The on-chain half of proof of reserves is the part anyone can check without permission. Balances are public, signatures demonstrate control, and transfers are permanent. What the chain never shows is exclusivity, because a balance is a fact about a ledger while a claim against that balance lives in an agreement nobody published.
What the chain actually shows
A public chain is a record of balances and the transfers that produced them. Anyone can query it, nobody needs an account, and the answer does not come from the party being examined. In a field where most claims are self-reported, that is unusual enough to be worth stating plainly.
It is also complete within its own scope. Every transfer that ever settled is there, in order, with amounts, and nothing can be quietly removed later. A reader who wants to see whether a balance existed at a particular block does not have to take anyone's word for it.
One consequence is worth keeping in mind while reading any disclosure: the chain is authoritative about quantities and silent about intentions. But the scope is narrower than it feels. The chain records what moved and where it sits; it does not record why, who ultimately owns it, or what somebody promised about it elsewhere.
Visible on chain and not visible
| The chain shows | The chain does not show |
|---|---|
| The balance at an address | Whether those coins are borrowed |
| Every historical transfer | Why a transfer happened |
| That a key signed a message | Whether one party alone holds that key |
| When funds moved | Whether they moved for the snapshot |
| That two addresses interacted | Whether they belong to the same entity |
| Contract code and its state | Off-chain agreements about the same assets |
Every row on the right is a real question about reserves, and none of them can be answered by better on-chain tooling. They are not gaps in the data; they are outside the data entirely.
How address ownership is proven
Publishing an address proves nothing on its own. Anyone can point at a wallet that holds a large balance and claim it, which is why an address list alone is a weaker artefact than it appears.
The demonstration that matters is a signature. The exchange signs an agreed message with the private key of each address, and anyone can verify that signature against the address's public key. Because spending also requires that key, the signature demonstrates the same capability that spending would, without moving anything.
The same reasoning explains why the addresses have to be published before the balances are read rather than chosen afterwards. A list assembled after the fact could be selected to look good, and the order of the two steps is what removes that possibility. That is why a message and a timestamp are usually included in what gets signed. Without them a signature could be replayed from an earlier occasion, so the content of the signed message is part of what makes the proof current rather than merely valid. Running this check is covered in how to verify proof of reserves.
Why a signature is not the same as exclusive control
A valid signature says somebody used the key. It does not say only one party can use it, and it does not say the assets under it are free of obligations to anyone else.
Two situations make this concrete. Coins can be borrowed shortly before a snapshot and returned after, producing signatures that are entirely genuine at a moment that was arranged. And the same assets can be pledged as collateral under an agreement that never touches a chain, so the balance is real, the signature is real, and a third party still has a claim on it.
There is also a subtler version in which nothing is borrowed at all and the assets simply belong to a group of entities whose internal arrangements are private. Neither case can be detected from the chain, because the chain has no field for encumbrance. This is the limit that survives every improvement in tooling, and it is one of the structural gaps set out in the limitations of proof of reserves.
What address clustering can and cannot tell you
Analysts often try to work out which addresses belong to the same operator by studying how funds move between them. Common spending patterns, consolidation behaviour and timing all leak information, and the results are frequently informative.
They are also inferences rather than proofs. An address can be used by a custodian on behalf of many clients, funds can pass through a shared service, and a cluster can be built or broken deliberately by anyone who understands how clustering works.
Clustering also degrades over time as operators change how they manage wallets, so a model that was accurate a year ago may be describing a structure that no longer exists. For a reader, this means treating third-party attribution as a useful cross-check and not as an independent confirmation. It is most valuable when it disagrees with a published list, because a disagreement is a question worth asking rather than an answer in itself.
How to run the on-chain half yourself
Take the published address list and read the balances at the stated snapshot height rather than today. A block explorer will do this, and using the stated height is what makes your reading comparable to the report's.
Then verify the signatures. Each one should be checkable against the address it claims and should contain the message the report says was signed, and a signature that verifies against a different message is not the same evidence.
Finally, look at movement around the snapshot. Large inflows shortly before and matching outflows shortly after are visible to anyone, and while they have innocent explanations, they are exactly the pattern worth asking about. What the assets themselves are made of is a separate quality question, taken up in crypto exchange reserve composition.
What the on-chain half is worth
It is the only part of the whole exercise that requires trusting nobody. That property is rare in finance and it should not be undersold because of what surrounds it.
It is also the half that answers the question people used to have no way of asking. Before public chains, whether a custodian held anything at all was simply unobservable, and the fact that it is now a query rather than a request is the actual advance here.
It is worth being precise about which of the three it actually settles, because vagueness here is what allows the whole disclosure to be oversold. The honest summary is that on-chain verification settles existence and control, narrows timing questions, and leaves exclusivity untouched. Two out of three, checkable by anyone, is a strong result as long as nobody claims it was three.
The bottom line
On-chain verification confirms that specific assets existed at specific addresses at a stated moment and that whoever published the report could sign for them. It says nothing about whether those assets were borrowed, pledged, or shared with someone whose claim never appeared on a chain.
Read it as the strongest and most independent part of a disclosure, and read the exclusivity question as something that needs a different kind of evidence entirely. For more from Bitbase Academy, keep reading.
Disclaimer: This article is educational content from Bitbase Academy, provided for information only. It does not constitute investment, trading, tax, or financial advice. Crypto assets are volatile; assess your own risk. Written as of September 2026; refer to the latest official information.
References
[1] Bitbase, Proof of Reserves — monthly disclosure, Merkle root and open-source verifier www.bitbase.com






