The standard method builds a merkle-tree of all customer balances and publishes the root, so each customer can check their own balance is included without seeing anyone else's. The custodian also proves control of on-chain wallets by signing messages or moving funds.
The obvious gap is liabilities. Proving you hold 100,000 coins says nothing if you owe 150,000, and nothing stops borrowed assets being paraded through a wallet on the snapshot date. A meaningful proof must cover liabilities too, and be repeated frequently rather than once after a scare.
Treat it as a partial control rather than a guarantee. Several firms that published reserve figures still failed, because the missing pieces were off-balance-sheet debts, related-party lending and outright fraud. Holding coins yourself in self-custody removes the question entirely, at the cost of taking key management seriously.
Related: merkle-tree, exchange-insolvency-risk, stablecoin-attestation, self-custody