Crypto Audits in 2026: DAC8, MiCA and the Tether KPMG Audit

By Iraklis Anastasiou · August 29, 2026
Standard financial checks aren't enough to secure the digital asset industry. As new frameworks like DAC8 mandate transparency, auditors must rely on deep technical expertise to verify everything from smart contracts to physical gold reserves.
In the wake of multiple high-profile crypto collapses, namely FTX and Zondacrypto, the digital asset industry has been forced to mature. It is abundantly clear that a traditional financial audit, designed for fiat bank accounts and physical inventory, is woefully inadequate for a crypto balance sheet. The unique nature of blockchain technology introduces financial assertions that require specialized scrutiny, pushing auditors to look beyond standard practices. Blockchain-based remittance companies, cryptocurrency exchanges, and stablecoin issuers are some of the immediate enterprises that will require crypto audits.
The Intricacies of Crypto Audits
When a standard auditor approaches a balance sheet, they test for existence, valuation, and rights and obligations. In traditional finance, verifying existence is often as simple as requesting a bank statement. In crypto, "existence" means proving control over the private keys that govern a wallet address. But control does not inherently equal ownership, which complicates the "rights and obligations" assertion. Are the assets held in a custodial capacity for users, or do they belong to the exchange?
Furthermore, valuation remains a complex puzzle. While Bitcoin and Ethereum have deep liquidity, valuing thinly traded altcoins or complex derivative tokens requires sophisticated fair-value modeling that accommodates hyper-volatility.
Why Auditors Need Technical Experts
Because of these complexities, standard CPAs often find themselves out of their depth. Under international auditing standards, auditors are increasingly relying on technical experts to provide assurance. Blockchain cybersecurity and data science specialists are needed to evaluate the architecture of cold and hot wallets, audit the underlying code of smart contracts, and assess the cryptographic proofs (such as Merkle trees) used by exchanges for proof of reserves on the assets they hold in an offchain environment.
Without this technical assurance, an auditor cannot confidently sign off on the financial statements, as a single, overlooked smart contract vulnerability could instantly wipe out a firm's reserves.
The Expanding Regulatory Net
The regulatory landscape has also shifted dramatically, forcing companies to adopt robust reporting systems. The European Union's DAC8 directive, which entered its implementation phase in January 2026, acts as a stringent crypto tax-reporting framework. It requires service providers to automatically gather and share transaction data and user tax residency information with authorities, closing the visibility gap between traditional finance and digital assets.
Coupled with the markets in crypto-assets (MiCA) regulation, which imposes strict rules on market conduct, compliance is no longer optional. A recent example underscores this strict environment: on August 14, 2026, Austria's financial market authority (FMA) issued Europe's first published MiCA penalty to Vienna-based exchange Bitpanda. The €70,000 fine penalized the firm for procedural misses regarding a crypto-asset white paper and its accompanying marketing disclosures.
Specifically, the FMA identified three technical breaches. First, Bitpanda submitted a required token white paper to the regulator fewer than the strictly mandated 20 working days prior to publication. Second, promotional material was distributed before the white paper was actually published, reversing the sequence MiCA demands. Finally, the marketing communication omitted mandatory disclaimers, such as a statement noting the document had not been reviewed by a competent authority, alongside required contact details.
Bitpanda swiftly addressed the intervention, characterizing the episode as a procedural misstep concerning timing and formal specifications rather than a deeper compliance failure. The firm opted for an accelerated, consensual conclusion to the proceedings with the FMA. The fine, while financially small for a major platform, especially given that Bitpanda secured a full MiCA license from Germany's BaFin earlier in the year, sends a powerful signal. It demonstrates a definitive shift from the mere issuance of licenses to active, rigid enforcement of disclosure standards across the European Economic Area.
Case Studies of Success
Despite the regulatory hurdles and technical challenges, industry leaders are proving that comprehensive audits are possible.
In mid-August 2026, Tether, the issuer of the world's largest stablecoin, announced the completion of its first full independent financial audit of its 2025 statements, conducted by Big Four firm KPMG US. For years, critics questioned whether Tether truly held the reserves it claimed. KPMG's audit went far beyond a standard digital check. To verify the "existence" and "valuation" assertions, auditors physically inspected and counted Tether's gold holdings in vault locations, rather than relying solely on custodian records. They also extensively audited the smart contracts and cryptographic proofs that bind the USDT tokens on various blockchains. The audit yielded a clean opinion, revealing that Tether held a staggering $6.814 billion in excess reserves above its liabilities, and generated over $10 billion in net profit for 2025. This granular level of physical and cryptographic verification represents a new gold standard for stablecoin issuers.
Meanwhile, Bitpanda has demonstrated that operational security is just as critical as financial assurance. In February 2026, the firm completed its first System and Organization Controls (SOC) 2 Type II attestation. Unlike a standard point-in-time financial audit, a SOC 2 Type II involves a months-long rigorous examination by independent auditors to ensure that a company's security controls, availability, and confidentiality are consistently and operationally enforced.
As the digital asset market continues to bridge the gap with traditional finance, the expectations placed on crypto balance sheets will only grow. The combined forces of DAC8, MiCA, and the demand for institutional-grade assurance dictate that a standard audit is merely the starting point. Today's successful crypto audits require a fusion of traditional accounting principles, deep cryptographic expertise, and an unwavering commitment to regulatory compliance.
How Ondology Labs can help: This fusion is exactly what we do. We deliver full crypto financial statement audits with our ICPAC-licensed audit partner, provide crypto audit support as the technical experts for audit firms and companies with their own auditors, and prepare DAC8 crypto reporting for CASPs in Cyprus and across Europe.
Related reading: How to read a proof of reserves report · The MiCA transition window closes in July 2026.