Trading 101

/

August 18, 2026

Proof of Reserves: What It Proves and What It Does Not

Merkle tree attestations commit to a snapshot of customer balances, not to solvency. A source-checked walk through what each proof of reserves format demonstrates, what it omits, and how strong the evidence is for each claim.

Blog Image
★★★★★
GET UP TO
$30,050 USDT
GET DEAL
★★★★☆
CLAIM UP TO
$8,000 USDT
GET DEAL
★★★★☆
GET 20% OFF
TRADING FEES
GET DEAL
★★★★★
No.1 DEX
VVIP LEVEL UP  
GET DEAL

Proof of reserves became the crypto industry's favourite trust signal after FTX collapsed in November 2022. Nearly four years on, most large exchanges publish some form of Merkle tree attestation, and the marketing around these reports routinely implies more than the underlying cryptography delivers. A Merkle tree attestation demonstrates that a snapshot of customer balances was committed to at one moment in time, and that on-chain assets at that moment matched or exceeded the committed total. It does not demonstrate solvency. It says nothing about bank loans, tax bills, legal judgments, obligations to affiliates, or whether the assets shown were borrowed for the occasion. This article works through what each proof of reserves format actually establishes, what each one omits, and where the evidence for these claims is strong or weak. It is a factual reference and does not constitute investment or financial advice.

What does a proof of reserves actually demonstrate?

A standard proof of reserves demonstrates two narrow facts: that the exchange controlled certain on-chain addresses at a snapshot date, and that the balances in those addresses equalled or exceeded a committed total of customer liabilities at that same date. The mechanism has two halves. On the asset side, the exchange signs messages from its wallets or moves funds at an agreed time, showing control of the keys. On the liability side, it builds a Merkle sum tree, a data structure in which every customer balance is a leaf, every parent node holds the sum and hash of its children, and the root commits to the grand total. Each customer receives a path from their leaf to the root, so they can check that their own balance was included in the total without seeing anyone else's.

That inclusion check is the entire customer-facing guarantee. As Ethereum co-founder Vitalik Buterin set out in his 19 November 2022 essay on the topic, the scheme's safety rests on enough users actually verifying their proofs, because an exchange that omitted accounts from the tree would only be caught if the omitted users checked. No major exchange publishes what share of its users perform this check, so the deterrent strength of the mechanism is not publicly measurable. That gap matters when a company's ability to survive a bank-run scenario is precisely the thing depositors care about, a dynamic familiar from the wider financial sector, where fintech bankruptcies surged even among firms with reassuring public dashboards.

Why did proof of reserves become the industry standard after FTX?

Because it was fast, cheap, and available at a moment when the alternative, a full audit, was not on offer. FTX filed for bankruptcy in November 2022, and within weeks nearly every large exchange rushed out a reserves page. The rollout immediately drew criticism from inside the industry. Kraken's then chief executive Jesse Powell said in late November 2022 that Binance's early publication was "pointless without liabilities," arguing that an asset list means nothing unless an independent party confirms that all customer claims, including accounts with negative balances, were counted (Cointelegraph, November 2022).

The accounting profession's brief involvement then fell apart in public view. Mazars, the firm that had produced an agreed-upon procedures report on Binance's bitcoin reserves in early December 2022, paused all proof of reserves work for crypto clients on 16 December 2022, citing "concerns regarding the way these reports are understood by the public" and stressing that such reports "do not constitute either an assurance or an audit opinion" (CoinDesk, 16 December 2022). Note the scope of what Mazars had actually examined: one asset, bitcoin, under agreed-upon procedures, at one date. Six days later, on 22 December 2022, the SEC's acting chief accountant Paul Munter warned investors to be "very wary" of proof of reserves claims, saying such a report "is not enough information for an investor to assess whether the company has sufficient assets to cover its liabilities" (Cointelegraph, December 2022).

The most complete official statement of the limits came on 8 March 2023, when the PCAOB's Office of the Investor Advocate issued an advisory telling investors to exercise caution because proof of reserve reports "are inherently limited." The advisory listed what these engagements do not address: the entity's total liabilities, the rights and obligations of asset holders, whether assets were borrowed to inflate the snapshot, whether assets remained available after the engagement date, and the effectiveness of internal controls (PCAOB Investor Advisory, 8 March 2023). That list, from the audit regulator itself, is the cleanest available statement of the gap between what these reports prove and what they are read as proving.

What does a Merkle tree attestation leave out?

It leaves out everything on the liability side that the exchange chose not to put in the tree, and everything that happened outside the snapshot moment. The omissions fall into five categories, each with a different level of severity.

Completeness of the liability set

A Merkle tree authenticates the records placed inside it. It cannot reveal accounts, product categories, or affiliated-entity obligations that were left out before the tree was built. Off-chain liabilities such as bank loans, tax obligations, or guarantees to sister companies never appear, because the format has no place for them. Buterin's essay is explicit that the fiat side of an exchange's balance sheet "would inevitably rely on fiat trust models," meaning banks and auditors, not cryptography.

The snapshot problem

Assets are measured at one instant, and nothing prevents funds from moving before or after it. The illustrative episode is the transfer of 320,000 ETH, worth roughly 416 million dollars at the time and about 85 percent of Crypto.com's ETH cold storage, to a Gate.io address on 21 October 2022, with around 285,000 ETH returned between 25 and 30 October (CryptoSlate, November 2022). Both companies denied any connection to reserve reporting. Crypto.com's chief executive called it a transfer to a whitelisted address made in error, and Gate.io stated that its own proof of reserves snapshot, taken on 19 October, predated the arrival of the funds. No wrongdoing was demonstrated, and the on-chain timing supports Gate.io's account. The episode still shows why the format invites suspicion: a point-in-time snapshot cannot, by construction, distinguish owned funds from borrowed ones, which is exactly the "borrowed assets" gap the PCAOB named in its advisory.

Negative balances and implementation bugs

A naive Merkle sum tree lets an operator insert fake accounts with negative balances to shrink the apparent liability total. Binance's answer, launched on 10 February 2023, was to add zk-SNARK proofs over batches of 864 users, proving that every leaf contributed to the claimed total and that no user's net balance was negative, with the prover code open sourced (Binance blog, 10 February 2023). The fix promptly demonstrated a further lesson: on 14 February 2023, security firm Hacken found a bug in that open-sourced circuit. A missing range check on the BasePrice parameter allowed the total user debt assertion to be bypassed, meaning fake debt figures could have passed verification, and Binance acknowledged that proofs generated before the fix could not be treated as valid (crypto.news, February 2023). The vulnerability was fixed after disclosure. The point is not that Binance acted in bad faith, there is no evidence of that, but that "cryptographically proven" is only as strong as the specific circuit, and circuit bugs are invisible to every user clicking a verify button.

Key control and encumbrances

Signing a message proves access to a key at that moment, not exclusive or continuing control. Kraken's own proof of reserves page, to its credit, states plainly that the method cannot "prove exclusive possession of private keys" and cannot "identify any hidden encumbrances" over the assets shown (Kraken proof of reserves page, accessed 18 August 2026). An asset that has been pledged as collateral elsewhere looks identical on-chain to an unencumbered one.

Assurance level of the engagement itself

Most third-party involvement in proof of reserves takes the form of agreed-upon procedures under AT-C section 215, not an examination under AT-C section 205 and not an audit. An agreed-upon procedures report recites what steps were performed and what was found, and expressly does not offer an opinion. The Network Firm, an accounting practice that performs these engagements and therefore has an interest in presenting them favourably, still concedes that customer legal rights to recover assets sit outside scope and that typical engagements cover only 70 to 80 percent of platform value, often just bitcoin and ether (The Network Firm blog). An admission against interest from a provider is worth noting, though the 70 to 80 percent figure is that firm's characterisation of its own market rather than an independently measured statistic.

