DeFiPunk'd

Bybit

CEX

TVL $15.0B
Type CEX
Chains Ethereum, Bitcoin, Tron, Solana, Mantle +31
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty hackerone.com Governance forum Docs bybit.com
About

Bybit is a centralized cryptocurrency exchange (CEX) allowing users to trade spot and derivatives markets, earn yield on idle assets, and access Web3 features including NFTs and DeFi integrations. Users deposit funds into Bybit-controlled custodial wallets across 35+ blockchains; Bybit holds all private keys and processes withdrawals through its internal risk and compliance systems. It is one of the largest exchanges by derivatives volume and gained significant attention in February 2025 when approximately $1.46 billion in ETH was stolen from its cold wallet in the largest crypto hack on record, with Bybit subsequently covering all losses and maintaining solvency.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability red
    Closed codebase

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  2. Control red
    Operator-controlled

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  3. Ability to exit red
    Withdrawals can be halted

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  4. Autonomy red
    Off-chain counterparty

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  5. Open Access red
    Permissioned by design

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Bybit has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 222addresses
  • 10verified source
  • 10proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

arbitrum0x1867…4e62TVL
arbitrum0x1c39…bd6fTVL
arbitrum0x7da0…058cTVL
arbitrum0x7e8c…621aTVL
arbitrum0x83d8…d5beTVL
arbitrum0x88a1…ade3TVL
arbitrum0x9322…2bd5TVL
arbitrum0x9d27…1bf0TVL
arbitrum0xa0ac…1dd4TVL
arbitrum0xbedf…54a2TVL
arbitrum0xd4d2…d35aTVL
arbitrum0xee5b…047aTVL
arbitrum0xf440…b9bcTVL
arbitrum0xf89d…aa40TVL
arbitrum_nova0xf89d…aa40TVL
avax0x0a7e…cf39TVL
avax0x1867…4e62TVL
avax0x1c39…bd6fTVL
avax0x3062…76a7TVL
avax0x88a1…ade3TVL
avax0x9322…2bd5TVL
avax0xbedf…54a2TVL
avax0xee5b…047aTVL
avax0xf440…b9bcTVL
avax0xf89d…aa40TVL
base0x1867…4e62TVL
base0x1db9…fcf4TVL
base0x7e8c…621aTVL
base0x88a1…ade3TVL
base0x9322…2bd5TVL
base0xbaed…439fTVL
base0xe1b2…5aebTVL
base0xee5b…047aTVL
bsc0x1867…4e62TVL
bsc0x318d…89b8TVL
bscSafeProxy0x388e…790bTVLproxyself 3/6
bsc0x88a1…ade3TVL
bsc0x9322…2bd5TVL
bsc0xbedf…54a2TVL
bsc0xc19b…48c5TVL
bsc0xc312…3878TVL
bsc0xc851…baf2TVL
bsc0xd4d2…d35aTVL
bsc0xee5b…047aTVL
bsc0xef3a…3b20TVL
bsc0xf440…b9bcTVL
bsc0xf89d…aa40TVL
bsc0xfe62…a17bTVL
celo0x5768…c92aTVL
celo0xf89d…aa40TVL
era0x1db9…fcf4TVL
era0xacf9…7e9fTVL
era0xee5b…047aTVL
era0xf89d…aa40TVL
ethereum0x01e2…4393TVL
ethereum0x076d…eed2TVL
ethereum0x0ac9…03aeTVL
ethereum0x13f5…1ddaTVL
ethereum0x180a…fa74TVL
ethereum0x1867…4e62TVL
ethereum0x187c…4100TVL
ethereum0x18e2…82f6TVL
ethereum0x1c39…bd6fTVL
ethereumProxy0x1db9…fcf4TVLproxy
ethereum0x223f…d0b5TVL
ethereum0x25c7…3dfdTVL
ethereum0x25c7…e1eaTVL
ethereum0x260b…4ceaTVL
ethereumGnosisSafeProxy0x2ebf…277fTVLproxyself 3/6
ethereum0x30ba…da54TVL
ethereum0x33ae…c74cTVL
ethereum0x3569…5fc7TVL
ethereum0x35bf…0a8aTVL
ethereum0x36cf…9686TVL
ethereum0x371c…791cTVL
ethereum0x3bd0…a789TVL
ethereum0x3cef…1d15TVL
ethereum0x3db4…b67dTVL
ethereum0x3ef2…ceb0TVL
ethereum0x412d…49f6TVL
ethereum0x41be…48a6TVL
ethereum0x429b…ede1TVL
ethereum0x448c…9d5cTVL
ethereum0x4865…4106TVL
ethereum0x495c…5cc2TVL
ethereum0x495e…699fTVL
