Proof of reserves, an attestation and a full audit are three different products, and the difference is not rigour but scope and who takes responsibility. A proof of reserves is a cryptographic claim about assets at one moment that you verify yourself. An attestation is a practitioner reporting on a narrow subject matter someone else prepared. An audit is an opinion on financial statements, liabilities included. Knowing which one you are holding tells you which questions it can answer.
Why the three get confused
All three arrive wrapped in the same language of assurance, and marketing rarely distinguishes them because the distinction is unflattering to whichever one is being offered. A platform with a proof of reserves has an incentive to let it sound like an audit; a platform with an attestation has the same incentive.
The confusion is also structurally easy. Each of the three does produce a document, each is periodic, and each says something true about assets. What differs is how much of the picture is in scope, and who is on the hook if the document is wrong.
That second question is the useful one. Assurance is not a feeling, it is a liability structure, and the three arrangements place that liability in three different places.
The three, compared
| Dimension | Proof of reserves | Attestation | Audit |
|---|---|---|---|
| What it covers | Assets at a snapshot moment | A defined subject matter | Financial statements as a whole |
| Who verifies | You, cryptographically | An independent practitioner | An independent auditor |
| Liabilities in scope | Only user balances in the tree | Only if explicitly included | Yes |
| Who is responsible | The platform, for what it published | The practitioner, for the report | The auditor, for the opinion |
| Typical frequency | Monthly | Periodic, by engagement | Annual |
Read the third row first. Whether liabilities are in scope is the difference that decides what the document can tell you about solvency, and it is the row most often skipped.
What a proof of reserves is
A proof of reserves is a cryptographic commitment plus a holdings claim. The platform snapshots user balances, builds a tree over them, publishes a root hash, and shows what it holds on-chain against the total.
Its distinguishing property is that you check it yourself. No third party sits between you and the arithmetic: you take your own proof file, recompute the path, and compare against a published root. That makes it the only one of the three where a user with no professional standing can reach a conclusion independently, which is a genuine strength rather than a consolation prize.
Its limits follow from the same design. It speaks about a moment, about the assets covered, and about balances that went into the tree. A platform's own disclosure page will usually say outright that this is not an audit opinion, and that statement is accurate rather than modest. How to run the checks is in how to verify proof of reserves.
What an attestation adds, and what it does not
An attestation is a report by an independent practitioner on a subject matter that someone else prepared. The subject matter is defined in the engagement, and the practitioner reports on whether the assertion about it is fairly stated.
What it adds is a professional in the loop with a reputation and a standard of care. What it does not add is scope: an attestation covering asset balances at a date covers exactly that, and it is silent about anything the engagement did not name. An attestation about reserves is not an audit of the business, and reading it as one is the most common error in this area.
Attestations also inherit the timing limit. A report about a moment tells you about that moment, so the same snapshot caveat that applies to a proof of reserves applies here too.
What a full audit covers
An audit produces an opinion on financial statements taken as a whole, which is a fundamentally larger claim. Liabilities are in scope by construction, because a balance sheet has two sides and an opinion on it cannot address only one.
That scope is why audits are annual rather than monthly, and why they cost what they cost. They involve sampling, controls testing, confirmations with third parties, and an opinion that carries professional liability. The output is not a number you check; it is a judgement someone is answerable for.
The trade-off is timeliness. An annual opinion about a year that ended months ago answers a different question than a monthly disclosure about balances a few weeks old, and neither is a substitute for the other.
Why a platform might publish one and not another
The honest answer is usually scope and cadence rather than concealment. A monthly cryptographic disclosure is something a platform can operate itself, at a frequency that matches how fast crypto balances move. An annual audit runs on a different clock and covers different ground.
There is also a difference in what each one demands of the reader. A proof of reserves gives you something to do; an audit gives you something to rely on. Platforms serving users who want to check things themselves have a reason to invest in the first, and the ability to check is worth more than the ability to be reassured.
None of that means one replaces another. The most informative position is a platform that publishes a verifiable monthly disclosure and is clear that it is not an audit, which is exactly what the liability discussion in proof of reserves and liabilities is about.
Which one answers your question
Match the document to the question rather than to the reassurance you want. If you are asking whether your balance was counted and whether holdings covered balances at a moment, a proof of reserves answers that and you can confirm it yourself.
If you are asking whether an independent professional reviewed a specific assertion, an attestation answers that, and the thing to read is which assertion was named in the engagement. If you are asking whether the business as a whole is solvent, only an audit addresses that, and even then it addresses the period it covers.
If a platform offers one and you needed another, the gap is information rather than a verdict. What matters is noticing the gap rather than accepting a document as an answer to a question it never asked. The structure behind the first of the three is explained in what is proof of reserves.
The bottom line
Proof of reserves, attestation and audit differ on scope, on who verifies, and on whether liabilities are in the picture. A proof of reserves is the only one you can check yourself, the only one that runs monthly, and the only one that covers assets at a snapshot rather than a full balance sheet.
An audit is the broadest and the slowest; an attestation sits between them and is only as wide as its engagement. None of the three is a version of another, and a platform saying its disclosure is not an audit is stating a fact about scope rather than making an admission. Read for scope first and the rest follows. For more from Bitbase Academy, keep reading.
Disclaimer: This article is educational content from Bitbase Academy, provided for information only. It does not constitute investment, trading, tax, or financial advice. Crypto assets are volatile; assess your own risk. Written as of September 2026; refer to the latest official information.
References
[1] Bitbase, Proof of Reserves — monthly disclosure, Merkle root and open-source verifier www.bitbase.com






