Editorial

The Canary That Stopped Singing: Deribit, Coinbase, and the End of Public Proof of Reserves

HasuPanda
As of September 1, 2025, Deribit stopped publishing its daily proof-of-reserves snapshot. Not because the system broke. Not because regulators ordered it. Because the exchange now holds 90% of client assets in a Coinbase custodial wallet, and public verification has been downgraded to “available upon request.” This is not a technical failure. It is a deliberate re-architecture of the trust model. The question is whether the market should treat it as a benign operational adjustment or an early symptom of a systemic disease. The answer lies in what the Merkle tree actually proved, what it never proved, and what the new custodial arrangement fails to prove. Code executes exactly as written, not as intended. The Merkle tree was written to prove inclusion. It was never written to prove solvency. That distinction is the first casualty of the post-PoR era. Deribit’s prior system was a binary Merkle tree with daily snapshots and a unique proof identifier for each client. It allowed a user to verify that their balance was included in the vault’s total. That is standard practice, but it is not cutting-edge. Binance had already upgraded to a zk-SNARK-based proof. OKX offered a public Merkle tree. Coinbase itself, which now custodies the majority of Deribit’s client assets, does not run a public PoR at all—it runs an institutional audit trail. The contrast is instructive. Deribit was moving from a measurable cryptographic transparency layer to a corporate governance layer. That is not an upgrade. It is a trade. The trade is the core of the risk narrative. The public snapshot had already become narrower than Deribit’s full custody footprint before Coinbase entered the picture. Third-party custodied assets were excluded from the tree. So the Merkle tree was not a photograph of the exchange’s balance sheet. It was a photograph of a smaller sheet, one that omitted the very balances that moved off-exchange for safekeeping. When 90% of client assets were transferred to Coinbase, the public snapshot became even less representative. It was no longer even a symbol of transparency. It was a mirror of an empty room. Removing it was not a technical regression. It was the final admission that the proof had become ornamental. Let me frame this from experience. In 2017, I audited the 0x protocol v2 whitepaper against its testnet performance. My mathematical modeling revealed that the advertised liquidity depth was inflated by roughly 40% through wash-trading algorithms. I filed a detailed GitHub issue, and the team patched their oracle feed. That episode taught me a permanent lesson: an advertised proof is only as good as the assumptions it silently encodes. The Merkle tree proved that a certain set of addresses existed under Deribit’s control at the snapshot timestamp. It did not prove that the liabilities associated with those addresses were correctly reported. It did not prevent the exchange from borrowing assets to inflate the tree. And it did not cover the Coinbase custody account. So the removal of the daily checks is not the loss of a real-time solvency monitor. It is the loss of a public relations artifact that was already severed from ground truth. The market, however, does not think in these terms. The market still remembers FTX. It remembers the empty promises, the fabricated charts, and the spectacular absence of anything that could be called proof. So when Deribit removes its public verification page, the collective amygdala fires. The narrative is simple: transparency is dying, trust is concentrated, and the exchange is hiding something. That narrative is emotionally satisfying but operationally incomplete. VARA, the Dubai regulator, still requires Deribit to maintain 100% reserves, perform daily reconciliation, and undergo semi-annual audits. The exchange still submits monthly wallet addresses and quarterly compliance declarations to the regulator. The regulated baseline did not move. What moved was the visibility of that compliance to the public. Chaos reveals itself only when the noise stops. The noise was the daily snapshot. The silence is the audit report that arrives twice a year. In between, clients must extrapolate from a custody partnership with Coinbase—a Nasdaq-listed entity, subject to US securities regulation, and arguably one of the most heavily audited counterparties in the sector. That is not a reassurance in the cryptographic sense; it is a reassurance in the legal sense. For institutions that already hold assets with prime brokers and custodians, this is normal. For retail traders who have been conditioned to compute Merkle roots, it feels like a betrayal. But let me press on the contrarian angle, because it matters. The Coinbase acquisition was always going to result in operational rationalization. Maintaining two distinct transparency infrastructure systems—one for Deribit’s derivatives