Back to Research
Crypto Exchange Proof of Reserves: A Solvency and Liquidity Audit Checklist
Exchange Risk
2026-06-2918 min read

Crypto Exchange Proof of Reserves: A Solvency and Liquidity Audit Checklist

C

Research Desk • Organizational attribution

Source Standard
6 source notes
Last Reviewed
2026-07-11

Crypto Exchange Proof of Reserves: A Solvency and Liquidity Audit Checklist

Short answer: Proof of reserves can show that an exchange controlled certain assets at a stated time. It does not, by itself, prove that customer liabilities were complete, reserves were unencumbered, clients legally own the assets, the platform can meet a withdrawal run, or the business is solvent. Evaluate five separate layers: asset control, liability completeness, legal availability, liquidity under stress, and independent assurance scope.

A green “100% backed” badge compresses too many questions into one ratio. The numerator may include illiquid tokens, affiliated assets, borrowed balances, or assets pledged to lenders. The denominator may omit derivatives, institutional accounts, pending withdrawals, negative balances, or entities outside the report. Even a mathematically correct snapshot can become stale one block later.

This guide turns proof of reserves into a reproducible review. It does not rate or endorse any exchange, and it cannot replace financial statements, regulatory supervision, or legal advice about customer rights.

Proof of Reserves, Solvency, and Liquidity Are Different Tests

Use the terms precisely.

TestCore questionTypical evidenceWhat it still misses
Asset controlCan the platform control the reported assets?Signed message, on-chain movement, custodian confirmationOwnership, encumbrance, liabilities
Customer liability proofWere customer claims included correctly?Merkle inclusion proof, account-level reconciliationOmitted accounts, off-chain obligations, methodology defects
CoverageDo eligible assets equal or exceed included liabilities?Asset-by-asset ratioTiming, legal rights, liquidity, hidden debt
SolvencyDo total assets exceed total liabilities across the legal entity?Complete audited financial statementsFuture losses and operational failure
LiquidityCan obligations be met when due without severe loss?Maturity ladder, stress test, withdrawal performanceExtreme or novel scenarios
Client-asset protectionAre customer assets segregated and protected from firm creditors?Law, contract, account structure, reconciliationCourt interpretation and cross-border conflict

An exchange can pass one test and fail another. It may control enough BTC to cover reported BTC customer balances while lacking fiat liquidity, carrying undisclosed corporate debt, or holding customer assets in an entity where insolvency treatment is unclear.

The PCAOB's investor advisory is blunt on this distinction. It warns that proof-of-reserve reports are not audits, may not address liabilities or rights, may not reveal temporarily borrowed assets, and do not assure internal controls, governance, future availability, or financial stability. The name of an accounting firm does not expand an engagement beyond the procedures in its report.

The Five-Layer Reserve Audit

Layer 1: Does the Exchange Control the Assets?

For on-chain assets, a platform can demonstrate control by signing an agreed message with relevant keys or moving a specified amount under controlled conditions. A block-explorer screenshot is weaker because anyone can point to a wealthy address.

Control evidence should include:

exact addresses or a reproducible address commitment;
the network and asset version;
snapshot block height and coordinated time;
proof method and challenge message;
treatment of multisignature, custodians, and omnibus wallets;
address additions and removals since the prior report;
independent verification that signatures or movements were valid.

Bitcoin transactions spend complete UTXOs and often create change outputs. Analysts should guard against counting both a source address and its relocated change as separate reserves. Wrapped and bridged assets create another risk: one underlying unit and several derivative representations can be counted more than once unless the methodology reconciles issuance and backing.

For assets held with banks or third-party custodians, blockchain control is insufficient or unavailable. The report needs direct confirmations, account ownership, restrictions, lien status, and reconciliation to the correct legal entity.

Layer 2: Are Customer Liabilities Complete?

The liability population is usually harder to verify than visible wallets. Ask which balances and products enter the denominator.

Liability categoryCommon omission or ambiguity
Spot customer balancesDormant, restricted, or institutional accounts may be excluded
Pending deposits and withdrawalsCutoff timing can shift the snapshot
Margin accountsNegative balances may improperly reduce gross obligations
DerivativesMark-to-market claims, collateral, and settlement obligations vary
Earn or lending productsCustomer claim may sit with an affiliate or borrower
Staked assetsRewards, lockups, slashing, and validator claims complicate amounts
Fiat balancesBanking entities and payment intermediaries may differ from crypto entity
Wrapped or bridged assetsIssuer and redemption liabilities can be double counted or omitted
Corporate and institutional accountsSeparate custody agreements may fall outside retail proof
Fees and unsettled tradesTiming and netting policies alter totals

The report should define whether liabilities are gross or net. A customer's $100 BTC claim and $80 margin debt should not automatically become only $20 of reserve need without explaining enforceable setoff rights, collateral terms, and stress behavior. Negative balances can be uncollectible precisely when reserves are needed.

Layer 3: Are Reserves Legally Available to Customers?

An asset can exist, be controlled, and still be unavailable for customer withdrawals because it is pledged, lent, subject to a lien, held for another entity, frozen, or caught in insolvency.

IOSCO's crypto-market recommendations focus on legal and operational segregation, reuse of client assets, ownership, reconciliation, custody disclosures, and independent assurance. These concerns cannot be solved with a wallet signature.

Review:

the contracting legal entity shown in account terms;
whether customer assets are held in trust, custody, bailment, or as unsecured claims;
whether assets are operationally separated from corporate property;
whether the platform may lend, stake, rehypothecate, or pledge them;
which customer consent applies to reuse;
treatment of forks, airdrops, staking rewards, and slashing;
applicable insolvency law and jurisdiction;
whether custodians have setoff, lien, or indemnity rights;
intercompany transfers and affiliate claims;
procedures for returning assets if the platform stops operating.

“Segregated on-chain address” and “legally segregated client property” are not synonyms. An exchange can use separate addresses in its internal architecture while the customer agreement creates only a contractual claim against the company.

Layer 4: Can the Exchange Survive a Withdrawal Run?

Coverage at market value is not the same as immediately spendable liquidity. A platform may keep most keys offline for security, stake assets with an unbonding period, lend them to counterparties, or hold thinly traded tokens whose quoted value disappears under sale pressure.

Create a liquidity ladder:

BucketExampleHaircut question
Same-day availableHot wallets, unrestricted bank cashAre transfer and banking rails operating?
Operationally releasableCold wallets requiring quorumHow long does authorization and signing take under stress?
Time-lockedStaked or contractually locked assetsWhat is the actual exit date and slashing risk?
Counterparty receivableLoans, OTC balances, affiliate claimsWill the counterparty pay during a market run?
Market-dependentThin tokens or concentrated holdingsWhat price survives liquidation of the required size?
Legally restrictedPledged, frozen, disputed, or liened assetsCan customers access any value at all?

Withdrawal performance is an observable complement to reports. Test small withdrawals periodically, record processing time and fee, and watch whether limits or documentation requirements change during stress. A successful small withdrawal does not prove system-wide liquidity, but repeated delays can contradict a polished reserve page.

Layer 5: What Did the Independent Provider Actually Do?

Read the report, not the logo.

Identify whether the work is:

a financial-statement audit;
a reasonable-assurance engagement;
a limited-assurance engagement;
agreed-upon procedures;
a consulting or technical verification;
an exchange-generated dashboard with no external provider.

For agreed-upon procedures, management and specified parties choose procedures, and the provider reports factual findings without deciding whether those procedures are sufficient for a broader solvency conclusion. A report can accurately say “we compared these addresses with this list at 12:00 UTC” while offering no opinion about completeness, ownership, or financial health.

Check the standard used, intended users, period or point-in-time date, entities, assets, liabilities, exclusions, materiality, sampling, control testing, subsequent events, provider independence, and management representations. Marketing language should never outrun the conclusion paragraph.

Four Coverage Ratios, Not One

Use several ratios to expose where confidence disappears.

1. Gross Reported Coverage

Reported reserve assets ÷ reported customer liabilities

This reproduces the platform's headline but accepts its eligibility and valuation choices.

2. Eligible Coverage

Unencumbered, customer-available reserve assets ÷ in-scope customer liabilities

Remove treasury tokens, pledged assets, affiliate receivables, and anything not demonstrably available to satisfy customers.

3. Liquid Coverage

Assets available within the stress horizon ÷ liabilities withdrawable in that horizon

If users can request withdrawal today, a seven-day staking exit does not belong in same-day liquidity.

4. Stress-Adjusted Coverage

Sum of each reserve asset after risk haircut ÷ stressed customer claims

Apply transparent haircuts for price, credit, liquidity, operational delay, and legal uncertainty. The haircut is a scenario assumption, not a fact, so publish it.

Worked Example: How “108% Backed” Becomes 72%

Consider a fictional exchange reporting $1.08 billion of reserves against $1.00 billion of customer liabilities.

Reserve componentReported valueAudit adjustmentEligible valueSame-day stressed value
BTC and ETH in verified wallets$650m15% market/liquidity haircut$650m$552.5m
Fiat and Treasury bills$200m$25m bank account subject to affiliate lien$175m$170m
Stablecoins$120m10% issuer/platform stress haircut$120m$108m
Exchange-issued token$70mExcluded due to wrong-way risk$0$0
Loan to affiliated market maker$40mNot a customer-available reserve$0$0
Total$1.08bn$945m$830.5m

Now adjust liabilities. The published denominator omitted $90 million from an affiliated lending program and netted $60 million of customer debit balances against obligations. Using a conservative gross approach:

Reported liabilities: $1.00 billion
Add omitted lending claims: $90 million
Add back negative-balance netting: $60 million
Adjusted customer claims: $1.15 billion

The ratios become:

RatioCalculationResult
Headline coverage$1.08bn ÷ $1.00bn108.0%
Eligible coverage$945m ÷ $1.15bn82.2%
Same-day stress coverage$830.5m ÷ $1.15bn72.2%

This example does not model a real platform. It shows why readers need asset composition and liability scope. A single headline percentage can change dramatically without discovering that any wallet was fake.

How Merkle Liability Proofs Work

A Merkle tree can commit to a large set of customer balances. Each user's balance contributes to a leaf; hashes combine through the tree until one root represents the dataset. The exchange publishes the root, and a user receives a proof path showing that the user's leaf was included without receiving every other customer's account data.

That solves a narrow problem: inclusion in the committed dataset. It does not independently prove:

every eligible customer was included;
balances and account ownership were correct;
the same liability was not represented inconsistently across entities;
negative balances were handled safely;
off-chain lending or derivatives claims were included;
the exchange did not create fake accounts to manipulate distribution;
the root corresponds to the asset snapshot cutoff;
assets remain available after the snapshot.

What a Strong Liability Proof Publishes

1.The exact balance calculation and cutoff rule.
2.Asset and product scope.
3.Treatment of negative balances, margin, derivatives, and unsettled trades.
4.A user-verification tool with open or inspectable logic.
5.Privacy safeguards against balance discovery and enumeration.
6.Independent reconciliation from account ledger to tree population.
7.Aggregate totals signed or otherwise committed at the snapshot time.
8.Historical roots and methodology versions.

Users should verify their own inclusion after each snapshot. If their balance is missing or wrong, preserve evidence and contact the platform immediately. Individual inclusion still does not establish total completeness.

Asset-Quality Rules

Reserve quality depends on how an asset behaves when the exchange itself is under pressure.

Stronger Characteristics

independently priced in deep markets;
no direct dependence on the exchange's survival;
clear legal ownership and no lien;
readily transferable on functioning networks or bank rails;
short maturity where maturity exists;
diversified custodians and banking counterparties;
transparent valuation and reconciliation.

Weaker Characteristics

exchange-issued or affiliate-linked token;
concentrated, thinly traded holding;
unsecured affiliate receivable;
locked staking or long redemption window;
wrapped asset with uncertain backing;
collateral already securing another obligation;
token whose liquidity is supplied mainly by the exchange itself;
bank balance in an account not legally owned by the reporting entity.

Exchange-issued tokens create wrong-way risk: the token can fall because confidence in the issuer falls, precisely when customers demand stronger reserves. Report them separately and apply a severe or complete eligibility haircut when assessing customer protection.

The Basel Committee's redemption-risk framework addresses stable-value cryptoassets rather than exchanges, but its principles offer a useful benchmark: clear ownership, low-risk and liquid reserve assets, ongoing valuation, stress testing, public composition, independent verification, and enough liquidity to meet redemptions under stress. An exchange reserve system should face at least comparable questions.

Entity and Scope Map

Large platforms often operate multiple companies across jurisdictions. Build a map before comparing assets and liabilities.

QuestionEvidence to collect
Who contracts with the customer?Terms of service and account statement
Who controls each wallet?Address proof and custodian confirmation
Who owes fiat balances?Banking and payment disclosures
Which entity runs derivatives?Product agreement and regulatory record
Where do earn/lending claims sit?Program terms and borrower identity
Are affiliates included in reserve report?Scope paragraph and entity list
Can assets move between affiliates?Intercompany policy and financial statements
Which insolvency law applies?Contract jurisdiction and legal opinion where available

Do not divide assets of Company A by liabilities of Company B merely because both share a brand. Conversely, an exchange cannot demonstrate group solvency by highlighting one well-funded entity while omitting another entity that owes customers.

Snapshot Manipulation and Window Dressing

Point-in-time reports are vulnerable to temporary balance changes. The PCAOB specifically warns that a reserve report may not reveal whether assets were borrowed for the snapshot or used afterward.

Look for:

large inflows immediately before the cutoff and reversals afterward;
transfers among exchanges that appear sequentially in several reports;
unexplained custodian or address changes;
report dates selected after fundraising or asset sales;
liabilities measured at a different time from assets;
recurring quarter-end movements;
assurance procedures that do not inspect subsequent transactions.

A stronger design uses frequent or continuous commitments, consistent methodology, historical archives, surprise testing, subsequent-event procedures, and periodic full financial audits. Continuous wallet dashboards improve timeliness but still cannot continuously prove off-chain liabilities or legal availability.

Withdrawal Stress Test

Reserve review should model a run rather than assume orderly redemptions.

Scenario

25% of withdrawable crypto claims request transfer within 48 hours.
Stablecoin prices fall 5% and one issuer pauses a banking route.
BTC and ETH fall 20%, increasing collateral and margin stress.
cold-wallet quorum loses one signer for 12 hours;
an affiliated borrower delays repayment;
fiat banks shorten operating hours or apply enhanced reviews.

Ask whether the exchange has enough hot and releasable assets by coin, not only in aggregate dollars. A surplus of BTC cannot satisfy an immediate USDC obligation unless conversion markets, banking, and customer terms permit substitution. Coin-by-coin coverage and operational timing both matter.

Stress Questions

What percentage of each liability can be withdrawn immediately?
What is the tested cold-to-hot transfer time?
Are withdrawal keys and signers independent of trading systems?
Can one bank, custodian, cloud provider, or stablecoin issuer halt operations?
Are customer assets lent or staked with mismatched notice periods?
What automatic withdrawal limits activate under unusual activity?
Has the platform published business-continuity and incident history?

Comparing Two Exchanges

Score evidence, not brand familiarity.

DimensionWeak disclosureStronger disclosure
Wallet controlScreenshot or unlabeled totalAddresses/commitment, signed challenge, block height
LiabilitiesNo denominatorReconciled customer population and user inclusion proof
Scope“Major assets”Entity, product, asset, and exclusion schedule
Asset qualityOne aggregate valueCoin-by-coin composition and eligibility policy
EncumbranceSilentLiens, lending, staking, reuse, and affiliates disclosed
Legal rightsMarketing statementContracting entity, segregation, insolvency treatment
AssuranceProvider logoStandard, procedures, limitations, conclusion, independence
CadenceOne crisis snapshotConsistent history and methodology versions
LiquidityReserve value onlyMaturity ladder, stress test, withdrawal operations
GovernanceNo controlsReconciliation, key controls, incidents, oversight

The stronger column still does not mean risk-free. It means the customer can identify assumptions and failure modes rather than trust an unexplained number.

Red Flags That Require Immediate Review

liabilities absent or materially older than the asset snapshot;
only selected tokens included without an exclusion list;
large reserve share in the exchange's own token;
customer funds lent or pledged without clear consent;
“audited” used for a non-audit procedure report;
assurance report withheld while conclusions are advertised;
unexplained changes in methodology or covered entities;
proof tool cannot reproduce the user's balance;
abrupt withdrawal caps, delays, or asset substitutions;
related-party receivables counted as liquid reserves;
liabilities netted against doubtful customer debts;
addresses duplicated across networks or wrapped assets;
no legal explanation of segregation and insolvency rights;
reserve publication appears only after market rumors.

One red flag does not prove fraud or insolvency. It identifies a question that the available disclosure has not answered.

Personal Exchange-Exposure Policy

Individuals cannot audit an exchange from the outside, but they can limit the consequence of uncertainty.

1.Keep only the balance needed for a defined trading or conversion purpose.
2.Set a maximum platform exposure as a percentage of total investable assets.
3.Count exchange, lending, staking, and stablecoin exposure by common counterparty.
4.Test withdrawals to the intended destination before urgency arises.
5.Use unique credentials, strong multifactor authentication, withdrawal allowlists, and device controls.
6.Preserve account statements, transaction IDs, tax records, and support correspondence.
7.Understand self-custody and recovery before moving long-term assets; it replaces counterparty risk with key-management risk.
8.Reassess after changes in terms, legal entity, banking partner, ownership, reserve method, or withdrawal behavior.

“Not your keys” captures one tradeoff but not the whole decision. Self-custody can remove exchange-credit exposure while introducing irreversible loss, inheritance, coercion, and operational risks. Use the <a href="/insights/crypto-wallet-recovery-seed-checklist-2026">wallet recovery and seed checklist</a> to test that system before treating it as safer.

