Kriptomat
exchangeKriptomat is an Estonian VASP-licensed exchange founded in 2018, serving 25+ European countries with 98% cold storage and no reported security breaches.
Platform Information
Founded
Headquarters
Two-Factor Authentication
An extra login step that protects your account even if your password is stolen.
Custodial
The platform holds your crypto on your behalf — you don't control the private keys.
KYC Required
Know Your Customer — you must verify your identity before trading or withdrawing.
Proof of Reserves
The platform publicly proves it holds enough assets to cover all customer funds.
Insurance
Customer funds are covered by insurance in the event of a hack or platform failure.
Supported Chains
About Kriptomat
Kriptomat is a custodial cryptocurrency exchange founded in February 2018 and headquartered in Tallinn, Estonia. Designed for European retail users, the platform serves over 400,000 registered accounts across 25+ countries and offers more than 400 tradeable cryptocurrencies alongside services such as automatic staking. Purchases are denominated in euros, with SEPA bank transfers processed at a flat €1 fee. Trading fees are 1.45% for bank transfers or up to 3.7% for credit card purchases.
Security
- 98% of customer crypto assets held in offline cold storage, distributed across hardware wallets placed in physical safety deposit boxes
- ISO/IEC 27001:2013 certified — an internationally recognised standard for information security management systems
- Two-factor authentication (2FA) available and recommended for all accounts
- Bug bounty programme maintained to incentivise responsible vulnerability disclosure
- Web Application Firewall and DDoS protection across all public-facing infrastructure
- 24/7 account and platform monitoring with automated alerting
- Sensitive data encrypted in transit and at rest across all platform services
- Multiple independent AML compliance audits conducted each year
- Customer assets are not lent out or used for operational purposes; the platform does not hold insurance on customer holdings
Regulation
- Virtual Asset Service Provider (VASP) licence issued by the Estonian Financial Intelligence Unit (FIU)
- Additionally registered as a VASP with the French AMF, Spanish CNMV, Polish Tax Administration Chamber, Greek Hellenic Capital Market Commission (HCMC), and Croatian HANFA
- MiCA authorisation process initiated in Estonia to obtain EU-wide passporting rights across all 27 member states
- Full KYC/AML verification required for all users; compliant with EU AML directives and GDPR
Incident History
No major security breaches or significant customer fund losses have been publicly attributed to Kriptomat since its founding in February 2018. The exchange has not appeared in published lists of major crypto hacks or exchange failures. Its combination of cold storage, ISO 27001 certification, and multi-jurisdictional regulatory oversight has contributed to this clean record.
Availability
Kriptomat operates across EU and EEA member states, as well as Switzerland, Turkey, and select Balkan countries including Albania, Bosnia and Herzegovina, Montenegro, and Serbia. Only euro is accepted as fiat currency, and all deposits and withdrawals rely on SEPA payment rails, restricting the service to users with euro-denominated bank accounts. The platform is not available to US residents.
Security & Score
Platform Safety Score
Based on incident history, security features, and track record
Security Features
Regulatory Information
Regulated In
Jurisdictions where this platform is officially licensed and subject to financial oversight.
Area Served
Countries or regions where this platform is available to users.
Notes
VASP licence issued by the Estonian Financial Intelligence Unit (FIU).
Incident History
No incidents recorded for this platform.
Frequently Asked Questions
Do you use Kriptomat?
Check how it affects your portfolio health score and get personalised risk insights.
Check your health score