Aster ALP

Orange · 41/100

Executive summary

Aster ALP is a multi-asset liquidity pool on BNB Chain that acts as counterparty to leveraged perpetual trades (up to 1001×), earning yield from trading fees, funding rates, and liquidations; it scores 55/100 (orange band) with a 15-point penalty for active regulatory enforcement.

  • Security: Multiple audits by PeckShield (May 2023, Apollox V2/ALP), Salus Security (Sept 2024 Earn contracts, June 2025 APX exchange), and CertiK (ongoing); findings included one high-severity slippage bug (resolved), centralization risks (mitigated), and admin-key trust issues (mitigated but not eliminated). Deployed BSC bytecode match to audited commits is not verifiable as of Sept 2026. Active Immunefi bug bounty with $200k max payout since April 2025.
  • Incidents: Sept 24, 2025 XPL perpetual price anomaly caused forced liquidations due to internal parameter error; Aster reimbursed affected users in USDT, but total loss and technical hardening are not disclosed.
  • Governance & custody: Non-custodial on-chain pool; no DAO governance verified—protocol decisions remain with core team. Admin topology, multisig threshold, timelock, and upgrade authority are not verifiable. Legal entity opaque; Terms cite Hong Kong law but no incorporation jurisdiction disclosed; Seychelles FSA explicitly denies any Seychelles nexus. Active regulatory enforcement penalty applied (details unspecified in facts).
  • Top risks: ALP holders bear directional counterparty risk to leveraged traders—NAV can fall sharply in adverse markets or liquidation gaps. Oracle dependency (Pyth/Chainlink/Binance) creates manipulation and stale-price risk; circuit-breaker thresholds and current oracle config not verifiable. Upgradeability via EIP-2535 Diamond with privileged admin; current role holders and emergency powers not verifiable. 48-hour burn lock and pool-liquidity constraints limit exit speed. Extreme leverage (1001×) amplifies tail risk.
  • Strengths: Capital-efficient single pool across all pairs; zero-slippage execution in Simple Mode; high reported APY (~25% BSC) from trading activity; backed by YZi Labs (Binance co-founders' family office) with CZ endorsement, providing strong reputational signal (unverified for institutional KYC).
  • Unverified: Current TVL, ALP token address, pool composition, largest collateral share, top trader concentration, and stress-test loss estimates all not verifiable as of Sept 2026. Founder identities pseudonymous; no public org chart or legal entity details. Deployed contract-to-audit bytecode match unavailable.
  • Recommended exposure: Limit to <2–5% of DeFi allocation given orange score and unverified admin controls. Suitable only for allocators comfortable with leveraged-counterparty risk, regulatory uncertainty, and potential NAV drawdowns. Require independent on-chain verification of admin keys, oracle config, and current pool composition before any position. Monitor perpetual open interest and funding rates closely; exit if governance opacity persists or if a second operational incident occurs.
  • Open questions: (1) Verify current BNB Chain ALP token and vault contract addresses, then match deployed bytecode to audited commits. (2) Identify admin/upgrader key holders, multisig threshold, and timelock delay. (3) Obtain current ALP asset breakdown, largest collateral %, and top-10 trader concentration. (4) Clarify legal entity, jurisdiction, and nature of active regulatory enforcement. (5) Stress-test pool NAV under BTC <$10k and 20% stablecoin depeg scenarios with live data. (6) Confirm oracle heartbeat, deviation thresholds, and circuit-breaker implementation on-chain.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 6 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2025-06-24 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 no open incidents
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL unavailable on DeFiLlama
Data confidence 88 7/7 critical categories; 15/37 verified facts; 37/37 fresh (180d)
  • Active regulatory enforcement (−15): legal fact records active enforcement or sanctions

