The full tokenomics data room process, freeThe whole course, free67 videos, 174 filesSee the course
Free Strategy Call

Proof of reserves

Proof of reserves is a published claim that an issuer or exchange holds assets at least equal to what it owes customers, usually supported by a CPA attestation and a Merkle tree letting each customer check that their own balance was counted. It is an attestation, not an audit: a practitioner reports on one narrow assertion, at one instant, against criteria the engaging party set. Assets-only proof of reserves, published without an independently tested liability figure, says almost nothing about solvency.

The hard side is liabilities, not assets. Anyone can show wallets. A proof of reserves not establishing what the firm owes, including obligations that never touch a customer account, is a screenshot with an accountant's letterhead on it.

How a Merkle tree proof of reserves is built01Balances frozenat one instant, set bythe firm02Accountshashedaccount ID plusbalance, per leaf03Leaves paired upeach node carries asubtotal04Root publishedone hash for thewhole book05Assets attestedwallet controlchecked by a CPA06Customersverifyeach checks theirown leaf

Scroll to see the full diagram

The tree proves your balance was included in a total. It proves nothing about whether that total is the whole of what the firm owes, and that is the number deciding solvency.

Attestation and audit are different products

An attestation engagement and a financial statement audit run under different standard sets and deliver different things. The AICPA's Statements on Standards for Attestation Engagements govern attestation reports for nonissuers, and the current codification, effective April 2026, divides into AT-C Section 100 on common concepts, Section 200 on level of service and Section 300 on subject matter.2 An attestation reports on a defined subject matter against stated criteria. An audit opines on whether a complete set of financial statements is fairly presented, for a period.

Proof of reserves is the first thing, sold with the vocabulary of the second. Note that the standards themselves separate level of service from subject matter, which is exactly the pair to check on any report you are handed.2 Two engagements can share a subject matter and deliver completely different assurance: one produces an opinion, another produces findings against procedures the engaging party chose, with no opinion at all. A heading reading "Independent Accountant's Report" tells you neither. The scope paragraph does.

What a Merkle tree actually establishes

The construction is straightforward. Take every customer account at one instant, hash an identifier and a balance into a leaf, then hash leaves in pairs upward until a single root hash represents the entire book. Publish the root. Give each customer the sibling hashes along their path and they can recompute the root themselves, confirming their balance was in the total without seeing anyone else's. Sum-tree variants carry a running subtotal at each node, so the root also carries the claimed total liability.

One named provider states the deliverable plainly: a CPA attestation report covering reserve assets greater than or equal to customer liabilities, reporting made available to customers, and subsequent customer verification through the Merkle tree.1 That is an honest and precise description of the engagement, and it is a far smaller claim than the word audit implies.

So what does it establish? Inclusion. Your balance was one of the leaves rolling up into the published root. What it does not establish: that the root covers every liability, that no leaf was fabricated, or that the assets on the other side of the comparison belonged to the firm on any day other than the snapshot date.

Four holes on the assets side

Borrowed coverage. If the snapshot instant is announced or negotiable, coverage can be arranged for it. Securities regulation reached for the fix decades ago: the examination date is chosen by the accountant, without notice, and is irregular from year to year.3 Almost no crypto proof of reserves works that way. The date is usually month end and usually known in advance.

Signatures that prove less than they look like. Signing a message from an address shows that somebody can sign. It does not show the address is exclusively controlled, unencumbered, or not being counted simultaneously by a second firm's report. Ruling out the second claim takes control evidence, and a signature is not control evidence.

Assets that are not really assets. Reserves carried at mark rather than at what they would fetch under stress, illiquid tokens the firm itself issued, and receivables from affiliates all land on the assets side of an inequality that then reads as satisfied.

And the snapshot itself. Twelve monthly attestations observe twelve instants in a year. Generously counting each as a full hour, that is twelve hours of observation against 8,748 hours nobody looked at, roughly a seventh of one percent of the calendar. Everything in the gap is outside the engagement by construction, and a well written report will say so.

One year under a monthly point in time attestation12 hrsObserved8,748 hrsNot observedHours in a calendar year

Scroll to see the full diagram

Cadence, not the accountant, sets the ceiling on what a proof of reserves can tell you. Raising frequency shrinks this gap; it does not change what sits inside the scope paragraph.

The liabilities problem, which is the whole problem

An exchange's liabilities are not a wallet balance. They are a database maintained by the firm being examined, and the practitioner can test only what the firm produces. Omitted accounts, negative balances netted against real ones, and obligations recorded outside the customer ledger entirely all shrink the claimed liability without touching a blockchain.

Merkle verification is the intended fix, and it works only if customers actually check. If one customer in a thousand verifies their leaf, an issuer can omit accounts with a high probability of not being caught. The cryptography is sound. The sampling is not. So the design consequence is a product decision rather than an accounting one: publish the verifier, put it one click from the account page, and expect to be judged on the verification rate rather than on the root hash.

What the report covers, and what it silently excludes

Six things to locate before you read the conclusion: the subject matter, the criteria it was measured against, the as-of instant, who the responsible party is, the level of service, and the use restriction. Management asserts and the practitioner reports on the assertion. If those six are not on the page, you are holding a letter rather than an attestation.

Assume the following are absent unless the report names them: liabilities not recorded in the customer ledger, encumbrances and rehypothecation, related party balances, controls over a period rather than at an instant, going concern, and everything happening between snapshots. None of these are defects in the practitioner's work. They are the scope the engagement was bought with.

The Tether order is where the gap between marketing and reserve composition got priced. The CFTC ordered Tether and Bitfinex to pay $42.5 million in October 2021, $41 million of it against Tether, over claims the stablecoin was fully backed by US dollars.6 The representation was the violation. Whatever documentation existed behind it did not carry the claim being made in public.

What FTX changed, and what it did not

FTX Trading and its affiliates filed for Chapter 11 in November 2022, and the attestation market repriced itself within weeks. In December 2022 Mazars halted proof of reserves work for crypto clients, and the reason reported at the time was that such reports "only provide a brief snapshot and do not show a firm's liabilities."4 That is a practitioner's own account of the limitation, from a firm that had been doing the work.

Test any report against the FTX fact pattern rather than against a checklist. The CFTC alleges that from at least May 2019 through November 2022, FTX customer assets were commingled with Alameda Research's assets and used by Alameda for its own trading, investment and expenses.5 Forty two months. An assets-side snapshot is not built to surface an encumbrance sitting behind assets that are genuinely present, and no increase in cadence changes that.

What actually replaced the pre-FTX practice was mostly the same product, published more often. Merkle roots became normal. Liabilities scope moved very little. The distinction the market still does not price is between an issuer picking the snapshot date and an accountant picking it unannounced.3 In our view that single variable separates a control from a marketing artifact, and it is the cheapest thing on this page to fix.

What we specify when a client needs proof of reserves

Start from the liabilities side and work back. The engagement has to include a liability figure the practitioner can independently reconcile, or it is not proof of anything. That means a customer ledger open to the practitioner, a Merkle root published with every report, a verifier customers can reach without asking for it, and a published verification rate.

Then set cadence against mint velocity. If backing is confirmed daily and the contract can mint continuously, the exposure window is a full day of issuance at whatever velocity the market allows. We treat the onchain mint gate as a control rather than as assurance: a feed pausing issuance when posted backing falls below supply is a circuit breaker, and a circuit breaker is not an accountant's opinion. Neither one substitutes for the other, and the oracle behind the feed is its own dependency to design.

Then the custody dependency, which decides whether any of this is independent. An attestation over assets held by a custodian that is a related person of the issuer is an attestation of the group's own numbers. Separating custodian, transfer agent and issuer is what makes the reporting layer worth reading, and it is settled in the custody arrangement long before an attestation scope gets drafted.

The honest version of this product, in our view, is narrower and more frequent than what most issuers publish, and it states out loud what it does not cover. Harder marketing page. Much better disclosure. Whether a specific reserve arrangement satisfies any particular regulator is fact-specific and belongs with counsel; nothing here is legal advice or a recommendation to buy, sell or hold any asset.

Common questions

Is proof of reserves the same as an audit?

No. Proof of reserves is an attestation engagement: a practitioner reports on one defined assertion, at one instant, against criteria the engaging party set. A financial statement audit opines on a complete set of financial statements covering a period. The AICPA attestation standards governing the first are a separate standard set from the auditing standards governing the second.2 The vocabulary overlaps. The assurance does not.

What does a Merkle tree proof of reserves actually prove?

It proves your balance was included in the total the firm claimed it owed at one instant. You recompute the published root hash from your own leaf and the sibling hashes along its path.1 It does not prove the total covers every account, that no leaf was fabricated, or that the assets compared against it were unencumbered and exclusively controlled. Inclusion is not solvency.

Why is assets-only proof of reserves not enough?

Because solvency is an inequality with two sides and assets are the easy side. Wallets are public; the customer ledger is not. Without an independently testable liability figure, a firm can display real assets while owing more than it holds, including obligations recorded outside the customer ledger. Mazars gave that reason when it halted crypto proof of reserves work in December 2022.4

How often should proof of reserves be published?

More often than your mint or redemption cadence, and on dates you do not control. A monthly attestation observes twelve instants in a year. Who picks the date matters more than how many dates there are: securities regulation has required unannounced examinations at irregular intervals for decades, and almost no crypto proof of reserves adopts that design.3

What should I look for in a proof of reserves report?

Six things, before the conclusion: the subject matter, the criteria, the as-of instant, who asserted what, the level of service, and the use restriction. Then read what is excluded. Liabilities outside the customer ledger, encumbrances, related party balances and anything occurring between snapshots are usually out of scope, and a properly written report will say so plainly.

See Tokenomics Audit for how this applies in practice.

Sources

  1. Merkle Tree Proof of Reserves for Crypto
    The Network Firm LLP, current
    An active PoR attestation provider's own description of the engagement scope: a CPA attestation report covering reserve assets greater than or equal to customer liabilities, plus customer verification through the Merkle tree.
  2. AICPA Statements on Standards for Attestation Engagements, currently effective
    American Institute of Certified Public Accountants, 2026
    The standard set governing attestation reports for nonissuers. Codification current as of April 2026, divided into AT-C Section 100 common concepts, Section 200 level of service, Section 300 subject matter.
  3. 17 C.F.R. § 275.206(4)-2, Custody of funds or securities of clients by investment advisers
    Cornell Law School Legal Information Institute, current
    Requires annual verification by actual examination at a time chosen by the accountant without notice and irregular from year to year. The contrast case for an issuer-selected snapshot date.
  4. The auditor of Binance and Crypto.com's reserves has reportedly stopped work with crypto clients in the wake of FTX's collapse
    Business Insider, 2022
    Dated report of Mazars halting crypto proof of reserves work in December 2022, carrying the firm's stated reason that such reports show a brief snapshot and not a firm's liabilities.
  5. CFTC v. Samuel Bankman-Fried, FTX Trading Ltd., Alameda Research LLC, complaint
    U.S. Commodity Futures Trading Commission, 2022
    Alleges FTX customer assets were commingled with Alameda's from at least May 2019 through November 2022 and used by Alameda for its own trading, investment and expenses.
  6. CFTC Orders Tether and Bitfinex to Pay Fines Totaling $42.5 Million (Release No. 8450-21)
    U.S. Commodity Futures Trading Commission, 2021
    Enforcement order over claims that USDT was fully backed by US dollars. The documented precedent for a gap between marketed backing and reserve composition.

Last reviewed 2026-08

Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.

Book a discovery call

100+ projects advised. Complete tokenomics in 4 to 6 weeks.