TECHNOLOGY / CRYPTO & DIGITAL ASSETS

Proof of reserves: useful evidence with important gaps

Understand what crypto proof of reserves can show about assets and liabilities, why snapshots are limited, and which custody, liquidity and legal questions remain.

In this guide

Source checked 8 September 2026 · Educational explanation, not a solvency verdict

The short answer

Proof of reserves (PoR) is a report or cryptographic process intended to show that a crypto company controlled certain on-chain assets at a particular time, sometimes alongside a snapshot of customer balances or liabilities. It can make a custodian’s asset claims more checkable. It does not automatically prove that all customer liabilities were included, that the assets were unencumbered, that they were not borrowed for the snapshot, that internal controls work, or that customers can withdraw in a future crisis.

The Public Company Accounting Oversight Board (PCAOB) warns that PoR reports are not audits and may not address liabilities, customer rights, borrowed assets, governance or future availability. So read PoR as one dated evidence layer—not as a guarantee, insurance policy, financial-statement audit or recommendation to keep assets with a provider.

Disclosure: This guide reviews current regulator, supervisory and provider documentation. It does not audit an exchange, verify a wallet address, test a withdrawal or rank providers. Coverage, legal rights, assets and reporting methods vary by entity and jurisdiction.

Why “reserves” is only half of the question

An exchange or issuer can show assets on a blockchain address. But customers have claims or balances that may be larger, differently defined or legally complex. The basic question is a relationship:

Are the relevant assets sufficient for the relevant liabilities, under the relevant rights, at the relevant time?

A wallet screenshot answers only a narrow asset-control question. A balance table may answer a narrow liability question. A robust review needs both, plus the legal and operational bridge between them. It also needs to ask whether assets are pledged, lent, rehypothecated, commingled, frozen, held by an affiliate or dependent on a custodian.

Proof of reserves needs assets, liabilities, rights and timing

A reserve snapshot becomes more useful when the asset side is read with liabilities, customer rights and timing.

This is why the term “proof of reserves” can mislead when read as “proof the company is solvent.” The name describes an evidence exercise, not a universal standard. PCAOB says there is no equivalent assurance to a financial-statement audit and that PoR engagements are not performed under PCAOB auditing standards.

How a typical crypto PoR process can work

1. Define the snapshot

The provider and service firm choose a date, asset list, wallet set, customer population and procedures. The report may cover spot balances but exclude margin, lending, derivatives, staked assets, fiat, affiliates or certain jurisdictions. The scope is part of the result. A “fully reserved” statement without a clear asset and liability universe is hard to interpret.

2. Verify or observe on-chain assets

The provider identifies blockchain addresses and the service firm performs procedures intended to confirm control or balances. Public explorers can show movements and balances, but an address label is not itself a legal ownership opinion. Assets can be moved after the snapshot, subject to claims, borrowed, or dependent on a custodian or multisignature arrangement.

3. Aggregate customer liabilities

Some providers create a list or commitment of customer balances. Kraken describes a Merkle-tree approach in which encrypted account records are combined into a root hash, allowing eligible clients to verify that their balance was included without publishing every account publicly. That is an attributed description of Kraken’s process, not an industry-wide rule.

Liability definitions matter. Is the list gross or net of collateral? Does it include negative balances, margin, loans, staking claims, pending withdrawals, fiat, institutional accounts, dormant accounts and off-platform obligations? A cryptographic commitment can show that a dataset was used; it cannot decide whether the dataset was complete or the legal claim is enforceable.

4. Compare and report

The provider or service firm compares the reported assets and liabilities under the chosen procedures. The result may be an attestation, agreed-upon procedures report, reserve ratio or dashboard. Read the exact engagement wording, date, asset list, procedures, exclusions and limitations—not only the headline ratio.

What PoR can usefully show

  • A dated view of identified on-chain assets associated with a provider or issuer.
  • Whether a stated account or balance was included in a particular cryptographic commitment, if the provider offers a verification path.
  • The assets, networks, customers and procedures the provider chose to disclose.
  • Changes between reports when the scope and definitions are genuinely comparable.
  • Questions worth asking about wallets, custodians, liabilities, restrictions and governance.

Those are meaningful transparency improvements when the data is complete, current and independently scrutinized. They still require the reader to understand what was actually tested.

The most useful reading habit is to turn every headline into a scope question. “One-to-one” might refer only to a list of supported spot assets. “Verified” might mean a service provider followed agreed procedures on a chosen date. “On-chain” might identify an address without explaining the legal right to the assets. A good report should make these boundaries visible. If it does not, the missing information is itself a risk signal, not a reason to fill the gap with assumptions.

What PoR cannot establish by itself

It is not necessarily an audit

PCAOB’s investor advisory says PoR reports are not audits, are not subject to PCAOB oversight or inspection, and provide no meaningful assurance equivalent to an audit. “Third-party” describes who performed a procedure, not the strength, independence or uniformity of the work.

It may not test liabilities

An asset-only snapshot can show coins but not the total claims against them. A provider may report a reserve ratio while excluding loans, derivatives, customer assets held in another system, or obligations that are difficult to value. Ask for the liability definition and reconciliation method.

It may be a point-in-time performance

An entity can control assets on the snapshot date and lose access later. The report may not show how assets were funded, whether they were borrowed, or whether a bank, custodian, keyholder or network dependency will work during a run. Freshness and update cadence matter.

On-chain control is not the same as a customer’s legal right to a specific asset. Terms can determine whether customers have a property claim, contractual claim, unsecured claim or another relationship. Bankruptcy, freezes, sanctions and jurisdiction can change the practical outcome.

It does not prove internal controls or good governance

The report may not test access controls, private-key management, segregation, change approvals, incident response, related-party transactions, code, employee access or decision-making. A visible address can coexist with weak operations.

A dated proof-of-reserves snapshot leaves questions before and after the date

A point-in-time result does not answer every funding, access or future-liquidity question.

Stablecoin reserves and exchange PoR are not identical

A stablecoin issuer may report reserve assets against tokens in circulation. An exchange may report crypto held against customer account balances. The questions overlap—assets, liabilities, custody, liquidity and rights—but the legal claims and mechanics differ.

For a stablecoin, ask whether holders can redeem, who is eligible, what asset backs the token, where reserves sit and how quickly they can be liquidated. K-0068 cautions that “backed” and “stable” do not guarantee price, redemption, reserve sufficiency or a legal claim. For an exchange, ask whether the snapshot includes your account type, assets, margin, staking and pending obligations, and what happens if the platform fails.

The Basel Committee’s cryptoasset standard provides a useful supervisory benchmark: reserve assets should be sufficient under stress, liquid, appropriately matched to the reference asset, managed with enforceable redemption objectives, disclosed regularly and independently verified or audited at stated intervals. That benchmark is not proof that a particular provider complies with it, but it illustrates the questions a headline PoR may leave unanswered.

A transparent example with assumptions

Imagine a provider reports 1,000 units of a token in controlled addresses and a Merkle commitment showing 900 units of customer balances on the snapshot date. On the surface, the ratio appears above one. But the conclusion changes if 150 units were borrowed, 200 units of customer liabilities were excluded, the address was controlled only temporarily, or the terms do not give customers a priority claim.

The arithmetic is not the hard part. The hard part is defining the numerator, denominator, rights, timing and procedures. A ratio without those assumptions can create false confidence. Do not compare two providers’ percentages unless the asset scope, customer scope, valuation method, date and assurance level match. Also ask whether the displayed values are gross or net, whether prices came from a reliable market, and whether a later correction process is disclosed. A polished dashboard can be easier to read than a technical report while still saying less about recovery rights.

A reader checklist

  • What exact date and time does the report cover?
  • Which legal entity, products, jurisdictions and assets are included?
  • Are customer liabilities included, and how are negative or leveraged balances handled?
  • Are margin, lending, staking, derivatives, fiat and pending withdrawals included?
  • Which wallet addresses were checked, and how was control established?
  • Could assets be borrowed, pledged, commingled or held by an affiliate?
  • What does the service firm actually say it did, and what did it not test?
  • Is the report an audit, attestation or agreed-upon procedures engagement?
  • Can an individual customer verify inclusion without revealing sensitive data?
  • What legal claim and recovery priority does the customer have if the provider fails?
  • How often is the process repeated, and what event triggers an update?
  • Which risks remain outside the report: keys, governance, code, banking, liquidity and jurisdiction?

Use the answers to narrow uncertainty, not to manufacture certainty. If a provider cannot explain scope, timing and exclusions plainly, the report is weak evidence for a custody decision.

Limits and next steps

K-0060 reminds readers that third-party custody transfers operational dependence to a custodian; K-0068 separates stablecoin reserve claims from guaranteed redemption. K-0075 is an internal observation about presenting evidence, audience fit and trade-offs—not an endorsement of another publisher’s scoring or layout.

For the control boundary, read exchange custody vs self-custody. For stablecoin reserve and redemption mechanics, read how stablecoins maintain their peg. These are educational resources, not a provider review or personal financial advice.

Sources

  1. PCAOB — Investor Advisory on Proof of Reserve Reports
  2. Basel Committee on Banking Supervision — Cryptoasset standard amendments
  3. Kraken — 2024 Proof of Reserves
  4. Kraken — Proof of Reserves scope and method
  5. Financial Stability Board — Recommendations for Global Stablecoin Arrangements