HostDeFi › Is Backpack safe
Is Backpack safe? The FTX survivors who bought FTX Europe
Backpack is two products wearing one brand: a self-custody wallet that holds nothing of yours, and a custodial exchange that holds everything you deposit. Its history is the strangest credibility story in this corpus — built by an FTX/Alameda alumnus, bankrupted 88% by FTX's collapse, then bought FTX Europe for $32.7M and took over its customer refunds.
What Backpack is — two products, one brand
Backpack is the ecosystem founded in 2022 by Armani Ferrante — the developer behind Anchor, the Solana framework a large share of ecosystem projects build on. Three limbs: Backpack Wallet (self-custody), Backpack Exchange (custodial spot/perps), and Mad Lads (the Solana flagship NFT collection that became the company's community spine). The safety question can only be answered per limb, because the custody story inverts between them.
The wallet: plain self-custody
Backpack Wallet is self-custody in the classic shape — keys generated and held on your device, seed phrase yours alone, nobody at Backpack can move or recover funds. Its lineage matters for trust: it descends from Ferrante's Coral xNFT work — an app-container wallet concept — rather than a fork of an incumbent. The risk set is the standard self-custody one: seed loss, phishing signatures, counterfeit app downloads.
The exchange: custodial, with the strangest history in the family
Backpack Exchange is a custodial venue — deposits are balances, balances are claims. What makes its risk read unusual is the company's documented FTX entanglement, in both directions:
- Burned by FTX: the team includes FTX/Alameda alumni, and Backpack itself lost ~$14.5M — 88% of operating funds — in the November 2022 collapse. It kept building on minimal funding through the bear market, a survival detail the company states in its own history.
- Bought FTX Europe: in January 2025 Backpack acquired FTX EU for $32.7M, inheriting the CySEC MiFID II license (273/15, now Trek Labs Europe Ltd) and the obligation to distribute FTX EU's outstanding customer fiat claims — it began processing those refunds ahead of the EU relaunch, framing them publicly as overdue.
The charitable read: a team that felt the custodial-failure cost firsthand, survived it, then voluntarily took creditors' restitution onto its own books. The skeptical read: the alumni lineage means FTX is in the DNA, not just the history. Both are in the record.
Backpack EU and the license perimeter
Since September 2025, Backpack EU offers regulated perpetual futures — one of the first MiFID-licensed perps venues in Europe. 'Regulated' is precise here: it covers the EU entity's licensed products under CySEC oversight. The global exchange for non-EU users remains a conventional offshore-style CEX — the license upgrades accountability for EU users specifically, it does not convert the whole venue into a regulated institution.
The risk stack, per product
| Product | Custody | Dominant risk |
|---|---|---|
| Backpack Wallet | Self-custody — keys on device | Seed loss; signature phishing; fake apps |
| Backpack Exchange (global) | Custodial — balances are claims | Young-venue solvency/withdrawal risk |
| Backpack EU | Custodial, CySEC/MiFID-licensed | Same class, narrower — licensed accountability |
| All | — | Phishing clones — 'FTX EU claim' lures are a live phish theme |
The custody split in daily terms
For a Backpack user the distinction becomes practical the moment money moves: tokens in the wallet are sovereign — no Backpack outage, insolvency, or freeze can reach them, and no Backpack employee can retrieve them if the seed is gone. Tokens on the exchange are claims on a company — one that now operates part of its book under CySEC oversight in Europe, which adds a regulator to the accountability chain for EU users, and a young exchange's balance sheet everywhere else. Neither is a defect; they are different instruments. The error is holding exchange balances with wallet expectations — assuming you can always withdraw because the wallet always could.
The phishing angle worth naming
Backpack's FTX EU obligation created an unusual phishing lure: 'claim your FTX EU refund' is a ready-made hook for fake claim portals, and the real claim flow lives at eu.backpack.exchange/claim — nowhere else. Any DM, email, or search-ad 'claims desk' asking for a seed phrase or a signature to 'release' fiat is a phish; real claim processing is a KYC/account flow, never a wallet-connect prompt.
Where Backpack stands
No documented wallet exploit or exchange drain; a verifiable hard history (survived losing 88% of its funds, then paid $32.7M to take on an FTX cleanup); a real EU license for the regulated limb — and the standing caveat that its exchange is still young by CEX standards. The dated read: self-custody wallet = standard-good; exchange = a custodial venue with unusual survival-and-restitution credibility and a short track record, whose EU arm carries actual regulatory accountability.
The verdict in one line: Backpack's wallet holds nothing and answers like every self-custody wallet; its exchange asks you to trust a young custodian whose defining credential is that it was burned by, survived, and then bought the cleanup of the worst custodial failure in crypto history.
Frequently asked questions
Is Backpack a legitimate company?
Yes — Backpack is the ecosystem built by Armani Ferrante, creator of Anchor (the Solana developer framework much of the ecosystem builds on), launched 2022 with the self-custody wallet and the Mad Lads NFT project, and now operating Backpack Exchange. Its unusual credibility detail: it lost 88% of its operating funds (~$14.5M) in the FTX collapse and kept building — then bought FTX Europe in Jan 2025 and took responsibility for returning that exchange's customer fiat.
Does Backpack hold your keys?
Two different answers for two products — the distinction the whole page rests on. Backpack Wallet is self-custody: keys on your device, seed in your hands, nobody holds them. Backpack Exchange is custodial: account balances live with the exchange and are claims on it — like any CEX, solvency and withdrawal integrity are the trust you extend. Confusing the two is the main way users misjudge it.
What is Backpack's FTX connection?
Twofold. (1) The team includes FTX/Alameda alumni, and Backpack itself lost ~$14.5M (88% of operating funds) when FTX collapsed — disclosed in its own history. (2) In January 2025 Backpack acquired FTX EU for $32.7M (renamed Trek Labs Europe Ltd), inheriting its CySEC MiFID II license (273/15) plus the obligation to distribute FTX EU's outstanding customer fiat claims — processing refunds it publicly framed as overdue. The alumni lineage cuts both ways: FTX survivors who then chose to take FTX creditors' problem onto their own books.
Has Backpack had security incidents?
No exchange-draining or wallet-exploit incident is publicly documented. The record worth citing is counterparty history, not hacks: the FTX-collapse loss (company-side, $14.5M), and the FTX EU acquisition which made Backpack the distributor of customer claims, not a victim. For the custodial exchange product the honest risk read is standard-CEX: funds on it are claims on a young exchange under a fresh EU regulatory umbrella — stronger accountability than an unlicensed venue, shorter track record than an incumbent.
Is Backpack Exchange regulated?
In Europe, yes — Backpack EU operates as Trek Labs Europe Ltd (the former FTX EU Ltd), authorized by CySEC under MiFID II license 273/15, and launched regulated perpetual futures in Europe (September 2025). That is a real regulatory perimeter — one of the first regulated perps offerings in the EU — while the global exchange remains a standard offshore-style CEX for non-EU users. 'Regulated' here is precise: it applies to the EU entity's licensed products, not a blanket promise.
What are Backpack's real risks?
Split by product. Wallet: the self-custody set — seed loss, phishing signatures, fake-app downloads. Exchange: the CEX set — custodial solvency and withdrawal risk on a comparatively young venue (mitigated but not eliminated by the EU license), plus phishing clones of a brand whose FTX EU claim portal is exactly the kind of page phishers imitate — 'claim your FTX EU funds' emails are a live lure. The FTX alumni history is reputational color, not a technical risk.