On Sept. 1, Deribit takes down the one page that let you check its math yourself.
The exchange is removing its public Proof of Reserves page. That page ran a daily snapshot customers could use to confirm their own balances were included in the liability set, and that anyone could add up and compare against the wallet holdings Deribit published. After Sept. 1, that check is gone.
What replaces it isn’t nothing. It’s just not public in the same way.
What you could actually do with the page
Deribit’s existing setup uses a privacy-preserving binary Merkle tree and a daily snapshot. Each client gets a unique proof identifier and uses it to find the hashed entries representing their balances. That’s the client-level half.
The other half is open to anyone: sum the liabilities in the file, then compare the total against the wallet balances Deribit published. No account required. No request form. You either got a number that reconciled or you didn’t.
That’s the specific capability being retired. Not a report about reserves, but a test you could run yourself, every day, without asking permission.
The Coinbase migration is the stated reason
Deribit said the change reflects a wallet infrastructure overhaul during its integration with Coinbase. Roughly 90% of client assets have moved into Coinbase custody arrangements since Coinbase acquired the derivatives platform in August 2025, according to the exchange.
Here’s the part worth sitting with. Deribit’s disclosures name Coinbase at the brand level but don’t identify the specific Coinbase legal entity holding the migrated assets. “Coinbase” is a corporate family, not an address.
A separate VARA service-provider list names Coinbase for custody and self-custody technology, also without specifying the entity.
The snapshot was already narrower than it looked
Before you mourn the page too hard, read its methodology. Assets held with third-party custodians are excluded, because they sit outside Deribit’s direct control. Copper ClearLoop is named as an example.
Which raises an obvious question the disclosures don’t answer: whether every Coinbase-held asset was already excluded from the snapshot. If a large share of client assets had already migrated out of the tree’s scope, the daily check had been shrinking for a while before anyone announced its removal.
What regulators still require
Deribit FZE’s obligations don’t go anywhere. Dubai’s Virtual Assets Regulatory Authority requires covered virtual asset service providers to maintain reserves equal to 100% of client liabilities, hold them one-to-one in the same asset, reconcile them daily and obtain an independent third-party reserve audit at least every six months.
Note the mismatch in the paperwork. Deribit’s notice refers to both annual and twice-yearly Proof of Reserves audits. VARA’s rule sets the reserve-audit minimum at once every six months. A separate VARA provision requires an annual financial-statement audit, with the annual report available to clients and the regulator on request.
Daily reconciliation still happens. You just can’t see it.
Regulator-facing isn’t customer-facing
Covered firms submit wallet addresses monthly to VARA, plus quarterly statements demonstrating compliance with financial requirements including reserve assets. That’s real oversight. It’s also oversight you’re not a party to.
VARA’s register lists Deribit FZE as an active exchange and broker-dealer VASP. Its membership terms allow assets to be held directly or through third-party custodians, while requiring segregation from company assets and preserving clients’ legal title.
For everyone else, Deribit said clients and counterparties may request audited financial statements and other due-diligence material. That’s a less frequent and less directly verifiable form of evidence than a file you could hash-check on a Tuesday afternoon.

What this is and isn’t
The page’s removal is not evidence of a reserve shortfall. Nothing here says the assets aren’t there.
It’s a reduction in what customers can test for themselves each day, leaving controls and reports that are less public, less frequent or available only on request. Deribit hasn’t promised a replacement public dashboard or continued client-level Merkle verification after Sept. 1.
If you hold a position on Deribit and you’ve ever pulled your proof identifier, do it before Sept. 1 and keep the file. After that, verifying anything means writing an email and waiting for someone to write back.