Choosing an exchange cannot be done solely by comparing fees, the number of currencies, or the appearance of the application. Information such as the legal identity of the company, the status of its licenses, how user assets are stored, the history of security incidents, and the quality of withdrawals are also important; however, this information is not published in a common format among Iranian exchanges.
Mihan Blockchain has defined 30 specific criteria for this review and has assessed 17 exchanges present in its comparison service using the same criteria.
This index does not issue a definitive ruling on whether an exchange is safe or not. The status of exchanges changes, and part of the risk also relates to how each user utilizes them. For this reason, we have also included items that you should check yourself before depositing money.
Comparing the services of Iranian exchanges, comparison guides typically put fees, the number of markets, deposit and withdrawal networks, applications, and trading features side by side. This information is useful for everyday selection. The current index focuses on another aspect: Are the claims of the exchange regarding identity, reserves, security, and market quality verifiable?
Reviewing the problems of Iranian exchanges shows that having many features does not always mean less risk. Withdrawal delays, long disruptions, weak responsiveness, or ambiguity regarding the exchange's responsibilities can directly harm users. For this reason, the number of tokens or the appearance of the application has not been included in the resilience score.
An exchange may provide a good user experience but publish little information about its reserves or legal structure. Another exchange may have fewer features but provide clearer documentation. The table shows this difference so that users do not base their choices solely on advertisements.
As a result, an exchange does not receive a score of zero for not publishing information; however, several general claims are not enough to achieve a high ranking. The <
The guidelines for the establishment, operation, dissolution, and supervision of cryptocurrency brokers by the Central Bank serve as the internal benchmark. This text outlines the requirements for establishment licenses and operational permits, capital, qualifications of managers, corporate governance, internal controls, anti-money laundering, audited financial statements, debt ratios, liquidity ratios, guarantees of performance obligations, proof of reserves, and conditions for license cancellation or dissolution.
According to a report by Mihan Blockchain, the approved minimum capital for type one is 400 billion IRR and for type two is 4,000 billion IRR. The final text differs from the draft of Shahrivar 1404; therefore, the assessment should be based on the latest approved version and any subsequent amendments, not on figures left from previous versions on the web.
A license is an important and critical criterion, but a license does not equate to guaranteeing user assets. The supervisory body can set the framework for entry and operation; however, independent assessments must still evaluate capital, liquidity, reserves, control quality, security incidents, and the ability to process withdrawals separately.
In Dey 1404, the Central Bank announced that no cryptocurrency exchange has its official license. This statement describes the situation as of that date and should not be generalized to 1405 without fresh examination. In each reporting period, the license status is only verifiable from the regulator's public list, a written response from the authority, or a document with a number and verifiable validity. If such a document is not available, the status is Unknown; neither Unlicensed nor Licensed.
Proof of reserves is not an audit of financial statements.
The PCAOB guide on Proof of Reserve reports warns that PoR is not an audit. These reports typically provide a snapshot of assets at a specific time and may not cover liabilities, customer rights, borrowed assets, internal controls, and the status after the report date.
Mihan Blockchain's article on the necessity of proof of reserves in Iranian exchanges has brought the issue of exchanges' access to sufficient assets into public discussion. However, in the current index, merely displaying a few wallet addresses or announcing a 100% ratio does not earn full credit.
Mihan Blockchain's Proof of Reserve guide also explains that proof of reserves can indicate the existence of assets but has inherent limitations. Therefore, the index separates five topics: asset segregation, custody model, coverage and frequency of PoR, proof of liabilities, and limitations on the use or collateralization of reserves.
PoR holds more value when the user can review their share of the total liabilities, the asset list is comprehensive, addresses and calculation methods are clear, off-balance-sheet obligations are not omitted, and the independent evaluator explicitly states the limitations of the work. Even in this case, PoR gains meaning alongside audited financial statements and custody controls, not as a substitute for them.
