Declaring proof of reserves is important, but it’s not enough

Declaring proof of reserves is important, but it’s not enough

‘Proof of reserve’ is the new catchphrase and promise by crypto leaders eager to allay investor fears. But loopholes remain and audits might not mean what you think, writes Anndy Lian.

Proof of reserves plays a critical role in the cryptocurrency industry by providing a vital security mechanism for investors. Given the industry’s lack of regulation and transparency, investors may have reservations about putting their money into the market. In response, many leaders in the industry are stepping up to assure users of their reserves.

“The #Binance Proof of Reserve system has now integrated with zk-SNARK, a zero-knowledge verification method. It will also be made open source. We hope this would help the entire industry benefit,” Changpeng “CZ” Zhao, the CEO of Binance, recently tweeted.

Ben Zhou, CEO of Bybit, has also reassured clients that “Bybit has always [been] committed to client fund safety and guarantees 1 to 1 reserves.”

OKX, led by founder, Mingxing “Star” Xu, recently announced their fifth proof-of-reserves report showing over US$8.9 billion in “clean assets” held in the exchange reserves, including over 100% reserves for BTC, ETH and USDT.

This past week, Texas also jumped on the “proof of reserves” bandwagon as its House of Representatives passed a bill that would require it for crypto companies operating in the U.S. state. By requiring adequate reserves, the proposed legislation seeks to prevent situations where a company is unable to meet its obligations to customers due to insufficient funds.

These words and measures may help alleviate some investor concerns that their digital assets held by a crypto exchange are safe and not being used by the exchange for other purposes, such as trading or investment. However, many crypto users still do not understand the concept of “proof of reserves” and how it works.

Here is an overview of what proof of reserves is all about, the potential gaps in how it’s being carried out, and how investors can demand more accurate and timely data for protecting their crypto holdings.

What proof of reserve does

Proof-of-reserve audits are crucial in verifying that exchanges hold the total amount of crypto assets they claim to have on behalf of their customers. This gives investors the confidence to know that their assets are securely stored and not at risk of being lost or stolen. It is especially important given the recent high-profile hacks and security breaches in the industry, which have resulted in the loss of millions of dollars worth of digital assets.

Proof of reserves provides a level of accountability for crypto exchanges. By ensuring that they are holding customers’ assets safely and securely, exchanges are incentivized to maintain high levels of transparency and openness. This can help to prevent suspicious or illegal financial activities from occurring on the exchange, which is vital for the overall credibility and legitimacy of the industry. Thus, it plays a crucial role in maintaining investor confidence and promoting the growth and success of the cryptocurrency industry.

But many people have a mixed understanding of what proof of reserve means and what it entails. There are three methods for proof-of-reserve verification, including “public wallet address,” “third-party audit,” and the most widely used “Merkle tree” proof.

  1. Proving reserves through public wallets

A public wallet is one method for proving reserves, which entails an exchange publicly sharing the addresses of its crypto wallets that contain customer funds. This approach offers a transparent and verifiable mechanism for both customers and regulators to confirm that the exchange is indeed holding the funds it claims to possess.

Through public wallets, customers of a crypto exchange can monitor the wallet addresses and ascertain that the funds contained in those wallets match the amounts they have deposited with the exchange. Such a high level of transparency can bolster trust between customers and the exchange and reassure customers that their funds are safe.

Apart from total transparency and enhancing accountability, a public wallet can also serve as an early warning mechanism for investors to detect any irregularities in a crypto exchange’s financial situation. For instance, if the balance of a wallet suddenly decreases without any explanation, it could signal potential fraudulent activity.

Just a word of caution: A public wallet may not be sufficient in revealing how the reserves are being managed or invested. Hence, it is critical to view a public wallet as just one part of a more extensive transparency and oversight framework, which includes other techniques such as live audits and continuous proof of solvency.

  1. Third-party audits

Third-party audits of proof of reserve are a method of validating an exchange’s reserves through an independent auditor. This approach aims to provide an unbiased evaluation of an exchange’s financial status and can enhance trust between customers, regulators and the exchange.

During a third-party audit, the auditor investigates the exchange’s records and verifies that the funds the exchange holds correspond to the amount owed to its customers. The auditor also confirms that the funds are held in secure and auditable accounts while scrutinizing any potential irregularities or discrepancies that may indicate fraudulent activities.

Using third-party auditors can yield several benefits, including preventing crypto exchanges from exaggerating their reserves or engaging in fraudulent activities, fostering confidence among customers and regulators, and promoting transparency and accountability within the largely unregulated cryptocurrency industry.

There are some drawbacks to relying on third-party audits for proof of reserves. Finding an impartial auditor with the required expertise and experience to carry out the audit may not always be feasible. In addition, the audit may only reflect a specific snapshot of the exchange’s financial status at a particular moment in time, potentially overlooking other fraudulent activities or ongoing mismanagement.

  1. Merkle tree

A Merkle tree is a cryptographic technique that plays a significant role in securing the blockchain. It employs a complex process that creates a series of hash values representing a block of transactions stored on the exchange. This process is done by combining the hash values of each transaction within the block, thus producing a unique hash value for the entire block.

The creation of this unique hash value is crucial as it provides an extra layer of security for the digital assets held by the exchange. Any attempt to tamper with a single transaction within the block would result in a change to the hash value of the entire block, which the system would detect. As a result, any unauthorized modification of the block can be quickly detected and prevented.

For crypto investors, verifying the hash value of their digital assets is an essential process that enables them to confirm the security of their assets. By doing so, they can be confident that their crypto assets are stored securely on the exchange and not stolen or compromised. Moreover, verifying the hash value of their assets is crucial because it helps to maintain their personal privacy regarding the total amount of assets held on the exchange.

Merkle tree provides this added privacy by only revealing the specific block of transactions that the hash value represents while not revealing any information about the total amount of assets held by the holder. This privacy protection is crucial for holders who want to verify the security of their assets while keeping the total amount of their assets private.

Importance of proving reserves

Proof of reserve plays a vital role in the cryptocurrency industry for three key reasons. Firstly, it allows customers to ensure the accuracy of their holding balances and verify that their assets are safe and secure. As the cryptocurrency market lacks regulation and transparency, It is an essential tool that empowers customers to confirm that their assets are not being used for unauthorized investment purposes, such as trading or lending.

Secondly, it incentivizes exchanges to operate in a more transparent and accountable manner. By verifying the accuracy of their reserve holdings, exchanges are held responsible for their actions, which promotes greater transparency and responsibility in the industry. This creates an environment that discourages suspicious or illegal financial activities, which is crucial for the growth and legitimacy of the market.

Thirdly, it prevents exchanges from acting like traditional banks by lending customer deposits to third parties. In the past, traditional banks have used customer deposits to make loans, putting depositors’ funds at risk. With proof of reserves, customers can verify that their assets are not being lent out, which provides peace of mind and ensures the safety and security of their assets. This important feature sets cryptocurrency exchanges apart from traditional banks and promotes trust and credibility in the industry.

Can public statements be trusted?

Publicly disclosing proof of reserves can have several benefits for cryptocurrency exchanges and crypto holders alike. By verifying the accuracy of reserve holdings, holders can feel confident that their assets are being securely stored and not being utilized for other purposes. This increased trust can attract more users to trade on the exchange, boosting its reputation and market share. Public proof of reserves can also help enhance the stability of an exchange’s operations by preventing the use of customers’ deposits for investment or other business activities. Many mainstream exchanges, including Binance, OKX, Bitget, KuCoin and Bybit, have publicly disclosed their reserves to showcase their commitment to transparency and security. By doing so, these exchanges create a more stable and sustainable operating environment.

While this is a step in the right direction toward greater transparency and accountability, such disclosures are not foolproof and may have some flaws and loopholes. For instance, exchanges can manipulate their reserves data by temporarily moving funds into a hot wallet just for the purpose of verification. Additionally, it only proves that an exchange has enough reserves at a specific point in time, and it does not guarantee that the reserves will remain the same in the future.

One potential solution to the flaws is combining proof of reserve with other transparency methods. Through the use of multiple methods, it is possible to instill greater confidence in both customers and regulators regarding an exchange’s adherence to its claims of reserve holdings. This is particularly critical as an exchange’s failure to maintain adequate reserves can have far-reaching consequences, including reputational damage and financial losses.

