Exchange Proof of Reserves: Why It Doesn't Protect Your On-Chain Destination Prize

Proof of reserves became a prominent exchange feature after the November 2022 FTX collapse. When it became apparent that FTX had been misusing customer deposits — lending them to its sister trading firm without customer knowledge — the industry scrambled to demonstrate that other exchanges held customer assets in full. Binance, Kraken, OKX, and others published Merkle tree proof-of-reserves attestations showing that customer balances were backed by exchange-held assets. The mechanism was presented as a guarantee of safety. The reality is more qualified, and specifically relevant to any Bitcoin holder who keeps BTC on an exchange with the intention of sending it on-chain for any purpose — including on-chain Bitcoin competition where prizes return to the sending address, which must be a personal self-custody address for the prize to return to the correct person. Bitok Arena Research examined what proof of reserves actually demonstrates and where it falls short.

Bitok Arena Says
Proof of reserves confirms the exchange held customer Bitcoin when the audit snapshot was taken — nothing more. It does not show liabilities beyond customer balances, solvency between snapshots, or the address attribution problem: an exchange sends Bitcoin from its shared hot wallet, not from the customer's personal address. A prize returning to the sending address returns to the exchange, not to the customer.

Proof of reserves, as typically implemented, shows that at the moment the snapshot was taken, the exchange held at least as much of each asset as customers were owed. It does not show what happens between snapshots. It does not show the exchange's liabilities beyond customer balances — loans taken against customer assets would not appear in a pure asset-side attestation. And for Bitcoin holders who want to send on-chain transactions from their personal address, it does not change the fundamental requirement: Bitcoin must be in a personal self-custody wallet for an on-chain transaction to originate from and return prizes to a personal address rather than an exchange's shared infrastructure.

What Proof of Reserves Actually Demonstrates

A complete proof-of-reserves audit using a Merkle tree structure allows any customer to verify that their specific account balance was included in the total liability count that the exchange's on-chain holdings were checked against. The audit has two components: the liability side (total customer balances) and the asset side (total on-chain Bitcoin held by the exchange). If assets meet or exceed liabilities, the exchange is fully reserved at that point in time. The FTX case illustrated that informal attestations of reserve adequacy — and even some formal ones — can fail to reveal the true structure of how customer assets are being used. FTX had made statements about customer asset safety while a related entity had access to customer funds.

Bitok Arena Research

Bitok Arena analysed proof-of-reserves attestations for what they show and what remains unaddressed.

Shows — Asset-to-liability ratio at snapshot date; individual customers can verify their balance was included in the Merkle tree.

Does not show: liabilities beyond customer balances — Loans taken against customer assets may not appear in a pure asset-side attestation.

Does not show: between-snapshot solvency — A quarterly audit says nothing about the other days in the quarter.

Does not address: prize return mechanics — Exchange sends Bitcoin from its shared hot wallet; prizes return to that address, not to the customer.

The connection to on-chain prize return is direct and structural: on-chain Bitcoin competitions track the sending address of each entry transaction and return prizes to that address after the round settles. An exchange sends Bitcoin from its shared hot wallet, meaning the sending address is the exchange's infrastructure address shared by potentially thousands of customers. A prize cannot be returned to one specific customer out of thousands sharing the same sending address — the address belongs to the exchange, not to the customer. Proof of reserves does not change this. It is a separate issue that the attestation does not address and cannot resolve.

Why Self-Custody Is the Structural Solution

Self-custody of Bitcoin before any on-chain transaction where the sending address matters is the single practice that addresses both the exchange risk concern and the prize return mechanism simultaneously. Exchange proof of reserves addresses neither problem completely: it is a point-in-time attestation that reduces but does not eliminate exchange failure risk, and it does nothing about the address attribution problem that prevents direct-from-exchange entries from returning prizes to the correct personal address.

Bitok Arena Research

Bitok Arena documented why self-custody is a structural requirement for on-chain competition, not an optional recommendation.

On-chain competition tracks sending addresses — Prizes return to the sending address after the round settles; the address must be a personal address for the prize to reach the correct person.

Exchange addresses are shared — Bitcoin sent from an exchange originates from the exchange's shared hot wallet; any prize returns to the exchange, not to the individual customer.

Self-custody address is personal — A bc1q address from a personal seed phrase belongs exclusively to the keyholder; prizes return there and nowhere else.

The sequence that actually protects an on-chain Bitcoin competition participant: exchange holds Bitcoin temporarily, participant withdraws to a personal self-custody wallet, participant sends from self-custody wallet to the competition destination. At the moment Bitcoin leaves the exchange and arrives in the personal wallet, exchange proof of reserves becomes irrelevant — the Bitcoin is no longer at the exchange. It is in the participant's own custody. The self-custody wallet sends the competition entry, and the same self-custody address receives the prize. Proof of reserves is a point-in-time attestation about a state that no longer applies once the Bitcoin has been withdrawn.

Using Exchange and Self-Custody Correctly

Exchanges serve a legitimate and important role in the Bitcoin ecosystem: they provide fiat-to-Bitcoin on-ramps, liquidity for buying and selling, and temporary custody during the conversion process. Using an exchange correctly means using it as a transient custody layer for Bitcoin that will be withdrawn to self-custody for actual use — not as a permanent holding solution for Bitcoin intended for on-chain activity. Proof of reserves makes that temporary exchange holding somewhat safer than it would be without the attestation. Moving to self-custody before any on-chain Bitcoin transaction makes the question of exchange solvency irrelevant to the transaction itself.

Bitok Arena Says
Exchange proof of reserves is a snapshot of one moment in the exchange's asset-to-liability ratio. Self-custody is a state where the private key is in the holder's possession and the Bitcoin is under their control. For any on-chain Bitcoin transaction where the sending address matters — including on-chain competition where prizes return to the sending address — self-custody before the transaction is the structural requirement. Proof of reserves does not and cannot substitute for it.

For Bitcoin holders who want to participate in on-chain Bitcoin competition and have their prizes return to their personal address, the workflow has a clear structure: fund a self-custody wallet from an exchange withdrawal, verify the self-custody wallet address is a personal bc1q or bc1p address that only the holder controls, send from the self-custody wallet to the competition destination. At that point, what the exchange holds, what it attests to, and whether its proof of reserves is rigorous are all irrelevant to the competition participation and prize return — because the Bitcoin is no longer there.

Bitok Arena Bottom Line

Bitok Arena's analysis found that proof-of-reserves attestations show asset-to-liability ratio at one snapshot date — not continuous solvency, not hidden liabilities, and not the prize return mechanics that require a personal sending address. Self-custody before the on-chain transaction is the structural solution: once Bitcoin moves from exchange to personal wallet, exchange solvency becomes irrelevant to both the transaction and any prize it earns.

⚡ READ MORE ⚡

Bitcoin competition insights, on-chain strategy, and crypto leaderboard analysis.

BITÓK ARENA
JOIN NOW