DeFiPunk'd

Polygon Bridge

Chain

TVL $2.3B
Type Chain
Chain Polygon
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty docs.polygon.technology Governance forum forum.polygon.technology Docs docs.polygon.technology
About

Polygon Bridge (PoS Portal) is the canonical asset bridge connecting Ethereum (root chain) to the Polygon PoS network (child chain). Users deposit ERC-20, ERC-721, or ETH into predicate contracts on Ethereum, which lock assets while equivalent tokens are minted on Polygon; withdrawals require burning tokens on Polygon, waiting for a Heimdall checkpoint (≈30 min), then submitting a Merkle proof to the RootChainManager on Ethereum to unlock funds. The bridge uses an upgradeable proxy architecture (EIP-897 DelegateProxy) with a RootChainManager as the central coordinator and separate predicate contracts per token type.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 4 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 5 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Polygon Bridge has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 67addresses
  • 20verified source
  • 5proxies
  • 0of 4 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-14.

ethereumInitializableAdminUpgradeabilityProxy0x7fc6…dae9TVLproxy
ethereumVyper_contract0xd533…cd52TVL
ethereumDai0x6b17…1d0fTVL
ethereumFRAXStablecoin0x853d…b99eTVL
ethereumFRAXShares0x3432…64d0TVL
ethereumMiniMeToken0x5a98…1b32TVL
ethereumLinkToken0x5149…86caTVL
ethereumMaticToken0x7d1a…ebb0TVL
ethereumOwnedUpgradeabilityProxy0x0000…b376TVLproxy0x0000…3cc9
ethereumUni0x1f98…f984TVL
ethereumFiatTokenProxy0xa0b8…eb48TVLproxy0xfcb1…ae3a
ethereumTetherToken0xdac1…1ec7TVL0xc6cd…a828
ethereumWBTC0x2260…c599TVL0xca06…beb7
polygonnull0x0000…0000TVL
polygonstakeManager0x5e3e…d908TVL
polygontvl0x0335…87b8TVL
polygontvl0x04fa…f828TVL
polygontvl0x0961…53a7TVL
polygontvl0x0a6e…7909TVL
polygontvl0x0cec…844eTVL
polygontvl0x0f5d…c942TVL
polygonIchiV2Polygon0x1111…c4d6TVL
polygontvl0x1494…3c2bTVL
polygonUChildERC20Proxy0x16ec…3db4TVLproxy
polygontvl0x249e…dc3bTVL
polygontvl0x3593…c95dTVL
polygontvl0x3845…a5d0TVL
polygontvl0x3a4f…b430TVL
polygontvl0x3f38…1550TVL
polygontvl0x401f…188bTVL
polygontvl0x40ec…bbdfTVL
polygontvl0x43df…4dddTVL
polygontvl0x467b…790fTVL
polygontvl0x4b52…588dTVL
polygontvl0x4f81…1c8dTVL
polygonTransparentUpgradeableProxy0x544c…7429TVLproxy
polygontvl0x56d8…f4b3TVL
polygontvl0x6f40…03ebTVL
polygontvl0x7396…db2fTVL
polygonChildERC200x8484…2b30TVL
polygontvl0x8888…4c60TVL
polygontvl0x8b38…1d81TVL
polygontvl0x8ffe…caeaTVL
polygontvl0x9534…136eTVL
polygontvl0x9695…9023TVL
polygontvl0x99fe…1452TVL
polygontvl0xa47c…1acdTVL
polygontvl0xa4ee…a3e3TVL
polygontvl0xa51f…5bf6TVL
polygontvl0xaaae…d42dTVL
polygontvl0xb4d9…c365TVL
polygontvl0xb6ee…7143TVL
polygontvl0xb705…cfaeTVL
polygontvl0xba10…4e3dTVL
polygontvl0xba8a…25efTVL
polygontvl0xc581…e491TVL
polygontvl0xc944…44a7TVL
polygontvl0xcc4a…46b9TVL
polygontvl0xcfce…d22aTVL
polygontvl0xd0cd…78c4TVL
polygontvl0xd2ba…3368TVL
polygontvl0xdb25…7ad8TVL
polygontvl0xdefa…7202TVL
polygonAltaFinanceChild0xe0cc…38f5TVL
polygonAddress0xe912…3fb4TVL
polygonVLFI0xee1e…a61fTVL
polygontvl0xff56…b0faTVL

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@0xPolygon

Security

[:] Source: DEFI@home quorum
Audits
5 audits
Security contact
https://docs.polygon.technology/tools/security/

Technical

[:] Source: DEFI@home quorum
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC