DeFiPunk'd

Sophon Bridge

Canonical Bridge

TVL $80.1M
Type Canonical Bridge
Chain Ethereum
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty Governance forum Docs docs.sophon.xyz
About

Sophon Bridge is the canonical ZK Stack Validium bridge connecting Ethereum (L1) to the Sophon network (L2, chain ID 50104). Users deposit ETH or ERC-20 tokens on Ethereum via BridgeHub, with funds escrowed in the L1NativeTokenVault; a separate custom L1USDCBridge (audited by Omniscia) handles native USDC bridging following Circle's Bridged USDC Standard. Withdrawals require a ZK validity proof and a 3-hour ValidatorTimelock delay before finalization on Ethereum. Upgrades to the shared ZK Stack contracts follow a 4d 3h–8d 3h standard governance path or can be executed instantly via the EmergencyUpgradeBoard (3/3 of SecurityCouncil, Guardians, and ZK Foundation Multisig); Sophon-specific chain parameters are controlled by the 4/7 SophonChainAdminMultisig.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 39 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 1 audit

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
  2. Autonomy tentative
    External message validators reduce autonomy

    Bridges rely on an external validator set, guardian signatures, or light-client proofs — a category-level autonomy risk independent of any specific implementation.

    Run your own prompt Submit run ↗
3 dimensions not yet assessed (Control, Ability to exit, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Sophon Bridge has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 41addresses
  • 3verified source
  • 2proxies

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-14.

ethereumTransparentUpgradeableProxy0x996d…db90TVLproxy
ethereumStAethir0xc96a…e59cTVL
ethereumTransparentUpgradeableProxy0xf553…f987TVL + discproxybridge
Ethereumadmin (EraChainAdminProxy - governance proxy for Matter Labs Multisig)0x2cf3…5063discoverymultisig
Ethereumadmin (SophonZkEvmAdmin governance proxy)0xe1ee…2ad3discoverygovernance
Ethereumgovernor (ProtocolUpgradeHandler - central upgrade contract for all ZK Stack)0xe30d…5ab3discoverygovernance
Ethereumguardian (EOA 4 - SophonTransactionFilterer superuser/whitelist manager)0x50b2…7cf9discoveryguardian
Ethereumguardian (Guardians multisig 5/8 - ZK Stack governance guardians)0x600d…86b8discoverymultisig
Ethereumguardian (SecurityCouncil 9/12 - ZK Stack security council)0x66e4…f410discoverymultisig
Ethereumguardian (SophonTransactionFilterer - L1->L2 censorship control)0x9d06…3063discoveryguardian
Ethereummultisig (EmergencyUpgradeBoard - 3/3 of SecurityCouncil+Guardians+ZKFoundation, zero-delay upgrades)0xece8…e3f6discoverymultisig
Ethereummultisig (Matter Labs Multisig 5/8 - ZK cluster admin)0x4e49…7828discoverymultisig
Ethereummultisig (SophonChainAdminMultisig 4/7 - chain admin)0xe464…52d1discoverymultisig
Ethereummultisig (ZK Foundation Multisig 3/5 - EmergencyUpgradeBoard signer)0xbc16…b51cdiscoverymultisig
Ethereumother (AvailBridgeV1 - Avail/Vector bridge for DA attestation)0x054f…9f0adiscoverybridge
Ethereumother (AvailL1DAValidator - Avail DA verification contract)0x8f50…0120discovery
Ethereumother (BridgeHub - ZK Stack registry and bridge entrypoint)0x303a…5213discoveryfactory
Ethereumother (ChainAssetHandler - chain migration management)0xdd5c…1076discovery
Ethereumother (ChainTypeManager - ZK Stack version and upgrade registry)0xc2ee…5f5cdiscoveryfactory
Ethereumother (CTMDeploymentTracker - ChainTypeManager asset tracker)0x6078…9860discovery
Ethereumother (Diamond - main ZK chain contract, L2 settlement anchor)0x05ed…41e3discovery
Ethereumother (DualVerifier - routes to PlonK or Fflonk verifier)0xcd27…7a45discovery
Ethereumother (EOA 1 - Validator EOA for committing/proving/executing L2 batches)0x7832…fe30discovery
Ethereumother (EOA 2 - Validator EOA for committing/proving/executing L2 batches)0xcd0b…55dadiscovery
Ethereumother (EOA 3 - tokenMultiplierSetter in SophonZkEvmAdmin)0xe148…cbf3discovery
Ethereumother (EOA 5 - Vector Relayer, commits Avail block ranges)0x27bf…787ddiscoverybridge
Ethereumother (L1Nullifier - L1 bridge bookkeeping, withdrawal finalization)0xd7f9…b2cbdiscoverybridge
Ethereumother (L1USDCBridge implementation)0x2ccd…6cbbdiscovery
Ethereumother (L1VerifierFflonk - ZK proof verifier)0xa38a…f442discovery
Ethereumother (L1VerifierPlonk - ZK proof verifier)0x7f33…f4ecdiscovery
Ethereumother (MessageRoot - aggregates bridge message roots)0x5ce9…b4addiscoverybridge
Ethereumother (RollupDAManager - allowed DA pairs registry)0xe689…3c45discoveryfactory
Ethereumother (RollupL1DAValidator - Ethereum calldata/blob DA validator)0x7221…9119discovery
Ethereumother (ServerNotifier - chain migration notifications)0xfca8…ce31discovery
Ethereumother (Vector - Avail DA commitment bridge)0x0299…298ddiscoverybridge
Ethereumproxy_admin (ProxyAdmin - owned by ProtocolUpgradeHandler)0xc2a3…2cf1discovery
Ethereumproxy_admin (ProxyAdmin #2 - owned by ProtocolUpgradeHandler)0x1e4c…be3ediscovery
Ethereumproxy_admin (ProxyAdmin #3 - owned by EraChainAdminProxy)0x257f…d29bdiscovery
Ethereumtimelock (ProtocolTimelockController L2->L1 - queues upgrades to ProtocolUpgradeHandler)0x085b…c714discoverytimelock
Ethereumtimelock (ValidatorTimelock - 3h delay before L2->L1 execution)0x2e51…b776discoverytimelock
Ethereumvault (L1NativeTokenVault - canonical escrow for all ZK Stack chains)0xbed1…11f6discoveryvault

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@sophon
GitHub
sophon-org

Security

[curated] Source: curated human overlay [:] Source: DEFI@home quorum
Audits
1 audit
Bug bounty
unknown
Security contact
product@sophon.xyz

Technical

[:] Source: DEFI@home quorum
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC