Earlier quoted context omitted.
Kraken does at least. AIUI their auditor is given a snapshot of all account balances at a particular point in time, and builds a merkle tree. You can then reconstruct your expected merkle leaf and verify that your specific account was included in the tree. You can verify on the auditor's website, or you can do it by hand. Kraken's help page even has code snippets in Python/Go/etc to make it easy! More info: https://w…
At the bottom of the proof-of-reserves page: > The procedure cannot identify any hidden encumbrances or prove that funds had not been borrowed for purposes of passing the audit. In other words, this is a fancier version of the kind of attestation that Tether makes, the ones that leave loopholes you can drive dump trucks through.
100% and this just drives me bonkers. I'm not entirely unsympathetic to wanting to avoid financial regulation, like while I disagree it's a good idea, I can understand wanting to build a system that is built on math and not people. Fine.
But isn't the whole point of crypto radical transparency? As in: you know at all times where all the coins are and the details of every transaction that has ever occurred? Shouldn't this meet 100% of your auditing needs? Why are audits even useful? Well, they're really helpful if you want to run a shell game off chain, but still assure customers that you're not gambling with their money so they keep giving you more of it.
Like, arguing in good faith here, this is just a worst of both worlds situation. You have an extremely slow financial transaction system that you still have to hand audit.