Revolut Plus
A plan byRevolut · Visa/Mastercard
Data verified on last change the sources
Worth it if you want a multi-currency account with an EU banking licence and deposit protection up to €100,000.
Avoid it if you want to self-custody your crypto, or you exchange beyond your plan’s monthly threshold.
Revolut is a multi-currency account with a European banking licence, available in 180+ countries and offering access to 200+ cryptos and stocks from the app. It provides a dedicated IBAN, direct debits and third-party transfers like a real bank. Crypto, however, is not self-custodied and KYC account freezes are frequent; FX is free only within a threshold.
Plus
- Price
- €4
- Issuance fee
- Free
- FX markup
- 0.5%
- Cashback currency
- Nessuno
- Required staking
- Nessuno
- ATM fee
- 2%
- ATM limit
- €200/mese gratis, poi 2%
- Net annual cost
- €48
- Free FX/month
- €3,000
- Free ATM/month
- €200
What's included
- 1 free subscription
- Purchase protection
- Ticket refund
Free card delivery. Exchange: +1% at weekends (Fri 5pm–Sun 6pm New York time) on all plans.
Data & conditions
§ Amounts in USD/GBP are shown in the service's native currency.
| Account fee | Free |
|---|---|
| IBAN | dedicato · LT · LT, GB, IE |
| Deposit guarantee | EU guarantee €100,000 |
| Multi-currency | Yes · 36 currencies |
| Outbound transfers to third-party IBANs | Yes |
| Utility direct billing | Yes |
| SEPA direct debit (SDD) | Yes |
| On-chain crypto withdrawal | Yes |
| SEPA transfer | Free |
| Card included | Carta virtuale e fisica inclusa |
| Interest on balance | 1.21% |
| Network | Visa/Mastercard |
| ATM withdrawal | 2% |
| Free ATM limit | €200–2,000/month free (plan-based), then 2% |
| Fund custody | Custodial (platform holds funds) |
| KYC | Full |
| Supported countries | EEA, UK, US, APAC, LATAM · 180+ countries |
| Stocks | Real — you own the security |
| Fractional shares | Yes |
| ETF | Yes |
| Stock and ETF commission | 0.25% of the order (0.12% on Ultra), €1 minimum, once the plan's free trades are used (1 Standard, 3 Plus, 5 Premium, 10 Metal and Ultra); no custody fee, 35 USD per position to transfer holdings to another broker |
| Securities custody | Revolut Securities Europe UAB (registered holder); assets in an omnibus account with a third-party provider |
| Italian withholding agent | No — you self-declare |
| Regulator | Bank of Lithuania, FCA |
| OAM Italy registration | Yes |
| Segment | B2C |
| Funding / solidity | 75M+ users · $75B valuation (Nov 2025) · $1.5B net profit (2024) |
| MiCA / License status | Licenza bancaria EUEMI (UK)FCA FCA (UK) · ECB/Bank of Lithuania (EU) |
Strengths
- Multi-currency account with EU banking licence and €100k deposit guarantee
- 180+ countries and 200+ cryptos and stocks in-app
- Dedicated IBAN, third-party transfers and direct debits like a bank
- No notable sovereignty advantage documented.
Weaknesses
- Crypto is not self-custodied
- Frequently reported account freezes for KYC checks
- FX free only within the plan’s monthly threshold
- Custodial: the platform holds your funds and can freeze or lose them.
- Full KYC required: verified identity, zero pseudonymity.
- Subject to regulation (FCA (UK) · ECB/Bank of Lithuania (EU)): reporting to authorities and freezes on order.
Verdict
The S rating is the top of the category: a multi-currency account with a European banking licence, deposit guarantee up to EUR 100,000, coverage in over 180 countries, a dedicated IBAN with direct debits and third-party transfers, and 200+ cryptos and stocks in-app. Available in Italy and OAM-registered. The only caveat for consumers is FX free only within the plan's monthly threshold and frequently reported account freezes for KYC checks.
The very strengths that help protection become limits here: crypto is not self-custodied and the frequent KYC account freezes show that it is Revolut deciding if and when you can reach your funds. An excellent custodial crypto showcase, but the antithesis of self-custody and censorship resistance.
Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.
"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.
Reputation
What happened to people who used Revolut, and what users say. External signals: they do not feed the promp.it rating.
Incidents & regulatory actions
Notable incidentsDocumented events with consequences still open. Each entry carries a source and a date.
-
Data breach Severe ● open
Data handed over to someone posing as a government agency: identity documents, verification selfies and full transaction history, Bitcoin included
This was not an intrusion: Revolut handed the data over itself, believing it was answering a government agency. A fraudulent information request came from an unauthorised account using the REAL email domain of a government agency — not a lookalike, the authentic one — and therefore passed sender authentication checks. In the notice sent to customers the company writes that it fulfilled the request «under the reasonable belief that it was an authentic government agency request». According to Revolut's notice, made public on 11 September 2026 by investigator ZachXBT who shared a copy, the data handed over includes: full name, date of birth, occupation, postal address, email and phone number; copies of identity documents (passport or driving licence) and the verification selfies submitted at onboarding; and on the financial side IBANs, account status and opening date, Bitcoin wallet reference numbers appearing in account statements, withdrawal records and the complete transaction history, including Bitcoin transfers. Revolut specifies that biometric facial telemetry data — distinct from the selfie images, which did leak — was not part of the disclosure. On 12 September 2026 a spokesperson publicly confirmed the episode to TechCrunch, calling it «a sophisticated external impersonation scam», and stated that «Revolut systems and customer funds are unaffected»: there were no account takeovers and no withdrawals. The company blocked the email address, alerted the government agency involved, law enforcement and financial regulators, and notified affected customers directly. WHAT WAS NOT KNOWN on 12 September, and it mattered: Revolut said a «limited» number of customers was affected but refused to give the figure or say which markets (see the 15 September update at the end); it does not name the impersonated agency; and it does not explain how a third party came to use its official domain. ZachXBT notes the number of accounts appears contained but that the attack seems aimed at high-net-worth individuals. The date on which the data was actually handed over is not known: the date recorded here is that of the notification emails received by customers. UPDATE 14-15 September 2026 — THE DATA IS NOW BEING PUBLISHED, NOT MERELY HELD. Accounts claiming to be behind the attack have opened a public extortion campaign across several Telegram groups. The Register, which saw those posts directly, reports that they contain snippets of data apparently belonging to high-profile individuals — chief executives, professional sportspeople, performing artists — and that the posters are threatening to release «more and more data every day until Revolut pays for leaking their customers», demanding a ransom of 10,000 bitcoin (over USD 780 million at 14 September 2026 prices). Recorded Future News reports the same demand and adds two elements: a customer whose data was circulated as proof did not dispute its authenticity, and among those publicly saying they were affected is Mark Karpelès, former chief executive of Mt. Gox. The Telegram account was subsequently suspended. Revolut, approached by both outlets, declined to comment on the existence of the ransom demand. BE CLEAR ON WHAT IS PROVEN AND WHAT IS NOT: that the extortion campaign exists and that excerpts of the data are circulating is documented by two independent outlets that saw the posts first-hand; that whoever is publishing them is genuinely the party that took the data remains THEIR claim, not an established fact, and no authority has confirmed it. A further UNCONFIRMED indication, which we report because it bears directly on readers in Italy: again according to Recorded Future News, the images circulated by that account suggest the fraudulent email originated from an ITALIAN domain. Italian authorities approached by the outlet did not respond, Revolut still does not name the agency, and the outlet itself states that not all details contained in the posts could be verified: this is an indication, not a finding. Sources close to the company tell The Register that the share of customers affected is small and that ongoing investigations and confidentiality obligations prevent it from saying more. It is not known whether the same compromised domain was used against other financial firms. UPDATE 15 September 2026 — THE FIGURE ARRIVES, AND THE REGULATORS SPEAK. The Financial Times, picked up by Reuters and by subsequent coverage, puts a number on the episode for the first time: 680 customers were affected, and Revolut has contacted all of them directly. The figure does not come from a company statement — Revolut had consistently refused to give one — but from press reporting: the company has neither denied nor publicly confirmed it. On the markets involved, something is finally visible: Irish public broadcaster RTÉ reports that 12 of the 680 are in Ireland, out of roughly 3.4 million Revolut customers in the country — a sign that the individuals were picked one by one, not lifted from an entire market. For Italy there is still no figure. On the authorities' side, silent until 14 September, there are now two public statements, and they should be read for what they actually say: the UK's ICO, the data protection regulator, states «we can confirm we have received a report and are assessing the information provided» — that is a preliminary assessment, NOT the formal opening of an investigation, and several outlets have wrongly reported it as one; the FCA, the UK financial regulator, says it is «aware of the reported incident involving Revolut» and is «engaging with the firm to understand the impact». Neither has announced any enforcement step. Meanwhile the extortion has not stopped: the group claiming the attack calls itself «Revolut Smilik» and has confirmed it wants a payment, repeating that it will publish «more and more data every day» until one arrives. Revolut still declines to comment. UPDATE 16-17 September 2026 — THE CHANNEL HAS A NAME AND IT IS ITALIAN, AND THE RANSOM COLLAPSES FROM 780 MILLION TO 3. (1) HOW THE REQUESTS ARRIVED. Since 12 September one precise question had gone unanswered: how did an outsider come to write from an authority's authentic domain? The channel the requests travelled on is now known: PEC, Italy's certified email system, the legally recognised service used by public administrations, companies and private citizens. According to Corriere della Sera sources, picked up on 16 September by Il Fatto Quotidiano and MilanoFinanza, the mailbox used is said to be that of the Prefecture of Reggio Calabria; the same name appears in a parliamentary question tabled by Democratic Party senators Lorenzo Basso and Antonio Nicita. BE CLEAR ON WHAT IS NOT ESTABLISHED, because the difference is substantial here: it is NOT settled whether the mailbox was genuinely taken over by someone — forensic experts are circulating the hypothesis of an infostealer, that is credentials stolen from a computer — or whether the sender was spoofed from outside. These are two scenarios with very different consequences for anyone using PEC, and the investigations exist precisely to tell them apart: until they do, the graver version is not the one written here. Italy's postal police is investigating for unauthorised access to a computer system and computer fraud; the National Cybersecurity Agency and the Bank of Italy are carrying out their own checks; the Italian data protection authority has opened enquiries. Italian authorities approached by the Irish Times declined to comment, while confirming that investigations are under way. The perpetrators further claim to hold 147 GB of material — 36,393 files in 5,223 folders — taken from Italian law enforcement systems: that is THEIR claim, verified by nobody, and should be read as such. (2) THE RANSOM DEFLATES. On 16 September the group published a 24-hour countdown and lowered its demand from 10,000 bitcoin to 6,000 monero, roughly USD 3 million, threatening otherwise to sell the files of the 680 customers to other criminal groups. The Financial Times reports this, having been shown a 60-second screen recording containing passports, driving licences and banking records, and CoinDesk picked it up on 16 September along with other outlets on 17 September. For the first time Revolut says something about the ransom, after days of «no comment»: «Revolut has not received any direct contact or demand from the individuals or group making these claims.» How to read that: a demand published on Telegram with a timer but never delivered to the company is pressure aimed at the public and the victims, not a negotiation under way; and a price falling from over 780 million to 3 in two days says above all that nobody is paying. (3) WHERE THE 680 ARE. Most are said to be in Switzerland and France, with residents of some thirty other countries — including the UK, Germany and Spain. This too is attributed to the attackers and not confirmed by Revolut. For Italy there is still no figure for affected customers: in this affair Italy appears as the origin of the channel used, not as the targeted market. (4) NOTHING HAS CHANGED ON THE REGULATORS, and this needs saying because the opposite is being written everywhere: numerous outlets, Italian ones included, state that the UK's ICO «opened an investigation» on 14 or 15 September. The ICO's own words are unchanged — it has received a report and is assessing the information provided — and on 15 September MLex, the specialist regulatory outlet, still headlined that the report «is being assessed». Until an act or a sentence from the authority says otherwise, the weaker verb is what stands here. Revolut has published nothing about the incident on its own X account: the latest post is from 3 September and concerns conditional approval from the US OCC. UPDATE 17 SEPTEMBER 2026 — WHERE THE CREDENTIALS CAME FROM, AND WHICH GROUP ENTITY RECEIVED THE REQUESTS. (1) For the first time there is a figure with a name attached instead of a generic hypothesis. Threat intelligence firm Hudson Rock says it holds roughly 300 compromised pec.interno.it webmail credentials in its own database — the certified-mail domain of the Italian Ministry of the Interior, which the Prefectures report to — all originating from machines previously infected by infostealers, the programs that harvest passwords saved in a browser. The firm draws an assessment from this, and words it carefully: the attackers may have bought or reused credentials already stolen by others, without needing to infect an Italian government employee themselves. CyberInsider reported this on 16 September 2026 and SecurityWeek on 17 September 2026. WHAT CHANGES AND WHAT DOES NOT: what changes is that the «infostealer» hypothesis now has a name and a number behind it, instead of being talk circulating among forensic experts; what does not change is that it remains unproven. A private firm's assessment is not the outcome of an investigation, and no Italian authority has yet said whether the mailbox was actually taken over or whether the sender was spoofed from outside. So both hypotheses stand here, exactly as before. The same articles also report — as the attackers' claim, not as verified fact — that a recovery address was added to the mailbox and the traffic monitored continuously, with outgoing fraudulent messages deleted. (2) IT IS NOW KNOWN WHICH GROUP ENTITY RECEIVED THE REQUESTS: not the British entity but Revolut Bank UAB, the group's Lithuanian bank, which serves customers in the European Economic Area, Italy included. Both outlets state this. (3) THE DEADLINE HAS PASSED AND NOBODY KNOWS HOW IT ENDED. The 24-hour countdown opened on the afternoon of 16 September expired on the afternoon of 17 September: as of the evening of 17 September no source reports a payment, a bulk publication of the 680 files, a sale to other groups or a fresh demand. Not knowing how it went is not good news: it only means nothing public has happened. The extortion remains open. On its own X account Revolut has now been silent about the incident for two weeks: the latest post is still the 3 September one about the OCC. UPDATE 19 SEPTEMBER 2026 — THE EXTORTION GOES QUIET, AND THIS ENTRY STOPS BEING FLAGGED AS «ONGOING». Forty-eight hours past the ransom deadline — the countdown expired on the afternoon of 17 September — still nothing public has happened: no payment, no bulk publication of the 680 files, no sale to other criminal groups, no fresh demand, no new claim. The coverage in this window repeats what was already known, with no new facts. Revolut remains silent about the incident on its own X account: the latest post is still the 3 September one about the OCC. So one thing changes, and it concerns how this case is displayed: until today the home security monitor flagged it as «ongoing», the state reserved for what is happening as you read it — an attack under way, funds moving, withdrawals still frozen. That is no longer the case here: the handover of the data was completed on 11 September, the threat to publish has been static for two days, and the Italian data protection authority's enquiries and the UK ICO's assessment are proceedings, not emergencies. The case therefore moves to the «open» state: not closed — the data is out and stays out — but nothing is happening right now. This is not a downgrade of how serious it is, which is unchanged, and it is reversible within an hour: if the 680 files are published or sold, or a new demand arrives, this entry returns to «ongoing» the same day. UPDATE 22 SEPTEMBER 2026 — THERE ARE TWO CLAIMED PERPETRATORS AND THEY ACCUSE EACH OTHER, THE DATA WAS ALREADY OUT IN JULY, AND MEANWHILE THE TEXT MESSAGES HAVE STARTED. (1) IT IS NOT ONE GROUP, AND UNTIL TODAY THIS ENTRY NAMED ONLY ONE: the correction comes first. Above you can read that the group «calls itself Revolut Smilik». In fact TWO Telegram channels claimed the attack: «IAmNotAVillain», the one behind the 6,000 monero demand (about 3 million dollars), and «Revolut Smilik», the one behind the 10,000 bitcoin demand. The former claims the latter is «an impersonator and scammer who used to work with us», who was handed a small sample of the data and is now claiming the whole breach as his own, and warns victims not to negotiate with anyone else. Both channels were suspended by Telegram; «iamnotavillain» later reappeared on a website of its own. This is reconstructed by KELA (analysis updated 15 September 2026) and BankInfoSecurity (15 September 2026). WHAT IT MEANS FOR THE READER: anyone among the 680 who gets contacted cannot tell from the name who actually holds their file — and the very fact that a sample passed between two parties means the data has already circulated. Which of the two versions is true has been established by nobody: these are criminals' competing claims, and we report them as such. (2) THE DATA WAS OUT BY LATE JULY AT THE LATEST — TWO MONTHS BEFORE CUSTOMERS WERE NOTIFIED. BankInfoSecurity reports that those blackmailed include Mark Karpelès, former CEO of Mt. Gox, crypto entrepreneur Marc Zeller and Felix Romer, founder of the gambling platform Gamdom, along with other industry figures, contacted directly by the perpetrator. One victim documented receiving extortion threats with Discord chat screenshots dated 26 JULY 2026, roughly two months before Revolut made the episode public. PRECISION ABOUT DATES IS NEEDED HERE, because it is the point on which this entry could most easily go wrong: the incident date remains 11 September 2026 because that is the verifiable date of the notification emails to customers, and the actual date the data was handed over is still not established either by Revolut or by any authority. What is now documented is something else, and it is enough to change how the case reads: the extortion of individual victims was already under way in July. Anyone who got the email on 11 September was not being told about something that had just happened. (3) HOW LONG IT ALLEGEDLY LASTED, AND WHY THE LITHUANIAN BANK SPECIFICALLY. According to the account the perpetrators gave the Financial Times, relayed by SecurityWeek on 17 September 2026, by American Banker on 18 September 2026 (updated 20 September) and by Cybernews, Revolut answered the fraudulent requests for about FIVE TO SIX MONTHS, not on a single occasion. The perpetrators say they picked Revolut Bank UAB, the Lithuanian subsidiary, precisely because it is obliged to answer a European Investigation Order — the cross-border demand for evidence that one EU member state can send another: they did not get around a compliance procedure, they targeted the duty to comply itself. They also say they selected their targets through on-chain analysis, identifying Revolut accounts holding significant crypto balances — which explains why the 680 are almost all people with visible wealth rather than a random slice of the customer base. American Banker adds the harshest detail: in at least one case a request submitted in the wrong form raised no suspicion, and Revolut staff reportedly explained how to correct it. IMPORTANT, AND DECISIVE: this entire paragraph is the PERPETRATORS' OWN ACCOUNT, given to the press and amplified from there. Revolut has confirmed neither the duration nor the number of requests, no authority has established it, and Cybernews itself headlines it as a claim. We do not write it as fact: we write it as what it is, a self-serving version which nonetheless comes from the only party that knows what happened, and which so far has not been denied. (4) THE EXTORTION SITE, AND ITS NUMBERS. KELA's analysis describes the infrastructure: a static page hosted on GitHub Pages, domain and DNS at GoDaddy, payment subdomain on GoDaddy Payments — something thrown together quickly with free or near-free services, not a structured organisation. The page displays screenshots presented as proof of the exchanges with the Italian mailbox and with the address [email protected], accuses Revolut of ignoring the breach notifications, and offers a contact via Telegram and Session to journalists and affected people alike. It claims nineteen «Document Revolut» archives and a 326 MB folder containing 688 files. A NOTE ON THE NUMBERS: 688 files are not 688 customers, and they do not match the 680 reported by the Financial Times; these are counts published by the perpetrators on their own site, not verified data. (5) THE MOST USEFUL THING TO KNOW TODAY: THE TEXT MESSAGES HAVE STARTED. Malwarebytes, which spotted it first (17 September 2026), and Infosecurity Magazine (21 September 2026) document a smishing campaign against Revolut customers. One affected customer received the message on Monday 14 September 2026, two days after the public announcement, and — this is the detail that makes the scam work — the text appeared IN THE SAME THREAD as genuine Revolut messages, slotting into the real conversation. The link leads to a page that asks for access to the phone's camera and, if granted, imitates Revolut's live video identity check, the one that asks you to turn your head, before asking for your password. The point is to harvest a selfie or video that can be reused to pass verification elsewhere or to make the next scam convincing. WHAT IS NOT PROVEN, and the company that found the campaign says so itself: Malwarebytes writes that «we don't yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly». The link to the breach is NOT treated as established here — and it is also why this campaign does not become a separate Revolut incident: third-party phishing is not the provider's own act. For the reader it makes little difference, because the defence is the same either way, and it is set out below. (6) WHY THIS ENTRY STAYS «OPEN» AND DOES NOT RETURN TO «ONGOING». On 19 September this entry set three conditions for returning to the «ongoing» state: bulk publication of the 680 files, their sale to other groups, or a fresh ransom demand. As of today none of the three has happened, and no source reports a payment. The extortion site is not a new fact — it already existed on 15 September, so before that decision: it simply had not been recorded here. The text-message campaign is the work of third parties and is not attributed to Revolut. The state therefore remains «open»: the case is not closed, the data is out and stays out, but nothing is happening right now that touches systems or funds. The earlier commitment still stands: if the files are published or sold, or a new demand arrives, it returns to «ongoing» the same day. On its own X account, Revolut still says nothing about the incident.
↗ source -
Regulatory action Severe ● open
Italian Competition Authority: EUR 11.5 million for unfair commercial practices, EUR 5 million of it over account freezes
The Italian Competition Authority fined the group EUR 11.5 million in total: EUR 5m for failing to disclose the extra costs and limits of “commission-free” investing, including fractional shares; EUR 5m for aggressive practices in suspending, limiting and blocking payment accounts, with insufficient pre-contractual information, no advance notice, no chance to respond and no adequate assistance; EUR 1.5m for unclear information on the requirements and timeframe to obtain an Italian IBAN instead of a Lithuanian one. Revolut said it disagrees with the findings and will appeal.
↗ source -
Fine Severe ✓ resolved
Bank of Lithuania: EUR 3.5 million fine for anti-money-laundering failings
A penalty on Revolut Bank UAB, the largest ever imposed by Lithuania's central bank. A scheduled inspection found deficiencies in monitoring business relationships and transactions, with failures to flag suspicious operations. No actual money laundering cases were established. Revolut settled via an administrative agreement and said it had fixed the procedural shortcomings.
↗ source -
Data breach Severe ✓ resolved
Data breach exposing 50,150 customers' personal data
Unauthorised database access via social engineering. 50,150 customers affected, 20,687 of them in the European Economic Area: names, addresses, emails, phone numbers and partial card data. Revolut said no PINs, passwords or funds were exposed and notified Lithuania's data protection authority. A wave of phishing SMS to users followed in the following days.
↗ source -
Data breach Moderate ● open
Breach at DriveWealth, the US broker Revolut used for US share trading: data exposed for customers who invested before December 2023, notices sent on 24 September 2026
Between 4 and 5 September 2026 an unauthorised party entered the network of DriveWealth, the New York broker-dealer that supplied Revolut with the infrastructure for US share trading, and exfiltrated personal data. Access was obtained through a social engineering campaign. On 24 September 2026 Revolut began emailing affected customers: these are European Economic Area users who traded US shares before December 2023, when data sharing with DriveWealth ended — the data was still being retained to meet regulatory requirements. For records linked to Revolut, the exposed information includes name, email address, phone number, postal address, employment information, country of citizenship, age, gender and part of the DriveWealth account number; in some cases the date of birth as well. According to DriveWealth's official notice, no passwords and no financial payment information such as credit card or bank account details were compromised, and identity documents were not compromised; the company further states that "no unauthorized brokerage account activity including trading, transfer, withdrawal, ACAT request, or balance or position alteration was identified". Revolut said its own systems, funds and customer accounts were not affected: the breach hit the supplier, not the bank. No figure for the number of Revolut customers involved has been published; DriveWealth's notice cites approximately 62,000 Rhode Island residents across its whole customer base, a figure that cannot be attributed to Revolut users alone. The same incident hit customers of the brokers Stake (notified on 21 September) and Hatch (on 22 September), which use the same infrastructure. It is the second episode in under two weeks to expose Revolut customer data, after the 11 September handover of identity documents and full transaction history to someone impersonating a government authority.
↗ source -
Hack / funds theft Moderate $20M ✓ resolved
Flaw in US payment systems exploited for over $20 million
A mismatch between European and US payment systems meant that on certain declined transactions Revolut erroneously refunded accounts with its own money. Organised criminal groups exploited the loophole for several months during 2022. The loss hit company money, not customer accounts, and only came to light after a US partner bank flagged it. The loophole was later closed. The date shown is that of the press report, not of the event.
↗ source
verified on
Public reviews
-
Google Play ↗
4.8/5
~
4,050,000 reviews
Count rounded by Google Play (4.05 million).
-
Trustpilot ↗
4.7/5
429,473 reviews
Read with caution: this is a paid profile and Revolut actively invites customers to review. Nearly all positive reviews read carried the “Invited” label, while negative ones were organic. There is no separate Italian page: it.trustpilot.com shows the same global profile, localised.
-
App Store ↗
4.9/5
~
220,000 reviews
Count rounded by the Italian App Store (220K ratings).
Weighted average across 3 public review platforms (4,699,473 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.
Community signal
not verified by usPublic opinions collected from third parties, not verified by us. Online reviews can be manipulated: read them as a hint, not as data. The promp.it verdict remains the one above, based solely on official documents.
What users praise
- Competitive FX rates and predictable spending abroad
- Fast, intuitive app: everything managed from the phone
- Instant transfers and easy bill splitting
- Many features in one app: multi-currency accounts, investing, savings
- Well suited to frequent travellers
What users criticise
- Sudden account freezes for “standard checks”, with no notice and no defined timeline
- Support only via in-app chat, often a chatbot, with no reachable human agent
- Fraud and unauthorised transactions not refunded, liability denied
- Transfers held or stuck for weeks
- Opaque costs: higher ATM withdrawal fees and penalties for downgrading paid plans
The service’s own official accounts are excluded from the count. Sample limited to Italian-language Trustpilot reviews from the last six months: 21 one-star and 12 five-star reviews read directly. Reddit and X were not accessible during verification and were excluded. Important caveat: the Trustpilot profile is a paid one and the positive reviews read were nearly all solicited by invitation, while negative ones were organic. The “mixed” band reflects exactly that gap between very high aggregate scores and negative organic feedback — a gap consistent with the Italian Competition Authority's findings on account freezes.
Voices from the community
-
I've been using it for a year now, mostly abroad, and I've never had any problems. I recommend it to everyone!
-
Account frozen for “standard checks”. Without notice, without explanation. You can't freeze the account of a business with recurring payments coming in and out. It lasted 10 days. Customer service's answer is always the same: we're sorry, we appreciate your patience, you'll be notified when the check is complete.
-
Account frozen, no human agent, just a chatbot and no certainty. After a week of being blocked I only dealt with chatbots and AI: there's no person to explain things to. If everything runs smoothly it's excellent, but if there's a problem it becomes a nightmare.
Every quote links to its original source: check for yourself, don’t trust the summary.
FAQ
Is crypto on Revolut self-custodied?
No: Revolut holds the crypto on your behalf, you do not control the private keys directly.
Does Revolut have deposit protection?
Yes, euro balances are covered by the EU guarantee up to €100,000 thanks to the EU banking licence.
How much does it cost to buy stocks and crypto on Revolut?
On stocks each plan includes a number of free trades per month (1 on Standard, 3 Plus, 5 Premium, 10 Metal and Ultra); beyond that you pay 0.25% of the order (0.12% on Ultra) with a €1 minimum. On crypto the fee depends on plan and 30-day volume: it starts at 1.49% on Standard and Plus below €10,000, 0.99% on Premium and Metal, 0.49% on Ultra.
Sources
- Official service page Plans & pricing · Regulatory framework · Trust & safety · Investors · +3 Data verified on Aug 25, 2026
- help.revolut.com Issuer · On-chain crypto withdrawals · Commissione azioni · Custodia titoli · +2 Data verified on Aug 25, 2026
- coindesk.com Past incidents Data verified on Jun 15, 2026
- cshub.com Past incidents Data verified on Jun 15, 2026
Show 6 more sources
- danelfin.com Stock ticker · Stock listing · IPO date Data verified on Jun 15, 2026
- investingintheweb.com Savings interest Data verified on Jun 15, 2026
- accountancyage.com Trust & safety Data verified on Jun 14, 2026
- app.intigriti.com Trust & safety Data verified on Jun 14, 2026
- caproasia.com Issuer Data verified on Jun 14, 2026
- globalbankingandfinance.com Company profile Data verified on Jun 14, 2026
Update history
- Filled the gap on investing costs. Stocks: real, fractional shares held through Revolut Securities Europe UAB, 0.25% per order (0.12% on Ultra) with a €1 minimum beyond the plan's free trades (1/3/5/10), no custody fee but 35 USD per position to transfer holdings out. Crypto: 1.49% below €10,000 of 30-day volume on Standard and Plus, falling to 0.49% above €250,000; Premium and Metal start at 0.99%, Ultra at 0.49% down to 0% above €250,000. Revolut is not an Italian withholding agent: capital gains and dividends must be self-declared.
- Real cost of the first card on the Standard plan clarified: issuance is free but delivery costs €6.99 (€19.99 express). Also documented the weekend exchange surcharge: +1% on all plans.
🔔 Notify me of changes
If you sign up from here we earn a commission, at no extra cost to you. It doesn’t change the rating: we tell you so you can check us.