More than US$3.4 billion in cryptocurrency was stolen between January and early December 2025, and one compromise, the February theft from Bybit, accounted for US$1.5 billion of it, according to Chainalysis. Chainalysis ties the rising losses at centralized services to "sophisticated attacks on private key infrastructure and signing processes." Both of the year's defining incidents began off-chain. Bybit's cold wallet was drained after attackers compromised a developer machine at its multisig wallet provider, and Coinbase disclosed that criminals had paid overseas support staff to copy customer data.
Those are platform failures, and the platform is what New York's BitLicense rule, Canada's platform undertakings and institutional custody clients ask to see evidenced. This guide ranks the firms that test it: exchange and custody applications, trading and withdrawal APIs, mobile apps, cloud accounts, signing infrastructure, admin and support consoles, and the pipelines and developer endpoints that can change what gets signed.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in 2021 and headquartered in Toronto with a London office. Two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP staff every engagement, backed by 18 published CVEs and Hall of Fame listings at the US Federal Reserve and PaySafe. For a crypto platform they test withdrawal APIs across every account and staff role, the mobile apps, the support consoles, the AWS accounts on the signing path and the staff who can move money, as a one-time annual test or a continuous program, with retesting and an attestation letter included.
This guide serves exchanges, custodians, wallet providers, stablecoin issuers, on-ramps and off-ramps, tokenization platforms and fintechs adding crypto in the United States and Canada. Every vendor entry was verified on the vendor's own site on 25 September 2026.
Quick answer: who are the best penetration testing companies for crypto exchanges and digital asset platforms in 2026?
The best penetration testing companies for crypto exchanges and digital asset platforms in 2026 are Stingrai, NCC Group, Halborn, Kroll, Trail of Bits, Kudelski Security, Cure53, Praetorian, Bishop Fox, Doyensec and Software Secured. Stingrai ranks first: a CREST-accredited firm whose two named penetration testers, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP and backed by 18 published CVEs, test an exchange's or custodian's withdrawal APIs, account recovery flows, support consoles, mobile apps, AWS accounts and staff, one-time or continuously, with retesting and an attestation letter included. NCC Group follows for its published custody assessment and CREST-listed testing, Halborn for crypto-native exchange and custody testing, and Kroll for exchange red teaming backed by incident response. Trail of Bits, Kudelski Security and Cure53 are the specialists for the cryptography inside the custody stack.

What crypto platforms are actually required to test
Three of the dozen regimes cited in US and Canadian crypto procurement put a penetration testing clock in writing: NYDFS Part 200, NYDFS Part 500 and the FTC Safeguards Rule. Most of the rest never use the phrase.
Does the NYDFS BitLicense require penetration testing?
Yes, with two clocks. 23 NYCRR Part 200, New York's virtual currency regulation adopted in June 2015, requires every licensee to run a cybersecurity program under a CISO, with a board-approved written policy and an annual report to the Department. Section 200.16(e)(1) is the testing clause: "Each Licensee shall conduct penetration testing of its electronic systems, at least annually, and vulnerability assessment of those systems, at least quarterly."
Section 200.16(e)(2) adds audit trails that allow "the complete and accurate reconstruction of all financial transactions and accounting." The written policy must even cover "monitoring and implementing changes to core protocols not directly controlled by the Licensee," a line written for forks and network upgrades. The annual test and the quarterly assessment are separate obligations.
Does Part 500 apply to a BitLicensee as well?
Yes. NYDFS's August 2022 consent order with Robinhood Crypto cited violations of both Part 200 and Part 500. Section 500.5(a)(1), as amended in November 2023, requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually," enforceable since 29 April 2024. The two rules stack, and Part 500's small-entity exemption from section 500.5 does not reach Part 200: a small licensee still owes the annual test. Detail is in the NYDFS penetration testing guide.
What does the GENIUS Act require of stablecoin issuers?
It makes security a category and leaves the detail to regulators. The GENIUS Act, signed on 18 July 2025, directs regulators to issue "appropriate operational, compliance, and information technology risk management principles-based requirements and standards" for permitted payment stablecoin issuers (section 4(a)(4)(A)(iv)). Section 10 limits custody of reserves and of "the private keys used to issue permitted payment stablecoins" to supervised custodians. The statute never uses the words penetration testing.
