Skip to content

EU9MY3 Crypto Resource

FIU Registered Crypto Apps in India 2026: Verify the Company, App and Device

  • Author: EDITORIAL TEAM
  • Last updated:
  • Educational information

FIU Registered Crypto Apps in India 2026: Verify the Company, App and Device content

Last updated: 2026

Author: EDITORIAL TEAM

Affiliate disclosure: This page may contain affiliate links. We may receive a commission when a reader registers or uses a service through one of these links, at no additional cost to the reader. Commercial relationships do not determine whether an app is described as registered, secure or suitable. Registration and security claims should always be checked independently before depositing money.

Financial-risk notice: Cryptocurrency and other Virtual Digital Assets are volatile and highly risky. FIU-IND registration does not protect your capital, insure your deposits, guarantee withdrawals or certify an app as secure. This guide is for general information and is not financial, investment, legal or tax advice.

Quick Answer: What Are FIU-Registered Crypto Apps in India?

An FIU-registered crypto app is a mobile application operated by, or connected to, a Virtual Digital Asset Service Provider registered as a reporting entity with the Financial Intelligence Unit–India.

The important detail is that the app itself is not what FIU-IND registers. Registration normally applies to the legal entity providing the VDA service.

That distinction creates two separate checks:

  1. Is the company behind the service registered with FIU-IND?
  2. Is the application on your phone genuinely published or authorised by that company?

Passing the first check does not automatically mean the second check has been passed.

A legitimate FIU-registered company can still be impersonated through:

  • A cloned Google Play listing
  • A fraudulent APK distributed on Telegram or WhatsApp
  • A misleading search advertisement
  • A fake customer-support page
  • A copied login screen
  • A remote-access scam
  • A lookalike website using a misspelled domain
  • An unofficial app that uses the real company’s logo

The safest approach is therefore not to search for a brand in an app store, tap the first result and assume it is genuine. Identify the legal company, verify its current FIU status, enter the company’s official website manually and use the app-store link published on that website.

FIU registration should be treated as a compliance checkpoint, not a promise that an exchange is financially sound, technically secure or suitable for your needs.

What FIU-IND Registration Actually Means

Virtual Digital Asset Service Providers operating for Indian users fall within India’s anti-money-laundering and counter-terrorist-financing framework. This can cover businesses involved in exchanging VDAs for fiat currency, exchanging one VDA for another, transferring VDAs, safeguarding VDAs or providing instruments that allow control over them.

Registered reporting entities may be required to perform functions such as:

  • Customer identification and KYC
  • Customer due diligence
  • Record keeping
  • Transaction monitoring
  • Suspicious transaction reporting
  • Enhanced checks for higher-risk activity
  • Sanctions screening
  • Appointment of compliance personnel
  • Cooperation with lawful information requests

FIU-IND’s downloads page lists updated AML and CFT guidelines for VDA reporting entities dated January 8, 2026, together with revised registration circulars. Government statements also confirm that the obligation is activity-based and can apply to offshore providers serving Indian users, not only companies with a physical office in India.

This is important because “registered” has a specific and limited meaning. It generally means the entity is brought within the reporting framework under the Prevention of Money Laundering Act and related rules.

It does not necessarily mean that:

  • The Government of India recommends the exchange
  • User deposits are insured
  • The exchange cannot become insolvent
  • All listed tokens have been reviewed or approved
  • The company’s cybersecurity cannot be breached
  • Withdrawals will always be processed quickly
  • Every advertisement made by the company is accurate
  • Every app displaying the company’s name is genuine
  • The exchange is free from operational disputes
  • Crypto has become legal tender in India

Government notices continue to describe crypto products and NFTs as potentially highly risky and warn that regulatory recourse may be limited. FIU-IND has also taken compliance action against offshore VDA providers, showing why a platform’s current status must be checked instead of relying on an old article or screenshot.

FIU Registration Is Not the Same as a Crypto Licence

Users often describe an exchange as “FIU licensed,” but that wording can create the wrong impression.

FIU-IND registration is primarily connected to AML, CFT, reporting and record-keeping obligations. It should not be presented as equivalent to a full investment-market licence, bank licence, deposit guarantee or government safety certificate.

A registered exchange can still experience:

  • A wallet compromise
  • A data breach
  • A liquidity shortage
  • A temporary withdrawal suspension
  • A banking-partner interruption
  • A token delisting
  • A support backlog
  • A legal dispute
  • An internal governance failure
  • A third-party service failure

Registration can improve accountability and visibility, but it cannot eliminate business, custody, market or technology risk.

That is why choosing among FIU-registered crypto apps in India requires more than finding an FIU badge in a website footer.

2026 Crypto-App Verification Shortlist

The following platforms are among the names frequently searched by Indian users when looking for FIU-registered crypto apps. This is a verification shortlist, not an official FIU register, endorsement or permanent declaration of status.

