~/tokens/exchange $ cat proof-of-reserves-kak-chitat.md
Proof-of-reserves: how to read exchange reports and what they don't show
Proof-of-reserves became the standard after November 2022: exchanges publish proof that client assets exist. Useful - but it's important to understand the method's limits.
What the report proves
The classic scheme is a merkle tree of liabilities plus wallet signatures: the exchange shows that (a) the sum of client balances equals X and (b) it controls addresses with assets ≥ X. A user can verify their balance is included in the tree. This honestly proves the presence of assets at the moment of the snapshot.
What the report does NOT prove
- Liabilities in full. Assets are visible, debts are not: the exchange may owe more than it showed (loans, hidden liabilities). Reserves without a full audit of liabilities are half the picture.
- Point in time. A snapshot as of a date: assets can be borrowed for the day of the report and returned afterward.
- Quality of reserves. Reserves in the exchange's own token or in illiquid assets formally "exist," but in practice can't be sold without a crash. The FTT lesson.
- Ownership rights. A wallet signature proves control, but not that the assets aren't pledged as collateral.
How to read it: look at the composition of reserves (share of BTC/ETH/stablecoins versus the exchange's own token), the regularity of reports, the name of the auditor, and most importantly - the ratio of reserves to liabilities for each asset separately. And remember: even a perfect report doesn't override the rule "the exchange is not a vault."