The rules are not final. By 25 September 2026 the OCC, the FDIC, the Treasury and the Federal Reserve had published proposals, the Fed's on 24 September, and none had issued a final rule. The Act takes effect 18 months after enactment or 120 days after final rules, whichever comes first, so the backstop of 18 January 2027 now governs. The OCC proposal shows where testing will land: its section 15.13(b)(3) would require "periodic independent testing" and processes to ensure key systems, "including smart contracts," operate as intended, and section 15.13(b)(5) would require "private key management, backup, and recovery" measures. From 18 July 2028, section 3(b) bars digital asset service providers from offering payment stablecoins unless a permitted issuer issued them.
Where does US market structure legislation stand?
There is no US market structure law. The House passed the Digital Asset Market Clarity Act (H.R. 3633) 294 to 134 on 17 July 2025, and the Senate Banking Committee reported a substitute on 1 June 2026. On 15 September 2026 the Senate failed to invoke cloture on the motion to proceed, 49 to 50 (Record Vote 234), and a motion to reconsider was entered (Congress.gov). The House text would give registered digital commodity exchanges the system safeguards principle the CFTC applies to futures exchanges, whose rule at 17 CFR 38.1051 requires covered exchanges to run external and internal penetration tests at least annually. Until a bill passes, that rule reaches only crypto derivatives venues registered with the CFTC as designated contract markets.
What do FinCEN and the FTC Safeguards Rule require of a money transmitter?
FinCEN's 2019 guidance restates that exchangers of convertible virtual currency "generally qualify as money transmitters under the BSA." That means registration under 31 CFR 1022.380 and an anti-money laundering program under 31 CFR 1022.210 that provides for "independent review to monitor and maintain an adequate program." Neither names penetration testing.
The federal rule that does is the FTC Safeguards Rule for non bank financial institutions. Its definitions at 16 CFR 314.2 include "a business that regularly wires money to and from consumers," and 16 CFR 314.4(d)(2) requires "annual penetration testing of your information systems" and six-monthly vulnerability assessments unless the institution runs effective continuous monitoring. For a state-licensed exchange or on-ramp outside bank, SEC and CFTC supervision, it is the federal rule most likely to put an annual test in writing, and a question for counsel.
What do state money transmitter and digital asset licences add?
Thirty-one states had enacted the CSBS Money Transmission Modernization Act in full or in part by 3 September 2026; its harmonized core is net worth, surety bonds and permissible investments. California added a crypto licence. Since 1 July 2026 its Digital Financial Assets Law has required a DFPI licence or an application filed by that date (Financial Code section 3201). Its security hooks are an annual report of "any material data security breach or cybersecurity event" (section 3211) and a pre-listing certification that a covered exchange "conducted a comprehensive risk assessment designed to ensure consumers are adequately protected from cybersecurity risk" (section 3505). Neither regime names penetration testing.
What do custodians need: SOC 1, SOC 2 and the safekeeping statement
No US statute requires a custodian to hold a SOC report; clients and their auditors do. A SOC 1 report covers controls "likely to be relevant to user entities' internal control over financial reporting," which is why a fund's auditor asks for it, and a SOC 2 Type II report covers security and related controls over a period. Neither is a penetration test. SOC 2 criterion CC4.1 names penetration testing only inside a point of focus, which the AICPA publishes as an aid rather than a requirement, so the test is evidence the auditor reads.
For bank custodians, the OCC, Federal Reserve and FDIC safekeeping statement of 14 July 2025 says a safekeeping audit "should address the nuances of crypto-assets, including an assessment of cryptographic key generation, storage, and deletion; controls related to transfer and settlement of customer assets; and the sufficiency of relevant information technology systems." It creates no new expectations, but it tells a custodian what an examiner will read.
What do the CSA and CIRO require of a crypto asset trading platform?
Canadian platforms are regulated as securities dealers, and custody is where the rules bite. CSA and IIROC Staff Notice 21-329 (March 2021) expects platforms that hold keys to protect "participants' assets and private keys from theft or loss," including rules for cold storage and "how private keys are created and stored." Staff also said they intend "to generally require third-party systems reviews to be conducted on an annual basis once operations begin."
CSA Staff Notice 21-332 (February 2023) put custody into the pre-registration undertaking. At least 80% of client crypto assets must sit with an Acceptable Third-party Custodian that has "obtained a Systems and Organization Controls (SOC) 2 Type 1 or SOC 2 Type 2 report within the last twelve months," and the platform commits to "appropriate policies and procedures related to IT security, cyber-resilience, disaster recovery capabilities and business continuity plans." In August 2024 the CSA and CIRO told platforms to prioritize registration as investment dealers and CIRO membership, ending the interim restricted dealer route. CIRO's IDPC Rule 3703 requires dealers to report cyber incidents within three days. None of these instruments names penetration testing. The systems review and the custodian's SOC 2 report are where test evidence gets read.
What does FINTRAC require?
Dealing in virtual currency, both exchange and transfer services, is a money services business activity under FINTRAC's rules, so platforms register as MSBs or foreign MSBs. The compliance program needs a risk assessment, training and an effectiveness review "every two years at a minimum." It does not name penetration testing.
What does Quebec's AMF expect?
The AMF regulates Quebec platforms through the CSA framework, and its fintech guidance says the Securities Act "may apply, even for crypto assets that are not considered securities." Crypto machines that take cash fall to Revenu Québec's money-services rules. The AMF names penetration testing once, in its ICT Risk Management Guideline (February 2020), which expects a financial institution to "subject its information security controls to various types of periodic independent assessments, tests and reviews as well as penetration testing and red team exercises." It covers the insurers, deposit institutions and trust companies the AMF supervises, which matters when a Quebec trust company holds crypto.
What do Canada's Stablecoin Act and payments rules add?
The Stablecoin Act, enacted in Bill C-15 with Royal Assent on 26 March 2026, makes the Bank of Canada the registrar and supervisor of issuers. Section 41 requires a risk management policy describing how the issuer will "implement cybersecurity safeguards to protect the issuer's systems and data against unauthorized access, disruption or misuse." It comes into force by order, and the Bank of Canada says the Department of Finance is leading work on the regulations. On-ramps that hold or move fiat may also fall under the Retail Payment Activities Act, whose regulations require a testing methodology to find "vulnerabilities in" systems and controls and an independent review at least every three years. Neither names penetration testing.
The crypto platform attack surface: what a good scope covers
The 2025 incidents drew the scope more clearly than any rule. Bybit said a "scheduled move of ETH from our ETH Multisig Cold Wallet to our Hot Wallet" was "manipulated by a sophisticated attack that altered the smart contract logic and masked the signing interface," moving more than 400,000 ETH and stETH worth over US$1.5 billion (Bybit, 21 February 2025). The FBI attributed the theft to North Korea's TraderTraitor activity, and Safe{Wallet} confirmed the attack was conducted by compromising one of its developer machines.
Coinbase's Form 8-K of 14 May 2025 said the threat actor appears to have paid "multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems," and preliminarily estimated costs at approximately US$180 million to US$400 million. Its own post put those affected at under 1% of monthly transacting users. No passwords, private keys or funds were exposed; the stolen data became an impersonation list.

Trading and withdrawal APIs. Object-level authorization on every account-scoped call, which the OWASP API Security Top 10 ranks first as API1:2023. Race conditions where concurrent withdrawals each pass a balance check, rate limits on login and orders (API4), automated abuse of withdrawal flows (API6), and API key scopes that keep trading separate from withdrawal (API5). The API penetration testing ranking goes deeper.
Account takeover and withdrawal addresses. Password and 2FA resets, device binding, allowlist changes and hold periods. A new address should trigger a hold and out-of-band confirmation that support staff cannot waive.
Mobile apps. Keychain and Keystore storage of tokens and keys, certificate pinning, root detection, transfer deep links and the backend API. The mobile app ranking compares specialists.
Custody and key management. What an approver sees against what gets signed, which is the Bybit lesson. Policy engine rules, quorum settings, administrative access to HSM partitions and MPC nodes, and backup and recovery.
Hot wallet operations. Sweep and rebalancing automation, balance thresholds, the services holding hot wallet credentials, and drain detection.
Admin and support consoles. What each agent role can view, search and export, audit logging, and phishing and vishing against support staff. Chainalysis reports North Korean operators "embedding IT workers inside crypto services," so the insider scenario belongs in scope.
Cloud, CI/CD and developer endpoints. AWS IAM paths to signing services, the pipelines that ship front ends and signers, and an assumed breach that starts on a developer laptop. The cloud penetration testing ranking covers the AWS side.
Onboarding vendors carry their own attack surface, covered in the KYC penetration testing ranking, and the statement of work template pins the scope down.
Smart contract audits are a different discipline
A smart contract audit reviews on-chain code: Solidity, Rust or Move contracts and their access control, arithmetic, upgrade paths and economic logic. A platform penetration test attacks the systems around the chain: web and mobile apps, APIs, consoles, cloud accounts, the signing workflow and the people who run it. A platform that issues a token, runs a bridge or holds assets in a contract wallet needs both, scoped and bought separately. This ranking covers platform testing, and Stingrai's work sits on the platform side of that line.
Buyers who need a smart contract audit should look at firms that specialize in it, such as OpenZeppelin, Zellic and Sigma Prime. Trail of Bits, Halborn and Doyensec, ranked below for platform work, also run smart contract audit practices.
How we ranked them
Eleven vendors were scored against nine criteria. Every claim traces to a page the vendor publishes itself.
Published digital asset work on the vendor's own site.
Platform scope coverage: web, trading and withdrawal APIs, mobile, cloud, networks and social engineering.
Custody and key management depth: signing workflows, approval policies, MPC and HSM configuration.
Authorization and business logic depth: withdrawal limits, race conditions and console roles.
Insider and social engineering testing: phishing, vishing and support-console abuse.
Independent accreditation. Every accreditation was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself.
Evidence quality: named testers, retesting and a report an examiner or a custody client's auditor can read.
Delivery model fit: one-time and continuous testing, a portal and tracker integration.
Pricing transparency: a number before the sales call.
Firms whose only crypto offer is smart contract auditing, blockchain analytics or incident response were not ranked.
The 11 companies at a glance
# | Company | HQ | Accreditations | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Toronto, ON | CREST Penetration Testing, firm level | Human-led or hybrid; one-time or continuous; portal | Yes, two per engagement | Included | Yes, from US$3,000 | Whole-platform testing with evidence for NYDFS, CSA, CIRO and custody clients | |
2 | Manchester, UK | CREST Penetration Testing, Threat-Led Penetration Testing and more; ISO 27001 | Consultant-led plus continuous; portal | Not stated | Offered | No | Custody workflow review with platform testing | |
3 | Miami, FL | ISO 27001, SOC 2 Type 2 (stated) | Crypto-native engagements; portal | Not stated | Periodic | No | Platform tests and smart contract audits together | |
4 | New York, NY | CREST Penetration Testing, Incident Response, SOC; ISO 27001 | Consultancy with red team and incident response | Not stated | Not stated | No | Red teaming and incident readiness | |
5 | New York, NY | None stated | Consultancy reviews | Yes | Yes | No | MPC, threshold signing and signing flows | |
6 | Cheseaux-sur-Lausanne, Switzerland | ISO 27001, SOC 2 Type II (stated) | Consultancy | Not stated | Yes | No | Application, network and cryptographic review together | |
7 | Berlin, Germany | None stated | Report-based; publishes reports | Yes, on published reports | Not stated | No | Publishable review of wallet or MPC code | |
8 | Austin, TX | CREST Penetration Testing | Engineer-led plus continuous platform | Not stated | Yes | No | API authorization and CI/CD pipeline testing | |
9 | Tempe, AZ | CREST Penetration Testing; ISO 27001 | Consultant-led plus continuous platform | Not stated | Not stated | No | Large trading platforms | |
10 | San Francisco, CA | None stated | Boutique, source-assisted | Not stated | Not stated | No | Desktop wallets and trading clients | |
11 | Ottawa, ON | None stated | PTaaS and fixed-scope tests; portal | Not stated | Three rounds over 12 months | Yes, starting prices | Canadian custody technology vendors |
"Not stated" means not published, not absent. "(stated)" marks a certification claimed on the vendor's own site.
1. Stingrai (top rated for crypto exchanges and digital asset platforms)
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
Its firm-level accreditation is listed on the CREST Marketplace, separate from the CREST CRT certifications individual testers hold, and it is rated 5.0 out of 5 from 19 reviews on Clutch and 4.9 out of 5 on G2. Two named penetration testers run every engagement, reviewed by the team lead and an engagement partner. The team has 18 published CVEs, including CVE-2025-50674 and CVE-2024-32136, includes a founding member of Uber's offensive security team, and holds Hall of Fame listings at the US Federal Reserve and PaySafe. Founder Arafat Afzalzada has 11 years in offensive security.
How it tests a crypto platform. Web and API testing runs authenticated across every account, API key and staff role, hunting broken object level authorization, withdrawal race conditions and the address-change and 2FA-reset flows that turn a takeover into a withdrawal. Mobile testing covers Keychain and Keystore storage, and pinning and root detection bypass with Frida and objection, under OWASP MASVS and MASTG. Cloud testing follows cross-account roles, bucket policies and metadata abuse in AWS toward signing services. Phishing and vishing target support and operations staff, and assumed-breach red team engagements can start on a developer laptop.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept, with live chat to the testers and Jira and Slack integration. Retesting is included, and every report carries an attestation letter and a verified badge. Stingrai runs both one-time annual tests, the cadence 23 NYCRR 200.16(e)(1) and 500.5(a)(1) name, and continuous programs that test every release. On the trading web app and its API, Snipe, Stingrai's autonomous agent for web applications and their APIs, hunts IDOR, broken authorization and business logic flaws and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; on a Hybrid engagement Snipe and the penetration testers test together throughout.
HQ: Toronto, Ontario, with a London, UK office. Delivery: human-led or hybrid, one-time or continuous. Portal: yes.
Named testers: yes, two per engagement. Retest: included. Pricing: published, US$3,000 Autonomous and US$6,800 Hybrid for one web application and its APIs (pricing). Accreditations: CREST Penetration Testing, firm level.
Strength: every claim is checkable on a public register, review site or CVE record.
Limitation: its scope is the platform around the keys. Protocol-level review of an MPC or threshold-signature library is specialist code audit work where Trail of Bits, Kudelski Security and Cure53 publish more.
Best for: US and Canadian exchanges, custodians, stablecoin issuers and on-ramps that need CREST-accredited, named-tester coverage across the whole platform.
2. NCC Group
NCC Group's blockchain security practice reports "dozens of successful engagements across exchanges, DeFi protocols, and custodial platforms." It offers a Crypto-Custody and Operational Security Assessment, a "comprehensive evaluation of key management systems, approval workflows, and supporting infrastructure," and tests trading and custody flows for "race conditions, replay attacks, and logic vectors." Its researchers published the Bybit technical analysis and, from October 2025, a series on private key security in blockchain operations.
HQ: Manchester, UK, with a US regional headquarters in Chicago. Delivery: consultant-led plus continuous testing. Portal: yes, the Cyber Services Portal.
Named testers: not stated. Retest: offered post remediation. Pricing: not published. Accreditations: CREST Penetration Testing, Threat-Led Penetration Testing and more, 19 years of membership; ISO 27001.
Strength: the only firm here publishing a named custody and operational security assessment beside CREST-listed testing.
Limitation: no tester names or pricing, and seniority varies across a large bench.
Best for: exchanges and custodians that want custody workflow review and platform testing from one accredited firm.
3. Halborn
Halborn is crypto-native. Its exchanges page says it "secures the full trade lifecycle with deep technical audits, penetration testing, and architecture reviews," and its custody page covers work "from MPC signing schemes and HSM configurations to wallet architecture and policy engines." Its cloud penetration testing spans AWS, Azure and GCP, IAM and CI/CD pipelines.
HQ: Miami, Florida (fully remote). Delivery: engagement-based testing, audits and advisory. Portal: yes, Halborn ONE.
Named testers: not stated. Retest: periodic retesting offered. Pricing: not published. Accreditations: ISO 27001:2022 and SOC 2 Type 2 (stated); no CREST Marketplace listing.
Strength: sector pages for exchanges, custody and stablecoins, more than 4,000 assessments completed, and platform testing, MPC and HSM review and smart contract audits under one roof.
Limitation: no CREST accreditation, and generic methodology on its testing pages.
Best for: crypto-native exchanges and custodians buying platform tests and smart contract audits together.
4. Kroll
Kroll's crypto cybersecurity page is addressed to "a crypto exchange, custodian, virtual asset service provider (VASP) or any organization involved in the cryptocurrency sector." It offers full-stack penetration testing, "Red Team attack simulations tailored for exchange infrastructure, smart contracts and DeFi integrations" and social engineering resilience work, alongside incident response and blockchain tracing.
HQ: New York, New York. Delivery: consultancy across testing, red teaming and incident response. Portal: not stated.
Named testers: not stated. Retest: not stated on the crypto page. Pricing: not published. Accreditations: CREST Penetration Testing, Incident Response and Security Operations Centre, 8 years of membership; ISO 27001.
Strength: testing, red teaming, incident response and tracing from one firm, which matters in the first hours after a theft.
Limitation: the crypto offer sits inside a financial crime practice, and its testing detail is brief.
Best for: exchanges and custodians that want red teaming and incident readiness from an accredited firm.
5. Trail of Bits
Trail of Bits reviews "complete blockchain systems, from smart contracts and protocol logic to nodes, bridges, governance, and off-chain infrastructure," which its blockchain page lists as "Indexers, keepers, APIs, backend services, signing flows, deployment pipelines, monitoring." Its cryptography practice covers "multi-party computation & threshold signature scheme analysis." A June 2025 review of an early DKLs23 library found two high-severity issues "that could have resulted in a key destruction attack." Its homepage counts 620 audits.
HQ: New York, New York (remote-first). Delivery: consultancy reviews. Portal: not stated.
Named testers: yes, assigned up front. Retest: yes, it re-tests patches. Pricing: not published. Accreditations: none stated; no CREST Marketplace listing.
Strength: the deepest published record here on MPC, threshold signatures and signing flows.
Limitation: sold as security review rather than labelled penetration testing, so confirm the report will serve as your annual test.
Best for: custodians and wallet providers whose risk sits in MPC, threshold signing or HSM configuration.
6. Kudelski Security
Kudelski Security, the Kudelski Group's cybersecurity division, tests "internal networks, web apps, mobile, APIs, and cloud services, all under one engagement" through its penetration testing service, and its blockchain assessment covers "cryptographic code and supporting infrastructure." The README of BNB Chain's tss-lib threshold-signature library credits Kudelski Security with "a full review of this library," reported in October 2019.
HQ: Cheseaux-sur-Lausanne, Switzerland, with US headquarters in Phoenix, Arizona. Delivery: consultancy with SIEM and ticketing integration. Portal: not stated.
Named testers: not stated; testers are OSCP-certified. Retest: yes. Pricing: not published. Accreditations: ISO 27001 and SOC 2 Type II (stated); no CREST Marketplace listing.
Strength: platform testing and cryptographic review from one firm with a US headquarters.
Limitation: its blockchain page names no exchange, custody or MPC scope.
Best for: custodians and exchanges that want application, network and cryptographic review in one engagement.
7. Cure53
Berlin-based Cure53 offers "penetration tests for online services" and "infrastructure, platform and cryptography audits," and publishes many of its reports. They include wallet assessments and a December 2024 audit of Coinbase's cb-mpc library that rated a key refresh weakness as high severity. The published reports name the reviewers.
HQ: Berlin, Germany. Delivery: report-based assessments. Portal: none stated.
Named testers: yes, on published reports. Retest: not stated. Pricing: not published. Accreditations: none stated; no CREST Marketplace listing.
Strength: public reports let a buyer judge depth before signing.
Limitation: report-centric delivery from a single Berlin office.
Best for: wallet and custody vendors that want a publishable review of wallet software or MPC code.
8. Praetorian
Praetorian's penetration testing covers web, mobile, "API & Microservices," cloud and networks, and it states: "We guide fixes, re-test, and verify vulnerabilities are closed." It publishes no crypto page. It ranks here for two open-source tools that fit the exchange surface: Hadrian, which "systematically tests every endpoint for authorization bypass, broken authentication, excessive data exposure," and Trajan, which tests CI/CD pipelines across GitHub Actions, GitLab CI, Azure DevOps and Jenkins.
HQ: Austin, Texas. Delivery: engineer-led assessments plus the Praetorian Guard continuous platform. Portal: yes, Guard.
Named testers: not stated. Retest: yes. Pricing: not published. Accreditations: CREST Penetration Testing, 2 years of membership.
Strength: in-house tooling for API authorization and CI/CD attack paths.
Limitation: no published exchange, custody or key management work.
Best for: cloud-native exchanges that want API and pipeline testing with continuous coverage.
9. Bishop Fox
Bishop Fox's financial services page describes testing "the applications and infrastructure that power your operations," from legacy banking platforms and trading environments to cloud and API-driven architectures, and names the NYDFS Cybersecurity Regulation among its frameworks. Its Cosmos platform adds continuous offensive security.
HQ: Tempe, Arizona. Delivery: consultant-led testing plus Cosmos. Portal: Cosmos, for continuous work.
Named testers: not stated. Retest: not stated. Pricing: not published. Accreditations: CREST Penetration Testing, 4 years of membership; ISO 27001.
Strength: trading environments and NYDFS named on its own page.
Limitation: no digital asset, wallet or custody content is published.
Best for: large trading platforms with an in-house security team.
10. Doyensec
Doyensec, a San Francisco firm founded in 2017, pairs source code review with dynamic testing in its web and API practice. Its team co-authored the OWASP Testing Guide and wrote Electronegativity, an open-source Electron security tool, which matters for desktop wallets and trading clients built on Electron. It also runs smart contract audits.
HQ: San Francisco, California. Delivery: boutique, source-assisted engagements. Portal: none stated.
Named testers: not stated. Retest: not stated. Pricing: not published. Accreditations: none stated; no CREST Marketplace listing.
Strength: source-assisted depth on web, API and desktop applications.
Limitation: no exchange or custody page, and a deliberately small client base.
Best for: wallet and trading client teams that can share source code.
11. Software Secured
Ottawa's Software Secured publishes a case study on testing an MPC-based digital asset custody product, with test plans for its Admin API and Oracle API and threat modelling of its "MPC-based (Multi-party Computation), zero-trust architecture." Its fintech page quotes the client's CTO saying the testing "validated those controls end-to-end."
HQ: Ottawa, Ontario. Delivery: PTaaS and fixed-scope tests. Portal: yes.
Named testers: not stated. Retest: three rounds over 12 months. Pricing: starting prices published. Accreditations: none stated; no CREST Marketplace listing.
Strength: a Canadian tester with published custody-platform work.
Limitation: a smaller bench, and no exchange-specific scope is published.
Best for: Canadian custody and wallet technology vendors.
Not ranked: Coalfire holds CREST Penetration Testing accreditation and runs an offensive practice, DivisionHex, but its financial services page leads with PCI DSS compliance and it publishes no digital asset or custody testing page. It suits platforms whose testing budget sits inside a PCI DSS assessment.
How much does crypto platform penetration testing cost in 2026?
Crypto platforms rarely buy a single test. A realistic annual scope covers the web application and APIs, the mobile apps, the cloud accounts, the consoles and a social engineering or red team exercise, which puts most exchanges and custodians in the enterprise band.
These bands are indicative, drawn from our cost research rather than quotes. In the US, a web application test runs about US$5,000 to US$30,000, an API test US$6,000 to US$30,000, a mobile app US$7,000 to US$35,000 per platform, a cloud test US$10,000 to US$50,000, and an enterprise program US$50,000 to US$150,000 or more a year (penetration testing cost guide). In Canada, a standard web application test runs about C$12,000 to C$25,000, an API test C$15,000 to C$25,000, a mobile app C$18,000 to C$30,000 per platform, a cloud test C$25,000 to C$40,000, a red team C$45,000 to C$65,000, and an annual PTaaS program C$40,000 to C$120,000 or more (Canadian cost guide).
Stingrai publishes its own prices. An Autonomous Pentest (Snipe only, no penetration testers) is US$3,000 per assessment and a Hybrid Pentest (Snipe and penetration testers together) is US$6,800, each for one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee. Every other scope, including mobile apps, AWS accounts, support consoles, signing workflows and red team work, is quoted: get a quote or see the pricing page.
Buyer checklist: ten questions to put to a vendor
Who exactly will test, and what do they hold? Names and certifications, written into the statement of work.
Is the firm accredited at firm level, and can we check it? Firm-level CREST accreditation and individual certifications are different claims.
Will you test the whole withdrawal path? Address changes, allowlists, limits, holds, approval policy and the signing request, end to end.
How do you test race conditions and replay on trading and withdrawal APIs, and what proof will we get?
Will you test every console role? Ask what a support agent can view, search and export, and how that is proven.
Is social engineering of support and operations staff in scope, and how is it authorized?
How will you test signing infrastructure without touching production keys? Agree a test environment, testnet assets or dry-run signing at scoping.
Do you cover the cloud and CI/CD paths that can change what gets signed, including developer endpoints?
Is retesting included, and does the report carry an attestation letter? NYDFS examiners, CSA and CIRO reviewers and custody clients all ask what happened after the finding.
Can you run the annual test and continuous testing of each release? A platform shipping weekly should not wait eleven months for the next look.
Frequently Asked Questions
Who are the best penetration testing companies for crypto exchanges and digital asset platforms in 2026?
The best penetration testing companies for crypto exchanges and digital asset platforms in 2026 are Stingrai, NCC Group, Halborn, Kroll, Trail of Bits, Kudelski Security, Cure53, Praetorian, Bishop Fox, Doyensec and Software Secured. Stingrai ranks first as a CREST-accredited firm whose two named penetration testers, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP and backed by 18 published CVEs, test withdrawal APIs, account recovery flows, support consoles, mobile apps, AWS accounts and staff, one-time or continuously, with retesting and an attestation letter included. NCC Group, Halborn and Kroll follow for custody assessment depth, crypto-native testing, and red teaming with incident response.
Does the NYDFS BitLicense require penetration testing?
Yes. Section 200.16(e)(1) of 23 NYCRR Part 200 requires each licensee to "conduct penetration testing of its electronic systems, at least annually, and vulnerability assessment of those systems, at least quarterly." NYDFS also holds virtual currency licensees to Part 500, whose section 500.5(a)(1) requires annual penetration testing from both inside and outside the information systems' boundaries by a qualified internal or external party. Part 500's small-entity exemption from section 500.5 does not extend to Part 200.
Does the GENIUS Act require penetration testing for stablecoin issuers?
Not by name. The Act, signed on 18 July 2025, directs regulators to set "appropriate operational, compliance, and information technology risk management principles-based requirements and standards" for permitted payment stablecoin issuers and limits custody of reserves and issuing keys to supervised custodians. As of 25 September 2026 no implementing rule was final, so the Act takes effect on 18 January 2027. The OCC's proposal would require periodic independent testing and private key management, backup and recovery measures.
What do Canadian regulators require of a crypto trading platform?
Platforms are expected to register as investment dealers and join CIRO, under a pre-registration undertaking in the meantime. Under CSA Staff Notice 21-332, at least 80% of client crypto assets must sit with a custodian holding a SOC 2 Type 1 or Type 2 report from the last twelve months. Staff Notice 21-329 signalled annual third-party systems reviews, CIRO requires cyber incident reports within three days, and FINTRAC requires MSB registration with a two-year effectiveness review. None of these names penetration testing.
Is a smart contract audit the same as a penetration test?
No. A smart contract audit reviews on-chain code for flaws in access control, arithmetic, upgrade paths and economic logic. A platform penetration test attacks the systems around the chain: web and mobile apps, trading and withdrawal APIs, admin and support consoles, cloud accounts, signing workflows and staff. The 2025 Bybit and Coinbase incidents both began off-chain. Platforms that issue tokens or hold assets in contracts need both, scoped and bought separately.
What should a crypto exchange penetration test cover?
Trading and withdrawal APIs for object-level authorization, race conditions and rate limits; account takeover paths including 2FA resets and withdrawal address changes; iOS and Android apps; the custody and signing workflow, including what an approver sees against what gets signed; hot wallet automation; admin and support consoles, including what each role can view and export; and the AWS accounts, CI/CD pipelines and developer endpoints that can change what gets signed.
How much does penetration testing cost for a crypto exchange or custodian?
Indicative bands from our cost research put a US enterprise program at US$50,000 to US$150,000 or more a year and a Canadian annual PTaaS program at C$40,000 to C$120,000 or more, because crypto platforms buy several scopes at once. Stingrai publishes an Autonomous Pentest at US$3,000 and a Hybrid Pentest at US$6,800 for one web application and its APIs, or US$650 and US$1,275 per month on 12-month plans, and quotes every other scope.



