Crypto Proof of Reserves: Attestation Services Compared
Compare crypto proof-of-reserves attestation services by methodology, frequency, verifiability, and exchange coverage. Merkle trees, zk-proofs, and audit firms ranked.
Proof of Reserves: Why It Matters
When users deposit funds on a crypto exchange, they surrender custody of their assets to a third party. The exchange promises to hold those assets on the user's behalf, but without independent verification, that promise is unenforceable. Proof of reserves (PoR) is the mechanism by which exchanges attempt to demonstrate that customer deposits are fully backed.
The concept gained urgency after the collapse of FTX in November 2022. FTX had no independent reserve verification, and an estimated $8 billion or more in customer funds were commingled with Alameda Research's trading operations. Within days of FTX's bankruptcy filing, nine major exchanges announced they would publish proof of reserves. The industry has since developed a range of attestation approaches, each with different tradeoffs in transparency, verifiability, and completeness.
Exchange Attestation Methods Compared
The following table compares how major exchanges prove their reserves. Methodology, attestation frequency, auditor independence, and liability coverage vary significantly across platforms.
| Exchange | Methodology | Frequency | Auditor / Verifier | Includes Liabilities | User Self-Verification |
|---|---|---|---|---|---|
| Binance | Merkle tree + zk-SNARKs | Periodic (40+ reports) | Self-published, open-source code | Partial (zk-SNARKs prove non-negative balances) | Yes |
| Kraken | Merkle tree + third-party audit | Quarterly | The Network Firm LLP | Yes (total client liabilities included) | Yes (personalized Merkle proofs) |
| OKX | Merkle tree + zk-STARKs | Monthly | Hacken | Partial (zk-STARKs verify balance integrity) | Yes |
| Coinbase | SEC-mandated audited financials | Quarterly (10-Q) and annual (10-K) | Deloitte & Touche LLP (PCAOB) | Yes (full balance sheet) | No (public filings only) |
| Bitget | Merkle tree + public wallet addresses | Monthly | Self-published, open-source MerkleValidator | No | Yes |
| Bybit | Merkle tree + third-party audit | Monthly | Hacken | No | Yes |
Kraken stands out for explicitly including total client liabilities in every report. Its September 2025 attestation confirmed reserve ratios above 100% across all covered assets, with BTC at 114.9%. Coinbase takes a fundamentally different approach: as a publicly traded company (NASDAQ: COIN), it relies on SEC-mandated audited financial statements that include both assets and liabilities, audited by Deloitte under PCAOB standards. For a broader look at exchange security practices, see the crypto exchange security comparison.
Proof-of-Reserves Methodologies
The technical approaches to proving reserves range from basic wallet address disclosure to sophisticated zero-knowledge proof systems. Each methodology offers different guarantees.
Merkle Tree Proofs
A Merkle tree is a cryptographic data structure where every customer balance is hashed and placed as a leaf node. Pairs of hashes are combined and hashed upward until a single Merkle root represents all balances. Each user receives a personalized Merkle proof: a path of sibling hashes from their leaf to the root that verifies their balance is included in the total.
Limitations: plain Merkle trees leak information about account distribution and total account count. More critically, an exchange could insert negative balances into the tree to artificially reduce the apparent total liability. This is why more advanced approaches layer zero-knowledge proofs on top.
zk-SNARKs (Binance)
Binance became the first centralized exchange to implement zk-SNARKs for proof of reserves in February 2023, partnering with Polyhedra Network. The zk-SNARK circuit verifies three properties without revealing individual account data: every user's balance is included in the global state, no account has a negative net balance, and the total sum equals the claimed aggregate. The implementation is open-source on GitHub, allowing independent review.
zk-STARKs (OKX)
OKX uses zk-STARKs instead of zk-SNARKs. STARKs use the FRI protocol and do not require a trusted setup, making them more transparent at the cost of larger proof sizes. They are also considered more resistant to potential quantum computing attacks. OKX has published 37 or more consecutive monthly reports using this methodology, independently audited by Hacken.
Chainlink Proof of Reserve
Chainlink's Proof of Reserve system provides automated, real-time verification for tokenized assets like stablecoins and wrapped tokens. Decentralized oracle network nodes fetch reserve data directly from custodians, cryptographically sign the results, and publish them on-chain. A key feature is the "Secure Mint" circuit breaker, which automatically halts minting if reserves drop below the token supply.
