How Proof of Reserves Should Work for Crypto Platforms
Proof of Reserves can improve transparency for crypto platforms, but only when assets, customer liabilities, wallet ownership, verification methods, and reporting limitations are addressed together.
Key takeaways
- Proof of Reserves should verify customer liabilities as well as on-chain assets.
- Merkle trees can help users confirm balance inclusion without exposing other customer records.
- Independent attestations are useful, but they are not the same as full financial audits.
- Snapshot reports should be supported by frequent updates, strong controls, and clear disclosures.
- Proof of Reserves improves transparency but does not independently prove solvency.
What Is Proof of Reserves?
Proof of Reserves is a verification method through which a crypto platform demonstrates that it controls identifiable assets associated with customer deposits. A credible process normally combines publicly visible blockchain balances with a structured calculation of customer liabilities, allowing users or independent reviewers to compare what the platform holds with what it owes.
Blockchain networks make certain asset balances publicly observable. When a platform identifies its reserve wallet addresses, users can usually inspect the assets held at those addresses through the relevant blockchain.
That visibility addresses only one part of the process. A wallet may contain substantial assets, but the public blockchain does not automatically reveal how much the platform owes its customers.
For that reason, a meaningful PoR exercise should answer two separate questions:
- Does the platform control the reported digital assets?
- Are those assets sufficient to support the customer balances included in the verification?
The second question requires a reliable liability calculation. Without it, customers are being shown assets without the information needed to assess whether those assets are adequate.
Why Do Crypto Platforms Need Proof of Reserves?
Crypto platforms need Proof of Reserves because customers often transfer control of their assets to a third party. Once assets are held in custodial wallets, users may have limited visibility over how those assets are stored, transferred, pledged, lent, or otherwise used. PoR can provide additional evidence beyond a platform’s own statements.
For a platform, a well-designed PoR process can support:
- Greater transparency over reserve holdings
- Independent inspection of disclosed wallet balances
- Customer verification of balance inclusion
- More disciplined asset and liability reconciliation
- Better internal reporting and documentation
- Clearer communication during periods of market stress
The process can also help management identify weaknesses in wallet records, reconciliation procedures, customer ledger data, or reporting responsibilities.
In practice, PoR should be treated as part of the platform’s wider financial control environment. It does not replace accounting records, risk management, cybersecurity, governance, or liquidity planning.
Proof of Reserves is most useful when it is treated as an ongoing control process rather than a one-time transparency announcement. — Consulting Journal observation
How Should Proof of Reserves Work?
An effective Proof of Reserves process should connect customer account records with verifiable reserve assets at a defined reporting time. The platform should calculate customer liabilities, protect confidential data, prove control of reserve wallets, and provide sufficient information for users or independent reviewers to test the published result.
1. Record customer balances at a defined time
The platform begins by taking a snapshot of customer balances at a specific date and time.
These balances represent amounts owed to customers. Depending on the platform’s services, the calculation may need to cover spot balances, pending withdrawals, accrued rewards, staking arrangements, margin accounts, or other customer entitlements.
The reporting scope should be clearly explained. Customers should be able to understand which products, entities, accounts, and assets are included or excluded.
A poorly defined snapshot can create a misleading result even when the mathematical calculation is correct.
2. Build a reliable liability record
Customer balances should be reconciled to the platform’s internal ledger and accounting records.
The platform should also consider whether balances can become negative. If negative balances are deducted from total liabilities without a valid basis, the reported obligation may appear lower than the amount the platform would realistically need to satisfy customer withdrawals.
Finance and Accounting teams should review how customer balances are classified, converted, grouped, and reconciled before they are included in the PoR calculation.
3. Use a Merkle tree for customer verification
A Merkle tree is a cryptographic structure that combines multiple records into a single summary known as a Merkle root.
In a PoR process, individual customer balances can be converted into hashed records. Those records are then combined through several layers until one root value represents the full dataset.
The customer can receive an inclusion proof that allows them to confirm that their record formed part of the liability calculation. Other customer balances do not need to be disclosed.
This approach can support privacy and efficient verification. However, its reliability still depends on the completeness and accuracy of the underlying data.
A technically correct Merkle tree cannot identify customer accounts that management excluded before creating the dataset.
4. Prove control of reserve wallets
Publishing a wallet address shows that assets exist at that address. It does not automatically prove that the reporting platform controls the wallet.
The platform should therefore provide evidence of ownership or control. This may involve signing a verification message with the relevant private key or completing another recognised control procedure.
The process should also identify whether assets are held directly, with third-party custodians, across multiple legal entities, or through arrangements that restrict their use.
5. Compare reserves with included liabilities
The platform should compare the value and quantity of verified assets with the corresponding customer liabilities.
Ideally, the comparison should be completed asset by asset. A platform should not assume that a surplus in one highly volatile or illiquid token can always compensate for a shortage in another asset customers expect to withdraw.
Where valuation is necessary, the report should explain the pricing source, valuation time, conversion method, and treatment of market movements.
6. Obtain independent verification
An external accounting firm, assurance provider, or specialist verification business may be engaged to test parts of the PoR process.
The reviewer may examine:
- Wallet ownership evidence
- Reserve balances at the reporting time
- Customer liability calculations
- Merkle tree construction
- Reconciliation procedures
- Exceptions identified during testing
- Management representations
- Scope limitations
The resulting report should clearly describe what was tested. An agreed-upon procedures engagement, attestation, and full financial statement audit are different services and should not be presented as interchangeable.
What Should a Credible Proof of Reserves Report Include?
A credible report should provide enough information for readers to understand the result, the verification process, and the areas not covered. It should identify the reporting entity, snapshot time, included assets, customer liabilities, wallet-control method, independent reviewer, verification scope, calculation methodology, exceptions, and significant limitations.
At a minimum, businesses should consider publishing:
- The legal entity or group covered by the report
- The date and exact time of the snapshot
- The digital assets included
- The disclosed reserve wallet addresses
- The method used to prove wallet control
- The total customer liabilities for each included asset
- The method used to construct liability proofs
- Instructions for customer balance verification
- The identity and role of any independent reviewer
- Material exclusions and methodology limitations
- The date of the previous and next expected update
Platforms should also archive previous reports. Historical reports help users assess whether transparency is consistent or only provided after market pressure.
Why Are Merkle Trees Important?
Merkle trees allow large customer datasets to be represented through a single cryptographic root while giving individual users a way to verify inclusion. They can reduce the need to publish identifiable account information, but they do not independently confirm that every liability was included or that the original records were accurate.
The customer verification process should be simple enough for non-technical users to follow. A platform may provide a verification tool, reference code, or clear instructions explaining how the user’s balance connects to the published Merkle root.
Technical accessibility matters. A verification feature has limited practical value when customers cannot locate it, understand it, or independently reproduce the result.
Platforms should also explain how they protect users from balance disclosure. Even when names are removed, poorly designed records may expose account details through predictable identifiers or weak hashing practices.
What Are the Main Limitations of Proof of Reserves?
Proof of Reserves normally confirms specified assets and customer liabilities at a particular point in time. It may not reveal borrowing, secured obligations, related-party transactions, operational losses, legal claims, liquidity restrictions, or assets moved shortly before the reporting date. It should therefore not be treated as a complete assessment of financial health.
It may provide only a temporary snapshot
A platform can hold sufficient reserves at the reporting time and move those assets later.
Frequent reporting can reduce this risk but may not eliminate it. Near real-time reporting can improve visibility, although the underlying liability data and wallet ownership must remain accurate.
It may exclude important obligations
Basic PoR reports often focus on customer deposits. The platform may also have loans, supplier balances, tax obligations, employee costs, derivatives exposure, legal claims, or amounts owed to related companies.
These obligations affect solvency even when customer assets appear fully backed.
Assets may be borrowed or restricted
Assets could be temporarily obtained before a snapshot. They may also be pledged as collateral, subject to custody restrictions, locked in protocols, or unavailable for immediate withdrawal processing.
The report should distinguish between assets that exist and assets that are freely available to meet customer claims.
It does not assess operating quality
Proof of Reserves does not normally evaluate cybersecurity, governance, internal controls, management conduct, private-key security, financial forecasting, or operational continuity.
A platform can pass a limited reserve verification while still having serious weaknesses in other areas.
Is Proof of Reserves the Same as Proof of Solvency?
No. Proof of Reserves focuses primarily on identifiable assets supporting customer balances. Proof of solvency requires a wider assessment of whether the business’s total assets are sufficient to meet all recognised liabilities. Solvency analysis may therefore require financial statements, complete liability records, valuation work, and broader independent assurance.
A business may show that customer deposits are supported while still facing unpaid operating expenses, debt, legal obligations, or liquidity problems.
Solvency also considers whether assets are realisable. A platform may own an asset with a high reported value, but that asset may be difficult to sell without creating a significant price decline.
PoR is therefore better viewed as one source of evidence within a broader financial assessment.
Example 1: A Dubai Crypto Custodian Preparing Its First PoR Report
A fictional Dubai-based custodian holds Bitcoin and stablecoins for corporate customers. Management initially plans to publish the balances of three reserve wallets.
During preparation, the finance team discovers that the customer ledger includes pending withdrawals and accrued service rebates that were not included in the first liability calculation.
The business pauses publication, reconciles the records, documents the scope, and adds customer verification through a Merkle tree.
The revised report is more useful because it connects disclosed assets with a clearly defined customer obligation rather than showing wallet balances in isolation.
Example 2: A UAE Trading Platform With Restricted Assets
A fictional UAE trading platform reports that its total crypto assets exceed included customer balances.
Further review shows that part of the reserve is pledged under a financing arrangement and another portion is locked for a fixed period.
Although the assets exist, they may not be immediately available to meet customer withdrawals.
The platform updates its disclosure to separate unrestricted reserves from encumbered assets. This gives users a more accurate view of liquidity and reduces the risk of an overly favourable interpretation.
What Common Mistakes Do Crypto Platforms Make?
Common PoR mistakes usually arise from incomplete scope, unclear reporting, weak reconciliation, or presenting a limited verification as broader assurance than it actually provides.
Businesses should avoid:
- Publishing reserve wallets without customer liabilities
- Failing to prove control of disclosed addresses
- Excluding certain customer products without explanation
- Netting negative balances against liabilities without adequate justification
- Using inconsistent valuation methods
- Treating illiquid tokens as equivalent to withdrawal-ready assets
- Ignoring pending withdrawals or customer rewards
- Publishing a report without a clear snapshot time
- Describing an attestation as a full financial audit
- Failing to explain restrictions, pledges, or collateral arrangements
- Using technical language without customer verification instructions
- Publishing one report and providing no later update
A transparency exercise can damage confidence when the methodology is vague or later found to be incomplete.
What Documents Should a Platform Prepare?
Before starting a Proof of Reserves engagement, the business should organise the records required to support both reserve assets and customer liabilities.
A practical preparation checklist may include:
- Complete list of reserve wallet addresses
- Evidence of wallet ownership or control
- Custodian statements and custody agreements
- Customer balance reports
- General ledger and sub-ledger extracts
- Asset-by-asset reconciliation schedules
- Pending deposit and withdrawal reports
- Staking, lending, and reward records
- Margin and negative-balance reports
- Details of pledged, borrowed, or restricted assets
- Related-party wallet records
- Asset valuation methodology
- Snapshot date and time documentation
- Merkle tree calculation files
- Customer inclusion-proof procedures
- Previous PoR reports and identified exceptions
- Internal approval and sign-off records
- Independent reviewer engagement terms
The business should also identify the individuals responsible for wallet operations, customer records, accounting reconciliation, technology, compliance, and external communication.
How Can KPM Global Services UAE Assist?
KPM Global Services UAE can support crypto businesses with the financial preparation and control work that typically sits around a Proof of Reserves exercise.
Depending on the platform’s activities and reporting requirements, support may include:
- Reviewing customer liability reconciliation procedures
- Mapping platform records to Accounting ledgers
- Preparing asset and liability schedules
- Identifying documentation gaps
- Reviewing the treatment of pending transactions
- Assessing the classification of restricted assets
- Supporting month-end and reporting controls
- Improving management reporting
- Preparing records for external accountants or verification providers
- Documenting financial processes and responsibilities
- Supporting broader audit and financial reporting readiness
Proof of Reserves is partly a technical process, but reliable results depend heavily on accurate books, complete customer records, clear ownership documentation, and consistent reconciliation.
KPM Global Services UAE does not guarantee a particular attestation, audit opinion, regulatory outcome, or acceptance by any authority. The appropriate scope will depend on the platform’s structure, services, legal entities, asset arrangements, and reporting objectives.
Final Advisory
Proof of Reserves can improve transparency when it verifies both sides of the customer relationship: what the platform controls and what it owes.
The strongest frameworks combine on-chain evidence, complete liability records, customer inclusion proofs, independent procedures, frequent updates, and clear limitations.
Business owners and investors should remain cautious when a platform publishes reserves without explaining liabilities, ownership, restrictions, or reporting scope. A large wallet balance is evidence of assets, but it is not by itself evidence of solvency, liquidity, governance quality, or operational safety.
For crypto platforms, the practical objective should be to build a repeatable reporting process supported by reliable Financial and Accounting records. That approach is more credible than treating PoR as a one-off communication exercise.
This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.
Questions and answers
Q: What does Proof of Reserves prove?
A: Proof of Reserves provides evidence that a crypto platform controls specified assets at a defined reporting time. A robust process also compares those assets with included customer liabilities, but it does not independently prove the platform’s overall solvency.
Q: Can Proof of Reserves guarantee that customer funds are safe?
A: No. PoR can improve transparency, but it does not eliminate cybersecurity, fraud, governance, liquidity, legal, or market risks. Users should review the methodology and wider financial information before relying on the result.
Q: Why are Merkle trees used in Proof of Reserves?
A: Merkle trees allow customers to confirm that their balances were included in a liability dataset without publishing every customer’s account information. Their reliability still depends on whether the platform included complete and accurate records.
Q: Is a Proof of Reserves attestation the same as a financial audit?
A: No. A PoR attestation or agreed-upon procedures report usually examines a limited set of reserve and liability information. A financial audit covers a broader scope and follows a separate professional reporting framework.
Q: How often should a crypto platform update its Proof of Reserves?
A: More frequent updates generally provide better visibility than a single annual or irregular snapshot. The appropriate frequency depends on the platform’s transaction volume, systems, asset movements, customer risk, and ability to maintain accurate liability records.
More in Crypto
View all Crypto →
UAE Stablecoin Rules Explained for Payment Businesses
The UAE regulates stablecoin payment activities through a dedicated CBUAE framework. Payment firms, issuers, wallets and merchants should assess licensing, governance and compliance obligations before launching services.

Why Crypto Regulation Will Make Digital Assets More Serious
Crypto regulation is pushing digital assets from hype toward maturity. For UAE founders, investors, and finance teams, the next phase is about licensing, controls, transparency, and serious market discipline.

Common Legal Risks in Crypto Business Models in the UAE
Crypto founders in the UAE must manage licensing, AML, token classification, tax records, disclosures, custody, data protection, and cross-border risk before scaling.