DeFiPunk'd

Derive

3 deployments · $134.2M aggregate TVL · Derivatives

Deployments

Each deployment is rated independently. Pick one to see its rating, risk analysis, and stage.

TVL $133.4M
Type Derivatives
Chains Hyperliquid L1, Arbitrum, Optimism, Base, Ethereum +2
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty immunefi.com Governance forum Docs docs.derive.xyz
About

Derive V2 is a self-custodial, high-performance derivatives trading platform supporting options, perpetuals, and spot trading. The protocol consists of three components: Derive Chain (an OP Stack-based Optimistic rollup secured by Ethereum), the Derive Protocol (settlement layer enabling permissionless margin trading), and the Derive Exchange (orderbook operator). The system is governed by the Derive DAO.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 1 address on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source, no audits

    A GitHub repository is published but no audit is recorded in DeFiLlama's dataset. Audits may exist upstream without being indexed here; open a PR with an overlay if so.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Derive V2 has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 42addresses
  • 38verified source
  • 18proxies
  • 7of 16 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-14.

arbitrumStakedUSDeOFT0x211c…e5d2TVL0xc964…406d5/10 Safe
arbitrumTransparentUpgradeableProxy0xff97…5cc8TVLproxy0x0000…0001
arbitrumFiatTokenProxy0xaf88…5831TVLproxy0xc7a5…ebc9
arbitrumUSDeOFT0x5d3a…ef34TVL0xc964…406d5/10 Safe
arbitrumTransparentUpgradeableProxy0xfd08…cbb9TVLproxy0x4dff…0bf83/5 Safe
arbitrumClonableBeaconProxy0x2f2a…5b0fTVLproxy
arbitrumClonableBeaconProxy0x3575…4dbeTVLproxy
arbitrumTransparentUpgradeableProxy0x82af…bab1TVLproxy
arbitrumOssifiableProxy0x5979…0529TVLproxy
baseOptimismMintableERC200x50c5…b0cbTVL
baseFiatTokenProxy0x8335…2913TVLproxy
baseOssifiableProxy0xc1cb…e452TVLproxy
berachainRSETH_OFT0x4186…b41fTVL0x7ac1…c18c
bscTransparentUpgradeableProxy0x04c0…150aTVLproxy
ethereumInitializableAdminUpgradeabilityProxy0x7fc6…dae9TVLproxy
ethereumFiatTokenProxy0xcbb7…33bfTVLproxy0xce56…16e6
ethereumDai0x6b17…1d0fTVL
ethereumERC1967Proxy0x1570…a138TVLproxy0xd7cd…4f243/5 Safe
ethereumBoringVault0x657e…c642TVL
ethereumTransparentUpgradeableProxy0x8236…4494TVLproxy0x055e…7e59
ethereumSavingsDai0x83f2…beeaTVL
ethereumProxyERC200xc011…2a6fTVL0xeb31…77694/8 Safe
ethereumStakedUSDeV20x9d39…3497TVL0x3b0a…18625/11 Safe
ethereumFiatTokenProxy0xa0b8…eb48TVLproxy0xfcb1…ae3a
ethereumUSDe0x4c9e…68b3TVL0x3b0a…18625/11 Safe
ethereumTetherToken0xdac1…1ec7TVL0xc6cd…a828
ethereumWBTC0x2260…c599TVL0xca06…beb7
ethereumUUPSProxy0xcd5f…b7eeTVLproxy0x9f26…0761
ethereumWETH90xc02a…6cc2TVL
ethereumWstETH0x7f39…2ca0TVL
EthereumDRV (Derive) token on Ethereum mainnet; ERC-20 with implementation contract at 0x4909ad99441ea5311b90a94650c394cea4a881b8 using EIP-1967 Transparent Proxy pattern0xb1d1…71bediscoverytoken
etlkLBTC0xecac…11c1TVL
hyperliquidWHYPE0x5555…5555TVL
mezoMUSD0xdd46…f186TVL
optimismDai0xda10…0da1TVL
optimismGovernanceToken0x4200…0042TVL
optimismOVMFiatToken0x7f5c…1607TVL
optimismFiatTokenProxy0x0b2c…ff85TVLproxy
optimismUSDT0x94b0…8e58TVL
optimismWBTC0x68f1…2095TVL
optimismWETH90x4200…0006TVL
optimismOssifiableProxy0x1f32…4ebbTVLproxy

Protocol Info

Security

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Audits
1 audit
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Voting token
DRV Ethereum: 0xb1d1eae60eea9525032a6dcb4c1ce336a1de71be
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC

Hallmarks

  1. Oct '21Lyra Token
  2. Nov '21Token Program Start
  3. Jun '22Lyra V1.1 End
  4. Jun '22Lyra Avalon Start
  5. Aug '22OP Rewards Distribution Start
  6. Jan '23Launch on Arbitrum