MKT
Centralised exchange

Bitfinex

The exchange that socialised a hack across every customer in 2016 — including untouched accounts — and whose proof of reserves is a 2022 text file.

Founded
2012
Registered
British Virgin Islands

The short answer

In 2016 it did something no other venue in this rating has done: after a hack, it imposed a 36% haircut on every customer, including accounts that were never touched, before eventually repaying in dollars. That is the precedent to weigh, because it establishes what the company believes it may do with your balance. Its proof of reserves today is a November 2022 blog post listing some wallet addresses — assets only, no liabilities, no attestor — and the proof-of-reserves URLs now 404. We score custody 3 out of 10.

Key facts

2016 socialised lossA 36% haircut applied to every customer after a hack, including accounts that were never touched, with repayment in dollars lateras of 14 Jul 2026
Proof of reservesA November 2022 blog post listing some wallet balances — assets only, no liabilities, no attestor. The promised periodic proof never arrived and the URLs now 404.as of 14 Jul 2026
"Insurance fund"Defined in Bitfinex’s own API documentation as the balance available to the liquidation engine — a derivatives backstop, not theft coveras of 14 Jul 2026
Custody score3 out of 10as of 14 Jul 2026
Effective cost, $10,000 BTC buy (measured by us)0.20%; 0.2162% at $100,000as of 14 Jul 2026
Order-book depth within 0.1% (measured by us)10.5 BTC — among the thinnest we measuredas of 14 Jul 2026
API response latency (measured by us)350 msas of 14 Jul 2026

Is Bitfinex safe? The 2016 precedent is the answer

One event tells you more about this venue than any current disclosure. After the 2016 hack, Bitfinex did not absorb the loss or pay out of a fund. It socialised it — imposing a 36% haircut on every customer account, including accounts the attacker never touched — and issued tokens that were eventually redeemed in dollars.

Holders were made whole in the end, which matters and is why this is not the worst incident record in our rating. What it established is more important than the outcome: this company has demonstrated that it regards customer balances as available to cover a loss the company failed to prevent. No other venue we rate has done that, and nothing since has revoked the precedent.

Today’s reserve evidence does not reassure. What exists is a November 2022 blog post listing some wallet balances, together with a promise to develop a periodic proof. It never arrived, and the proof-of-reserves URLs on the site now return 404. What that gives you is assets on one date four years ago, with no liabilities and nobody attesting it — which is not a proof of reserves in any sense that helps.

The insurance fund does not close the gap either. Bitfinex’s own API documentation defines it as the balance available to the liquidation engine, which is a derivatives backstop for bankrupt leveraged positions and not cover for stolen customer assets. We score custody 3 out of 10.

What it costs, and how thin the book is

A $10,000 bitcoin buy cost 0.20% on 14 July 2026 — twice the cheapest venues, half of Coinbase. Unremarkable in either direction.

The book is the problem. We measured 10.5 BTC of depth within 0.1% of best ask, among the thinnest of anything we priced and about a eighteenth of Kraken’s. Effective cost rose to 0.2162% at $100,000, and beyond that the depth binds hard.

API response latency measured 350 ms, mid-table.

Bitfinex retains a reputation for professional trading tooling that dates from an era when it carried far more of the market’s volume. On what we can measure today it is an averagely priced venue with a thin book and the weakest reserve disclosure in the rating.

Incident record

DateTypeAmountWere users made whole?
2 Aug 2016Hack or exploit—Eventually, and by a route nobody else has used: Bitfinex spread the loss across every customer with a 36% haircut, including accounts that were not touched, issuing tokens that were later redeemed in dollars. Holders were made whole in the end; the precedent is that the company treated every balance as available to cover a loss it did not prevent.source

In our ratings

Compared with

Our coverage of Bitfinex

Questions people ask

What happened to Bitfinex in 2016?

It was hacked and responded by socialising the loss: a 36% haircut applied to every customer account, including accounts the attacker never touched, with tokens issued that were later redeemed in dollars. Holders were eventually made whole, and the precedent it set stands.

Does Bitfinex have proof of reserves?

Not in any useful sense. A November 2022 blog post lists some wallet balances — assets only, no liabilities, no attestor — and the promised periodic proof never appeared. The proof-of-reserves URLs on its site now return 404.

Is Bitfinex’s insurance fund theft cover?

No. Bitfinex’s own API documentation defines it as the balance available to the liquidation engine — a derivatives backstop for bankrupt leveraged positions, not protection for stolen customer assets. No theft fund exists.

Is Bitfinex related to Tether?

The two companies share ownership history and have long been discussed together. For the stablecoin issuer’s reserves, attestations and profitability see our [Tether profile](/companies/tether); this page covers the exchange.

What changed

  • 27 Sept 2026 — Profile published.