International Benchmark Patterns
Kaiko's ranking of centralized spot exchanges evaluates them across six dimensions: Governance, Business, Technology, Data Quality, Security, and Liquidity. The Mihn Blockchain Index adopts Kaiko's multi-dimensional and weighted structure but redesigns it for the risks of the Iranian market: financial resilience and custody receive independent weights, and evidence coverage is published separately from the score.
The FSB and IOSCO framework for digital asset markets focuses on conflicts of interest, market manipulation, customer asset protection, operational and technological risks, regulatory cooperation, and distribution to retail customers.
The final IOSCO report also considers the segregation of customer assets, disclosure of custody models, management of conflicts between trading, market-making, and asset custody, and market transparency rules as key to investor protection. These criteria have been incorporated into the columns of custody, market quality, governance, and user rights.
30 criteria have been examined in six groups: legal and regulatory status, financial health, asset custody and reserves, security and service continuity, market quality and withdrawal, and information transparency and user rights. The importance of all criteria is not equal; for example, reserves and withdrawal capabilities carry more weight than the apparent features of the platform. The tables below show the precise definition of each criterion.
To read the final result, it is not necessary to know all the technical details of this section. These tables have been published for clarity in the review method.
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| G1 | Legal identity, registration ID, and official address | The legal name, registration number, national ID, address, and a clear relationship between the brand and the published company must be available. | 4 | Yes |
| G2 | License or license application status | The type of license, issuing authority, number, scope, and validity date must be verifiable from the regulatory source. | 5 | Yes |
| G3 | Ultimate ownership and key managers | Effective shareholders, ultimate beneficiaries, board members, and senior managers with verifiable backgrounds must be disclosed. | 4 | No |
| G4 | Control structure and conflict of interest | Audit, risk, and compliance committees, independence of controls, and documented conflict of interest policies must be in place. | 4 | Yes |
| G5 | AML/CFT, KYC, and transaction monitoring | Policies for identity verification, anti-money laundering, counter-terrorism financing, and transaction monitoring must be clear and up-to-date. | 3 | No |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| F1 | Audited Financial Statements | The latest financial statements, notes, independent auditor's opinion, and specified financial period must be available. | 5 | Yes |
| F2 | Capital Adequacy and Source of Capital | Registered capital and its compliance with the type of activity and minimum requirements, along with reliable documentation, must be specified. | 4 | Yes |
| F3 | Debt Ratio | The debt ratio must be calculated based on the audited financial statements and compared with regulatory limits. | 4 | No |
| F4 | Current and Liquidity Ratios | The ability to cover current liabilities with liquid assets must be assessed based on audited data. | 4 | Yes |
| F5 | Guarantee of Commitments and Recovery/Exit Plan | Assurance of commitment fulfillment, financial continuity plan, customer repayment, and clear exit or dissolution procedures must be provided. | 3 | Yes |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| C1 | Separation of Client Assets from Company | Client funds and crypto assets must be maintained in segregated accounts and wallets, and this separation must be documented. | 5 | Yes |
| C2 | Custody Model and Key Control | The custodian, storage location, key control, multi-signature/MPC, geographical distribution, and third-party disclosures must be provided. | 4 | Yes |
| C3 | Proof of Reserves: Coverage and Frequency | Covered assets, addresses, time of snapshots, frequency, and PoR verification methods must be clear. | 4 | No |
| C4 | Proof of Liabilities and User Verification Capability | Liabilities to clients, off-balance sheet commitments, and Merkle/individual verification methods must be within the scope of review. | 4 | Yes |
| C5 | Collateral, Borrowing, and Reserve Usage Restrictions | Borrowing assets for the evaluation day, collateralization, lending, or corporate use of reserves must be reviewed and disclosed. | 3 | Yes |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| S1 | Security Audit and Standards | Independent audit, test scope, date, evaluating entity, and standards such as ISO 27001 or equivalent controls must be documented. | 3 | No |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| S2 | Hot/Cold Architecture and Withdrawal Control | The ratio of cold storage, hot wallet limits, multi-signature, whitelisting, and withdrawal controls must be explained. | 3 | Yes |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| S3 | Incident History and Response Quality | Significant incidents, discovery time, damage scope, communication, compensation, and post-incident corrections should be recorded. | 3 | Yes |
