The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Proof of Reserves Explained: How to Check an Exchange Attestation Yourself

A proof of reserves shows that a crypto exchange controlled customer balances on a given reporting date. Here is how to recalculate your own holding in the Merkle tree, and why the attestation says nothing about solvency.

Closed storage vessel of matte glass on a metal shelf, the lid lying beside it, the interior remaining in half-shadow
15 min read
Share:

Between August 17 and August 31, 2026, deadlines expire at several trading venues that force German investors to sell or withdraw their balances. Anyone doing so inevitably faces a question that never comes up in everyday use: is the balance shown in the account overview actually held at the exchange? The industry's answer to that question is called proof of reserves. Until now there has been no German-language guide explaining how an investor recalculates such a reserve attestation and where its evidential value ends.

This article closes that gap using a concrete example and our own measurements. cryptoticker.io collected this analysis itself on August 18, 2026.

Proof of Reserves: what an exchange reserve attestation actually measures

Proof of reserves is an audit procedure carried out at regular intervals by an independent auditor. It is designed to show that a custodian genuinely holds the assets it claims to hold on behalf of its customers. To do so, the auditor takes an anonymised snapshot of all account balances, condenses it into a particular data structure and compares the result with the holdings on the exchange's blockchain addresses.

The decisive addition is the signature. The exchange must sign with the private keys of the audited addresses and thereby demonstrate that it controls them. Only the combination of both elements produces a meaningful statement. An address with a large balance proves nothing on its own, because it could belong to anyone.

The division of roles matters. The auditor confirms an arithmetic operation, not a business position. On a given reporting date, the auditor states that the controlled holdings match or exceed the aggregated customer balances. The procedure says nothing in itself about the company's liabilities, about loans, or about whether the exchange is financially sound.

Merkle tree and Merkle root: how every customer balance becomes a single fingerprint

The technical core is a tree structure built from checksums. Each individual customer account is hashed together with its balances into a short value, the leaf of the tree. Each pair of adjacent leaves is hashed together again, the result is hashed with its neighbour, and so on until a single value remains. That value is the Merkle root.

The usefulness of this construction lies in its sensitivity. If a single digit of any balance anywhere in the tree changes, the Merkle root changes completely. An exchange therefore cannot quietly remove individual balances after the fact without the published root value ceasing to match.

Privacy is preserved at the same time. No individual balance can be reconstructed from the root value, and during verification a customer sees only their own path through the tree, not the balances of others. That is precisely why the procedure has prevailed over the alternative of simply publishing a list of all balances.

Record ID and Merkle leaf ID: how to check your own balance step by step

The documented example used here is Kraken's publicly available method, because this provider describes the calculation openly and gives customers their own verification tool. The page was readable and reproducible without logging in when accessed on August 18, 2026.

The process has four stages. First you log in to your account and open the reserve attestation section. It lists the audits your account was included in, with the date, the audit firm and the scope of the audit. In the second step you select an audit and display the values that went into the tree for your account.

The third step is the calculation itself. Your account code, your customer identifier with the provider and the identifier of the audit in question are combined via SHA-256 into what is known as the record ID. This record ID is concatenated with your balances and hashed with SHA-256 again, and the first 16 characters of the result form your Merkle leaf ID. The provider sets out this calculation itself and points out explicitly that the notation of the amounts and the order of the values must be exactly right, because otherwise a different hash results.

In the fourth step you check whether your Merkle leaf ID sits in the published tree. Two routes are available: the audit firm's tool, into which the first 16 characters are entered, or recalculating the path up to the root value yourself. Code examples in several programming languages are available for the second route. Anyone who does not code will manage with the first.

The practical value of this exercise is often underestimated. The calculation turns a question of trust into an arithmetic problem with an unambiguous result. Either your own balance sits in the audited tree or it does not.

Reserve ratio as of June 30, 2026: what ratios between 100.3 and 105 percent tell you

The page accessed gave June 30, 2026 as the reporting date of the most recent audit. The coverage ratios disclosed on August 18, 2026 were as follows: bitcoin 102.9 percent, ether 100.5 percent, solana 100.6 percent, XRP 102.3 percent, cardano 100.3 percent, and for USD Coin, Tether and USDG a figure of more than 105 percent in each case.

A ratio above 100 percent means that the verified holdings exceed the aggregated customer balances in that asset. The distance from the 100 mark is neither a seal of quality nor a yield. It is simply a buffer made up of the exchange's own holdings and rounding. The reverse case would be the interesting one, and the figures do not show it on this reporting date.

Shallow wooden tray of smoothly raked sand holding a single geometric ring imprint whose edges have already begun to blur, with a heavy metal stamp beside it
A reserve attestation is an imprint from one single reporting date, and it loses its sharpness as soon as the holdings move afterwards.

Scope of the audit: eight tiles displayed, six assets named in the text

One discrepancy on the page itself stood out on access, and it matters for interpretation. The overview showed eight tiles with coverage ratios, cardano and USDG among them. The explanatory section below it, by contrast, named six assets as falling within the scope of the most recent audit: bitcoin, ether, solana, USD Coin, Tether and XRP.

For a customer this has an immediate consequence. Anything outside the scope of the audit does not appear in your own recalculation either. Someone holding a dozen smaller assets in their account receives no statement at all about the overwhelming majority of their portfolio, even if the audit was conducted impeccably. Which of the two figures on the page describes the current position cannot be determined from outside; in case of doubt the list in the audit report linked inside the account applies.

Regulated Crypto Exchanges ComparedRegulated Crypto Exchanges Compared

What proof of reserves does not prove: liabilities, borrowed funds and copied keys

The most valuable section of the page audited is the one in which the provider lists the weaknesses of its own procedure. It states there that the procedure evidences control over holdings at the time of the audit, but cannot prove exclusive possession of private keys should these have been copied by an attacker. It continues: "The procedure cannot identify any hidden encumbrances or prove that funds had not been borrowed for purposes of passing the review." Hidden encumbrances therefore remain invisible, and the procedure does not show whether funds were borrowed specifically in order to pass the review.

The provider also notes that keys may have been lost or holdings stolen since the last audit, and that the evidential value depends on the expertise and independence of the auditor. That is remarkably candid, and for readers it is the most important part of the entire page.

From this follows the central limitation that is almost entirely absent from German-language coverage: a reserve attestation without audited liabilities says nothing about a company's solvency. An exchange can demonstrate full coverage and still carry heavy debts. Anyone reading the attestation as a certificate of solvency is reading it wrongly. A complete picture would emerge only if an auditor examined both sides of the balance sheet, and that is exactly what the standard procedure does not deliver.

Our own survey of August 18, 2026: 20 requests across 15 provider pages

To test how accessible such attestations actually are, on August 18, 2026 between 09:52 and 10:05 UTC we accessed the attestation pages of 15 trading venues that matter to German investors, plus five supplementary requests on alternative paths. Method: direct request to the relevant address with a standard browser identifier, redirects were followed, and the delivered text was then searched for a reporting date. Objects examined: 20 requests.

The result is sobering. At exactly two of the 15 providers a reporting date appeared in the delivered text and was therefore discoverable without logging in and without browser scripts: Kraken with June 30, 2026 and KuCoin with July 31, 2026. Three further pages did deliver readable text, but no date that could be assigned unambiguously to the most recent audit.

Five pages rejected the automated request with status code 403. That is a bot defence and not evidence that no attestation exists there; in a browser these pages are reachable as normal. Two addresses responded with 200 but delivered virtually no text, because the content is assembled only in the browser. One page responded with status code 202 and zero bytes.

Bot blocks, 404s and empty pages: why the direct route to an attestation often leads nowhere

Four requests ended with status code 404, meaning the address did not exist in that form. Those affected included the German-language path of one provider whose English-language version of the same page responded with 200, as well as two providers where no attestation page sat at the obvious address.

Caution is required here, and we say so explicitly. A 404 at an expected address does not prove that a provider maintains no reserve attestation. It proves only that the direct route to it is not the one you would assume. For a reader wanting to check quickly, however, the difference is slight, because both end in the same outcome: they find nothing.

The practical conclusion from the survey is therefore to look for the attestation inside the logged-in account rather than through a search engine or a guessed address. Where an audit has taken place, it is usually held in the account area together with the tool for your own recalculation. Anyone who cannot find the entry there has received their answer by other means.

Workshop lamp with a metal shade above a long wooden bench, its cone of light reaching only a small part of the surface while the rest lies in darkness
The audited section lies in the light, while the far larger part of the company balance sheet remains unlit by the procedure.

Snapshot instead of live balance: why an attestation dated June 30 is 49 days old on August 18

The two reporting dates measured show where the real weakness lies in practice. The attestation with the reporting date of June 30, 2026 was 49 days old on the day of the survey, the one dated July 31, 2026 still 18 days. An exchange's holdings can change completely in that time without the published ratio reflecting it.

