Proof of Reserves vs an Audit: What Exchanges Really Prove

Proof of reserves can show that an exchange controlled certain assets at a point in time, but it is not a full financial audit. Here is how to read the evidence without assuming…

Crypto Security & Regulation6 min read
Reviewed and updated by the editorial team in 2026.

After an exchange failure, the phrase proof of reserves often appears in banners, dashboards, and press releases. It sounds reassuring, but it answers a narrower question than many customers assume. A reserve check may help show that a platform controlled specific on-chain assets at a particular time. It does not automatically establish that the company is solvent, that customer liabilities are complete, or that the assets will remain available tomorrow.

Quick answer: proof of reserves is evidence about selected assets and, in some implementations, customer balances. A financial-statement audit examines a broader reporting framework that includes assets, liabilities, transactions, controls, and disclosures. Neither removes custody risk, and a proof-of-reserves report should never be treated as a guarantee.

What is proof of reserves?

In crypto, proof of reserves usually combines two kinds of evidence:

  1. Asset evidence: the platform demonstrates control of blockchain addresses, often by signing a message or moving funds under agreed procedures.
  2. Customer-balance evidence: customer account balances are committed to a data structure, commonly a Merkle tree, so an individual user can check whether a balance was included without seeing every other customer’s balance.

A Merkle tree turns many records into one cryptographic root. If the exchange gives you a valid Merkle path, you can verify that your record contributed to that root. This is useful, but the result is only as complete as the input data. A cryptographic commitment cannot reveal an omitted account, an undisclosed loan, or an obligation held by a related company.

What a strong reserve report can demonstrate

A carefully designed engagement may provide evidence that:

  • specified wallets held specified assets at the measurement time;
  • the platform controlled the private keys needed to use those wallets;
  • a customer balance was included in the reported liability population;
  • the measured reserves met a stated ratio against the measured customer balances; and
  • an independent practitioner performed the procedures described in the report.

Read the exact wording. “Agreed-upon procedures,” “attestation,” “assurance,” and “audit” are not interchangeable labels. The report should identify the entities, assets, networks, time, procedures, assumptions, and limitations. A dashboard without a signed report and methodology is weaker evidence.

What proof of reserves does not prove

The US Public Company Accounting Oversight Board has warned investors that proof-of-reserve reports are not audits and may not address the completeness of liabilities, whether assets were borrowed for the snapshot, the effectiveness of internal controls, or what happened after the measurement date. Those gaps matter because solvency is about the whole balance sheet, not one side of it.

A reserve ratio can look healthy while material risks remain:

  • Missing liabilities: loans, legal claims, vendor obligations, derivatives, or balances at affiliates may be outside the calculation.
  • Encumbered assets: coins may be pledged as collateral or subject to another party’s claim.
  • Temporary balances: assets can be borrowed or moved into visible wallets shortly before a snapshot.
  • Valuation risk: reserves made largely of an affiliated or illiquid token may fall sharply when customers try to withdraw.
  • Operational risk: private-key failures, fraud, cyberattacks, or weak approvals can still prevent access to assets.
  • Entity mismatch: the company holding assets may not be the legal entity that owes customers money.

Proof of reserves vs a financial audit

QuestionProof of reservesFinancial-statement audit
Main focusSelected reserve assets and sometimes customer balancesFinancial statements as a whole
Time periodOften a point-in-time snapshotPeriod-end balances plus activity during the reporting period
LiabilitiesMay include only defined customer obligationsTests material liabilities presented under the reporting framework
ControlsOften outside scopeConsidered to plan the audit; separate control assurance may also exist
OpinionDepends on the engagement; often no audit opinionAuditor expresses an opinion on the financial statements
Guarantee against failureNoNo

An audit is broader, but it is not a prediction of future survival and does not make custodial funds risk-free. Audit quality, reporting framework, scope, auditor independence, and the age of the statements still matter.

A practical exchange due-diligence checklist

  1. Open the full report. Do not rely on a marketing summary or a reserve percentage copied by a third party.
  2. Check the date and frequency. A transparent snapshot can become stale quickly.
  3. Identify the reporting entity. Compare it with the legal entity named in your customer agreement.
  4. Inspect the asset mix. Cash-like, liquid external assets behave differently from thinly traded or affiliated tokens.
  5. Read the liability definition. Look for exclusions involving affiliates, institutional loans, margin positions, or derivatives.
  6. Verify your inclusion. If a Merkle proof is offered, use the exchange’s documented verifier and retain the result. Inclusion does not prove completeness, but exclusion is an immediate concern.
  7. Look for independent financial statements. Confirm the auditor and report type rather than accepting the word “audited” without evidence.
  8. Test withdrawals cautiously. A successful small withdrawal is not proof of solvency, but unexplained delays or changing rules are warning signs.
  9. Limit custodial exposure. Funds needed for active trading face different trade-offs from long-term holdings. Learn the difference between an exchange account and a self-custody wallet.

Red flags in reserve claims

Be cautious when a platform publishes wallet balances without liabilities, uses its own token as a major reserve, provides no reproducible methodology, changes the scope between reports, or calls a narrow procedures report a “full audit.” Claims such as “100% safe” or “zero risk” are incompatible with the realities of custody, markets, and software.

Also remember that business model matters. A centralized platform can lend, pledge, or pool assets according to its terms. Before depositing, read how the platform differs from a decentralized venue in our CEX vs DEX comparison.

Frequently asked questions

Does a 100% reserve ratio mean an exchange is solvent?

Not necessarily. The ratio is meaningful only if both the asset and liability populations are complete, correctly valued, legally available to the right entity, and measured under a credible method.

Can a Merkle proof show that other users were omitted?

No. It can show that your record belongs to a published root. It cannot independently prove that every customer and liability was included.

Is self-custody always safer?

No. Self-custody removes exchange-credit risk but transfers key management, backup, transaction, and phishing risk to the user. The safer arrangement depends on competence, controls, and purpose.

This article is educational and is not financial, accounting, or legal advice.

Sources and further reading