Every exchange that publishes a Merkle root describes it as proof of reserves. Most of them are describing proof of inclusion, which is a much weaker claim, and the gap between the two is where customers get hurt.
Proof of inclusion says: your balance was one of the leaves that summed to this root. That is genuinely useful. It means we cannot quietly omit you from the total, and it means you can detect it if we try.
What it does not say is anything about liabilities that were never entered as leaves. An exchange that owes $10B to customers and $8B to a lender it never disclosed can publish a perfectly valid Merkle root covering only the first number.
The second gap is the asset side. A signed message from an address proves control at a moment in time. It does not prove the assets were not borrowed an hour earlier and returned an hour later, which is precisely what happened in at least two well-documented cases.
Our attestation closes the second gap with continuous address monitoring rather than a point-in-time signature, and closes the first with a liability attestation from an external firm covering off-balance-sheet obligations. Both are published. Neither is sufficient alone.
Read our attestation and ask what it does not cover. Then ask the same question of every venue holding your assets. The answer is usually more interesting than the headline number.