Evidence and risk■Verified evidence/△CautionMaterial claims checked against current sources.; those sources show trade-offs worth reading.
Last reviewedReviewed 25 Aug 2026KYC checked 25 Aug 2026 · verified jurisdiction · Source → official termsHow to cite this pageSource coverageVerified evidenceRecorded riskCaution
Evidence and facts
Evidence and facts
CUNICULA SCORE 4.0
28/100△Limited evidencePrivacy 3/25 · Control 0/20 · Transparency 0/20 · Security 17/25 · Accountability 8/10 · Cap 69 · Method
JURISDICTIONGE
CAUTIONTwo thefts were reported in 2024: $26.1M on February 16 and $2.8M on April 1. The service attributed the incidents to infrastructure vulnerabilities involving third-party providers. The operating team is not named.
AUDITED BYNo audit listed
OPERATOR DATAUnknown
SOURCE COVERAGE
■Verified evidenceSELF-REPORTED4/4Reviewed 25 Aug 2026 · Source → official terms
LAST CHECKED2026-08-25
LAST UPDATED2026-08-25
Specs
DOCUMENT CHECKlight
IDENTITY EXPOSURELevel 3/4
KYC TRIGGERSNo account is required for an ordinary exchange, but current AML rules permit order suspension and requests for source-of-funds details or identity verification when risk controls trigger.
FEE0.5–1%
CATEGORIESSwap
FEATURESFixed rate, Variable rate, No account, Instant, Refund address
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
Analysis
OVERVIEW
FixedFloat supports fixed and floating rate swaps with no account and Lightning Network support; the jurisdiction field lists Marshall Islands, while its legal registration is separately reported as London, UK per Tracxn, with no individual founders named.
LIMITS
Two 2024 hacks are documented: $26.1M stolen in February and a further $2.8M in April by the same attacker group exploiting third-party hosting; the team cooperated with law enforcement afterward by its own account, but the record still flags user funds as being at elevated risk.
USEFUL FOR
Fits users who have weighed the 2024 breach history against the fixed-rate, no-account swap flow before sending funds.
The recorded KYC level is "light". No account is required for an ordinary exchange, but current AML rules permit order suspension and requests for source-of-funds details or identity verification when risk controls trigger.
Which payment methods are accepted?
Please check the provider site for accepted payment methods.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
No. The recorded jurisdiction is GE, which is not a Five Eyes country. This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 3 of 4. Hosted operator data has not been established. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-08-25, and recorded risk is caution.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Apply full-service rereview and score 4.0
Checked at, Corporate / Legal entity, Corporate / Reviewed at, Corporate / Source, and 9 more
Corporate registry information updated
Corporate / Entity type
Corporate registry information updated
Corporate
Full service history
updated
Reconcile score 4.0 evidence
Score assessment / Control model
noncustodial-hosted → unknown
Score assessment / Operator data exposure
extensive → unknown
Score assessment / Source model
closed → unknown
Score review
not set → Outcome: PASS; Checked at: 2026-08-25; Inputs: Operator data exposure: unknown; Control model: unknown; Source model: unknown; Audit: Score eligible: no; Reason: No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit.
registry research 2026-08-08, → current official Terms reviewed 2026-08-25; prior Georgian registry evidence retained
Jurisdiction
MH → GE
KYC requirement
none → light
KYC last checked
2026-07-17 → 2026-08-25
KYC level
0 → 3
Kyc note
Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR. Terms updated March 2025: orders funded from flagged sources can be suspended pending source-of-funds verification. → No account is required for an ordinary exchange, but current AML rules permit order suspension and requests for source-of-funds details or identity verification when risk controls trigger.
Last reviewed
2026-06-22 → 2026-08-25
Source reviewed
official site → https://ff.io/terms-of-service
Score assessment
not set → Operator data exposure: extensive; Control model: noncustodial-hosted; Source model: closed
Fixed and floating rate crypto-to-crypto swaps, no account required. Supports Lightning Network and major crypto assets. Progress tracker. (Zero routine KYC) → Fixed and floating rate crypto swaps with no account required, supporting Lightning Network and major assets.
HACKED TWICE IN 2024: $26.1M stolen February 16, 2024 (409 BTC + 1,728 ETH). Same attacker returned April 1, 2024 stealing $2.8M. Infrastructure vulnerabilities via third-party providers. Team fully anonymous. Proceed with caution — user funds at elevated risk. → Two thefts were reported in 2024: $26.1M on February 16 and $2.8M on April 1. The service attributed the incidents to infrastructure vulnerabilities involving third-party providers. The operating team is not named.
Recorded risk
not set → caution
Tagline
A privacy-preserving tool offering genuine utility. → not set
Data(fixedfloat): record March 2025 source-of-funds screening terms
KYC last checked
2026-06-22 → 2026-07-17
Kyc note
Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR. → Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR. Terms updated March 2025: orders funded from flagged sources can be suspended pending source-of-funds verification.
not set → HACKED TWICE IN 2024: $26.1M stolen February 16, 2024 (409 BTC + 1,728 ETH). Same attacker returned April 1, 2024 stealing $2.8M. Infrastructure vulnerabilities via third-party providers. Team fully anonymous. Proceed with caution — user funds at elevated risk.