Attestation vs Audit: What Stablecoin Reports Really Say
Every major stablecoin publishes reserve reports. Almost none of them are audits, and the difference decides what the document is worth.
Every major stablecoin publishes reserve reports. Almost none of them are audits, and the difference decides what the document is worth.
An attestation is a limited engagement in which an accounting firm confirms that stated assets existed at a single point in time, based on information the issuer supplies. A financial statement audit is a broader annual examination with an opinion on the whole entity, including liabilities and internal controls. Most stablecoins publish attestations, not audits. Read the report for the date, the scope, who prepared it, the exact reserve composition and where the assets are held.
"Fully backed and independently verified" appears on nearly every stablecoin's front page. The document behind that sentence is usually a two-page attestation covering one calendar date, and understanding what it does and does not establish is the difference between informed confidence and a slogan.
An attestation engagement has an accounting firm report on a specific assertion made by management — typically that reserve assets at a stated date equalled or exceeded tokens in circulation. The firm performs agreed procedures on information the issuer provides, and the report says exactly what those procedures were.
This is genuinely useful. A recurring attestation from a recognised firm, with a consistent format, means someone independent looked at custodian confirmations and compared totals. It is far better than nothing, and it is why the top-scoring assets in our stablecoin ratings all publish monthly.
What it is not: an opinion on the issuer's financial position, an examination of liabilities beyond the tokens, a statement about internal controls, or a claim about any date other than the one printed on it. A snapshot report can be satisfied by assets present on the last day of the month and absent on the others — window dressing is exactly what a point-in-time procedure cannot rule out.
An audit covers a full reporting period and produces an opinion on financial statements as a whole: assets, liabilities, equity, and whether the statements fairly present the entity's position. It considers going concern and, in the more rigorous engagements, internal controls.
It is more expensive, slower, and annual rather than monthly. It also catches things an attestation structurally cannot: undisclosed liabilities, related-party exposure, and whether the reserves are encumbered.
The honest position is that both matter and they answer different questions. Monthly attestations tell you the backing is there regularly; an annual audit tells you the company behind it is what it says it is. An issuer with both is in a different category from one with either.
Once you have the report, the composition line is where the risk lives. Work down it in this order.
**Short-dated Treasury bills and overnight repo** are the safest category — days of duration, government credit. **Treasury money market funds** are close behind, with a fund wrapper between you and the paper. **Bank deposits** are a credit exposure to specific banks, and the 2023 depeg of USDC after Silicon Valley Bank's failure was precisely this risk becoming real for one weekend. **Commercial paper and corporate credit** carry issuer risk and can be illiquid when everything is being sold at once. **Secured loans, precious metals and other digital assets**, which appear in Tether's breakdown, are not equivalent to bills and should be assessed separately.
Then check duration. Reserves in three-month bills are effectively cash; reserves in longer paper carry mark-to-market losses if rates move and redemptions arrive at the same moment.
As of what date, and how long ago was that? Who prepared it, and are they a firm with something to lose? What exactly was in scope — reserves only, or the entity? Is the composition itemised by instrument and maturity, or summarised into a pie chart? And where are the assets held, and is the custodian named?
A report that answers all five is doing real work. A monthly PDF with a single number and no custodian is a marketing document with a letterhead.
Two exposures sit outside every attestation. The first is redemption access: reserves being adequate does not mean you can convert at par. Most issuers redeem only for verified institutional clients above a minimum size, so retail holders depend on secondary market liquidity — the subject of redemption access.
The second is legal and operational control: freeze functions, jurisdiction, and what happens to reserve assets if the issuer enters insolvency. Whether tokenholders have a direct claim on reserves or rank as unsecured creditors is a matter of corporate structure and law, not accounting, and it is disclosed in terms of service rather than in the attestation.
Prefer issuers with monthly attestations from a recognised firm plus an annual audit, a reserve composition itemised down to maturity, named custodians, and a regulatory framework that mandates all of it. Where an asset scores well on backing but poorly on disclosure, size the position accordingly — and treat any yield above the risk-free rate on a fiat-backed stablecoin as a signal that something in the structure is doing more than holding bills.

A Merkle-tree snapshot is evidence, not a solvency statement. Here is exactly what an exchange proves when it publishes reserves, and the three gaps every programme leaves open.

A myth-busting look at the difference between letting an exchange hold your keys and holding them yourself, with the real-world collapses that made the distinction matter.
Protocols advertise that they are audited. The useful information is in what was audited, when, by whom, and what the team did about the findings.