Security · Reviewed Aug 19, 2026 · 7 min read
Proof of Reserves: What It Proves, What It Hides
Merkle-tree attestations show an exchange holds coins. They say nothing about who else is owed them.
Reviewed by CryptoExID Editorial · Aug 19, 2026 · Editorial policy · how we make money
Why proof of reserves exists at all
Before November 2022, almost nobody asked exchanges to prove they held customer coins. Then FTX collapsed and it turned out billions in customer assets had quietly left the building. Within weeks, Binance, Kraken, OKX, Bybit and most other large venues rushed out proof-of-reserves pages. That timing tells you something: PoR is a trust product born from a trust crisis, not a regulatory requirement.
We treat proof of reserves as a meaningful positive signal in our scoring. Binance, Kraken, Bybit, OKX, Bitget, KuCoin and Gate.io all publish it, and our safest-exchanges ranking adds an explicit bonus for it. But we score it as one input among many, because of what it structurally cannot show.
How a Merkle-tree attestation works
The mechanics are simple. The exchange takes a snapshot of every customer balance, hashes each one, and combines the hashes pairwise into a tree until a single root hash remains. That root gets published. You can take your own account, hash your balance, and verify your leaf rolls up into the published root. If it does, your balance was included in the snapshot.
On the asset side, the exchange signs messages from its wallets or moves a token amount to prove it controls the addresses. An outside firm then compares the on-chain assets to the Merkle root of liabilities and states whether assets cover customer balances at that moment.
What it actually proves
A well-run PoR proves two narrow things. First, that at one point in time the exchange controlled wallets holding at least as much of each asset as customers were owed. Second, that your specific balance was counted in the liability total, assuming you bother to verify your leaf. Almost nobody does, which weakens the whole exercise, but the option exists.
That is genuinely useful. It would have caught FTX, whose problem was not hidden hacking but assets that simply were not there. When Kraken or OKX publishes a reserve ratio above 100% asset by asset, the most basic form of fraud gets harder to run.
What it hides
The liability side is the weak point. An attestation shows the balances the exchange chose to include in the snapshot. It cannot prove no accounts were left out. If an exchange excluded its ten largest creditors from the tree, the ratio would look great and the verification would still pass for every customer who checked.
PoR also says nothing about debts. An exchange can hold every customer coin and simultaneously owe a billion dollars to lenders with a claim on those same wallets. Coins can be borrowed for the snapshot date and returned the next morning. And a point-in-time snapshot from last quarter tells you nothing about today.
Attestation versus audit
The firms that sign PoR reports are careful to call them attestations or agreed-upon procedures, not audits. The difference matters. In an audit, the accountant forms an independent opinion on complete financial statements, tests internal controls, and takes on liability for the conclusion. In an attestation, the firm confirms a narrow calculation the exchange defined, using data the exchange supplied.
Several accounting firms have publicly walked away from crypto attestation work precisely because clients marketed the reports as audits. When an exchange homepage says audited proof of reserves, we read the underlying report. In almost every case the fine print says otherwise.
How we score it
Our base ranking weighs Security at 20% and Regulation at 18%. On the safest-exchanges page those rise to roughly 30% and 28%, plus a bonus for publishing proof of reserves, a never-hacked history and insurance coverage. PoR earns part of that bonus, not all of it, because an attestation without a clean incident record is a press release, not protection.
We are honest about our limits too. We score from public attestations and incident history. We cannot see internal key management, off-chain liabilities or corporate loans. Nobody outside the exchange can, and any rating site claiming otherwise is guessing.
FAQ
Is proof of reserves the same as an audit?
No. An audit is an independent opinion on complete financial statements including liabilities and controls. A PoR attestation only confirms a narrow asset-versus-snapshot calculation defined by the exchange itself. The signing firms explicitly disclaim audit status.
Which exchanges publish proof of reserves?
In our dataset Binance, Kraken, Bybit, OKX, Bitget, KuCoin and Gate.io all publish regular PoR reports. Kraken has run a formal program since 2014, longer than most.
Can proof of reserves be faked?
The asset side is hard to fake outright, but coins can be borrowed for the snapshot date, and the liability tree can quietly omit accounts. That is why we treat PoR as one signal, not a guarantee.
Should I verify my own balance in the Merkle tree?
Yes, if your exchange offers a self-verification tool. It takes a few minutes and confirms your balance was actually counted. The system only deters fraud if enough users check.
Does proof of reserves show whether an exchange has debts?
No. An exchange can hold every customer coin while owing large sums to outside lenders. PoR covers assets against customer balances at one moment and is silent on everything else.