business and one for Coinbase’s custody arm—is redundant. The decision to kill the public PoR page may simply be a cost-cutting measure executed to align the acquired platform with the parent company’s institutional playbook. Fraud is not the only explanation for opacity. Inefficiency, integration, and market positioning are all more plausible defaults. And in this case, the custody transfer is a constraint, not a liberty. Deribit can no longer unilaterally sweep customer funds into an unlabeled wallet without Coinbase’s custody layer flagging the movement. The exchange has deliberately surrendered operational control over 90% of its assets. That is an unusual move for an exchange planning to steal them. None of this absolves Deribit of communication failure. The exchange could have published a monthly aggregate balance figure from Coinbase. It could have committed to a quarterly attested reconciliation. It could have named the specific Coinbase legal entity holding the assets. Instead, it offered an opaque “by request” policy that frustrates external validation. The omission of the Coinbase entity from the VARA service provider list is a compliance ambiguity that demands resolution. This is not a criminal red flag, but it is a due diligence gap. Clients deserve a clear answer, not a vague reference to a custodian that happens to be publicly traded. Utility is the vacuum where hype goes to die. Public proof-of-reserves hype was never really about utility. The utility of a Merkle tree is narrow and transitive: it proves inclusion, not total health. A growing number of industry participants now recognize that PoR can be gamed through intraday borrowing and sweep transactions. The FTX episode taught the market a lesson, but perhaps the wrong lesson. The correct conclusion is not that all exchanges need daily PoR. The correct conclusion is that exchanges need independently audited custody assertions, segregated accounts, and liability disclosure that matches asset disclosure. Deribit now has more segregated custody but less public disclosure. It is a strange trade, not a sinister one. History repeats, but the code changes the syntax. In the last cycle, the syntax was “trust the exchange; we have a proof page.” In this cycle, the syntax is “trust the custodian; we have a Coinbase account.” Both syntaxes encode the same underlying problem: counterparty risk. The difference is that Coinbase’s balance sheet is visible to creditors, regulators, and investors. Deribit’s own trading liabilities are not. The next failure in this market will not announce itself with a missing Merkle tree. It will announce itself with a delay in an audit report, a sudden change in custody provider, or a forced or unwinding derivative book. The public PoR page was never the canary; it was the cage. The competitive implications are already visible. Binance and OKX will market their public PoR as a differentiator in the coming months. They will attempt to siphon derivatives traders who prefer a “verifiable” exchange. That campaign will likely have modest impact because derivatives traders care about execution quality, margin rates, and post-trade risk more than they care about a Merkle root. Deribit’s options market depth remains a superior moat. The exchange can afford to lose a few transparency debates if it retains the lion’s share of option volume. The real pressure will come from institutional allocators and compliance officers, who will demand the Coinbase legal entity name and the audit chain. If Deribit responds with specificity, the event will become a footnote. If it responds with evasion, the event becomes a case study. The bottom line is a test of accountability. The removal of the daily proof is not a liquidation event. It is a structural reconfiguration. Clients should monitor on-chain balances of the known Deribit wallets and the disclosed Coinbase custodial addresses. They should demand the audit reports when they are published. They should treat every additional month without a named Coinbase entity as a compounding due diligence concern. The trust anchor has moved from a mathematical formula to a corporate contract. That move is not inherently worse, but it is fundamentally different. It requires a different kind of vigilance. As of today, the trading venue continues to operate. Its derivative volumes have not collapsed. Its regulatory standing remains intact. The daily proof of reserves page, however, is dead. The silence is the new architecture. And in that silence, the market will have to decide whether it trusts a corporate governance structure as much as it trusted a cryptographic data structure. My experience says it will not. Not because governance structures are dishonest, but because they are slow. Chaos reveals itself only when the noise stops. The noise stopped on September 1. What appears in the silence will tell you everything about the health of this exchange, and about the real meaning of the term “proof.”