Deribit moved 90% of client assets to Coinbase, then killed its daily proof-of-reserves check

Deribit announced it will discontinue its public Proof of Reserves page on September 1, removing a daily transparency tool that allowed customers to independently verify their account balances and cross-check the exchange’s total liabilities against its published wallet holdings.

The derivatives exchange attributed the change to a wallet infrastructure overhaul occurring as part of its integration with Coinbase, which acquired Deribit in August 2025. Approximately 90% of client assets have been transferred into Coinbase custody arrangements since the acquisition closed.

What’s Being Removed

Deribit’s existing Proof of Reserves system used a privacy-preserving binary Merkle tree structure with daily snapshots. Each client could use a unique proof identifier to locate the hashed entries representing their balances, while any member of the public could sum the file’s total liabilities and compare that figure to wallet balances published by Deribit.

The daily public snapshot had limitations even before its removal. According to Deribit’s stated methodology, assets held with third-party custodians were already excluded from the Proof of Reserves because they fell outside Deribit’s direct control, with Copper ClearLoop named as an example of such an arrangement.

Proof of Reserves systems have become increasingly common in the cryptocurrency industry following major exchange collapses in 2022. These mechanisms allow customers to verify that exchanges maintain sufficient assets to cover all customer balances, addressing fundamental concerns about solvency and operational integrity that emerged after high-profile failures.

What Remains

Deribit said that regulator-required reserve, reconciliation, and audit controls will continue in place. However, these controls do not provide the same daily public visibility that the discontinued Proof of Reserves page offered.

After September 1, clients and counterparties may request audited financial statements and other due-diligence materials on demand. The exchange has not promised a replacement public dashboard or continued client-level Merkle verification, meaning customers will lose the ability to perform real-time, self-directed verification of their holdings.

The shift from continuous public transparency to on-demand reporting reflects a broader trend in the industry as custody models evolve. When assets move to regulated custodians, exchanges often argue that responsibility for reserve verification shifts to the custodian’s own regulatory framework, reducing the need for parallel verification mechanisms at the exchange level.

Regulatory Requirements Persist

Deribit operates as Deribit FZE under Dubai’s Virtual Assets Regulatory Authority, which maintains distinct requirements that remain unaffected by the removal of the public page. VARA regulations require covered virtual asset service providers to maintain reserves equal to 100% of client liabilities, hold them on a one-to-one basis in the same asset, reconcile them daily, and obtain independent third-party reserve audits at least every six months.

Deribit’s regulatory notice references both annual and twice-yearly Proof of Reserves audits. VARA’s rules set the reserve-audit minimum at once every six months, and a separate provision requires an annual financial-statement audit that must be made available to clients and the regulator upon request.

Additional VARA requirements mandate that covered firms submit wallet addresses monthly and statements demonstrating compliance with financial requirements, including reserve assets, on a quarterly basis. VARA’s register lists Deribit FZE as an active exchange and broker-dealer virtual asset service provider.

These regulatory safeguards operate independently of Deribit’s operational decisions. Even with the removal of the public page, the compliance infrastructure remains subject to regulator oversight, and violations would constitute regulatory infractions rather than merely customer-initiated verification gaps.

Custody Arrangements Unclear

Deribit’s disclosures name Coinbase at the brand level regarding the migrated assets but do not identify the specific Coinbase legal entity holding the transferred client funds. A separate VARA service-provider list names Coinbase for custody and self-custody technology services without specifying which Coinbase entity is involved.

VARA membership terms allow assets to be held directly or through third-party custodians while requiring segregation from company assets and preservation of clients’ legal title. The regulatory framework does not prevent the use of third-party custody arrangements, but requires proper disclosure and controls.

The lack of specific entity identification raises questions about regulatory supervision. Custody arrangements typically involve distinct legal structures designed to segregate customer assets from operational trading entities, but this separation is only meaningful when clearly disclosed and properly documented.

Transparency Trade-Off

The removal of the public Proof of Reserves page does not indicate a reserve shortfall at Deribit. Rather, it represents a reduction in what customers can independently verify on a daily basis, replacing a granular, transparent mechanism with controls and reports that are less public, less frequent, or available only upon request.

This transition reflects broader tensions in cryptocurrency regulation between formal compliance requirements and voluntary transparency practices. While regulatory audits and reserve requirements may technically satisfy legal obligations, the elimination of daily public verification removes a tool that served as both a customer safeguard and a competitive differentiator for exchanges emphasizing accountability.