| S4 | Business Continuity and Crisis Recovery | RTO/RPO, backup, alternate site, crisis testing, and public status page should be documented. | 3 | No |
| S5 | User Account Security and Vulnerability Disclosure | 2FA, anti-phishing, session management, withdrawal notifications, bug bounty program, and vulnerability reporting path should be in place. | 3 | No |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| M1 | Reliable Volume | Volume with raw data, method for removing self/constructed trades, and the ability to reproduce calculations should be supported. | 3 | No |
| M2 | Depth, Spread, and Price Slippage | Order depth at specified levels, spread, and slippage for standard order sizes and major pairs should be measured. | 4 | Yes |
| M3 | Liquidity Stability Under Stress | Market quality during low depth hours, price spikes, banking disruptions, and operational crises should be tested. | 3 | No |
| M4 | Market Surveillance and Trading Conflicts | Control of manipulation, wash trading, employee trading, dependent market making, and market halt processes should be clear. | 3 | Yes |
| M5 | Performance and Withdrawal Rules | Real-time processing, limits, network fees, scheduled stops, and withdrawal SLA should be recorded. | 2 | Yes |
| Code | Criterion | Operational Definition | Weight | Critical |
|---|---|---|---|---|
| D1 | Fees and Change History | Transaction fees, deposits, withdrawals, and ancillary services along with change history and calculation examples should be published. | 2 | No |
| D2 | Quality of Public Data and API | Transactions, order book, OHLCV, API documentation, rate limits, and finality status should be accurate and verifiable. | 2 | No |
| D3 | Terms of Use and Risk Disclosure | Asset ownership, liability limits, sanction risks, asset blocking, asset deletion, and changes to terms should be clear with version and date. | 2 | Yes |
| D4 | Complaints, Support, and Dispute Resolution | Official complaint channel, response time, escalation path, complaint resolution statistics, and dispute resolution authority should be specified. | 2 | No |
| D5 | Privacy and Data Incident | Type of data collected, location/duration of storage, sharing with third parties, user rights, and data breach disclosure procedures should be clear. | 2 | Yes |
For each score, the source and review date are recorded; from official documents and financial statements to the exchange's own page, on-chain data, API, or verifiable media reports. If sufficient evidence is not found, the result remains <
Evaluating sources is not uniform. The regulatory authority's document, audited financial statements, and reproducible data carry more weight than promotional claims. Information provided by the exchange itself is assessed only after being matched with an independent source.
The date of the document is also important. Licenses, withdrawals, and security incidents are re-evaluated with each update; market data must be fresh, and annual financial statements should be updated.
Mihan Blockchain collects the official company name, website, registration number, national ID, CEO details, year of operation, office address, official channels, appointed representative, and a copy of the establishment advertisement from each exchange. This information helps connect the exchange's brand to the registered company and its official accountability pathway.
The form information is matched with the official gazette or registration systems. The result of this section can be one of three states: <
The CEO's national ID, representative's contact information, office address and postal code, economic code, and uploaded files are not published in the article. Only the necessary information for public introduction and verification of the exchange is displayed.
The existence of guidelines does not, by itself, clarify the status of any exchange. The public list of licenses, type of license, scope of services, and validity date must be reviewed as of the data cutoff date. This indicator distinguishes between <
A wallet address may indicate the existence of some assets; however, without liabilities to customers, off-balance sheet commitments, ownership, and lack of collateralization, no conclusions about repayment ability can be drawn. Therefore, PoR in this indicator is only four points out of 100; the custody and reserves set carry 20% weight, and the financial statements are assessed separately.
The Excoino case in Mihan Blockchain shows that prolonged withdrawal delays, quality of communication, order of payment claims, and user access to legal pathways must become independent indicators. Brand longevity or user count does not replace settlement capability. In evaluating individuals, each claim is assessed solely based on published documents and the official response of the party being evaluated.
The dissection of the Nobitex hack highlighted the importance of hot and cold wallet architecture; however, the security indicator does not solely award points based on the percentage of cold storage. The time of discovery, scope of the incident, service continuity, communication, compensation, control adjustments, and the ability to verify reports post-incident also have separate scores.
The report on the status of Iranian exchanges following cyberattacks in June 2025 showed that a single incident could simultaneously halt deposits and withdrawals across multiple platforms. This shared dependency must be considered in the business continuity test and stress scenario.
Mihan Blockchain's guide on the ability of Iranian exchanges to protect assets explains the difference between hot and cold wallets and user account controls. This indicator connects these controls to the document, testing frequency, and quality of incident response.
Risk analysis of custody and sanctions on Iranian exchanges indicates that limited access to infrastructure, stablecoin issuers, foreign custodians, or cloud services can affect user assets. The exchange must explain significant dependencies, the blockage scenario, and the secure asset transfer plan.
The liquidity article points out the issue of fabricated volume as a measure for evaluating exchanges. Instead of relying on volume numbers, the index assesses order depth, spread, price slippage, liquidity concentration, and market behavior during stressful hours. Data must be reproducible with specified order size and sampling time.
The cryptocurrency insurance guide explains that exchange insurance is not necessarily government coverage or a complete loss guarantee. In the index, merely using the term "insurance" does not score points. The insurer's name, policy, total cap, user, deductible, exclusions, types of covered events, and claims history must be verifiable. An internal fund without financial statements and clear withdrawal rules is, at best, considered limited.
Before publishing the score of any exchange, an authentication form is first submitted to connect the brand to the legal entity and official representative. Then, a table of evidence, registration discrepancies, and unknown cases is provided to the same representative, allowing at least five working days for a response. A response only changes the score if it provides a document that meets the same criteria and is verifiable. Completing the identity form, promotional text, or unsubstantiated claims cannot replace financial statements, PoR, security audits, or market data.
Conflicts of interest must also be disclosed alongside the results: advertising, business cooperation, affiliate relationships, sponsorship, or any financial relationship between the media and the exchange. The sales or advertising team does not interfere in scoring. Any score changes after publication are recorded in the changelog with the date, reason, changed criteria, and previous version.
The table of Mihan Blockchain is the starting point for review. Even an exchange that has published more information may later face disruptions, hacks, or regulatory limitations. Before use, check these items according to your needs and amount:
Not having a score does not necessarily indicate misconduct or insecurity. In many cases, public information has been insufficient. For the user, this lack of information is a decision-making factor, as it indicates a risk that cannot currently be accurately assessed.
No. PoR can indicate the existence of assets at a given time, but it may not cover liabilities, borrowed assets, collateralization, internal controls, and the status after the reporting date.
No. A license indicates regulatory status. Reserves, liquidity, custody, security controls, and withdrawal capabilities must be assessed separately.
Volume can be inflated or artificial. Order book depth, spread, price slippage, and liquidity stability under stress provide more accurate information.
Sensitive data from the form, including national ID, representative contact information, address, postal code, and uploaded files, are not published in the public domain and access to them is restricted. Public scores should rely on verifiable witnesses or results of verifications that can be explained without disclosing personal data. Any potential financial relationship between the media and the exchange is also disclosed separately.
This indicator shows the level of transparency of verifiable information at a specific date. Its result does not guarantee future security, compensation, or withdrawal capability under any circumstances. Mihn Blockchain periodically updates the published data and documents; users should also review fees, withdrawals, support, security settings, and the amount of assets at risk according to their circumstances before depositing money.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.






















![[Editorial] The Rails Are Laid Before the World Notices](/public-static/8_1497610e7c.png?format=avif)






