Tech

Proof of reserves, explained: what it proves and what it hides

After FTX, every big exchange started publishing one. Here is what it actually shows, how to check your own balance is in it, and the one thing it can never prove.

In November 2022, FTX looked solvent right up until the week it was not. It held customer deposits, published confident numbers, and had a chief executive the industry treated as a grown-up. Then it turned out the money customers thought was sitting safely on the exchange had been lent, moved, and spent. Billions of dollars of balances were real on the screen and gone in the vault.

The response, within weeks, was an industry-wide scramble to publish something called proof of reserves. It is now a badge you will see on almost every large exchange. It sounds like the answer to exactly what went wrong. It is worth understanding what it really is, because it solves a smaller part of the problem than the name suggests.

Proof of reserves shows you what an exchange holds. It does not show you what it owes.

What proof of reserves actually is

When you keep crypto on an exchange, you do not hold it. The exchange holds it and owes it to you, the same way a bank holds your deposit and owes you the balance. Your account screen is a promise, not the coins themselves. Proof of reserves is an attempt to put evidence behind half of that promise: to show, on the public blockchain, that the exchange really controls the assets it claims to.

A serious proof of reserves has two halves. The first is the reserves themselves: the exchange publishes the wallet addresses it controls, or signs messages proving control, so anyone can open a block explorer and add up the coins actually sitting there. The second is the liabilities side, and this is where the clever part lives.

The Merkle tree, in plain English

To prove what it owes to customers without publishing everyone's private balance, an exchange uses a structure called a Merkle tree. Picture every customer balance as a brick. Each brick is hashed, meaning turned into a short fingerprint that reveals nothing about the number behind it. Pairs of fingerprints are combined and hashed again, and again, until the whole set of customer balances rolls up into a single fingerprint at the top called the Merkle root. Change any one balance anywhere and the root changes.

The exchange publishes that root. Then it lets you, individually, confirm your own balance was baked into it. You never see anyone else's number, and no one sees yours, but the math ties them all together into one total the reserves are supposed to cover.

How to verify your own balanceOn an exchange that publishes Merkle proof of reserves, log in and find the proof or audit page. It will show your account's record ID and a short chain of fingerprints. Paste them into the exchange's verification tool, or an independent one, and it recomputes up to the published root. If it matches, your balance was counted in the snapshot the reserves have to cover. If your exchange offers no way to do this, that absence is itself an answer.

The part the badge does not cover

Here is the trap. Proving you hold assets, and even proving those assets cover the customer balances in the tree, is not the same as proving you are solvent. Solvency is assets minus everything you owe. Proof of reserves usually measures only the first number and only some of the second.

An exchange can pass a proof of reserves and still be underwater, for reasons the snapshot never sees:

It is a photograph, not a video. A proof of reserves captures one moment. An exchange can borrow coins the day before, pose for the picture, and return them the day after. This is not hypothetical; auditors flagged exactly this pattern of borrowed, snapshot-timed funds after 2022, and at least one accounting firm stopped doing crypto reserve reports rather than stand behind them.

It sees on-chain assets, not off-chain debts. The tree covers customer crypto balances. It does not show loans the company took out, guarantees it made, money owed to a sister company, or a hole in its fiat banking. A firm can hold every coin it owes customers and still owe far more to lenders standing ahead of them.

The liabilities can be understated. A dishonest exchange can try to shrink the total it needs to cover by slipping fake negative balances into the tree. Good schemes now use extra cryptographic proofs to rule this out, but a plain Merkle root on its own does not guarantee the total is honest.

A photograph of a full vault tells you nothing about the debts written on the wall you cannot see.

This is why the more complete idea is proof of solvency, which pairs proof of reserves with a real proof of liabilities and, ideally, an independent auditor who checks the whole picture rather than one blockchain snapshot. When you see a reserves badge, the useful question is not "do they have reserves" but "reserves against what, measured when, and checked by whom."

How to read a reserves claim honestly

You do not need to be an accountant to grade one. Four questions get you most of the way:

Can you verify your own balance? A real Merkle proof lets you confirm your account is in the snapshot. A logo that just says "proof of reserves" with nothing to click is marketing.

Are the reserve wallets public? You should be able to see the actual addresses and count the coins yourself on a block explorer, not just read a number the exchange typed.

Is a third party involved, and how often? A one-time attestation from two years ago is weaker than a recurring review by a named, independent firm. Continuous is better than annual; annual is better than never.

Do they show liabilities, not just assets? The exchanges taking this seriously publish both sides and let you see the ratio between them. The ones showing only a big pile of assets are answering an easier question than the one that matters.

If checking claims like these is new to you, our walkthrough on reading a crypto project honestly covers the same instinct applied to a token's contract and supply. And because stablecoins are really just an IOU backed by a reserve, the same reasoning applies to them; we go deeper on that in stablecoins vs volatile coins.

The rule underneath all of it

Proof of reserves is a genuine improvement. Ten years ago the only assurance an exchange offered was the word "trust." Now, on the better platforms, you can independently confirm your balance is counted and the coins exist. That is real, and it is worth choosing platforms that offer it over ones that do not.

But notice what even a perfect proof of reserves does not remove: the exchange is still in the middle, still able to be borrowed against, hacked, frozen, or ordered by a court, and its solvency is still a promise you are trusting between snapshots. The badge lowers the risk. It does not delete it.

Which leads to the oldest rule in crypto, the one FTX taught a fresh generation the hard way. The only balance sheet you never have to take on faith is your own wallet. Coins you hold in self-custody cannot be lent out behind your back, because there is no one in the middle to lend them. That is not the right answer for every dollar, and self-custody carries its own responsibility, but it is the reason the phrase "not your keys, not your coins" survives every cycle.

This posture, evidence over assurance, is the standard worth holding every platform to, including any that Bremo builds. The Bremo token is documented at bremo.tech with its supply and contract public and checkable on-chain, and it states plainly where it is today rather than what it might be worth. Do not take that on faith either. The whole point is that you can go and look.

General technology and financial education, not investment advice. Cryptocurrency is volatile and speculative, and holding assets on any exchange carries counterparty risk regardless of a proof-of-reserves claim. Always verify current details yourself, and never invest more than you can afford to lose.
Keep reading