Proof of reserves formats: what each demonstrates and what each omits
FormatWhat it demonstratesWhat it omits
Published wallet addressesAssets existed at those addresses when checkedOwnership vs borrowing, all liabilities, key control over time
Merkle tree self-attestationCommitted liability snapshot, per-user inclusion checksCompleteness of the tree, off-chain liabilities, anything after the snapshot
Agreed-upon procedures report (AT-C 215)A named firm performed listed steps at a date and reports findingsAny opinion or assurance, internal controls, liabilities beyond the defined scope
zk-SNARK or zk-STARK proof of reservesMerkle guarantees plus no negative balances, without exposing user dataEverything the Merkle format omits, plus reliance on the correctness of the circuit
Audited financial statementsOpinion on the full balance sheet including liabilitiesPoint-in-time as of the reporting date, depends on auditor quality

What do the big exchanges actually publish in 2026?

As of August 2026 the large exchanges publish regular Merkle-based reports, increasingly with zero-knowledge layers, and none of it amounts to a solvency statement. OKX publishes monthly, its July 2026 report being its 45th, using a zk-STARK over 22 listed assets and displaying self-reported reserve ratios between roughly 101 and 112 percent, for example 105 percent for BTC and 103 percent for ETH (OKX proof of reserves page, accessed 18 August 2026). Those ratios are the exchange's own presentation, not independently audited figures. Kraken's most recent snapshot is dated 30 June 2026, covers six assets including BTC, ETH, SOL, USDC, USDT and XRP, extends to margin and futures collateral, and is reviewed by an independent accountant whom the public page does not name (Kraken proof of reserves page, accessed 18 August 2026). Binance continues its zk-SNARK plus Merkle system. Coinbase, as a US-listed company, publishes audited consolidated financial statements instead, which an August 2026 CryptoSlate review of the sector describes as the only disclosure among major venues that covers the full financial position including liabilities (CryptoSlate, 8 August 2026).

Reserve disclosures at major exchanges, as of 18 August 2026
ExchangeMethodCadence and scopeIndependent involvement
BinanceMerkle tree plus zk-SNARK, code open sourcedPeriodic snapshots, major assetsNone currently disclosed on an opinion basis
OKXMerkle tree plus zk-STARKMonthly, 22 assets, self-reported ratios 101 to 112 percentSelf-published, no audit opinion
KrakenMerkle tree with client-side verificationRegular snapshots, latest 30 June 2026, six assets plus margin and futures collateralIndependent accountant, unnamed on the public page
CoinbaseAudited financial statements as a listed companyQuarterly and annual filings, full balance sheetRegistered public auditor, PCAOB oversight

What would proving solvency actually require?

Solvency is assets minus all liabilities, so proving it requires a complete liability picture that no on-chain format can supply on its own. A Merkle proof can, at best, commit to the customer deposits an exchange admits to. The bank debt, the tax position, the intercompany guarantees and the litigation exposure live in the traditional accounting world, which is why the credible end state looks like cryptographic proofs for the crypto-native part combined with financial statement audits and regulatory supervision for the rest. That hybrid is already the direction of travel in adjacent regulated sectors. Banks entering crypto custody do so under FDIC-supervised custody frameworks, and the capital treatment of their crypto exposures is being fought out under Basel III rules that banks are actively pushing back on. Both regimes assume examined balance sheets, not screenshots of wallet dashboards.

The standard-setting work has moved slowly. The AICPA published proposed criteria for stablecoin issuers' reserve disclosures on 5 December 2023, with feedback due by 29 January 2024, and these are criteria, meaning benchmarks an attestation can measure against, rather than binding standards (Ledger Insights, 5 December 2023). Stablecoins are the one corner of the market where reserve reporting is hardening into regulation, a shift covered in our review of the US Treasury's stablecoin guidelines. For exchanges, no equivalent binding regime existed as of the PCAOB's 2023 advisory, and the August 2026 sector reviews cited above still describe scope, methodology and included entities as varying exchange by exchange. Investors screening venues on transparency grounds, including those doing so through ESG-styled digital asset funds, should treat the presence of a proof of reserves page as a floor, not a certification.

How strong is the evidence behind this article's claims?

Unevenly, and the table below grades each load-bearing claim rather than asking you to take the whole piece on trust. Claims resting on regulator publications and primary exchange pages are strong. Claims about what could happen in theory, or about episodes where intent was never established, are weaker and are marked as such.

Self-assessment of the strength of each claim made in this article
ClaimEvidence typeStrength
Proof of reserves reports carry no audit-level assurancePrimary regulator statements, PCAOB 8 March 2023 and SEC 22 December 2022, plus Mazars' own wordingStrong
Merkle attestations are point-in-time and omit off-chain liabilitiesPCAOB advisory, Buterin's technical essay, Kraken's own stated limitationsStrong
Naive Merkle sum trees permit negative-balance manipulationTechnical analyses by Buterin and Binance, confirmed as a design concern by the zk-SNARK fixesStrong on theory, weak on practice, no documented case of a major exchange exploiting it
zk circuits themselves can be buggyOne verified incident, the Hacken finding of 14 February 2023, fixed after disclosureModerate, a single documented case
The Crypto.com and Gate.io transfer was reserve window dressingOn-chain timing analysis, denied by both firms, snapshot predated the transferWeak, presented here only as an illustration of what snapshots cannot rule out
Typical attestation engagements cover 70 to 80 percent of platform valueStatement by a firm that sells these engagements, not independently measuredWeak to moderate, self-interested source, admission against interest
OKX reserve ratios of 101 to 112 percentOKX's own page, accessed 18 August 2026, self-reported and unauditedModerate as a record of what OKX publishes, weak as a fact about OKX's finances
Few users verify their Merkle proofsNo exchange publishes verification rates, so the claim is an inference from absenceWeak, unverifiable with public data, stated as a design dependency rather than a measured fact

What are the most common questions about proof of reserves?

The questions below cover the points readers most often get wrong, starting with the audit distinction that regulators have repeatedly corrected.

Is a proof of reserves the same as an audit?

No. Most are self-published or backed by agreed-upon procedures reports, which state findings without offering any opinion. Mazars said its own crypto reports "do not constitute either an assurance or an audit opinion," and the PCAOB's March 2023 advisory said such reports provide no meaningful assurance.

Can a proof of reserves detect assets borrowed just for the snapshot?

No. The PCAOB advisory lists borrowed assets as a gap these engagements do not address. On-chain data shows balances, not the legal ownership or lending arrangements behind them.

What is a Merkle sum tree in plain terms?

It is a way of publishing a total of all customer balances such that each customer can check their own balance was counted, without anyone seeing other customers' balances. It proves inclusion of what was put in, and nothing about what was left out.

What do zk-SNARKs and zk-STARKs add?

They let an exchange prove that every account contributed to the claimed total and that no account carries a negative balance, without exposing individual data. Binance introduced this on 10 February 2023 and OKX uses a zk-STARK monthly. The proof is only as trustworthy as the circuit, as the February 2023 Hacken bug showed.

Which disclosure comes closest to demonstrating solvency?

Audited financial statements, because they cover liabilities as well as assets. Among major venues, Coinbase is the one that publishes them, as a consequence of being a US-listed company.

How should a reserve ratio like 105 percent be read?

As the exchange's own statement that snapshot assets exceeded the customer liabilities it chose to include, for the listed assets, on one date. It is not a statement that the company's total assets exceed its total liabilities.

Where do these claims come from?

Every source below was opened and checked during the research for this article on 18 August 2026, and each date given in the text is the date carried by the source itself.

This article is a factual reference on disclosure formats and their limits. It does not constitute investment or financial advice, and nothing in it is a recommendation to use or avoid any exchange or asset.

No items found.
★★★★★
GET UP TO
$30,050 USDT
GET DEAL
★★★★☆
CLAIM UP TO
$8,000 USDT
GET DEAL
★★★★☆
GET 20% OFF
TRADING FEES
GET DEAL
★★★★★
No.1 DEX
VVIP LEVEL UP  
GET DEAL

Stay ahead of the markets

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.