Proof of reserves (PoR) is a process by which a crypto exchange or custodian provides evidence that it holds sufficient assets to cover customer balances at a given point in time. It typically combines a public snapshot of customer liabilities with verifiable on-chain data showing control of corresponding reserves.
PoR emerged as a transparency tool after high-profile exchange failures. It is intended to give users and the market some assurance that the platform is solvent and not using customer funds recklessly. However, PoR is not a full audit and has important limitations.
Why proof of reserves is used
Proof of reserves addresses several trust and transparency issues.
Demonstrating solvency
- Shows that the platform holds enough crypto assets to match or exceed customer balances.
- Helps reassure users that their funds are not being used for risky bets without backing.
- Provides a baseline check against obvious insolvency (liabilities exceeding assets).
Increasing transparency
- Gives the market a way to independently verify, at least partially, the platform’s claims.
- Reduces reliance on marketing statements alone (“we are safe”, “fully backed”).
- Can be part of a broader transparency programme including audits, attestations, and regular reporting.
Responding to regulatory and market pressure
- After several exchange collapses, regulators and users have demanded more proof that platforms hold customer assets.
- Some jurisdictions are moving toward mandatory attestations or audits of reserves.
- PoR is often a first step, even if not yet a full regulatory requirement.
How proof of reserves works
Implementations vary, but most PoR processes follow a similar pattern.
1. Snapshot of customer liabilities
- At a specific date and time, the platform records all customer balances for relevant assets (for example, BTC, ETH, stablecoins).
- This forms the “liabilities” side: how much the platform owes to users.
- The snapshot may be:
- Aggregated (total balances per asset).
- More granular (per-account balances, often in a privacy-preserving form).
2. Proving control of reserves
- The platform demonstrates that it controls on-chain addresses holding at least as much of each asset as the customer liabilities.
- Common methods include:
- Publishing a list of reserve addresses and signing a message with the private keys to prove control.
- On-chain data is public, so anyone can verify the balances of those addresses at the snapshot time.
3. Comparing assets and liabilities
- The platform shows that:
- Total reserves (on-chain balances of proven addresses) ≥ total customer liabilities (from the snapshot).
- This is often presented as a ratio (for example, 1:1 or higher, meaning reserves fully cover or exceed liabilities).
- Some platforms also disclose:
- Their own corporate holdings separate from customer funds.
- Breakdown by asset (for example, BTC reserves vs BTC liabilities).
4. Third-party involvement (in some cases)
- Some PoR reports are prepared or reviewed by external auditors or accounting firms.
- The auditor may:
- Verify the snapshot process.
- Confirm control of reserve addresses.
- Issue an attestation or limited assurance report.
- This adds credibility compared to a purely self-reported PoR, but still may not be a full statutory audit.
What proof of reserves can prove
PoR can provide some useful assurances, within limits.
Sufficient assets at a point in time
- Shows that, at the snapshot date, the platform held enough on-chain assets to cover customer balances for the assets included.
- Provides evidence that the platform is not obviously insolvent for those assets at that moment.
Control of specific addresses
- Demonstrates that the platform controls the private keys to the published reserve addresses.
- Reduces the risk that the platform is claiming assets it does not actually control.
Basic transparency
- Gives users and analysts something concrete to review instead of relying solely on verbal assurances.
- Enables some degree of independent verification using public blockchain data.
What proof of reserves cannot prove
PoR has significant limitations that users must understand.
Not a full audit
- PoR is typically a point-in-time snapshot, not a continuous monitor.
- It does not necessarily cover:
- All assets (some may be excluded, such as certain tokens, fiat balances, or off-chain positions).
- All liabilities (for example, undisclosed obligations, loans, or derivatives).
- It does not provide the same depth as a full financial statement audit under established standards.
No guarantee over time
- Reserves can change after the snapshot:
- The platform could move or spend reserves shortly after the report.
- New liabilities could be incurred that are not reflected.
- A PoR report from last month does not prove solvency today.
Does not prove quality or accessibility of assets
- Assets may be:
- Locked in smart contracts with restrictions.
- Pledged as collateral elsewhere.
- Held in structures that are not immediately accessible to meet withdrawals.
- PoR does not always reveal encumbrances, liens, or legal restrictions on the reserves.
Fiat and off-chain assets are harder to verify
- For fiat balances (bank deposits, cash equivalents):
- There is no public ledger equivalent to a blockchain.
- PoR often relies on bank letters, screenshots, or auditor confirmations, which are easier to manipulate or misrepresent.
- Off-chain lending, derivatives, or other positions may not be fully visible.
Does not prove sound risk management
- A platform can be “fully backed” at a snapshot but still:
- Engage in risky activities with its own capital or future flows.
- Have poor operational security, governance, or compliance.
- Be vulnerable to runs, liquidity mismatches, or legal actions.
- PoR does not assess business model sustainability or operational risk.
Types of proof of reserves
Different approaches offer varying levels of assurance.
Self-reported PoR
- The platform publishes its own report without external review.
- May include:
- List of reserve addresses.
- Snapshot of liabilities.
- Simple calculations showing reserves ≥ liabilities.
- Pros: fast, cheap, frequent.
- Cons: lower credibility; relies on trust in the platform’s data and honesty.
Auditor-attested PoR
- An external accounting firm reviews the PoR process and issues an attestation or limited assurance report.
- The auditor verifies:
- Control of reserve addresses.
- Accuracy of the liability snapshot (to some extent).
- Consistency of the reserve-to-liability calculation.
- Pros: higher credibility than self-reported.
- Cons: still not a full audit; scope may be limited; snapshots remain point-in-time.
Merkle tree–based proofs
- The platform constructs a Merkle tree of customer balances:
- Each leaf represents a user’s balance (often hashed for privacy).
- The root is published, and users can verify that their own balance is included without revealing others’ data.
- Combined with proof of control of reserve addresses, this can show that total liabilities are covered.
- Pros: allows individual verification while preserving some privacy.
- Cons: still depends on the integrity of the underlying data and does not address off-chain issues.
Continuous or frequent PoR
- Some platforms aim to publish PoR reports regularly (for example, monthly or quarterly).
- This provides a more up-to-date picture than a one-off report.
- However, gaps between reports still leave room for changes in between.
Proof of reserves vs full audits
PoR is often confused with audits, but they are different.
Proof of reserves
- Focus: primarily on crypto assets and customer balances.
- Scope: limited to reserves and liabilities included in the snapshot.
- Frequency: can be done more frequently, but often point-in-time.
- Assurance: limited; not a full statutory audit.
- Regulation: not always mandated; often voluntary or market-driven.
Full financial audit
- Focus: entire financial position, including all assets, liabilities, equity, income, and expenses.
- Scope: comprehensive, covering on-chain and off-chain items, contingent liabilities, related-party transactions, etc.
- Frequency: typically annual, sometimes quarterly.
- Assurance: higher, conducted under established auditing standards.
- Regulation: often required for regulated entities (banks, broker-dealers, some VASPs depending on jurisdiction).
PoR can be a useful complement to audits, but it is not a substitute.
Limitations and risks
Users and regulators should be aware of several key limitations.
Snapshot risk
- A platform could window-dress: arrange temporary reserves just for the snapshot, then revert afterwards.
- Without continuous monitoring or strong controls, PoR can be gamed.
Incomplete coverage
- Some assets or liabilities may be excluded from the report.
- Fiat balances, certain tokens, or complex products may not be fully captured.
- Users may assume “fully backed” means more than it actually does.
False sense of security
- PoR can create a perception of safety that is not fully justified.
- Users may overlook other risks: operational security, governance, regulatory compliance, business model viability.
- A platform with PoR can still fail due to non-balance-sheet issues.
Jurisdictional and regulatory gaps
- Standards for PoR are not yet uniform across jurisdictions.
- Different auditors may apply different scopes and methodologies.
- Regulators are still developing frameworks for what level of proof is required.
How proof of reserves affects users
From a user’s perspective, PoR shows up in several ways.
Transparency pages and reports
- Platforms may publish:
- PoR reports on their website or blog.
- Dashboards showing reserve ratios by asset.
- Links to auditor attestations or technical details (Merkle roots, reserve addresses).
- Users can review these to gauge the platform’s transparency posture.
Marketing and trust signals
- “Proof of reserves” is often used in marketing to signal safety and solvency.
- Users should read the details:
- Which assets are covered?
- When was the snapshot?
- Was an external auditor involved?
- What exactly is being attested?
Decision-making
- PoR can be one factor in choosing where to hold or trade crypto.
- However, it should not be the only factor; users should also consider:
- Regulatory status and licences.
- Security track record (hacks, incidents).
- Corporate governance and ownership.
- Terms of service, insurance, and user protections.
Good practices for users
To interpret proof of reserves more wisely:
- Treat PoR as a positive signal, not a guarantee of safety or solvency.
- Check the date of the PoR report; more recent is better, but still point-in-time.
- Look for details on scope: which assets, which liabilities, and whether fiat is included.
- Prefer platforms that use external auditors or attestation providers with clear methodologies.
- Combine PoR information with other due diligence: regulation, security, reputation, and your own risk tolerance.
- Avoid keeping more funds on any single platform than you are comfortable losing, regardless of PoR claims.
Good practices for platforms
For exchanges and custodians implementing PoR:
- Be transparent about methodology, scope, and limitations of your PoR reports.
- Include as many assets and liabilities as practicable; clearly disclose exclusions.
- Use reputable third-party auditors or attestation providers where possible.
- Publish PoR regularly and update promptly when material changes occur.
- Complement PoR with broader transparency: financial statements, risk disclosures, and regulatory compliance information.
- Avoid overstating what PoR proves; do not imply it is equivalent to a full audit or a guarantee against failure.