Registration, legal entities, app availability and service features can change. Recheck every platform on the day you intend to register or deposit.

Crypto app or platform2026 verification positionWhat to confirm independently
CoinDCXThe platform identifies itself as an FIU-registered reporting entity and names Neblio Technologies Private Limited as its registered entity.Match the legal entity and REID against current FIU information. Follow the store link from the official CoinDCX domain.
CoinSwitchThe platform states that it is FIU registered and compliant with Indian AML requirements.Find the current operating legal entity in its terms, then match it with FIU records and the store publisher.
MudrexMudrex’s compliance page identifies RPFAS Technologies Private Limited and publishes an FIU registration number.Verify that the registration remains current and that the app-store developer is authorised by the same business.
ZebPayFrequently included in Indian FIU-registered exchange coverage.Confirm the present Indian operating entity, active registration and official app-store seller.
SunCryptoFrequently included in 2026 FIU-app and exchange lists.Do not rely on third-party rankings; check the legal entity, REID, current store publisher and withdrawal terms.
WazirXCommonly searched as an Indian crypto app and reporting entity.Verify its current legal entity, operational status, custody arrangements and withdrawal availability before use.
UnocoinOften included in domestic exchange comparisons.Check current registration, legal entity, publisher name, INR methods and fee schedule.
GiottusCommonly listed among Indian crypto platforms.Confirm current FIU status, official app source, security controls and customer-support domain.
Delta Exchange IndiaSearched mainly for crypto derivatives and INR-settled products.Verify the exact legal entity, product risks, tax treatment and whether the app is intended for Indian customers.
Pi42Commonly searched for INR-denominated crypto derivatives.Confirm the legal operator, FIU status, contract terms and whether the product involves ownership of VDAs.

CoinDCX, CoinSwitch and Mudrex currently publish FIU-registration claims on their own websites. Mudrex’s compliance page, for example, names RPFAS Technologies Private Limited and displays registration number VA00031079. These are useful supporting signals, but a company’s own statement should still be checked against current government information.

Broader 2026 exchange coverage includes platforms such as SunCrypto, ZebPay, WazirX, Unocoin, Delta Exchange India, Pi42 and Giottus. However, some published lists are sponsored or non-editorial, which makes independent verification particularly important.

How to Verify an FIU-Registered Crypto App in India

Use the following process before creating an account or sending money.

Step 1: Identify the Exact Legal Entity

Start on the platform’s official website. Do not begin with its Google Play or App Store listing.

Look in:

  • Terms of use
  • User agreement
  • Privacy policy
  • AML policy
  • Compliance page
  • Risk disclosure
  • Corporate information
  • Website footer
  • Grievance policy

You are looking for the legal company name that contracts with Indian users.

A consumer brand and its legal operator may have completely different names. Searching FIU information only for the consumer-facing brand could produce no result even when its operating entity is registered.

Record:

  • Consumer brand
  • Legal entity
  • Registered office
  • Corporate identification details, where available
  • FIU reporting-entity ID, where published
  • Grievance contact
  • Official support domain
  • Date of your check

If different pages show different company names, stop and clarify which entity provides the particular service you plan to use.

A company can operate separate entities for:

  • Spot trading
  • Derivatives
  • Custody
  • Wallet services
  • International customers
  • Indian customers
  • Web3 products
  • Payment processing

Do not assume one entity’s registration automatically applies to every related product.

Step 2: Check Current FIU-IND Information

Go directly to the official FIU-IND website rather than following a link sent by a promoter, support agent or social-media account.

Review current VDA guidelines, registration circulars, public notices and available reporting-entity information. FIU-IND’s published materials were updated again in January 2026, so a certificate or article from 2023 should not be your only evidence.

Search using the legal entity, not only the brand.

Compare:

  • Exact spelling
  • “Private Limited,” “Limited,” “LLP” or overseas suffixes
  • Registration ID
  • Country of incorporation
  • Registered address
  • Current status
  • Date of the document or notice

Be cautious when a platform offers only a cropped certificate image. A screenshot can be old, incomplete or reused after a status change.

Stronger evidence includes:

  • A complete certificate with identifiable details
  • A reporting-entity ID
  • A matching legal name in official information
  • A recent compliance statement
  • Consistency between the official site, terms and app-store publisher
  • No conflicting FIU enforcement notice

Where a public list cannot be located or interpreted confidently, request the platform’s reporting-entity ID and verify it through current FIU-IND information or official communication. Do not treat “FIU compliant” as identical to “currently registered” unless the platform provides verifiable details.

Step 3: Manually Enter the Official Website

Type the domain yourself.

