Auditing Cryptocurrency: Wallet Control, Valuation, and DeFi

Auditing cryptocurrency means building an evidence base that traditional procedures were never designed to produce: no bank confirms the balance, no register lists the owner, and no physical asset can be counted. Instead, the auditor works from public ledger data, cryptographic proof of control over private keys, fair value measurements taken every reporting period under ASC 350-60, and tests of the controls surrounding key custody. The 2025 shift to fair value accounting under ASU 2023-08 now shapes every engagement covering fiscal years that began after December 15, 2024.1Financial Accounting Standards Board (FASB). Accounting for and Disclosure of Crypto Assets

The Accounting Framework You’re Auditing Against

ASU 2023-08, codified as ASC 350-60, replaced the old indefinite-lived intangible model that carried crypto at cost less impairment and never wrote it back up. Qualifying crypto assets are now measured at fair value each reporting period, with gains and losses running through net income.2Financial Accounting Standards Board (FASB). ASU 2023-08: Intangibles – Goodwill and Other – Crypto Assets (Subtopic 350-60)

Scope matters, and it’s narrower than many entities assume. To qualify, an asset must be an intangible, must not give the holder enforceable rights to underlying goods or services, must sit on a distributed ledger secured by cryptography, must be fungible, and must not have been created by the reporting entity or a related party. NFTs fail fungibility. Wrapped tokens that convey rights to another crypto asset fall outside the scope. Fiat-backed stablecoins may be excluded if they represent a claim on underlying reserves. Entity-created tokens are excluded regardless of how they trade. When you audit an entity’s holdings, confirm each asset actually falls within ASC 350-60 before accepting fair value treatment; anything outside the scope needs a different framework and different procedures.2Financial Accounting Standards Board (FASB). ASU 2023-08: Intangibles – Goodwill and Other – Crypto Assets (Subtopic 350-60)

Presentation and disclosure now drive a lot of the workpaper trail. Crypto assets appear separately from other intangibles on the balance sheet, and remeasurement gains and losses appear separately in the income statement. For each significant holding, the entity must disclose the asset’s name, cost basis, fair value, and units held; smaller holdings are aggregated. Annual filings require a rollforward showing additions, dispositions, gains, and losses. The cost-basis method (FIFO, specific identification, or average cost) must be disclosed. For any holdings subject to contractual sale restrictions at the balance sheet date, the entity discloses fair value, the nature and remaining duration of the restrictions, and what would cause them to lapse.2Financial Accounting Standards Board (FASB). ASU 2023-08: Intangibles – Goodwill and Other – Crypto Assets (Subtopic 350-60)

Proving the Entity Actually Controls the Wallets

Existence, in crypto, splits into two questions. Whether the balance sits at a given address is trivially verifiable: pull the entity’s public wallet addresses, load a blockchain explorer, and confirm the balance as of the balance sheet date. Whether the entity controls those assets is the harder question, because a public address says nothing about who holds the private key that authorizes transfers.

The standard procedure is a signed-message test. You supply an arbitrary message, watch the entity sign it using the private key associated with the reported address, and then verify the signature against the public address on-chain. A valid signature proves the entity held the private key at the moment of the test. Run this against every self-custodied wallet the entity claims.3AICPA & CIMA. Auditing Digital Assets: Considerations for Existence and Rights and Obligations

How Storage Shapes the Procedures

Hot storage keeps keys online. Auditing hot storage means testing the security architecture around them: access logs, penetration testing results, and monitoring systems for unauthorized access attempts.

Cold storage keeps keys entirely offline, usually on dedicated hardware devices or similar air-gapped media. The audit turns physical. You may need to observe retrieval of a hardware device from a vault, confirm it has not been tampered with, and watch the signing happen in a controlled environment. The initial key-generation ceremony is worth attending or verifying through documentation, because that moment establishes the security of everything downstream.4PwC Switzerland. Crypto Custody: Risks and Controls From an Auditor’s Perspective

Multi-signature wallets require a minimum number of keys from a larger set to authorize a transaction. Verify that the entity controls at least the threshold number of keys, that the keys are held by distinct individuals, and that duties are segregated so no single person can move funds. Multi-party computation setups distribute key fragments across parties without ever assembling the whole key. The audit logic is similar in principle, but you have to understand the specific MPC protocol and confirm adequate controls cover each fragment throughout its lifecycle.

Fraud Signals

The FTX collapse showed how commingled funds and fabricated records can hide inside an exchange. Watch for wallet addresses that show large inflows immediately before audit dates followed by outflows shortly after; transactions routed through mixing services with no business purpose; balances that cannot be independently confirmed because the entity relies on a single internal system with no external verification; and addresses tied to known illicit activity. Any resistance to performing a signed-message test, or an offer of screenshots in place of live blockchain verification, is itself a red flag and should raise the assessed risk of material misstatement.

Measuring Fair Value

Because ASC 350-60 requires fair value every reporting period, valuation is no longer a once-a-year impairment exercise. Fair value follows ASC 820’s three-level hierarchy: Level 1 for quoted prices in active markets for identical assets, Level 2 for observable inputs on similar or less actively traded assets, and Level 3 for unobservable inputs requiring the entity’s own modeling.

Picking the Principal Market

Crypto assets trade on hundreds of exchanges at once, and prices differ meaningfully across them. ASC 820 requires measurement based on the principal market: the market with the greatest volume and activity that the entity can actually access. If no principal market can be identified, the entity uses the most advantageous market instead.

Most valuation disputes start here. Price aggregators that blend data from multiple exchanges are not themselves markets where a transaction would take place, so they can’t serve as the principal market source. The entity must identify a specific exchange it regularly transacts on and evaluate that exchange’s reliability, including regulatory oversight, operational history, and data quality. Trading pairs matter too: a token’s BTC pair and its USDC pair on the same exchange can show different liquidity, and each pair may produce a different implied fair value. Test the entity’s principal market determination by comparing its selected price against independent sources at the exact valuation date and time, with two or more independent corroborations as standard practice.5ICAEW. Considerations for Auditing Cryptocurrencies

Thinly Traded Tokens

Bitcoin and Ethereum generally qualify for Level 1 treatment. Tokens with thin volumes or narrow exchange listings move to Level 2 or Level 3, and Level 3 means the entity builds its own valuation model that you have to test assumption by assumption.

Common approaches for illiquid tokens include discounted cash flow analysis for tokens that generate yield, cost-based methods drawing on tracked development expenses, and scenario analysis for instruments like Simple Agreements for Future Tokens. Tokens with vesting restrictions often require a discount for lack of marketability, which may be estimated using option-pricing models adapted for the extreme volatility of digital asset markets.

Stablecoins, Airdrops, and Staking Rewards

A fiat-backed stablecoin is designed to trade at or near $1.00, but you can’t just accept the peg. Review the reserve composition and any third-party attestations. For algorithmic stablecoins, examine the collateralization mechanism and its resilience under stress. The GENIUS Act, signed into law in 2025, now requires permitted stablecoin issuers to back each coin on a one-to-one basis with U.S. currency or similarly liquid assets and to publicly disclose their redemption policy and monthly reserve details.6U.S. Congress. S.1582 – GENIUS Act

Assets from hard forks and airdrops raise a recognition question tied to tax treatment. Under IRS guidance, a taxpayer has no gross income from a hard fork alone; income arises when the taxpayer actually receives units of a new cryptocurrency and has dominion and control over them. The recognition date is generally when the asset is recorded on the distributed ledger, unless the taxpayer cannot yet transfer or dispose of it, in which case recognition is deferred until they gain that ability.7Internal Revenue Service. Revenue Ruling 2019-24

Staking rewards are typically measured at fair value on the date they become available to the entity. Trace the on-chain reward distribution records and confirm fair value at each distribution date.

