Веерх ↑

Proof of reserves

Learn how proof of reserves works, what it can and cannot prove, and its limitations.

Proof of reserves (PoR) is a process by which a crypto exchange or custodian provides evidence that it holds sufficient assets to cover customer balances at a given point in time. It typically combines a public snapshot of customer liabilities with verifiable on-chain data showing control of corresponding reserves.

PoR emerged as a transparency tool after high-profile exchange failures. It is intended to give users and the market some assurance that the platform is solvent and not using customer funds recklessly. However, PoR is not a full audit and has important limitations.

Why proof of reserves is used

Proof of reserves addresses several trust and transparency issues.

Demonstrating solvency

  • Shows that the platform holds enough crypto assets to match or exceed customer balances.
  • Helps reassure users that their funds are not being used for risky bets without backing.
  • Provides a baseline check against obvious insolvency (liabilities exceeding assets).

Increasing transparency

  • Gives the market a way to independently verify, at least partially, the platform’s claims.
  • Reduces reliance on marketing statements alone (“we are safe”, “fully backed”).
  • Can be part of a broader transparency programme including audits, attestations, and regular reporting.

Responding to regulatory and market pressure

  • After several exchange collapses, regulators and users have demanded more proof that platforms hold customer assets.
  • Some jurisdictions are moving toward mandatory attestations or audits of reserves.
  • PoR is often a first step, even if not yet a full regulatory requirement.

How proof of reserves works

Implementations vary, but most PoR processes follow a similar pattern.

1. Snapshot of customer liabilities

  • At a specific date and time, the platform records all customer balances for relevant assets (for example, BTC, ETH, stablecoins).
  • This forms the “liabilities” side: how much the platform owes to users.
  • The snapshot may be:
    • Aggregated (total balances per asset).
    • More granular (per-account balances, often in a privacy-preserving form).

2. Proving control of reserves

  • The platform demonstrates that it controls on-chain addresses holding at least as much of each asset as the customer liabilities.
  • Common methods include:
    • Publishing a list of reserve addresses and signing a message with the private keys to prove control.
  • On-chain data is public, so anyone can verify the balances of those addresses at the snapshot time.

3. Comparing assets and liabilities

  • The platform shows that:
    • Total reserves (on-chain balances of proven addresses) ≥ total customer liabilities (from the snapshot).
  • This is often presented as a ratio (for example, 1:1 or higher, meaning reserves fully cover or exceed liabilities).
  • Some platforms also disclose:
    • Their own corporate holdings separate from customer funds.
    • Breakdown by asset (for example, BTC reserves vs BTC liabilities).

4. Third-party involvement (in some cases)

  • Some PoR reports are prepared or reviewed by external auditors or accounting firms.
  • The auditor may:
    • Verify the snapshot process.
    • Confirm control of reserve addresses.
    • Issue an attestation or limited assurance report.
  • This adds credibility compared to a purely self-reported PoR, but still may not be a full statutory audit.

What proof of reserves can prove

PoR can provide some useful assurances, within limits.

Sufficient assets at a point in time

  • Shows that, at the snapshot date, the platform held enough on-chain assets to cover customer balances for the assets included.
  • Provides evidence that the platform is not obviously insolvent for those assets at that moment.

Control of specific addresses

  • Demonstrates that the platform controls the private keys to the published reserve addresses.
  • Reduces the risk that the platform is claiming assets it does not actually control.

Basic transparency

  • Gives users and analysts something concrete to review instead of relying solely on verbal assurances.
  • Enables some degree of independent verification using public blockchain data.

What proof of reserves cannot prove

PoR has significant limitations that users must understand.

Not a full audit

  • PoR is typically a point-in-time snapshot, not a continuous monitor.
  • It does not necessarily cover:
    • All assets (some may be excluded, such as certain tokens, fiat balances, or off-chain positions).
    • All liabilities (for example, undisclosed obligations, loans, or derivatives).
  • It does not provide the same depth as a full financial statement audit under established standards.

No guarantee over time

  • Reserves can change after the snapshot:
    • The platform could move or spend reserves shortly after the report.
    • New liabilities could be incurred that are not reflected.
  • A PoR report from last month does not prove solvency today.

Does not prove quality or accessibility of assets

  • Assets may be:
    • Locked in smart contracts with restrictions.
    • Pledged as collateral elsewhere.
    • Held in structures that are not immediately accessible to meet withdrawals.
  • PoR does not always reveal encumbrances, liens, or legal restrictions on the reserves.

Fiat and off-chain assets are harder to verify

  • For fiat balances (bank deposits, cash equivalents):
    • There is no public ledger equivalent to a blockchain.
    • PoR often relies on bank letters, screenshots, or auditor confirmations, which are easier to manipulate or misrepresent.
  • Off-chain lending, derivatives, or other positions may not be fully visible.

Does not prove sound risk management

  • A platform can be “fully backed” at a snapshot but still:
    • Engage in risky activities with its own capital or future flows.
    • Have poor operational security, governance, or compliance.
    • Be vulnerable to runs, liquidity mismatches, or legal actions.
  • PoR does not assess business model sustainability or operational risk.

Types of proof of reserves

Different approaches offer varying levels of assurance.

