The wrong time to investigate a crypto exchange is after withdrawals stop. Before sending rupees or crypto, check the company behind the platform, its Indian compliance status, how customer assets are held, whether withdrawals work and what protections actually apply.
No checklist can make an exchange risk-free. The goal is to reject weak or opaque platforms before they hold meaningful funds.
Quick 12-point checklist
| Check | Minimum evidence to look for |
|---|---|
| 1. Legal entity | Company name, jurisdiction, address and usable contact details |
| 2. FIU-IND status | Claim traceable to current FIU-IND material, not only an exchange advertisement |
| 3. Account ownership | Bank account and payment instructions match the disclosed business |
| 4. Withdrawal test | A small rupee and crypto withdrawal complete successfully |
| 5. Custody terms | Terms explain who controls assets and whether they may be lent or pledged |
| 6. Reserve evidence | Scope, date, liabilities and assurance provider are clear |
| 7. Account security | Strong MFA, withdrawal allowlist, device/session controls and alerts |
| 8. Incident record | Disclosed hacks, freezes and customer remediation can be researched |
| 9. Liquidity | Order book supports the intended trade size without excessive slippage |
| 10. Total fees | Trading, spread, GST, withdrawal and network costs are visible |
| 11. Support | A test question receives a specific and accountable answer |
| 12. Exit plan | Records are exportable and funds are not unnecessarily concentrated |
1. Identify the legal entity
A brand name is not enough. Find the company that operates the platform, where it is incorporated and which entity accepts customer money. Read the terms of service and privacy notice; these usually identify the contracting party more clearly than the homepage.
Warning signs include:
- no company name or physical address;
- support available only through Telegram or WhatsApp;
- payments requested to a changing personal bank account;
- terms that name a different business from the deposit instructions; and
- no explanation of which law governs a dispute.
Save a copy of the relevant terms when opening the account. Terms can change, and the version accepted may matter if there is a later complaint.
2. Verify the FIU-IND claim—and understand its limit
Virtual-digital-asset service providers covered by India’s anti-money-laundering framework are required to register with the Financial Intelligence Unit – India as reporting entities. FIU-IND publishes registration circulars and AML/CFT guidance for VDA service providers.
Do not rely only on an “FIU registered” badge. Check current FIU-IND resources and make sure the legal name matches the platform.
Registration is important, but it is not a government guarantee of:
- solvency;
- cyber security;
- price quality or liquidity;
- reimbursement after a hack;
- suitability of a token; or
- immediate access to customer funds.
Treat it as one compliance requirement, not a safety certificate.
3. Check where rupee deposits go
Before transferring funds, compare the beneficiary name with the disclosed operating entity or payment partner. Understand whether deposits use UPI, IMPS, NEFT or another rail, and read the limits and expected processing times.
Never send money to a personal account because someone claiming to be support says the normal channel is “under maintenance.” Contact the platform through a known official route if the beneficiary changes unexpectedly.
4. Test both kinds of withdrawal
A deposit test is incomplete without an exit test. Start with an amount small enough to lose without financial harm, then:
- withdraw rupees to the verified bank account;
- withdraw a supported crypto asset to an address you control, if on-chain withdrawal is part of the intended use;
- confirm the fee and processing time; and
- check whether unexpected manual reviews or extra payments are demanded.
Some legitimate withdrawals can be delayed by compliance checks. The red flag is an unexplained block combined with pressure to deposit more, pay a “tax unlock fee” or contact an unofficial agent.
5. Read the custody and asset-use terms
The balance shown in an app does not reveal how assets are held behind the scenes. Look for answers to these questions:
- Are customer assets segregated from company assets?
- Can the company lend, stake or pledge customer assets?
- Who controls the private keys?
- Are assets held with a third-party custodian?
- What happens if the company or custodian becomes insolvent?
- Which assets, if any, have insurance and what events are excluded?
If the terms grant broad rights to reuse customer assets, the user may be taking credit risk in addition to crypto price risk.
6. Do not confuse proof of reserves with a full audit
A proof-of-reserves report can show that an exchange controlled certain assets at a particular time. It can be useful, but it may omit liabilities, affiliated-company exposures and activity between snapshots.
