On May 1, HTX published a proof-of-reserves snapshot that was supposed to reassure users. It failed. By May 30, 71,853.22 stETH — worth roughly $135 million — had left the very address HTX called its reserve. The funds traveled through two intermediate wallets and stopped inside an address Etherscan labels Poloniex 9. That same address carried an older tag: Justin Sun 4. This is not asset custody. This is a shell shifting weight between its own pockets. Code does not lie, but it often omits the truth. What HTX omitted is who actually controls the assets users think are safe.
Proof-of-reserves was designed to replace trust with arithmetic. Merkle trees, signed addresses, independent auditors, live verification. HTX's latest report has none of that. Instead, it hides assets behind a category called "ThirdParty." No entity named. No signature. No way to verify. The chain is only as strong as its weakest node, and HTX's weakest node has always been custody.
Let me walk the path with precision.
- The reserve snapshot shows 71,853.22 stETH in 0x18709e89bd403f470088abdacebe86cc60dda12e.
- On May 30, the full balance moved to 0x7C103bbAE0DA51AE929dE97A98633668ddE80d04.
- From there, the funds moved to 0x8FCA4adE3a517133fF23ca55CdAea29C78C990b8 — an address Etherscan labels Poloniex 7.
- Then to 0x29065a4C1f2F20d1E263930088890d6F49Fe715a — Poloniex 10.
- Finally to 0x176F3DAb24a159341c0509bB36B833E7fdd0a132 — Poloniex 9, previously tagged "Justin Sun 4."
Etherscan labels are not court exhibits. They are breadcrumbs maintained by a private labeling team. But when four separate jumps trace a single control group — HTX, Poloniex, and Justin Sun are not strangers; they are overlapping shells — the pattern becomes a signal. In my own experience tracking exchange flows, including a 2020 audit of the Zcash Sapling implementation, I learned that labels are the beginning of an investigation, not the end. This trail does not end well for HTX.
The deeper issue is not the stETH itself. The issue is what HTX chose not to disclose. If a genuinely independent custodian held the stETH, HTX could have named it. It did not. The only reason to use the word "ThirdParty" is to avoid saying "Poloniex" or "Justin Sun." That is not transparency. That is a dark pool wearing a name tag.
TRM Labs has sharpened the accusation. According to the report, HTX rapidly rotates addresses to stay ahead of sanctions screening. Address rotation is legitimate when done for privacy or key security. When done to evade OFAC filters, it ceases to be security. It becomes concealment. The May transfers look less like treasury management and more like a system designed to be un-linkable. Scalability is a trilemma, not a promise. But this is not about scalability. It is about controllability, and HTX is optimizing for un-controllability.
Now examine the Bitcoin position. The report alleges that more than half of HTX's reported Bitcoin holdings are not native BTC but tokenized BTC, worth hundreds of millions. Tokenized Bitcoin is a claim on Bitcoin, not Bitcoin itself. If the issuer is an independent, audited custodian, the claim is tolerable. If the issuer is Poloniex or another Justin Sun-affiliated entity, the claim becomes a double-entry promise with no visible underlying reserve. The chain is only as strong as its weakest node. A tokenized-BTC stack held by an affiliate is two weak nodes holding each other up.
Let me be surgical about the hidden structure. HTX appears to be using Poloniex as an off-balance-sheet asset pool. The reserve report says: we have assets. The on-chain trail says: those assets sit with a related party. This lets HTX deliver a headline number while keeping actual custody dark. To the user, the promise is "your stETH is safe." To the investigator, the reality is "your stETH is inside a control network whose labels change faster than its ownership."
Is this theft? I lack evidence to say theft. It may be sloppy treasury management. It may be an attempt to keep assets beyond the reach of subpoenas. It may be all of the above. But in a post-FTX market, intent matters less than structure. FTX was not prosecuted because of Alameda's intent; it was prosecuted because the structure allowed assets to mix without user visibility. HTX's new reserve categories recreate that structure.
The contrarian reading: perhaps assets are simply pooled for liquidity. Exchanges frequently move funds between wallets to manage withdrawals and market-making. Poloniex and HTX share a parent. Moving funds between affiliates is not inherently criminal. But proof-of-reserves is designed to remove the need for "perhaps." If users must assume good faith from a holding company that rotates addresses to avoid sanctions screening, the proof is meaningless.
There is also legal fragility. If HTX is rotating addresses to stay ahead of OFAC screening, every downstream exchange that accepts HTX funds inherits that contaminated history. The stETH in Poloniex 9 is not just an asset. It is a liability awaiting a subpoena. The compliance risk does not stay inside HTX. It radiates to every counterparty that touches the same custody graph.
Takeaway: The next time HTX publishes a reserve report, ignore the total. Read the line items. If the words "ThirdParty" appear without a name, ask one question: third party relative to what? Relative to a publicly listed custodian with audited controls, or relative to another pocket of Justin Sun's empire? Proof-of-reserves only works when the custodian is independent, audited, and named. HTX has replaced all three with a category label. Verification is not a white-glove service. It is the price of admission. And in this case, the admission price has been paid in stETH by users who will never see the fine print.