There are 381 neobanks worldwide, but only 25 currently operate with a crypto licence, according to NeobankBeat. The gap reflects how difficult it is to turn a crypto product into a financial service that banks, payment partners and customers are willing to trust.
For a crypto neobank, credibility is part of the product. Crypto services still carry a higher due-diligence burden than conventional banking products, so operators need to show more than a polished app and a list of partners. They need evidence that their controls can withstand external scrutiny.
This article breaks down the main assurance signals and what they prove: licensing, certifications, security audits, bug bounties and custody. We then apply the same criteria to five crypto neobanks: ether.fi Cash, KAST, Plasma One, Tria and Kolo, comparing what each discloses publicly and how far that evidence goes.
What does a crypto neobank need before anyone trusts it with money?
More than one document. A crypto neobank that expects deposits shows six layers of evidence:
- Licences for the regulated activities it performs
- Security certifications (ISO 27001, SOC 2) and resilience regulation (DORA)
- Smart contract audits
- Penetration testing
- A bug bounty
1. Which entity holds which license?
A crypto neobank's operations break down into five legal and operational functions:
- Neobank Ltd provides crypto-asset services. In the EU, these generally require authorisation under MiCA. Other jurisdictions run their own regimes, such as VARA in Dubai and the Monetary Authority of Singapore (MAS) under the Payment Services Act.
- Neobank Payments Ltd provides fiat and payment services. Depending on the activity and jurisdiction, this needs an Electronic Money Institution (EMI), Payment Institution (PI), bank or other authorisation.
- Issuer X issues the Visa or Mastercard card. It needs both the regulatory authorisation and the card-scheme approval, and those are separate.
- Processor Y provides payment-processing infrastructure. A pure technical provider can support a regulated institution without its own licence. A processor that performs regulated services needs one.
- Custodian Z holds and administers users' crypto-assets. In the EU, that is a regulated service under MiCA and requires CASP authorisation.
One entity can perform several of these functions and outsource the rest. What counterparties check is which legal entity performs each regulated activity, and which authorisation covers it. A neobank can market itself in 40 countries while one entity in its chain is authorised in none of them.
Why does the legal entity matter more than the brand?
A crypto brand can market the card under its own name while another regulated entity issues it. Look at the Wirex example below:

Wirex Limited holds UK FCA authorisation for its e-money activities, while its crypto services have involved Wirex Digital Services S.r.l., an Italian company registered with OAM. One brand, two regulatory frameworks.
2. Security certifications and DORA
ISO/IEC 27001 certifies an information security management system (ISMS). It covers how you identify security risks, define controls, manage access, review those controls and respond to incidents. A counterparty's risk team can read your certificate scope instead of auditing you themselves.
SOC 2 is an independent auditor's report on your controls against the Trust Services Criteria, with security as the most common category. A Type I report assesses whether controls are suitably designed at a point in time. A Type II report also tests whether they operated effectively over a period, commonly 3 to 12 months. SOC 2 vs ISO 27001 covers which one your counterparty is likely to accept.
The Digital Operational Resilience Act (DORA) is an EU regulation for financial entities in scope, including CASPs and payment institutions. It sets requirements for ICT risk management, incident reporting, resilience testing and ICT third-party risk. DORA also requires a register of contractual arrangements with ICT third-party service providers, and for a card programme, that register typically includes the processor. What DORA requires walks through the obligations if you're still preparing.
All five neobanks we reviewed point to the same certificate: Rain's SOC 2. That report covers the issuer's controls. It doesn't cover the neobank's app, wallet or backend.
3. Smart contract audits
A smart contract audit finds vulnerabilities in the on-chain code your neobank relies on, and the report doubles as evidence for users, banks and partners. Two limits decide what it's worth:
- Scope: code outside the audit gets none of its protection.
- Version: the audit covers the code as the reviewers saw it, and every later deploy can introduce new vulnerabilities.
The August drain hit both. The attackers used deprecated infrastructure that the audit never covered.
A trust benchmark for audits:
- Audit the contracts your neobank uses, including critical integrations with card infrastructure.
- Publish the audit scope and the reviewed versions.
- Publish remediation status for every finding.
- Re-audit after material code or architecture changes.
Our other article, the smart contract audit process shows how a review runs end to end.
4. Penetration testing
A smart contract audit reviews on-chain code. A penetration test looks for weaknesses in everything around it: the app, APIs, authentication, backend, cloud infrastructure and admin interfaces. Attackers don't need to break a contract they can route around. In Q2 2026, keys, signers and infrastructure accounted for 88.3% of losses, according to Hacken's Q2 2026 security report.
In many setups, pentesting is a formal requirement:
- DORA requires financial entities in scope to run an ICT security-testing programme.
- PCI DSS requires it for cardholder-data environments.
- MAS, APRA and the HKMA require it for the institutions they regulate.
- ISO 27001 and SOC 2 can use it as control evidence, though neither makes it mandatory.
Certain DORA entities must also undergo threat-led penetration testing (TLPT). During it, you identify your critical functions and the systems behind them, and testers run a realistic attack scenario against them.
5. Bug bounties
A bug bounty pays independent researchers to report vulnerabilities instead of exploiting them. Two things decide whether it protects you:
- Scope: which assets researchers are allowed to test.
- Reward pool: how much you pay, and for which severity.
A large reward means little if the programme excludes the systems handling customer funds. Gnosis Chain's bounty offers up to $2 million, but a protocol-level bounty may not cover Gnosis Pay's card infrastructure, and the card module is what got exploited in June 2026.
What five crypto neobanks disclose publicly
If a bank, fintech, or institutional counterparty is assessing a crypto card programme, the first step is often desk research: checking the issuer, licences, assurance reports, security testing and vulnerability disclosure programme.
Hacken did research on some popular neobanks across these trust metrics. We reviewed Ether.fi Cash, KAST, Plasma One, Tria, Kolo. Here are the results of our due diligence:

A few points are worth noting about the research.
Firstly, it was based solely on public sources, and the real result may be quite unpublished, but present.
Also, all five neobanks use Rain as an card issuer or issuing partner. As a result, Rain's SOC 2 report appears across the products, but that does not make it a certification of the neobanks themselves.
Three of five do not disclose a bug bounty. For the other products, we did not find public evidence of a neobank-specific audit or bounty programme in our review.
Licensing evidence is not uniform. Some products point to licences or regulated partners, while others provide less direct evidence in their public materials.
So what makes a crypto neobank trustworthy?
A paper trail. Every layer covers a defined part of the business, and counterparties check where each one stops.




