# Audited Crypto Derivatives Exchanges in 2026, Ordered by the Record Behind the Audit

Updated: 24 September 2026 | Book readings 22 September 2026 | The Margin Brief desk

## Summary

Ordered by the record behind the audit, the audited crypto derivatives exchange at the head of this
sheet is Extended, level with Aster: both publish audit reports, run a bounty anyone can report into and
have gone 24 months without losing user money. An auditor's mark measures scrutiny, never solvency.

Weighting: Exit liquidity 30 · Collateral and settlement 22 · Cost per round trip 20 · Loss record and audits 14 · Contracts and asset classes 9 · Getting a position on 5, fixed 22 September 2026. Method: https://insurancerefocused.com/how-we-rate

## What the figures decide

1. Joint first on the record: Extended and Aster, each with reports on file, a published bounty and no user money lost in 24 months.
2. The auditor disagrees with the record. Extended, joint first here, carries the lowest CertiK Skynet mark on the page at 80.5, and that page lists none of the two reports Extended itself publishes.
3. The weighted total of all six criteria did not set these rows either: by that total Lighter stands first of the six at 12.5 of 15, from the third row.
4. Report counts run from two to nine and change nothing above two: the criterion pays for a second outside audit and stops counting there.
5. One venue here lost user money inside the window: Hyperliquid, whose own vault took about $4.9 million in November 2025 and about $4 million in March 2025.

## Six venues in the order their audit record gives them, September 2026

Reports on file, a bounty anyone can report into, and 24 months of loss history. That is one of the six
criteria and 14 of the 100 points; here it sets the sequence and nothing else does. The CertiK Skynet
mark in the next column is an outside register, and it runs close to the reverse of this order: the
lowest mark on the page, 80.5, holds row one, and the highest,
94.36, the last row. It is printed beside the record rather than in place of it,
because it is the number most readers arrive holding and the disagreement is the thing worth seeing.

| # | Venue | CertiK Skynet | What the record behind it shows | Maker / taker | Markets | Model |
|---|---|---|---|---|---|---|
| 1= | Extended | 80.5 A | 2 reports, bounty published, no user loss | 0% / 0.025% | 325 | Hybrid |
| 1= | Aster | 93.88 AAA | 7 reports, bounty published, no user loss | 0% / 0.040% | 578 | Own layer 1, operator-run |
| 3= | Lighter | 90.25 AA | 9 reports, no bounty, no user loss | 0% / 0% | 214 | Hybrid, ZK-proven |
| 3= | edgeX | 88.14 AA | 9 reports, no bounty, no user loss | 0.040% / 0.045% | 172 | Hybrid |
| 3= | Hyperliquid | 92.14 AA | 2 reports, bounty published, losses in 24 months | 0.015% / 0.045% | 324 | On-chain order book |
| 3= | EVEDEX | 94.36 AAA | 2 reports, no bounty, no user loss | 0.015% / 0.045% | 52 | Hybrid |

Venue facts as of 18 September 2026; the CertiK Skynet column read on 23 September 2026; entry-tier fees on the BTC perpetual. Access differs by country.

## Assessments

### 1. [Extended](https://extended.exchange/) — two reports and a price on a critical finding

CertiK Skynet 80.5 A.

Extended publishes two audits of the settlement layer it runs on: ChainSecurity over the Starknet
Perpetual contracts, and a Code4rena competition that put 39 Cairo contracts in front of a public
field. Its bounty pays up to $500,000 for a critical report, on a published schedule
([Extended bounty programme](https://docs.extended.exchange/extended-resources/more/bounty-program), checked 18 September 2026), and no user money has gone missing
in the window. Its Skynet mark is 80.5 ([CertiK
Skynet](https://skynet.certik.com/projects/extended), read
23 September 2026).

- Works: Two audit reports on file, ChainSecurity and a public Code4rena competition; Bounty of up to $500,000 for a critical report, paid on a published schedule.
- Falls short: CertiK's own page for it lists no audits and marks it 80.5, the lowest here; No documented withdrawal that works without the operator.
- Not for: a desk that reads the auditor's mark as the summary.

### 1. [Aster](https://www.asterdex.com) — seven reports, and a chain nobody outside can check

CertiK Skynet 93.88 AAA.

Aster links seven audit reports from its own documentation — Salus Security over the vault and the
Earn contracts, PeckShield over two of the Earn products, Halborn over the USDF pair — and runs an
Immunefi bounty paying up to $200,000, live
since 16 April 2025 ([Immunefi](https://immunefi.com/bug-bounty/aster/information/), checked 18 September 2026). Skynet marks it
93.88 (AAA). What those reports cover is the
contracts, not the layer 1 the book now sits on.

- Works: Seven audit reports linked from its own documentation; Immunefi bounty of up to $200,000, live since 16 April 2025.
- Falls short: Chain core code is closed-source; no external validators in phase one; DefiLlama removed its perpetual volume data in October 2025, saying it could not verify wash trading.
- Not for: a trader who needs the chain holding the margin validated from outside.

### 3. [Lighter](https://lighter.xyz) — nine reports, and nowhere to send a finding

CertiK Skynet 90.25 AA.

Lighter publishes nine reports from three firms: zkSecurity over the prover circuits, Nethermind over
the core contracts and the Desert Mode exit that is meant to work when the sequencer stops, Zellic
over the contracts on Ethereum. Skynet marks
it 90.25 (AA) and lists three of the nine.
There is no public bounty: findings go to an address, and what they earn is at the venue's discretion
([Lighter disclosure policy](https://docs.lighter.xyz/security/security-vulnerability-disclosure-policy.md), checked 18 September 2026).

- Works: Nine audit reports on file, from three outside firms; Priority exit on Ethereum and a documented shutdown mode.
- Falls short: No public bug bounty; findings go to an address and rewards are discretionary; A 4.5-hour outage in October 2025, compensated afterwards.
- Not for: a researcher who wants a published schedule before reporting.

### 3. [edgeX](https://pro.edgex.exchange) — nine reports from six firms, and no bounty

CertiK Skynet 88.14 AA.

edgeX keeps nine reports from six firms in a public repository: RigSec and SlowMist over V1, then
Halborn, Zellic, Spearbit and Binenet over V2 and the contracts around it. Skynet marks it 88.14
(AA). No
bounty appears anywhere in its documentation or help centre, read 18 September 2026
([edgeX documentation](https://edgex-1.gitbook.io/edgeX-documentation/llms.txt), checked 18 September 2026), and a withdrawal that bypasses the operator
is documented and has been since V2.

- Works: Nine reports from six outside firms, kept in a public repository anyone can read; Withdrawal that bypasses the operator.
- Falls short: No bug bounty programme in its documentation or help centre, read 18 September 2026; A token flash crash in June 2026 liquidated positions; goodwill payments were capped at 100,000 USDC per user.
- Not for: a researcher with nowhere to send what they find.

### 3. [Hyperliquid](https://hyperliquid.xyz) — a bounty to a million, and a vault that has lost money

CertiK Skynet 92.14 AA.

Hyperliquid publishes two Zellic reviews, both of the bridge contract rather than of the chain that
carries the book, and runs its own bounty paying up to 1 million USDC for a critical report
([Hyperliquid bug bounty](https://hyperliquid.gitbook.io/hyperliquid-docs/bug-bounty-program.md), checked 18 September 2026). Skynet marks it
92.14
(AA). The third part of the criterion is where it loses the
place: its own vault has taken losses inside the window.

- Works: Bug bounty of up to 1 million USDC; Open interest of $8.7 billion on CoinMarketCap, 22 September 2026.
- Falls short: Vault losses of about $4.9 million in November 2025 and about $4 million in March 2025; Both audits are of the bridge contract, not of the chain that carries the book.
- Not for: traders wary of a venue-run vault that has taken losses.

### 3. EVEDEX — two reports from one firm, and no bounty

CertiK Skynet 94.36 AAA.

EVEDEX carries two audit reports on CertiK Skynet, the latest delivered on 28 July 2025 over a single
contract, with one informational finding acknowledged and nothing above it. The same page marks the
project 94.36 (AAA) and records no bounty, neither
CertiK's own nor a third party's. Position data reaches Arbitrum once enough of it has changed, in
batches rather than trade by trade.

- Works: Two audit reports on file, the latest with one informational finding acknowledged; No user money lost in the 24 months read.
- Falls short: No bug bounty programme listed on CertiK Skynet; Both reports on that page are the same firm's, so no second name stands behind the contracts; Position data is written to Arbitrum in batches rather than trade by trade.
- Not for: UK retail clients, and desks that want an exit not dependent on the operator.

## Sources quoted

> "users can utilize direct blockchain interactions to verify their balances and execute withdrawals, completely bypassing the operator" — edgeX documentation, V2 Self-Custody, 18 September 2026. https://edgex-1.gitbook.io/edgeX-documentation/edgex-v2/self-custody

> "All transactions are validated and settled on Starknet, ensuring transparent and verifiable state transitions." — Extended documentation, Technical Architecture, 18 September 2026. https://docs.extended.exchange/about-extended/technical-architecture

> "Bug Bounty Program | No CertiK Bug Bounty | CertiK Bounty No | 3rd Party Bounty No" — CertiK Skynet, EVEDEX project page, 18 September 2026. https://skynet.certik.com/projects/evedex

## What being an audited crypto derivatives exchange proves, and what it does not

An audit is a firm reading named code at a named moment. It says that somebody outside the venue
looked, what they looked at, and what they found. It does not say the venue is solvent, that the
matching engine behaves, or that a deposit is recoverable — and nothing on this site says a deposit
is covered, protected or insured, because on these venues it is not.

The two columns disagree, which is the useful part. Extended holds the lowest Skynet mark here at
80.5 (A) and the strongest published
record: a ChainSecurity review of the Starknet contracts it settles on, a Code4rena competition over
39 Cairo contracts, and a bounty paying up to $500,000 for a critical report. CertiK's page for it
lists no audits at all. A Skynet mark is a proxy for scrutiny, and one firm's proxy at that.

## What the record leaves uncovered

Three gaps survive even a full mark on this criterion. An audit is scoped: Hyperliquid's two reports are both of the bridge
contract, not of the chain that carries the book. A bounty is an invitation to report, not evidence
that anyone has. And a clean 24 months is history, which is what it is worth on the day the window
moves.

Completeness is the same test turned on the auditor. CertiK's own page lists fewer reports than the
venue itself publishes in four of the six cases here: none of Extended's two, one of Aster's seven,
three of Lighter's nine and two of edgeX's nine. The mark in that column is built on what the
auditor's page holds, not on what the venue does.

## How the figures were taken

Nobody publishes what an exit costs, so depth, spread and impact are this desk's own: every public BTC
perpetual book read over 122 polls between 21 September 2026 and 22 September 2026, no account anywhere, no order of ours. Charges, margin
demands, ladder rungs, market lists and audit history are each venue's own record on 18 September 2026.
Six weights, settled 22 September 2026 and unchanged since, carry 6 venues
([how we rate](/how-we-rate)).

Read the margin figures as arithmetic, not as a warning: a documented cap divided into a hundred thousand
dollars of exposure, closed out at the maintenance level with collateral still in the account.
Settlement, exit routes and audit history are what each venue publishes, never the whole of it. Fee
columns are the entry tier, before cashback or volume tiers, and BTC alone was measured, its smaller
neighbours on the same venues being thinner.

## FAQ

### Which crypto derivatives exchanges have been audited?

All six on this page publish at least two reports by an outside firm: Lighter and edgeX nine apiece,
Aster seven, and Extended, Hyperliquid and EVEDEX two each, read on 18 September 2026. The
criterion pays for the second report and stops counting there, so the count separates almost nothing
above two.

### What is a CertiK Skynet score?

A standing mark one auditor keeps on a project, moving with what it observes rather than fixed at the
date of a report. Every venue here was read on 23 September 2026 so the column compares like with
like. It proxies scrutiny; it says nothing about solvency, and it is one firm's view.

### Does a high audit mark mean a deposit is protected?

No page on this site says a deposit is covered, protected or insured, because on these venues it is
not. A mark says an auditor has looked at named code. What can be checked is narrower: reports on
file, a bounty anyone can report into, and whether user money went missing in the last 24 months.

### Which of these venues runs a bug bounty?

Three of the six. Extended pays up to $500,000 for a critical report on its own schedule, Aster up to
$200,000 through Immunefi, and Hyperliquid up to 1 million USDC. Lighter takes findings at an address
and rewards them at its discretion; edgeX and EVEDEX publish no programme at all.

### Has any of these venues lost user money?

One, on the definition used here: money taken by an exploit, lost through a venue-run vault or
swallowed by an outage, and not paid back in full. Hyperliquid's own vault took about $4.9 million in
November 2025 and about $4 million in March 2025. A position the market closed out is not counted.

### Why does the venue with the highest audit mark sit last here?

Because the order follows the record rather than the mark. Two reports from one firm, no bounty
anyone can report into, and a clean window carry the same points as two reports anywhere else, and a
published bounty is three points this venue does not take. The mark is printed beside it, unchanged.

### Who audited each of these venues?

ChainSecurity and a Code4rena competition for Extended; Salus Security, PeckShield and Halborn for
Aster; zkSecurity, Nethermind and Zellic for Lighter; RigSec, SlowMist, Halborn, Zellic, Spearbit and
Binenet for edgeX; Zellic for Hyperliquid; CertiK for EVEDEX. Every report is linked from the venue's
own documentation or from the auditor's, read on 18 September 2026.

### Do these audits cover the whole exchange?

None of them does. Each report names its scope, and the scope is contracts: a bridge, a vault, a
settlement layer, a set of circuits. The matching engine that takes an order, the sequencer that
orders it and the operator holding the keys are outside every report read here, and they are what a
position depends on hour to hour.

### How often is an audit record worth re-reading?

Often enough that a date belongs beside it. The venue facts here were read on 18 September 2026 and
the auditor's marks on 23 September 2026. A mark moves on its own; a bounty can be withdrawn; the 24
months of loss history rolls forward, and a window that is clean today loses that as it moves.

### What does an audit not tell you about an exit?

Nothing at all. A closed position is sold into whatever is resting in the book at that instant, and
no report measures that. This desk reads it separately, and the venues on this page are set out by
the depth behind an exit on the [depth ranking](/top-crypto-derivatives-exchanges).

## Editorial note

These are leveraged perpetual futures: the margin behind a position is all of what it can lose. Placement here is paid for; the order of the table is not. Corrections: editorial@insurancerefocused.com.

The Margin Brief desk, 24 September 2026

Placement in this file is paid for; the order of every table follows the published formula and nothing else.