Do not reach a crypto exchange through:

  • An unsolicited SMS
  • A WhatsApp group
  • A Telegram channel
  • A shortened URL
  • A QR code from an unknown account
  • A social-media reply
  • A search advertisement promising a bonus
  • A customer-support number found in a comment
  • An APK download portal

Check for spelling substitutions such as:

  • An extra letter
  • A missing letter
  • A hyphen added to the domain
  • A different domain extension
  • A zero replacing the letter “o”
  • A capital “I” replacing a lowercase “l”
  • An unrelated subdomain

HTTPS alone is not proof that a site belongs to the real exchange. Fraudulent websites can also obtain valid security certificates.

Step 4: Open the App Store Through the Official Website

Once you are confident that the website is genuine, use the Google Play or Apple App Store button published on that website.

This reduces the risk of choosing:

  • A sponsored clone
  • A similarly named wallet
  • An unofficial portfolio tracker
  • A copied app with a modified icon
  • A fraudulent app using the brand as a keyword

Do not search generically for the brand and automatically choose the first result.

Official-store availability is a useful safeguard, but it is not enough on its own. Store review systems can remove many harmful apps, yet no store can guarantee that every listing is permanently safe.

Google says Play Protect scans apps for potentially harmful behaviour, can warn about harmful apps and may block unverified apps using sensitive permissions commonly exploited in financial fraud. Google also requires cryptocurrency exchanges and wallet providers to register their developer accounts as organisations.

Step 5: Inspect the Developer or Publisher

Before tapping Install, examine the complete store listing.

Check:

  • Developer or seller name
  • Developer address
  • Developer email
  • Official website
  • Privacy-policy domain
  • App-support link
  • Other apps from the same publisher
  • Last update date
  • Version history
  • Data-safety information
  • Requested permissions
  • Recent critical reviews

Google Play requires verified developer information and displays certain legal and contact information to users. Financial apps, including cryptocurrency exchanges and software wallets, must use an organisation developer account.

The publisher does not always have to be identical to the exchange’s consumer brand. A legitimate app might be published under:

  • Its parent company
  • Its registered Indian company
  • A recognised technology subsidiary
  • A documented developer account

However, the relationship should be explainable and supported by the official website.

Pause when you see:

  • A generic developer name with no corporate connection
  • A support email using Gmail, Outlook or another free provider
  • A privacy policy on an unrelated domain
  • A recently created listing impersonating a long-established platform
  • Misspelled branding
  • An unrelated publisher portfolio
  • Repeated complaints that the app is fake
  • A request to contact support only through Telegram
  • A demand to install a second “security” application

Download counts and ratings are supporting signals, not conclusive proof. They can be manipulated, inherited or misinterpreted.

Step 6: Review the Permissions Before Logging In

A crypto app may reasonably request certain permissions when you use a feature that needs them.

Examples include:

PermissionPossible legitimate purposeSafer setting
CameraIdentity-document capture, selfie verification or wallet QR scanningAllow only while using the app
NotificationsLogin alerts, withdrawal notices or price alertsAllow only alerts you need
Photos or filesUploading a selected KYC documentUse selected-file access where available
LocationFraud checks or jurisdiction controlsPrefer while-in-use access
BiometricsLocal app lock or transaction confirmationEnable with a strong device passcode

Other permissions require a much stronger explanation:

  • Full contact-list access
  • Call-log access
  • Continuous background location
  • Microphone access without a relevant feature
  • Accessibility-service control
  • Device-administrator privileges
  • Permission to display over other apps
  • Unrestricted file access
  • SMS access beyond limited OTP handling
  • Ability to install unknown applications

Google’s policy says access to sensitive data should be necessary for the app’s stated functionality, limited to disclosed purposes and requested in context. High-risk permissions such as SMS and call-log access are subject to additional declaration and approval requirements.

A permission request is not automatically malicious. The correct question is whether the access is proportional to the feature being used.

For example, camera access during KYC is understandable. Permanent access to your microphone, contacts, messages and accessibility controls is much harder to justify for basic crypto trading.

Step 7: Complete a Small Deposit and Withdrawal Test

Do not make your first transaction the largest amount you intend to use.

After completing KYC:

  1. Add a small amount through an official payment method.
  2. Confirm that the balance appears correctly.
  3. Make a low-value purchase.
  4. Review the trading fee and spread.
  5. Sell a small portion.
  6. Request a small INR or crypto withdrawal.
  7. Record the processing time and final amount received.
  8. Confirm whether any TDS entry appears in the platform’s tax records.
  9. Download the transaction statement.
  10. Test the official support channel with a non-urgent question.

A successful small test does not guarantee future withdrawals, but it can reveal immediate problems such as:

  • Unexpected fees
  • Unsupported banks
  • Account-name mismatches
  • Missing transaction histories
  • Withdrawal restrictions
  • Incomplete KYC
  • Unclear wallet fees
  • Poor customer support

Fake Crypto Apps: Warning Signs Indian Users Should Know

Fake crypto applications do not need to imitate every part of a genuine exchange. They need only to look convincing long enough to capture a password, OTP, wallet address or deposit.

