Proof of reserves and insurance funds: what 37 crypto venues actually have
13 of 37 venues publish proof of reserves and hold an insurance fund; 9 have neither. But each phrase covers four different things — self-funded reserves, real third-party policies, narrow guarantees, and buffers that aren't insurance at all.
Thirteen of the 37 venues we track publish proof of reserves and hold an insurance fund. Nine have neither. But the interesting part isn't the count — it's that both phrases mean four different things each, and nobody tells you which one they're using.
We check every venue against five criteria, two of which are exactly these. So we have the underlying answers written down for all 37. This is what they look like laid side by side.
The count first
| Venues | |
|---|---|
| Publish proof of reserves | 25 of 37 |
| Hold an insurance fund | 16 of 37 |
| Both | 13 |
| Neither | 9 |
As assessed on 28 July 2026. Every check on our platform pages carries its written justification and a source link.
"Insurance fund" is four different things
Here is where the checkbox stops being useful. Sorted by what they actually are:
1. A self-funded reserve the venue controls. Binance's SAFU is $1B+ with public reserve addresses. Bitget runs a $600M+ Protection Fund. Bybit's is $400M+, updated monthly. MEXC's Guardian Fund is $100M. These are real money, publicly addressed — but the venue owns them and decides when they pay. Gate.io is admirably blunt about it: its SAFU is "not third-party insured, but of public size."
2. Actual third-party insurance. Coinbase carries a Lloyd's of London policy ($255M) plus FDIC coverage up to $250,000 on USD balances. Nexo's $775M runs through BitGo and Ledger Vault, covering hot-wallet assets. This is the only category where someone outside the venue is contractually on the hook.
3. A narrow guarantee that looks broader than it is. Bitvavo reimburses up to €100,000 per account — but only for unauthorised-access incidents. That is a real protection and a good one. It is not a fund that pays you if the venue fails.
4. Not insurance at all. Lido, Rocket Pool, StakeWise and Marinade are grouped under the same checkbox, and none of them hold a fund in the ordinary sense. Rocket Pool node operators bond RPL against slashing. StakeWise caps minting at 91.5% LTV so overcollateralisation absorbs losses. Marinade uses validator bonds covering downtime. These are structural buffers against a specific technical failure, not a pot of money for when things go wrong.
If you were comparing "has insurance: yes" across those four, you were comparing nothing.
The biggest funds are not on the safest venues
| Venue | Fund | Our grade |
|---|---|---|
| Binance Earn | $1,000M | C |
| Nexo | $775M | C |
| OKX Earn | $700M | B |
| Bitget Earn | $600M | A |
| BingX Earn | $400M | B |
| Gate.io Earn | $100M | B |
| MEXC Earn | $100M | C |
Grade is how many of our five checks a venue passes, not a judgement on the fund.
The two largest funds on our board belong to C-graded venues. Coinbase, which passes all five checks, does not headline a fund size at all — its protection is a Lloyd's policy and FDIC coverage, which are stronger instruments and smaller numbers.
Fund size measures how much the venue set aside. It does not measure whether the venue needs it, who decides when it pays, or whether anyone outside can enforce it.
"Proof of reserves" splits three ways
Twenty-five venues publish something. It falls into three groups that are not comparable.
Attested by a named firm — 10 venues. Someone outside the venue signs off.
| Venue | Attested by |
|---|---|
| Coinbase Earn | Deloitte |
| Kraken Earn | Armanino, Mazars |
| Bitvavo Staking | The Network Firm |
| Nexo | Armanino, then Moore |
| Ledn | Armanino |
| WhiteBIT | Hacken |
| KuCoin | Hacken |
| Gate.io Earn | Hacken |
| MEXC Earn | Hacken |
| CoinEx Earn | SlowMist |
Self-built Merkle tree only — 4 venues. Binance, OKX, Bitget and BingX. You can verify your own balance is in the tree. You cannot verify the liability side is complete, because the venue built the tree. Better than nothing, weaker than it sounds.
Verifiable on-chain by construction — 11. Lido, Rocket Pool, StakeWise, Marinade, Jito, Frax, Mantle and Coinbase's cbETH are non-custodial: every validator position and exchange rate is public by design, so there is nothing to attest. Backpack publishes a daily zk-SNARK proof. Uphold runs a real-time dashboard refreshed roughly every 30 seconds. Gemini sits under NYDFS supervision with monthly attestation on GUSD.
That third group is the one most comparison tables get wrong. A DeFi protocol has no reserves to prove — it has no custody. Ticking the same box for Lido and for Binance flattens a difference that matters more than either number.
The gap that actually matters is between the first group and the second. A Merkle tree proves inclusion. An accounting firm's attestation puts someone's licence behind the liability side too.
The nine with neither
| Venue | Grade |
|---|---|
| Bitstamp | C |
| Bitpanda Staking | C |
| Robinhood Crypto | D |
| Nebeus | D |
| Bitfinex | D |
| CoinDepo | F |
| Telegram Wallet | F |
| Lune.fi | F |
| YouHodler | F |
Four of the nine grade F, which is unsurprising. The two that should give you pause are Bitstamp and Robinhood Crypto — both large, both regulated in serious jurisdictions, and neither publishes reserves or holds a fund we can verify.
Regulation and transparency are different things. A venue can pass the licence check and still tell you nothing about what it holds.
What neither check protects against
Both of these are worth having and neither is what most people think it is.
A reserve attestation is a photograph. It shows the venue held what it claimed on the day it was taken. It says nothing about the day after. Every collapsed lender in 2022 was solvent at some point before it wasn't, and a monthly attestation would have caught none of them at the moment it mattered.
A fund is sized for an incident, not a failure. $1B sounds enormous until you set it against a venue's total customer balances, which are usually a large multiple of it. These funds are built for a hot-wallet breach — one bad day, contained. They are not built for the venue itself going under, and no venue claims otherwise.
Neither covers the thing that actually took the money last cycle. Celsius did not lose customer funds to a hacker. It lost them by lending them out and not getting them back. A reserve snapshot taken while the loans were still performing would have looked fine, and no insurance fund pays out on a business model.
That is why we score five checks rather than two, and why the regulation and track-record checks carry the same weight as these.
What we'd actually do with this
If you want someone outside the venue on the hook: that narrows to Coinbase and Nexo, and read what each policy covers, because they cover different things.
If you want to verify reserves yourself: the named-attestation list is short and it is the one worth using. A Merkle tree from the venue is better than nothing and weaker than it sounds.
If a venue advertises a large fund: check what kind. "$1B SAFU" and "$255M Lloyd's policy" are not comparable numbers, and the smaller one is the stronger instrument.
If a venue has neither: that is not automatically disqualifying — Bitstamp is not Celsius — but you are relying entirely on regulation and track record, so those two had better be strong.
Every venue's five checks, with the evidence and source link for each, are on its page. Start with the platform list or read how to compare APY and risk for what the other three checks test. Counterparty risk covers the failure mode all of this is insuring against.
Not financial advice. Grades summarise five checks; they are not a guarantee, and no fund makes a deposit safe. Figures as assessed on 28 July 2026 — verify on the venue before depositing.
Educational content, not financial or legal advice. Sources are linked in the text.