A proof of reserves is a cryptographic check that answers one narrow question: does a crypto exchange or custodian actually hold the digital assets it claims to hold on behalf of its customers? It pairs blockchain verification of wallet balances with a privacy-preserving tally of what the platform owes its users, and if reserves meet or exceed those obligations, the report passes. What it does not do is evaluate the exchange’s debts, judge whether those reserve assets could be sold at their stated value, or tell you anything about the day after the snapshot. Understanding the gap between what the procedure proves and what it quietly ignores is the difference between informed trust and false confidence.
What the Report Is Trying to Prove
The target is a 1:1 reserve ratio: every token a customer sees in their account should correspond to a real token sitting in a verifiable wallet. If an exchange claims to hold 100,000 Bitcoin on behalf of users, the report checks that wallets under the exchange’s control contain at least that amount.
That sounds reassuring, and it is, as far as it goes. The catch is that “as far as it goes” is not nearly as far as most users assume. Think of the report as a photograph of someone’s wallet, not a portrait of their financial health.
How the Asset Side Gets Verified
Verifying reserves means proving that the exchange controls specific blockchain wallets and confirming how much those wallets hold. Blockchain balances are public, so anyone can look up how much Bitcoin sits at a given address. The hard part is proving who controls the wallet.
The exchange demonstrates control by signing a challenge message with the private key associated with each wallet. This works the same way you would prove you own an email account by responding to a verification link. The signed message typically includes a timestamp and a unique random value, called a nonce, so that the signature cannot be reused from a prior audit. If the cryptographic signature checks out against the wallet’s public key, ownership is confirmed for that moment.
An auditor or the public can then independently verify the wallet balance on the blockchain. The total across all verified wallets becomes the reserves figure in the report. This part of the process is genuinely robust. Blockchain math does not lie about balances, and cryptographic signatures are essentially impossible to forge. The manipulation risks live elsewhere.
How the Liability Side Gets Verified
The liability side is harder and more trust-dependent. The exchange needs to prove how much it owes all of its customers combined, without revealing any individual customer’s balance. The standard tool is a Merkle tree, a data structure that lets you verify a piece of data belongs to a larger set without seeing the rest of the set.
The simplified version: the exchange takes every customer’s balance, hashes it into an irreversible string, and pairs those hashes together. Each pair gets hashed again, and those results get paired and hashed again, layer after layer, until a single hash sits at the top. That top hash, the Merkle root, is a cryptographic fingerprint of every customer balance in the tree. The sum of those balances is the platform’s total liability. The auditor compares that liability against the total reserves. If reserves meet or exceed liabilities, the report passes.
The Merkle Tree’s Blind Spot
The core problem is that the exchange itself builds the Merkle tree from its own internal database. If the exchange omits accounts, fabricates negative balances, or simply lies about what customers are owed, the Merkle tree will faithfully reflect that fraudulent data. A Merkle root proves internal consistency, not honesty. Verifying that the inputs are complete and truthful requires either trusting the exchange or applying additional checks well beyond a standard proof of reserves engagement.
Zero-Knowledge Proofs as an Upgrade
Some platforms now pair Merkle trees with zero-knowledge proofs, specifically zk-SNARKs, to close part of that gap. A zero-knowledge proof lets the exchange prove that every account balance in the tree is non-negative and that the sum is correct, without publishing any of the underlying balances. This prevents the negative-balance trick, where an exchange inserts fabricated accounts with negative values to artificially reduce reported liabilities. Individual balances stay hidden while the mathematical constraints are verifiable by anyone. It is a meaningful improvement, but it still relies on the exchange providing a complete customer list.
What Proof of Reserves Does Not Cover
The limitations are where informed users separate themselves from everyone else. The procedure’s narrow scope creates several gaps that can make a passing report dangerously misleading.
Off-Chain Liabilities
The report covers only on-chain customer balances. It says nothing about the exchange’s traditional debts: bank loans, vendor obligations, corporate bonds, intercompany transfers, or margin obligations. An exchange could control $500 million in Bitcoin while owing $600 million to creditors, and the report would show everything as fully backed. It shows asset coverage against customer deposits. It does not reveal solvency.
Asset Quality
Reserves get counted at face value. If 40% of the reserves consist of the exchange’s own proprietary token, an illiquid altcoin, or assets locked in a staking contract with a six-month withdrawal period, the report treats them identically to Bitcoin or stablecoins. In a bank run scenario, those reserves might be worth a fraction of their reported value or simply unavailable. The report confirms quantity, not liquidity or realizability.
Snapshot Timing
Every report reflects a single moment. The exchange’s financial position could change dramatically minutes afterward. This creates a well-known gaming opportunity: an exchange can borrow assets before the snapshot, pass the audit, then return them. The industry calls this window dressing, and it is essentially undetectable from the report alone. A quarterly or even monthly snapshot gives no assurance about the other 29 days.
Borrowed or Encumbered Assets
A related problem is that the report does not distinguish between assets the exchange owns outright and assets it has borrowed, rehypothecated, or pledged as collateral elsewhere. Wallets verified through cryptographic signing prove control at that moment, not unencumbered ownership. An exchange could be showing you assets it is obligated to return to a lender next week.
Who Performs the Audit, and Why It Matters
Most proof of reserves engagements are structured as agreed-upon procedures, a type of accounting engagement in which the auditor performs only the specific tests the client asks for. The auditor does not express an opinion on whether the financial picture is fair or complete. They confirm only that the math they were asked to check adds up.
There are currently no established professional audit standards specifically governing this work. The scope is whatever the exchange and auditor negotiate, which means two reports from different exchanges might cover very different ground even though both carry the same label.
The fragility of that arrangement became visible in late 2022 when Mazars Group, the accounting firm conducting Binance’s proof of reserves work, paused all such engagements with crypto clients. The method Mazars used examined only the reserves side of Binance’s balance sheet without vetting claims about liabilities. After Mazars withdrew, Binance publicly stated that it had approached the Big Four accounting firms, all of which were unwilling to conduct the work for a private crypto company. That reluctance from established auditors tells you something about the professional risk these engagements carry.
How It Compares to a Traditional Financial Audit
People sometimes treat a proof of reserves report as roughly equivalent to a financial audit. It is not, and the differences are not just technical.
A traditional financial audit covers everything: the balance sheet, income statement, cash flows, all assets and liabilities on-chain and off, and the internal controls the company uses to produce its financial reports. The auditor evaluates whether the books, taken as a whole, fairly represent the company’s financial position. A proof of reserves covers one slice: do these specific wallets hold at least as much as these specific customer balances?
A full financial audit provides reasonable assurance that the statements are free from material misstatement, the highest level of confidence an auditor offers. A proof of reserves engagement typically provides limited assurance at most, and many are structured as agreed-upon procedures that provide no assurance at all. The auditor simply reports findings from the specific tests performed.
Publicly traded companies are required to file audited financial statements with the SEC, including annual reports on Form 10-K containing an independent auditor’s report.1SEC.gov. All About Auditors: What Investors Need to Know Those audits follow Generally Accepted Accounting Principles and are examined by auditors registered with the Public Company Accounting Oversight Board. Proof of reserves, for most crypto exchanges, remains entirely voluntary.
Where Regulation Is Starting to Require It
For general-purpose crypto exchanges, proof of reserves remains a marketing decision rather than a legal obligation. The GENIUS Act (Guiding and Establishing National Innovation for U.S. Stablecoins Act) changes that specifically for stablecoin issuers. The law requires permitted payment stablecoin issuers to publish a monthly composition report of their reserves, examined each month by a registered public accounting firm, with the CEO and CFO personally certifying accuracy.2Federal Register. Implementing the Guiding and Establishing National Innovation for US Stablecoins Act for the Issuance of Stablecoins by Entities Subject to the Jurisdiction of the Office of the Comptroller of the Currency
Stablecoin issuers with more than $50 billion outstanding face an additional requirement: annual GAAP-compliant financial statements audited under PCAOB standards, the same framework that governs publicly traded companies.2Federal Register. Implementing the Guiding and Establishing National Innovation for US Stablecoins Act for the Issuance of Stablecoins by Entities Subject to the Jurisdiction of the Office of the Comptroller of the Currency
Worth flagging: the GENIUS Act applies to stablecoin issuers, not to exchanges holding Bitcoin, Ethereum, or other volatile assets on behalf of traders. For those custodians, no federal law currently requires a proof of reserves report. Whether broader legislation eventually extends mandatory reserve verification to exchanges is an open question.
Continuous Verification as an Alternative to Snapshots
The snapshot problem has pushed the industry toward continuous verification systems that monitor reserves automatically rather than relying on periodic reports. Chainlink’s Proof of Reserve product is the most prominent example, providing automated on-chain monitoring that publishes verified reserve data to the blockchain in near real-time.3Chainlink. Proof of Reserve Rather than trusting a quarterly PDF, users and smart contracts can query reserve status at any time.
The more interesting feature is programmable enforcement. Automated reserve feeds can be wired into a token’s minting logic so new tokens cannot be created unless reserves cover them. Circuit breakers can pause redemptions or cap withdrawals when reserve ratios drop below thresholds. Projects using this approach include wrapped Bitcoin products, tokenized treasury instruments, and at least one major Bitcoin ETF seeking to increase transparency around its holdings.3Chainlink. Proof of Reserve
Continuous verification does not solve every problem. It still cannot see off-chain liabilities or assess asset quality. But it eliminates the window-dressing problem entirely, because there is no defined snapshot window to game.
How to Verify Your Own Inclusion
If an exchange publishes a proof of reserves report, you can usually check whether your balance was included in the liability calculation. The exchange provides you with two pieces of data: your leaf hash, a cryptographic representation of your account balance, and a Merkle path, a set of intermediate hashes connecting your leaf to the published root. You combine your leaf hash with the first hash in the path, run them through the same hash function the tree uses, and repeat at each level. If your final computed hash matches the Merkle root the exchange published, your balance was included in the total.
Most exchanges that offer this verification provide an in-app tool that does the computation for you with one click. If you want to verify independently without trusting the exchange’s own tool, open-source verification scripts are available for most major implementations. One caveat: you are confirming that your balance was included in the tree, not that the tree is complete. Other accounts could still be missing.
What to Look for in a Report
Not all reports are equal, and the label alone tells you very little. When evaluating one, the details that matter most are often the ones buried in footnotes or simply absent.
- Who performed the audit. A registered public accounting firm carries more weight than an unnamed internal team or a blockchain analytics company. If no auditor is named, treat the report skeptically.
- What assets were included. A report covering only Bitcoin while the exchange holds dozens of tokens is leaving most of the picture out.
- Whether liabilities were independently verified. Some reports verify only the asset side and take the exchange’s word on liabilities. That is half an audit at best.
- Whether user verification is available. If the exchange does not offer a way for you to check your own Merkle proof, the liability side is essentially unverifiable by anyone outside the engagement.
- What is excluded. Read scope limitations carefully. Exclusions for “certain asset types,” “assets held by affiliated entities,” or “balances subject to pending transactions” can hide significant gaps.
A proof of reserves report is a useful data point when you understand its boundaries. It confirms that specific wallets hold specific amounts and that a stated set of customer balances falls within that coverage. Treat it as one input alongside the exchange’s regulatory status, insurance coverage, corporate structure, and track record. The exchanges that collapsed did not fail because their reserves reports were wrong. They failed because the things a reserves report does not measure were catastrophically broken.