Testing Custody and Key-Management Controls

Private key management is where a crypto audit either succeeds or fails. A lost or compromised key means permanent, irreversible loss; there is no fraud department to call. The control environment around keys deserves more attention than almost any other area.

Segregation of Duties

No single person should be able to generate a key, authorize a transaction, and hold the backup. Verify segregation through access logs, operational policies, and organizational structure. Dual control is the floor for transaction signing.4PwC Switzerland. Crypto Custody: Risks and Controls From an Auditor’s Perspective

Address whitelisting is another testable control. Well-run operations restrict withdrawals to pre-approved addresses, and adding a new address to the whitelist should require multiple independent approvals and a mandatory delay. Select a sample of high-value transactions and trace each one through the full approval workflow, from initiation to execution, confirming no step was bypassed.

Third-Party Custodians

When an entity uses a third-party custodian, the audit shifts from directly testing key controls to evaluating the custodian’s control environment. The primary tool is a Type 2 SOC 1 report covering the custodian’s internal controls over financial reporting, with testing results across a period. Focus on the sections covering key management, physical security of cold storage, and logical access controls. A SOC 2 report adds coverage of security, availability, processing integrity, confidentiality, and privacy. Review both for exceptions and evaluate whether any noted control failures could affect the entity’s financial statements. If the custodian’s SOC report doesn’t cover the full reporting period, or if you identify gaps in the complementary user entity controls the entity is responsible for, additional procedures are needed to bridge them.

Disaster Recovery

Business continuity carries existential weight in crypto custody. Review the entity’s plan for recovering access if a physical disaster destroys hardware, a system failure corrupts storage, or key personnel become unavailable. Confirm that backups exist in secure, geographically separate locations, that backup security matches the primary keys, and ideally observe a test of the recovery procedure to confirm it works.

Auditing DeFi Positions

When an entity holds positions in DeFi protocols, every position is governed by smart contract code rather than a counterparty’s discretion, and you need to understand enough about that code to assess the risks it creates.

Smart Contract and Oracle Risk

You typically won’t perform a code review yourself, but you do need to evaluate whether a qualified independent firm has audited the contract’s security. The scope and findings of that review matter: identified vulnerabilities, unresolved issues, and the reputation of the reviewing firm all feed the risk assessment. When no independent security review exists, the assets held in that protocol carry significantly higher risk, and you should consider whether the entity has adequately disclosed that exposure.

Many DeFi protocols rely on oracles to feed external data, particularly asset prices, into smart contract logic. Oracle manipulation is one of the most exploited attack vectors in DeFi. Protocols using a single liquidity pool as their price source are highly vulnerable because flash loans can temporarily distort pool prices. More robust designs use decentralized oracle networks that aggregate multiple sources, or time-weighted average prices that smooth short-term manipulation. Assess which mechanism the protocol uses and whether its safeguards are adequate.

Liquidity Pools

An entity that provides liquidity to a decentralized exchange or lending pool receives pool tokens representing a proportional share. Trace the initial deposit, verify pool token issuance, and recalculate the entity’s share using the protocol’s formula at the reporting date. Account for impermanent loss, which occurs when the relative prices of the deposited assets change after the deposit; it isn’t a realized loss in the traditional sense, but it affects the fair value of the pool token and must be reflected in the valuation. Accrued fees and interest need separate verification: trace fee accumulation on-chain and confirm the entity’s proportional entitlement based on the pool’s documented distribution formula.

Wrapped Tokens and CDPs

Wrapped tokens require dual verification. Confirm the wrapped token exists on the host blockchain, then verify that the corresponding native asset is held in reserve on the original blockchain. Cross-chain verification is more complex than single-chain work and may require examining the wrapping protocol’s reserve proofs or using specialized cross-chain monitoring tools.

Collateralized debt positions create both an asset and an obligation. Verify collateral deposited, amount borrowed, and the current collateralization ratio against the protocol’s liquidation threshold. If the ratio sits close to that threshold, assess whether the entity has disclosed the risk of automatic liquidation and whether any impairment or liability recognition is needed.

Governance Tokens

Governance tokens grant voting rights on protocol changes such as fee structures and collateral requirements. Evaluate whether the entity’s holdings give it significant influence or control over the protocol. If the entity can meaningfully direct the protocol’s operations through its voting power, the investment may require different accounting treatment than a passive holding.

What Proof-of-Reserves Reports Actually Prove

Exchanges began publishing proof-of-reserves attestations after FTX. Know what they show and what they don’t before you rely on one.

A typical PoR engagement has two parts. The exchange publishes or provides its on-chain wallet addresses, and the balances at those addresses are verified. The exchange also constructs a Merkle tree of all customer account balances, which lets individual customers verify their balance was included in the total without revealing other customers’ information. The attestor compares total on-chain reserves against total customer liabilities in the Merkle tree.

The limits are significant. A PoR is a point-in-time snapshot; an exchange could borrow assets to inflate its reserves before the attestation date and return them after. Signing a message proving control of a wallet does not prove ownership free of encumbrance; the assets could be borrowed or rehypothecated. A PoR typically doesn’t capture undisclosed liabilities, off-balance-sheet obligations, or intercompany transfers that would make the reserve picture misleading. It is not a full audit. It doesn’t examine internal controls, test for fraud, evaluate going concern, or opine on the financial statements as a whole. Treat any PoR report from an exchange or custodian as limited evidence of asset existence at a single point in time, and supplement it with procedures covering the full reporting period.

Reconciling With Tax Reporting

Brokers must report gross proceeds from digital asset transactions on Form 1099-DA starting in 2025. Beginning January 1, 2026, brokers must also report cost basis for certain transactions, giving the IRS a much fuller picture of taxpayer gains and losses.8Internal Revenue Service. Final Regulations and Related IRS Guidance for Reporting by Brokers on Sales and Exchanges of Digital Assets

The entity’s cost-basis records are now subject to external verification in a way they weren’t before. Test whether the entity’s internal tracking of acquisition dates, purchase prices, and disposal proceeds reconciles with the information that will appear on Form 1099-DA. Discrepancies between the entity’s records and broker-reported data create potential tax liabilities that may need recognition or disclosure.

The cost-basis method the entity selects — FIFO, specific identification, or average cost — must be disclosed under ASU 2023-08 and applied consistently. Verify the chosen method is actually being followed and that lot-level tracking supports the reported gains and losses.2Financial Accounting Standards Board (FASB). ASU 2023-08: Intangibles – Goodwill and Other – Crypto Assets (Subtopic 350-60)

One boundary worth flagging: as of early 2026, the wash sale rule that applies to stocks and securities does not apply to digital assets. An entity can sell a crypto asset at a loss and repurchase it immediately without the loss being disallowed. Entities with aggressive tax-loss harvesting strategies should disclose the risk that future legislation could close this gap.

Classifying the Token Before Anything Else

Not every digital asset is treated the same, and classification often determines which accounting framework, regulatory regime, and audit procedures apply. The SEC uses the Howey test to determine whether a digital asset qualifies as a security: an investment of money in a common enterprise with a reasonable expectation of profits derived from the efforts of others.9U.S. Securities and Exchange Commission. Framework for Investment Contract Analysis of Digital Assets

If a token is a security, registration or an exemption is required, and the full federal securities disclosure framework applies. Verify that the entity has properly classified its holdings and accounted for any securities under the appropriate GAAP framework rather than defaulting to ASC 350-60. Payment stablecoins issued under the GENIUS Act are explicitly not securities under that legislation, but other stablecoins without that designation may still face classification questions.6U.S. Congress. S.1582 – GENIUS Act

Utility tokens that provide access to a platform’s services, governance tokens that grant voting rights, and tokens that generate yield through staking or lending each carry different risk profiles and may require different audit approaches. With any unfamiliar token, assess classification first, then choose the valuation and disclosure framework that fits.