Proof of Reserves (PoR) gives crypto exchange users evidence of the assets an exchange holds and the customer liabilities those assets are intended to cover.
On CoinGecko, just 79 of 166 exchanges have verified reserves. This means that users of more than half of these exchanges do not have evidence that the exchange has sufficient reserves to cover its liabilities in the event of mass withdrawals.
In this article, we explain what PoR verification is, why exchanges use it, and how to verify whether an exchange has sufficient reserves to cover customer liabilities, including how to check your personal balance using a Merkle tree.
What Is Proof of Reserves?
Proof of Reserves (PoR) is a method of verifying an exchange's assets and comparing them with its customer liabilities. An independent assessor checks the assets reported by the exchange, verifies control of the relevant wallets, and reviews the liabilities included in the assessment.
The purpose is to provide evidence that the exchange holds enough assets to cover the customer liabilities included in the scope of the assessment.
Since 2019, CoinGecko has developed and introduced Trust Score to users as a more reliable and multi-dimensional measure of an exchange's quality. The Trust Score methodology goes beyond reported volume to consider a comprehensive set of components, including liquidity, cybersecurity, and more, to arrive at an overall score for an exchange.
How Proof of Reserves Works
PoR combines two types of evidence: proof of assets and proof of liabilities.
For liabilities, an exchange can use a Merkle tree. Customer balances are converted into cryptographic hashes and combined into a tree. The final hash, called the Merkle root, acts as a fingerprint of the reported balances at the time of the assessment.
A customer can receive a Merkle proof containing the hashes needed to verify that their balance is included in that tree. This allows the customer to verify inclusion without exposing every customer's balance.
For assets, the assessor verifies that the exchange controls the reported blockchain addresses. This can involve cryptographic signatures or transactions requested by the assessor. The assessor then compares the verified assets with the customer liabilities included in the assessment.
The result is a point-in-time comparison between assets and liabilities. It does not establish the exchange's financial position in every respect.
A useful PoR should let you answer two questions:
- What assets does the exchange control?
- Do those assets cover its customer liabilities?
For example:
- Reserves: $500 million
- Customer liabilities: $450 million
- Reserve coverage: 111%
This means an exchange has enough assets to cover all existing customer liabilities.
How to Verify CEX Reserves
We demonstrate the process using the KuCoin Proof of Reserves verification report, published on August 10, 2026.
1. What Assets Are Included in PoR?
Every PoR has a defined scope, so you should check which assets and networks were included.
The KuCoin assessment covered BTC, ETH, USDT, and USDC across 38 networks, including Bitcoin, Ethereum, Tron, Solana, BSC, Arbitrum, Base, and TON.

Why are only four assets reviewed? A PoR assessment is performed against a defined scope. The exchange and assessor determine which assets and networks are included in the verification. The four assets covered by the KuCoin assessment represent only part of the assets traded on the exchange. The result therefore does not verify every asset or the exchange's complete financial position.
2. Does the Exchange Control the Wallets?
Another important part of reserve verification is ensuring that the wallets in scope are controlled by the exchange.
Look for evidence of control - this can include cryptographic signatures, on-chain transactions requested by the assessor, or another method that demonstrates the exchange can access the reported funds.
For the KuCoin assessment, the exchange provided public keys and wallet addresses for the assets in scope. KuCoin then initiated small outgoing transactions from the reported addresses using amounts specified by Hacken. Hacken then monitored the relevant blockchains and confirmed that the transactions originated from the expected addresses.
You may also encounter other ownership verification methodologies. One common method is signature verification, where the exchange signs a predefined message using the private key associated with the reported wallet address. The assessor then verifies the signature against the corresponding public key, providing evidence that the exchange controls the private key without requiring it to transfer any funds or reveal private key.

