Contents Lesson 8 of 16

5 min read · professional

Why is proof of reserves weaker than it sounds?

After FTX, exchanges began publishing "proof of reserves." The phrase sounds like a solution to the problem the previous two lessons described. It is a partial answer to half of the question, and knowing which half is the entire skill.

Solvency has two sides

Solvency means assets ≥ liabilities. Almost every published proof addresses the assets and waves at the liabilities.

The standard construction has two parts:

  • Reserves. The exchange publishes the addresses it controls and demonstrates control — by signing a message with each key, or by moving a specified amount. Anyone can then read the balances on chain.
  • Liabilities. Customer balances are arranged into a Merkle tree; the exchange publishes the root hash and gives each customer a proof that their own balance is included. A customer can verify their leaf without seeing anyone else's.

It is genuinely clever. It is also defeatable in at least five specific ways.

The five gaps

1. Liabilities are self-declared. Nothing in the scheme prevents the exchange from leaving accounts out of the tree. Omitting customers reduces the claimed liabilities directly. Detection depends on the omitted customers checking their own inclusion — and in practice almost nobody does. A naive sum can also be gamed with negative-balance leaves, which is why stronger designs use a Merkle sum tree together with a zero-knowledge proof that every balance is non-negative. Most published proofs do not go that far, and the ones that do should say so explicitly.

2. It is a snapshot. The proof describes one moment. Assets can be borrowed before the snapshot and returned after it. Two entities can even display the same coins on different dates. A single dated attestation says nothing about the day before or the day after.

3. Control is not ownership. A signature proves the signer can spend. It does not prove the coins are unencumbered — they may be borrowed, pledged as collateral, or subject to somebody else's claim.

4. Off-chain liabilities are invisible. Loans, bonds, obligations to non-customer counterparties, related-party debts, judgments and pending settlements appear nowhere in the tree and nowhere on the chain.

5. It says nothing about controls. Reserves can match liabilities on Tuesday and leave the building on Thursday, if the operational controls permit it. Every failure in this unit was a controls failure before it was a balance-sheet failure.

Read the assurance wording

There is a second, quieter question: who checked? Several exchange publications in 2022 were agreed-upon procedures reports rather than audits. In an AUP engagement the firm performs exactly the procedures the client specified and reports what it found — and expressly issues no opinion. That is a materially different document from an audit, and the distinction is visible in the report's own language. One prominent accounting firm paused its crypto assurance work in December 2022 shortly after producing such a report for a large exchange.

A worked example

An exchange publishes addresses holding 130,000 BTC, and a Merkle root summing to 125,000 BTC of customer balances. Headline: a 104% reserve ratio.

Every one of the following is fully consistent with that publication:

  • 20,000 BTC were borrowed for 48 hours around the snapshot date.
  • 40,000 BTC of customer balances were never placed in the tree.
  • A $900m off-chain loan is secured against the same coins.

None of these requires the published numbers to be false. They are simply outside what the proof proves.

What a stronger version looks like

Liabilities attested by an auditor with access to the internal ledger; a proof-of-liabilities scheme with cryptographic non-negativity; frequent and unannounced snapshots rather than a scheduled one; explicit disclosure of encumbrances and off-chain obligations; and separately from all of it, a clear legal answer about client-asset segregation. Some platforms do several of these. The point is not that proof of reserves is worthless — it is that it answers one question, and you should know which.

Try it now

  1. Take any published proof of reserves and answer three questions in three lines: does it include liabilities, who verified them, and on what date? Most reports answer fewer than three.
  2. If you hold assets on a platform that publishes one, actually verify your own account's inclusion in the Merkle tree. The scheme's security depends on customers checking, and it degrades to nothing if they do not.
  3. Search the document for the words "audit," "opinion" and "agreed-upon procedures," and note which appear. The difference between those terms is the entire assurance question, and it is usually decided in one sentence.