Can You Trust a Centralized Exchange Proof of Reserves Attestation
The FTX collapse is the lesson that keeps on teaching. In November 2022, a centralized exchange claiming billions in assets turned out to have a hole in its balance sheet large enough to swallow customer funds whole. FTX had published attestations. Auditors had signed off. And yet the money was gone. That single event should make anyone suspicious of any exchange claim that cannot be verified independently.
A proof of reserves attestation sounds technical and reassuring. It is neither. Here is what it actually does.
An exchange collects every customer balance. It hashes each one individually. Those hashes are then paired, hashed again, paired again, and hashed again. The process repeats until one single hash remains. That is the Merkle root. The logic is straightforward: if any single customer balance changes, the root changes completely. The exchange publishes this root and invites customers to verify that their own balance is included in the tree.
That is the mechanics. The theory is sound. The practice is where trust breaks down.
What a Merkle proof does not show
A Merkle tree proof confirms that your balance appears somewhere in the exchange's database at a specific moment. It does not confirm that the exchange actually holds those assets. It does not show liabilities. It does not reveal whether the exchange borrowed against customer deposits, lent them out, or simply created fake entries in a database.
FTX had an auditor attestation. The attestation covered Alameda Research's balance sheet. It did not cover the commingled customer funds that had been swept into Alameda's trading book. An attestation is a snapshot. A snapshot captures only what someone chooses to show you at that moment.
A proof of reserves without a corresponding proof of liabilities is incomplete. You are checking that the numbers add up on one side of the ledger. You are not checking that the other side is not negative. An exchange could have $10 billion in customer deposits, but if it also owes $9 billion in off-chain debt to creditors, the net position is not the same as the gross number.
Real-time monitoring: a different game entirely
An auditor's snapshot is dated the moment it is published. Between attestations, anything can happen. This is where on-chain monitoring tools change the calculus.
Platforms such as Arkham, Nansen, and Glassnode track wallet movements in real time. They do not rely on an exchange voluntarily publishing a hash. They watch the blockchain itself. When an exchange says it holds 100,000 Bitcoin, you can check the public addresses it controls and see whether the balance is actually there. You can watch it drain in hours if a run starts.
This is not a substitute for a proper audit. It is a complement. Real-time monitoring catches what attestations miss: the slow bleed, the sudden transfer to an unexplained wallet, the movement of funds that should be sitting still.
The limits of on-chain verification
On-chain monitoring has its own blind spots. An exchange can control wallets you do not know about. It can move funds between addresses to create an illusion of reserves. It can borrow crypto from a market maker, deposit it into a known address, take the snapshot, and return the borrowed funds.
Still, the gap between what an attestation shows and what on-chain analysis reveals is enormous. An attestation is a single point in time. On-chain data is continuous. An attestation is self-reported. On-chain data is public by default.
What you should actually do
Do not treat a proof of reserves attestation as proof of solvency. Treat it as what it is: a statement that someone's database had certain entries at a certain time. Verify it against on-chain wallet watches. Look for exchanges that publish both reserve and liability proofs. Prefer exchanges that submit to regular, third-party audits with real liability disclosure.
If an exchange publishes only a Merkle root and no liability statement, you are looking at half a picture. The other half is the part that sank FTX.
The lesson is not new. It is just expensive. Trust is not something an exchange earns by publishing a hash. It is something it earns by showing you the full ledger, on chain, in real time, with no place to hide. Anything less is an invitation to guess.
And you should not have to guess with your money.
Not financial advice. zebusolana.com publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.