Investor.gov warns that proof-of-reserves and similar reports are not equivalent to financial-statement audits. When reviewing one, ask:
- Which wallets and assets were included?
- Were customer liabilities independently tested?
- Is the report a snapshot or continuous evidence?
- Who performed the work and what assurance standard was used?
- Can an individual customer verify inclusion without exposing private data?
An exchange claiming that a reserve snapshot makes insolvency impossible is overstating what the evidence shows.
7. Evaluate account-security controls
At minimum, enable a unique password and multi-factor authentication that does not depend only on SMS. Hardware security keys or authenticator apps generally reduce exposure to SIM-swap attacks, although no method removes every risk.
Useful exchange controls include:
- withdrawal-address allowlists;
- a delay after a new withdrawal address is added;
- new-device and new-login alerts;
- active-session management;
- anti-phishing codes in legitimate emails; and
- the ability to disable account recovery through weak channels.
CERT-In warns that phishing commonly uses urgent messages and copied branding. Reach the exchange through a bookmark or typed address, not an unexpected link.
8. Research the incident and withdrawal history
Search the company and legal entity with terms such as “hack,” “withdrawal freeze,” “data breach,” “complaint” and “insolvency.” One complaint does not prove misconduct, but repeated reports with the same pattern deserve investigation.
For a past incident, examine what the company disclosed, how quickly it communicated, whether customers were made whole and what changed afterward. Silence or deletion of reasonable questions is a poor trust signal.
9. Check liquidity, not only listed coins
An exchange can list hundreds of assets and still offer poor execution. Inspect the spread and order-book depth for the exact trading pair.
Estimate the average execution price for the intended order size. A low headline fee does not compensate for several percent of slippage on a thin market.
10. Calculate the total cost
Record:
- maker and taker fees;
- spread between bid and ask;
- rupee deposit and withdrawal charges;
- crypto withdrawal fees;
- network fees and any exchange markup;
- applicable GST treatment; and
- currency-conversion costs.
The cheapest-looking platform can be expensive once spread and withdrawal costs are included.
11. Test support before there is a crisis
Ask a specific question about withdrawals, custody or fees. A useful response should address the question and link to the relevant policy. A generic reply telling the user to “wait patiently” does not demonstrate operational competence.
Use only support channels linked from the official application or domain. Administrators who message first on social media are often impersonators.
12. Plan for records and concentration risk
Export transaction history regularly and keep deposit, trade, fee, transfer and withdrawal records outside the platform. Those records can be needed for tax reporting, source-of-funds checks or a complaint.
Do not keep more on one platform than the intended purpose requires. Self-custody removes exchange-counterparty risk but replaces it with private-key, backup and transaction risk. Anyone choosing it should learn on a small amount, verify backups and never store a seed phrase in email, cloud notes or a chat.
If something goes wrong
Preserve screenshots, transaction hashes, beneficiary details, support tickets and the exact URLs used. Contact the exchange and bank through verified channels.
For suspected financial cyber fraud in India, the National Cyber Crime Reporting Portal instructs users to call 1930 immediately and file at cybercrime.gov.in. Speed can matter when authorities and financial intermediaries attempt to stop funds from moving further.
Bottom line
An exchange deserves trust only after its identity, compliance claims, withdrawals, custody terms, security and costs survive scrutiny. FIU registration and proof of reserves can be useful evidence, but neither replaces the rest of the checklist.
Advertisement
Sources and review
This article was checked against the primary or authoritative sources below on .
- VDA service-provider guidance and registration circulars — Financial Intelligence Unit – India
- Investors should exercise caution with alternatives to financial-statement audits — Investor.gov
- Preventing online scams — CERT-In
- National Cyber Crime Reporting Portal — Indian Cybercrime Coordination Centre
Frequently asked questions
No. FIU registration is an anti-money-laundering compliance check. It does not by itself prove solvency, cybersecurity, fair execution or that every customer withdrawal will be available on demand.
No. A proof-of-reserves report can be a point-in-time view of selected assets and may not show all liabilities, related-party exposures or what happens between snapshots.
Exchange custody and self-custody have different risks. Users considering self-custody should first learn seed-backup, address-verification and transaction safety with a small amount.
Advertisement