By leveraging additional methods, such as live audits and continuous proof of solvency, it is possible to detect fraudulent activities in real time, thereby providing a more detailed and current view of the exchange’s financial position. This proactive approach to monitoring can enable irregularities to be immediately identified and addressed, in contrast to relying on infrequent or less comprehensive audit approaches.

Necessary but not sufficient

The dynamic nature of the crypto industry suggests that proof of reserve may not be the ultimate solution but rather a building block to the development of more advanced and robust methods of verifying reserves. Despite its limitations, it is a formidable tool in the crypto industry’s quest for greater transparency and accountability. While it is true that disclosing proof of reserve is not infallible, it represents a significant stride in the right direction, as it bolsters confidence in the sector and cultivates a more mature market.

The widespread adoption of proof of reserve could significantly enhance the credibility and legitimacy of the crypto industry. This would benefit investors and open doors to innovative financial tools and services that could revolutionize the broader economy. Ultimately, as the crypto industry evolves and adapts, its limitations could be addressed and overcome, leading to greater trust and confidence in the sector.

To me, trust can be a really “cheap” word. If you are truly worried, withdraw your crypto and keep it all to yourself and only yourself.

The best way to test proof of reserve is to put on a stress test. If the exchange can withstand withdrawals of any sort in a timely manner, this is the best proof.

 

Source: https://forkast.news/proof-of-reserves-is-important-but-not-enough/

j j j

The 1940s legal test that could pave the way for crypto regulation

The 1940s legal test that could pave the way for crypto regulation

Binance USD (BUSD) is a stablecoin issued by New York-based Paxos Trust Company and is backed 1:1 by the US dollar. However, recent regulatory scrutiny by the US Securities and Exchange Commission (SEC) has raised questions about whether BUSD should be considered a security.

There are arguments for and against this, which I’ll dive into in this article. Most interestingly, the Howey Test and legislation from the 1940s could have a key role to play in this most modern of financial disputes.

Security or not security

To begin, it is important to understand what a security is. According to the SEC, a security is any investment contract, note, stock, or instrument that represents an ownership interest in a company, partnership, or investment pool, or that is offered as a means of raising capital.

In the case of BUSD, the SEC issued a notice to Paxos stating that the stablecoin should have been registered as a security.

The regulator argued that BUSD meets the definition of a security because it is offered as a means of raising capital, has the potential for profit or loss, and derives its value from the success of a third party, namely Binance.

However, Paxos has disputed this classification. The company has even threatened litigation.

There are several arguments for why BUSD is not a security. First, BUSD is a stablecoin, which means that its value is pegged to the US dollar.

This pegging makes it less likely to experience the volatility associated with other cryptocurrencies. As a result, BUSD may not meet the definition of an investment contract because it does not have the potential for significant price fluctuations.

Second, BUSD is not an investment in a company or partnership, but it’s a digital asset that represents a claim on a reserve of US dollars held by Paxos. This means that BUSD does not represent an ownership interest in any entity and is not used to raise capital.

Third, BUSD is used primarily as a means of payment and is not marketed as an investment. Unlike securities, which are marketed to investors expecting a profit, BUSD is promoted as a stablecoin used for transactions.

On the other side of the coin (pun intended), there are arguments for security classification.

To start, BUSD is backed by Paxos, which is a regulated financial institution. This means that investors may view the stablecoin as a safe investment, similar to a money market fund or certificate of deposit.

Next, the fact that BUSD derives its value from the success of Binance may be enough to classify it as a security. Investors may be purchasing the asset with the expectation of profit.

Lastly, the fact that BUSD is used primarily as a means of payment does not necessarily stop it from being a security. The SEC has previously classified cryptocurrencies like Bitcoin and Ethereum as commodities, despite their use as a means of payment.

The Howey Test for cryptocurrencies

The Howey Test is a legal standard used to determine whether a financial instrument is a security. There is debate over whether the almost 100-year-old test can be applied to digital assets, so some experts have proposed a modern-day version tailored to cryptocurrencies.

This version would include looking at several factors.

The first – as with the original test – is whether there is an investment of money. However, if a digital asset issuer has not sold any assets to build its project, it is unlikely to be considered a security.

The second factor is whether there is an expectation of profits from the investment. If a digital asset is utility-based and is used for purposes other than investment, such as voting, it is unlikely to be considered a security.

