Proof of Reserves
Evidence that a custodian controls specified assets at a point in time.
Proof of Reserves, often shortened to PoR, is a method used by a crypto custodian to show that it controls specified assets at a particular time. It may combine signed wallet ownership, on-chain balances, customer-liability summaries, and third-party procedures. The result is evidence with a defined scope, not automatic proof of solvency or customer protection.
For on-chain assets, a custodian can publish addresses and demonstrate control by signing a message or moving a small amount. Users can verify balances through the blockchain. Customer balances are often placed into a Merkle tree, a cryptographic structure that produces one root value. Each customer can receive a proof that their record was included without seeing every other customer's balance.
This process matters because customers of a centralized platform cannot normally observe how deposited assets are held or used. Transparent wallet balances and inclusion proofs can expose some shortfalls and make unsupported claims harder. Regular reporting also gives users more information than a company's unsupported statement. However, usefulness depends on complete inputs, independent work, and clear definitions.
Proof of Reserves has major limitations. Assets can be borrowed temporarily, pledged elsewhere, or subject to claims not visible on-chain. A report may omit fiat liabilities, loans, expenses, affiliated entities, or negative customer balances. It may not establish legal ownership or whether assets are available for withdrawal. A snapshot also says little about transactions immediately afterward.
The engagement type matters. Agreed-upon procedures report specific factual findings selected for the engagement and do not express an audit opinion. The US Public Company Accounting Oversight Board has cautioned that PoR reports are not audits and may provide no meaningful assurance about sufficient assets to meet customer liabilities. Marketing should not present limited verification as a complete financial-statement audit.
Users should read the full report, identify the provider and standards, check the date, and compare covered reserves with clearly defined liabilities. Verify personal inclusion and independently inspect disclosed wallets, but do not treat either step as proof that the dataset is complete. Stronger assessment also considers audited financial statements where available, custody arrangements, withdrawal performance, governance, internal controls, and legal rights in insolvency.
Frequently asked questions
- A custodian identifies reserve wallets or other assets and may sign messages or transfer funds to demonstrate control. Customer balances can be summarized in a Merkle tree, allowing each user to verify inclusion without publishing every account. An independent provider may perform agreed procedures. Methods differ, so readers must examine the scope, date, assets, liabilities, and verification performed.
- No. A reserve snapshot may omit liabilities, borrowed assets, related-party obligations, legal ownership, internal controls, or events immediately before and after testing. It does not guarantee that customers can withdraw or that the business is solvent. The PCAOB has warned that proof-of-reserve engagements are not audits. Users should seek fuller financial, custody, governance, and regulatory information.
- Use the custodian's official verification tool or open implementation to recreate the Merkle proof from the supplied account record and root. Confirm the snapshot date, balance, asset, and liability sign, while protecting any identifying code. Then verify that the published root matches the report. Inclusion proves only that the submitted dataset contained the record, not that all liabilities were included.
