How to tell a real audit from a proof-of-reserves screenshot
A proof-of-reserves post and an audit look similar but prove different things. Here's how to check which one an exchange actually gave you.
A crypto exchange or lending platform posts a chart, a Merkle tree link, or a PDF with a Big Four-adjacent logo and calls it "audited." Before you move funds based on that post, it's worth knowing that "proof-of-reserves" and "audit" are not interchangeable words. One tells you a company holds some coins on a given day. The other tells you whether its books are honest. Most collapses in this industry involved companies that had done the first and never the second.
What does proof-of-reserves actually prove
Proof-of-reserves (PoR) is a snapshot. A firm signs a message from wallets it controls, or publishes a Merkle tree so users can check their balance is included, and totals it up against on-chain holdings. Kraken's PoR writeup is a decent example of the mechanics: it shows assets exist at that moment, and it can show that your specific balance was counted in the total.
What it does not show is liabilities. PoR checks the asset side of the ledger, not what the company owes. FTX could have produced a wallet signature the week before it collapsed, because it briefly held customer coins before lending them to Alameda. A snapshot photo of a full vault says nothing about the loan against the vault that's due Tuesday. PoR also says nothing about off-chain IOUs, rehypothecated collateral, or assets held at a sister company that could vanish in a related-party transaction.
What does a real audit check that a snapshot doesn't
A financial statement audit, the kind governed by AICPA or PCAOB standards, examines both sides: assets, liabilities, and the relationship between them over a period of time, not one instant. An auditor tests internal controls, samples transactions, confirms bank and custody balances directly with third parties, and issues an opinion on whether the statements are "fairly presented," with a name and a firm's legal liability attached to that opinion.
The gap matters because most exchanges that publish PoR explicitly do not get an audit opinion on it. Binance's own 2022 PoR report, produced with Mazars, was labeled an "Agreed-Upon Procedures" (AUP) engagement, not an audit. Mazars said as much in the fine print and then stopped doing crypto AUP work entirely for all its clients in December 2022, citing "concerns regarding the way these reports are understood by the public." That single sentence from an accounting firm is the clearest signal in the entire industry: even the firms writing these reports don't want them read as audits.
Why don't more exchanges just get audited
Two real reasons. First, a full audit requires disclosing liabilities, corporate structure, and related-party loans, exactly the information exchanges have historically preferred to keep opaque. Second, audit firms have gotten cautious about crypto clients since 2022; the risk of reputational damage from a client blowing up mid-engagement, as happened to several firms tied to FTX and Celsius, outweighs the fee for many mid-size accounting shops. So "we can't find an auditor who will take us" is sometimes true, and sometimes a convenient excuse.
What should you actually check before trusting the claim
Look for four things in the actual document, not the press release. First, the report's title: does it say "audit," "audit opinion," or "agreed-upon procedures"? AUP reports describe steps taken, not a conclusion about accuracy. Second, does it name a licensed audit firm and an opinion date, or just "a leading accounting firm" with no signature. Third, does the report cover liabilities and off-balance-sheet obligations, or only asset addresses. Fourth, is it recurring. A single PoR snapshot from 14 months ago tells you nothing about today's balance sheet; reputable ongoing disclosures come quarterly at minimum.
If an exchange can't produce a dated, named, liabilities-inclusive audit opinion and instead points you to a Merkle tree tool, treat that as useful but partial information; it rules out one failure mode (assets don't exist at all) while leaving the more common one (assets don't cover liabilities) completely unaddressed.
