TL;DR: A proof of reserves audit can mean two different things: a periodic CPA attestation (a firm's signed opinion on a snapshot of reserve data) or a cryptographic proof (a re-runnable, math-based check anyone can verify). They serve different needs and work best together, not as substitutes, attestation carries accounting authority, cryptographic proof carries independent, on-demand re-verification.
Confusing the two processes behind a proof of reserves audit, a CPA attestation versus a cryptographic verification, leads to overclaiming on both sides. This article shows how periodic attestation and cryptographic verification reinforce each other: where each is strongest, and why the most robust proof of reserves setup layers the two together rather than choosing between them.
Key Takeaways:
- The term can refer to a CPA's periodic attestation or a cryptographic, on-chain proof, and the two check fundamentally different things.
- Periodic attestation carries professional accounting authority but is a point-in-time snapshot, stale the moment it publishes.
- Cryptographic proof of reserves is independently re-verifiable at any time, but it is not a licensed opinion on a company's full financial statements.
- The two complement each other: attestation for accounting assurance, cryptographic proof for continuous, machine-checkable re-verification between attestation cycles.
What is a proof of reserves audit?
A proof of reserves audit is any process that verifies a stated reserve backing is accurate, and it splits into two distinct methods that get conflated in casual usage: CPA attestation and cryptographic proof. Attestation is a licensed accounting firm's signed opinion, produced through Agreed-Upon Procedures or an Examination engagement, following a defined professional standard. Cryptographic proof is a mathematical check, typically a Merkle tree combined with a Zero-Knowledge Proof, that anyone with the right verifier can re-run themselves.
Both methods answer "is this backed?" but from different directions. A CPA attestation answers it through professional judgment applied to reconciled data, an accountant traces the numbers, checks the sourcing, and signs their name to the result. A cryptographic proof answers it through math, the proof either verifies against the public inputs or it doesn't, with no professional judgment involved in the check itself.
Entities that recur across this space: CPA firm, Agreed-Upon Procedures, Examination engagement, reserve composition, Merkle root, Zero-Knowledge Proof, and reconciliation. Keeping these distinct matters because a reader who conflates "audited" with "cryptographically proven" ends up trusting a claim neither method fully supports. That same trap shows up in tokenized assets, where
reported asset data is not enough on its own.
How does a periodic CPA attestation work?
A CPA firm ingests an issuer's reserve data, reconciles on-chain liabilities against off-chain assets, and issues a signed opinion covering a specific snapshot, refreshed on a fixed cycle, most commonly monthly. Firms specializing in this work, The Network Firm is one example, pull data through dozens of integration methods, API, FTP, bank statements, custody records, and produce an attestation that follows recognized AICPA-grade standards.
The strength of this method is professional accountability. A licensed firm puts its name and its liability behind the number. Regulators and institutional counterparties treat that signature as meaningful in a way no automated check currently replicates, which is why
audit-grade data integrity remains the institutional baseline. The US GENIUS Act formalizes this cadence for payment-stablecoin issuers: a monthly reserve-composition disclosure examined by a registered accounting firm, with CEO/CFO certification, and PCAOB-standard annual audits for issuers above $50B in reserves.
The weakness sits in the calendar. A monthly attestation is accurate for the day it was produced. The three weeks or more that follow are unmonitored by the attestation itself. A depositor reading a report on day 20 of the cycle is reading data that is, at best, three weeks old.
How does cryptographic proof of reserves differ from attestation?
Cryptographic proof of reserves replaces a signed opinion with a math-based check, a Merkle tree of balances combined with a Zero-Knowledge Proof, that any party can re-run against public data without trusting whoever generated it. Binance's zk-SNARK PoR and OKX's zk-STARK PoR are the most mature production examples, both proving that all customer balances sum to a published total, that no balance is negative, and that every account is included, without revealing individual holdings.
The core distinction is re-runnability. An attestation is trusted because a licensed firm signed it. A cryptographic proof is trusted because the reader (or their software) verified the math directly, no professional judgment or third-party signature required in that step. That difference is what makes continuous, on-demand PoR possible in a way a human-executed audit cycle cannot match at the same frequency.
| Dimension | Periodic CPA attestation | Cryptographic proof of reserves |
|---|
| Basis of trust | Licensed firm's signed opinion | Math verified independently by any party |
| Frequency | Monthly or quarterly, fixed cycle | Re-runnable on demand, no fixed cycle |
| What's checked | Reconciled reserve data against accounting standards | A Merkle-committed dataset against a stated condition |
| Who can re-verify | Relies on trusting the firm's process | Anyone with the proof and a public verifier |
| Regulatory standing | Recognized under GENIUS Act, AICPA standards | Not a recognized compliance substitute on its own |
| Data exposure | Attestor sees full underlying data | Can prove the condition without exposing balances |
Attestation is the recognized accounting baseline; cryptographic proof adds continuous, independent re-verification on top. Together they cover what neither does alone.
What gap does cryptographic proof close that attestation leaves open?
Cryptographic proof closes the between-attestation gap: the weeks where a monthly report is technically still "current" but has not been re-checked against real-time reserve state. Attestation gives depositors a trustworthy number once a cycle. It does not give them a way to check that number again on day 15 without waiting for the next report.
A cryptographically re-runnable proof does not carry the same weeks-long staleness, because the check itself can be regenerated whenever a counterparty wants to look, rather than only when the firm's next engagement completes. This does not make attestation obsolete. It makes attestation the trusted baseline and cryptographic proof the layer that keeps that baseline checkable between cycles, closer to what our
proof of reserves explainer covers when it distinguishes snapshot PoR from continuous verification.
Why do attestation and cryptographic proof complement rather than replace each other?
Attestation carries professional and regulatory authority that a math proof alone does not, while cryptographic proof offers continuous re-verification a human-executed audit cycle cannot match; a stablecoin issuer needs both, not one instead of the other. Regulators recognize CPA opinions under a defined standard. They do not, today, recognize a Zero-Knowledge Proof as a legal substitute for that opinion, even when the math is sound.
The reverse is also true. A CPA attestation cannot be re-run by a depositor at 2am to check if reserves still hold; a cryptographic proof can. Positioning one as a replacement for the other overstates what either delivers on its own. The honest architecture is layered: attestation for the accounting relationship regulators recognize, cryptographic proof for the independent re-verification (Merkle trees plus Zero-Knowledge Proofs) that keeps the claim checkable in the gaps between attestation cycles.
zkDatabase sits in that second layer. It does not replace the CPA relationship or issue an opinion on a company's books. It generates a proof that a committed dataset, the same reserve data the attestation already covers, satisfies a stated backing condition, so any counterparty can re-run that specific check without waiting for the next monthly cycle or trusting a dashboard's word for it. Our piece on
what proof of reserves actually proves covers the honest boundary between "assets exist" and "the company is fully solvent," a distinction that applies to both attestation and cryptographic methods equally.
Where does this show up for stablecoin issuers specifically?
Stablecoin issuers face the sharpest version of this gap, because their reserves back a token that trades continuously, while their attestation cycle runs monthly at best. A token that settles every second is only as verifiable, moment to moment, as the last report someone bothered to read.
That mismatch is why several issuers now layer an oracle-fed or cryptographic reserve check on top of their existing attestation, rather than swapping one for the other. Our
stablecoin reserve verification piece covers this specific pressure in more depth, and our companion article on
oracle feeds versus cryptographic proof for stablecoins walks through the two supplementary approaches issuers are actually adopting today.
Bottom line
A reserve audit is not one thing. Periodic attestation and cryptographic proof check different aspects of the same claim, on different cadences, with different sources of trust. Reading either as a full replacement for the other misreads what each one does. The stronger posture, for an issuer or a reader evaluating one, is attestation as the recognized baseline and cryptographic proof as the layer that keeps that baseline checkable in real time.
Explore zkDatabase
See how zkDatabase generates a re-runnable reserve proof that complements an issuer's existing attestation relationship.
FAQ
What is a proof of reserves audit?
A proof of reserves audit refers to either a periodic CPA attestation, a licensed accounting firm's signed opinion on reserve data, or a cryptographic proof, a math-based, independently re-runnable check of the same claim. The two terms get used interchangeably, but they check the claim through different mechanisms and carry different standing.
Is a cryptographic proof of reserves the same as an audit?
No. A cryptographic proof of reserves is a math-based verification that anyone can re-run against public data; a financial audit is a licensed professional's examination following recognized accounting standards. Cryptographic proof complements an audit relationship by keeping the reserve claim checkable between formal attestation cycles, rather than substituting for the accountant's opinion.
How often should proof of reserves be updated?
Periodic CPA attestation typically runs monthly, the cadence formalized by the GENIUS Act for US payment-stablecoin issuers. Cryptographic proof of reserves can be regenerated and independently re-verified on demand, since the check itself does not depend on waiting for a scheduled accounting engagement.
Can zkDatabase replace a company's existing reserve attestation?
No. zkDatabase generates a cryptographic proof over committed reserve data, functioning as a supplementary, independently re-verifiable layer alongside an issuer's existing CPA attestation, not a replacement for it. The attestation still carries the recognized accounting and regulatory standing; zkDatabase makes that same underlying claim re-checkable at any time without exposing the balances behind it.