Is Axiom Trade Safe? Custody, MEV Protection, and the 2026 Incident Explained
Table of Contents
Axiom Trade is documented as non-custodial, and no breach of the platform has been publicly reported as of August 2026. Wallet keys are held through Turnkey, Turnkey states that Axiom "never controls user funds or keys," and you receive a 12-word seed phrase at signup that is exportable from Settings at any time into Phantom, Rabby or Solflare. No smart contract exploit, platform breach or key compromise has been publicly documented against Axiom. There is one confirmed incident and it was not an intrusion: in February 2026 investigator ZachXBT published evidence that an Axiom business-development employee had used an internal customer-support dashboard to view users' wallets and trading history over roughly ten months. Axiom confirmed that internal tools had been abused and removed access to them. No user funds were reported taken and no private keys were reported exposed, because the dashboard granted visibility rather than control. On the published record, the failure sat in internal access governance rather than in key custody.
That summary is the whole answer. The rest of this page is the detail behind it: what the custody model actually bounds, the incident record in full, MEV protection, and the phishing campaigns reported against Axiom.
Custody: What Axiom Does and Doesn't Control

Source: Turnkey, used under fair use for educational purposes
Axiom's documentation says it never holds your funds or your private keys. Wallet infrastructure runs on Turnkey, which documents its own product as key management inside air-gapped secure enclaves. You get a 12-word seed phrase at signup, retrievable at any time from Settings, and Axiom's own documentation recommends exporting it into Phantom, Rabby, or Solflare so you retain access "under any circumstances."
That recommendation isn't theoretical. In August 2025, a Pump.fun API change broke selling across trading bots built on top of it, Axiom included, for several hours. Traders who'd already exported their seed phrase could fall back to Pump.fun's site or Jupiter directly and sell. Traders who hadn't were stuck. See our troubleshooting guide for the full account.
The February 2026 Incident, Explained Plainly
This is the story most competitor comparison pages lead with when discussing Axiom, and it deserves an honest account rather than either burial or sensationalism. What follows is the summary; we also keep a full record of the insider trading incident and what it actually involved, including Axiom's statement as published and what remains unresolved.
What happened: in February 2026, investigator ZachXBT published an investigation into a senior Axiom business-development employee who had access to an internal customer-support dashboard. According to that investigation, the dashboard let staff look up any user by wallet address, referral code, or account ID and see their full wallet history, tracked-wallet lists, and linked accounts, with no logging of who accessed what. The investigation alleged this access was abused over roughly 10 months, including front-running trades based on information seen through the dashboard.
Axiom's response, stated directly: the company confirmed that internal customer support tools had been abused, said it had removed access to the tools involved, and said it would continue investigating and hold those responsible accountable.
What this was not: an intrusion. No smart contract exploit was reported, no private key was reported compromised, and no user funds were reported taken from a wallet. On the published record this was privilege abuse and a privacy failure involving internal access, and nothing in the reporting describes Axiom's non-custodial architecture being defeated. That distinction matters for how you weigh the risk going forward, because nothing published points at the wallet-security model that holds your funds.
What's unresolved: as of this writing, no firings, charges, or user compensation have been publicly confirmed. One outlet reported firings, but the primary reporting supports only the removal of tool access, so treat any consequence beyond that as unconfirmed.
We're covering this directly because several competitor platforms already lead their own Axiom comparison content with this story, and a site that omits it isn't giving you the full picture.
