Proof of Reserves: What It Actually Proves — and What It Doesn't
Crypto exchanges increasingly publish 'proof of reserves' to reassure customers, but the exercise has real limits that investors should understand.

The short answer
- Proof of reserves (PoR) is a way to show that an exchange holds crypto assets matching customer balances at a specific point in time.
- It typically combines a cryptographic count of on-chain holdings with an attestation, but it is not the same as a full financial audit.
- PoR generally does not verify liabilities beyond what's disclosed, off-chain assets, or whether the exchange has any debt or double-counted collateral.
- Regulators and accounting bodies have flagged that these reports are usually 'agreed-upon procedures,' not audits under generally accepted auditing standards.
- Investors should treat PoR as one data point among many, not a guarantee of solvency or safety of funds.
After several high-profile collapses in the crypto industry, exchanges began publishing what they call 'proof of reserves' reports. The idea sounds reassuring: a exchange demonstrates it actually holds the crypto assets it says it does. But the term covers a range of practices, and understanding its limits matters as much as understanding what it shows.
What Proof of Reserves Actually Involves
In its most common form, proof of reserves has two parts. First, the exchange or a third party takes a snapshot of customer account balances and produces a cryptographic summary, often using a method called a Merkle tree, which lets individual users verify their own balance was included without seeing everyone else's data. Second, the exchange shows that its on-chain wallet balances, at that same moment, are equal to or greater than the sum of customer balances. Some exchanges hire an accounting or auditing firm to perform this comparison and issue a report.
The core claim, when done correctly, is narrow: at a specific point in time, the assets on the blockchain that the exchange controls were sufficient to cover the liabilities it reported to the reviewer. That is a useful signal, but it is far more limited than many customers assume.
What It Does Not Verify
- Liabilities beyond what's disclosed: The exercise typically relies on the exchange's own reported customer balances. It does not independently confirm that all liabilities, including loans, promissory notes, or obligations to institutional partners, were included.
- Point-in-time snapshots, not continuous coverage: Reserves can be moved before or after the snapshot. A healthy balance on the day of the report says nothing about the day before or after.
- Off-chain or non-crypto assets: Cash held at banks, equity investments, or other assets are usually outside the scope of a crypto-focused proof of reserves.
- Control and legal ownership: Showing an exchange has access to keys controlling certain wallets is not the same as proving those assets are legally unencumbered, or that they haven't been borrowed to appear on the balance sheet temporarily.
- Double-counting risk: If the same collateral is pledged in reserve for multiple platforms or reused shortly before and after a snapshot, headline totals can be inflated without violating the letter of the exercise.
Why This Isn't the Same as an Audit
Groups like the American Institute of Certified Public Accountants (AICPA) have noted that most proof-of-reserves reports are structured as 'agreed-upon procedures' engagements, not full audits performed under generally accepted auditing standards. In an agreed-upon procedures report, the accounting firm performs specific, limited steps that the client asks for and reports factual findings, but it does not offer an opinion on whether the financial statements as a whole are fairly presented or free of material misstatement. That distinction matters: a report can be accurate about what it checked while still leaving significant blind spots about the company's overall financial health.
The U.S. Securities and Exchange Commission and other regulators have separately emphasized, in various public statements and enforcement contexts, that platforms dealing in crypto assets are subject to standard disclosure and custody rules where applicable, and that marketing claims about reserves or safety of customer funds should not be mistaken for regulatory endorsement or audited financial statements.
How to Read a Proof-of-Reserves Report
- Check who performed it: An independent accounting firm's involvement is generally more meaningful than a report an exchange produces entirely in-house.
- Look for the scope statement: Does it explicitly say what was and wasn't covered, including whether liabilities were independently verified?
- Note the date: A snapshot from months ago tells you little about current conditions.
- Consider it alongside other signals: Regulatory licensing, insurance disclosures, corporate transparency, and the entity's regulatory history all matter for assessing custodial risk.
The Bottom Line
Proof of reserves can add a useful layer of transparency, letting customers cryptographically verify that their balance was included in a snapshot that matched on-chain holdings. But it is not a substitute for a full financial audit, and it says little about liabilities, off-chain assets, or what happens between snapshots. Investors who custody assets on any platform, crypto or otherwise, should treat these reports as one input among several when assessing counterparty risk, not as a guarantee that funds are safe.
Sources
- AICPA guidance on proof-of-reserves engagements and agreed-upon procedures — AICPA & CIMA
- SEC statements on crypto asset market participants and disclosure — U.S. Securities and Exchange Commission
- FDIC consumer guidance on crypto and deposit insurance misconceptions — Federal Deposit Insurance Corporation
Spotted an error? Tell our corrections desk.