Identification

protocol identification

two sources

Protocol identification

  • Name: Aster ALP (Aster Liquidity Pool)
  • Website / App: Main site asterdex.com, ALP interface at the Earn → ALP page (English path /en/earn/alp).
  • Docs: Aster ALP sections under Aster docs (Earn / Product / Simple mode / 1001x).
  • Category: Perpetual DEX liquidity pool / market‑making vault. ALP is a multi‑asset pool token whose NAV is driven by perp trading P&L, trading fees, funding fees, liquidations, and platform fees; ALP LPs are the counterparty to on‑chain perp trades in Simple/1001x modes.
  • Chains: ALP can be minted on BNB Chain (BSC) and Arbitrum. The user‑specified focus chain is BSC.
  • Native token (for this pool): ALP is the liquidity‑pool ERC‑20 and market‑making token for Aster’s Simple/1001x perps. Aster also has other ecosystem tokens (e.g. USDF, asBNB) but ALP is the relevant pool token for this query.
  • Launch date: Not explicitly stated in docs; ALP functionality and staking guides are live by mid‑2025 and referenced in a 2025 AMA and external guides. Exact launch date is Not verifiable as of 2026‑09‑04. Main contract addresses (BSC) & verification status
  • Aster maintains an official Smart Contracts registry page listing contract addresses per supported network, including ALP-related contracts. However, specific ALP ERC‑20 and pool contract addresses on BSC are not visible in the retrieved snippets, and I cannot cross‑check them against explorer data here.
  • Without direct access to those addresses plus an explorer view, whether the ALP token and pool contracts are verified (source code published and matched) on BSC explorers is Not verifiable as of 2026‑09‑04.
  • Dune on‑chain references (TVL, volume, ALP APY) exist for Aster on BNB Chain, but query IDs and exact contract mappings are also Not verifiable as of 2026‑09‑04. Fork lineage / upstream relationships
  • Aster (formerly Astherus) is described as the result of a merger between Astherus (yield protocol) and APX (perp DEX on BNB Chain). ALP appears as the unified liquidity pool for the Simple on‑chain perp mode and 1001x product.
  • Docs and public materials do not explicitly identify ALP as a fork of a specific upstream protocol (e.g., GMX GLP or other perps vaults), nor do they detail which smart‑contract changes were made vs upstream.
  • There is no retrieved evidence that ALP smart‑contract changes have been audited by named auditors, nor of any malicious‑modification incidents in ALP‑like forks of Aster/APX.
  • Accordingly, fork status, code‑level diffs vs any upstream, and audit coverage for ALP are Not verifiable as of 2026‑09‑04.
Evidence (15)

maturity

unverified

Aster ALP appears to be a live product, not a pure landing page: the docs explicitly describe minting and burning ALP on a functioning earn page at https://www.asterdex.com/en/earn/alp, with wallet connection and transaction-based mint/burn flows on BNB Chain. The documentation also exposes an API program for the broader Aster platform, including API key creation and API documentation, which supports the conclusion that there is an open developer API surface. What is not verifiable from the available sources is whether the ALP page is fully healthy end-to-end right now, whether deposits/withdrawals are currently working without errors, and whether there are broken links or template/fake-metric signs on the live site as of 2026-09-04.

The on-chain verification step is unavailable in this run, so any TVL or live-flow claims from the project or aggregators remain unverified marketing claims here.

Evidence (4)

Security

bug bounty

one source

Aster’s bug bounty program is active and hosted on Immunefi. It has been live since 16 April 2025, with a maximum payout of $200,000. Scope includes smart contracts, websites, and applications; critical smart-contract issues pay 10% of funds directly affected, subject to a $50,000 minimum and $200,000 cap.

Critical web/app issues pay a flat $7,500 only for losses requiring no user action or key leakage; other critical web/app impacts pay $4,000. Proof of concept is required for all severities, and payouts are in USDT on BSC. Publicly visible results from the program were not verifiable in the available sources as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$200K
Since
2025-04-16
Evidence (3)

counterparty risks

unverified

As of September 6, 2026, no active external dependency failure was identified in the reviewed sources; however, live on-chain verification is unavailable. dependency_failure_active: null. max_exposure_pct: null. Scope / product dependency. Aster ALP is the liquidity pool for Aster’s 1001x/Simple Mode perpetuals. ALP providers bear pool PnL, trading fees, funding-fee and liquidation outcomes; therefore, the primary counterparty is Aster’s own perpetual-trading and liquidation engine, not a neutral AMM. This remains an unverified marketing/documentation claim because Dune verification is unavailable. Oracle and manipulation risk. Aster documentation states that 1001x uses Pyth as the primary feed, Chainlink for cross-checking, and Binance Oracle as fallback; a stated 1% Pyth/Chainlink deviation triggers a circuit breaker.

