Crypto.com released a Mazars proof-of-reserves report on December 9, 2022, presenting evidence that the exchange controlled at least as much of nine specified crypto assets as it owed customers at a defined snapshot.
The report placed the exchange’s reserve ratios between 101% and 106% as of 00:00:00 UTC on December 7. Its publication was consequential because centralized trading platforms were under intense pressure to demonstrate custody and balance-sheet discipline after FTX entered bankruptcy proceedings on November 11.
The narrow result mattered, but so did the boundary around it: Mazars called the work an agreed-upon-procedures engagement, not a financial audit, and expressed neither an audit opinion nor an assurance conclusion.
What Mazars examined
The engagement covered BTC, ETH, USDC, USDT, XRP, DOGE, SHIB, LINK and MANA held in customer spot and margin accounts across eight named blockchain networks. Mazars reported reserve ratios of 102% for BTC, 101% for ETH, 102% for USDC, 106% for USDT, 101% for XRP, 101% for DOGE, 102% for SHIB, 101% for LINK and 102% for MANA.
Each percentage divided the nominal quantity of an asset that Crypto.com reported controlling by the corresponding net customer liability in that asset. These were asset-unit ratios, not dollar-valued capital ratios. Mazars did not disclose the nominal quantities of either the assets or liabilities, citing confidentiality.
Mazars obtained the wallet-address list and asset reports from Crypto.com management, then independently retrieved the balances of those addresses from their respective blockchains. It also directed movements from the listed addresses and verified the resulting transaction hashes, corroborating the company’s control of the associated private keys at the snapshot.
How customer liabilities were tested
The liability side depended on Crypto.com’s internal records. Mazars inspected management’s extraction scripts, observed management query the production database and performed row-count and sum checks on the resulting customer-liability report. The underlying data showed a latest update time of 23:59:59 UTC on December 6.
Mazars then generated a Merkle root from the customer data. That structure allowed an individual customer to verify cryptographically that the customer’s record was included in the liability dataset without exposing every other account balance. It did not enable the public to inspect the complete liability ledger or independently prove that every eligible account had been included.
The report also noted that its liability data did not distinguish the nine assets between native and non-native blockchains. For the engagement, balances on different supported networks were therefore assessed interchangeably within each asset class.
What the report did not establish
The engagement was performed under ISRS 4400, which requires the practitioner to report the factual results of procedures agreed with the client. Mazars explicitly said it made no representation about whether those procedures were appropriate and that no independence requirement applied to the engagement.
Its findings covered only the nine in-scope assets and the December 7 snapshot. The report did not examine subsequent transactions or balances, publish a complete corporate balance sheet, value assets against liabilities in a common currency, assess liquidity under a withdrawal surge or disclose Crypto.com’s corporate debts and contingent obligations.
Those limits meant “fully reserved” had a specific definition: the in-scope crypto assets controlled by Crypto.com were at least equal in nominal units to the corresponding net customer liabilities contained in the examined report. It did not mean Mazars had certified the solvency of every Crypto.com entity or guaranteed that every customer obligation could be met under every market condition.
The event-day conclusion
On December 9, the defensible conclusion was that Crypto.com had submitted nine asset categories to an external, documented matching process and published ratios exceeding 100% at one timestamp. That offered customers more evidence than unsupported corporate assurances and introduced a mechanism for verifying inclusion in the liability set.
It remained a point-in-time transparency exercise rather than comprehensive financial assurance. Contemporaneous reporting recognized both sides of that record: the published ratios showed excess in-scope assets, while accounting specialists cautioned that the procedure was not an audit. The distinction was central to evaluating what proof of reserves could—and could not—resolve during the institutional trust crisis of December 2022.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

