Who may find this file useful
Security-conscious users who will configure strong account controls and distinguish Kraken Exchange, Kraken Pro and Kraken Wallet before acting.
Operator & custody investigation
This investigation reads Kraken’s security, proof-of-reserves, entity and fee claims against the limits stated in its own primary documents.
Editorial assessment: Kraken presents a useful set of account-security controls and a comparatively inspectable proof-of-reserves process. The same evidence requires restraint: a snapshot is not a solvency audit, and EEA services may pass through different entities depending on the activity.
Security-conscious users who will configure strong account controls and distinguish Kraken Exchange, Kraken Pro and Kraken Wallet before acting.
The platform publishes meaningful control and reserve evidence, but the evidence is scoped, point-in-time and unable to answer every liability or service-quality question.
Public evidence has been reviewed; account, funding, trading, withdrawal and support scenarios are specified as controlled routes with defined inputs and records.
Evidence-backed strengths
Material limitations
Kraken Exchange is custodial; Kraken Wallet is a separate self-custody application.
Global and EEA terms allocate services across different entities; the relevant activity must be matched to its contract.
Kraken documents platform and account controls plus point-in-time reserve verification, with explicit limitations.
Instant and Pro pricing differ. Funding methods can impose 72-hour or seven-day withdrawal holds.
Investigative analysis
Each conclusion is tied to the primary records immediately below it. Links open the publisher’s original material.
Kraken’s own help centre distinguishes its custodial Exchange from Kraken Wallet, where the user holds the recovery material. This is not a cosmetic product split: it changes who can restore access, impose account restrictions and authorise transfers.
Sources: Kraken Support · KrakenThe EEA terms allocate crypto-asset, e-money and certain investment or derivative services among Irish and Cypriot entities. That granularity is useful evidence, yet it prevents a blanket claim that every feature a European visitor sees has the same permission or counterparty.
Sources: Kraken · KrakenKraken documents cold/hot-wallet practices, passkeys, granular two-factor authentication and Global Settings Lock, alongside ISO 27001 and a SOC 2 Type 1 examination. These records support the existence of controls; they do not show that every user enabled them or that the examination covered every product, threat and future period.
Sources: Kraken · KrakenThe reserve page reviewed for this edition displayed a 30 June 2026 snapshot and a route for customers to check Merkle inclusion. Kraken also identifies point-in-time and encumbrance limitations. We therefore treat PoR as evidence about selected balances at a date, not a financial-statement audit or solvency guarantee.
Sources: KrakenKraken’s fee schedule separates consumer Instant transactions from the Kraken Pro maker/taker model. Its funding documentation also records methods that may be processed quickly while imposing a 72-hour or seven-day withdrawal hold. Comparing only arrival time would omit the condition most relevant to an urgent exit.
Sources: Kraken · Kraken SupportThe SEC’s 2023 staking settlement is a primary record about a specific US service and period. It is material context but does not by itself establish the status of every current Kraken product. Current contracting terms and registers still need to be read beside that history.
Sources: US SEC · Kraken · KrakenClaim → evidence → gap
Each module keeps the decision consequence beside the evidence and the unresolved gap. Primary material was retrieved on .
Kraken documents a comparatively granular control set.
The documentary record supports a reproducible Pro scenario.
The procedure is scoped and point-in-time.
Published funding methods can carry 72-hour or seven-day holds.
Adjacent sources: Kraken Support · Kraken
Adjacent sources: Kraken
Adjacent sources: Kraken
Adjacent sources: Kraken
Adjacent sources: Kraken Support
Adjacent sources: Kraken
Accountable scenario file
Each row specifies a fixed protocol with defined inputs and record.
Fixed inputs: One entity, rail, amount and verified account.
Record: Deposit cost, tradable time, withdrawable time and notices.
PublishedFixed inputs: Passkey, 2FA and Global Settings Lock on a no-value account.
Record: Sensitive-setting change, recovery dependencies and delay enforcement.
PublishedFixed inputs: Fixed pair, notional and UTC window; market plus passive limit.
Record: Depth, spread, fee, fill, slippage, cancellation and API parity.
PublishedFixed inputs: Named entity and one non-urgent written request.
Record: Consent controls, response owner, accuracy and escalation route.
PublishedChange timeline
Product-specific permissions remain a live diligence question.
Reserve evidence must keep its asset and time boundary.
Scenario parameters can now be frozen.
Alternatives
Listed-company disclosure and a familiar retail route outweigh security-setting depth.
Broader markets/APIs are essential and the local entity is clearly available.
Conclusion control
Method
Change log
Added ten claim files and four reproducible control, funding, execution and remedy scenarios.
FAQ
No; it is self-custodial.
No; it is scoped point-in-time evidence.
Yes, depending on the documented method.
It can slow sensitive changes; its recovery/bypass path is recorded as a fixed verification input.
Reviewed on by Candid Ledger Editorial Team; independent editorial review by Candid Ledger Review Team.