When customer withdrawals spiked at FTX in early November 2022, they exposed a hole of roughly $8 billion where customer money was supposed to be. The funds had been moved to the affiliated trading firm Alameda Research without authorization or disclosure, and software was used to hide the gap. On November 11, 2022, FTX, Alameda, and more than a hundred affiliated entities filed for bankruptcy in what United States prosecutors later called one of the largest financial frauds in the country's history. In the months that followed, exchanges raced to publish documents reassuring depositors that their funds were safe. Many of those documents were labeled "proof of reserves." This is the first article in a three part series on what that phrase actually means, how a real cryptographic proof works, and why the chain a proof commits to determines how much it is worth.
The Promise and the Gap
The intuition behind proof of reserves is simple and sound. A custodian holding customer assets should be able to show, on demand, that the assets are really there. In traditional finance this assurance comes from a chain of regulated intermediaries, segregated accounts, and audited financial statements. Crypto, where a custodian can hold billions in bearer assets that move in seconds, promised something better: a custodian could point directly at the blockchain and let anyone verify the balances for themselves.
The gap is between that promise and what most published reports deliver. After FTX, the word "proof" was attached to a wide range of documents, many of which were neither proofs in the cryptographic sense nor audits in the accounting sense. For a treasury team or institutional allocator deciding where to place assets, the distinction is not academic. It determines whether the reassurance you are reading actually constrains what the custodian can do with your money.
Attestation, Audit, and Proof Are Three Different Things
It helps to separate three terms that are often used interchangeably. An attestation, more precisely an agreed-upon-procedures engagement, is a report in which an accounting firm performs a specific, limited set of checks that the client requested and reports what it found. The firm does not give an opinion on whether the financial statements are fairly presented. It confirms that, on the procedures it was asked to run, the numbers matched. The scope is defined by the client, not by an auditing standard.
A financial audit is broader. An auditor examines the financial statements as a whole, tests internal controls, and issues a formal opinion on whether the statements present the entity's position fairly. Audits are governed by professional standards and carry far more weight, which is also why few crypto-native exchanges have produced full audited statements.
A cryptographic proof of reserves is different again. It does not depend on a firm's judgment at all. It uses blockchain data and cryptography so that anyone, in principle, can verify two things: that the custodian controls the on-chain assets it claims (proof of assets), and that those assets cover what it owes customers (proof of liabilities). The next article in this series walks through exactly how that machinery works. The point here is that "proof of reserves" in marketing usually refers to an attestation, sometimes wrapped around a partial cryptographic component, and almost never to a full audit or a complete two-sided proof.
How Fragile the Reports Can Be
The fragility became visible quickly. In December 2022, just weeks after FTX, the accounting firm Mazars paused all proof-of-reserves work for crypto clients, including Binance, Crypto.com, and KuCoin, citing concerns about the way the public was interpreting the reports. A document that was meant to rebuild trust was withdrawn precisely because it was being read as more than it was. That episode is the clearest signal that the gap between the label and the substance was real, and that even the firms producing the reports were uncomfortable with how much weight they carried.
Three Structural Weaknesses
Set aside outright fraud and assume a custodian and its accountants are acting in good faith. A reserves report can still mislead because of how the exercise is built.
The first weakness is the liabilities gap. Showing assets is only half of solvency. An exchange is solvent only if its assets are at least equal to what it owes its customers and other creditors. A report that displays a large pile of on-chain assets but does not account for the full set of liabilities, including off-chain loans and obligations, can suggest health while the institution is deeply underwater. Solvency is a statement about both sides of the balance sheet, and many reports only photograph one side.
The second weakness is snapshot gaming. A proof of reserves typically captures balances at a single moment. If the timing is known or the assets are not genuinely the custodian's, an entity can borrow assets shortly before the snapshot, photograph a healthy balance, and return the borrowed funds afterward. Observers in the crypto community have repeatedly raised this concern, noting that platforms can move funds immediately after a snapshot is taken. A single photograph cannot tell you whether the assets were there the day before or the day after.
The third weakness is the control assumption. Signing a message from an address demonstrates that someone can sign with that key at that time. It does not prove that the custodian alone controls the key, that the key was not borrowed for the exercise, or that the same assets are not being claimed by another party. Exclusive, sole control is exactly the property that matters for custody, and a signature does not establish it on its own.
What This Means for Institutions
For an institution, the practical takeaway is to read the label and then read past it. The questions worth asking are concrete. Does the report cover liabilities as well as assets, or only assets? Is it a one-time snapshot or a continuing process? Is it an attestation against client-defined procedures, a full audit, or a verifiable cryptographic proof? Who can independently check it, and with what data? A reassuring headline number that fails these questions is closer to a press release than to evidence.
None of this means proof of reserves is worthless. The underlying idea, that a custodian holding transparent bearer assets should be able to prove backing in a way anyone can verify, is one of the few genuine advantages a blockchain-based system has over the opaque ledgers that failed in 2022. The problem is that the strongest version of the idea is rarely what gets published. The next article in this series shows what the strong version looks like: proof of assets, a Merkle-tree proof of liabilities, and the zero-knowledge upgrades that close the obvious holes. The third article turns to the question that even a perfect proof leaves open, which is whether the ledger underneath the proof can be quietly rewritten.
This article is for informational purposes only and does not constitute investment advice.
Mintlayer Web Services provides Bitcoin-native issuance and settlement infrastructure built so backing can be verified at the base layer, not just asserted in a report. Learn more →