Loading prices…

How to Read an RWA Attestation Report: A Plain-English Guide

Most RWA attestation PDFs are 30+ pages of accounting language. Here are the four lines and two ratios that actually tell you whether the token is safe.

How to Read an RWA Attestation Report: A Plain-English Guide

What an RWA attestation report actually is

A tokenized real-world asset (RWA) is a blockchain token that claims to represent a share of an off-chain asset, usually a U.S. Treasury bill, a short-duration bond, or a money-market fund share. The token only has value if the off-chain asset exists, is owned by the issuer, and is worth what the issuer says it is. The attestation report is the document that is supposed to prove this.

Here is the part that trips people up. An attestation is not the same thing as an audit. A financial audit, the kind a public company files, is a full examination of financial statements under Auditing Standards (GAAS) or International Standards on Auditing (ISA), and it ends in an opinion on whether the statements are fairly presented. An attestation is a narrower engagement. The issuer prepares an assertion (called a management assertion), and an independent CPA firm performs procedures to test that assertion. The output is a report, not a clean-or-qualified opinion on the whole company.

Two flavors cover most of the RWA market you will see. Point-in-time attestations check a single date, like a wallet balance or a share registry at 5pm on the last day of the month. Period-of-time attestations cover a window, often monthly, and reconcile things like issuance, redemption, and yield accrual across the whole period. The type matters because a point-in-time report tells you nothing about what happened in between, and a period-of-time report can miss a snapshot mismatch that exists right now.

The four lines that matter, and the two ratios you can compute from them

Open any attestation PDF for a major tokenized Treasury product like BUIDL, USDY, OUSG, USYC, or USTB, and you will find a long table of figures. Most of them are accounting scaffolding. Four lines carry almost all the signal.

The first line is total assets. This is the dollar value of what the issuer's vehicle actually holds, including cash, T-bills, repo agreements, and any incidental interest receivable. The second line is total liabilities. For a tokenized Treasury, this is usually small (a custody fee, a payable to the manager), but it is the line that turns total assets into net asset value. The third line is net asset value (NAV). NAV is what one share of the underlying fund is worth, to several decimal places. The fourth line is the reserve composition breakdown, which tells you, in percentages, how the total assets are split between, say, U.S. Treasury bills maturing in under 90 days, reverse repurchase agreements collateralized by Treasuries, and money-market fund shares.

From those four lines you can compute two ratios that do most of the risk-detection work. The first is the NAV-to-supply ratio. Divide the NAV by the on-chain token supply. The result should equal the token's stated price per token, usually 1.00 USD for a tokenized money-market product. If it does not, something is off in the reconciliation, and you should look at the auditor's notes. The second is the liquidity-coverage ratio. Divide the value of assets maturing in under 30 days by the liabilities. For a tokenized Treasury, anything above 10 is comfortable, because the fund can meet every redemptions wave in the next month without rolling positions.

Big-4 audit vs AICPA SOC report, and why the difference matters

When you read crypto Twitter, you will see claims like 'audited by a Big-4 firm' or 'SOC 2 Type II compliant.' These are not the same thing, and the difference has real consequences for what you can rely on.

A Big-4 (or large national) audit firm is one of the biggest global accounting networks. The brand is a soft signal of quality, but the engagement still defines the deliverable. A Big-4 firm can write a SOC 1 report, a SOC 2 report, or an attestation under the AICPA's AT-C standard, and each of those has different evidence requirements. The brand on the letterhead is not the assurance.

An AICPA SOC 1 report is about internal controls over financial reporting. It tells you whether the issuer's controls around share issuance, redemption, and reconciliation are designed and operating effectively. A SOC 2 report is about security, availability, and processing integrity. Tokenized-asset issuers increasingly publish SOC 2 Type II reports, which cover a window (usually 6 or 12 months) and are good evidence for operational hygiene, but they say nothing about whether the assets are real or about the NAV. For that you want the AT-C attestation, sometimes called an examination report under SSAE 18. That is the document that contains the four lines above.

Practical rule. If an issuer's marketing page only links to a SOC 2 and calls it 'audited,' treat it as a marketing document, not a fidelity claim. The real evidence is the AT-C report, dated within the last 90 days, with a clean opinion paragraph and no scope-limitation paragraph.

Real red flags: auditor changes, scope limitations, qualified opinions

Every attestation report has a section near the end titled something like 'Basis for Opinion' or 'Procedures Performed.' That is where the risk lives. Three phrases in particular tell you whether the issuer is being transparent or hiding something.

The first red flag is a change of auditor between reports. If the previous month was signed by a national firm and the current month is signed by a small local practice, ask why. Common benign reasons do exist (a parent-company reorganization, fee renegotiation), but unexplained switches are how past collapses in crypto started. The 2022 failure of the centralized Voyager entity, for example, was preceded by disclosure friction with its previous auditors, and the 2022 collapse of the Terra algorithmic stablecoin had no auditor at all. Auditor continuity is a soft signal, but it is a free signal.

The second red flag is a scope limitation. This is a paragraph where the accountant says they could not perform a procedure they wanted to perform, usually because management did not provide records or because a third party (a custodian, a transfer agent) did not respond to a confirmation request. The phrase to look for is 'except as described in our report' or 'subject to the following.' A single isolated scope limitation is not fatal. Repeated scope limitations across reports, or a scope limitation on something as basic as confirming the cash balance, is a serious signal.

The third red flag is a qualified opinion. This is the accountant saying, in formal language, that the report is fine except for one specific issue. The classic example is 'the financial statements are fairly presented except for the effects of the matter described in the basis-of-emphasis paragraph.' If that paragraph describes a difference between the on-chain supply and the audited share registry, you have a real problem. A qualified opinion is not a clean bill of health, and the issuer's marketing page will almost never mention it. You have to read the report.

How on-chain supply should reconcile to the attestation's NAV

Every tokenized Treasury product has a token supply visible on a block explorer. That supply, multiplied by the token's nominal price, should equal the NAV in the attestation report, plus an allowance for issuance and redemption in flight at the report's cut-off time.

The reconciliation works like this. On the day the report covers, the issuer's subscription queue has a list of pending mints. The redemption queue has a list of pending burns. Both have dollar values. The NAV should equal (tokens in circulation at the snapshot time × nominal price) plus (pending mints at the nav-per-share) minus (pending redemptions at the nav-per-share). If it does not, there is a rounding gap, a queue mismatch, or a real problem. The report will usually cite a tolerance, like 'rounding difference not exceeding $50.'

What you actually want to do is compute the gap yourself. Pull the token supply from a reliable explorer, multiply by the stated per-token value, and compare to the NAV. A persistent gap larger than the report's stated tolerance, or a gap that grows month over month, is a signal. Some of the largest 2022 centralized-finance failures showed exactly this pattern in the months before the collapse: the supply number on the marketing page was not the supply number on the audited statement. You will not always have access to the explorer data the issuer uses, but you can usually triangulate from the largest block explorer and the issuer's own dashboard.

What the report does not tell you

Even a clean attestation report does not eliminate several risks that token holders care about. The first is market risk. A tokenized Treasury fund holds Treasuries, and Treasuries can lose value if interest rates move sharply. The report covers holdings at a point in time, not the forward path of rates. The second is legal risk. The token is a contractual claim against the issuer, not a direct ownership claim on the underlying assets. If the issuer goes bankrupt, the token holders are unsecured creditors, and the recovery depends on the bankruptcy court's treatment of the assets the issuer held in custody. The third is counterparty risk. The report confirms the assets exist on the report date, but if the custodian fails the next day, the report is not a guarantee. The fourth is technology risk. The on-chain token can be compromised by a smart-contract bug, even if the off-chain assets are pristine. The 2022 Wormhole bridge exploit is the canonical example of a perfect off-chain backing paired with a broken on-chain representation.

Attestation is an evidence layer. It is the most rigorous evidence that exists in the RWA tokenization market today, and it is a real achievement that major issuers publish them monthly. It is not a guarantee of safety, and it is not the same as supervision. Treating it as one or the other is a category error.

How to follow RWA attestation news the smart way

RWA tokens move fast, and the attestation reports that back them move faster. Tracking which issuers publish on time, which switched auditors, and which added a scope limitation is a losing game if you try to do it by hand. Zippfeed surfaces RWA headlines with sentiment scoring (bullish, neutral, or bearish) and an importance rating, so you can spot the risk signals before they make the front page.

Frequently asked questions

What is a point-in-time vs period-of-time attestation in RWA tokenization?
A point-in-time attestation checks a single date, usually the last day of the month, and confirms balances as of that moment. A period-of-time attestation covers a window, often one month, and reconciles issuance, redemption, and yield across the whole period. Point-in-time reports miss movement between reports. Period-of-time reports can miss a snapshot mismatch that exists right now. Most major tokenized Treasury products publish both each month.
Is an RWA attestation report the same as an audit?
No. An audit is a full examination of financial statements under GAAS or ISA and ends in an opinion on whether the statements are fairly presented. An attestation is a narrower engagement where the issuer prepares a management assertion and an independent CPA firm performs procedures to test it. The output is a report, not a fair-presentation opinion. Most RWA attestations are AT-C examinations under the AICPA's SSAE 18 standard, which is rigorous but not identical to a full audit.
Should I trust a tokenized Treasury product with a Big-4 auditor?
The brand on the letterhead is a soft signal of quality, but the engagement type is what matters. A Big-4 firm can write a SOC 1, a SOC 2, or an AT-C attestation, and each has different evidence requirements. The brand is not the assurance. For tokenized Treasury products, the document that actually verifies the assets and NAV is the AT-C examination report, not the SOC 2 report. This is education, not financial advice, and you should read the report yourself before trusting any product with your money.
What is a qualified opinion in an RWA attestation report?
A qualified opinion is the accountant's formal way of saying the report is fine except for one specific issue. It usually appears as a paragraph beginning with 'except for' or 'subject to.' For a tokenized Treasury, the most common qualified clause is a mismatch between the on-chain token supply and the audited share registry. A qualified opinion is not a clean bill of health, and most issuers will not mention it on their marketing page. You have to read the report's opinion paragraph to see it.
Related tokens
$BUIDL $USDY $OUSG $USYC $USTB