How Kraken and Gemini Kept Users Losses at Zero Across a $1.9 Billion Exploits Era

Coinbase
Coinmama


The moment a major centralized exchange gets hit, my inbox fills up with the exact same message: “Where can I move my funds that has NEVER been hacked?”

First it was Bybit losing a record-breaking $1.4 billion, and now Bitget gets hit for over $350 million. It’s completely understandable why everyone is frantically looking for a pristine, untouched fortress.

The trouble is, looking for an exchange with a “clean record” is asking the wrong question entirely.

In crypto, asking which centralized exchange has never been hacked is a bit like asking which airport has never experienced bad weather. Sure, you can find a few that haven’t faced a major catastrophe yet, but treating a clean track record as a safety guarantee fundamentally misunderstands how exchange security works.

itrust

Binance Was Hacked, and It Said So

Let me clear up the Binance assumption first. Binance’s own security breach update says it discovered a large-scale breach on May 7, 2019 at 17:15:24 UTC.

Attackers obtained user API keys and 2FA codes, then withdrew 7,000 BTC in a single transaction.

Binance said this hit only its BTC hot wallet, which held about 2% of its total BTC, and that it would cover the loss from its SAFU fund. If you thought Binance had a spotless record, that’s why it doesn’t.

How Kraken and Gemini Kept Users Losses at Zero Across a $1.9 Billion Exploits Era

What “Never Hacked” Actually Means

I looked for a major exchange with zero security incidents of any kind and didn’t find one. What I did find were two exchanges where I couldn’t locate a documented case of customer funds lost to an outside breach: Kraken and Gemini.

Both have had incidents. Those incidents just never reached customer money, and that difference is what this piece is about.

Kraken: The Boring Fortress

Kraken’s security page describes crypto infrastructure kept in secure cages under 24/7 armed-guard surveillance. It also lists ISO/IEC 27001:2022 certification and a completed SOC 2 Type 1 examination. What I found more interesting is on its support pages. Employees get fully managed, hardened devices, internal systems require hardware-based multi-factor authentication, and no single person can access Kraken’s physical systems alone.

That matters because of how the recent big hacks worked. I walked through how Bybit’s signers were fooled, and how Bitget’s backend was spoofed, in How Backend Spoofing Took $351M From Bitget’s Liquidity Layer. In both cases the vaults held and the process around them gave way. Bitget’s own incident page says a critical backend system inside its wallet infrastructure was compromised. Kraken’s public emphasis on internal access controls reads to me like a company that worries about exactly that. I can’t see inside its architecture, so treat that as my read, not a finding.

Kraken isn’t spotless. In June 2024, its chief security officer said researchers exploited a bug and withdrew nearly $3 million from Kraken’s treasuries, not client assets.

In April 2026 it disclosed insider access incidents involving support staff, and Nick Percoco said that systems were never breached and funds were never at risk. Kraken also publishes a Proof of Reserves with an external accountant, so clients can check their own balances.

Gemini: Paperwork as a Security Strategy

Gemini’s Trust Center says it was the first crypto exchange and custodian to obtain SOC 1 Type 2 and SOC 2 Type 2 certifications, with the exam conducted by Deloitte. It also lists ISO/IEC 27001:2022 and describes itself as a full-reserve exchange. Audits don’t stop attackers, but they force a company to document and defend how it handles access and money.

How Kraken and Gemini Kept Users Losses at Zero Across a $1.9 Billion Exploits Era

Gemini’s incidents came through vendors, not its own vaults. In December 2022 it said a third-party vendor incident exposed customer emails and partial phone numbers, with no impact on its systems, funds or accounts. In 2024, a banking partner’s incident hit customer ACH details, and Gemini said its own systems were unaffected. Neither event touched customer coins, but both show that your security perimeter includes every vendor you use.

Coinbase: Clean on Funds, Not on People

I’m not putting Coinbase on the never-lost-funds list, because I couldn’t find a primary source that certifies its wallet record either way. What its own disclosure shows is a different kind of attack. Criminals bribed overseas support agents to steal customer data. Coinbase refused a $20 million ransom demand, set up a $20 million reward fund instead, and pointed to an 8-K filing it made on May 15, 2025. It said no passwords, private keys or funds were exposed, and that it would reimburse customers who were tricked into sending funds to the attacker. A breach doesn’t need to touch a wallet to hurt.

How Kraken and Gemini Kept Users Losses at Zero Across a $1.9 Billion Exploits Era

Did the Clean Ones Help Anyone?

This is where the story surprised me. In the primary sources I checked, I found no public offer of help to Bybit or Bitget from Kraken, Gemini or Coinbase. Kraken’s documented help is different in kind. In 2014 it was selected to assist the Mt. Gox trustee, and it says it was later chosen for Mt. Gox and FTX creditor distributions. That is cleanup after failure, not a hand to a peer in a live crisis.

The exchanges that did show up were the ones that had been through it. As I noted in the Bitget piece, Bybit’s Ben Zhou publicly offered help and said Bitget had supported Bybit during its own hack.

How Kraken and Gemini Kept Users Losses at Zero Across a $1.9 Billion Exploits Era

Bitget’s first security notice put the loss at $351.6 million, and its protection fund holds more than $464 million.

It has since published tracing and recovery bounty updates and said withdrawals are resuming in phases.

My Take

I don’t think a spotless record means an exchange is safer, and I wouldn’t say it out loud. It probably means nobody has found the gap yet, or the gap hasn’t paid off for an attacker. The exchanges I’d trust are the ones that publish their controls, submit to audits, and tell you fast when something goes wrong, including the embarrassing stuff. Whatever platform you use, keep only what you’re actively trading on it.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*