DeFiPunk'd

BounceBit CeDeFi Yield

Basis Trading

TVL $345.7M
Type Basis Trading
Chains BounceBit, Binance, Ethereum, Solana, Base
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty Governance forum Docs docs.bouncebit.io
About

BounceBit is a CeDeFi (centralized finance + decentralized finance) Layer 1 blockchain that enables institutional-grade yield strategies through regulated custody (Ceffu, Standard Chartered) and delta-neutral trading. Users can deposit BTC, ETH, stablecoins, and other assets into strategy vaults (BBTC, BBUSD, BBETH, BBNB, BBSOL), which are represented as rebasing BB-Tokens on the native BounceBit chain and earn yield through funding rate arbitrage, node staking, and ecosystem DeFi opportunities.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 6 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    No public repo or audits

    Neither a GitHub repository nor any audit is recorded. At Phase 0 this is the most conservative verifiability signal DeFiPunk'd can assign.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

BounceBit CeDeFi Yield has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 28addresses
  • 14verified source
  • 9proxies
  • 4of 5 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

baseTransparentUpgradeableProxy0x1317…e586TVLproxy
bouncebitBBUSD0x7777…5222TVL
bouncebittvl0x426c…4131TVL
bouncebittvl0x7f26…aaf7TVL
bouncebittvl0xd4de…1813TVL
bouncebittvl0xf5e1…81dcTVL
bscTransparentUpgradeableProxy0x55a5…867dTVLproxy
bscTransparentUpgradeableProxy0xdafd…442eTVLproxy
bscTransparentUpgradeableProxy0xf5e1…81dcTVLproxy
bscBEP20Token0x7130…ad9cTVL
bscTransparentUpgradeableProxy0x4714…d2f9TVL
bscTransparentUpgradeableProxy0x38d2…de0eTVLproxy
bscTransparentUpgradeableProxy0xf3fb…85c6TVL
bscBEP20USDT0x55d3…7955TVL
ethereumTransparentUpgradeableProxy0x1ddd…680fTVLproxy0x83f6…86df4/7 Safe
ethereumTransparentUpgradeableProxy0xa2b2…3085TVLproxy0x83f6…86df4/7 Safe
ethereumTransparentUpgradeableProxy0xf5e1…81dcTVL + discproxy0x83f6…86df4/7 Safe
ethereumTransparentUpgradeableProxy0xfe32…1df6TVLproxy0x83f6…86df4/7 Safe
ethereumTetherToken0xdac1…1ec7TVL0xc6cd…a828
EthereumBBUSD (BounceBit USD) proxy at 0x77776b40C3d75cb07ce54dEA4b2Fd1D07F865222 using EIP-1967 transparent proxy pattern; implementation at 0xbc8570ae1dae11d8b439fa1845753bef2eda6eb10x7777…5222discovery
Ethereumblacklist contract0x373d…602ddiscovery
EthereumBounceBit Token (BB) deployed on Ethereum at 0xd459ECeddafcc1d876a3be7290A2E16e801073a3; uses BBOFT implementation with LayerZero cross-chain support; constructor args show owner 0x681a12a2e496FBe469092D7aD029fF3B8cEFaaFb0xd459…73a3discoverytoken
Ethereumdelegate (BBOFT token cross-chain)0x83f6…86dfdiscoverytoken
Ethereuminitial_owner (BBOFT token)0x681a…aafbdiscoverytoken
EthereumLayerZero endpoint0x1a44…728cdiscovery
Ethereum,Binance,BounceBitBBTC (Bitcoin on BounceBit) token address: 0xF5e11df1ebCf78b6b6D26E04FF19cD786a1e81dC on BSC, ETH, and BB chains; cross-chain transfer handled by BTC Bridge0xf5e1…81dcdiscoverybridge
Ethereum,Binance,BounceBitBBUSD (Stablecoins on BounceBit) token address: 0x77776b40C3d75cb07ce54dEA4b2Fd1D07F865222 on BSC, ETH, and BB chains0x7777…5222discoverytoken
unknownWrapped BB Token Address: 0xF4c20e5004C6FDCDdA920bDD491ba8C98a9c5863; BB native token total supply capped at 2,100,000,000; dual-token staking for chain security0xf4c2…5863discoverytoken

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@bounce_bit

Security

[defillama] Source: DeFiLlama
Audits
unknown
Bug bounty
unknown
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Voting token
BB Ethereum: 0xd459ECeddafcc1d876a3be7290A2E16e801073a3
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC