Data indicates that a proof-of-reserves statement is only as honest as the address list attached to it. On May 1, HTX published a reserve snapshot showing 71,853.22 stETH, worth roughly $135 million, sitting at address 0x18709e89bd403f470088abdacebe86cc60dda12e. On May 30, that stETH began moving. The destination was not an independent custodian. The destination was a cluster of addresses labeled Poloniex, including one previously labeled “Justin Sun 4.” This is not a hack. This is a custody audit that fails the address test.
Assumption is the adversary of verification. I have repeated that line in every serious review I have written since the 2022 collateral collapse analysis, when a decentralized exchange ignored my warning about oracle price manipulation and later lost $15 million in user funds. The HTX case demands the same discipline.
Context: Post-FTX Reserve Proofs
After FTX collapsed, the industry promised transparency. Exchange reserve reports would include signed addresses, Merkle-tree attestations, and independent third-party verification. The minimum standard was clear: users should be able to verify that the assets on the balance sheet are controlled by the exchange, not by an unnamed related party.
HTX has moved in the opposite direction. Its proof-of-reserves now classifies a significant share of assets under a category called “ThirdParty” without identifying who that third party is. A third-party custodian is not a third party if the label never names it. For a user, an anonymous custodian is no custodian at all.
The timing makes this worse. TRM Labs, a blockchain intelligence firm, has stated that HTX rapidly rotated addresses after being subject to sanctions to stay ahead of transaction screening. Address rotation is not a security feature. It is a traceability control. Legitimate exchanges rotate addresses for operational reasons, but routine rotation that follows sanctions scrutiny invites a different conclusion: the exchange is trying to make its assets harder to follow.
Protos reported that HTX did not respond to key questions, and Poloniex declined to disclose its reserve addresses. That silence is itself a data point. A compliant exchange under scrutiny would publish a signed auditor statement. Instead, HTX published a vague category label.
Core: The On-Chain Path
Let me walk through the transaction path, because the details matter.

The May 1 snapshot address, 0x18709e89bd403f470088abdacebe86cc60dda12e, held 71,853.22 stETH. On May 30, funds moved from that address to 0x7C103bbAE0DA51AE929dE97A98633668ddE80d04. From there, the funds moved to 0x8FCA4adE3a517133fF23ca55CdAea29C78C990b8, labeled on Etherscan as “Poloniex 7.” The next hop went to 0x29065a4C1f2F20d1E263930088890d6F49Fe715a, labeled “Poloniex 10.” The final stop was 0x176F3DAb24a159341c0509bB36B833E7fdd0a132, labeled “Poloniex 9.”
Here is the detail that should stop any compliance officer: 0x176F... was previously labeled “Justin Sun 4” before being relabeled as a Poloniex address. Etherscan labels are not court evidence. But when a reserve address, an intermediate address, and multiple exchange labels all point to the same control network, the probability of coincidence becomes negligible.
The path reconstructs as follows: HTX reserve address to mid-tier address to Poloniex-labeled address to an address previously tied directly to Justin Sun. That is not independent custody. That is internal token movement inside a related-party orbit.

In my audit work, I have seen this exact pattern before. In 2020, when a Mumbai yield-farming protocol failed, the first sign of trouble was not a hack. It was a series of internal transfers that repositioned collateral between contracts controlled by the same deployer. The visible balance remained high. The control structure had changed. Users discovered the difference after the loss. “ThirdParty” categories in a proof-of-reserves are the financial equivalent of that internal transfer: visible, yet unverifiable.
The “ThirdParty” Control Structure
The phrase “ThirdParty” in a reserve report should mean a regulated, independent custodian with a published legal name and a signed custody agreement. In HTX’s case, the category appears to conceal a related-party relationship. This is not a technical innovation. It is a step backward from the standard that exchanges like BitMEX or Kraken set when they exposed cold wallet addresses to public scrutiny.
A meaningful proof-of-reserves uses Merkle trees, signed addresses, and a third-party auditor. It allows a user to verify that their share of the total liabilities is backed by a specific asset at a specific address. HTX’s current format does none of that. By moving assets into “ThirdParty,” it has effectively told users: trust us.
There is also the question of the previous $1.3 billion transfer that Protos highlighted. When an exchange moves an amount of that size between affiliated entities, it changes the risk surface. It may be a legitimate rebalancing. It may also mean that reserves are being pooled with a sibling exchange’s liabilities. Without a legal entity boundary, those two explanations are indistinguishable.
The reserve proof has lost external verification. I assign high confidence to that conclusion because the address path is verifiable, the “ThirdParty” label is self-reported, and no independent auditor has signed HTX’s latest disclosure. The burden of proof should be on the exchange.
The Asset Quality Problem
HTX’s Bitcoin reserves add another layer of concern. According to the report, more than half of the BTC on HTX’s balance sheet consists of tokenized Bitcoin, not native Bitcoin. This is a critical distinction. Native Bitcoin is a bearer asset. Tokenized Bitcoin is a claim on an issuer. If the issuer is an independent, regulated custodian, the claim may be acceptable. If the issuer is a related entity, the claim is only as strong as that entity’s balance sheet.
The report suggests the tokenized BTC appears to be held by Poloniex-related addresses. That would mean HTX’s reserve assets are not only in related-party custody; they are also in a related-party wrapper. This is a double credit risk. If the wrapper issuer faces a solvent but operationally illiquid event, or if the same control environment must defend multiple balance sheets simultaneously, the “reserve” becomes a stack of IOUs from the same family.
This is what I call low-quality reserve substitution. The exchange displays a large dollar figure, but the actual high-liquidity native asset has been replaced by a tokenized claim. The substitution matters because tokenized BTC can be subject to freezing, minting pauses, or legal orders that do not affect native BTC. Users who believe they are protected by Bitcoin are actually protected by a counterparty.
Let me be precise: I cannot prove insolvency from this evidence. Insolvency would require a full liabilities ledger, which HTX has not made available. But the burden of proof should be on the exchange. A proof-of-reserves that reveals nothing about custody, names no independent auditor, and relies on unlabeled “ThirdParty” classifications is not proof. It is an assertion. Assumption is the adversary of verification.
Regulatory and Sanctions Exposure
There is a regulatory dimension that too many technical reviews ignore because it is invisible on-chain. TRM Labs’ statement about rapid address rotation is not neutral. Sanctions compliance requires transaction screening. If an exchange deliberately rotates addresses to evade screening, it may be violating the legal framework of the jurisdictions where it operates. In my 2024 work reviewing a proposed Bitcoin ETF infrastructure, I learned that multi-signature thresholds and custodian identity are regulatory requirements, not optional features. The same logic applies here.
An exchange that keeps its reserve addresses opaque may be able to move funds without alerting compliance software. But on-chain forensic tools can still reconstruct the path. The stETH migration from HTX to Poloniex addresses is a public record. Any regulator with access to a block explorer can see the control network. The question is whether regulators choose to act.
Risk Assessment
The following risk markers are supported by the available data:
- Centralized governance with related-party custody: confirmed by the address path.
- Administrator or controller authority exceeding normal limits: supported by the “Justin Sun 4” label history.
- No independent third-party audit: supported by the absence of a signed auditor statement in the report.
- Non-transparent reserve addresses: confirmed by the “ThirdParty” classification.
- Possible sanctions-evasion screening: supported by TRM Labs’ statement and the rapid address rotation.
Each of these markers is individually explainable. Together, they create a pattern that demands a formal response from HTX.
Contrarian: What the Bulls Got Right
There is a fair reading of the same facts. No frozen withdrawals have been reported. HTX appears to be processing customer redemptions. The stETH transfer could reflect legitimate liquidity management between affiliated entities, perhaps to facilitate Poloniex user withdrawals. The address labels on Etherscan are maintained by volunteers and can be wrong or misleading. The previous “Justin Sun 4” label may have been removed for good reason.
I have to acknowledge that a forensic narrative is not a conviction. The movement of collateral between affiliated addresses is a hallmark of mismanagement when a collapse follows, but it is not itself proof of fraud. Many legitimate organizations move assets between subsidiaries on a daily basis. In a bull market, this kind of internal transfer is often invisible; in a bear market, it is called a crime. The market context matters, but it does not change the technical baseline.
What the bulls get right is this: the absence of a smoking gun is not a gun. If the exchange survives, these transfers will be described as routine treasury operations. If it fails, they will be described as the moment reserves became unverifiable. The same data supports both stories. That is precisely why the industry needs a better standard than a self-published snapshot.

Takeaway: The Accountability Call
The solution is not more token engineering. It is legal and technical binding. A proof-of-reserves must tie each address to a legal entity, name the independent auditor, disclose the custodian’s identity, and commit to a public address-change policy. If an exchange changes its reserve addresses, it must explain why. If a category says “ThirdParty,” it must say who.
I have been asked many times why I spend so much time on address labels and audit categories. The answer is boring and unforgiving: because verification is not a feature, it is a discipline. HTX has one obvious way to refute this report: publish a signed statement from an independent auditor, identify the “ThirdParty” custodian, and provide a transparent reconciliation of the stETH migration. Until that happens, the only rational position is skepticism.
The baseline in this industry should be that reserve statements are unverified until proven otherwise. Not because every exchange is dishonest, but because assumption is the adversary of verification. And in a bull market, that adversary is the only one that still gets paid.