ethereum0x4be6…0ddcTVL
ethereum0x4ce0…40bcTVL
ethereum0x4e19…1a6cTVL
ethereum0x4e5e…7d16TVL
ethereum0x554e…63ddTVL
ethereumProxy0x5a07…5e78TVLproxyself 3/6
ethereum0x5c4e…276dTVL
ethereum0x61b2…b717TVL
ethereum0x6206…69efTVL
ethereum0x6242…dc9fTVL
ethereum0x63be…0936TVL
ethereum0x6516…022fTVL
ethereum0x6522…7e90TVL
ethereum0x695f…ce8bTVL
ethereum0x6b9b…abe3TVL
ethereum0x6bd8…ee3eTVL
ethereumGnosisSafeProxy0x6f45…bb0cTVLproxyself 3/6
ethereum0x7016…5786TVL
ethereum0x70f5…863fTVL
ethereum0x7218…8829TVL
ethereum0x7743…4a48TVL
ethereum0x79ae…4433TVL
ethereum0x7a84…f6eeTVL
ethereum0x7c41…8b51TVL
ethereum0x7e8c…621aTVL
ethereum0x801b…f1aeTVL
ethereum0x80a9…6628TVL
ethereum0x80d4…bf65TVL
ethereum0x855e…6d48TVL
ethereum0x869b…4d68TVL
ethereum0x86db…3851TVL
ethereum0x8859…1e66TVL
ethereum0x88a1…ade3TVL
ethereum0x8968…f822TVL
ethereum0x8a24…26e5TVL
ethereum0x8c28…d25fTVL
ethereum0x8d6d…f3a2TVL
ethereum0x8ed5…a3ebTVL
ethereum0x8fa1…4d4aTVL
ethereum0x922f…8c3dTVL
ethereum0x9322…2bd5TVL
ethereum0x9336…7922TVL
ethereum0x9814…8f8aTVL
ethereum0x9cdb…25bdTVL
ethereum0xa1ab…df09TVL
ethereumProxy0xa2e5…be6dTVLproxyself 3/7
ethereum0xa312…b647TVL
ethereum0xa428…7380TVL
ethereum0xa4b9…bf30TVL
ethereumProxy0xa7a9…ed06TVLproxyself 3/6
ethereum0xa9ac…16afTVL
ethereum0xa9cf…6d11TVL
ethereum0xab97…ee2bTVL
ethereum0xad85…7549TVL
ethereum0xb246…c8eaTVL
ethereum0xb587…178dTVL
ethereum0xb829…7589TVL
ethereum0xbaed…439fTVL
ethereum0xbce9…02efTVL
ethereum0xc221…c440TVL
ethereum0xc273…3da7TVL
ethereum0xc63f…c71dTVL
ethereum0xc6c6…a93fTVL
ethereum0xc93e…13b4TVL
ethereum0xcab3…a8e8TVL
ethereum0xcacc…6f94TVL
ethereum0xcf4b…4aaeTVL
ethereum0xd07e…8814TVL
ethereum0xd4d2…d35aTVL
ethereum0xd7c4…ee02TVL
ethereum0xd860…b65fTVL
ethereum0xdae4…f2f6TVL
ethereum0xdba3…c09dTVL
ethereumProxy0xe1ab…9215TVLproxyself 3/6
ethereum0xe466…f243TVL
ethereumProxy0xe579…2a87TVLproxyself 3/7
ethereum0xec94…3ee0TVL
ethereum0xee5b…047aTVL
ethereum0xee62…462eTVL
ethereum0xefef…bc5cTVL
ethereum0xf2f4…fd94TVL
ethereum0xf358…4de8TVL
ethereum0xf42a…f173TVL
ethereum0xf440…b9bcTVL
ethereum0xf833…3b1aTVL
ethereum0xf89d…aa40TVL
ethereum0xf8f0…4002TVL
fantom0xf89d…aa40TVL
hyperliquid0x1b0b…0761TVL
hyperliquid0x1c39…bd6fTVL
hyperliquid0x1d83…37f7TVL
kava0xf89d…aa40TVL
klaytn0x0051…41b3TVL
linea0x4695…eaf4TVL
linea0xf89d…aa40TVL
manta0x5888…836cTVL
manta0xa6a9…d2b6TVL
manta0xf89d…aa40TVL
mantle0x036c…d932TVL
mantle0x0d4d…ca48TVL
mantle0x4a67…a69cTVL
mantle0x5888…836cTVL
mantle0x5980…ac1dTVL
mantle0x70f5…863fTVL
mantle0x98be…0394TVL
mantle0xbce9…02efTVL
mantle0xc868…f1f1TVL
mantle0xcbf4…6ebaTVL
mantle0xd374…840bTVL
mantle0xd816…a9c5TVL
mantle0xe080…826bTVL
mantleGnosisSafeProxy0xee62…462eTVLproxyself 3/6
mantle0xf229…1f1cTVL
optimism0x1db9…fcf4TVL
optimism0x5f44…a155TVL
optimism0x6d37…e92fTVL
optimism0x75df…553aTVL
optimism0x88a1…ade3TVL
optimism0x9322…2bd5TVL
optimism0xc0e1…62aeTVL
optimism0xd1c3…e0acTVL
optimism0xee5b…047aTVL
optimism0xf89d…aa40TVL
plasma0x01ea…3dcaTVL
polygon0x1347…74ecTVL
polygon0x1867…4e62TVL
polygon0x7e8c…621aTVL
polygon0x9322…2bd5TVL
polygon0xa85c…e2ceTVL
polygon0xee5b…047aTVL
polygon0xf89d…aa40TVL
scroll0xf89d…aa40TVL
sonic0x6378…ebe4TVL
sonic0x678c…44beTVL
sonic0x86db…3851TVL
taiko0xf89d…aa40TVL

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@Bybit_Official

Security

[:] Source: DEFI@home quorum
Audits
2 audits
Security contact
security@bybit.com

Technical

[:] Source: DEFI@home quorum
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC