Deribit, a prominent cryptocurrency derivatives exchange, is set to discontinue its daily public Proof of Reserves (PoR) page on September 1, a move that will remove a critical tool for clients to independently verify the inclusion of their balances and reconcile aggregate liabilities against published wallet holdings. While the exchange assures that regulator-required reserve, reconciliation, and audit controls will remain in place, these measures will not offer the same level of immediate public transparency that the daily Merkle check provided. This strategic shift coincides with a significant migration of client assets to Coinbase custody and a broader overhaul of Deribit’s wallet infrastructure, raising questions about the future accessibility of verifiable asset data for its user base.

The exchange, in a communication detailing the change, cited the ongoing integration with Coinbase as the primary driver for discontinuing the daily PoR publication. Since Coinbase’s acquisition of the derivatives platform in August 2025, Deribit has progressively transferred approximately 90% of its client assets into custody arrangements managed by Coinbase. The disclosures from Deribit identify Coinbase at a brand level but do not specify the precise legal entity within the Coinbase umbrella that is holding these substantial migrated assets. This lack of granular detail could potentially complicate due diligence efforts for some stakeholders.

The Mechanics of Deribit’s Proof of Reserves

Deribit’s previous PoR system was built upon a foundation of privacy-preserving technology, employing a daily snapshot of client balances and a Merkle tree structure. This methodology allowed each client to utilize a unique proof identifier to locate the hashed entries corresponding to their individual account balances within the larger dataset. Concurrently, any interested party, including clients and the broader public, could sum the total liabilities presented in the daily file and compare this aggregate figure against the wallet balances that Deribit publicly disclosed. This dual-layer verification process was designed to foster trust and provide a tangible method for users to confirm the exchange’s solvency.

However, the scope of this public snapshot was not all-encompassing. Deribit’s own methodology acknowledged that assets held by third-party custodians were excluded from the public PoR calculation. The rationale provided was that these assets were outside of Deribit’s direct control. The exchange previously named Copper ClearLoop as an example of such an excluded custodian. A critical, and as yet unaddressed, point of clarification is whether the assets now held by Coinbase, representing a substantial majority of client funds, were already excluded from the previous public PoR calculations prior to this change, or if their migration to Coinbase custody is the direct catalyst for the removal of the public verification tool.

Deribit moved 90% of client assets to Coinbase, then killed its daily proof-of-reserves check

Transition to Less Public Verification Methods

Following the September 1st transition, Deribit has not announced any plans for a replacement public dashboard or a continuation of the client-level Merkle verification process. Instead, the exchange has indicated that clients and counterparties will need to rely on alternative forms of due diligence. These will include the ability to request audited financial statements and other relevant due-diligence materials. While these documents serve as crucial components of regulatory compliance and institutional trust, they represent a less frequent and less directly verifiable form of evidence compared to the daily, self-service checks previously available. This shift moves away from real-time, user-initiated verification towards a more retrospective and auditor-dependent assurance model.

Regulatory Framework and Remaining Controls

The discontinuation of Deribit’s public PoR page does not absolve Deribit FZE, the Dubai-based entity, of its regulatory obligations. In Dubai, the Virtual Assets Regulatory Authority (VARA) mandates that covered virtual asset service providers (VASPs) maintain reserves equivalent to 100% of their client liabilities. These reserves must be held one-to-one in the same asset class and reconciled on a daily basis. Furthermore, VARA requires independent third-party reserve audits to be conducted at least every six months.

Deribit’s own disclosures have previously referred to both annual and semi-annual Proof of Reserves audits. The VARA rulebook sets a minimum frequency of once every six months for these reserve audits. Additionally, a separate VARA provision mandates an annual financial statement audit, with the resulting annual report being made accessible to both clients and the regulator upon request. These regulatory requirements ensure that while public visibility might decrease, a framework of independent oversight and verifiable financial health remains.

Regulator-Facing Reporting and Transparency

Beyond reserve audits, covered firms operating under VARA’s purview are obligated to submit a range of information to the regulator. This includes monthly submissions of wallet addresses and quarterly statements that demonstrably prove compliance with financial requirements, crucially including the status of reserve assets. These regulator-facing reporting mechanisms are designed to provide VARA with continuous oversight and the ability to intervene if necessary, even if this information is not directly accessible to the general public.

VARA’s public register confirms that Deribit FZE holds an active license as a VASP, functioning as both an exchange and a broker-dealer. The exchange’s membership terms, as outlined in its support documentation, permit assets to be held either directly by Deribit or through third-party custodians. A key stipulation is the mandatory segregation of client assets from the company’s own corporate assets, ensuring that clients retain their legal title to their holdings. The recent list of authorized third-party service providers explicitly names Coinbase for both custody and self-custody technology, though, as previously noted, the specific legal entity within Coinbase remains unspecified.

Deribit moved 90% of client assets to Coinbase, then killed its daily proof-of-reserves check

Implications and Market Analysis

The removal of Deribit’s daily public Proof of Reserves check represents a significant reduction in the level of readily available, user-verifiable information regarding the exchange’s asset holdings. While the move is framed as a consequence of infrastructure changes and increased reliance on Coinbase custody, it undoubtedly shifts the burden of assurance from a transparent, daily public verification to a more indirect, request-based system involving audited reports.

This change could have several implications for market participants:

  • Reduced Transparency: The most immediate impact is a decrease in the transparency of Deribit’s operations. Clients accustomed to daily self-verification will lose this direct oversight.
  • Increased Reliance on Audits: The reliance on periodic audits and financial statements means that any potential issues might be identified and disclosed with a delay, compared to the real-time nature of the previous Merkle checks.
  • Due Diligence Burden: Clients and counterparties will need to be more proactive in conducting their own due diligence, requesting and scrutinizing the provided documentation. This may disproportionately affect smaller retail investors who may lack the resources or expertise for such detailed analysis.
  • Market Confidence: While Deribit operates under a robust regulatory framework in Dubai, the reduction in public transparency could, for some market participants, lead to a subtle erosion of confidence, especially in an industry that has historically grappled with trust issues following past exchange collapses.
  • Industry Trend: This move by Deribit could potentially signal a broader trend among exchanges to streamline or reduce public-facing PoR mechanisms, especially as custody solutions become more integrated and regulated. However, it also highlights the ongoing tension between operational efficiency, regulatory compliance, and the demand for radical transparency from crypto users.

It is crucial to emphasize that the removal of the public page is not, in itself, evidence of a reserve shortfall. Rather, it signifies a fundamental change in how asset backing is communicated to the public, moving from a directly verifiable daily snapshot to a system that relies more heavily on formal audits and direct requests for information. The effectiveness and perceived trustworthiness of this new system will largely depend on the rigor of the remaining regulatory controls, the frequency and depth of independent audits, and the responsiveness of Deribit in providing requested documentation to its clients and counterparties. The long-term impact on Deribit’s market position and user trust will likely be shaped by how effectively it navigates this transition and addresses any residual concerns about asset visibility in the post-September 1st era.