← All categories
Finance
Trading apps that sell your orders, exchanges that sell surveillance tools to ICE, and buy-now-pay-later debt traps disguised as shopping features. $4.3B in fines and one suicide.
24 devices analyzed. Set your privacy comfort level to filter.
What we found
CoinSpot: F$2.4 million stolen from Australia's largest crypto exchange through a basic private key compromise.
On November 8, 2023, hackers drained 1,283 ETH ($2.4 million) from two CoinSpot hot wallets via a private key compromise. CertiK confirmed it was a "probable private key compromise." The stolen funds were laundered through THORChain and Wan Bridge to evade tracking.
Binance: FBinance said it had robust compliance programs.
DOJ settlement (November 2023): Binance pled guilty to conspiracy to violate the Bank Secrecy Act, operating an unlicensed money services business, and willful violation of IEEPA. Binance failed to report transactions associated with Hamas's Al-Qassam Brigades, Palestinian Islamic Jihad, Al Qaeda, and ISIS. Treasury Secretary Janet Yellen: "Binance turned a blind eye to its legal obligations in the pursuit of profit. Its wilful failures allowed money to flow to terrorists, cybercriminals, and child abusers." Total penalty: $4.316 billion -- the largest enforcement action in Treasury Department history.
Chase App: FJPMorgan's own due diligence flagged 27% of its mortgage loans as failing.
In November 2013, JPMorgan Chase agreed to pay $13 billion -- the largest settlement to a single corporation in DOJ history -- to resolve claims that it misled investors about mortgage-backed securities. JPMorgan admitted that its employees knowingly sold loans to investors that were shakier than claimed. Internal due diligence found 27% of loans were failing, but the bank packaged at least half of those into securities and sold them anyway. The settlement included $9 billion in cash and $4 billion in borrower relief. The deal was negotiated in secret and never subjected to judicial review. The loans helped trigger the 2008 financial crisis that cost millions of Americans their homes.
Swyftx: FSwyftx says your sensitive identity data stays with their compliance team.
Under the ATO data-matching program running since 2019, Swyftx shares names, contact details, wallet addresses, transaction records, and trade values with the Australian Taxation Office. In May 2024, the ATO confirmed it had requested personal and transaction details on 1.2 million Australian crypto users from exchanges.
Worldcoin / World ID: FSam Altman's company offered free crypto in exchange for scanning your eyeballs with a metal orb.
Worldcoin's iris-scanning Orb has been banned or investigated in Kenya, Spain, Portugal, France, Germany, Brazil, and India. Kenya suspended operations after finding Worldcoin collected biometric data without adequate consent. Spain's data protection authority ordered deletion of all data collected from Spanish citizens. The project, co-founded by Sam Altman, offered free crypto tokens in exchange for iris scans — targeting developing countries where people were most likely to trade biometric data for small payments.
NAB App: DNAB bankers forged customer signatures to create home loans that people never applied for.
NAB's "introducer" program paid third parties commissions for referring home loan customers. NAB bankers fabricated customer information, forged signatures, and falsified loan documents to push through mortgages. Some customers didn't know they'd applied for loans. The Royal Commission heard evidence of 20 NAB bankers under investigation; several were dismissed. Customers were left with mortgages they never applied for or couldn't afford. The "rigorous assessment" was a forged signature.
Westpac App: DWestpac processed 23 million transactions that violated anti-money laundering law.
AUSTRAC fined Westpac $1.3 billion in September 2020 for 23 million contraventions of AML/CTF laws — the largest fine in Australian corporate history. AUSTRAC found Westpac failed to adequately monitor transactions to the Philippines and Southeast Asia that were consistent with patterns used to pay for child exploitation material. Westpac's LitePay product enabled low-value international transfers with virtually no monitoring. The bank processed the payments. The children had no compliance framework.
CommBank App: DCBA's compliance team told management that Intelligent Deposit Machines were being used to launder money.
AUSTRAC fined CBA $700 million in June 2018 — the largest civil penalty in Australian corporate history at the time. CBA's Intelligent Deposit Machines were used for money laundering: 53,506 transactions went unreported, some linked to terrorism financing. CBA's compliance team flagged the issue years before regulators acted — management ignored the warnings. CEO Ian Narev resigned. AUSTRAC CEO Nicole Rose said: "The sheer scale of the non-compliance is significant."
How audits work in this category
Common standard: SOC 2 Type II / PCI DSS
What it covers: SOC 2 verifies security controls. PCI DSS verifies credit card data handling. Both are mandatory for payment processing.
What it misses: Neither covers what the app does with your transaction data beyond payments. Robinhood held both while selling order flow data. Revolut held SOC 2 during a period when 50,000+ customers were exposed to fraud.
Product Auditor Standard Trust signals
Revolut DUnknownSOC 2 Type II
Robinhood DUnknownSOC 2 Type II
Wise CDeloitteSOC 2 Type IIBig Four
Gold standard for this category:
  • Strong encryption
  • Transparent data sharing policies
  • Regulatory compliance (not just audit compliance)
  • Breach disclosure track record
Transparent fees, regulated in multiple jurisdictions, public incident reporting.
For the auditors' own track record, see Who Audits the Auditors?

Your privacy tolerance