The third factor is whether the investment of money is in a common enterprise. If the project is decentralized and not controlled and operated by a centralized entity, it is unlikely to be considered a security.

The fourth is whether any profit comes from the efforts of a promoter or third party. If the profit primarily comes from the community, which has nothing to do with the issuance of the digital asset, it is unlikely to be considered a security.

Improving the Howey Test

One approach to adapting the Howey Test to fit cryptocurrencies better is to examine the underlying tech of the digital asset being scrutinized. This would involve evaluating whether the cryptocurrency is sufficiently decentralized and functional to qualify as a utility token rather than a security.

If a token is used mainly to access a blockchain network or platform, and its value is tied to its use rather than speculation, it may not fit as a security.

The SEC has also brought cases against companies that issue cryptocurrencies but do not meet the requirements of the Howey Test. This suggests to me that the SEC is trying to apply the standard to cryptocurrencies even though it may not be completely apt.

While there are some potential ways to improve the test’s application, the ongoing debate highlights the need for greater clarity and guidance from regulators regarding the treatment of cryptocurrencies.

Seeking clarity

While the Howey Test can serve as a starting point for regulation, it is essential to adapt and refine the rules to better reflect the realities of the cryptocurrency market.

A more nuanced and flexible approach is required to ensure innovation while protecting investors from fraud, and more fleshed out regulatory guidance can establish clarity in the market. To do this, authorities should work collaboratively with industry players.

To end where we started, it’s important to note that BUSD should not be classified as a security. Its main purpose is to serve as a payment method rather than an investment tool, and it’s not structured to produce returns for investors in the same manner as conventional securities.

BUSD’s value – with its link to the US dollar’s value – is meant to remain steady instead of being influenced by the speculative pressures that frequently hit other cryptocurrencies. So, let’s keep it this way.

 

Source: https://www.techinasia.com/1940s-legal-test-crypto-regulation

j j j

The US Treasury department’s first report on DeFi: Is it fair

The US Treasury department’s first report on DeFi: Is it fair

The U.S. Department of the Treasury published the 2023 DeFi Illicit Finance Risk Assessment, the first illicit finance risk assessment report conducted on decentralized finance (DeFi) in the world. This report highlights the risks associated with the burgeoning decentralized cryptocurrency market, stating that it threatens national security and requires greater oversight and enforcement against money laundering. The report addresses explicitly decentralized finance (DeFi) services and their need to comply with anti-money laundering and terrorist financing laws, in addition to highlighting the threat posed by cybercriminals and ransomware attackers.

While there are still a couple of unclear things, the report pointed out that fiats currency is used in illicit finance more than cryptocurrencies. I agree with this statement.

What is decentralized cryptocurrency?

Decentralized cryptocurrency is a type of digital currency that operates independently of intermediaries such as banks and payment processors. Unlike traditional currencies, decentralized cryptocurrencies are not controlled by any central authority or government. It offers several advantages over traditional financial systems. For one, users of decentralized exchanges do not need to transfer their assets to a third party, reducing the risk of company or organization hacks, failures, fraud, or theft. The decentralized nature of cryptocurrencies allows for peer-to-peer transactions directly between individuals, facilitating faster and more efficient transactions.

Decentralized Finance, commonly known as DeFi, is a disruptive phenomenon that has shaken the traditional financial sector to its core. In essence, DeFi is a remarkable unraveling of conventional finance that has taken the fundamental aspects of banking, insurance, and exchange, such as lending, borrowing, and trading, and disentangled them from the traditional financial infrastructure. Instead, DeFi utilizes innovative technology protocols that operate in a decentralized manner, enabling many individuals to reach consensus efficiently and make informed decisions.

Illicit activities prefer fiat or crypto?

According to a Chainalysis report, illicit activities associated with cryptocurrencies include malware, terrorism financing, outright stealing of crypto funds, investment fraud, sanctions evasion, and ransomware are on a rise. Despite the increasing popularity of cryptocurrencies, recent research indicates that fiat currency is still the preferred choice for criminals engaging in money laundering. In fact, fiat currency is used for money laundering 800 times more often than cryptocurrencies, according to a report by the United Nations Office on Drugs and Crime.

Fiat currencies like the USD are still more commonly used in illicit financial activities compared to cryptocurrencies. The report noted that while there has been an increase in the use of cryptocurrencies in money laundering and other illicit activities, fiat currencies remain the primary means of payment for such activities. It also highlights that the anonymity and lack of regulation in the cryptocurrency space can make them an attractive option for criminals. However, the vast majority of illicit financial activities still involve traditional fiat currencies as the barrier to entry into cryptocurrency is still high and not widely accepted.

The U.S. dollar was the second most commonly counterfeited currency in the world in 2015, with one in 10,000 US dollars being forged. The $20 bill is the most commonly counterfeited banknote in the United States, while overseas counterfeiters are more likely to make fake $100 bills. The amount of counterfeit currency in circulation can affect everyone who receives the counterfeit money and is unable to pass it on. This problem can be reduced using Central Bank Digital Currency (CBDC). With money going digital, tracing where the money went becomes easier. This would be a story to share on another occasion.

Only 0.24% of all cryptocurrency transactions in 2022 were tied to illicit activity. This was up from 0.12% in 2021, according to Chainalysis. Despite the recent increase in the share of all cryptocurrency activity associated with illicit activity, it still only represents a small percentage of overall cryptocurrency activity compared to fiat currencies.

Why not use cryptocurrency since it’s anonymous?

Of course not. Fiat money is generally considered more stable than cryptocurrency, its issuance and governance are dictated by central banks, whereas blockchain protocols, code, and communities govern cryptocurrency. It is also true that cryptocurrencies are vulnerable to abuse due to their decentralization and borderless transactions. But it is worth noting that while crypto transactions are not entirely anonymous, they can be more difficult to trace than fiat transactions. This anonymity has led to concerns that cryptocurrencies may facilitate illicit finance activities, such as money laundering and terrorist financing.

Cryptocurrency transactions are recorded on a public ledger called the blockchain, which anyone can view. Due to cryptocurrencies’ trackable nature, I would say that the transactions made and recorded on chain are generally more transparent and traceable than cash transactions. This makes it difficult for criminals to use cryptocurrency for illicit activities without leaving a trail. On the other hand, cash transactions are often untraceable and can be easily used for money laundering and other illegal activities.

An anti-cryptocurrency lobbyist once pointed out to me that some privacy-focused cryptocurrencies, such as Zcash are designed to be untraceable. I corrected him in front of the public consultation group that the right phrase to use is “They are designed to be more difficult to trace.” This means that it would be more complex if you want to track it, but it is not impossible.

Privacy-focused cryptocurrencies prioritize privacy and anonymity, making tracing transactions back to their originators difficult. Take Monero as an example, is an open-source, decentralized cryptocurrency launched in 2014 and has become one of the most popular privacy-focused cryptocurrencies in the market. Monero’s combination of stealth addresses, ring signatures, and confidential transactions makes it almost impossible to trace transaction details. It has gained a reputation for its level of privacy and security. However, while they can offer higher levels of privacy and security than traditional money, the trade-off is that privacy-focused measures may make it more difficult to track activity and could lead to government regulation or taxation. Again, the words used here are “almost impossible” and “more difficult”. It is still possible to track.

Conclusion

The U.S. Treasury Department’s report has caused quite a stir among crypto traders, with some warning about the impact it could have on the market. While the report is the first illicit finance risk assessment conducted on DeFi, it is essential to note that there is currently no generally accepted definition of DeFi. This makes it difficult to pinpoint exactly what type of DeFi services are at risk of being used for illicit purposes. It is important to note that the report does not necessarily mean that the government will immediately impose stricter regulations on the DeFi market. Instead, it lays the foundation for future regulations and greater oversight.

One thing to keep in mind is that while the report focuses on the risks associated with decentralized cryptocurrency markets, it does not necessarily condemn cryptocurrency as a whole. In fact, Federal Reserve Chairman Jerome Powell has recently stated that crypto itself is not the problem but rather the lack of regulation.

So, what does this mean for the future of cryptocurrency? While it is impossible to predict exactly what will happen, we will likely see increased scrutiny and regulation of the DeFi market in the coming years. This could lead to greater stability and security in the crypto market as a whole, making it a more attractive investment option for traditional investors.

 

Source: https://www.financialexpress.com/business/blockchain/the-us-treasury-departments-first-report-on-defi-is-it-fair/3056602/lite/

j j j