ORDERBOOK V3 / INTERIM AUDIT SUMMARY
V3 Audit
An overview of zkSecurity’s review of Derive Orderbook v3: what was reviewed, what was found, and the responses recorded in the report.
zkSecurity
Two-week engagement · Two consultants · Began 7 September 2026
The review examined selected components supporting protocol state transitions and liveness. It was a scoped code review, not an assessment of the entire Derive platform.
Scope of review
Selected Rust components for protocol state management, batch processing and data-availability verification, together with Solidity contracts supporting settlement, custody and withdrawals.
Findings at a glance
11 findings across four severity levels. The statuses below reflect client responses documented in the report.
High
01
Recorded as fixed
Medium
01
Acknowledged
Low
05
2 recorded as fixed; 3 acknowledged
Informational
04
Acknowledged
Acknowledged does not mean resolved. Recorded fixes reflect the client responses in the report and are not presented here as independently verified remediation.
Understanding the scope
The review was limited to the code and scope identified in the report. Migration correctness and the resulting initial state were excluded. The final mainnet deployment script was not reviewed; applicable portions of the testnet deployment script were reviewed instead.
A security audit does not guarantee the absence of vulnerabilities. This summary is not a certification of security or regulatory compliance.
Full report availability
The full technical report will be made public in due time. Until then, this page provides an interim summary without disclosing individual vulnerability details.