SEC-Mandated Audits (Coinbase)
Coinbase does not publish a crypto-native PoR report. Instead, Deloitte audits its financial statements under PCAOB standards. External auditors randomly sample cold storage wallet addresses and require Coinbase to demonstrate ownership via key signing ceremonies. Coinbase CEO Brian Armstrong has argued that Deloitte's annual audit and SEC quarterly filings provide stronger assurance than PoR snapshots, while citing privacy concerns for institutional clients whose wallet addresses would be exposed.
Audit Firms and Their Crypto History
The landscape of firms willing to attest to crypto reserves has shifted dramatically since FTX's collapse. Several prominent firms exited the space, while specialized new entrants emerged to fill the gap.
| Firm | Status | Notable Clients | Key Events |
|---|---|---|---|
| Mazars | Paused crypto PoR (Dec 2022); re-entered for stablecoin attestations (2025) | Formerly Binance, Crypto.com, KuCoin | Cited concerns about public misunderstanding of PoR reports |
| Armanino LLP | Exited crypto audits (Dec 2022) | Formerly Kraken, Nexo, FTX US | Exited amid scrutiny of past FTX US audit work |
| The Network Firm LLP | Active (formed March 2023) | Kraken, CoinShares | Founded by ex-Armanino digital-asset team; Miami-based |
| Grant Thornton | Active | Circle (USDC attestations) | Uses proprietary "Merkle platform" for forensic analytics |
| Hacken | Active | OKX, Bybit, Gate.io, Crypto.com | Blockchain security firm; pioneered PoR audits in 2019 |
| Deloitte | Active (public company audits only) | Coinbase | PCAOB engagement; does not offer PoR for private crypto firms |
The exit of Mazars and Armanino in December 2022 left a significant gap. Forvis Mazars US has since re-entered the space with a narrower focus on stablecoin reserve attestations, publishing compliance guidance in November 2025. The Big Four accounting firms remain largely unwilling to conduct PoR attestations for private crypto companies, though they will audit publicly traded crypto firms under standard SEC engagement rules.
For a detailed look at stablecoin reserve audits specifically, see our research on stablecoin reserve transparency and auditing.
The Liability Gap: What Proof of Reserves Does Not Prove
The fundamental limitation of proof of reserves is that it proves assets exist without proving the absence of liabilities. An exchange could hold $1 billion in verifiable on-chain assets while owing $3 billion to users, and a standard PoR report would show nothing wrong.
Vitalik Buterin articulated this problem in his November 2022 post "Having a safe CEX: proof of solvency and beyond," arguing that true proof of solvency requires both proof of assets and proof of liabilities. Most PoR implementations address only the asset side.
Additional blind spots include:
- Point-in-time snapshots: an exchange could borrow assets to pass the check and return them afterward
- Off-chain obligations: fiat debts, legal liabilities, and traditional financial obligations are invisible to on-chain proofs
- Encumbered assets: reserves shown in a report could be borrowed, rehypothecated, or pledged as collateral without disclosure
- No continuous assurance: monthly or quarterly snapshots leave gaps between verification points
The PCAOB issued a March 2023 advisory stating that PoR engagements "are not audits" and "do not provide any meaningful assurance to investors." The SEC's Acting Chief Accountant Paul Munter published a similar warning in July 2023, cautioning that crypto auditors risk suspension for misleading claims about what PoR attestations actually prove.
Industry Standards and Regulation
Standardization efforts are beginning to bring consistency to a fragmented landscape. The AICPA published its "2025 Criteria for Stablecoin Reporting," a 27-page framework covering three core areas: redeemable tokens outstanding, redemption assets available, and comparison between tokens and reserves. A follow-up Part II added criteria for controls supporting token operations.
In Europe, the MiCA regulation (fully effective December 30, 2024) requires stablecoin issuers to maintain full 1:1 reserve backing with liquid assets, keep at least 30% of reserves in segregated bank accounts, and submit to regular reserve audits. The EU began a MiCA stablecoin rewrite in mid-2026 after the initial reserve rules were criticized for favoring incumbent issuers.
In the US, the GENIUS Act represents the most significant federal stablecoin legislation under development, though comprehensive PoR requirements for exchanges remain absent from current US law. For more context on the regulatory landscape, see our research on the GENIUS Act and stablecoin regulation.
Stress Testing: The Bybit Hack
The strongest validation of a proof-of-reserves system comes not from routine attestations but from crisis response. On February 21, 2025, Bybit suffered a $1.5 billion hack attributed to North Korea's Lazarus Group: the largest single theft in crypto history. Bybit replenished its reserves within 72 hours through emergency funding from Galaxy Digital, FalconX, and Wintermute, securing approximately 447,000 ETH. Hacken's subsequent PoR audit confirmed full re-collateralization across all major assets.
