Original research · Reviewed August 19, 2026

Crypto bot security study: 15-platform evidence review

We analyzed the structured evidence in every current product profile to measure disclosure—not to declare any platform safe. Counts update automatically when product data changes.

RT
Research byRiven Trust Research Desk

Product research, evidence review and claim verification

What did the study find?

Among the 15 platforms in our current research dataset, 13 have supported public evidence for their API permission model, 10 have verified evidence for a no-withdrawal model, and 0 include a publicly linked independent platform-security audit in our source records.

Security disclosure findings

API permission model documented13 of 15 · 87%

Verified or partially verified in the structured trust profile.

No-withdrawal model verified10 of 15 · 67%

A clear prohibition or non-applicable built-in model supported by reviewed evidence.

Meaningful public security documentation15 of 15 · 100%

Dedicated security material or sufficiently detailed supported controls.

Independent platform-security audit linked0 of 15 · 0%

A public audit of a token or unrelated component does not count as assurance for the trading platform.

Unresolved performance or AI claims7 of 15 · 47%

Products with at least one relevant claim not fully verified.

Architecture distribution

Architecture changes who is responsible for secrets, uptime and patching. The categories below are simplified for cross-product comparison; hybrid products may expose more than one model.

Cloud or hybrid SaaS11 of 15 · 73%
Self-hosted or self-hosted hybrid3 of 15 · 20%
Custodial exchange bots1 of 15 · 7%

How the counts are calculated

Every value is produced during the build from product trust factors, source types, architecture categories and stored claim statuses. “Documented” means the current dataset contains supporting public evidence; it is not a penetration test. “Independent audit linked” requires a source record that explicitly identifies independent audit or assurance coverage for the platform.

Unknown information remains unknown. We do not infer that a missing audit means insecure software, or that published security language proves implementation effectiveness.