JustCryptos
JustCryptos warrants rejection. It is not a smart-contract bridge. It is a Poloniex-custodied wrapping service that issues TRC-20 representations of BTC, ETH, and other assets on TRON, with no published contract addresses, minting logic, or on-chain architecture found in this review. The only way to obtain or redeem the wrapped tokens is through a Poloniex account, an exchange Justin Sun has owned and controlled since 2019 and whose hot wallet was drained of more than $100M in a November 2023 breach. This is fully custodial, single-entity, KYC-gated exposure to a custodian with a realized, not theoretical, security failure on record.
- JustCryptos publishes verifiable wrapped-token contract addresses and custody or reserve architecture, not only a claimed transparency webpage
- An independent, named custodian separate from Poloniex’s own hot wallets holds backing reserves, or an independent proof-of-reserves audit is published
- A genuinely permissionless mint or redeem path is demonstrated that does not require a Poloniex account
- No further Poloniex hot-wallet security incident occurs for 24 consecutive months following the November 2023 breach
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
JustCryptos issues TRC-20 wrapped tokens (BTC, ETHB, LTC, DOGE, and others per its own site) on TRON. Its own materials describe the process only as a ”trusted swap service” relying on ”premium platforms such as Poloniex and the BitTorrent Chain.” There is no permissionless on-chain mint path a user can interact with directly, and this review found no published wrapped-token contract addresses or minting logic. The site claims an ”open and transparent” supply-verification page, but this is a self-reported claim, not one that has been independently verified.
Control and governance
The service is fully custodial and centralized. Poloniex holds the underlying assets and controls the minting and burning of the wrapped tokens. Justin Sun has owned Poloniex since his 2019 acquisition, and the exchange is closely tied to the TRON/JUST ecosystem for which this bridge is named. The product discloses no multisig, independent custodian, or on-chain governance process.
Incident record
Poloniex suffered a major hot-wallet breach beginning around 2023-11-10, which Poloniex confirmed on 2023-11-14. More than $100M was drained (reports range $100M to $126M), including more than 20,000 BTC and 10,000 ETH, across 357-plus transactions from the exchange’s hot wallet. Sun offered the attacker a 5% white-hat bounty and reimbursed affected users. The same hot-wallet custody model that was breached is, in structural terms, what backs JustCryptos’ wrapped tokens today. This is a realized failure in the custodian’s history, not a hypothetical risk.
Exit
Redemption requires a Poloniex account and its KYC process. A holder cannot exit to the native asset without going through the exchange. The only non-custodial exit path is a secondary-market sale of the wrapped TRC-20 token on a TRON DEX, subject to thin liquidity and slippage relative to major-chain alternatives.
Comparison
JustCryptos has weaker disclosure than either WBTC (a named multisig across three jurisdictions, even though this registry separately rejects WBTC for custody concentration) or Binance-Peg BTCB (at least a disclosed upgradeable-proxy contract architecture, also rejected in this registry). JustCryptos discloses no contract addresses and no custody structure beyond ”Poloniex,” and that custodian has a confirmed nine-figure hot-wallet loss on record. Holding the native asset avoids all of this. The custodian’s owner, Justin Sun, is a separate source of regulatory-optics risk that this registry has already documented elsewhere. The SEC’s 2023 unregistered-securities and wash-trading suit against Sun was dropped in February 2025 shortly after Sun invested $30-75M in the Trump family-linked World Liberty Financial venture. This registry’s USDD memo treats that timeline as an unresolved conflict-of-interest fact rather than a settled matter, and it applies just as directly to Poloniex’s owner.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- AlphaGrowth — JustCryptos & JST Token · secondary · accessed 2026-08-17
Supports: product overview - JUST Network — official site · primary · accessed 2026-08-17
Supports: mechanism description, supported assets, Poloniex dependency - Cryptopolitan — Justin Sun’s Poloniex hacked for over $100 million · secondary · accessed 2026-08-17
Supports: November 2023 hack - Crypto Daily — Poloniex hacker identified, $10M bounty offered · secondary · accessed 2026-08-17
Supports: incident response - Decrypt — Justin Sun-owned exchange Poloniex hacked for at least $126 million · secondary · accessed 2026-08-17
Supports: loss figure
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|