The incident demonstrated both the value and the limits of PoR. The monthly Hacken audits confirmed Bybit's solvency after recovery, but a PoR snapshot taken during the 72-hour gap would have shown a massive shortfall. Only ~$42.3 million (3%) of the stolen assets were frozen or recovered.
Self-Custody: Eliminating the Need for Attestation
Every proof-of-reserves system exists because users have surrendered control of their assets to a third party. The self-custody model eliminates the problem entirely: when users hold their own private keys, no attestation, auditor, or trust assumption is required. The blockchain itself is the proof, and the user is both custodian and verifier.
Users who held assets in cold storage or non-custodial wallets were completely unaffected by FTX's collapse. This is the foundational principle behind "not your keys, not your coins." However, self-custody introduces its own tradeoffs: users bear sole responsibility for key management, and loss of a seed phrase means permanent loss of funds.
Protocols like Spark are designed to make self-custody practical for everyday use. Spark enables users to hold and transfer Bitcoin and stablecoins like USDB in a self-custodial manner with instant settlement and near-zero fees, removing the performance gap that historically pushed users toward custodial exchanges. For a deeper comparison, see the self-custody vs. custodial guide.
Frequently Asked Questions
What is proof of reserves in crypto?
Proof of reserves is a verification process where a crypto exchange or custodian demonstrates that it holds sufficient assets to cover all customer deposits. The most common approach uses Merkle trees to let individual users verify their balance is included in the total, combined with on-chain wallet address disclosure showing the exchange controls the claimed assets. More advanced implementations add zero-knowledge proofs to protect user privacy while proving balance integrity.
Which crypto exchanges have proof of reserves?
As of 2026, major exchanges with active PoR programs include Binance (Merkle tree + zk-SNARKs), Kraken (Merkle tree audited by The Network Firm), OKX (Merkle tree + zk-STARKs audited by Hacken), Bitget (Merkle tree, self-published), and Bybit (Merkle tree audited by Hacken). Coinbase publishes SEC-audited financial statements instead of crypto-native PoR. Gate.io and Crypto.com also maintain PoR programs.
Is proof of reserves the same as an audit?
No. The PCAOB stated in March 2023 that PoR engagements "are not audits" and "do not provide any meaningful assurance to investors." A full audit examines both assets and liabilities, evaluates internal controls, and follows established accounting standards (like PCAOB or GAAP). Most PoR attestations verify only that assets exist on-chain at a single point in time, without assessing liabilities, off-chain obligations, or whether the assets are encumbered.
What is the liability gap in proof of reserves?
The liability gap refers to the fact that standard PoR only proves assets exist without proving the absence of debts or obligations. An exchange could show $5 billion in on-chain reserves while secretly owing $8 billion to users, creditors, or counterparties. Kraken and Coinbase are notable exceptions: Kraken includes total client liabilities in every PoR report, and Coinbase's SEC filings include full balance sheets. Most other exchanges verify only the asset side.
How do zk-proofs improve proof of reserves?
Plain Merkle tree proofs leak information about account distribution and cannot prevent an exchange from inserting negative balances to deflate its apparent liabilities. Zero-knowledge proofs (zk-SNARKs and zk-STARKs) solve both problems: they verify that no account has a negative balance and that all balances sum to the claimed total, without revealing any individual account data. Binance uses zk-SNARKs (with Polyhedra Network) and OKX uses zk-STARKs (which avoid the need for a trusted setup).
Does self-custody eliminate the need for proof of reserves?
Yes. When users hold their own private keys, no third-party attestation is necessary. The blockchain itself serves as the proof, and the user can verify their holdings at any time. This is why FTX's collapse only affected users who had deposited funds on the exchange. Protocols like Spark make self-custody practical for daily transactions by offering instant settlement and low fees, closing the usability gap that traditionally drove users to custodial platforms.
Which audit firms verify crypto reserves?
The main active firms are The Network Firm LLP (Kraken), Hacken (OKX, Bybit, Gate.io), Grant Thornton (Circle/USDC), and Deloitte (Coinbase via SEC engagement). Mazars and Armanino both exited crypto attestation work in December 2022, though Forvis Mazars US has since re-entered for stablecoin-specific attestations. The Big Four remain broadly unwilling to conduct PoR for private crypto companies.
This tool is for informational purposes only and does not constitute financial advice. Proof-of-reserves data is based on publicly available exchange reports, auditor publications, and regulatory filings. Reserve ratios, attestation frequencies, and auditor relationships change over time. Always verify current data directly with the exchange or auditor before making custody decisions.
Build with Spark
Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.
Read the docs →
