Proof of Reserves Is Not Proof of Clean Funds: What AML Checks Are Still Needed
An exchange publishes its reserve wallet addresses. The balances match the reported snapshot. An auditor or verification provider confirms control of the selected wallets. Customers can verify their inclusion in the liabilities structure through a Merkle Proof. The company announces that its reserves are transparent and fully backed. But none of this shows whether the assets in those wallets arrived from hacks, scams, sanctioned services, mixers, borrowed counterparties, or unscreened customer deposits. The balance confirms that assets exist. It does not confirm that their provenance and AML risk are acceptable.
Proof of Reserves and AML review answer fundamentally different questions. PoR asks: what assets are present and controlled within a defined snapshot and methodology? AML review asks: where did those assets come from, through which wallets and services did they pass, who was the counterparty, and what risk remains now? Financial audit asks: how are assets, liabilities, rights, obligations, and financial position reflected under applicable accounting and assurance standards? Legal review asks: are the assets available to customers, are they encumbered, and how do applicable rules treat them?
The PCAOB (Public Company Accounting Oversight Board) has noted that Proof of Reserves reports may cover asset verification only at a specific point in time and do not necessarily address liabilities, borrowed assets, or subsequent availability.
This article explains what PoR can and cannot demonstrate, how to define the full reserve perimeter, which wallets and transactions need screening, how to verify the source of reserve funds, how to assess acquisition counterparties, how monitoring should work between PoR snapshots, and what to do when material AML exposure is identified. The phrase "clean funds" is used in the title as a common search term — in the body, the more accurate framing is acceptable AML risk, assessed reserve assets, documented provenance, or no material identified high-risk exposure.
What Proof of Reserves Can Actually Demonstrate
Existence and Control of Included Assets
Depending on the methodology, PoR may help confirm the presence of specified assets, balances on specified wallets or custody accounts, the entity's ability to sign a message or otherwise demonstrate control, inclusion of a wallet in the reported reserve set, the amount held at a specified date, time, or block, assets included under the stated methodology, and — where a Merkle Tree or equivalent is used — a customer's ability to verify their inclusion in the liability structure.
Several important qualifications apply. Only the defined scope is verified — unidentified or excluded wallets are not automatically covered. Control of one key or address does not always reveal legal ownership. A custody provider may control keys operationally while assets are held for another entity. And "assets observed" and "assets available for customer withdrawals" are not always the same conclusion.
Relationship Between Reserves and Included Liabilities
Some PoR models compare reserve assets with customer liability data. Liability inclusion may use Merkle Trees or other commitments, but the completeness of liabilities depends on the methodology, records, and controls used. A PoR that shows only assets is not proof of solvency. Even an asset-to-liability ratio does not necessarily reveal other corporate liabilities, contingent obligations, loans, or encumbrances. The engagement scope must be read carefully. AML review does not replace liabilities verification, and liabilities verification does not replace AML review.
A Point-in-Time Position
PoR typically relates to a specified snapshot. Assets may have arrived shortly before the snapshot. They may be moved, loaned, pledged, or withdrawn afterward. Wallet risk and attribution can change after publication. Subsequent inflows may have different provenance. A verified reserve address today does not guarantee an identical balance or risk profile tomorrow.
What Proof of Reserves Does Not Show About AML Risk
- Where the reserve assets came from. A PoR balance does not automatically show whether assets were received through customer deposits, treasury purchases, OTC trades, market makers, loans, affiliated entities, token issuance, staking rewards, DeFi positions, collateral liquidations, asset recovery, acquisition of another business, or transfer from an undisclosed internal wallet. An identical balance can have completely different provenance.
- What the assets touched before entering the reserve wallet. Even if the immediate sender is an exchange, custodian, OTC desk, market maker, treasury wallet, or related company, the funds may have earlier exposure to hacks, scams, stolen assets, sanctioned addresses, mixers, darknet services, ransomware, fraud networks, unregulated services, or high-risk cross-chain routes. The immediate counterparty and the full source path are different layers.
- Whether the assets remain low-risk. Risk can change because an address receives new inflows, reserve funds are moved through another wallet, a counterparty is later sanctioned, a previously unknown address is attributed to a hack or fraud cluster, a historical transaction receives new entity attribution, reserve assets are deployed into DeFi, or an internal wallet becomes connected with unscreened customer funds. A low-risk result at the publication date is not a permanent status.
- Whether all reserve wallets belong to the same risk perimeter. A published reserve set may not show deposit wallets, temporary transit wallets, settlement wallets, internal treasury wallets, off-exchange balances, third-party custody accounts, staking or DeFi contracts, wrapped assets on other chains, wallets added after the snapshot, or assets moving between affiliated entities. AML review must establish the full operational perimeter — not screen only the addresses published on a PoR page.
Start with a Complete Reserve-Asset Inventory
Directly controlled on-chain wallets. Build an inventory of cold wallets, hot wallets, treasury wallets, omnibus wallets, settlement wallets, withdrawal wallets, deposit consolidation wallets, operational liquidity wallets, staking wallets, collateral wallets, chain-specific reserve wallets, and emergency or recovery wallets. For each wallet, record the blockchain, address, asset, function, owner or responsible entity, key-control arrangement, custodian if applicable, date added, relationship to the PoR calculation, whether customer and corporate assets are commingled, and expected inflow and outflow types.
- Third-party custody and off-platform assets. If reserves are held by an institutional custodian, another exchange, a broker, bank, qualified custodian, fund administrator, or affiliated company, record the legal account holder, beneficial ownership, custodian agreement, assets and amounts, withdrawal rights, restrictions, pledged or encumbered status, sub-custodian structure, whether blockchain addresses are disclosed, how AML screening is performed, and who monitors subsequent movements.
- Token, chain, and contract-level positions. The inventory must account for native assets, stablecoins, wrapped assets, token contract addresses, chain and chain ID, bridged versions, staking derivatives, LP tokens, vault shares, tokenized treasury assets, assets locked in smart contracts, pending bridge transfers, and assets represented by receipt tokens. An identical ticker does not mean the same asset or the same risk.
- Internal transfers and temporary wallets. Maintain a mapping of source wallet, destination wallet, reason for transfer, amount, timestamp, approval, whether the address remains active, whether the wallet participates in the next PoR snapshot, whether the transaction was screened, and whether the balance was temporarily held for a snapshot, settlement, or security operation.
Screen Reserve Wallets for Current AML Exposure
For each material reserve wallet, check sanctions status, direct exposure to designated addresses, links to stolen or exploit-related funds, fraud and scam exposure, mixer exposure, darknet or ransomware exposure, high-risk exchange or service exposure, direct and indirect connections, named entities, source and destination distribution, transaction behavior, recent risk changes, historical incidents, and exposure percentage and amount where available. Evaluate not only the current balance but also how assets entered, what left, whether risky funds remain, whether the wallet regularly receives unscreened inflows, and whether risk originates from one isolated transaction or a repeated pattern.
Verify the Source of Reserve Funds
This section focuses on the reserve-specific dimension.
- Customer deposits added to reserves. If the reserve wallet includes aggregated customer deposits, verify whether deposits were screened before consolidation, whether high-risk deposits were isolated, whether deposit addresses are mapped to customer accounts, whether material reserve inflows can be traced back to accepted deposits, whether decisions and alerts are retained, whether rejected or frozen funds were excluded or separately identified, whether customer and corporate assets are commingled, and whether the business can reconstruct origin after sweeping deposits into an omnibus wallet.
- Treasury purchases and OTC acquisitions. Record the counterparty, KYB result, trade confirmation, asset, amount, price, settlement addresses, payment source, transaction hashes, ownership of the sending wallet, sanctions and adverse-information checks, reason for the transaction, and whether the counterparty acts as principal or intermediary.
- Loans, credit, and temporarily transferred assets. Verify the lender, loan agreement, maturity, collateral, right to use assets, repayment obligation, source wallet, transaction path, whether assets are included in the reserve calculation, whether the methodology clearly explains borrowed or encumbered assets, and whether the counterparty and funds were AML-screened.
- Staking, rewards, DeFi, and protocol income. Record the protocol, smart contracts, deposited assets, receipt tokens, reward addresses, transaction paths, timing, protocol risk exposure, sanctions and exploit history, whether funds passed through commingled pools, and how valuation and ownership are established.
- Transfers from affiliates or related companies. Verify the legal relationship, beneficial owners, purpose of transfer, intercompany agreement, source wallet, origin before the affiliate, whether the transfer represents capital, loan, settlement, or custody movement, counterparty jurisdiction, sanctions and adverse information, and whether the affiliate conducted equivalent AML screening. A transfer from a group company does not reset blockchain provenance.
Perform KYB and Counterparty Due Diligence on Reserve Acquisition
On-chain screening of reserve wallets should be complemented by verification of the parties through which assets were acquired or are held. Check relevant OTC desks, brokers, market makers, lenders, custodians, exchanges, liquidity providers, token issuers, affiliated companies, treasury managers, and DeFi service operators where identifiable. A reputable counterparty reduces uncertainty but does not replace transaction screening. A clean wallet result does not replace KYB. A licensed counterparty does not guarantee that every transferred asset has acceptable provenance.
Screen the Transactions That Build and Move the Reserves
- Inbound reserve transactions. For material inflows, check the sending address, transaction hash, source of funds, asset, amount, counterparty, transaction type, sanctions and risk screening result, screening date, and consistency with the documented source-of-funds record.
- Internal and outbound reserve movements. For material transfers between reserve wallets or from reserve wallets to exchanges, DeFi protocols, bridge contracts, or external counterparties, check the destination address, transaction purpose, authorization, consistency with reserve policy, whether the destination is screened, and whether the movement changes the reserve composition or perimeter.
- Transactions near the PoR snapshot. Large or unusual inflows or outflows within a short window around the snapshot date require particular attention — not because all pre-snapshot activity is suspicious, but because the snapshot captures a single moment, and material movements around that moment may affect the representativeness of the balance.
What Should Happen When Material AML Exposure Is Found in Reserves
A high-risk result on a reserve wallet or transaction is a starting point for analysis. The business should confirm the specific alert, determine how the flagged assets entered the reserve perimeter, assess whether the flagged assets remain in the current balance, review linked wallets and counterparties, evaluate any sanctions or reporting implications, apply proportionate controls, and document the impact on the reserve calculation and disclosures.
Not every historical exposure requires the same response. A small, old, indirect exposure through a large exchange has different significance than a recent direct receipt of freshly stolen assets.
Ongoing AML Monitoring Between PoR Snapshots
A PoR snapshot captures reserve status at one moment. Between snapshots, reserve wallets continue to receive deposits, process withdrawals, interact with counterparties, and move funds through internal infrastructure. Risk does not pause between publication dates. Wallet risk can change through new sanctions designations, newly attributed exploit or fraud clusters, and entity relabeling. Transaction flows can introduce new exposure through large OTC purchases, new custody arrangements, affiliate transfers, and DeFi deployments. Reserve architecture can change through new wallets, retired wallets, changed custody providers, added chains, and modified bridge routes. Active reserve wallets should be monitored continuously or re-screened according to a documented risk-based schedule.
A Note on "Clean Funds"
The expression "clean funds" is a simplification. AML screening does not issue an absolute certificate of cleanliness, does not prove the legality of each asset, evaluates known risk exposure based on available data, and helps the business make a documented, risk-based decision. The appropriate language is: assessed reserve assets, documented provenance, no material identified high-risk exposure, risk-screened reserves — not "certified clean reserves."
Conclusion
Proof of Reserves can help demonstrate that specified assets exist within a defined perimeter at a specified time. It does not demonstrate where those assets came from, what services they passed through, who supplied them, or whether they carry sanctions, theft, fraud, or other high-risk exposure. AML screening of reserve wallets, transactions, counterparties, and source-of-funds documentation is a separate process that answers a separate question. An exchange or custodian that publishes a PoR report without addressing the provenance and risk profile of its reserve assets has answered the existence question but not the origin question. And for regulators, auditors, banking partners, institutional clients, and increasingly for retail users, the origin question matters as much as the balance.
FAQ
Does Proof of Reserves Prove That Crypto Funds Are Clean?
No. Proof of Reserves may show that specified assets exist and are controlled within a defined snapshot, but it does not automatically show where those assets came from or whether they have sanctions, theft, fraud, mixer, or other high-risk exposure. AML screening and source-of-funds review are separate processes.
What Is the Difference Between Proof of Reserves and AML Screening?
Proof of Reserves focuses on the existence and, depending on the methodology, control and coverage of reserve assets. AML screening analyzes wallet history, transaction routes, counterparties, sanctions exposure, source of funds, and changes in risk over time.
Can a Crypto Exchange Have Sufficient Reserves That Carry High AML Risk?
Yes. An exchange may hold enough assets to meet the liabilities included in its PoR methodology while some reserve assets still have material exposure to stolen funds, sanctioned addresses, scams, mixers, or unscreened deposits. Financial sufficiency and AML provenance are different questions.
Which Reserve Wallets Should Be Screened?
The review should cover more than publicly disclosed cold wallets. Depending on the business, it may include hot wallets, treasury wallets, omnibus wallets, deposit-consolidation wallets, settlement wallets, staking addresses, custody accounts, bridge wallets, and other addresses that build or move reserve assets.
What Is Source of Reserve Funds?
Source of reserve funds is the documented origin of assets included in a business's reserve perimeter. The assets may come from customer deposits, treasury purchases, OTC transactions, loans, affiliated entities, staking rewards, DeFi activity, token issuance, or other business operations.
Are Reserve Wallet AML Checks Needed Only on the PoR Snapshot Date?
No. A snapshot check can become outdated after new transactions, sanctions designations, exploit attributions, or changes in wallet ownership and infrastructure. Active reserve wallets should be monitored continuously or re-screened according to a documented risk-based schedule.
Does a High-Risk Reserve Wallet Mean All Reserve Assets Are Illicit?
No. A high-risk result is a signal requiring analysis. The business should examine the risk category, amount, directness, timing, current balance, transaction path, wallet function, and attribution confidence. Historical or indirect exposure may not have the same significance as direct receipt of recently stolen assets.
Should Counterparties That Supply Reserve Assets Be Checked?
Yes. Exchanges and custodians should apply KYB and sanctions checks to relevant OTC desks, brokers, market makers, lenders, custodians, affiliates, and other counterparties that provide or hold reserve assets. Counterparty due diligence should be combined with on-chain transaction screening.
What Should a Business Do If High-Risk Funds Are Found in Its Reserves?
The business should confirm the alert, identify how the assets entered the reserve perimeter, determine whether the funds remain in the current balance, review linked wallets and counterparties, assess any sanctions or reporting implications, apply proportionate controls, and document the impact on its reserve calculation and disclosures.
Can a Business Claim That Its Reserves Are AML-Certified?
It should avoid broad claims such as "AML-certified," "completely clean," or "zero illicit exposure." A more defensible statement defines the wallets, assets, date, screening method, risk threshold, limitations, and ongoing monitoring process used for the review.