A stablecoin attestation is a snapshot opinion from an independent accounting firm that the reserves a publisher claimed on a specific date roughly match its books; a reasonable-assurance audit is a far more rigorous examination under AICPA standards that tests controls, sampling, and evidence. Only a handful of dollar stablecoins have ever been audited, which is why most reserve reports you read are attestations rather than audits.
Key takeaways
- An attestation and an audit are different services under AICPA AT-C sections, and the standard used determines what the opinion actually proves.
- Reserve-at-a-date evidence says nothing about whether the issuer stayed solvent the day after the report was signed.
- Big-4 reasonable-assurance audits are rarer than small-firm attestations, partly because the issuer pays the firm doing the work.
- Tether's choice to publish attestations rather than audits has been a deliberate, multi-year position, and BUSD's collapse shows what an unregulated attestation regime looks like in practice.
Why stablecoin reserve reports confuse almost everyone
If you have ever compared USDC, USDT, BUSD, or TUSD and tried to figure out which one is safest, you have probably run into a wall. Every issuer says they are backed. Every issuer posts a report. And every issuer calls that report, in casual language, an audit. They are not the same thing, and the gap between them is large enough to change how you should think about the risk of holding any stablecoin.
The confusion is not accidental. Words like audited, verified, attested, and reviewed are used interchangeably in marketing copy, even though they describe services with very different levels of scrutiny. A reasonable-assurance audit, the kind most readers imagine when they hear the word, requires an accounting firm to gather evidence, test internal controls, sample transactions, and issue a formal opinion. An attestation, by contrast, can be a much narrower engagement in which the firm expresses a lower level of confidence, often about a single date, using a limited set of procedures.
Understanding the difference matters because stablecoins hold trillions of dollars of cumulative user funds and have already failed. The 2022 collapse of TerraUSD showed that algorithmic claims of being backed were worthless the moment confidence broke. The Paxos-issued BUSD episode showed a different problem: an issuer whose reserves were attested rather than audited, and whose attestation regime quietly ended when regulators got involved. If you hold stablecoins, you are trusting the issuer's claim about its own solvency. The level of independent verification behind that claim is the difference between trust and verification.
The real risks of mistaking an attestation for an audit
The first risk is the false sense of security. When Circle publishes a report and the press calls it an audit, a reader reasonably assumes an accounting firm has poked through every transaction, tested every control, and concluded that USDC is solvent. What the firm has actually done, in many cases, is verify that on one specific date, the assets Circle reported roughly matched the liabilities Circle reported. That is meaningful, but it is a much weaker claim.
The second risk is date dependence. A reserve-at-a-date report, which is what most stablecoin attestations are, says nothing about what happened the day before or the day after. If the issuer moved money out of reserves on March 31 at 11:59 PM and moved it back on April 1 at 12:01 AM, a snapshot opinion might still be issued. This is not a hypothetical concern. Several stablecoin issuers have been criticized for structuring their reporting windows to coincide with favorable balances.
The third risk is the issuer-pays-the-firm problem. The accounting firm that signs the opinion is paid by the stablecoin issuer. This is true for audits of public companies too, but in the public-company world, an audit committee of independent directors picks the firm, and the auditor faces severe liability if it misses a material misstatement. In stablecoin attestations, the engagement is often narrower, the liability is often capped by contract, and the firm's incentive to push back on a large client can be real.
The fourth risk is the collapse precedent. BUSD was, for most of its life, attested rather than audited. When New York regulators forced Paxos to stop minting BUSD, the attestation regime simply stopped, and holders were left wondering what the reserves looked like at the moment of wind-down. The lesson was not that BUSD was a fraud. The lesson was that attestation regimes can vanish overnight with no warning, while audit opinions have legal weight and continuity.
What an attestation actually is, in plain English
An attestation is a service performed by an independent certified public accountant under professional standards set by the AICPA, the American Institute of Certified Public Accountants. The relevant standards live in the AT-C sections of the AICPA's codification. These sections cover several flavors of attestation, and they differ in how much work the CPA does and how much confidence the opinion expresses.
The most common level is a limited assurance engagement, sometimes called a review-level attestation. The CPA performs inquiry and analytical procedures, checks whether the numbers tie to source documents, and issues an opinion that says whether anything came to their attention suggesting the numbers are materially wrong. The opinion language is carefully hedged: nothing came to our attention, rather than these numbers are correct.
There is also a reasonable-assurance attestation, which is closer to an audit in depth but is still not the same as a full financial statement audit. The CPA gathers more evidence, performs more substantive testing, and expresses positive assurance: in their opinion, the numbers are fairly stated. Many stablecoin reserve reports issued by smaller firms fall into this category, and they are stronger than review-level reports but still narrower than a full audit.
The crucial point is that an attestation is defined by the engagement and the standard, not by the word on the cover page. If a CPA signs a report and says it is an attestation under AT-C section 205 or 210, that is what it is, regardless of how the issuer markets it. If the report claims to be an audit but does not follow the auditing standards of the AICPA's AU-C sections, then it is not an audit, no matter what the headline says.
What an audit actually is, in plain English
An audit is governed by a different set of standards, also written by the AICPA, but in the AU-C sections rather than the AT-C sections. These are the standards used to audit public companies in the United States, and they require a much deeper level of work than any attestation.
Specifically, an audit requires the CPA to obtain an understanding of the entity's internal controls, assess the risk of material misstatement, design audit procedures in response to that risk, perform substantive testing on a sample basis, evaluate going concern, and issue a formal opinion on whether the financial statements are fairly stated in accordance with the applicable reporting framework. The opinion covers the financial statements as a whole, not just a single date or a single number.
For stablecoins, a full audit would mean the firm has tested whether the reserves actually existed on the date of the report, whether they were properly controlled by the issuer, whether the liabilities match what was issued and redeemed, and whether the controls around minting and burning are working. The firm also confirms that the assets are what the issuer says they are, which matters for stablecoins that hold commercial paper, treasury bills, certificates of deposit, and other instruments that vary in liquidity and credit quality.
Only a small number of stablecoin issuers have ever had a full audit at the reasonable-assurance level. Circle, the issuer of USDC, has historically obtained attestations rather than full audits, although it has increased the rigor of its reporting over time. Tether, the issuer of USDT, has consistently published attestations and has explicitly declined to obtain a full audit, citing cost and complexity. TUSD and BUSD have historically published attestations from smaller firms. The pattern is consistent: attestations dominate, audits are rare.
Why Big-4 audits are not the same as 'fully backed'
There is a second layer of confusion that the Big-4 accounting firms (Deloitte, PwC, EY, and KPMG) tend to be involved. When a Big-4 firm signs a stablecoin report, readers often assume the highest level of scrutiny has been applied. That is usually not the case, because the Big-4 engagement is itself typically an attestation rather than an audit.
A Big-4 attestation is still better than a small-firm attestation in several ways. The firm has more resources, more specialized expertise in financial instruments, and a stronger professional reputation at stake. It is also harder for an issuer to quietly switch firms if it does not like the answers, because the Big-4 firms are fewer and the relationship is more visible. But the underlying standard, if it is AT-C rather than AU-C, is still the attestation standard, and the opinion still says what the attestation standard says it says.
This is why the Big-4 versus small-firm distinction is important but not decisive. A Big-4 attestation is stronger than a small-firm attestation. A Big-4 reasonable-assurance audit is stronger than a Big-4 attestation. And no report of any kind proves that the issuer stayed solvent every day of the year, only that the evidence the firm examined supports the opinion it issued on the date it was issued.
For a stablecoin holder, the practical takeaway is to read the actual opinion paragraph of any reserve report, not just the headline. Look for the engagement standard (AT-C section 205, 210, 305, or AU-C section overall), the level of assurance (limited or reasonable), the date or period covered, and the specific subject matter of the opinion. If those four things do not add up to what the marketing says, the marketing is overstating the case.
The BUSD precedent: what an unregulated attestation regime looks like
BUSD is the cleanest case study in why attestation regimes are not equivalent to audits. BUSD was issued by Paxos Trust Company, a New York-regulated trust, and for most of its life its reserves were attested by a smaller accounting firm. The reports were labeled in ways that suggested rigorous independent verification, and they were generally accepted as such.
When the New York Department of Financial Services ordered Paxos to stop minting BUSD in February 2023, the attestation regime did not provide a graceful wind-down. Holders had no audited financial statements to point to, no going-concern opinion, and no formal assurance that the reserves at the moment of wind-down matched the liabilities outstanding. Paxos honored redemptions and the stablecoin wound down without losses to holders, but that outcome was a function of the regulator's involvement and Paxos's own operational capacity, not of the attestation regime itself.
The lesson from BUSD is that an attestation regime is only as strong as the regulatory framework around it. When a regulator steps in, an attestation stops being useful because the issuer can no longer operate the way the attestation assumed. An audit, by contrast, produces a historical record with legal weight, and the financial statements remain useful even if the issuer's business changes overnight.
This is also why the Tether position is worth understanding. Tether has, for years, declined to obtain a full audit and has instead published attestations from smaller firms, most recently BDO. The choice has been deliberate and has been explained by Tether as a matter of cost, complexity, and the fact that Tether's reserves include instruments that are harder to audit at the reasonable-assurance level. Whether or not that explanation is satisfying, the practical effect is that USDT holders have always relied on a weaker form of verification than USDC holders, regardless of how the reports are described in headlines.
How to read a stablecoin reserve report without getting fooled
The single most useful habit is to find the actual opinion paragraph. It is usually near the end of the report, in a section titled something like Report of Independent Accountants or Opinion. The opinion will state what was examined, what standard was followed, and what level of assurance is being expressed. If the report does not include that paragraph, or buries it, that itself is a signal.
Next, look for the date. A report dated March 31 tells you the reserves as of March 31, not as of any other date. If the issuer is making claims about being fully backed on an ongoing basis, the report does not support that claim. It supports a snapshot.
Then look at what the reserves actually are. Treasury bills are different from commercial paper, which is different from certificates of deposit, which is different from bitcoin, which is different from receivables. A report that says reserves total $X billion is less informative than one that breaks down the composition by asset class, maturity, and credit quality. Attestations often include this breakdown, but the level of detail varies widely.
Finally, check who signed the report. A Big-4 firm is not the same as a small firm, and a long engagement history with the same firm is not the same as a new engagement. Stablecoin issuers that have stable, long-standing relationships with their accounting firms tend to provide more consistent reporting than those that rotate firms frequently. That is a soft signal, but it is one worth weighing.
What to actually do with this information
If you hold stablecoins, the practical implication is that you should not assume any stablecoin is audited unless you have personally confirmed it. The default assumption should be that the issuer's reserve report is an attestation, that it covers a single date, and that the firm signing it is paid by the issuer. None of those facts make the stablecoin unsafe, but they should set your expectations.
For larger holdings, the difference matters more. A few hundred dollars in USDC is a different risk profile from a few hundred thousand dollars in any single stablecoin, because the consequences of an attestation regime ending overnight scale with the size of the position. Diversifying across more than one issuer is the simplest hedge against the failure of any single attestation regime.
None of this is financial advice, and none of it changes the basic truth that stablecoins carry risks that no report can fully eliminate. The reports are useful, and they are much better than nothing, but they are not the same as a regulator-insured bank deposit and they should not be treated as one.
Stay ahead of stablecoin reporting changes
Stablecoin reserve reporting is evolving, with new regulations in the United States, Europe, and elsewhere pushing issuers toward more rigorous standards. The reports that issuers publish will change in form and substance over the next several years, and the names of the firms signing them will rotate. Tracking those changes by hand is impractical for most users. Zippfeed surfaces stablecoin headlines with sentiment scoring and an importance rating, so you can see which reserve reports actually matter and which are routine.