• Pricings

  • Stablecoin

    Crypto Exchanges With Proof of Reserves: How They Compare

    July 14, 2026

    8 mins read

    A comparison of crypto exchanges with proof of reserves, the method each uses, from auditor-built Merkle trees to zk-SNARK and zk-STARK proofs, and what each design proves.

    TL;DR: Most major crypto exchanges with proof of reserves publish a Merkle tree of customer balances checked against signed wallet holdings. The strongest add a Zero-Knowledge Proof: Binance uses a zk-SNARK, OKX a zk-STARK, and Backpack a recursive proof refreshed daily, while others rely on an independent auditor. All prove the exchange's own book at a snapshot, not continuously.
    How crypto exchanges implement proof of reserves differs sharply, from an auditor assembling a Merkle tree to full Zero-Knowledge Proofs that keep individual accounts private, and those differences decide what is actually proven. This article compares the major exchanges' implementations, what each method verifies, where all of them stop, and how zkDatabase provides the cryptographic core for building or upgrading such a system.
    Key Takeaways:
    • Crypto exchanges with proof of reserves generally build a Merkle tree of liabilities and check it against signed on-chain asset wallets.
    • Binance wraps its proof in a zk-SNARK and OKX uses a zk-STARK, both proving totals and non-negative balances without exposing individual accounts.
    • Backpack refreshes a recursive proof daily, pushing exchange proof of reserves closer to continuous than the usual monthly cycle.
    • Every exchange proof of reserves covers only that exchange's own book at a snapshot; zkDatabase generalizes the same construction into a continuous, re-verifiable layer.

    What does proof of reserves mean for a crypto exchange?

    For a crypto exchange, proof of reserves is an on-chain demonstration that the assets it controls cover the balances it owes customers, built by combining a Merkle tree of liabilities with signed wallets proving asset control. It answers the direct post-FTX question, are customer funds actually there, without the exchange publishing every individual account.
    The mechanism has two sides that must meet. The liability side aggregates every customer balance into a Merkle tree whose single root commits to the total. The asset side signs on-chain wallet addresses to show the exchange holds coins of a certain value. Proof of reserves passes when the signed asset total covers the liability total the tree commits to.
    Recurring entities across exchange proof of reserves: Merkle root, non-negative balance constraint, cold wallet attestation, zk-SNARK, zk-STARK, and inclusion proof. The method an exchange chooses determines which of these it actually enforces, and that is what the comparison below turns on.

    Which crypto exchanges publish proof of reserves, and how?

    The major exchanges split by cryptographic strength: Binance uses a Merkle tree plus a zk-SNARK, OKX a zk-STARK over a Merkle sum tree, Backpack a recursively-proven system refreshed daily, and others such as Kraken rely on an independent auditor building the tree. The gap between an auditor-assembled tree and a zero-knowledge construction is the difference between trusting how the tree was built and verifying that it was built correctly.
    Binance has run its zk-SNARK proof of reserves since early 2023 and is the largest exchange on that model, proving that all balance leaves are included and none are negative. OKX publishes a zk-STARK, which needs no trusted setup, over an encrypted Merkle sum tree and ships an open-source verifier so users can re-run the check. Backpack's approach, derived from OKX's algorithm and improved with recursive proving, updates daily and emphasizes full user self-verification with less reliance on an auditor.
    ExchangeMethodRefreshWhat stands out
    BinanceMerkle tree + zk-SNARKPeriodic / frequentLargest deployment on a zero-knowledge construction
    OKXzk-STARK + Merkle sum treeMonthlyNo trusted setup; open-source verifier published
    BackpackRecursive proof (Plonky2-based)DailyNear-continuous cadence, strong self-verification
    KrakenAuditor-built Merkle treePeriodicIndependent auditor assembles and checks the tree
    Others (Bybit, Crypto.com, MEXC)Standard Merkle tree or auditor attestationPeriodicInclusion checks without the zero-knowledge layer
    Details and cadences move, so treat any specific figure as a point to re-verify on the exchange's own reserves page before relying on it.

    What do Zero-Knowledge Proofs add over a plain Merkle tree?

    A Zero-Knowledge Proof lets an exchange prove three things simultaneously, that all balances sum to the published total, that no balance is negative, and that every account is included, without revealing any individual holding, which a plain Merkle tree cannot enforce on its own. It removes the assumption that the auditor assembled the tree honestly and replaces it with a check on the construction itself.
    This matters because a plain Merkle tree still permits a dishonest builder to omit accounts or hide a negative balance; the zero-knowledge constraint makes those states unprovable rather than merely discouraged. That is why the zk-SNARK and zk-STARK designs are considered the strongest exchange proof of reserves in production, and also the most private. For a fuller walkthrough of the mechanism, see our explainer on how on-chain reserve proofs work.
    The trust that remains, for every exchange in the table, is the reported input data. A proof confirms a computation over the balances it is given; it cannot confirm those balances were reported truthfully. Cryptography closes the construction gap, not the source-honesty gap.

    What does exchange proof of reserves not cover?

    Exchange proof of reserves covers only that exchange's own book, and only at the moment the snapshot was taken, so it says nothing about third-party token issuers and nothing about the reserve state between snapshots. A passing check last month describes last month.
    Two limits follow. First, scope: an exchange proving its own solvency tells a user nothing about a stablecoin or tokenized asset held on the platform, whose backing is a separate question handled by oracle-fed or cryptographic reserve verification at the issuer level. Second, timing: most exchange proofs run on a periodic cycle, so a shortfall can open and close between updates without users seeing it, which is the specific gap Backpack's daily cadence narrows and a continuous proof removes.
    Bottom line: exchange proof of reserves answers "are my funds on this exchange backed right now-ish," not "is every token I hold fully solvent, continuously." Reading it as the latter overstates what a snapshot of one book can show.

    How does zkDatabase fit for exchanges building proof of reserves?

    zkDatabase provides the same Merkle-tree-plus-Zero-Knowledge-Proof construction the leading exchanges hand-build, as a ready-made, continuous database layer, so an exchange can reach zero-knowledge-grade proof of reserves without engineering the circuit from scratch. The hardest part of the strongest designs, the cryptographic core, comes built in.
    For an exchange without an in-house proving team, that lowers the bar to Binance- or OKX-level verification, and it changes the cadence: because the data is committed continuously, the reserve proof can be regenerated and independently re-verified on demand rather than published monthly. That is independent re-verification (Merkle trees plus Zero-Knowledge Proofs) as an operating property, not a periodic report. zkDatabase supplies the verification layer; it does not act as the exchange's auditor or vouch that reported balances are complete. For how the same layer serves stablecoin and RWA issuers, see proof of reserves for stablecoins.
    Explore zkDatabase See how zkDatabase gives an exchange a ready-made, continuously re-verifiable proof of reserves without building the circuit in-house.

    FAQ

    Which crypto exchanges have proof of reserves?

    Most large exchanges publish proof of reserves, with different methods. Binance uses a Merkle tree plus a zk-SNARK, OKX uses a zk-STARK with an open-source verifier, Backpack refreshes a recursive proof daily, and Kraken relies on an independent auditor building the tree. Others such as Bybit, Crypto.com, and MEXC run standard Merkle-tree checks. Always confirm the current method on each exchange's own reserves page.

    What is the best proof of reserves method for an exchange?

    The strongest production method pairs a Merkle tree with a Zero-Knowledge Proof, as Binance's zk-SNARK and OKX's zk-STARK do, because it proves balances sum correctly, none are negative, and all are included, without exposing individual accounts. A plain auditor-built Merkle tree is weaker because it still requires trusting how the tree was assembled rather than verifying the construction.

    Does exchange proof of reserves guarantee my funds are safe?

    No. Exchange proof of reserves shows the platform's assets covered customer liabilities at a snapshot, on its own book. It does not prove continuous solvency between snapshots, does not cover undisclosed liabilities, and does not verify the backing of third-party tokens you hold on the platform. It is a meaningful check with clear limits, not a full safety guarantee.

    How does zkDatabase help with proof of reserves for exchanges?

    zkDatabase offers the same Merkle-tree-plus-Zero-Knowledge-Proof construction the top exchanges build by hand, as a ready-made continuous layer. An exchange can use it to reach zero-knowledge-grade proof of reserves without engineering the circuit itself, and because data is committed continuously, the proof can be independently re-verified on demand rather than only at a monthly snapshot.