Four years after FTX, crypto exchanges still prove assets without proving solvency
Four years after FTX’s collapse forced exchanges to publish proof-of-reserves systems, institutional investors still cannot independently verify whether crypto platforms are solvent, only that they hold specified assets at a single point in time. This gap leaves major risks unaudited: hidden liabilities, pledged collateral, and complex corporate structures that could obscure the true financial condition of exchanges managing billions in customer funds.
- Proof-of-reserves systems verify only that exchanges control specified assets at a single moment, not whether all customer balances appear in the dataset or are actually recoverable.
- Major platforms including Binance, OKX, Kraken, and Crypto.com have published reserve dashboards and cryptographic verification tools since the November 2022 FTX collapse.
- True solvency assessment requires auditing liabilities, collateral pledges, corporate ownership structures, and legal claims, data that cryptographic proofs do not and cannot expose.
- November 2022 Date when FTX collapsed, triggering industry-wide push for proof-of-reserves disclosures
- 4 years Time elapsed since FTX collapse with no standardized solvency verification framework adopted
- 5 major exchanges Platforms now publishing some form of reserve verification, though methodologies remain inconsistent
Nearly four years have passed since FTX’s November 2022 implosion exposed the dangers of unverified claims about exchange solvency, yet the cryptographic tools that emerged in its wake have created a false sense of security.
Exchanges from Binance to Crypto.com now offer customers the ability to verify their individual balances using Merkle trees, zero-knowledge proofs, and wallet-signing mechanisms that cryptographically confirm asset possession. However, this technological progress masks a fundamental limitation: these systems prove only that an exchange controlled specified assets at a specified moment.
They reveal nothing about whether the exchange disclosed all liabilities, whether customer balances are pledged as collateral to lenders, whether corporate ownership structures create claims senior to customer rights, or whether the legal entity signing the proof actually controls the assets in question.
For institutional investors managing exposure to major exchanges through trading, custody, or lending arrangements, this gap represents a material audit and counterparty risk that remains unresolved.
Merkle trees and wallet signatures expose asset holdings but hide liabilities and collateral claims
The technical architecture underlying current proof-of-reserves systems is sound in isolation. An exchange can publish wallet addresses and use private key signatures to prove control without moving assets, avoiding both security risks and tax complications.
Merkle trees convert individual customer balances into cryptographic hashes that combine into a single root hash, allowing each customer to verify their balance contributed to that root without revealing anyone else’s account data. Binance enhanced this model with zero-knowledge proofs (zk-SNARK), which confirm calculations followed stated rules while keeping balances private.
OKX publishes wallet information and downloadable proof files, Kraken offers account-level verification for covered balances, and Crypto.com provides a Merkle-based verification interface.
These innovations improved dramatically on the pre-FTX model, which required users to trust corporate claims with no cryptographic verification. They can expose false claims about asset holdings, make large withdrawals more visible to observers, and allow customers to confirm their individual balances are represented in the exchange’s dataset.
A customer who successfully verifies their balance through a Merkle tree has real evidence that the exchange controls enough of a particular asset to theoretically cover their position.
The verification stops there.
What these systems cannot expose includes whether every customer balance appears in the dataset being verified, how much the exchange owes to lenders, whether displayed coins have been pledged as collateral against those loans, whether the assets claimed are available for withdrawal or encumbered by claims from creditors or counterparties, and whether the legal entity that claims to control the wallet is the same entity responsible for repaying the customer.
A customer may verify their balance successfully while the exchange simultaneously has liabilities exceeding its assets when all obligations are factored in. The cryptographic proof provides no window into the balance sheet as a whole.
Solvency requires auditing liabilities, collateral structures, and corporate ownership that proofs cannot reach
Determining whether an exchange is solvent requires a fundamentally different inquiry than verifying asset possession. Solvency depends on the relationship between assets and liabilities measured across the full scope of the company’s obligations.
An exchange might control 100,000 Bitcoin verifiable through cryptographic proof, yet owe 110,000 Bitcoin to creditors, hedge funds, or affiliate entities through loan agreements, margin positions, or corporate guarantees. A Merkle tree cannot detect this condition because liabilities exist in corporate records, loan documents, and legal structures, not in blockchain data.
The problem deepens when collateral arrangements are considered. Exchanges frequently pledge customer assets or exchange-controlled reserves as collateral against loans used to fund operations or prop up affiliate ventures. These pledges create claims senior to customer rights in bankruptcy or insolvency proceedings.
A proof-of-reserves disclosure might show that an exchange controls a specific quantity of Bitcoin, without noting that those same coins are pledged to a lender and thus unavailable for customer withdrawal in a stress scenario. The cryptographic proof is technically accurate but operationally misleading.
Corporate ownership and subsidiary structures add another layer of opacity. An exchange’s wallet might be controlled by a foundation, holding company, or subsidiary entity that is legally or operationally separate from the corporate entity responsible for repaying customers.
Control over the wallet does not guarantee that customers have a valid claim to those assets in legal proceedings, especially across jurisdictions. The cryptographic evidence of asset possession tells an investor nothing about whose legal claim to those assets would prevail in a dispute, restructuring, or bankruptcy scenario.
FTX had substantial assets on its balance sheet up until the moment it did not.
The exchange controlled billions in FTT tokens, cryptocurrency holdings, and other property that could be cryptographically verified. What could not be verified through any technical means was whether those assets were actually available to repay customers or whether they had been misappropriated, pledged away, or commingled with affiliate entities’ obligations.
A proof-of-reserves system, had FTX published one, would not have flagged the hidden loans to Alameda Research, the corporate loans between related entities, or the misaligned incentives that made assets nominally controlled by FTX legally unavailable to its customers.
Industry fragmentation leaves institutional investors without standardized solvency frameworks
In the years since FTX’s collapse, exchanges have adopted proof-of-reserves systems on voluntary, inconsistent terms. Binance publishes a reserve dashboard with customer verification tools and incorporated zk-SNARK technology. OKX releases wallet information and downloadable proof files.
Kraken offers account-level verification for a subset of balances. Crypto.com provides a Merkle-based interface. None of these systems use identical methodologies, audit frequencies, or scope definitions, making it impossible for an investor to compare exchanges on a standardized basis or to assess what each proof actually covers.
Critically, no exchange has published a standardized, third-party audited solvency statement comparable to what traditional financial institutions provide. A bank publishes balance sheets audited by major accounting firms, disclosing all material liabilities, related-party transactions, collateral arrangements, and corporate structures.
Crypto exchanges publish cryptographic proofs of asset possession that, while technically rigorous, address a narrower question than solvency.
An institutional investor managing counterparty exposure to an exchange cannot point to a single audited document that maps assets against all liabilities and answers the question: if this exchange became insolvent tomorrow, could all customer claims be satisfied?
Some platforms have taken incremental steps toward broader disclosure. Reserve ratios published by certain exchanges purport to show that liabilities covered by assets exceed 100 percent, addressing the solvency question in aggregate. However, these figures rely on self-reported liability data and are not independently verified.
A reserve ratio cannot distinguish between liabilities to customers and liabilities to lenders, cannot expose collateral pledges that reduce available assets, and cannot map corporate structures that might create senior claims.
Regulatory pressure has not yet forced standardized solvency verification across the industry
Regulators in the European Union, Hong Kong, and the United States have