The Documented Incident Record, as of August 2026
The complete public record, so you can see what is and is not on it. Where nothing is documented we say so, rather than presenting silence as a clean bill of health.
| Date | Incident | Type | Funds or keys affected |
|---|---|---|---|
| Feb 26, 2026 | Reported employee abuse of an internal support dashboard to view user wallets (ZachXBT; the abuse of internal tools confirmed by Axiom) | Privilege abuse and privacy failure | None reported. The reporting describes visibility, not control |
| Aug 2025 | Selling broke for several hours across terminals built on the Pump.fun API, Axiom included | Third-party availability outage | None reported. Funds inaccessible through Axiom, not lost |
| n/a | Smart contract exploit | None publicly documented | n/a |
| n/a | Platform breach or intrusion | None publicly documented | n/a |
| n/a | Private key or seed phrase compromise | None publicly documented | n/a |
Where this comes from. The February 2026 incident was published by ZachXBT and covered by The Block, CoinDesk, Forbes, crypto.news and FinanceFeeds, and Axiom confirmed the tool abuse publicly. The August 2025 outage was widely reported and affected the Pump.fun-dependent ecosystem rather than Axiom alone. The three "none documented" rows mean exactly that: we found no public evidence of them, which is different from proof that nothing happened. The February incident surfaced through an outside investigator rather than through disclosure, so absence of evidence on this domain deserves less confidence than usual.
What the architecture bounds, and what it does not. This is the useful part, because it tells you the worst case rather than the current case.
Keys live with Turnkey and you hold an exportable seed phrase, and in that arrangement the seed phrase is what controls the wallet. Whoever holds it can use the wallet without Axiom being online, cooperative or trustworthy. That is the structural bound worth understanding, and it is why the February 2026 incident, on the published record, involved information rather than funds.
What the architecture does not bound is information. Your positions, your history and the wallets you track are visible to whoever holds the internal tooling, and the February reporting showed that set was wider than users assumed. It also does not bound anything you hand over yourself. No architecture protects a seed phrase typed into a phishing site, which is the realistic way Axiom users actually lose funds.
The full account of the February 2026 incident covers Axiom's statement as published and what remains unresolved.
MEV Protection
Every buy on Axiom offers three MEV modes: Off, Reduced (routes through Jito), and Secure (whitelisted validators only, slower but harder to sandwich). An October 2025 analysis published by 0xGhostLogs reported that Axiom users made up roughly 70% of Solana sandwich-attack victims over the prior year, out of about 529,000 SOL extracted across roughly 222,000 victims. That analysis does not attribute the share to a flaw in Axiom's infrastructure, and it sits alongside Axiom's large share of Solana terminal routing volume. Setting MEV protection to Secure is the highest-leverage security setting on the platform, and it costs you nothing but a slightly slower fill.
Tip
MEV protection only matters on buys, since there's nothing to front-run on a sell. Leave it on Secure by default.
Active Phishing You Should Know About
Full detail, including the tells in a fake sign-up flow and what to do if you already entered details, is in how to verify you're on the real Axiom Trade. The short list:
- auth-axiom.trade appears on the MetaMask, ScamSniffer and SEAL blocklists, checked August 2026.
- axiom-trade.pro and axiom.trading have been reported as lookalikes in community blocklist submissions. We have not independently verified either, and new lookalikes appear constantly, so treat any list as incomplete.
- Axiom documents no Telegram bot. Its support page lists Discord tickets on its official server as the support channel and states that staff never message users first, so a Telegram bot or an unprompted DM claiming to be Axiom is unverified at best and should get nothing from you.
- Fake mobile apps have been reported by users. Axiom documents no official native app as of 2026, see is there an official Axiom app for the full picture. It is a progressive web app only, so anything in an app store claiming to be Axiom does not match anything Axiom publishes.
2FA and What Actually Protects Your Account
There's no documented two-factor authentication system. Email signup uses a one-time code at registration only. On a non-custodial platform this matters less than it would on a custodial exchange, because the real dependency is your seed phrase, which Axiom cannot recover if you lose it and which no legitimate support process has any reason to request. Axiom's own support page states that its staff never message users first.
Trade on Axiom
Sign up through our link and the 10% referral fee discount applies automatically to every trade.
Trade on AxiomThe Honest Summary
Axiom's core architecture holds up on the evidence available: non-custodial by its own documentation, exportable keys, and no publicly reported breach as of August 2026. The February 2026 incident is real, confirmed by Axiom itself, and worth knowing before you trade. On the published record it was a privacy and governance failure, and nothing in it describes the wallet infrastructure that holds your funds being defeated. Weigh both facts, not just one.
