The ledger remembers what the promoters forgot. On September 1st, Deribit—the dominant force in crypto options trading—quietly switched off the lights on its public proof of reserves page. This wasn't a technical glitch. It was a deliberate decision, announced alongside news that 90% of customer assets now sit in Coinbase's institutional custody. The exchange that once offered daily snapshots of its solvency via Merkle trees now offers... an on-demand request form. Since the FTX collapse, the industry has treated public proof of reserves as a sacred ritual. Deribit just performed a public autopsy on that assumption, and the corpse is still warm.
Here's the uncomfortable timeline. In 2022, after Sam Bankman-Fried's empire evaporated into a black hole of commingled funds, every exchange scrambled to appear transparent. Binance rolled out zk-SNARKs-based proof of reserves. OKX published Merkle tree snapshots. Even the laggards promised something—anything—to prove they weren't the next collapse. Deribit, meanwhile, implemented a standard binary Merkle tree system with daily snapshots and unique proof identifiers. It was never cutting-edge technology. But for years, it was sufficient. Clients could verify their balances existed within a tree that attested to the exchange's overall solvency. It wasn't perfect. It wasn't real-time. But it was a checkable fact.
Then came the Coinbase acquisition and the subsequent custody migration. Deribit's daily checks vanished. In their place: a promise of annual financial statement audits, semi-annual audits per VARA requirements, and monthly wallet address submissions to the Dubai regulator. Let me pause here for a reality check. Monthly wallet address submissions are not reserve proofs. A semi-annual audit is a rearview mirror, not a headlight. And a public verification page being replaced by a "consultation" process is not a technical upgrade—it's a rollback.
Based on my audit experience, I've seen this pattern before. Just as every rug pull leaves a trail of gas fees, every erosion of transparency leaves a trail of shifted obligations. The key is following where the responsibility moves. In this case, it has moved from a cryptographically verifiable process held by the client to an institutional trust arrangement held by Coinbase. That's not necessarily malicious. But it is a fundamental shift in the risk architecture—and no one is talking about it in those terms.
The technical mechanics of what Deribit removed are worth dissecting coldly. The old system operated with a set of precise, mathematical parameters. It used a binary Merkle tree—a data structure allowing efficient verification of large datasets. Each day, the exchange would publish a root hash committing to its liabilities. Each client could search for their own balance within that tree, generating a unique proof identifier. This is genuinely useful technology. It allows a customer to independently verify that their claim is included in the exchange's total obligations and that the total obligations don't exceed the assets the exchange claims to hold.
What replaced it? The report notes that Deribit's public snapshot coverage was already narrower than its full custody footprint. This is a critical point. The assets held by third-party custodians—including the pre-September arrangement with Copper ClearLoop and now the 90% sitting with Coinbase—were likely not included in the Merkle tree snapshots. So the old system was already partially blind. But the new system asks you to trust the custodian's institutional grade security, the exchange's regulatory compliance, and the fiduciary responsibility of a publicly traded American company. Perhaps that trust is deserved. But it is a fundamentally different operating principle. The market should be aware that we've moved from a world of 'show me the proof' to a world of 'trust our institutional partners.'
On the market front, this is a potential headwind for Deribit's institutional credibility. Deribit's competitive moat has always been its derivatives trading depth—specifically in options, where it remains the global leader by a significant margin. The exchange's liquidity breeds more liquidity; it is a deep, sticky pool. But in a sideways market where exchanges are clawing for institutional inflows, transparency is a weapon. Binance and OKX both still offer public proof of reserves. Coinbase itself, as a public company, is subject to Sarbanes-Oxley internal control attestations—a different kind of transparency altogether.
This puts Deribit in a curious middle ground. It has apparently adopted some of Coinbase's institutional ethos without inheriting Coinbase's public reporting obligations. The exchange will face questions from risk committees and treasury managers who read the headlines. Those managers will also notice that Deribit is regulated by VARA in Dubai, which mandates 100% reserves, daily reconciliation and semi-annual audits. That is a real regulatory backstop. It is not, however, a substitute for client verifiability.
