DeFiPunk'd

Binance CEX

CEX

TVL $151.5B
Type CEX
Chains Ethereum, Bitcoin, Binance, Solana, Ripple +27
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty bugcrowd.com Governance forum Docs binance.com
About

Binance is the world's largest centralized cryptocurrency exchange by trading volume, serving over 270 million registered users across 180+ countries. Users can buy, sell, and trade hundreds of cryptocurrencies via spot, margin, futures, and options markets using a traditional order-book model. Binance operates as a fully custodial exchange, holding user assets in proprietary hot and cold wallets and publishing monthly Proof of Reserves attestations using a Merkle-tree approach. It also maintains a Secure Asset Fund for Users (SAFU), an emergency insurance fund funded by a percentage of trading fees.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability red
    Closed codebase

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  2. Control red
    Operator-controlled

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  3. Ability to exit red
    Withdrawals can be halted

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  4. Autonomy red
    Off-chain counterparty

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  5. Open Access red
    Permissioned by design

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Binance CEX has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 11addresses
  • 2verified source
  • 1proxies
  • 0of 1 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

Binancetreasury (hot wallet, BSC)0x631f…a161discoverytreasury
bscOwnedUpgradeabilityProxy0x40af…11c9TVLproxy
ethereumBNB0xb8c7…dd52TVL0x00c5…8454
Ethereumtreasury (Binance 14, multi-chain EOA)0x28c6…1d60discoverytreasury
Ethereumtreasury (Binance 16, multi-chain EOA)0xdfd5…963ddiscoverytreasury
Ethereumtreasury (Binance 18, multi-chain EOA)0x9696…6976discoverytreasury
Ethereumtreasury (Binance 7)0xbe0e…33e8discoverytreasury
Ethereumtreasury (custody wallet)0x3f5c…f0bediscoverytreasury
Ethereumtreasury (hot wallet 2)0xb125…038ediscoverytreasury
Ethereumtreasury (hot wallet 20)0xf977…acecdiscoverytreasury
Ethereumtreasury (hot wallet)0x631f…a161discoverytreasury

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@binance
GitHub
3 repositories

Security

[:] Source: DEFI@home quorum
Audits
1 audit
Security contact
https://www.binance.com/en/support/faq/responsible-disclosure-program-1df3b3e90b5b4cb3a40a08f8b9cd18c8

Technical

[:] Source: DEFI@home quorum
Voting token
BNB Binance: 0xB8c77482e45F1F44dE1745F52C74426C631bDD52
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC