for BTC, ETH, SOL, and one random large-cap token at three times a day (and on demand) to measure:
- Depth within ±0.1% of mid (in USD).
- Depth within ±0.5% of mid.
- Bid-ask spread in basis points.
- Resilience under volatility (measured during FOMC, CPI, and exchange-specific events).
3.3 Slippage Benchmarks (25% of pillar)
For each exchange we model the slippage on standard order sizes:
| Order Size | BTC slippage target | ETH slippage target |
|---|---|---|
| $100k | <2 bps | <3 bps |
| $1M | <8 bps | <12 bps |
| $10M | <25 bps | <40 bps |
| $50M | <80 bps | <120 bps |
Exchanges that beat these get full marks; those exceeding them lose points per additional 5 bps of slippage.
3.4 Settlement Reliability (15% of pillar)
- Funding-rate settlement accuracy on perpetuals.
- Settlement finality on options expiry.
- Withdrawal processing time (median + 95th percentile).
- No-cancellation rate of resting orders during volatility events.
Pillar 4: Regulatory Compliance (20%)
In 2026, an exchange’s regulatory posture directly determines which of your readers can actually use it — and how safe their funds are on a five-year horizon. Compliance is no longer a checkbox.
4.1 Licensing Footprint (40% of pillar)
We track a canonical licence matrix:
| Jurisdiction | Licence / Registration | Score weight |
|---|---|---|
| EU (MiCAR CASP) | Authorised in at least one EU member state (FMA, BaFin, AMF, AFM, etc.) | High |
| US (FinCEN MSB / state MTLs) | New York BitLicense or equivalent | High |
| UK (FCA crypto registration) | FCA-authorised under FSMA + crypto promotion rules | High |
| UAE (VARA / ADGM) | Operational licence in Dubai or Abu Dhabi | Medium-High |
| Singapore (MAS MPI / DPT) | Major Payment Institution or Digital Payment Token licence | Medium-High |
| Australia (AUSTRAC DCE) | Registered digital currency exchange | Medium |
| Hong Kong (SFC Type 1/7) | Securities and Futures Commission virtual asset trading platform | Medium |
| Canada (CIRO / FINTRAC) | Registered and PIP-compliant | Medium |
| Other FATF-compliant | Local licence where the exchange actually onboards users | Low |
Exchanges operating without a licence in their primary onboarding jurisdictions are capped at 50 on this pillar.
4.2 AML / KYC Rigor (25% of pillar)
- Tiered KYC with biometric / liveness checks.
- Travel Rule compliance via Notabene, Sygna, or in-house (TRP) with covered counterparty coverage.
- On-chain analytics integration (Chainalysis, Elliptic, TRM Labs) for both deposits and withdrawals.
- Public sanctions screening (OFAC, EU, UN, UK).
- Suspicious Activity Reporting (SAR) volume disclosed in regulator filings where available.
4.3 Jurisdictional Stability & Concentration Risk (20% of pillar)
A licence in one jurisdiction is great. A licence that gets revoked (Binance in the UK, 2023) is a recurring theme. We track:
- Number of licence actions, fines, or warnings in the last 24 months.
- Concentration risk: a single-jurisdiction exchange scoring high on local licence but with no fallback is downgraded.
- Sanctions exposure: founders or key staff with adverse checks = automatic pillar cap.
4.4 Operational Compliance (15% of pillar)
- Segregated customer funds (statutory trust, qualified custodian).
- Insurance fund disclosures (size and source).
- Public financial statements or audited accounts where mandated (e.g. US, EU, HK).
- Incident reporting SLA published and historically met.
Pillar 5: User Experience (15%)
UX may be the lightest pillar by weight, but a poor UX is often the difference between a user staying on a platform or being phished by a fake one.
5.1 Interface & Trading Tools (30% of pillar)
- Web platform stability (no crashes under load — tested at quarterly volatility windows).
- Mobile app parity (≥90% of features available on iOS and Android).
- Advanced order types (stop-limit, OCO, TWAP, iceberg, trailing).
- API quality (REST rate limits, WebSocket stability, FIX support for institutional).
- Customisation (layouts, hotkeys, portfolio views).
5.2 Customer Support (25% of pillar)
- Live support response time (median, by tier).
- 24/7 multilingual coverage.
- Quality of resolution, not just speed — we run mystery-shopper incidents quarterly.
- Public status page (status.
.com) accuracy. - Responsible disclosure turnaround.
5.3 Fee Transparency & Competitiveness (25% of pillar)
- Spot maker/taker fees vs the cohort median.
- Withdrawal fees vs network cost benchmark (we penalise exchanges charging >3× network cost).
- Deposit fees (zero is the expected default for crypto; fiat fees disclosed transparently).
- Spread markups disclosed on retail on-ramps (Banxa, MoonPay, etc.).
- VIP tier fairness — beyond VIP 4 the gaps should be objectively defensible.
5.4 Onboarding & Localisation (15% of pillar)
- Time-to-first-trade for KYC-verified user.
- Supported languages.
- Fiat rails (SEPA, Fedwire, FPS, PIX, UPI, etc.).
- Local payment methods (Apple Pay / Google Pay / iDEAL / OXXO / etc.).
5.5 Uptime & Incident Communications (5% of pillar)
- 99.9% uptime SLA published.
- Historical uptime vs SLA.
- Post-mortem publication after material incidents.
How We Re-Score Existing Reviews
Every exchange we have ever reviewed is being re-scored against this rubric. The 28+ active reviews on Boxmining are tagged “Updated 2026 Rating” once republished. Where our new rubric produces a materially different score, we publish a “What changed” callout box at the top of the article.
We re-score on a rolling quarterly cadence at minimum, and immediately on:
- Any new major security incident.
- Any new material regulatory action (licence gained or revoked).
- A material change in 24h volume or liquidity (≥30% deviation from trailing 90-day average).
- New product launches that materially change the rubric weights (e.g. an exchange launching tokenised stocks).
Editorial Independence
Our review methodology is editorial and independent. We do not accept payment for a higher score. Some links in our reviews are affiliate links — where they exist, they are disclosed at the top of the relevant article and never influence a pillar score. Affiliate compensation funds the work behind the rubric but never the rubric itself.
If you are an exchange and you believe our data is materially wrong, please contact us with on-chain or API evidence. We publish corrections publicly, with the original score retained in the article’s edit history.
How To Use This Rubric Yourself
To self-score an exchange against this rubric:
- Pull the exchange’s 24h spot volume from CoinGecko and top-of-book depth for BTC and ETH.
- Check the licence register — most are public (ESMA CASP register, FinCEN MSB database, FCA register).
- Audit the wallet disclosure — top-tier exchanges publish cold wallet addresses and PoR attestations.
- Cross-reference any security incidents against on-chain analytics (Chainalysis Reactor, Nansen).
- Apply the weighted formula to get your overall score.
If your number differs significantly from ours, please tell us — methodology is iterative and we’d rather converge to the truth than defend a number.
Frequently Asked Questions
Q: Why is Trustworthiness weighted 25% when Security is its own pillar? A: Because “trustworthiness” is broader than “no hacks.” It also encompasses solvency, transparency, and incident response — all factors that determine whether an exchange will be there in five years.
Q: Do you review DEXes with this rubric? A: DEXes get a parallel rubric with adjusted weights (Trustworthiness drops to 15% because there is no custodian, Liquidity rises to 30%, and we add an On-Chain Transparency pillar at 20%). DEXs are tagged in our system with a “DEX Methodology” badge.
Q: How do you handle wash trading? A: We cross-reference aggregate volume against (a) on-chain settlement flows via Flipside, (b) API-disclosed volume, and (c) top-of-book depth ratios. Exchanges materially over-reporting get flagged and their Liquidity pillar capped.
Q: Why is your score for some legacy exchanges lower than the exchange’s own marketing claims? A: Because their marketing claims are not our rubric. Most legacy exchanges publish a single “Trust Score” from a third-party data provider. We use those data points as inputs — not as a substitute for our own methodology.
Q: Can exchanges pay to be reviewed? A: No. Reviews are initiated by our editorial team based on user demand and our coverage priorities. We do accept test accounts and support tickets from exchanges, but those do not affect scoring.
This rubric is the canonical Boxmining 2026 exchange review methodology and supersedes any earlier documented process. It will be revisited at least annually and republished under the same URL with a clear changelog below.
Changelog
- 2026-07-04 — Initial publication of the 2026 rubric. Replaces the 2023 methodology. Adds MiCAR, Travel Rule, on-chain transparency, slippage benchmarks, and post-Bybit security architecture criteria.
Share
Found this useful?
Share it with someone who'd want to read it.

Michael Gu
Michael Gu, Creator of Boxmining, stared in the Blockchain space as a Bitcoin miner in 2012. Something he immediately noticed was that accurate information is hard to come by in this space. He started Boxmining in 2017 mainly as a passion project, to educate people on digital assets and share his experiences. Being based in Asia, Michael also found a huge discrepancy between digital asset trends and knowledge gap in the West and China.



