ORDERBOOK V3 / INTERIM AUDIT SUMMARY

V3 Audit

An overview of zkSecurity’s review of Derive Orderbook v3: what was reviewed, what was found, and the responses recorded in the report.

zkSecurity

Two-week engagement · Two consultants · Began 7 September 2026

The review examined selected components supporting protocol state transitions and liveness. It was a scoped code review, not an assessment of the entire Derive platform.

Scope of review

Selected Rust components for protocol state management, batch processing and data-availability verification, together with Solidity contracts supporting settlement, custody and withdrawals.

Findings at a glance

11 findings across four severity levels. The statuses below reflect client responses documented in the report.

High

01

Recorded as fixed

Medium

01

Acknowledged

Low

05

2 recorded as fixed; 3 acknowledged

Informational

04

Acknowledged

Acknowledged does not mean resolved. Recorded fixes reflect the client responses in the report and are not presented here as independently verified remediation.

Understanding the scope

The review was limited to the code and scope identified in the report. Migration correctness and the resulting initial state were excluded. The final mainnet deployment script was not reviewed; applicable portions of the testnet deployment script were reviewed instead.

A security audit does not guarantee the absence of vulnerabilities. This summary is not a certification of security or regulatory compliance.

Full report availability

The full technical report will be made public in due time. Until then, this page provides an interim summary without disclosing individual vulnerability details.