Security & verification

Everything we know, published.

Crupto is independently developed and currently distributed as an unsigned Windows executable. Rather than talk around that, here is the exact release, its exact hash, and its full third-party scan result — including the detections.

VirusTotal

2 / 71engines detected this file
View VirusTotal report

Scan result for crupto-terminal.exe, 8.35 MB, SHA-256 0e18edda43865eb31d70b52e01cc9f8ef763c492ef8ab18318a8ef6044f98d4f

    VirusTotal aggregates results from multiple security vendors. Detection results can include heuristic and machine-learning classifications, particularly for new or unsigned software. A VirusTotal result should be considered one part of evaluating software rather than a guarantee of safety.

    The two detections above are machine-learning and heuristic classifications rather than signature matches on known malware. We are not telling you to disregard them — we are telling you they exist, which engines produced them, and that most engines in the same scan, Microsoft included, returned Undetected. Judge it with that in front of you.

    Release information

    crupto-terminal.exe

    Version
    Current Official Release
    File size
    8.35 MB
    Platform
    Windows 10 / 11, 64-bit
    VirusTotal
    2 / 71 engines detected this release · view report
    SHA-256
    0e18edda43865eb31d70b52e01cc9f8ef763c492ef8ab18318a8ef6044f98d4f

    This scan belongs to this release and no other. When a new build ships, it gets a new hash and a new scan, and both are republished here together. We don't carry an old result forward onto a new executable.


    Windows

    Why does Windows SmartScreen show a warning?

    Crupto is independently developed and currently distributed as an unsigned Windows executable. Because the application does not have a commercial code-signing certificate and may not have established Windows reputation, Windows SmartScreen may display a warning when you first run it.

    This warning does not by itself mean that Crupto is malware. It means Windows has not seen this file signed by a known publisher or downloaded enough times to have built reputation for it. Plenty of legitimate independent software sits in exactly that position, and so does plenty of malware — which is why the warning exists and why you shouldn't simply wave it away.

    What actually resolves the uncertainty is verification: confirm that the file you downloaded matches the official SHA-256 hash published on this website. That tells you the file is the one we shipped and hasn't been tampered with in transit.

    We will never ask you to turn off your security software. Don't disable Windows Defender, don't permanently switch off SmartScreen, and be wary of any software that tells you to. If you've verified the hash and choose to proceed, use Windows' normal one-time prompt for that specific file and leave your protection on.


    Independent development

    No code signing, no company behind it.

    Crupto is an independently developed software project. It does not currently use commercial Windows code signing, and there is no company, investor or institution behind it — just the developer and this website. We'd rather say that plainly than dress it up.

    There are no certifications, no regulatory approvals and no exchange partnerships to report, because none exist. Crupto connects to public exchange market-data endpoints as any client would; that is not an affiliation.


    Credentials

    Where your API keys live.

    The terminal itself needs no credentials at all. The market data it displays is public, so there is no exchange account to connect and no trading key to hand over.

    Three credentials are optional, and only unlock specific panels: a free Finnhub key for the stocks/gold/silver/oil panel, a free Etherscan key for the ETH exchange-flow panel, and a Telegram bot token if you want alerts forwarded to Telegram.

    Any key you add is stored locally on your own computer, in the application's own configuration, rather than being uploaded to crupto.co. We don't receive it, we can't see it, and there is no Crupto account for it to sync to.

    What we won't claim. We are not claiming those stored credentials are encrypted, and we are not claiming other software running on your computer couldn't read them. A local configuration file is as safe as the machine it sits on. If that matters to you, keep the optional keys out of the app — every panel they unlock is optional, and the terminal runs fine without them.


    Good practice

    API security habits worth keeping.

    None of this is specific to Crupto, and Crupto cannot guarantee you protection against a compromised credential. It's just the baseline for anyone handing an API key to any software.


    Automation

    Analysis and automation are different things.

    Automation is separate from analysis. The terminal's own panels only read the market — they place no orders and need no trading credentials. The bundled bots and anything you load through the Bot Lab are automation: they can act without manual intervention and may result in losses. Bots pulled from GitHub are third-party code you should read before you trust it. You are responsible for understanding and configuring any automation before enabling it.

    The Bot Lab pulls code from GitHub repositories you choose and runs it on your machine. That code is written by third parties, is not reviewed by us, and can do whatever its author wrote it to do. Read a bot before you run it, and treat any bot that asks for a withdrawal-enabled API key as a red flag.