Come Sept. 1, the one page that let anyone check Deribit’s arithmetic disappears.
The exchange is retiring its public Proof of Reserves page. That page produced a daily snapshot customers could use to confirm their own balances appeared in the liability set, and that any observer could tally up and weigh against the wallet holdings Deribit published. After Sept. 1, that check is gone.
Something does take its place. It simply isn’t public in the same way.
What the page actually let you do
Deribit’s current setup relies on a daily snapshot and a privacy-preserving binary Merkle tree. Every client receives a unique proof identifier and uses it to locate the hashed entries standing in for their balances. That covers the client-level side.
The other half was open to all comers: add up the liabilities in the file, then set the total against the wallet balances Deribit published. No account needed. No request form. Either you got a number that reconciled or you didn’t.
That is the precise capability being retired. Not a report about reserves, but a test you could run yourself, every day, without asking permission.
The Coinbase migration is the stated reason
Deribit said the change follows an overhaul of its wallet infrastructure carried out during its integration with Coinbase. Roughly 90% of client assets have shifted into Coinbase custody arrangements since Coinbase acquired the derivatives platform in August 2025, according to the exchange.
Here’s the part worth sitting with. Deribit’s disclosures cite Coinbase at the brand level but stop short of identifying the specific Coinbase legal entity holding the migrated assets. “Coinbase” is a corporate family, not an address.
A separate VARA service-provider list also names Coinbase for custody and self-custody technology, again without specifying the entity.

The snapshot’s scope was already tighter than it looked
Before mourning the page too hard, read its methodology. Assets parked with third-party custodians are excluded, since they sit beyond Deribit’s direct control. Copper ClearLoop is named as an example.
Which prompts an obvious question the disclosures leave unanswered: whether every Coinbase-held asset was already outside the snapshot. If a large share of client assets had already moved beyond the tree’s scope, the daily check had been narrowing for some time before anyone announced its removal.
What regulators still require
Deribit FZE’s obligations aren’t going anywhere. Dubai’s Virtual Assets Regulatory Authority requires covered virtual asset service providers to maintain reserves equal to 100% of client liabilities, hold them one-to-one in the same asset, reconcile them daily and obtain an independent third-party reserve audit at least every six months.
Note the mismatch in the paperwork. Deribit’s notice mentions both annual and twice-yearly Proof of Reserves audits. VARA’s rule puts the reserve-audit minimum at once every six months. A different VARA provision calls for an annual financial-statement audit, with the annual report available to clients and the regulator on request.
Daily reconciliation carries on. You just can’t see it.
Regulator-facing isn’t customer-facing
Covered firms hand wallet addresses to VARA monthly, along with quarterly statements demonstrating compliance with financial requirements including reserve assets. That is real oversight. It is also oversight you’re not a party to.
VARA’s register shows Deribit FZE as an active exchange and broker-dealer VASP. Its membership terms permit assets to be held directly or through third-party custodians, while requiring segregation from company assets and preserving clients’ legal title.
For everyone else, Deribit said clients and counterparties may request audited financial statements and other due-diligence material. That is a less frequent and less directly verifiable form of evidence than a file you could hash-check on a Tuesday afternoon.

What this is and isn’t
Pulling the page is not evidence of a reserve shortfall. Nothing here says the assets aren’t there.
What it is: a reduction in what customers can test for themselves each day, leaving behind controls and reports that are less public, less frequent or available only on request. Deribit has not promised a replacement public dashboard or continued client-level Merkle verification after Sept. 1.
If you hold a position on Deribit and have ever pulled your proof identifier, do it before Sept. 1 and keep the file. After that, verifying anything means writing an email and waiting for someone to write back.



















STAY ALWAYS UP TO DATE