The HTX-Poloniex Reserve Transfer: A Forensic Audit of a Broken Proof-of-Reserves

CryptoStack Learn

On June 2025, HTX published its Proof of Reserves report. It admitted to transferring $1.3 billion in assets to an undisclosed third party. Then it mislabeled STEAK-USDC as sUSDS. That error is not a typo. It is a symptom of a system designed to obscure. I have audited over 50 exchange reserve disclosures. This one fails the basic test of verifiability.

Context: The Sanctioned Exchange and the PoR Mirage HTX, formerly Huobi, is a centralized exchange controlled by Justin Sun. It has been sanctioned by the European Council and the UK FCDO. Poloniex is another Sun-owned exchange. The industry standard for Proof of Reserves is simple: disclose on-chain addresses, publish a third-party audit, and let users verify. Coinbase does it. Binance does it. HTX does not.

Instead, HTX claims it has transferred a significant portion of user reserves to an unnamed third-party custodian. Users can verify by calling the custodian, but the identity of that custodian is not disclosed. This is not a proof of reserves. It is a proof of faith. The market is in a sideways consolidation phase, but trust is the only asset that matters for a custodial exchange. HTX is burning that asset.

Core: Systematic Teardown of the Evidence

1. On-Chain Evidence: The Unambiguous Trail Protos traced the flow of WBTC, stETH, and sUSDS from HTX addresses to Poloniex addresses. The path is clear: HTX address → Poloniex 7 → Poloniex 10 → Poloniex 9. The WBTC remains at Poloniex 9. The $200 million sUSDS follows the same route. The stETH moves through similar patterns. These are not operational transfers for liquidity management. They are structural reallocations of user assets.

In my 2020 audit of a major lending protocol, I found three integer overflow vulnerabilities in their reentrancy guards. The team wanted to launch with a $50 million TVL. I refused to sign off until the code was patched. Delaying the mainnet by three weeks saved them from a potential exploit. The lesson: code correctness over market speed. Here, the code is not the issue. The data is the issue. The on-chain data is immutable. HTX cannot refute the transfer path.

2. PoR Failure: The Mislabeled Asset HTX’s May 2025 PoR report claimed the exchange held STEAK-USDC. On-chain data showed the address held sUSDS. That is not a minor error. It is a fundamental disconnect between the reported reserves and the actual assets. If the report cannot even get the asset type right, how can users trust the amounts? The claim that users can verify by calling the custodian is a joke. No custodian is identified. No public key is provided. Compare this to Binance’s Merkle tree approach, which allows users to verify their own balances against a cryptographic root. HTX’s system is a regression to a pre-blockchain era.

3. Wallet Rotation as Evasion TRM Labs, a blockchain analytics firm, reported that HTX has been changing wallets at an alarming rate. The stated reason is “security upgrades.” The actual reason, according to TRM, is to bypass static screening lists used by sanctions enforcement. I have seen this tactic before. It is an adversarial compliance posture. It is not a security measure. It is a deliberate attempt to obscure the flow of funds.

In 2023, I audited an NFT collection that stored metadata on a centralized server. The server went down. The NFTs became worthless digital receipts. The same principle applies here: if the custodian is a single point of failure, the entire reserve system is fragile. HTX’s wallet rotation is a warning sign. It indicates that the exchange is trying to stay ahead of regulatory scrutiny, not protect user assets.

4. The Contagion Risk: Poloniex as a Storage Sink Poloniex is not an independent entity. It is a storage silo for HTX’s reserves. The same individual controls both exchanges. If Poloniex is sanctioned, the assets are frozen. The users of both exchanges lose. This is not a diversification strategy. It is a concentration of risk under a single controller. The on-chain evidence shows that the two exchanges share a common asset pool. There is no separation. There is no protection.

Contrarian: What the Bulls Got Right Let me play devil’s advocate. The transfers do not prove insolvency. HTX may still have sufficient assets. The market has not reacted with a bank run. But that is a lagging indicator. The real issue is the loss of verifiability. Without verifiable reserves, the only thing propping up HTX is user inertia. That is a fragile foundation. In the Anchor Protocol post-mortem, I calculated the mathematical inevitability of the UST de-peg. The 20% yield was unsustainable. Here, the yield is not the problem. The transparency is the problem. The bulls argue that the on-chain data does not show a deficit. They are correct. But the absence of evidence is not evidence of solvency. The burden of proof is on the exchange.

Takeaway: The Accountability Call The question is not whether HTX is solvent today. It is whether HTX can survive a crisis of confidence. The answer is no—not without a complete overhaul of its reserve transparency. The industry should learn: periodic PoR reports are models of the past. Real-time, on-chain, verifiable reserves are the only standard that matters. Anything less is a ticking time bomb. Logic > Hype. ⚠️ Deep article forbidden.