3. What Customer Liabilities Are Included?
A PoR should state which customer liabilities it measures. Some assessments cover spot balances only. Others may include margin positions, lending balances, or staked assets. The liability scope directly affects the coverage calculation:
Reserve coverage = verified reserves ÷ verified customer liabilities
An exchange that publishes wallet balances without corresponding customer liabilities is not giving users enough information to calculate coverage and determine whether it can cover those liabilities.
For the KuCoin assessment, Hacken received a liabilities report covering client balances greater than 0.00000000 for the four in-scope assets. For the reserves report, KuCoin provided aggregated liability data rather than individual account details.
This protects customer privacy while limiting the assessor's ability to connect an individual balance to a specific account.
4. What Is the Reserve Coverage?
There are two main approaches to Proof of Reserves: 1:1 reserve backing and overall customer-liability coverage.
With 1:1 reserve backing, each asset held by customers is matched by an equal or greater amount of the same asset in the exchange's reserves. For example, if customers collectively hold 1,000 BTC, the exchange should hold at least 1,000 BTC in verified reserves. This approach provides direct coverage for each asset and is generally considered the stronger model from a risk-management perspective. Some regulatory frameworks also emphasize or require asset-level backing.
The more common approach is to assess whether the exchange's total reserves cover its total customer liabilities. Under this model, the exchange can use a smaller set of liquid reserve assets to cover liabilities across the platform. This can be more practical and can reduce reliance on less liquid assets or volatile altcoins.
However, the composition of those reserves matters. If an exchange uses its own native token as a significant reserve asset, the apparent coverage can deteriorate rapidly if the token loses value. The collapse of FTX illustrated this risk: FTX's balance sheet relied heavily on FTT, its native token, creating a feedback loop between the exchange's solvency and the value of its own asset.
Reserve coverage therefore needs to be assessed not only by its percentage, but also by the method used and the assets providing the coverage.
For an asset-level PoR, an exchange could be fully backed in BTC but undercollateralized in USDT. For an overall-liability PoR, the exchange may instead use BTC, ETH, USDT, and USDC to cover customer liabilities across the platform.
The quality and liquidity of the reserve assets also influence the strength of the coverage. BTC, ETH, USDT, and USDC have deep markets and can generally be transferred or sold more easily than an exchange's own token or an asset with limited liquidity.
In our example, KuCoin's report shows collateral above 100% for each asset:
5. When Was the Information Verified?
A PoR is a snapshot, which describes the reserve position at a specific point in time.
Therefore it's important to check the verification date, not just the publication date, given the two dates may differ. How often the exchange publishes a new assessment should also be checked.
The KuCoin report was published on August 10, 2026, while the technical verification took place on July 31, 2026.
This is the main limitation of any point-in-time PoR. An exchange can move assets after the snapshot. More frequent assessments reduce the gap but do not eliminate it.
In plain terms, PoR reports become stale. How quickly this happens depends on how often the exchange publishes new verification reports:
- Daily snapshots become stale within 24 hours.
- Monthly attestations become stale within a few weeks. This is a common cadence for centralized crypto exchanges.
- Quarterly audits become stale within three months, leaving a longer period in which an exchange's financial position can change.
Limits of Proof of Reserves
PoR is useful, but it does not answer every question about an exchange. It generally does not establish:
- Whether reserves are encumbered. Assets can be pledged as collateral, locked in other protocols, or subject to legal claims.
- What happens between snapshots. Assets can move after the assessment.
- The quality of the reserves. Two exchanges can report the same coverage ratio while holding very different assets.
- Operational and security risk. PoR does not show whether an exchange's infrastructure is secure, how it manages access controls, or how it responds to incidents.
This is where broader exchange risk assessment becomes important. CORE3 complements CoinGecko's Trust Score and Proof of Reserves by assessing the dimensions that PoR does not cover, including exchange security, solvency, and transparency. This provides users with a deeper view of an exchange's risk profile than reserve verification alone.
For this reason, "Proof of Reserves: yes/no" is a limited measure. The quality and scope of the evidence matter.
For Exchanges: Publish Evidence That Users Can Verify
Exchanges can make their PoR more useful by publishing the information needed to assess it independently.
At a minimum, this should include:
- assets and networks covered
- reserve wallet addresses
- the method used to verify wallet control
- customer liabilities included in the assessment
- reserve coverage for each asset
- reserve composition
- assessment and verification dates
- assessment frequency
- whether customers can verify their own inclusion
- the independent assessor and the scope of its work
A reserve figure on its own gives users little to verify. Detailed, recurring, and independently verifiable disclosures provide much stronger evidence.
Looking Beyond Proof of Reserves
Proof of Reserves is useful, but it covers only one part of exchange risk. It can show whether specific assets covered customer liabilities at a point in time. But it’s not scoped to assess broader security: if the exchange's infrastructure is secure, whether its reserves are exposed to other risks, or how transparent and resilient its operations are.
CoinGecko's Trust Score provides a broader view by considering factors such as liquidity, cybersecurity, regulation, and incident history. Its cybersecurity component is supplemented with CORE3 data of exchanges’ penetration test, bug bounty, and Reserves verification audit.

Apart from Trust Score, on its platform, CORE3 provides deeper insight into exchange risk across three dimensions: Security, Solvency, and Transparency. For Solvency, it goes beyond a simple PoR yes/no check by assessing the quality and scope of reserve evidence, including reserve composition, verification methodology, and disclosure transparency. Security assessment covers the technical and operational risks that PoR does not address, while Transparency assesses the quality and availability of information needed to independently assess an exchange.

Together, these signals provide a more complete picture of exchange risk. Proof of Reserves can provide evidence that an exchange has sufficient assets to cover the liabilities included in an assessment. CORE3 supplements this evidence with security, solvency, and transparency data to help users assess the broader Probability of Loss.
For exchanges, publishing verifiable reserve information is one way to demonstrate financial transparency. Making this information available for independent assessment gives users and institutions more evidence to evaluate the exchange.
Explore exchange risk assessments on CORE3 and compare exchanges on CoinGecko.
This article is written in collaboration with CORE3.