Every month, exchanges publish their proof of reserves. If large sums suddenly flow in right before the snapshot, the numbers can look better for a short while. But this makeup won't survive the next scheduled audit, and on-chain traces can't stay hidden.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
If you see an address receive a huge deposit just before the snapshot, don't rush to call the platform a fraud. Walk through the steps below to check for yourself – only then can you tell if it's a one-off user action or a deliberate attempt to pad the books.
Step 1: Lock Down the Exact Snapshot Time and the Public Addresses
What to do
Get the exact block height or UTC time of the proof-of-reserves snapshot announced by the exchange, together with its official list of cold and hot wallet addresses.
How to do it
- Log in to Binance or OKX, find the Proof of Reserves page. Usually, the snapshot time and the matching block height are shown right at the top.
- Copy every public address listed on that page. Pay special attention to addresses marked as used only for the proof – don't focus only on deposit addresses.
- If you don't have an account yet, you can still see this data in the audit section after signing up.
Done when
You have a record containing the exact snapshot time, the block height, and the full address list. A screenshot works well.
Risk reminder: Some small platforms intentionally publish an incomplete address set, keeping borrowed funds in undisclosed addresses and moving them out after the snapshot. Looking only at the few addresses shown on the website won't catch this. You must demand the full Merkle tree proof data; otherwise, treat the disclosure as invalid.
Step 2: Use On-Chain Tools to Trace Net Flows Around the Snapshot
What to do
Define a window from 24 hours before the snapshot to 6 hours after it, then calculate the net inflow for each public address.
How to do it
- Use Arkham Intelligence, Nansen, or OKLink. Enter the addresses from Step 1 and filter by the time window.
- Watch for two red flags: single transfers over $5 million within 2 hours before the snapshot, and outflows of the same size within 1 hour after the snapshot. If several large deposits are sent back along the exact same path right after the snapshot, it's almost certainly temporary fund injection.
- Export the inflow/outflow data as CSV. Use a simple sum formula to get the net inflow, then compare it with the total reserve increase the exchange claims.
Done when
You can clearly state: during that period around the snapshot, how much BTC, ETH, and USDT the address group gained or lost on net, and whether it matches the reserve increase the platform announced.
Common mistake: Many newcomers mistake an exchange's internal consolidation transfers for external deposits and think every large on-chain move is foul play. In reality, normal transfers from hot wallets to cold wallets also create many transactions.
The correct approach is to only look at the interaction between known user deposit addresses and the public proof addresses. Ignore internal transfers between wallets that carry the same platform label.
Step 3: Use Merkle Tree Data to Check If Your Own Assets Are Included
What to do
Through the Merkle tree proof provided by the exchange, confirm that your own account balance really was part of the snapshot. If your balance is missing or doesn't match, the reserve numbers, no matter how pretty, mean nothing for you.
How to do it
Case A: You have a Binance account
- Go to the Proof of Reserves page, find the verification tool, and enter your account ID and the asset snapshot record.
- Binance will return a hash path. You can run the SHA-256 algorithm yourself to match it against the public Merkle tree root hash.
- Check the official audit report to make sure the root hash signed by the auditor matches the one published on-chain.
Case B: You have an OKX account
- Go to the audit page and download the file with your personal asset snapshot data.
- OKX provides an open-source verification tool. Find the code on GitHub, run it locally, and input your asset hash and sibling nodes from the file to obtain the root hash.
- Compare it with the root hash stored on-chain. If they match, your assets were correctly counted in the total liabilities snapshot.
Done when
The root hash you computed locally matches the one the exchange published on-chain, and you can find that same root hash in the audit report. Only then is your personal asset inclusion confirmed, and the snapshot data truly meaningful.
If a platform only reveals total reserves without a Merkle tree proof, you have no way to verify whether your own liability is covered. In that case, even a sky-high reserve ratio is not trustworthy.
Step 4: Check If the Auditor Is Independent and Whether the Data Updates Consistently
What to do
Judge the independence of the audit report and how often it is refreshed. This keeps you from being misled by a single round of dressed-up data.
How to do it
- Look up the accounting firm's name. Does it have a global reputation? If the auditor is a tiny firm nobody has heard of, or if the platform hired a security team that only checked on-chain balances, the proof carries far less weight.
- Look at every snapshot report from the past six months. Compare how total reserves and total liabilities changed across reports. If total reserves suddenly jump 30% in one report and then drop right back in the next, it's very likely that money was borrowed just for the snapshot.
- Check whether the exchange writes the Merkle tree root hash into a public blockchain transaction. Only a hash stored on-chain cannot be secretly changed later. JSON files displayed on a website can be swapped at any time.
Done when
You can draw a trend line of reserve changes for the past half year, and confirm that each data point has an independent audit, a hash on-chain, and a fluctuation range that makes sense.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
FAQ
Q1: Can exchanges know the snapshot time in advance and borrow funds precisely for it?
Some exchanges use a random snapshot mechanism. In theory, the time is unpredictable. But the random algorithm is rarely fully open-source, so users cannot verify this claim. There is no verifiable data showing that the random snapshot code of major platforms has passed a third-party audit, so leaks or fixed-interval manipulation are still possible.
Q2: Some platforms claim they hold excess reserves. Does that make snapshot tricks irrelevant?
Excess reserves only mean that at the snapshot moment, assets exceed liabilities. It doesn't rule out temporary padding right before. If a platform borrows $50 million and returns it immediately after the snapshot, the reserve ratio might look like 120%, but the actual share of assets backing user funds hasn't changed. Only continuous, verifiable Merkle tree proofs combined with on-chain flow analysis can rule out short-term cosmetics.
Q3: I have no technical background. Is there a simple tool to spot if data has been dressed up?
Use exchange asset dashboards like Nansen or Arkham. Look directly at the 24-hour net flow of exchange reserves. If a snapshot day shows an abnormal spike in net inflows, followed by an almost identical net outflow the very next day, it's very likely a temporary move. These tools filter out internal consolidation transfers automatically, making them suitable for non-technical users.
Next, you can compare the conclusions you verified with the next snapshot's data. Usually, wait one month and then check the new proof-of-reserves page and the on-chain net inflow indicators. If data for two consecutive periods is stable, the Merkle tree root is consistent, and the auditor hasn't changed, then the pre-snapshot fund inflows didn't systemically dress up the numbers. You can then include the exchange in your regular safety monitoring.


