Open app

NexFlow › Is Deribit safe

Is Deribit safe? The options venue whose $28M loss cost the user nothing — then sold for $2.9B

Deribit's file is the shortest honest answer in this family: yes, it was breached — a wallet-server compromise that drained $28M from its hot wallets in November 2022 — and no, it never touched a user. Ninety-nine percent of funds sat in cold storage, company reserves absorbed the loss the same day, and the insurance fund wasn't needed. Three years later Coinbase paid $2.9 billion for the venue — the largest acquisition in crypto — which is the market's own verdict on what that incident record was actually worth.

Updated September 28, 2026 · By the NexFlow editorial desk · Sources linked throughout; vendor claims labeled.

What Deribit is

Deribit is the world's dominant crypto derivatives venue — the platform where institutional options liquidity for BTC and ETH concentrates, routinely carrying the overwhelming majority of listed crypto options volume. Founded 2016 in the Netherlands, later Panama-domiciled, it serves a professional clientele rather than the retail long-tail — the venue hedge funds and market makers mean when they say 'crypto options.'

In August 2025 it stopped being an independent data point: Coinbase completed its ~$2.9 billion acquisition of Deribit — the largest M&A deal in crypto history — folding the options powerhouse under the same public-company disclosure regime the corpus already scored in the Coinbase file. The safety question now reads two ways: the venue's own record, and the parent's.

November 1, 2022: the wallet-server compromise

Just before midnight UTC on November 1, attackers gained access to Deribit's wallet server — the critical detail, because this was not a phished employee or a signed-away approval: the server that initiates withdrawals was itself compromised, letting the attacker drain the hot wallets it spoke for.

The take: ~691 BTC, ~6,947 ETH, and ~$3.39M USDC — about $28 million total, which PeckShield and CertiK clocked as the third-largest private-key compromise of 2022. The stolen funds sat quiet until November 5, then began the familiar march through Tornado Cash (1,610 ETH in 17 transactions). CertiK's read: private-key leakage — the same mechanism class as BitMart and CoinEx, executed on the most valuable derivatives book in crypto.

Why the user never felt it

Three numbers explain the outcome. 99%: the share of user funds in cold storage, company policy stated before the incident ever happened — the hot float the attacker reached was the small slice. Same-day: the speed of the cover statement — 'loss is covered by company reserves' within hours, before the rumor cycle could price a bank run. $40M: the insurance fund that wasn't needed at all, untouched while reserves absorbed the loss from a separate pocket.

Platform trading never stopped; client assets, cold storage, and every custody partner (Fireblocks, Copper Clearloop, Cobo Loop) were explicitly unaffected. Withdrawals paused only for security checks. The incident's net user experience was a maintenance window — which is what 'reserves are real' looks like when it's tested rather than asserted — the difference between a PoR dashboard and a Tuesday night.

The postscript the market wrote

This family measures cover reflexes by what venues do under stress; the M&A market priced Deribit's record differently — in billions. Coinbase's ~$2.9B acquisition (agreed May 2025, closed August 2025) is the largest in crypto history, bought the dominant options book, and — for this page's purposes — represents a public company's diligence verdict on a venue that had a documented breach on file. The hack demonstrably didn't discount the asset.

What changes for a user post-acquisition: the venue inherits Coinbase's disclosure posture and audit surface — and inherits the parent's risk surface too (the Coinbase file's SMS-recovery incident and impersonation economy now sit one org chart away). The honest net: the acquisition makes Deribit's custody governance a public company's problem, which is the strongest oversight class this corpus recognizes.

The residual risks that outlive the acquisition

The November 2022 file still teaches: a wallet-server compromise means the attacker didn't steal a key so much as become the operator for an evening — a deeper failure than a leaked seed, mitigated only by the cold/hot split capping what the server could reach. The options-venue specifics matter too: custody here concentrates in fewer, larger institutional accounts, so tail risk is lumpier than a retail book's; and derivatives platforms carry liquidation-engine risk (the Hyperliquid JELLY file's cousin) that custody pages alone don't price — Deribit's dominance makes its margin machinery quasi-systemic for the whole options market.

None of that undercuts the record — it scopes it. Deribit answered the only question a custody incident can ask ('whose balance sheet absorbs the hit?') with the best possible answer, and then sold the whole institution to the most scrutinized balance sheet in American crypto.

Where Deribit stands

In the breached-and-covered tier Deribit is the clean-sheet entry: smallest loss of the cluster, fastest cover, zero user impact, an insurance fund it didn't even need — and the only venue in the family whose post-incident verdict was written by an acquirer's diligence team at $2.9 billion. The honest caveat is the one the incident itself supplied: the compromise reached the withdrawal machinery, which is the deepest layer — the cold-storage ratio is the only reason the lesson cost $28M instead of the book.

Frequently asked questions

Was Deribit hacked?

Yes — November 1, 2022, just before midnight UTC. Attackers compromised Deribit's wallet server — the machine authorized to initiate withdrawals — and drained ~$28M (≈691 BTC, ~6,947 ETH, ~$3.4M USDC) from hot wallets, later washed through Tornado Cash. Client assets, cold storage, and custody partners were explicitly unaffected.

Did Deribit users lose money?

No — company reserves covered the full loss the same day, and the $40M insurance fund wasn't touched. Trading never stopped; withdrawals paused only for security checks. Of the breached-venue files in this corpus it's the cleanest user outcome: the entire incident lived on the company's balance sheet, which is exactly where it belonged — the incident is the cleanest demonstration in this corpus that a well-structured treasury converts a breach from a user event into a company expense line — the outcome every 'who eats the loss' question is really asking for.

Is Deribit owned by Coinbase now?

Yes — Coinbase completed its ~$2.9B acquisition of Deribit in August 2025, the largest M&A deal in crypto. For the safety question it upgrades the oversight class (public-company disclosure, consolidated audit surface) while folding Deribit's record into a parent's that also has incidents on file — the page scores both, but the custody mechanics stayed the same: 99% cold storage and a demonstrated cover reflex.

What does the 99% cold-storage figure actually prove?

That the blast radius was pre-capped by policy, not luck. The attacker reached the withdrawal server — the deepest possible compromise — and still only got the ~1% float. That's the same 'hot float' math that cost BitMart $196M and CoinEx $70M; Deribit's smaller float is why an equivalent mechanism cost a fraction. Cold/hot ratio is the single most predictive number on a custodian's security page.

Is Deribit safe for retail users?

Structurally it's the strongest custody record in the derivatives tier — but it is a professional options venue: product complexity is its own risk class (leveraged positions liquidate regardless of how sound the custody is). 'Safe' splits into 'will the venue lose my collateral' — excellent record — and 'will I lose it trading options' — the product's nature, unchanged by who owns it.

Deribit vs Bybit — what changed after their incidents?

Same supply-side lesson, different blast radius. Bybit's $1.5B Safe{Wallet} compromise (Feb-2025) was bigger but integration-layer; Deribit's $28M was smaller but reached the withdrawal machinery itself. Both covered losses from reserves instantly, neither touched user balances — the two cleanest cover reflexes in the corpus — and Deribit's verdict came via acquisition while Bybit's came via a stress-test it self-published in real time.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product