Who checks the checkers

In the weeks after FTX collapsed in November 2022, one detail kept snagging attention. The exchange had auditors. Real ones, with letterheads; one of them, Prager Metis, advertised itself as the first accounting firm to open a headquarters in the metaverse. The statements were signed, and eight billion dollars of customer money was missing anyway. Out of the wreckage the industry produced a promise with a satisfying ring to it: proof of reserves. No more trust, went the pitch. Cryptographic receipts, on-chain, for anyone to verify. Then came a quieter detail. That December the accounting firm Mazars, which had just produced Binance's proof-of-reserves report, stopped all work for crypto clients and pulled its reports from the web. The report it withdrew had checked only one side of the ledger.
That one-sidedness is the heart of the problem. Proving assets is the easy half: a wallet can sign a message, and the whole world can watch the balance. Solvency is assets minus liabilities, and liabilities do not live on a blockchain. Who is owed what, which deposits were pledged twice, what was borrowed the night before the snapshot and returned the morning after: all of it sits in databases and side letters, exactly where the trouble has always lived.
It helps to know the vocabulary the profession itself uses carefully and marketing departments do not. An audit is an opinion on a company's financial statements as a whole, formed under standards that require independence and professional skepticism: reasonable assurance, obtained by testing rather than accepting. An attestation confirms that particular numbers were as stated, at a particular moment, under procedures the client agreed to. The strongest claims in crypto tend to be attestations wearing the word audit in the press release. Tether, the largest stablecoin, has published quarterly attestations from a serious firm for years, along with a promise of a full audit that has now been pending for most of a decade. The numbers may well be fine. The point is that the checkmark and the check are different objects.
None of this is a crypto invention. Enron's books were blessed by Arthur Andersen, then one of the five great audit firms on earth, which shredded documents as the client burned and was destroyed alongside it. The lesson the profession drew was structural rather than personal: the checker was paid by the checked, the conflicts that arrangement breeds are documented at book length, and the firm discovered the cost of them only when it ceased to exist. Every assurance scheme since has been an attempt to manage that same conflict, never to abolish it, because the checked always pays somewhere in the chain.
Follow the chain up and it does not terminate. Auditors are inspected by oversight boards, which answer to regulators, who answer to politicians, who answer, in theory, to the people who had their savings on the exchange. Each link adds slack, and asking who checks the checkers eventually returns to where it started. Expecting the chain to end in certainty is the category error. Chains of assurance do not end. They are anchored, and the anchor is exposure: what the checker stands to lose by being wrong. Andersen's partners lost the firm. A boutique with a metaverse office and one big client has nothing at stake but the client, which is to say the fee, which is to say nothing.
Better designs exist, and honesty requires describing both their promise and their ceiling. The strongest proof-of-reserves schemes now publish the liability side as a Merkle tree, letting every customer verify that their own balance was included in the total the assets were checked against; an exchange that omits depositors to look solvent risks being caught by any one of them. On-chain funds go further, running the entire ledger in public. These are real improvements, and they still stop at the chain's edge: no cryptography can see the loan taken quietly against the reserves, the court order pending, or the second set of books. Mathematics verifies what was written down. The historic problem has always been what wasn't.
So the practical questions about any attestation, proof, or seal of approval are three. Who performed it, and would their name survive its failure? What exactly did it cover, and what did it decline to look at? And what happens to the checker if it turns out to be wrong? Continuous verification beats quarterly, and liabilities on-chain beat liabilities in a spreadsheet. As for the old signature against the new ceremony, keep the categories straight: reputation is collateral rather than truth, cryptography is verification rather than completeness, and neither substitutes for scope, meaning what was checked and what was carefully not. The deepest tell is exposure. The links in the chain that cost nothing to give are the ones that snap.