Self-reported PoR

  • The platform publishes its own report without external review.
  • May include:
    • List of reserve addresses.
    • Snapshot of liabilities.
    • Simple calculations showing reserves ≥ liabilities.
  • Pros: fast, cheap, frequent.
  • Cons: lower credibility; relies on trust in the platform’s data and honesty.

Auditor-attested PoR

  • An external accounting firm reviews the PoR process and issues an attestation or limited assurance report.
  • The auditor verifies:
    • Control of reserve addresses.
    • Accuracy of the liability snapshot (to some extent).
    • Consistency of the reserve-to-liability calculation.
  • Pros: higher credibility than self-reported.
  • Cons: still not a full audit; scope may be limited; snapshots remain point-in-time.

Merkle tree–based proofs

  • The platform constructs a Merkle tree of customer balances:
    • Each leaf represents a user’s balance (often hashed for privacy).
    • The root is published, and users can verify that their own balance is included without revealing others’ data.
  • Combined with proof of control of reserve addresses, this can show that total liabilities are covered.
  • Pros: allows individual verification while preserving some privacy.
  • Cons: still depends on the integrity of the underlying data and does not address off-chain issues.

Continuous or frequent PoR

  • Some platforms aim to publish PoR reports regularly (for example, monthly or quarterly).
  • This provides a more up-to-date picture than a one-off report.
  • However, gaps between reports still leave room for changes in between.

Proof of reserves vs full audits

PoR is often confused with audits, but they are different.

Proof of reserves

  • Focus: primarily on crypto assets and customer balances.
  • Scope: limited to reserves and liabilities included in the snapshot.
  • Frequency: can be done more frequently, but often point-in-time.
  • Assurance: limited; not a full statutory audit.
  • Regulation: not always mandated; often voluntary or market-driven.

Full financial audit

  • Focus: entire financial position, including all assets, liabilities, equity, income, and expenses.
  • Scope: comprehensive, covering on-chain and off-chain items, contingent liabilities, related-party transactions, etc.
  • Frequency: typically annual, sometimes quarterly.
  • Assurance: higher, conducted under established auditing standards.
  • Regulation: often required for regulated entities (banks, broker-dealers, some VASPs depending on jurisdiction).

PoR can be a useful complement to audits, but it is not a substitute.

Limitations and risks

Users and regulators should be aware of several key limitations.

Snapshot risk

  • A platform could window-dress: arrange temporary reserves just for the snapshot, then revert afterwards.
  • Without continuous monitoring or strong controls, PoR can be gamed.

Incomplete coverage

  • Some assets or liabilities may be excluded from the report.
  • Fiat balances, certain tokens, or complex products may not be fully captured.
  • Users may assume “fully backed” means more than it actually does.

False sense of security

  • PoR can create a perception of safety that is not fully justified.
  • Users may overlook other risks: operational security, governance, regulatory compliance, business model viability.
  • A platform with PoR can still fail due to non-balance-sheet issues.

Jurisdictional and regulatory gaps

  • Standards for PoR are not yet uniform across jurisdictions.
  • Different auditors may apply different scopes and methodologies.
  • Regulators are still developing frameworks for what level of proof is required.

How proof of reserves affects users

From a user’s perspective, PoR shows up in several ways.

Transparency pages and reports

  • Platforms may publish:
    • PoR reports on their website or blog.
    • Dashboards showing reserve ratios by asset.
    • Links to auditor attestations or technical details (Merkle roots, reserve addresses).
  • Users can review these to gauge the platform’s transparency posture.

Marketing and trust signals

  • “Proof of reserves” is often used in marketing to signal safety and solvency.
  • Users should read the details:
    • Which assets are covered?
    • When was the snapshot?
    • Was an external auditor involved?
    • What exactly is being attested?

Decision-making

  • PoR can be one factor in choosing where to hold or trade crypto.
  • However, it should not be the only factor; users should also consider:
    • Regulatory status and licences.
    • Security track record (hacks, incidents).
    • Corporate governance and ownership.
    • Terms of service, insurance, and user protections.

Good practices for users

To interpret proof of reserves more wisely:

  • Treat PoR as a positive signal, not a guarantee of safety or solvency.
  • Check the date of the PoR report; more recent is better, but still point-in-time.
  • Look for details on scope: which assets, which liabilities, and whether fiat is included.
  • Prefer platforms that use external auditors or attestation providers with clear methodologies.
  • Combine PoR information with other due diligence: regulation, security, reputation, and your own risk tolerance.
  • Avoid keeping more funds on any single platform than you are comfortable losing, regardless of PoR claims.

Good practices for platforms

For exchanges and custodians implementing PoR:

  • Be transparent about methodology, scope, and limitations of your PoR reports.
  • Include as many assets and liabilities as practicable; clearly disclose exclusions.
  • Use reputable third-party auditors or attestation providers where possible.
  • Publish PoR regularly and update promptly when material changes occur.
  • Complement PoR with broader transparency: financial statements, risk disclosures, and regulatory compliance information.
  • Avoid overstating what PoR proves; do not imply it is equivalent to a full audit or a guarantee against failure.
Spend your
crypto.
Don’t sell it
Join the members who figured it out.

Cookies preferences

✕

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

Necessary

Necessary
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.