July 28, 2026
16 min read

Proof of Reserves, Attestations and Exchange Transparency Controls: A Complete Guide for Crypto Compliance Teams

Learn how Proof of Reserves, reserve attestations, and exchange transparency controls strengthen trust in crypto markets. This guide explains how exchanges verify asset backing, the role of independent attestations, key transparency practices, regulatory expectations, and the limitations compliance teams should understand.

Ian Hart
Proof of Reserves illustration showing secured crypto assets, reserve verification dashboards and audit data explaining how exchanges demonstrate customer asset backing.

Customers of cryptocurrency exchanges need confidence that the assets displayed in their accounts are genuinely held, appropriately safeguarded and available for withdrawal. Following several high-profile failures in the crypto market, exchanges have faced growing pressure to provide clearer evidence about customer assets, liabilities, custody arrangements and financial health.

Proof of Reserves, commonly abbreviated as PoR, is one method used to provide this transparency. A typical Proof of Reserves process attempts to demonstrate that an exchange controls cryptoassets sufficient to cover the customer balances included within a defined calculation.

However, Proof of Reserves is not the same as a complete financial audit. A reserve snapshot may verify selected wallets and customer liabilities at one moment without examining the exchange’s wider debts, corporate governance, operational controls, related-party transactions or ability to remain solvent.

This complete guide connects several related questions. Teams that need a simpler starting point can first review what Proof of Reserves means in practice, then compare reserve attestations with financial audits and examine the wider exchange transparency controls that support customer-asset protection.

What Is Proof of Reserves?

Proof of Reserves is a process through which a crypto exchange, custodian or similar platform demonstrates that it controls specified assets intended to support customer balances.

A basic Proof of Reserves exercise compares two figures:

  • The value of assets controlled by the platform

  • The value of customer liabilities included in the assessment

If the verified assets equal or exceed the included customer liabilities, the platform may report a reserve ratio of at least 100%.

For example, suppose an exchange reports that customers are collectively entitled to 10,000 units of a particular cryptoasset. The exchange would need to demonstrate control of at least 10,000 units to claim full asset backing for that asset, subject to the scope and methodology of the exercise.

The calculation sounds straightforward, but its reliability depends on several questions:

  • Were all relevant customer liabilities included?

  • Does the exchange genuinely control the reported wallets?

  • Were any assets borrowed temporarily?

  • Are customer assets pledged, lent or otherwise restricted?

  • Were corporate liabilities and off-chain obligations considered?

  • Was the information independently tested?

  • Does the report cover only one moment in time?

A meaningful Proof of Reserves disclosure should answer these questions rather than presenting a reserve ratio without context.

Why Proof of Reserves Matters for Crypto Exchanges

Crypto exchanges frequently hold assets on behalf of large numbers of customers. In many cases, customers cannot independently observe how their deposited assets are stored, whether they have been transferred elsewhere or whether the exchange maintains sufficient liquid assets to honour withdrawals.

This creates an information imbalance between the exchange and its customers.

Proof of Reserves can reduce part of that imbalance by providing evidence that customer assets exist and that the exchange controls the relevant wallet infrastructure. It may also help identify shortages before they develop into a wider customer-protection problem.

A well-designed PoR programme can support:

  • Customer confidence

  • Internal asset reconciliations

  • Detection of reserve shortfalls

  • Custody oversight

  • Governance reporting

  • Independent assurance

  • Regulatory engagement

Nevertheless, customers should not assume that an exchange is financially secure solely because it publishes a PoR report. The PCAOB has warned that Proof of Reserves reports are inherently limited and may not establish that an exchange has enough assets to meet all customer liabilities. It also notes that these engagements are not subject to one uniform standard.

How Merkle Trees Enable Reserve Verification

A Proof of Reserves process must demonstrate not only that assets exist but also that customer balances have been included without publicly revealing every customer’s account information.

Merkle trees are commonly used for this purpose.

A Merkle tree is a cryptographic data structure in which individual pieces of data are hashed and repeatedly combined until they produce one final value known as the Merkle root. The National Institute of Standards and Technology describes it as a structure where hashed data is combined until a single root hash represents the complete dataset.

In a PoR exercise, individual customer balances may form the leaves of the tree. These balances are hashed, combined with other hashes and eventually represented by the Merkle root.

Each customer can receive a Merkle proof that allows them to check whether their balance was included in the liability dataset. The customer does not need access to the balances of other users.

A simplified process works as follows:

  1. The exchange creates a record of eligible customer balances.

  2. Each account record is converted into a cryptographic hash.

  3. The hashes are combined through multiple levels.

  4. One Merkle root represents the complete liability dataset.

  5. Customers receive the information required to verify their inclusion.

Merkle trees help protect customer privacy and make silent changes to the dataset more detectable. Changing one included balance would produce a different Merkle root.