A reserve attestation is therefore a dated snapshot rather than a live balance, and that is not negligence on the providers' part but inherent in the procedure. An audit requires a signature and an auditor, and both happen at a point in time. Anyone reading the ratio should therefore always look first at the date beside it. A ratio without a visible reporting date is not information.

For assessing a provider, the interval between two audits is almost more revealing than the ratio itself. A venue that has itself audited monthly delivers a finer-grained picture than one that does so once every six months. Both occur in the market, and both can be read off the published reporting dates.

Hardware Wallets ComparedHardware Wallets Compared

A reserve attestation and regulatory authorisation are two different things

One point is regularly conflated. Proof of reserves is a voluntary undertaking by a company. Nobody orders it, its scope is set by the provider itself, and it can be discontinued at any time. Regulatory authorisation is something else: the status is tied to statutory requirements, is granted by an authority and can be withdrawn.

Neither substitutes for the other. A provider without authorisation is not brought under supervision by an attractive reserve attestation, and an authorised provider without a reserve attestation is not automatically opaque. Both should therefore be checked when choosing a trading venue. Which providers in Germany are under supervision, and how to recognise it, is set out in the overview of regulated crypto exchanges.

We did not verify the precise reference for the European requirements on segregating customer assets against the text of the regulation ourselves for this article, and we therefore deliberately name no article number. Anyone who needs this to be legally watertight should consult the official text rather than a summary.

When checking it yourself pays off and when self-custody is the better answer

Depending on the route taken, the recalculation costs between five minutes and just under an hour. The effort is worthwhile above all in two situations: when a larger sum sits at a trading venue for a longer period, and when unrest arises around a provider and you want to know whether your own balance was included in the most recent audit at all.

The recalculation does not, however, replace the fundamental decision about where holdings are kept. At best an attestation confirms that a third party controlled the funds on a given reporting date. The power of disposal remains with that third party. Anyone who wants it for themselves cannot avoid self-custody, with everything that entails. How the current deadlines and forced conversions at trading venues are stacking up right now is shown in the overview of reporting dates through the end of August. That a trading venue can cease operations is likewise no theoretical case, as the wind-down of another provider since the end of July shows.

Tax on withdrawals to your own wallet: what a transfer triggers and what it does not

One question comes up regularly in this context. A pure transfer of holdings between two wallets belonging to the same person is not a sale and does not in itself trigger a private disposal transaction under Section 23 of the German Income Tax Act. The holding period continues to run. The position is different where holdings are sold or forcibly exchanged beforehand, because a disposal then exists and the one-year deadline becomes relevant.

The date of the transfer nevertheless matters for your own records, because acquisition dates otherwise become impossible to assign cleanly later on. For the individual case the usual rule applies: tax advice beats a rule of thumb.

Limits of this analysis: what could not be verified on August 18, 2026

There are three things we could not clarify, and we write them down rather than paper over them. First, for the five pages with bot defences and for the pages that assemble their content only in the browser, it was not possible to establish whether and when an audit last took place there. The absence of a date in our measurement is not a statement about the provider.

Second, we were unable to inspect the audit reports themselves, because they sit in the logged-in customer area. All figures on ratios and reporting dates come from the providers' publicly accessible overview pages.

Third, we have made no statement about whether any particular exchange is solvent. That cannot be established with this procedure in principle, and it is not the subject of this article either.

Checking a reserve attestation: what to take away

  1. Look at the date first, then at the ratio. An attestation without a visible reporting date is worthless, and a reporting date weeks in the past does not describe today's holdings. Which trading venues have themselves audited regularly at all is a selection criterion like fees and asset choice: a look at the crypto exchange comparison is worth it before opening an account.
  2. Check inside your account whether your own balance sits in the tree. The route runs through the account area, not through a guessed address. Anyone unwilling to wait for the result moves holdings into self-custody; the devices for that are listed in the hardware wallet comparison.
  3. Record what you moved and when. Transfers between your own wallets are not a sale, but without records acquisition dates can barely be evidenced later. The tools for that are set out in the overview of tax software and portfolio trackers.

The primary source for the method described here is openly available online: the documentation of the reserve attestation, including the calculation and a self-assessment of its limits. The second reporting date measured comes from KuCoin's attestation page.

(As of August 18, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker