VERSE PRESS

Crypto News, Global First.

Exchange Reserves Are Still a Black Box for Most Users. Here Is What That Costs.

A Polish exchange collapse, a Pakistani regulatory first, and a cryptographic tool that most platforms still do not use correctly.

|

A Poland-based crypto exchange lost 99.7% of its Bitcoin holdings over approximately 20 months without its approximately 30,000 users knowing. That event, the April 2026 collapse of Zondacrypto, is the clearest recent demonstration that proof of reserves (PoR), the industry's primary answer to exchange transparency, remains unevenly adopted, with some platforms lacking any meaningful implementation at all. As regulators in Pakistan, Nigeria, and South Africa move to codify reserve requirements, the gap between what PoR promises and what it actually delivers is becoming a practical concern for retail users across emerging markets.

What Happened at Zondacrypto

On-chain forensics firm Recoveris documented that Zondacrypto's Bitcoin hot wallet dropped from 55.7 BTC in August 2024 to as low as approximately 0.086 BTC across March and April 2026. Recoveris identified 511 transfers totalling approximately $21 million flowing from Zondacrypto wallets to a single Kraken deposit address across six networks between December 2025 and April 2026. The correlation between stablecoin outflows and user complaints registered a Pearson coefficient of 0.92, meaning the on-chain bleed and customer distress were nearly perfectly synchronized.

When the exchange's CEO cited a 4,500 BTC wallet as proof of solvency, the claim unraveled quickly. According to a Disruption Banking investigation, the CEO admitted the exchange could not access those coins because the private key belonged solely to founder Sylwester Suszek, who had disappeared in 2022 after selling the exchange in 2021. Zondacrypto is the most significant European exchange failure since the collapse of FTX in November 2022. FTX was a Bahamas-registered exchange that unraveled after CoinDesk reporting revealed that its affiliated trading firm, Alameda Research, held a balance sheet heavily concentrated in FTT, FTX's own exchange token. That structure concealed an $8 billion customer fund shortfall and made plain exactly why independent, on-chain reserve visibility matters.

What Proof of Reserves Actually Is

Proof of reserves is a cryptographic auditing method. On the liability side, an exchange compiles all customer balances into a Merkle tree: a data structure that hashes individual balances together into a single verifiable fingerprint. Each user can check whether their own balance appears correctly in that tree. On the asset side, the exchange signs messages from its wallets, proving it controls the addresses holding customer funds.

The limitation is that this snapshot approach only captures one moment in time. PwC's digital assurance team has argued that PoR does not provide meaningful trust and transparency because it ignores off-balance-sheet liabilities, lacks standardized audit procedures, and produces results that vary so widely across firms that they cannot be meaningfully compared. PwC advocates instead for full financial statement audits under SOC1/ISAE 3402 Type 2 reports.

The more advanced version of PoR uses zero-knowledge proofs, a cryptographic technique that lets an exchange prove all balances are non-negative and correctly summed without revealing any individual account. Ethereum co-founder Vitalik Buterin described the approach plainly: "The simplest thing we can do is put all users' deposits into a Merkle tree and use a ZK-SNARK to prove that all balances in the tree are non-negative and add up to some claimed value." Several leading exchanges now publish implementations at varying levels of sophistication and frequency. Binance publishes monthly attestations using zk-SNARKs. OKX uses a related zk-STARK variant. Backpack runs recursive proofs refreshed daily. Kraken has operated a cryptographic PoR program since 2014, the longest continuous program in the industry. Overcollateralization figures from recent third-party audits show further variation: MEXC showed 135% Bitcoin overcollateralization in a December 2025 Hacken audit, while Phemex reported 131% across major assets in April 2026.

Why This Matters More Outside the United States

Sub-Saharan Africa processed $205 billion in on-chain volume between July 2024 and June 2025, a 52% year-on-year increase, according to Chainalysis. Stablecoins account for 43% of that volume, used primarily as dollar substitutes for remittances and inflation protection. Nigeria alone recorded $92.1 billion in on-chain transactions. These are not institutional traders hedging portfolios. They are retail users storing household savings in exchange-held stablecoins, and the data supports that characterization directly: Sub-Saharan Africa's retail transfer share (transactions under $10,000) stands at 8% of total volume, meaningfully above the global average of 6%, according to Chainalysis. A Zondacrypto-scale failure in Lagos, Nairobi, or Accra would cause direct material harm to everyday finances.

Regulators in the region are responding at different speeds, and it is worth mapping where each jurisdiction sits on the compliance spectrum. Pakistan has moved furthest. The Virtual Assets Act 2026 explicitly mandates that exchanges file cryptographic proof of reserves reconciled against customer liabilities with the Pakistan Virtual Asset Regulatory Authority (PVARA), verified by Chartered Accountants annually. That makes Pakistan one of the first jurisdictions anywhere to treat PoR as a legal filing requirement rather than a voluntary best practice. Nigeria occupies a middle position: its Securities and Exchange Commission requires licensed exchanges to submit solvency undertakings and periodic third-party audits under the Investments and Securities Act 2025, with a minimum capital requirement of 2 billion naira and a compliance deadline of June 30, 2027. South Africa's FSCA requires independent audits as part of its Crypto Asset Service Provider licensing regime, but stops short of mandating cryptographic reserve proofs. India, with tens of millions of crypto users, has no comparable PoR mandate yet under its Financial Intelligence Unit (FIU-IND) registration framework, the country's current primary mechanism for bringing virtual asset service providers into regulatory scope.

What Comes Next

Researchers and developers are now working on what they call Proof of Solvency: a framework that verifies both assets and liabilities simultaneously, closing the loophole that allows an exchange to hold sufficient reserves while carrying hidden debts elsewhere. One specific academic proposal, LPOR (Layered Proof of Reserves), formalised in a 2025 arXiv paper (arXiv:2606.08211), attempts to codify this layered approach to reserve verification in a rigorous technical standard. At the regulatory level, EU markets are expected to see minimum PoR standards under the Markets in Crypto-Assets Regulation (MiCA), the EU's comprehensive crypto licensing framework, within 18 months from mid-2026, according to industry analysts. The U.S. CLARITY Act is tracking a similar timeline.

For users on exchanges that already offer Merkle tree verification, Kraken and Binance both provide tools to check whether your individual balance appears correctly in a published proof. Using them costs nothing and takes minutes. Given what happened in Poland, that is a reasonable two minutes to spend.