DeFiPunk'd

OKX

CEX

TVL $23.7B
Type CEX
Chains Ethereum, Bitcoin, Solana, Doge, Tron +14
View on DeFiLlama ↗
Control criteria
Upgradeability Unknown Bug bounty hackenproof.com Governance forum Docs web3.okx.com
About

OKX is a centralized cryptocurrency exchange (CEX) offering spot, margin, perpetual, options, and futures trading across hundreds of tokens, where user assets are held in custody via OKX-controlled hot and cold wallet systems employing semi-offline multi-signature security. Alongside the custodial exchange, OKX operates an on-chain DEX aggregator (OKX DEX) deployed as upgradeable smart contracts on Ethereum and 15+ EVM-compatible chains, routing trades through external liquidity sources. OKX publishes monthly Proof of Reserves reports using zk-STARK cryptographic attestation, audited by Hacken, to allow users to verify that reserves exceed liabilities. The OKB token (Ethereum proxy contract 0x75231f58) is OKX's native exchange token used for fee discounts and ecosystem participation.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability red
    Closed codebase

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  2. Control red
    Operator-controlled

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  3. Ability to exit red
    Withdrawals can be halted

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  4. Autonomy red
    Off-chain counterparty

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

  5. Open Access red
    Permissioned by design

    Centralized exchanges are not onchain protocols. They are operated by a single legal entity that custodies user funds, can freeze withdrawals, and has full discretion over the codebase.

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

OKX has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 305addresses
  • 7verified source
  • 7proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

arbitrum0x0938…589eTVL
arbitrum0x42cf…ea57TVL
arbitrum0x6238…bbe6TVL
arbitrum0x77a9…3634TVL
arbitrum0x8828…5b9eTVL
arbitrum0xafee…ad72TVL
arbitrum0xb835…6b14TVL
arbitrum0xb8b0…e85aTVL
arbitrum0xbf94…420bTVL
arbitrum0xda22…e7fcTVL
arbitrum0xed55…d90fTVL
arbitrum0xf281…95b0TVL
Arbitrumother (DEX token approval on Arbitrum/Optimism/Fantom)0x70cb…2f58discoverytoken
Arbitrumrouter (DEX Router on Arbitrum)0x01d8…3b4cdiscoveryrouter
avax0x3d34…219cTVL
avax0x6238…bbe6TVL
avax0x7e4a…4308TVL
avax0xb2cf…5fc6TVL
avax0xc94b…f1feTVL
base0x0db6…95d7TVL
base0x10b7…fa0dTVL
base0x3959…0454TVL
base0xc880…f391TVL
BNB Chainother (DEX token approval on BNB Chain)0x2c34…cdd6discoverytoken
BNB Chainrouter (DEX Aggregation Router on BNB Chain — TransparentUpgradeableProxy)0x9333…8babdiscoveryrouter
era0x4612…6bfdTVL
era0x4e7b…c0d4TVL
era0x539c…bca1TVL
era0x65a0…7997TVL
era0x837c…cb94TVL
era0x868d…6d7fTVL
era0x91db…d480TVL
era0xa7ef…93f3TVL
era0xaac9…1eecTVL
era0xacfd…76ffTVL
era0xb1c5…ba13TVL
era0xbfbb…d10fTVL
era0xc708…96fdTVL
era0xd4ca…2383TVL
era0xdd91…3500TVL
era0xea9a…4ecfTVL
era0xebe8…2caeTVL
era0xf598…0de4TVL
era0xf785…4840TVL
era0xf9b5…cbdbTVL
ethereum0x0003…8d4eTVL
ethereum0x01c2…51e8TVL
ethereum0x01f6…d3a4TVL
ethereum0x01f7…0585TVL
ethereum0x03ae…9d3eTVL
ethereum0x03d0…46b6TVL
ethereum0x0475…baf4TVL
ethereum0x0607…de09TVL
ethereum0x0632…24bbTVL
ethereum0x0695…bb0bTVL
ethereum0x06d3…dcb6TVL
ethereum0x073f…3ad7TVL
ethereum0x0750…6ad6TVL
ethereum0x0799…749cTVL
ethereum0x08af…e898TVL
ethereumERC1967Proxy0x08f6…b483TVLproxy
ethereum0x0938…589eTVL
ethereum0x0a13…82f9TVL
ethereum0x0c48…63f9TVL
ethereum0x0ff9…fdb1TVL
ethereum0x11b1…1e31TVL
ethereum0x1278…c087TVL
ethereum0x12a8…0fcfTVL
ethereum0x16b5…8d93TVL
ethereum0x1738…e980TVL
ethereum0x17e9…591aTVL
ethereum0x1811…1b61TVL
ethereum0x19ab…54fcTVL
ethereum0x1a55…7a4fTVL
ethereum0x1c62…d086TVL
ethereumERC1967Proxy0x1dfc…e1d4TVLproxy
ethereum0x1e43…0870TVL
ethereum0x221a…da4fTVL
ethereum0x2523…676dTVL
ethereumERC1967Proxy0x2670…81a0TVLproxy
ethereum0x267b…2653TVL
ethereum0x276c…d5fdTVL
ethereum0x2976…ef50TVL
ethereum0x2c8f…a161TVL
ethereum0x30c1…3ae2TVL
ethereum0x313e…d369TVL
ethereum0x32dc…8199TVL
ethereumERC1967Proxy0x3425…23a3TVLproxy
ethereum0x3b96…6e03TVL
ethereum0x3b98…5e4fTVL
ethereum0x3bb0…42adTVL
ethereum0x3c58…b8f4TVL
ethereum0x3d23…7e86TVL
ethereum0x3d55…179fTVL
ethereum0x3e7d…9458TVL
ethereum0x3f48…ad16TVL
ethereum0x400d…067dTVL
ethereum0x4106…de64TVL
ethereum0x4243…68f2TVL
ethereum0x4279…b3e5TVL
ethereum0x42cf…ea57TVL
ethereumERC1967Proxy0x445f…bd97TVLproxy
ethereum0x45d9…8d52TVL
ethereum0x45f3…2a2aTVL
ethereum0x4612…6bfdTVL
ethereum0x47eb…87daTVL
ethereum0x4848…c6bfTVL
ethereum0x48c4…5f4aTVL
ethereum0x4a11…0433TVL
ethereum0x4bcb…a98dTVL
ethereum0x4d19…f21dTVL
ethereum0x4d61…4edaTVL
ethereum0x4e27…9f51TVL
ethereum0x5041…081aTVL
ethereum0x5273…6821TVL
ethereum0x52b3…ab4cTVL
ethereum0x539c…bca1TVL
ethereum0x5594…ed53TVL
ethereum0x56fd…3dffTVL
ethereum0x5938…753cTVL
ethereum0x5a15…213aTVL
ethereum0x5b27…f634TVL
ethereum0x5b87…a841TVL
ethereum0x5c52…e5f2TVL
ethereum0x5ca3…5d0fTVL
ethereum0x5f51…655dTVL
ethereum0x5f82…58b8TVL
ethereum0x608c…e3d7TVL
ethereum0x65a0…7997TVL
ethereum0x65e8…7ea6TVL
ethereum0x6667…7f09TVL
ethereum0x66e6…a706TVL
ethereumERC1967Proxy0x6709…24a6TVLproxy
ethereum0x6884…3d6dTVL
ethereum0x68b5…e907TVL
ethereum0x68e2…1662TVL
ethereum0x69a7…f396TVL
ethereum0x6a45…3414TVL
ethereum0x6b7b…11d0TVL
ethereum0x6d29…fea9TVL
ethereum0x6d8c…5ce1TVL
ethereum0x6dc1…f3a6TVL
ethereum0x6ede…6529TVL
ethereum0x6fb6…0113TVL
ethereum0x6fd4…f522TVL
ethereum0x728d…eba9TVL
ethereum0x730d…dbb3TVL
ethereum0x7397…7dc1TVL
ethereum0x767a…511cTVL
ethereum0x778e…1ecbTVL
ethereum0x7926…2298TVL
ethereum0x793a…63cbTVL
ethereum0x7a91…5e3cTVL
ethereum0x7a93…213eTVL
ethereum0x7c70…d943TVL
ethereum0x7cfe…365dTVL
ethereum0x7d4a…b86bTVL
ethereum0x7f61…240cTVL
ethereum0x7fe8…997bTVL
ethereum0x7fea…1b13TVL
ethereum0x8033…035fTVL
ethereum0x8167…f6a4TVL
ethereum0x83a3…9ec3TVL
ethereum0x85dc…134bTVL
ethereum0x868d…6d7fTVL
ethereum0x86ae…40bbTVL
ethereum0x8734…1b08TVL
ethereumERC1967Proxy0x87d0…eaf9TVLproxy
ethereum0x88c9…b2a2TVL
ethereum0x89b2…7a19TVL
ethereum0x8ad7…ac3bTVL
ethereum0x8c3c…22d8TVL
ethereum0x8f1a…6f22TVL
ethereum0x91d4…debeTVL
ethereum0x92ea…d4eaTVL
ethereum0x932d…0f87TVL
ethereum0x9723…0138TVL
ethereum0x98ec…a128TVL
ethereum0x9938…e8d5TVL
ethereum0x994d…5448TVL
ethereum0x9b64…d34fTVL
ethereum0x9ce5…58c4TVL
ethereum0x9d65…44aaTVL
ethereum0x9db8…317eTVL
ethereum0x9e13…472fTVL
ethereum0x9e3b…ea85TVL
ethereum0xa015…53e6TVL
ethereum0xa268…003dTVL
ethereum0xa27c…491fTVL
ethereum0xa68c…0c2dTVL
ethereum0xacf9…ed67TVL
ethereum0xae0c…92ffTVL
ethereum0xb072…ec52TVL
ethereum0xb0a2…3d64TVL
ethereum0xb47a…b6d7TVL
ethereum0xb4ec…64f7TVL
ethereum0xb640…1ee5TVL
ethereum0xb8ed…6138TVL
ethereum0xb99c…49ccTVL
ethereum0xba0a…60f4TVL
ethereum0xba7f…6159TVL
ethereum0xba96…e165TVL
ethereum0xbda2…96f2TVL
ethereum0xbe2e…6fc5TVL
ethereum0xbfbb…d10fTVL
ethereum0xbfef…573fTVL
ethereum0xc0d0…7674TVL
ethereum0xc184…97ceTVL
ethereum0xc275…d2f5TVL
ethereum0xc526…2961TVL
ethereum0xc545…d91aTVL
ethereum0xc672…3ceaTVL
ethereum0xc68c…c3e4TVL
ethereum0xc708…96fdTVL
ethereum0xcab0…3a88TVL
ethereum0xcb09…1bb3TVL
ethereum0xcba3…6ab6TVL
ethereum0xcbc7…045bTVL
ethereum0xcc5d…4b2aTVL
ethereum0xcd5b…8c12TVL
ethereum0xce9a…2ca7TVL
ethereum0xd03e…ad6eTVL
ethereum0xd049…1a49TVL
ethereum0xd19d…f419TVL
ethereum0xd266…1078TVL
ethereum0xd576…f03fTVL
ethereum0xd5f8…7634TVL
ethereum0xd776…74b6TVL
ethereum0xd7f4…f0a0TVL
ethereum0xd99d…32adTVL
ethereum0xd9a3…0a70TVL
ethereum0xdad2…0c81TVL
ethereum0xdb0e…4ad0TVL
ethereum0xdc3c…ee10TVL
ethereum0xdce8…94daTVL
ethereum0xddf8…8c94TVL
ethereum0xde01…283fTVL
ethereum0xdeb6…5443TVL
ethereum0xe2ef…223bTVL
ethereum0xe3bb…a9c3TVL
ethereum0xe404…cd74TVL
ethereum0xe6ee…d146TVL
ethereum0xe7b2…0ff1TVL
ethereum0xe7c8…1450TVL
ethereum0xe917…8f99TVL
ethereum0xe983…2da3TVL
ethereum0xea3b…143fTVL
ethereum0xeaed…c038TVL
ethereum0xeb19…ba86TVL
ethereum0xedc0…bf0dTVL
ethereum0xee1c…36fbTVL
ethereum0xf02e…8fc1TVL
ethereum0xf418…41baTVL
ethereum0xf598…0de4TVL
ethereum0xf683…2617TVL
ethereum0xf785…4840TVL
ethereum0xf7b1…9064TVL
ethereum0xf7c6…e4d2TVL
ethereum0xf8b4…75e8TVL
ethereum0xfa13…b14bTVL
ethereum0xfad7…2d2dTVL
ethereum0xfcb2…cf7aTVL
ethereum0xfe90…a1adTVL
ethereumother (CEX primary exchange wallet)0x6cc5…da7bTVL + disc
ethereumother (cold wallet, $1.2B across 15 chains)0x611f…b09dTVL + disc
ethereumother (deposit funder)0xc5a9…2396TVL + disc
ethereumother (hot wallet 3)0xa9ac…4573TVL + disc
ethereumother (OKX 20, exchange wallet)0x7eb6…1ef2TVL + disc
ethereumother (OKX 24, exchange wallet)0xbf94…420bTVL + disc
ethereumother (OKX 3, exchange wallet)0xa7ef…93f3TVL + disc
ethereumother (OKX wallet)0x96fd…0bcdTVL + disc
Ethereumother (DEX token approval contract)0x40aa…cd7fdiscoverytoken
Ethereumother (hot wallet 2)0x4e7b…c0d4discovery
Ethereumother (hot wallet)0x4b4e…06e5discovery
Ethereumother (OKX NFT 3 contract)0xa7fd…0f7cdiscoveryfactory
Ethereumrouter (DEX aggregation router — TransparentUpgradeableProxy)0x3b3a…6790discoveryrouter
Ethereumrouter (DEX Router 2)0x7d0c…6b36discoveryrouter
Ethereumrouter (DEX Router)0x2e1d…8764discoveryrouter
Ethereumtoken (OKB token — OwnedUpgradeabilityProxy, impl 0x81a4eea0ab6dd6a010b7318a662a43d0ca25e094)0x7523…a86cdiscoverytoken
linea0x0ba3…b8ebTVL
linea0x6df7…6771TVL
linea0xd3d7…c240TVL
linea0xe4b7…a008TVL
linea0xe69a…e162TVL
optimism0x2d2c…0939TVL
optimism0x42cf…ea57TVL
optimism0x5ff1…9277TVL
optimism0x63a3…95ffTVL
optimism0x7332…9844TVL
optimism0x8895…b681TVL
optimism0x8d37…a832TVL
optimism0xb521…bb1dTVL
optimism0xc66c…55c4TVL
optimism0xcba6…0116TVL
optimism0xebe8…2caeTVL
polygon0x4120…b143TVL
polygon0xbe78…d19dTVL
polygon0xf812…0c5cTVL
polygonother (OKX 1, exchange wallet on Polygon)0x0695…bb0bTVL + disc
Polygonother (DEX token approval on Polygon)0x3b86…4e31discoverytoken
scroll0x4ac4…86f9TVL
scroll0x611f…b09dTVL
scroll0x8243…1e64TVL
scroll0x8553…6aebTVL
scroll0xe4f4…3d6fTVL

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@okx
GitHub
3 repositories

Security

[:] Source: DEFI@home quorum
Audits
1 audit
Security contact
https://cantina.xyz/bounties/00992789-fcd1-4bda-862e-463b0c73faa9

Technical

[:] Source: DEFI@home quorum
Voting token
OKB Ethereum: 0x75231f58b43240c9718dd58b4967c5114342a86c
Upgradeability
Unknown

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC