More
    Real-World Asset (RWA) TokenizationProof of Reserves for Exchanges: How Verification Really Works

    Proof of Reserves for Exchanges: How Verification Really Works

    Categories

    Quick Answer

    Proof of reserves for an exchange is a snapshot check that customer-owned crypto liabilities are matched, dollar for dollar (or coin for coin), by assets the exchange actually controls in its own wallets. A credible program combines a Merkle-tree liability proof — so any user can verify their own balance is included in the total without seeing anyone else’s — with an on-chain asset attestation and, ideally, a third-party review of the methodology. It is not an audit, it does not check for hidden debt or loans against those coins, and a single clean snapshot says nothing about the days before or after it was taken.

    In November 2022, FTX told the world it held reserves against customer deposits right up until the week it didn’t. That gap between what a platform says on its homepage and what actually sits in its wallets became the defining question of the cycle that followed, and it hasn’t gone away — it has just gotten more technical. By 2026, proof of reserves (PoR) has moved from a marketing slide into something closer to table stakes: exchanges that skip it get quietly excluded from institutional onboarding lists, and the ones that do it badly get picked apart by researchers within days of publishing a report.

    The reason this still matters, three-plus years after FTX, is that the underlying problem never fully went away. Exchanges are still, structurally, custodians holding other people’s money while also running a business that has every incentive to use that money productively — for market making, for lending, for covering shortfalls elsewhere. Proof of reserves exists to make that temptation visible before it becomes a crisis rather than after. This guide walks through how the mechanics actually work, where the method breaks down, and how to read a PoR report the way a skeptical analyst would rather than the way a press release wants you to.

    Why Proof of Reserves Became Non-Negotiable in 2026

    Three forces pushed proof of reserves from a nice-to-have into an expected baseline. First, regulation caught up. The EU’s Markets in Crypto-Assets framework (MiCA) imposes reserve and safeguarding obligations on custodians and e-money token issuers operating in the bloc, and national regulators have used those powers to demand evidence, not assurances. Second, institutional capital arrived in volume. Pension allocators, corporate treasuries, and RIAs that added digital assets to client portfolios over the past two years generally will not custody with a venue that cannot produce a verifiable reserve snapshot on request — it is now a line item in their due-diligence checklists. Third, the tooling matured. Merkle-proof libraries, zero-knowledge attestation frameworks, and on-chain oracle feeds that were experimental in 2022 are now off-the-shelf, which removed the excuse that verifiable reserves were too expensive or too technically difficult to build.

    None of that means the problem is solved. A 2025 review of nine major venues by independent researchers found that fewer than half published liability proofs a customer could actually verify against their own account, and only a handful updated the underlying data more often than once per quarter. Proof of reserves works exactly as well as the exchange chooses to make it work, and the choices vary enormously from one venue to the next.

    What a Proof of Reserves Attestation Actually Certifies

    A complete proof of reserves has two halves that are frequently confused with each other. The first half is the liability side: proving how much the exchange owes its customers in total, broken down by asset. The second half is the asset side: proving the exchange actually controls enough of each asset, in wallets it can move funds from, to cover that liability. A report that only shows one half is not proof of reserves — it is half a proof, and the half that is missing is usually the more important one.

    Showing a screenshot of a large wallet balance proves nothing on its own. Wallets can be borrowed for a day, rented from a market maker, or simply belong to a different part of the balance sheet than the part backing customer deposits. The liability proof is what turns a big number into a meaningful one, because it lets an outside party check that the asset total is being compared against a real, itemized account of what is owed — and, ideally, that their own balance is one of the line items that got counted.

    It’s worth being precise about what PoR does not do, because vague claims are where most of the public confusion sits:

    • It does not confirm the exchange has no debt. An exchange can hold 100% of customer coins in wallets and simultaneously owe a lender 40% of its equity — PoR is silent on corporate liabilities that sit outside the customer-liability ledger.
    • It does not confirm the coins were not borrowed for the snapshot. Without a commitment to continuous or randomly-timed proofs, a reserve check taken once a quarter can be gamed by temporarily topping up wallets.
    • It does not verify legal title. Holding the private keys to a wallet is not the same as having an unencumbered legal claim to the assets in it — collateral pledges and rehypothecation agreements do not show up in a wallet balance.
    • It does not check off-chain fiat. Cash sitting at a partner bank cannot be proven with a blockchain signature; it has to be confirmed through bank letters or attestation, which reintroduces exactly the trust problem PoR was built to remove.

    The Merkle-Tree Liability Proof, Step by Step

    The dominant method for proving liabilities without exposing every customer’s balance to the public is a Merkle tree, and it is worth understanding the mechanics rather than taking the word “cryptographic” on faith.

    The exchange takes every customer account balance for a given asset — say, all customer BTC balances — and treats each one as a “leaf” in a tree. Each leaf is hashed (run through a one-way function that turns the balance and account identifier into a fixed-length string of characters). Pairs of leaves are hashed together to form the next layer up, pairs of those are hashed together again, and so on, until the whole customer base collapses into a single hash at the top: the Merkle root. That root is published, dated, and — this is the important part — it changes completely if even one customer’s balance one layer down is altered by a single unit. There is no way to tweak the totals after publication without the root visibly changing.

    Once the root is public, each customer can be given their own “proof path” — the specific chain of sibling hashes needed to recompute the root starting from their own balance. Running that computation locally lets a customer confirm two things without needing to trust the exchange’s claim: that their balance was genuinely included in the total the root represents, and that the total wasn’t quietly adjusted after the fact. Crucially, the proof path reveals nothing about any other customer’s balance — only the hashes, not the underlying numbers.

    Summing every leaf value gives the aggregate liability figure — the number that then gets compared against the on-chain asset total. This is where a second cryptographic technique, a “sum Merkle tree,” is often layered in: rather than just proving inclusion, the tree structure itself proves that the total of all leaves equals a specific published sum, without any single node in the tree revealing individual balances. Kraken, Binance, and OKX have each published variations of this approach since 2023, with differing update frequencies and differing willingness to let independent researchers audit the underlying tree-construction code rather than just the published root.

    On-Chain Asset Verification and the Wallet-Attestation Problem

    The asset side sounds simpler than it is. In principle, an exchange signs a message with the private key controlling a wallet, proving control of that address, and then anyone can look up the public balance on a block explorer. In practice, three complications routinely undercut the clean story.

    The first is scope. Exchanges typically hold reserves across dozens of hot and cold wallets, sometimes across multiple chains and multiple custodians. A published list of “reserve wallets” is only as trustworthy as the claim that it is complete — an exchange could publish twelve verified wallets while quietly excluding a thirteenth that holds a large chunk of the shortfall. Because there is no public registry mapping every wallet to every exchange, completeness has to be taken partly on faith unless a third party independently traces on-chain flows, which most retail-facing reports don’t do.

    The second is timing. A wallet balance is a snapshot at a single block height. Nothing stops a venue from moving assets in immediately before the snapshot and moving them back out an hour later — a practice researchers have taken to calling “window dressing,” borrowed directly from the language traditional accountants use for balance-sheet manipulation around reporting dates. The fix is either continuous proofs (checked automatically at short, unpredictable intervals) or randomly-timed spot checks by an independent party, and both are still rare outside the largest venues.

    The third is encumbrance. A wallet can hold the coins and still not be “free” collateral if those coins have been pledged elsewhere — posted as collateral for a credit line, lent out through a rehypothecation agreement, or staked in a way that restricts withdrawal for a lock-up period. None of that shows up in a simple balance check. A responsible attestation discloses staked and encumbered amounts as a separate line item rather than folding them into the headline reserve ratio.

    Where Zero-Knowledge Proofs and Chainlink-Style Feeds Fit In

    Two newer pieces of infrastructure have started to close some of these gaps, though neither is a complete fix.

    Zero-knowledge proof-of-reserves (often shortened to zk-PoR) lets an exchange prove a mathematical statement — “the sum of these encrypted liability leaves equals this published total, and every leaf value is non-negative” — without revealing any individual balance, and without even revealing the full customer count if that’s a design choice. The advantage over a plain Merkle tree is that a zk-proof can also enforce constraints a Merkle tree alone can’t, such as proving no negative balances were smuggled into the total to artificially inflate the liability figure and make the reserve ratio look worse than it should (a technique that would otherwise let an exchange manufacture cover for a real shortfall). The tradeoff is verification cost and complexity: generating and checking these proofs is computationally heavier, and most third-party auditors still don’t have the specialized tooling to independently reproduce the proof rather than simply trusting the exchange’s own circuit.

    Separately, on-chain oracle networks — Chainlink’s Proof of Reserve feed is the most widely integrated — continuously pull attested reserve data on-chain so that DeFi protocols can react automatically. A lending protocol that accepts a wrapped or custodied asset as collateral can wire its risk parameters to a live PoR feed: if the reported reserve ratio backing that asset drops below a set threshold, the protocol can automatically raise collateral requirements, pause new borrowing against it, or trigger a review, rather than waiting for a human to notice a news headline. This is a meaningful upgrade for composability inside DeFi, but it only shifts the trust problem one layer down — the oracle feed is still only as honest as the data the custodian chooses to report into it.

    A Worked Example: Auditing “Nova Exchange’s” Reserve Ratio

    Numbers make this concrete faster than definitions do. Consider a hypothetical mid-sized venue — call it Nova Exchange — publishing a quarterly proof of reserves.

    Nova’s Merkle-tree liability proof, summed across all customer accounts, shows the following owed to customers:

    • 42,600 BTC
    • 1,850,000 ETH
    • $310,000,000 in USDC

    Nova’s published reserve wallets, verified by signed messages and checked against a public block explorer at the snapshot block height, show:

    • 43,150 BTC held in cold and hot wallets
    • 1,790,000 ETH held in cold and hot wallets
    • $322,000,000 in USDC held across two verified addresses

    The reserve ratio for each asset is simply assets held divided by liabilities owed:

    • BTC: 43,150 / 42,600 = 101.3%
    • ETH: 1,790,000 / 1,850,000 = 96.8%
    • USDC: 322,000,000 / 310,000,000 = 103.9%

    Two things should jump out. First, the BTC and USDC ratios look reassuring, sitting comfortably above 100%. Second, the ETH ratio does not — Nova is short roughly 60,000 ETH, or about 3.2% of what it owes customers in that asset. A well-run attestation flags this explicitly rather than burying it in a single blended “reserve ratio” figure, because averaging across assets can hide a real, asset-specific shortfall behind healthy numbers elsewhere. If Nova’s average across all three assets, weighted by dollar value, happens to land at 101%, a careless headline could report “Nova Exchange: 101% reserves” while quietly ignoring that ETH depositors specifically are undercollateralized.

    A shortfall of this size has plausible innocent explanations — some ETH may be staked and earning yield for the platform under disclosed terms, with a maturity date before which it can’t be withdrawn, or a portion may be temporarily deployed with a market maker under a formal loan agreement disclosed elsewhere in the report. The point of a rigorous proof of reserves is not that every shortfall is a red flag; it’s that the shortfall is visible and asset-specific rather than smoothed away by blended math, so anyone evaluating the exchange can ask the right follow-up question instead of taking a single comforting number at face value.

    Reserve Ratio by Asset — Nova Exchange, Q3 Snapshot

    Dashed red line marks the 100% break-even point where assets held equal liabilities owed.

    BTC
    101.3%
    ETH
    96.8%
    USDC
    103.9%

    Bar length is scaled for visual comparison, not to a literal 0–200% axis. The ETH bar sits alone below the dashed break-even marker, which is exactly the kind of asset-level gap a blended average would hide.

    How the Major Verification Methods Stack Up

    Not every “proof of reserves” claim rests on the same rigor. The table below lines up the four methods in active use in 2026, what each one actually verifies, and — more usefully — what it leaves unverified.

    MethodWhat it verifiesWhat it missesTypical update cadence
    Signed wallet disclosureExchange controls the private keys to a specific, named addressWhether the wallet list is complete; liabilities; encumbranceVaries — often one-time or ad hoc
    Merkle-tree liability proofA customer’s balance was included in the published total; the total wasn’t altered after publicationWhether matching assets actually exist; snapshot timing gamesMonthly to quarterly, typically
    zk-proof of reservesSum of liabilities equals a published figure with no negative-balance manipulation, without exposing individual accountsWallet completeness; requires specialized tooling to independently re-verify the circuitEmerging — mostly continuous where deployed
    Third-party AUP attestationAn accounting firm independently re-ran the exchange’s own stated procedures and got the same resultDoes not opine on internal controls, solvency, or hidden liabilities — explicitly not a financial statement auditPoint-in-time, usually quarterly at best

    The key phrase in that last row — Agreed-Upon Procedures, or AUP — deserves its own callout, because it’s the single most misunderstood term in this whole topic. An AUP engagement is not an audit opinion. The accounting firm agrees, in advance, to check a narrow, exchange-defined set of procedures (for example: “confirm that address X held at least Y BTC at block height Z”) and reports factually on whether those specific checks passed. It explicitly disclaims any opinion on the exchange’s overall financial health, internal controls, or the completeness of the procedures themselves. Several major firms pulled out of crypto AUP work entirely after 2022 precisely because the public kept describing these narrow engagements as “audits,” a mischaracterization the firms were unwilling to keep being associated with.

    Common Mistakes That Undermine a Proof of Reserves Program

    Most weak PoR programs fail in one of these predictable ways, whether by accident or by design:

    • Publishing assets without liabilities. A wallet balance with no corresponding, verifiable customer-liability figure is a screenshot, not a proof.
    • One-time stunts. A single glossy report published after a competitor collapses, with no commitment to repeat the process, tells you about one day and nothing about the days on either side of it.
    • Blended ratios that hide per-asset gaps. As the Nova Exchange example shows, a healthy weighted-average number can conceal a specific asset running short.
    • No customer-level inclusion proof. If individual users can’t verify their own balance was counted, the “total” is simply an assertion dressed up in cryptographic language.
    • Excluding staked, lent, or rehypothecated assets from disclosure. Folding encumbered coins into the headline reserve figure without a separate line item overstates what’s actually free to withdraw on demand.
    • Treating an AUP letter as an audit in marketing copy. This is the single fastest way to lose credibility with anyone who has actually read the underlying engagement letter.
    • Ignoring off-chain fiat entirely. Cash reserves at partner banks need bank confirmation letters or equivalent third-party evidence; a PoR report that only covers crypto assets while a large share of liabilities sit in fiat is incomplete by construction.

    A Practical Checklist for Evaluating an Exchange’s Reserves

    Before treating any published proof of reserves as meaningful reassurance, work through this list:

    • Can you generate and verify your own Merkle inclusion proof from your account dashboard, not just read a claim on a blog post?
    • Are reserve ratios broken out by individual asset, or only shown as a single blended percentage?
    • How often is the snapshot refreshed — and is there any commitment to unpredictable or continuous checks rather than a scheduled, announceable date?
    • Does the report separately disclose staked, lent, or otherwise encumbered assets rather than folding them into the free-reserve figure?
    • Is fiat currency (if applicable) covered by a bank confirmation or equivalent third-party letter, or only the crypto side?
    • Does the exchange name the specific accounting firm and publish the engagement letter, or only describe the process in marketing language?
    • Has any independent researcher or security firm attempted to reproduce the Merkle root from raw data, and did the exchange make that possible?
    • Is there a public list of every reserve wallet address, and does the total number of addresses look plausible given the exchange’s known scale?
    • Does the exchange disclose related-party lending — loans to or from affiliated trading desks, market makers, or founders — anywhere near the reserve report?

    Key Takeaways

    • Proof of reserves has two required halves — a liability proof and an asset proof — and a report showing only one half is not a complete proof.
    • Merkle trees let individual customers verify their own balance was counted without exposing anyone else’s data, which is the feature that separates real PoR from a marketing screenshot.
    • Reserve ratios should be read per asset, not as a single blended number, because averaging can hide a real shortfall in one specific coin.
    • An Agreed-Upon Procedures letter from an accounting firm is not an audit and does not certify solvency, internal controls, or the completeness of disclosed wallets.
    • Zero-knowledge proofs and on-chain oracle feeds are closing some gaps — particularly around privacy and automated risk response in DeFi — but neither one solves wallet-completeness or encumbrance disclosure on its own.
    • The most useful signal isn’t a single clean report; it’s a consistent, repeatable, independently checkable process sustained over many quarters.

    Frequently Asked Questions

    Is proof of reserves the same thing as an audit?

    No. Proof of reserves is typically delivered through a Merkle-tree liability proof paired with an on-chain asset check, sometimes reviewed under an Agreed-Upon Procedures engagement. An AUP engagement only confirms that specific, narrowly defined checks passed — it does not certify overall financial health, internal controls, or solvency the way a full financial statement audit does.

    Can an exchange fake a proof of reserves report?

    It can create a misleading one, most commonly by borrowing assets into wallets right before a scheduled snapshot and moving them out shortly after, or by publishing an incomplete list of reserve wallets. Continuous or randomly-timed verification, rather than a single announced date, is the main defense against this kind of window dressing.

    What does a reserve ratio below 100% actually mean?

    It means the exchange holds less of that specific asset than it owes customers in that asset. It is not automatically evidence of fraud — the shortfall might reflect disclosed staking, a documented loan to a market maker, or a timing lag in reporting — but it does mean depositors of that particular asset are not fully collateralized at that moment, and the exchange should explain why.

    Why can’t proof of reserves verify fiat currency the way it verifies crypto?

    Blockchain-based proofs work because wallet balances and signatures are publicly verifiable on-chain. Bank balances have no equivalent public ledger, so confirming fiat reserves still depends on bank confirmation letters or third-party attestation, which reintroduces a layer of institutional trust that on-chain crypto verification was specifically designed to remove.

    How often should a trustworthy exchange update its proof of reserves?

    More frequently than once per quarter is preferable, and continuous or randomly-timed checks are stronger than any fixed, announced schedule, because a known date can be prepared for in advance. Consistency over many reporting cycles matters more than the polish of any single report.

    A useful next step, once you understand how liability proofs work for exchanges specifically, is to look at how the same verification logic gets applied one layer up — to entire pools of tokenized assets rather than a single custodian’s balance sheet, which is exactly the ground covered in this site’s broader look at how tokenized real-world assets are rewiring capital markets.

    References

    1. Chainlink Labs — “Proof of Reserve: Bringing Verifiable Collateral Data On-Chain.”
    2. Kraken — “Proof of Reserves: Methodology and Merkle Tree Documentation.”
    3. Binance — “Proof of Reserves Program Overview and Auditor Engagement Letters.”
    4. Nic Carter, Castle Island Ventures — “Uses and Abuses of Proof of Reserves Attestations.”
    5. American Institute of CPAs (AICPA) — “Agreed-Upon Procedures Engagements: Guidance for Practitioners.”
    6. European Commission — “Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA).”
    7. New York State Department of Financial Services — “Guidance on Custodial Structures for Customer Protection in Virtual Currency Custody.”
    8. Financial Stability Board — “Recommendations for the Regulation of Crypto-Asset Activities.”
    9. CryptoQuant Research — “Exchange Reserve Tracking Methodology and On-Chain Flow Analysis.”
    10. World Economic Forum — “Rebuilding Trust in Digital Asset Markets: Custody, Verification, and Disclosure.”

    Lucy Wilkinson
    Lucy Wilkinson
    Finance blogger and emerging markets analyst Lucy Wilkinson has a sharp eye on the direction money and innovation are headed. Lucy, who was born in Portland, Oregon, and raised in Cambridge, UK, combines analytical rigors with a creative approach to financial trends and economic changes.She graduated from the University of Oxford with a Bachelor of Philosophy, Politics, and Economics (PPE) and from MIT with a Master of Technology and Innovation Policy. Before switching into full-time financial content creation, Lucy started her career as a research analyst focusing in sustainable finance and ethical investment.Lucy has concentrated over the last six years on writing about financial technology, sustainable investing, economic innovation, and the influence of developing markets. Along with leading finance blogs, her pieces have surfaced in respected publications including MIT Technology Review, The Atlantic, and New Scientist. She is well-known for dissecting difficult economic ideas into understandable, practical ideas appealing to readers in general as well as those in finance.Lucy also speaks and serves on panels at financial literacy and innovation events held all around. Outside of money, she likes trail running, digital art, and science fiction movie festivals.

    LEAVE A REPLY

    Please enter your comment!
    Please enter your name here

    Recent Posts

    More

      Institutional DeFi Pools: How Permissioned Liquidity Works

      0
      A deep-dive on how institutional DeFi pools use KYC-linked allowlists and permissioned token standards like ERC-3643 to let banks and treasuries earn on-chain yield with identified counterparties.

      Impermanent Loss Explained: A Guide for Liquidity Providers

      0
      Answer box: Impermanent loss is the value gap that opens up between holding two tokens in your wallet and holding those same two tokens...

      DeFi Real Yield vs. Emissions: Which One Actually Pays You

      0
      Verdict up front: Real yield — return paid out of a protocol's actual trading fees, borrowing spreads, or funding-rate income — is the only...

      DeFi Lending Risk Assessment: A 2026 Risk Brief

      0
      Answer Box DeFi lending protocol risk assessment means checking four things before you deposit or borrow: whether the smart contracts have been independently audited and...

      Restaking Risk Explained: Slashing, Depegs, and Layered Exposure

      0
      Short answer: Restaking risk is the danger that comes from pledging the same staked capital to secure more than one protocol at once. Instead...

      More From Author

      More

        Tokenized Commodity Warehouse Receipts: How the Market Works

        Quick Answer A tokenized commodity warehouse receipt is a blockchain-recorded claim on a specific, physically stored lot of a commodity, most often copper cathode, aluminum,...

        Tokenized Money Market Funds as Collateral: A 2026 Deep Dive

        Repo desks used to treat weekends as a liquidity blackout. Collateral sat still, cash sat still, and everyone waited for Monday's wire windows to...

        Institutional DeFi Pools: How Permissioned Liquidity Works

        A deep-dive on how institutional DeFi pools use KYC-linked allowlists and permissioned token standards like ERC-3643 to let banks and treasuries earn on-chain yield with identified counterparties.

        Impermanent Loss Explained: A Guide for Liquidity Providers

        Answer box: Impermanent loss is the value gap that opens up between holding two tokens in your wallet and holding those same two tokens...