The numbers are stark. According to Protos' on-chain investigation, HTX shifted over $1.3 billion in reserve assets—WBTC, stETH, sUSDS—to addresses controlled by Poloniex, another exchange under the same ultimate control. The logic is simple: if you cannot verify the custodian, you cannot verify the reserve. And if the reserve is moved to a sibling entity under sanctions pressure, the architecture of trust collapses.
Context: The Sanctions Trap
In June 2025, the EU Council and UK FCDO imposed sanctions on HTX. The exchange responded by restructuring its Proof of Reserves (PoR) system. In its June PoR report, HTX admitted—for the first time—that it had transferred billions in assets to an undisclosed third party. The website claimed users could verify balances by contacting the custodian, but the custodian's identity was never revealed.
This is not a technical glitch; it is a deliberate opacity upgrade. The market, however, has been slow to price this risk. I've audited exchange reserve proofs since 2020, and this pattern—moving assets to a 'black box' custodian under the same controller—is the classic precursor to a liquidity crisis. The only difference is that this time, the chain is public.
Core: The On-Chain Trail
Protos traced the flow with cryptographic precision. WBTC moved from an HTX address to Poloniex 7, then to Poloniex 10, and finally settled in Poloniex 9. sUSDS worth ~$200 million followed a similar path: HTX → 0x7fed2E... → Poloniex 7 → Poloniex 10 → Poloniex 9. stETH and other assets also appeared in Poloniex addresses. The path is mathematically consistent: the two exchanges share a common liquidity pool.
But the real signal is not the transfer itself—it's the wallet rotation. TRM Labs reported that HTX began changing wallets at an 'astonishing speed' after the sanctions. Their global policy head, Ari Redboard, explicitly stated this is a technique to 'stay ahead of static-list screening.' When I read that, I immediately recalled the same pattern from the 2022 Terra collapse: rapid wallet rotation to obscure the outflow of funds. HTX claimed it was a 'normal security measure.' The logic is inconsistent with the evidence.
Then there is the PoR data error. HTX's May report claimed to hold STEAK-USDC, but on-chain data showed the same address held sUSDS. A single mismatch could be a typo. But when you combine it with the undisclosed custodian and the wallet rotation, it becomes a systemic failure of reporting integrity. Code is law, but logic is the judge.
Contrarian: The Blind Spot
Most pundits will focus on the compliance angle—sanctions, OFAC, freezing assets. That is important, but it misses the deeper technical lesson. The real vulnerability is not that HTX moved assets; it is that the PoR system itself was never designed to withstand adversarial pressure. The industry's PoR model relies on periodic snapshots and static addresses. Once a sanction is imposed, the exchange can simply rotate wallets and shift assets to a sibling entity, and the snapshot becomes meaningless.

This is not a bug; it is an architectural feature. Security is not a feature; it is the architecture. The current PoR infrastructure allows a single controller to maintain a 'shadow reserve'—a set of addresses that are not disclosed to the public but are used to satisfy regulatory queries. The on-chain data reveals that Poloniex is acting as HTX's proxy custodian, absorbing billions in assets without corresponding liabilities. The economic implication is profound: the yield from stETH and sUSDS that should belong to HTX users is now flowing to Poloniex's balance sheet.
Takeaway: The Crypto-Sanctions Chessboard
Forward-looking judgment: the market will eventually price this trust deficit. Users will migrate to exchanges with transparent, real-time, verifiable reserves. The Poloniex-HTX case will become a textbook example of how sanctions can be technically circumvented—but only temporarily. Compiling truth from the noise of the blockchain will eventually expose every shell game. The question is not whether HTX's reserves are real; the question is whether the next panic will trigger a bank run before the truth is fully compiled. The stack overflows, but the theory holds.