Riven Trust Research / Evidence Study

Crypto Bot Security Study

Abstract

This study analyzes security evidence stored for 54 crypto automation products in Riven Trust's current dataset. It compares external API authority, verified no-withdrawal controls, public security documentation, independent platform-audit evidence and execution architecture. The strongest dataset-wide gap is independent assurance: product documentation is common, but a company statement is not an audit and an audit of a token or isolated component does not establish platform-wide security. Findings are product-level counts generated from structured records. The dataset is selected rather than exhaustive, documentation and regional availability can change, and unavailable evidence does not prove that a control is absent.

Dataset 2026-08.4Coverage 54 productsPublished August 21, 2026Reviewed August 21, 2026
RT
Research byRiven Trust Research Desk

Product research, evidence review and claim verification

Key findings

Security evidence is uneven across architectures

Key finding40/54

API-permission evidence

Verified or partially verified product-level evidence for the external API permission model.

Key finding20/54

Verified no-withdrawal evidence

A supported prohibition for the external key; native exchange cases remain Not Applicable.

Key finding42/54

Meaningful security documentation

Dedicated security material or sufficiently detailed supported controls.

Key finding0/54

Independent platform audits linked

Token and isolated-component audits do not count as platform-wide assurance.

Security disclosure findings

Security disclosure across the current product dataset54 products; product-level statistics
External API permission model documented40 of 54 · 74%

Verified or partially verified for products that use an external key.

No-withdrawal model verified20 of 54 · 37%

Native exchange cases are Not Applicable rather than counted as external-key controls.

Meaningful public security documentation42 of 54 · 78%

Documentation is evidence of disclosure, not proof of implementation effectiveness.

Independent platform-security audit linked0 of 54 · 0%

The audit must match the trading platform's actual scope.

Unresolved performance or AI claims30 of 54 · 56%

Products with at least one relevant claim not fully verified.

Source: Riven Trust, Dataset 2026-08.4 · Reviewed August 21, 2026

Architecture distribution

Architecture changes who is responsible for secrets, uptime, custody and patching. Hybrid products can expose more than one model.

Execution architecture represented in the dataset54 products; categories can reflect hybrid scope
Cloud SaaS or other hybrid27 of 54 · 50%
Self-hosted or local hybrid12 of 54 · 22%
Exchange-native bots12 of 54 · 22%
Managed strategies3 of 54 · 6%
Source: Riven Trust, Dataset 2026-08.4 · Reviewed August 21, 2026

Method and source context

All headline statistics are product-level counts generated during the build from typed trust factors, public source records, architecture fields and claim statuses. They must not be compared directly with the 168 claim-level records or 328 source-level records as though those denominators measured the same thing.

Primary sources establish what a provider publishes. Regulator and company-registry records establish only their stated jurisdiction and entity scope. Independent high-authority work requires a relevant method and accountable publisher; independent reporting adds context. Multiple company-controlled URLs remain one provider's evidence, not independent corroboration.

“Documented” does not mean penetration-tested. Missing audit evidence is not proof of insecure software, and no execution architecture is universally safest.