Proof of reserves audits in Cyprus
Prove your reserves back every customer balance.
Independent proof of reserves attestations for exchanges, custodians, stablecoin issuers, and funds across Cyprus and the EU. We verify cryptographic control of your wallets, establish what you owe customers, and publish an attestation your users and supervisors can actually rely on.
Reserves Alone Prove Nothing
A wallet balance is only half the equation. Solvency is a comparison, and an attestation that shows one side without the other is marketing rather than assurance.
The assets you hold
Every reserve address proven under your control by cryptographic signature or a nominal transfer on our instruction — not simply named to us. Balances are read directly from the chain at an agreed snapshot, across hot, cold, multi-signature, and MPC custody.
The liabilities you owe
The full customer balance ledger, tested for completeness and committed to a Merkle tree so any individual customer can verify their own inclusion. This is the half that is routinely skipped, and the half that makes the ratio meaningful.
Who Needs Proof of Reserves
Anyone holding crypto that ultimately belongs to someone else — and increasingly, anyone who has to satisfy a supervisor, counterparty, or acquirer that it is really there.
Exchanges & trading platforms
Demonstrate to customers and regulators that deposits are fully backed, and turn a recurring attestation into a competitive claim you can actually substantiate.
Custodians & wallet providers
Evidence segregation of client assets and the integrity of custody controls across hot, cold, multi-signature, and MPC arrangements.
Stablecoin & token issuers
Attest that circulating supply is backed by reserves held as stated, on the frequent cadence holders and MiCA-conscious counterparties expect.
Funds & treasuries
Give investors, boards, and administrators independent verification of holdings and net asset value at period end.
CASPs authorised in Cyprus
Support CySEC supervision and MiCA client-asset safeguarding obligations with documented, repeatable evidence rather than management assertion.
Businesses holding crypto on balance sheet
Verify treasury holdings for auditors, lenders, insurers, and acquirers who will not take a block explorer screenshot as evidence.
How the Engagement Works
Methodology fixed before testing starts, so the result cannot be shaped after the fact.
Scope & methodology
We agree which entities, wallets, custodians, and customer liabilities are in scope, and fix the methodology and snapshot timing in writing before any testing begins.
Prove wallet control
You demonstrate control of every reserve address cryptographically — a signed challenge message or a nominal transfer on our instruction. Unproven addresses are excluded.
Establish customer liabilities
We extract the full customer balance ledger, test the controls around it for completeness, and build a Merkle tree so individual customers can verify their own inclusion.
Compare, test & investigate
Reserves are measured against liabilities asset by asset. Any shortfall, unexplained movement, or third-party exposure is investigated rather than netted away.
Attestation report
You receive a report stating the reserve ratio, the methodology, the Merkle root, and the limitations — written to be published, not just filed.
What It Does and Doesn't Prove
We state the limits in the report itself. An attestation that overclaims damages the business it was meant to reassure.
It does prove
- You controlled specific wallets holding specific balances at the snapshot
- Those balances covered the customer liabilities recorded in your ledger
- Individual customers can verify their own balance was counted
- The methodology was fixed in advance and applied by an independent firm
It does not prove
- Anything about your position before or after the snapshot moment
- That no liabilities exist outside the ledger we were given
- Overall financial health — that needs a full financial statement audit
- That assets deployed with third parties carry no counterparty risk
We reduce snapshot risk with unannounced timing, control testing over the liability ledger, and a recurring cadence — and we recommend pairing attestations with a financial statement audit.
Proof of Reserves, MiCA and CySEC
MiCA never uses the phrase "proof of reserves", but it creates the obligations that make one the practical form of evidence. Crypto-asset service providers must segregate and safeguard client assets; asset-referenced and e-money token issuers face specific reserve, custody, and reporting requirements. For a CASP authorised in Cyprus under CySEC supervision, a recurring attestation is a direct way to show client assets are held as claimed — documented, repeatable, and independent of management assertion.
Read our note on the MiCA transition windowProof of Reserves FAQ
What is a proof of reserves audit?
A proof of reserves engagement independently verifies that the crypto assets a custodian holds are sufficient to cover what it owes its customers. It has two halves that must both be done: proving control of the reserve wallets on-chain, and establishing the total customer liability from the internal ledger. Only the two together demonstrate solvency — a wallet balance on its own proves nothing about what is owed against it.
Is proof of reserves the same as a financial statement audit?
No, and the distinction matters. A proof of reserves engagement is a targeted attestation about assets and customer liabilities at a point in time. A financial statement audit is a much broader opinion covering the whole entity — revenue, expenses, going concern, related parties, and off-balance-sheet obligations. Proof of reserves is faster and more frequent; a full audit is deeper. Most crypto businesses eventually need both, and we provide each.
How do you prove we actually control our wallets?
Through cryptographic proof rather than assertion. We have you sign a challenge message with the private keys controlling each reserve address, or move a nominal amount on our instruction, so that control is demonstrated rather than claimed. Addresses you merely name to us — including ones you might have borrowed sight of — do not count as reserves.
How are customer balances verified without exposing customer data?
With a Merkle tree. Each customer balance is hashed into a tree whose root we publish alongside the attestation. Any customer can then check that their own balance was included in the total we verified, using a proof unique to them, without seeing anyone else's data. We test the tree construction ourselves rather than taking the output on trust, because a Merkle proof is only as good as the completeness of the leaves fed into it.
What are the real limitations we should disclose?
Proof of reserves is a snapshot. It shows the position at a moment, and it cannot by itself rule out assets borrowed shortly before that moment and returned after, nor liabilities kept outside the ledger we were given. We mitigate this with unannounced timing, control testing over the liability ledger, and recurring attestations rather than a single one — and we state the residual limitations plainly in the report, because an attestation that overclaims is worse than none.
How often should we publish proof of reserves?
Quarterly is the emerging norm for exchanges and custodians, and monthly is increasingly expected of stablecoin issuers. A single one-off attestation has limited assurance value — the credibility comes from an unbroken series, published on a schedule you commit to in advance and keep to even in a bad quarter.
Does MiCA require proof of reserves?
MiCA does not use the phrase "proof of reserves", but it imposes obligations that proof of reserves is the practical way to evidence: crypto-asset service providers must segregate and safeguard client assets, and asset-referenced and e-money token issuers face specific reserve, custody, and reporting requirements. For a CASP authorised in Cyprus under CySEC supervision, a recurring reserves attestation is a direct way to demonstrate that client assets are held as claimed.
Which chains and assets can you attest to?
Bitcoin, Ethereum and the major EVM chains, and the other principal networks, together with the stablecoins and tokens issued on them. We handle multi-signature and MPC custody arrangements, and assets held with third-party custodians or deployed into staking and lending — though the latter carry counterparty risk we identify separately rather than counting at face value.
How long does an engagement take?
For a first engagement, typically a few weeks from scoping to report, with most of that spent establishing the liability side and testing the controls around it. Once the methodology is agreed and the data pipeline is in place, recurring attestations run substantially faster.
More questions answered on our general FAQ.
Related Reading
Ready to publish your reserves?
Tell us about your custody setup and customer base. We will scope the engagement, agree the methodology, and set a cadence you can sustain.