However, a valid Merkle proof only shows that a customer was included in the published dataset. It does not prove that every customer or liability was included.

Proof of Assets vs Proof of Liabilities

A complete Proof of Reserves calculation requires both asset and liability information.

Proof of Assets

Proof of Assets demonstrates that the exchange controls specified cryptoassets.

An exchange may publish relevant wallet addresses and sign a message using the associated private keys. The signature can demonstrate control without transferring the assets.

Blockchain data can then be used to verify the balances held in the identified wallets at the selected time.

Proof of Assets should examine:

  • Wallet addresses included in the calculation

  • Ownership or control of private keys

  • Assets held through third-party custodians

  • Assets deployed in staking or decentralised protocols

  • Encumbered, pledged or borrowed assets

  • Asset valuation methodology

  • Cut-off time used for the snapshot

A blockchain balance does not automatically mean that an asset is available to meet customer withdrawals. Assets may be locked, pledged, lent, subject to legal claims or held for another purpose.

Proof of Liabilities

Proof of Liabilities represents the amounts that the exchange owes to customers.

This may include customer deposit balances, pending withdrawals and other contractual entitlements. Depending on the scope, it might not include general corporate debt, legal claims, tax liabilities or obligations to lenders.

A Merkle tree can help customers verify that their balances were included, but the underlying liability records must still be tested for completeness and accuracy.

Compliance and assurance teams should investigate whether the exchange:

  • Included every relevant customer account

  • Used the correct cut-off time

  • Included pending and disputed withdrawals

  • Prevented negative balances from improperly reducing liabilities

  • Treated margin and lending accounts correctly

  • Reconciled the PoR dataset with its internal ledger

Proof of Assets without reliable Proof of Liabilities provides an incomplete picture. Similarly, a liability calculation is of limited value if the reported assets are not genuinely controlled and available.

Reserve Attestations and Independent Assurance

An exchange may engage an external accounting or assurance firm to perform procedures relating to its reserve calculation.

The term attestation is sometimes used broadly, but different engagements may provide very different levels of assurance.

In an agreed-upon procedures engagement, the practitioner performs procedures specified by the engaging parties and reports the findings. The practitioner may not provide an overall opinion on whether the exchange is solvent or whether all liabilities were included.

A review or examination engagement may provide a defined level of assurance against established criteria, depending on the applicable professional standards and agreed scope.

Compliance teams should examine:

  • The type of engagement performed

  • The professional standard applied

  • The independence of the provider

  • The assets and entities covered

  • The definition of customer liabilities

  • The testing of wallet ownership

  • The reporting date and frequency

  • Any limitations or qualifications

  • Whether management selected the procedures

The presence of an accounting firm’s name should not be treated as automatic evidence of a financial audit. The PCAOB has stated that a Proof of Reserves attestation is generally outside its inspection and enforcement authority, even when performed by a PCAOB-registered firm.

Proof of Reserves vs Financial Audits

Proof of Reserves and financial statement audits serve different purposes.

A PoR engagement generally focuses on specified customer liabilities and assets at a particular time. It may answer a narrow question: did the exchange control enough of the specified assets to cover the included customer balances on the reporting date?

A financial statement audit examines the company’s financial statements as a whole. It includes assets, liabilities, revenue, expenses, equity, disclosures and other financially significant matters under an established accounting framework.

An audit may also consider internal controls, accounting estimates, related-party transactions, legal obligations and events occurring after the reporting date.

A PoR report may not identify:

  • Corporate borrowing

  • Unrecorded liabilities

  • Loss-making business operations

  • Related-party exposures

  • Customer asset misuse between reporting dates

  • Weak cybersecurity or private-key controls

  • Legal claims

  • Liquidity mismatches

  • Assets borrowed shortly before verification

The SEC’s former chief accountant warned that non-audit crypto assurance arrangements are neither as rigorous nor as comprehensive as financial statement audits and may provide investors with little or no meaningful assurance.

Because the terminology is often misused, compliance teams should be clear on the difference between a reserve report and a full audit. A focused comparison of reserve attestations versus financial audits helps explain what each process can and cannot prove.

Exchange Transparency Controls

Exchange transparency should extend beyond a publicly displayed reserve ratio.

A mature transparency framework should provide customers and regulators with information about:

Asset Segregation

Customer assets should be appropriately separated from the exchange’s corporate assets. Internal records must clearly identify which assets belong to customers and which belong to the business.

IOSCO’s crypto-market recommendations emphasise custody, segregation and protection of client money and assets as central investor-protection requirements.

Reconciliations

The exchange should regularly reconcile:

  • Customer ledger balances

  • On-chain wallet balances

  • Third-party custodian records

  • Pending deposits and withdrawals

  • Internal treasury accounts

Unresolved differences should be investigated and escalated promptly.

Asset-Use Disclosures

Customers should be told whether their assets may be lent, staked, pledged, reused or transferred to third parties.

Consent should be clear and should not be hidden within complex terms and conditions.

Governance and Reporting

Senior management should receive regular information about reserve coverage, reconciliation breaks, custody incidents, liquidity pressure and control failures.

Material shortages should trigger predefined escalation and remediation procedures.

Withdrawal and Liquidity Monitoring

An exchange may hold enough assets in total while lacking sufficient immediately available assets to meet withdrawals.

Liquidity monitoring should consider withdrawal concentrations, locked assets, settlement delays and dependence on third-party custodians or banking partners. 

PoR works best when it sits inside a broader transparency framework. Practical controls around segregation, custody governance, liability reporting and disclosure are explored further in exchange transparency control best practices.

Custody and Wallet Ownership Verification

Verifying a wallet balance is not enough. An exchange must demonstrate that it controls the wallet and has appropriate safeguards over the associated private keys.

Wallet ownership verification may involve:

  • Cryptographic message signing

  • Small test transactions

  • Custodian confirmations

  • Examination of key-management records

  • Review of multi-signature arrangements

  • Testing access and approval controls

Compliance teams should understand where keys are generated, stored and backed up; who can authorise transactions; and how access is removed when employees leave.

They should also assess whether customer assets are held in omnibus wallets, individually segregated wallets or with third-party custodians.

The FCA’s developing crypto-custody framework has focused on safeguarding arrangements and reducing the likelihood and impact of failures involving firms that hold customer cryptoassets.

Exchange Solvency and Customer Protection

Proof of Reserves is often described as evidence of solvency, but reserve coverage and solvency are not identical.

An exchange may have enough selected cryptoassets to cover customer balances while still facing substantial debts, operating losses, legal claims or liquidity problems.

A more complete solvency assessment considers:

Assets: Cryptoassets, cash, investments, receivables and other resources controlled by the exchange.

Liabilities: Customer entitlements, corporate debt, expenses, legal obligations and other amounts owed.

Liquidity: The ability to access assets quickly enough to meet withdrawals and other payments.

Asset quality: Whether reported assets are volatile, restricted, illiquid or dependent on tokens issued by the exchange or affiliated parties.

Operational resilience: Whether customers can access their assets during market stress, cyber incidents or third-party failures.

Proof of Reserves can provide one useful piece of this assessment, but it cannot establish customer protection on its own.

Regulatory Expectations for Transparency

Regulatory approaches vary by jurisdiction, but several common expectations are emerging.

Authorities increasingly focus on customer-asset segregation, accurate recordkeeping, custody governance, conflicts of interest, transparent disclosures and controls designed to protect customers during insolvency.

IOSCO’s global recommendations call for cryptoasset service providers to arrange for the protection and segregation of customer assets and to disclose relevant custody arrangements and risks.

Within the European Union, MiCA establishes requirements for cryptoasset service providers, including custody policies, recordkeeping and arrangements designed to safeguard customer cryptoassets.

In the United Kingdom, the regulatory framework for cryptoasset custody continues to develop. Compliance teams should monitor final FCA rules rather than assuming that voluntary PoR publications satisfy future custody or client-asset obligations.

Regulators are unlikely to regard a public wallet dashboard as a substitute for governance, segregation, reconciliations, financial reporting and independent oversight.

Limitations of Proof of Reserves

Proof of Reserves has several significant limitations.

Point-in-Time Reporting

A report may show assets held on one date without showing what happened before or after the snapshot.

Omitted Liabilities

The exchange may exclude corporate debt, pending claims or customer balances that fall outside the selected scope.

Temporary Borrowing

Assets might be borrowed or transferred into wallets shortly before verification.

Asset Encumbrance

Reported assets may be pledged, lent, locked or subject to claims from other parties.

Incomplete Entity Coverage

A report may cover one company or platform while excluding affiliates that share assets, liabilities or operational functions.

Valuation Risk

Reserve ratios can change quickly when volatile assets are valued in fiat currency.

Privacy and Data Risks

Poorly designed Merkle disclosures may expose account information or allow attackers to infer customer balances.

Lack of Standardisation

PoR reports use different definitions, procedures, reporting formats and assurance levels, making comparison difficult.

These limitations do not make Proof of Reserves useless. They mean that users must interpret each report according to its exact scope.

Best Practices for Compliance Teams

Compliance teams should treat PoR as part of a wider customer-asset control framework.

  1. Define the scope clearly. Identify the legal entities, products, wallets, assets and customer liabilities covered.

  2. Reconcile assets and liabilities regularly. Do not rely only on quarterly or annual snapshots.

  3. Verify wallet control. Combine blockchain balances with cryptographic signing, custody records and key-management evidence.

  4. Test liability completeness. Reconcile the Merkle dataset with the exchange’s full customer ledger.

  5. Identify encumbered assets. Separate assets that are locked, lent, pledged or otherwise unavailable.

  6. Use independent assurance. Select appropriately qualified providers and publish the engagement type, standards and limitations.

  7. Maintain segregation controls. Prevent customer assets from being used for general corporate purposes without valid authority.

  8. Monitor liquidity and withdrawals. Assess whether available reserves can meet realistic customer demand.

  9. Publish understandable disclosures. Explain methodologies, exclusions, reporting dates and reserve ratios in plain language.

  10. Combine PoR with broader assurance. Use financial audits, custody-control reviews, cybersecurity testing and governance oversight.

Future Trends in Exchange Transparency

Exchange transparency is likely to move beyond occasional reserve snapshots.

More platforms may adopt near-real-time dashboards showing wallet balances and reserve ratios. Zero-knowledge proofs could allow exchanges to demonstrate liability coverage without exposing sensitive customer information.

Cryptographic systems may also become better at showing that liabilities are complete, balances are non-negative and assets have not been counted by multiple related entities.

Independent assurance standards may become more consistent as regulators, accounting bodies and the crypto industry develop clearer expectations.

Future transparency frameworks are also likely to integrate:

  • Proof of Assets and Liabilities

  • Liquidity information

  • Custody-control reporting

  • Asset-segregation evidence

  • Financial audits

  • Operational resilience metrics

  • Continuous regulatory reporting

These developments could make Proof of Reserves more useful, but cryptographic verification will still need to be combined with legal, financial and operational oversight.

Frequently Asked Questions

What Is Proof of Reserves?

Proof of Reserves is a method used by crypto exchanges or custodians to demonstrate that they control specified assets intended to cover customer balances included in a reserve calculation.

Does Proof of Reserves Prove an Exchange Is Solvent?

No. It may show that selected assets cover selected customer liabilities at one moment, but it may not include corporate debt, legal claims, liquidity risks or other financial obligations.

How Do Merkle Trees Support Proof of Reserves?

Merkle trees allow customer balances to be combined into one cryptographic root. Individual customers can verify that their balance was included without viewing the balances of other customers.

What Is the Difference Between Proof of Assets and Proof of Liabilities?

Proof of Assets verifies the assets controlled by the exchange. Proof of Liabilities measures the amounts the exchange owes to customers. Both are required for a meaningful reserve comparison.

Is a Proof of Reserves Attestation an Audit?

Not necessarily. A PoR attestation may cover only defined assets, liabilities and procedures. A financial statement audit examines the company’s broader financial position under established auditing and accounting standards.

Can an Exchange Manipulate a PoR Snapshot?

A point-in-time snapshot can potentially be distorted through temporary borrowing, asset transfers, omitted liabilities or narrow entity coverage. Independent testing and continuous monitoring reduce this risk.

Does a 100% Reserve Ratio Guarantee Customer Withdrawals?

No. Assets may be illiquid, locked, pledged or unavailable during operational disruption. Withdrawal capability depends on liquidity, custody controls and operational resilience as well as total reserve value.

What Should Customers Look for in a PoR Report?

Customers should examine the reporting date, covered assets, included liabilities, wallet-control procedures, independent provider, assurance standard, exclusions and whether assets are encumbered.

How Often Should Proof of Reserves Be Performed?

The appropriate frequency depends on the exchange’s size, risk and transaction volume. Continuous internal reconciliations are preferable, while external verification should occur regularly and after significant changes.

What Is the Future of Proof of Reserves?

Future systems are likely to combine real-time on-chain data, zero-knowledge proofs, stronger liability verification, standardised assurance and broader disclosures about liquidity, custody and solvency.

Conclusion

Proof of Reserves can improve exchange transparency by helping customers and compliance teams verify that specified customer liabilities are supported by identifiable assets.

Merkle trees, wallet signing and blockchain verification make it possible to provide evidence without publicly exposing every customer balance. Independent attestations can add further confidence when their scope, standards and limitations are clearly explained.

However, Proof of Reserves is not a complete financial audit and does not independently prove solvency. It may not reveal hidden debts, temporary borrowing, asset encumbrance, liquidity shortages or weak operational controls.

To build a practical working understanding of reserve reporting, attestations and transparency governance, explore Proof of Reserves, Attestations and Exchange Transparency Controls. The course is designed for compliance teams that need to evaluate PoR reports, liability coverage, wallet-control evidence, segregation, custody governance and disclosure risks.