Fake Sign-In Pages

A clone may display a realistic login page and then claim that your password is incorrect. In the background, it has already sent the password to the attacker.

It may then request:

  • An SMS OTP
  • An authenticator code
  • Your email password
  • A withdrawal PIN
  • A wallet recovery phrase

A legitimate exchange should never need your wallet seed phrase to verify an exchange account.

Fake Deposit Addresses

A fraudulent app may show prices and balances copied from public data while directing deposits to a wallet controlled by the attacker.

Always compare:

  • Asset
  • Blockchain network
  • Address
  • Memo or destination tag
  • Minimum deposit
  • Network confirmation requirement

Send a small test before transferring a larger amount.

Clipboard Replacement

Some malware monitors copied cryptocurrency addresses and replaces them with the attacker’s address.

Before confirming a withdrawal, compare:

  • First six characters
  • Last six characters
  • Network
  • Address format
  • Saved label

Do not rely only on the first few characters.

Fake KYC Collection

A clone may ask for PAN, Aadhaar details, a selfie, bank information and a signature. Even if no crypto is stolen immediately, the identity package could be reused for other fraud.

KYC should be performed only inside the verified app or official website.

Remote-Access Scams

A caller may claim to be from the exchange and ask you to install:

  • AnyDesk
  • TeamViewer
  • QuickSupport
  • Screen-sharing software
  • An “account recovery” APK

Do not open a crypto app while sharing your screen. An attacker may observe:

  • Your login
  • Email
  • OTP
  • Authenticator code
  • Wallet address
  • Available balance
  • Withdrawal flow

End the call and contact the platform through the support page on its manually entered official domain.

Fake Bonus and Upgrade Links

Scammers often use urgency:

  • “Install the new India app today”
  • “Your account will be frozen”
  • “Complete re-KYC within one hour”
  • “Claim a private bonus”
  • “Move funds to a safe wallet”
  • “Download the tax-compliant version”
  • “Activate FIU verification”

Compliance language does not make a message genuine.

Android Safety Checklist

Android users should avoid sideloading crypto apps wherever possible.

An APK is an Android installation package. Installing an APK from outside Google Play can bypass normal store-level controls and update protections.

Never install an APK received through:

  • WhatsApp
  • Telegram
  • Email
  • File-sharing sites
  • Cloud-storage links
  • Discussion forums
  • QR codes
  • Search advertisements
  • Influencer comments
  • Unverified support chats

Where an exchange officially provides an APK on its own domain, treat it as a higher-risk installation path.

Before considering it, verify:

  • The domain is genuine
  • The company confirms the APK is official
  • A checksum or digital signature is published
  • The checksum matches after download
  • The reason for avoiding Google Play is clearly explained
  • Updates will come from a controlled source
  • No “unknown sources” permission remains unnecessarily enabled

Additional Android protections include:

  • Keep Android security updates current.
  • Keep Google Play Protect enabled.
  • Avoid rooted devices for exchange access.
  • Remove unknown device-administrator apps.
  • Review accessibility-service permissions.
  • Restrict notification access.
  • Disable “install unknown apps” after legitimate use.
  • Use a strong device PIN rather than a simple pattern.
  • Check whether unfamiliar apps can display over other apps.
  • Review battery settings for suspicious apps running continuously.
  • Remove third-party keyboards you do not fully trust.

A third-party keyboard can potentially observe sensitive information entered through it. Never type a wallet recovery phrase into an exchange app, keyboard, cloud note or online form.

iPhone and iPad Safety Checklist

On iPhone, install the application using the App Store link on the platform’s official website.

Check:

  • Seller name
  • App-support page
  • Developer website
  • Privacy label
  • Version history
  • Recent reviews
  • Requested access
  • Whether the app is available in the Indian App Store

After installation, go to Settings → Privacy & Security and review access to:

  • Contacts
  • Photos
  • Camera
  • Microphone
  • Location
  • Bluetooth
  • Local network
  • Tracking

Apple’s App Privacy Report can show how frequently an app accesses sensitive data and which internet domains it contacts. The information is stored on the device and can help identify activity that does not match how you use the application.

To enable it:

  1. Open Settings.
  2. Tap Privacy & Security.
  3. Tap App Privacy Report.
  4. Turn on App Privacy Report.
  5. Allow time for the report to collect activity.
  6. Review the crypto app’s sensor and network access.

Unexpected contact with a domain does not automatically prove fraud. Apps may use cloud, analytics or security providers. However, repeated access to unrelated or suspicious domains deserves investigation.

Avoid using jailbroken devices for financial applications because jailbreaking can weaken operating-system protections and application isolation.

Account Security After Installing the Genuine App

Installing the correct application is only the beginning.

Use a Unique Password

Create a password that is:

  • Long
  • Random
  • Unique to the exchange
  • Stored in a reputable password manager
  • Not based on your name, birthday or phone number

Never reuse your:

  • Email password
  • Banking password
  • Social-media password
  • Work password
  • Password from another exchange

Credential-stealing attacks become much more damaging when the same password works across multiple services.

Secure the Email Account First

Your email account is often the recovery channel for your crypto account.

Protect it with:

  • A unique password
  • Two-factor authentication
  • Current recovery details
  • Login alerts
  • Review of connected devices
  • Removal of unknown forwarding rules
  • Removal of suspicious third-party access

An attacker who controls your email may be able to reset your exchange password and hide security alerts.

Prefer Stronger Authentication Than SMS Alone

SMS authentication is better than using only a password, but it can be exposed to SIM-swap, phishing and number-takeover attacks.

Where supported, consider:

  • Authenticator-app codes
  • Passkeys
  • Hardware security keys
  • Device-bound confirmation
  • Biometric confirmation combined with a secure device passcode

Authenticator codes are not immune to phishing. A fake login page can ask you to enter a current code and relay it immediately.

Never give an authentication code to:

  • Customer support
  • A caller
  • A Telegram administrator
  • A screen-sharing technician
  • A website opened from an unsolicited message

Enable Withdrawal Protection

Where available, enable:

  • Withdrawal-address allowlisting
  • New-address waiting periods
  • Anti-phishing codes in emails
  • Login alerts
  • Withdrawal alerts
  • Session management
  • Device approval
  • Account freeze options

Address allowlisting is particularly useful because a stolen password may not be enough to send assets to a newly added wallet immediately.

Review Active Sessions

Remove:

  • Unknown browsers
  • Old phones
  • Devices you sold
  • Sessions from unexpected locations
  • API keys you no longer use
  • Third-party trading tools you no longer trust

API keys can provide powerful access. Do not enable withdrawal permission unless it is absolutely necessary.

Do Not Store Seed Phrases on the Phone

A recovery phrase belongs to a self-custody wallet, not an exchange login.

Do not store it in:

  • Screenshots
  • Gallery folders
  • Email drafts
  • Cloud notes
  • Messaging apps
  • Clipboard history
  • Password fields
  • Contact entries
  • Online documents

Anyone with the seed phrase may be able to control the wallet without needing your exchange password.

How to Compare FIU-Registered Crypto Apps

FIU registration should be a minimum compliance filter rather than the only selection factor.

1. Legal-Entity Transparency

Prefer platforms that clearly publish:

  • Full company name
  • Registered address
  • Reporting-entity ID
  • Grievance contact
  • Privacy policy
  • AML information
  • Risk disclosure
  • User agreement

A brand that hides its contracting entity makes independent verification harder.

2. INR Deposit and Withdrawal Support

Check the currently available methods rather than relying on an old review.

Possible methods may include:

  • UPI
  • IMPS
  • NEFT
  • RTGS
  • Direct bank transfer
  • Payment-gateway transfer

Payment availability can change because exchanges depend on banking and payment partners.

Before depositing, confirm:

  • Minimum amount
  • Maximum amount
  • Processing fee
  • Supported account types
  • Name-match requirement
  • Normal processing window
  • Failed-payment process
  • Refund process
  • Withdrawal limit
  • Whether manual review may apply

Do not interpret “instant withdrawal” as a guarantee. Banks, compliance checks, technical maintenance and transaction monitoring can delay processing.

3. Trading Fees and Spread

A zero-fee claim does not necessarily mean the transaction is cost-free.

Compare:

  • Maker fee
  • Taker fee
  • Buy/sell spread
  • INR deposit fee
  • INR withdrawal fee
  • Crypto withdrawal fee
  • Network fee
  • Conversion markup
  • Recurring-buy fee
  • Derivatives fee
  • Liquidation charge
  • Inactivity or membership fee

A simple app may quote an all-inclusive price rather than displaying an order-book fee. Compare the final number of units received, not only the advertised percentage.

4. Custody and Withdrawal Control

Ask:

  • Can crypto be withdrawn to a private wallet?
  • Are all listed assets withdrawable?
  • Are withdrawals supported on the required network?
  • Is address allowlisting available?
  • Is there a waiting period for a new address?
  • Does the app publish custody information?
  • Are assets mixed with company operating funds?
  • Is proof-of-reserves information available?
  • Is there any independent assurance?
  • What does proof of reserves omit?

Proof of reserves can help show that certain assets exist at a point in time, but it may not show all liabilities, loans, corporate obligations or internal controls.

5. Security and Incident Transparency

Useful signals include:

  • Prompt incident disclosures
  • Clear status pages
  • Independent security certifications
  • Bug-bounty programmes
  • Cold-storage controls
  • Multi-signature processes
  • Withdrawal monitoring
  • Device management
  • Anti-phishing tools
  • Published recovery procedures

Do not describe an app as the “safest” based only on one certificate or marketing claim.

6. Tax Records

An India-focused app should make it reasonably practical to download:

  • Trade history
  • Deposit history
  • Withdrawal history
  • Fee details
  • TDS information
  • Profit-and-loss records
  • VDA transaction reports

A tax report generated by an exchange may assist with filing, but the taxpayer remains responsible for reviewing accuracy.

7. Support Quality

Test support before transferring a large amount.

Check:

  • Whether the domain is official
  • Whether a ticket number is issued
  • Normal response time
  • Escalation process
  • Grievance-officer information
  • Whether support asks for sensitive information
  • Whether phone numbers are published officially
  • Whether the company warns about impersonators

No legitimate support agent should ask for a password, seed phrase, private key or full authentication code.

Crypto Tax and TDS in India in 2026

Tax compliance is separate from FIU registration.

For relevant periods, official Income Tax Department material explains that income from transferring VDAs is generally taxed at 30%, plus applicable surcharge and cess. The cost of acquisition may be deducted, but other expenditure and loss set-off are restricted. Schedule VDA requires transaction-level reporting, and losses are reported according to the applicable VDA rules rather than freely offset against profitable transactions.

A simple example:

  • Bitcoin purchased for ₹100,000
  • Bitcoin later sold for ₹140,000
  • Basic gain before applying personal tax details: ₹40,000

The special VDA tax rate may apply to the taxable gain, along with applicable surcharge and cess. Exact treatment can depend on the transaction, taxpayer and tax year, so consult a Chartered Accountant for personal advice.

The 1% TDS Rule

The VDA TDS mechanism generally uses a 1% rate on consideration paid for a qualifying transfer to a resident, subject to applicable thresholds and rules.

The older Section 194S framework used annual thresholds of:

  • ₹50,000 when consideration was paid by a specified person
  • ₹10,000 for other payers

The Income Tax Department states that rates and monetary thresholds were retained during the transition to the Income Tax Act, 2025. For relevant payments or credits from April 1, 2026, the new Act’s Section 393 framework applies rather than continuing to use old section numbers for current transactions.

This means the statement “every crypto trade always has 1% TDS” is too broad.

Applicability can depend on:

  • Whether the transfer is covered
  • Whether the recipient is resident
  • Transaction value
  • Annual threshold
  • Who is responsible for deduction
  • Whether an exchange facilitates the transaction
  • Whether consideration is paid in cash, kind or another VDA
  • Date of payment or credit
  • Current tax rules

TDS is not the same as final income tax. It is a tax deduction recorded against the taxpayer and may affect cash flow even when the eventual taxable result is different.

Maintain Your Own Records

Download statements regularly rather than waiting until the end of the year.

Keep:

  • Date and time of acquisition
  • Date and time of transfer
  • Asset
  • Quantity
  • INR value
  • Cost of acquisition
  • Sale consideration
  • Fees
  • TDS
  • Wallet address
  • Transaction hash
  • Bank reference
  • Exchange statement
  • Transfer between your own wallets
  • Gifts or airdrops
  • Staking or reward records

Do not assume the exchange will permanently retain every report in the format you need.

Self-Custody Versus Leaving Crypto on an Exchange

An FIU-registered app can help users buy, sell and report transactions, but it remains a centralised service.

When crypto stays on an exchange, the platform controls the private keys and may impose:

  • Withdrawal limits
  • Compliance holds
  • Network restrictions
  • Maintenance windows
  • Address reviews
  • Delisting deadlines

Self-custody gives the user direct control of the keys, but it transfers the responsibility for security entirely to the user.

Self-custody risks include:

  • Losing the seed phrase
  • Sending to the wrong address
  • Selecting the wrong network
  • Signing a malicious smart-contract approval
  • Buying a counterfeit hardware wallet
  • Exposing the seed phrase to malware
  • Losing access with no recovery service

Neither model is automatically risk-free.

A cautious user may keep only the amount needed for active trading on an exchange while storing longer-term assets through an independently secured method. That decision should reflect the user’s technical ability, transaction needs and risk tolerance.

What to Do If You Installed a Suspicious Crypto App

Act quickly, but do not continue interacting with the suspected application.

1. Disconnect the Device

Turn on airplane mode or disconnect Wi-Fi and mobile data if you believe malware is transmitting information.

2. Use a Different Trusted Device

From another clean device:

  • Change the exchange password.
  • Change the associated email password.
  • Revoke active sessions.
  • Reset two-factor authentication.
  • Review withdrawal addresses.
  • Remove unknown API keys.
  • Contact official support.
  • Freeze the account if the platform provides that option.

3. Protect Linked Financial Accounts

Review:

  • Bank transactions
  • UPI activity
  • Card activity
  • Email security alerts
  • SIM status
  • Exchange withdrawals
  • Wallet transfers

Contact the bank immediately when an unauthorised financial transaction is suspected.

4. Preserve Evidence

Before wiping the device, where safe, retain:

  • App name
  • Publisher
  • Store URL
  • Screenshots
  • Message history
  • Phone number
  • Email address
  • Transaction ID
  • Wallet address
  • Bank reference
  • Date and time
  • Support conversation
  • Fraudulent domain

Do not reopen a malicious app merely to collect more evidence.

5. Report the Incident

India’s National Cyber Crime Reporting Portal provides reporting paths for financial fraud and other cybercrime. The official cybercrime helpline for immediate financial-fraud reporting is 1930.

Also report the suspicious listing to:

  • Google Play
  • Apple App Store
  • The genuine exchange
  • Your bank
  • Your mobile operator, if a SIM attack is suspected

6. Consider a Full Device Reset

Simply uninstalling malware may not remove every component.

Where compromise is likely:

  • Back up only essential personal files.
  • Do not back up the suspicious APK.
  • Reset the phone.
  • Reinstall apps from official stores.
  • Change important passwords again.
  • Restore access carefully.
  • Monitor accounts over the following weeks.

Seek qualified technical assistance when you are uncertain.

Common Problems and Practical Fixes

FIU Badge Is Shown but I Cannot Find the Company Name

Open the terms and privacy policy. Look for the legal entity contracting with Indian users.

Ask support for:

  • Full legal name
  • FIU reporting-entity ID
  • Registration date
  • Current compliance contact

Do not deposit until the information can be reconciled.

The Store Publisher Does Not Match the Brand

Check whether the publisher is a documented parent, subsidiary or authorised technology company.

The relationship should be visible on the official website or in official terms. A vague support response is not enough for a financial application.

UPI Deposit Is Pending

Do not repeat the payment immediately.

First:

  1. Check whether the bank debited the amount.
  2. Record the UPI reference.
  3. Check the exchange’s status page.
  4. Open a ticket through official support.
  5. Confirm expected reconciliation time.
  6. Avoid anyone offering to “release” the deposit for an extra payment.

Withdrawal Is Under Review

Possible reasons include:

  • Incomplete KYC
  • New device login
  • Recently changed password
  • New withdrawal address
  • Unusual transaction pattern
  • Source-of-funds review
  • Sanctions or blockchain-screening alert
  • Bank-name mismatch
  • Technical maintenance

Ask for the exact missing document and anticipated review process. Submit documents only through the verified app or website.

Support Asked Me to Pay a Tax Before Releasing Crypto

Treat this as a major warning sign.

Scammers frequently demand:

  • Unlock fees
  • Verification deposits
  • GST payments
  • AML clearance fees
  • Withdrawal taxes
  • Security deposits

Verify all charges inside the official account and fee schedule. Do not send crypto to a “support wallet.”

The App Wants Accessibility Permission

Accessibility access can allow an app to observe screen content or interact with other applications.

Do not grant it unless there is a clear, necessary, documented accessibility function and you have verified the app beyond doubt.

A trading app that refuses to work without unexplained accessibility access should be treated cautiously.

Frequently Asked Questions

What is the safest FIU-registered crypto app in India?

There is no single app that can be guaranteed to be the safest.

FIU registration covers AML and reporting obligations; it does not prove that an exchange has the strongest custody, finances, customer support or cybersecurity.

Compare legal transparency, publisher authenticity, withdrawal controls, account protection, custody disclosures, incident history, fees and support.

Does FIU registration make a crypto exchange legal in India?

FIU registration means the provider is registered as a reporting entity for relevant PMLA obligations. It should not be described as blanket legal approval of every product, token or activity offered by the exchange.

Crypto is not legal tender in India, and the broader regulatory environment continues to evolve.

Is FIU registration mandatory for offshore crypto exchanges?

Government statements say the AML and CFT obligations are activity-based and can apply to offshore VDA providers serving Indian users, regardless of physical presence in India. FIU-IND has issued notices and taken action against offshore providers for non-compliance.

How do I find the official FIU list?

Begin at the official FIU-IND website and review its current downloads, VDA guidelines, registration circulars and public information.

Search for the platform’s complete legal entity rather than only its consumer brand. Where the current registration cannot be confirmed from available information, ask for the platform’s reporting-entity ID and verify it through official channels.

Is an FIU certificate enough?

No.

Check:

  • Certificate date
  • Legal entity
  • Registration ID
  • Current status
  • Official FIU information
  • Whether the entity covers the service you will use
  • App-store publisher
  • Official website
  • Security controls

A certificate image does not prove that the installed application is genuine.

Can a fake crypto app appear on Google Play or the App Store?

Official stores provide important screening and removal controls, but store presence should not be your only check.

Open the listing from the platform’s official website, verify the publisher, inspect contact information and review permissions before logging in.

Should I download a crypto APK?

Avoid third-party crypto APKs.

Never install an APK received through messaging apps, cloud links, forums or unofficial download sites. Even where an official company offers an APK, verify the domain, signature and checksum and understand why the store version is unavailable.

Which permissions should worry me?

Pay particular attention to:

  • Accessibility services
  • Call logs
  • Full SMS access
  • Contacts
  • Device-administrator access
  • Permission to install other apps
  • Display-over-other-apps access
  • Unrestricted file access
  • Persistent background location

Assess whether the requested permission is necessary for a feature you initiated.

Is authenticator-based 2FA completely safe?

No security method is completely safe.

Authenticator codes reduce dependence on SMS but can still be stolen through phishing, malware or screen sharing. Passkeys or hardware security keys may provide stronger phishing resistance where supported.

Does an FIU-registered exchange automatically deduct 1% TDS?

Many India-focused platforms facilitate applicable TDS deductions, but the legal rule is more detailed than “1% on every transaction.”

Thresholds, residency, transaction type, payment method and who facilitates the transfer can affect the position.

Is TDS the same as the 30% crypto tax?

No.

TDS is a deduction mechanism on qualifying consideration. The 30% special rate relates to taxable income from VDA transfers, along with applicable surcharge and cess.

Keep transaction-level records and consult a qualified tax professional.

Can crypto losses be adjusted against profits?

Official tax material restricts deduction and set-off of VDA losses. Schedule VDA generally requires transaction-level disclosure, with positive amounts carried into the return under the applicable rules. Do not assume that a loss on one token automatically reduces a gain on another.

Does FIU registration guarantee withdrawals?

No.

Withdrawal processing may be affected by liquidity, banking partners, compliance reviews, cybersecurity incidents, maintenance and account restrictions.

Always perform a small test and avoid leaving money on an exchange solely because it displays an FIU badge.

How often should I recheck FIU registration?

Recheck before making a material deposit and periodically while continuing to use the platform.

Also recheck after:

  • A major regulatory announcement
  • A company restructuring
  • A change in legal terms
  • A new Indian operating entity
  • A domain or app change
  • A service suspension
  • An enforcement notice
  • A merger or acquisition

What should I do if the app publisher changes?

Do not automatically accept the update.

Check the official website, app update notes, legal terms and company announcement. Contact official support when the new publisher’s relationship to the registered entity is unclear.

Should beginners use multiple crypto apps?

Using multiple apps can reduce dependence on one platform, but it also creates more passwords, KYC records, tax statements and attack surfaces.

A beginner may be better served by first learning to secure and document one account properly.

Final Verification Checklist

Complete this checklist before depositing money into any crypto app in India.

Company Verification

  • I found the complete legal entity in the platform’s official terms.
  • I checked current FIU-IND information.
  • I recorded the date of verification.
  • I checked the reporting-entity ID where available.
  • I did not treat registration as government endorsement.
  • I reviewed the risk disclosure and grievance contact.

App Verification

  • I typed the official website manually.
  • I opened the app-store listing through the official website.
  • I checked the developer or seller name.
  • I checked the support email and privacy-policy domain.
  • I reviewed recent critical reviews.
  • I avoided third-party APKs.
  • I checked the app’s permissions.

Device Security

  • My operating system is updated.
  • My device is not rooted or jailbroken.
  • I use a strong screen-lock PIN.
  • I removed unknown remote-access apps.
  • I reviewed accessibility and screen-overlay permissions.
  • I do not store seed phrases in screenshots or cloud notes.

Account Security

  • I use a unique password.
  • My email account has strong two-factor authentication.
  • I enabled the strongest exchange authentication available.
  • I enabled withdrawal allowlisting where supported.
  • I enabled login and withdrawal alerts.
  • I reviewed active sessions and API keys.
  • I know that support will never need my password or seed phrase.

Financial and Tax Checks

  • I reviewed trading fees and spreads.
  • I reviewed INR deposit and withdrawal limits.
  • I completed a small deposit test.
  • I completed a small withdrawal test.
  • I downloaded my transaction history.
  • I reviewed TDS records.
  • I understand that crypto gains may be taxed at the special VDA rate.
  • I will consult a Chartered Accountant for personal tax questions.

Final Verdict

The phrase “FIU registered crypto apps India” can be misleading because FIU-IND registration generally belongs to the legal service provider, not to an app icon or download file.

A proper verification process should connect four things:

The consumer brand → the legal entity → the FIU registration → the genuine app-store publisher

If any link in that chain cannot be verified, do not deposit money until the discrepancy is resolved.

FIU registration is an important compliance signal, particularly for KYC, AML monitoring, record keeping and suspicious-transaction reporting. It is not a substitute for checking custody risk, fees, withdrawal policies, tax records, app authenticity, device permissions and account security.

The best choice is not necessarily the app with the most coins, the largest bonus or the highest rating. It is the platform whose legal identity you can verify, whose genuine app you can confidently identify, whose risks and fees you understand, and whose security controls you are prepared to use correctly.