Reserve Review Worksheet

Copy these fields into a dated note for each platform:

Report identity

Report URL and archive date:
Snapshot time and block heights:
Legal entities covered:
Products and customer groups covered:
Assets and liabilities excluded:
Assurance provider and engagement type:

Coverage calculations

Reported assets:
Reported liabilities:
Gross reported coverage:
Ineligible or encumbered assets removed:
Omitted or conservatively adjusted liabilities added:
Eligible coverage:
Same-day liquid coverage:
Stress assumptions and stress-adjusted coverage:

Legal and operational review

Customer property classification:
Reuse, lending, staking, and lien rights:
Custodians and banks:
Withdrawal limits and tested processing time:
Latest inclusion-proof result:
Unresolved questions and escalation date:

Using the same worksheet over time makes methodology drift visible and prevents a new marketing layout from being mistaken for better evidence.

Frequently Asked Questions

Does proof of reserves prove an exchange is solvent?

No. It may verify selected assets at a point in time. Solvency requires a complete view of assets and liabilities across the relevant legal entities, including debt, contingent obligations, affiliates, ownership, and encumbrances.

Is a proof-of-reserves report an audit?

Not necessarily, and commonly not. The PCAOB warns that these reports are not financial-statement audits and may be agreed-upon procedures or other work outside PCAOB oversight. Read the engagement type and conclusion.

What does a Merkle proof tell me?

It can show that your balance was included in a dataset committed by a published Merkle root. It does not show that every other liability was included or that the exchange owns enough unencumbered liquid assets.

Should customer debit balances reduce reserve liabilities?

Only after careful analysis of enforceable setoff, collectability, collateral, and stress timing. Gross presentation is often more conservative because customers with negative balances may default during the same event that triggers withdrawals.

Are exchange-issued tokens valid reserves?

They may have market value, but they create severe wrong-way risk because their price can collapse with confidence in the exchange. Analyze them separately and avoid relying on them for customer-protection coverage.

Does an on-chain wallet prove ownership?

A valid signature or controlled movement proves key control at that time, not necessarily beneficial ownership or freedom from liens. Custodians, borrowers, affiliates, and customers can have different legal interests in the same assets.

How recent should a reserve report be?

There is no universal safe age. More frequent reporting reduces staleness but does not repair incomplete scope. Compare asset and liability timestamps, preserve historical reports, and examine material transactions immediately before and after snapshots.

Can a fully reserved exchange still pause withdrawals?

Yes. Assets may be cold, locked, pledged, operationally inaccessible, on a disrupted network, or denominated differently from requested withdrawals. Solvency and liquidity are related but distinct.

Is self-custody always safer?

No. It removes some intermediary risks but makes the holder responsible for key security, recovery, inheritance, transaction accuracy, and physical protection. The safer arrangement is the one whose specific failure modes are understood and controlled.

Conclusion

Proof of reserves is useful evidence when its scope is narrow and explicit. It can establish control of named assets, help customers verify liability inclusion, and make changes over time more visible. It becomes misleading when a snapshot is sold as a complete solvency, liquidity, or customer-protection certificate.

The practical response is not to dismiss every report. Recalculate it. Separate reported, eligible, liquid, and stress-adjusted coverage. Map the legal entities. Read the assurance conclusion. Test withdrawals. Then size platform exposure for the uncertainty that remains.

What to Read Next

Read the <a href="/insights/stablecoin-proof-of-reserves-checklist-2026">stablecoin proof-of-reserves checklist</a> next. Stablecoin issuers add a different liability structure, reserve-asset mandate, redemption mechanism, and banking-liquidity problem that should not be analyzed as though it were an exchange wallet report.

CryptosEyes provides general educational research, not individualized legal, accounting, or investment advice. Reserve disclosures and customer rights vary by entity, jurisdiction, product, and date.

Source & Review Basis

This article is reviewed against the source types below. Source links are provided to help readers verify primary documents, market context, and methodology independently.

Related research

C

About the Author: CryptosEyes Research

CryptosEyes Research is the editorial desk behind CryptosEyes, an independent site that tracks public-company crypto exposure with source notes, repeatable calculations, and plain-English risk context. Figures on this site come from company filings, press releases, and market-data providers - never invented - and each article carries source notes so readers can verify claims for themselves.

View Full Research Profile
Reviewed against source notes and calculations
Exchange Risk
Research note: This article is educational market research, not financial advice. Crypto and public equity data can change quickly; see our methodology and editorial policy for sourcing, review, and correction standards.
Important: Educational Purposes OnlyThe data, charts, treasury tracking metrics (including mNAV and SPS), and research provided on CryptosEyes.com are for informational and educational purposes only. They do not constitute certified financial, investment, or trading advice. Digital assets like Bitcoin and Ethereum are highly volatile. Always conduct your own research and consult with a registered financial advisor before making investment decisions.