Now, let me play contrarian with the bulls here. There are actually three arguments in favor of what Deribit did, and they deserve to be articulated rather than dismissed. First, the Merkle tree proof of reserves system that Deribit abandoned is—let's be honest—severely limited. It does not prove that the assets backing the liabilities haven't been lent out, or that they aren't sitting in an off-chain bank account that could be frozen. It proves only that the exchange's own accounting is internally consistent. In light of the FTX collapse, where the Merkle tree proof was an illusion because the assets were actually co-mingled and vaporized, one could argue that daily Merkle snapshots give a false sense of security.
Second, moving to a qualified institutional custodian like Coinbase reduces, if not eliminates, the operational nightmare of running a global, private key management operation. The risk of a hot wallet breach is drastically reduced. The segregation of assets is legally clearer. For a derivatives exchange holding billions in collateral, this could be a genuine security upgrade.
Third, the acquisition itself means Deribit is now backed by a regulated U.S. company with deep pockets. There is a meaningful difference between an unregulated offshore entity risking bankruptcy and a subsidiary of a NASDAQ-listed company. As someone who has spent 28 years observing this industry's cycles, I can tell you that the latter scenario has historically been the more reliable one.
So I'll accept this: Deribit's custody arrangement is arguably more robust now. The counter-argument—the one that keeps me awake—is that the exchange has taken a cultural step backward in an industry that desperately needs fewer trust assumptions, not more. We are returning to a relationship-based mode of finance, which is precisely what these cryptographic tools were designed to supersede.
Silence in the code is louder than the contract. The absence of a public verification endpoint after September 1st is a statement in itself. Deribit now promises to funnel requests for PoR data down to its compliance or relationship management channels. This is a request for trust, rather than a presentation of fact. For retail traders on the platform, the practical impact of this change is minimal—they'll still trade, they'll still withdraw. For anyone responsible for allocator-level decisions, this raises the cost of due diligence and introduces a new variable into the composition of the firm.
The deeper architecture of this deal is worth observing. In one stroke, Coinbase becomes the custodian for a significant percentage of the world's crypto options collateral. They are moving from being an exchange and custodian to being the settlement layer for other exchanges. That centralization of asset holding is not inherently dangerous—but it is significant. And the industry should not sleepwalk into a world where everybody's assets are concentrated into a single point of failure simply because it reduces short-term operational risk.
Regulatory bodies, of course, will be monitoring. VARA's requirements remain unchanged; this move complies with the letter of the law. But regulators, like auditors, see only the rearview mirror. They check the boxes after the roadmap has been drawn. By the time a regulator discovers a problem, civil markets have already absorbed the shock.
There is also a strategic element which deserves a cold, analytical eye. By pushing Deribit's proofs of reserves to an on-demand basis, Coinbase adds to its own institutional allure. They can now tell they can now tell institutional clients, "Come to us and you get Coinbase custody plus access to the world's deepest crypto order books." This may be the first step in a slow assimilation of Deribit into the broader Coinbase ecosystem. The Deribit brand might persist for the next two to three years, but the architecture suggests that its operational independence—and with it, its unique transparency culture—is being retired.
So, what should an investor or a client actually do with this information? The signals to watch are clear. Monitor Deribit's on-chain asset balances for signs of outflow. Watch for any VARA policy updates on public reserve reporting. And keep a close, almost paranoid eye on Coinbase's custody security record. If Coinbase suffers a hack or an operational failure, we will see just how much of Deribit's resilience was outsourced.
Every rug pull leaves a trail of gas fees. And every door closing on a transparency dashboard leaves a trail in the regulatory filings and migration patterns of market participants. On-chain cameras are turning away from the vault while the vault itself is being moved. The ledger remembers what the promoters forgot. We will, too. The important thing is to watch who moves where—and why. In the meantime, one question lingers for Deribit and Coinbase to answer: If the reserves are as solid as you claim, why are the data only available on demand?


