Proof of Reserves in 2026: What Actually Proves an Exchange Is Solvent
Not every proof of reserves report proves what it claims. Here is how to read one properly in 2026, and what a genuine solvency attestation looks like.

Proof of reserves became a category-defining topic after the 2022 collapses, and by 2026 nearly every major venue publishes some form of attestation. The problem is that "proof of reserves" is not a defined standard — it is a marketing phrase that covers everything from a genuine cryptographic solvency proof to a screenshot of a wallet balance. If you keep meaningful funds on an exchange, or you buy verified accounts on venues you will custody assets with, you need to be able to tell those apart.
What a real proof of reserves proves
A complete proof of reserves has three components. First, proof of assets: the exchange demonstrates on-chain control of a set of addresses holding at least the total balance of customer deposits. Second, proof of liabilities: the exchange publishes a cryptographic commitment (typically a Merkle tree) of every customer's balance, such that the sum of all leaves equals the claimed total liabilities. Third, an independent attestation that ties the two together at a specific point in time.
Any report missing any of these three components is not proof of solvency. Proof of assets alone tells you the exchange has coins but not whether it has enough. Proof of liabilities alone tells you the sum of customer balances but not whether the exchange can pay them. A screenshot of a dashboard proves nothing.
Merkle tree liabilities, done right
The liability side is where most reports fall short. A properly constructed Merkle tree lets every individual customer verify that their own balance is included in the total, without revealing other customers' balances. When you log in, you get your leaf hash and the sibling hashes needed to reconstruct the root. You hash your way up and confirm the root matches the exchange's published root.
Check two things. First, that the tree actually commits to non-negative balances — early implementations were vulnerable to exchanges inserting negative-balance leaves to reduce the apparent liability total. Modern implementations use zero-knowledge range proofs to prevent this. Second, that the tree includes all liability types, not just spot balances. Perpetual futures collateral, unrealized PnL, staked balances, and locked promotional balances all need to be in the tree or the total is understated.
Proof of assets: address control and freshness
The asset side has two failure modes. The first is asset borrowing: an exchange rents Bitcoin from another entity for the moment of the snapshot, publishes the snapshot, and returns the coins. Any credible attestation now requires signed messages from the addresses at multiple points in time, not just one, plus verification that the balances have not moved to different addresses immediately after the snapshot.
The second failure mode is address commingling. If the exchange proves control of addresses that also hold third-party assets (custody customers, treasury holdings, market-maker inventory), the proof of assets overstates what actually backs retail deposits. Any credible report identifies which addresses are exclusively customer-deposit-backing and excludes commingled addresses from the total.
Attestation vs audit
Almost every 2026 proof of reserves report is an "attestation," not an "audit." Attestations are opinions on a specific procedure at a specific moment — much cheaper and faster than audits, and much narrower in scope. A full audit tests internal controls, evaluates going-concern risk, examines related-party transactions, and stands behind an opinion on the entity's overall financial position. A proof of reserves attestation confirms only that the numbers on this page match what the attester procedures found on this day.
That is not necessarily bad — a well-scoped attestation from a reputable firm is genuinely useful. But do not read "attested by [Big 4 firm]" as equivalent to "audited by [Big 4 firm]." Read the actual attestation letter to see what was in scope and what was explicitly excluded. Off-balance-sheet liabilities, related-party loans, and derivative exposure are commonly excluded, and those are exactly where solvency risk actually lives.
What to look for in the report
Read the attestation letter, not the press release. Confirm the date is recent (quarterly at minimum; monthly is better). Confirm the attester is a real accounting firm with a checkable license, not a "blockchain audit" boutique with no standing. Confirm the report lists which assets are covered — many exchanges publish proofs for BTC and ETH only and quietly omit stablecoin liabilities, which are typically the largest single balance category on any modern venue.
Check that customer verification tooling actually works. Log in, generate your proof, hash it up to the root, confirm it matches the published root. If the tool is broken, unavailable, or produces a root that does not match, treat that as a red flag independent of what the marketing page claims.
What's missing even from good reports
Even a properly-constructed proof of reserves does not prove solvency in the going-concern sense. It does not tell you whether the exchange has hedged its market-maker positions correctly. It does not disclose the credit exposure to affiliated entities. It does not reveal loans made against the exchange's own token as collateral. Those are the exposures that took down FTX, and no snapshot-based proof will catch them. Use proof of reserves as one input, not the only input.
What to do about it as a user
Diversify custody. Do not keep more on a single exchange than you would tolerate losing to that exchange's operational or fraud risk. Move idle funds to self-custody on a hardware wallet. For balances that must live on an exchange (active trading capital, staking positions with lockups, promotional balances), prefer venues that publish proof-of-reserves reports on a monthly cadence with a reputable attester, and prefer venues in jurisdictions with meaningful segregation-of-customer-funds regulation (EU MiCA-compliant venues, UAE VARA-regulated venues, some US state trust charters).
Why this matters for account buyers
Buying a verified account on a venue with weak proof of reserves inherits that venue's solvency risk. When we curate exchange listings on KYC Marts, we weight jurisdictional strength and attestation quality alongside KYC depth. A Tier 3 account on a venue with monthly attestations from a top-tier accounting firm is a materially safer purchase than a Tier 3 account on a venue whose "proof of reserves" is a wallet balance screenshot. The verified account itself is only as valuable as the venue behind it.
The reader's checklist
Before you keep balance on any exchange in 2026: is there a proof of reserves report dated within the last 90 days? Is it attested by a licensed accounting firm? Does it cover all assets you hold, not just BTC and ETH? Can you personally verify your leaf in the Merkle tree? Are the addresses in the asset proof exclusively customer-backing? If any answer is no, either reduce your balance on that venue or pick a different venue. The cost of that discipline is low; the cost of skipping it is, occasionally, everything.
Ready to buy or sell on KYC Marts?
Browse verified listings or contact us on WhatsApp at +44 7474 711525 or Telegram @verifiedmarts to confirm an order.