Following several exchange failures, proof of reserves became a standard offering, and what it actually establishes is worth being precise about.

The asset side

Demonstrating control of addresses holding claimed assets.

Which is done by signing messages from those addresses or by moving funds in a demonstrable way.

This proves control at a point in time, not continuously.

The liability side

Demonstrating the total owed to customers.

Which is the harder half and is what distinguishes a real proof from a partial one.

Merkle tree constructions allow individual customers to verify their balance is included without revealing others' balances.

How the tree works

Customer balances are hashed into a tree with a published root.

Each customer receives a path proving their inclusion.

Which lets them verify individually, and the total is only trustworthy if enough customers check.

The borrowed funds problem

An exchange can borrow assets before a snapshot and return them afterwards.

Which defeats a point-in-time asset proof entirely.

This has been demonstrated in practice, which is why frequency and unpredictability of attestation matter.

Negative balances

An exchange could include negative entries to reduce apparent liabilities.

Which is why constructions incorporating range proofs demonstrating all balances are non-negative have been proposed.

Zero-knowledge approaches addressing this exist and adoption has been limited.

What it does not cover

Off-chain liabilities, loans, obligations to counterparties and corporate debt.

Which means an exchange can pass a proof of reserves and still be insolvent.

Full assurance requires an audit of the whole balance sheet, which is a different exercise entirely.

Auditor involvement

Some exercises are reviewed by accounting firms and some are self-published.

Which differ substantially in the assurance provided.

Several major firms withdrew from this work following concerns about how their involvement was represented.

Reading a report

Check whether liabilities are covered, whether an independent party was involved, how frequently it is repeated, and what is explicitly excluded.

Frequency

A single snapshot proves less than regular unannounced attestations.

Which is why some venues publish continuously updated address balances.

Continuous asset visibility with periodic liability attestation is the stronger combination available today.

Privacy considerations

Publishing addresses reveals holdings and transaction patterns.

Which is a commercial concern for venues and a transparency benefit for users.

Zero-knowledge constructions aim to prove solvency without revealing the underlying detail.

Regulatory alternatives

Several jurisdictions require segregation of client assets and independent audit.

Which addresses the same concern through supervision rather than through cryptography.

The two approaches are complementary rather than competing.

What users can do

Verify your own inclusion where a venue provides the proof.

Which takes minutes and only works if enough users do it.

Verification rates have been low, which weakens the whole mechanism.

The underlying point

Proof of reserves reduces one specific uncertainty and does not establish solvency.

Which is worth stating clearly, since it has been marketed as though it does.

What auditors will and will not sign

Accounting firms distinguish between agreed-upon procedures and an audit opinion.

Which are very different levels of assurance and are frequently conflated in reporting.

Agreed-upon procedures reports state exactly what was done and provide no opinion on the whole.

Historical failures

Platforms that published reserve information and subsequently failed demonstrate the limits.

Which generally involved liabilities the published information did not cover.

Each case sharpened understanding of what these exercises need to include.

Implementation variations

Some venues publish address lists, some publish signed messages, some use third-party verification.

Which differ in what a user can independently confirm.

Address lists that anyone can watch continuously are the most user-verifiable approach.

Custodial versus self-custody

The whole discussion exists because assets are held by a third party.

Which is avoidable by holding assets directly, at the cost of taking on operational responsibility.

That trade is the actual decision, and proof of reserves only improves one side of it.

Standards development

Industry bodies have worked on common formats and minimum requirements.

Which would allow comparison between venues.

Adoption has been partial, and the absence of a standard means each venue defines its own scope.

Practical takeaway

Treat it as one signal among several rather than as a solvency guarantee.

What a complete exercise would include

Continuous asset visibility, regularly attested liabilities with non-negativity proofs, independent verification and full scope disclosure.

Which no widely used implementation currently provides in full.

Understanding the gap is the point rather than dismissing the exercise, since partial assurance is still better than none.

A note on incentives

A venue publishing a limited exercise gains reputational benefit for effort that falls well short of an audit.

Which is why the scope disclosure matters more than the headline.

Reading what a report explicitly excludes is generally more informative than reading what it includes.

A closing observation

A venue can pass every proof of reserves exercise currently in common use and still be insolvent, because none of them address off-chain liabilities. That is not an argument against the practice — it is an argument for understanding exactly what it establishes.