Get Tokenomics

Proof of Reserves for Physical Collateral

You can't hash a silo. Proving tokenized grain, metal, or oil exists—and isn't pledged twice—is an attestation stack, not a Merkle tree.

In 1963, Tino De Angelis borrowed a fortune against tanks of soybean oil in Bayonne, New Jersey. The tanks held mostly seawater, with a thin film of oil floating on top for the inspector; some were plumbed together so the same oil could be pumped ahead of the man with the dipstick. The receipts were issued by American Express’s own field-warehousing subsidiary. When it unwound, roughly $180M evaporated—about $1.9B today—and it took the brokerage Ira Haupt & Co. down with it during the week President Kennedy was shot.

The Salad Oil Scandal is the oldest lesson in real-world-asset finance: a token is only as good as the proof that the thing behind it exists and belongs to you. Sixty years later, “proof of reserves” is a phrase everyone in crypto knows—and almost everyone applies to physical collateral without noticing that the crypto version does not survive the trip to a warehouse. You can’t hash a silo. This article is about what you do instead, and why it is objection number one in every RWA deal we see—the honest gap the financing-economics framework flagged and left open.

Why crypto proof of reserves does not transfer

After FTX imploded in November 2022 with roughly an $8B hole between claimed and actual reserves, exchanges rushed to publish proof of reserves. The mechanism is two proofs bolted together. Proof of assets: the exchange signs messages from its on-chain wallets, so anyone can sum the reserves on a public block explorer. Proof of liabilities: every customer balance is hashed into a leaf of a Merkle tree, combined pairwise up to a single root; each user checks that their own balance is included in that root without seeing anyone else’s. The best implementations wrap a zero-knowledge proof over the tree—a zk-SNARK at Binance, a zk-STARK at OKX—to prove no account was slipped in with a negative balance, which is the exact trick a naive sum hides.

The property that matters is this: crypto proof of reserves is self-verifying. You do not have to trust the exchange, or even the auditor. You read the chain and recompute the hashes yourself. That trust-minimized, anyone-can-check quality is the whole point—and it is precisely what physical collateral has none of.

And notice where even crypto PoR is contested: on its off-chain, self-reported side. The asset side is cryptographically checkable for ownership and total—but not for the completeness of the wallet set, nor for the single instant it captures. The liability tree, meanwhile, is whatever the exchange chooses to include. On 21 October 2022, two days after Gate.io’s PoR snapshot, Crypto.com transferred around 320,000 ETH—some 80–85% of its ETH—to Gate.io, then it came back a week later; the CEO called it an accidental cold-storage misfire. Accidental or not, it is the textbook picture of how a point-in-time attestation can be flattered by borrowed coins. Binance’s report covered only Bitcoin, about 16.5% of client assets. Its attestor, Mazars, paused all crypto work that December and pulled the reports from its own site. That is why an attestation is not an audit: an attestation checks one management assertion at one date; an audit reviews the whole balance sheet over a period. That gap is only now closing: as of July 2026 Circle has been audited annually by Deloitte since FY2022 on top of monthly attestations, and Tether engaged a Big Four firm in March 2026 for its first full USDT audit, above its quarterly attestations. Under MiCA what forced USDT off EU venues was the absence of e-money authorisation rather than the missing audit, but the reserve-transparency regime is the same pressure; the fiat-backed peg model lives or dies on it.

Hold that thought and cross to a warehouse. For physical collateral, the entire object of proof is that contested off-chain side. There is no public ledger of the world where anyone can independently confirm that the grain is in the silo, or that it was pledged to only one lender. Proof of reserves’ single genuine superpower—self-verification—is exactly the property that does not make the jump. What replaces it is a chain of people who sign their names, backed by a stack of evidence that makes their signatures expensive to fake.

The two failures the stack has to stop

Every physical-collateral fraud is one of two shapes, and both open a gap between the paper and the physical thing at the moment the paper is issued.

The first is the collateral isn’t there, or isn’t what the paper says. Salad Oil is the archetype—seawater under a film of oil. Its modern twin: in 2023 Trafigura took a roughly $577M charge after cargoes billed as refined nickel turned out to be carbon steel and other steel and iron products. Of the more than 156 containers inspected, not one held nickel. No registry and no price feed would have caught it, because the documents were internally perfect; only someone opening the box at origin would have.

The second is double-issuance—the same physical asset pledged to several lenders at once. This is the one that dominates RWA conversations, and its reference case is Qingdao. In 2014, a metals trader at the Chinese ports of Qingdao and Penglai used duplicated warehouse receipts to pledge a single stock of alumina, aluminium and copper to lender after lender, much of it structured as commodity repos. Roughly 400,000 tonnes of metal worth about $380M was leveraged into an estimated $4.2B of financing across 18 Chinese and 7 international banks; Chinese-bank exposure alone topped $3B. Citi, Mercuria, Standard Chartered, HSBC, Glencore, and Trafigura were all in it; Citi and Mercuria fought over a $270M metal repo in the London courts. When authorities discovered the duplicate receipts in May 2014, they locked the warehouses—which meant no one could even verify their own exposure. There was no registry reconciling receipts against physical stock, and no lender held independent custody. Both holes are the whole story.

Brazil has its own live version. The Grupo Safras warehouse group in Sorriso, Mato Grosso entered judicial recovery in May 2025 with R$1.78bn of debt and roughly 900 creditors, about 800 of them local farmers who had delivered grain that the stock records no longer showed. Banco do Brasil alone was in for R$303.6M. Grain in, records that don’t reconcile: the title diverged from the goods, exactly as at Qingdao. We walked through what a default like this actually recovers in the AgroGalaxy post-mortem—but that is the sister question. AgroGalaxy asks what you get back after a borrower fails; proof of reserves asks whether the collateral was ever there, and pledged only once, in the first place.

The attestation stack

If you cannot hash the silo, you build layers, and you price the trust each one still requires. None of them is cryptographic. Each has a cost and a failure mode, and the discipline is knowing which layer stops which fraud.

The layers, and what each one is for
  • Registry / title uniqueness. One warrant per physical unit—minted once, retired on release, impossible to re-pledge or forge. This is the layer Qingdao’s duplicated receipts and Access World’s 2017 fake nickel warrants both slipped past. It is the systemic defense against double-issuance: independent custody closes the vector at a single custodian, but only a shared registry catches the same lot pledged through two of them. Reconciling the release of goods against retirement of the title matters as much as the issue—on-chain is where all of it is cheapest to enforce.
  • Telemetry. Silo level sensors, weighbridge integration on every truck in and out, CCTV. Cheap, and it proves flow—but it proves movement, not custody, and a determined operator can spoof it. Sensor data alone does not move a lender’s required discount.
  • Collateral manager. The load-bearing layer, where trust actually begins. But custody is necessary, not sufficient: Salad Oil’s warehouser had custody and still signed for water. The legal form and the signer’s independence are everything (next section).
  • Assay and substance. Verify what is in the box, not just the paperwork—the layer Trafigura’s nickel was missing. A grade certificate at intake, sampled by an independent surveyor.
  • Price oracle. For the value side: a median of independent references (for grain, CEPEA/ESALQ, B3, and CBOT/ICE), a heartbeat, a deviation trigger, and a fail-closed default. This is the tractable part—it is the same shape as any DeFi oracle.
  • On-chain record. The token and registry hold the attestation, not the grain. This is what people mistake for the proof; it is only the ledger the proof is written into.

The mistake in most “tokenized commodity, fully backed, proof of reserves on-chain” pitches is collapsing this stack to its last two layers. An oracle and an on-chain record are real work, but they verify a number and a signature. They say nothing about whether the physical thing exists, and the uniqueness a registry enforces is only ever as good as the issuance discipline feeding it. Gold in a vault—the clean case we cover in the ownership-model piece, where PAXG publishes monthly vault attestations and XAUT pairs quarterly BDO attestations with a Chainlink Proof of Reserve feed—attestations, note, not audits, even in the easy case—makes this look easy, because a bar in an allocated vault is discrete, high-value, and rarely moves. Grain, oil, and base metal are fungible, bulk, and in constant motion. And because bulk grain is commingled rather than boxed, the registry tracks a pro-rata share of a common mass, not a discrete unit—so dividing a shortfall becomes its own problem on top of double-issuance. That is where the model breaks, and where the middle layers earn their fee.

Who signs the attestation

The single most important design choice in physical proof of reserves is who signs, in what legal capacity, how often, and with what liability. Everything else is instrumentation feeding that signature.

The pivotal distinction is CMA versus SMA. Under a Collateral Management Agreement, the manager—an SGS, Bureau Veritas, Control Union, Cotecna, or Drum Risk—takes physical custody and control of the stock, becomes the legal bailee, and holds the goods to the lender’s order in a tripartite structure. Under a Stock Monitoring Agreement, the manager only inspects and reports; title and control stay with the borrower. The gap between them is the gap between “an independent party holds your collateral” and “an independent party looked at your collateral last month.” Neither is publicly priced; the working band we are validating with collateral managers puts a CMA near 0.25–1.0% a year on stored value, with an SMA a half or a third of that, and it is worth exactly what it costs less.

Attestation frequency is the next knob—we treat a signed daily stock statement as the floor and continuous, event-driven reporting keyed to the weighbridge as the target for live collateral, though whether lenders demand the latter is exactly what we are asking them—and a deviation threshold sets when a discrepancy freezes the line and calls margin—somewhere between 1% and 5% of stock, though which number lenders’ risk teams actually accept is still an open question we are putting to them.

But the failure mode that no amount of frequency fixes is the captured signer, and it arrives in two shapes. The first is capture by identity—auto-emissão: an operator issuing warehouse receipts on its own grain, in its own warehouse, as its own borrower. When issuer, warehouse, and borrower are one entity, the attestation is a company vouching for itself. The second is capture by operation, and it is the one people miss. American Express’s warehousing arm was a legally separate company from Allied Crude, and it still signed for tanks of seawater—because it sat on the borrower’s site, ran on the borrower’s staff, and was paid by the borrower. Legal separation was never the safeguard; independence in practice was. The structural fix has to satisfy both: a third-party depositário that leases and operates the warehouse unit and issues the titles, with its own people and its own fee source, so the party that signs has nothing to gain from the grain going missing. Whether that workaround holds in Brazilian law—and whether auto-emissão is permissible at all—is still with counsel. If you read one thing off a proof-of-reserves claim, read whether the signer is independent of the borrower. If it isn’t, the rest is theater.

The economics, and why most claims are hand-waving

Instrumenting a warehouse is not free, which is why so much of the market waves at proof of reserves rather than paying for it. Vendors do not publish prices, so these are the bands we are testing with them rather than observed market rates: somewhere under $10k to north of $70k per unit for sensors, weighbridge integration and cameras, plus hundreds to a few thousand dollars a month for monitoring software and service; and the collateral manager takes its 0.25–1.0% on top. On a modest lot those costs are a real drag on the spread, which is why they get skipped.

Then there is the ground truth. In Brazil, only about 17.6% of warehouses hold the SNCUA certification, per a June 2026 MAPA figure—and in the same month, certification became voluntary under a new law. The state stepped back from the very filter that independent finance leans on, exactly where independent attestation is now needed most. Even the paper trail is thin: actual CDA/WA issuance is not publicly aggregated by B3, the registries, or the central bank, so the instrument that is supposed to make grain financeable is itself opaque. When someone tells you their tokenized-commodity product has proof of reserves, the first question is not “is it on-chain”—it is “who is the collateral manager, are they independent, and what did the instrumentation cost.” The honest answers are usually a much shorter list than the deck implies.

The honest limits

No physical proof of reserves is cryptographic, and pretending otherwise is how the next fraud gets funded. What the stack buys is a chain of liability expensive to corrupt: an independent custodian with something to lose, telemetry that has to be actively falsified rather than passively trusted, an assay that opens the box, a registry that refuses a second pledge, and an oracle that fails closed. Every one of those layers has a defeat—a colluding manager, spoofed sensors, an inspector shown the wrong tank, insurance that litigates for years instead of paying, a court that freezes enforcement inside a recovery. The goal is not to eliminate trust. It is to concentrate it in a named, independent, liable party and to make betraying it cost more than the collateral is worth.

Reading a physical proof-of-reserves claim
  • Who signs, and are they independent of the borrower? If issuer, warehouse, and borrower are the same entity, stop here.
  • CMA or SMA? Custody and control, or inspection and a monthly report—know which you are paying for.
  • Is there a unique-title registry? One warrant per unit, retired on release. Without it, double-issuance is unpriced.
  • Is the substance verified, not just the paper? An assay at intake, or you are trusting the label on the box.
  • What is the attestation cadence and the deviation trigger? Daily-signed is the floor; name the percentage that freezes the line.
  • Does the oracle fail closed? A price feed that keeps quoting through a source outage is worse than none.
  • Is release reconciled to redemption? Goods leaving must retire the title—weighbridge-out matched to warrant retirement, authorized by someone independent.
  • Is the title legally perfected? Existence and uniqueness are not enough—will the warrant hold against third parties and inside a recovery?
  • Tokenizing a physical asset?

    We design the custody and verification model deal by deal—the collateral structure, who signs the attestation and in what legal capacity, the oracle and registry, and the honest cost of the stack. Before you promise anyone their collateral exists.

    Get in touch

    The takeaway

    Crypto proof of reserves works because anyone can check the chain. A silo has no chain, so its proof of reserves is a different instrument entirely: a stack of attestation layers, each stopping a specific fraud, each with a cost and a defeat, all resting on whether the party who signs is independent of the party who borrows. Salad Oil, Qingdao, Trafigura, Grupo Safras—sixty years and four asset classes—are one lesson repeated: the token was fine, the paper was fine, and the collateral was seawater, or steel, or pledged to five other lenders. This is the layer the financing economics rests on, and the one most decks leave off the slide. Proving the reserve is real is not the boring part of a real-world-asset deal—it is the gate everything downstream is priced through.