Frequently Asked Questions
Axiom describes itself as non-custodial. Wallet keys are held through Turnkey, Turnkey states that Axiom 'never controls user funds or keys,' and you can export your seed phrase from Settings at any time. No breach of Axiom itself has been publicly reported as of August 2026. There was a February 2026 incident in which, according to investigator ZachXBT, an employee used an internal support dashboard to view user wallets. Axiom confirmed the abuse and said it removed access to the tools. No funds or keys were reported compromised.
No breach of Axiom itself has been publicly reported as of August 2026, which is not the same as proof that none occurred. Searches for an Axiom hack often surface incidents at unrelated companies that share the name, so check which company a report is actually about before you draw a conclusion from it.
In February 2026, investigator ZachXBT published an investigation alleging that an Axiom business-development employee used an internal 'god mode' support dashboard to look up users' wallets and trading activity over roughly 10 months. Axiom confirmed that internal customer support tools had been abused, said it removed access to the tools involved, and said it would continue investigating. No user funds or private keys were reported compromised.
Axiom documents itself as non-custodial and names Turnkey as the provider that holds wallet keys. Turnkey states that Axiom 'never controls user funds or keys.' You receive a 12-word seed phrase at signup that you can export into Phantom, Rabby, or Solflare at any time, and Axiom's own documentation recommends doing exactly that.
auth-axiom.trade appears on the MetaMask, ScamSniffer and SEAL blocklists, checked August 2026. Other lookalike domains have been reported in community blocklist submissions, and new ones appear constantly, so a domain being absent from any list means nothing. Axiom documents Discord tickets as its only support channel and states that its staff never message users first, so treat a Telegram bot or an unprompted DM claiming to be Axiom as unverified.
There is no documented two-factor authentication system as of August 2026. Email signup uses a one-time code at registration only. The real security dependency is your seed phrase, which Axiom cannot recover if lost, and that matters more on a non-custodial platform than a second login factor would.
Cite this page
These figures are free to quote. Copy the citation or the link below.
Plain-text citation
Axiompedia. "Is Axiom Trade Safe? Custody, MEV Protection, and the 2026 Incident Explained." Published August 6, 2026, updated August 14, 2026. https://axiompedia.com/security/is-axiom-trade-safeHTML link
<a href="https://axiompedia.com/security/is-axiom-trade-safe">Is Axiom Trade Safe? Custody, MEV Protection, and the 2026 Incident Explained — Axiompedia</a>Embed this incident table
The attribution line is part of the snippet. Please keep it.
Methodology and reuse
The incident record below is every publicly reported Axiom Trade security event we could find, with the ones we could not find stated as absences rather than left out. They were read from the ZachXBT's February 2026 investigation and Axiom's own response to it on with every entry traced back to the report that established it, and nothing listed that no source establishes. Sources change what they publish, so treat any figure older than that date as needing a fresh check — the date above is the one to compare against.
You may republish these figures with attribution and a link to https://axiompedia.com/security/is-axiom-trade-safe.
Axiompedia is an independent educational resource. It is not affiliated with, produced by, reviewed by, endorsed by, or sponsored by Axiom Innovations Inc., the operator of axiom.trade, or any of its affiliates. "Axiom" and the Axiom logo are trademarks of Axiom Innovations Inc., used here only to identify the product this site writes about. Full disclaimer.
Disclaimer: Nothing on this site is legal, tax, financial or investment advice. Trading carries risk, including total loss. Whether any activity described here is permitted where you live, and how it is taxed, depends on your jurisdiction and your circumstances. Consult a qualified professional and the primary sources before acting. Past performance does not indicate future results. Always check the primary source and do your own research before trading. This site contains referral links, which are disclosed on the disclosure page.
Ready to Start Trading?
Sign up on Axiom through our link for a 10% discount on trading fees, applied automatically with referral code axiompe.
Save 10% on Fees