Earlier Aster documentation also describes weighted prices using Binance, Huobi, and Kraken. This creates dependency on oracle publishers, exchange market data, update latency, stale prices, and governance/configuration of feed selection. Oracle contracts, heartbeat settings, deviation thresholds, and ALP-specific liquidation implementation are Not verifiable as of September 6, 2026. Stablecoin, LST/restaking and external-protocol exposure. ALP minting assets and current pool weights are not independently observable here; therefore exposure to USDT, USDC, BNB, LSTs, restaked assets, or other tokens is Not verifiable as of September 6, 2026.

Aster separately documents USDF as USDT-backed and Ceffu-custodied, but this does not establish that ALP reserves are held with Ceffu or materially invested in USDF. Bridges / chains. Documentation says ALP can be minted on BNB Chain and Arbitrum. The bridge, canonical-token mapping, validator/multisig set, and cross-chain exposure are Not verifiable as of September 6, 2026. The requested BSC scope should therefore be treated as BNB Chain only; Arbitrum exposure is outside scope. Custodians, CEX/MM and RWA. Aster’s ALP market-making depends on Aster’s own venue and oracle-linked external exchange prices.

Direct CEX custody, named market makers, RWA issuers/SPVs, and insolvency protections are Not verifiable as of September 6, 2026. Failure scenarios: oracle divergence or outage; Aster liquidation-engine error; extreme trader PnL/bad debt; USDT or pool-asset depeg; bridge halt/replay; BNB Chain outage/reorg; or centralized custodian/venue insolvency. No quantitative maximum-loss percentage can be established without current pool composition and liabilities.

Evidence (5)

crypto custody

unverified

Aster ALP is best described as a non-custodial on-chain liquidity pool on BNB Chain: users mint ALP into the pool, and the pool smart contracts act as the trading counterparty and settlement layer rather than a centralized custodian. The broader Aster platform also describes its perpetual trading flow as self-custodial, while Aster’s separate USDF/asUSDF product uses institutional custody arrangements, so custody is product-specific rather than uniform across the protocol.

Evidence (3)

incident

two sources

On September 24, 2025 UTC, Aster’s BNB Chain XPL perpetual market experienced an abnormal price event during the transition from pre-launch to regular trading. Aster attributed it to an internal parameter-configuration error: the index price remained in pre-launch mode after a cap was removed, producing an XPL price near $4 while other venues were around $1.30. The discrepancy triggered forced liquidations, abnormal fees, and user losses; the affected component was the XPL perpetual market, not the ASTER token contract or custody system.

Aster said the issue was resolved by approximately 21:45 UTC, reimbursed liquidated users directly in USDT, and later issued a second compensation round for related trading and liquidation fees. Users were reported fully reimbursed. The total realised loss, compensation amount, and any protocol-funded shortfall were not disclosed: Not verifiable as of September 6, 2026.

No external attacker or attacker proceeds were reported. Technical hardening beyond the immediate correction was not publicly documented: Not verifiable as of September 6, 2026. Current status: resolved.

Date
2025-09-24
Cause
Other
Attacker proceeds
$0
Status
resolved
Reimbursed
Yes
Event id
aster-xpl-perpetual-price-anomaly-2025-09-24
Evidence (4)

incident

one source

I found one clearly reported Aster incident since launch: on September 25, 2025, Aster’s newly listed Plasma (XPL) perpetual pair showed irregular price fluctuations, with XPL on Aster briefly spiking to about $4 while other venues were near $1.30. The reported effect was user liquidations and a token drop of more than 14%; Aster said it reimbursed affected traders in USDT, but the exact loss amount and compensation total were not disclosed. The precise root cause was not publicly confirmed; one cited explanation was a manually configured index-price error, but this remains unverified.

The response/fix described in reporting was rapid reimbursement and a price-glitch correction, but the technical remediation details were not published.

Date
2025-09-25
Cause
Other
Evidence (1)

key management

unverified

Aster ALP’s published documentation does not describe any cryptographic key-management architecture (for example, whether keys are stored in an HSM, managed by a multisig, rotated by a DAO, or controlled by a custodian). The only directly relevant statement I found is that ALP is a liquidity pool for Aster perps and that ALP holders act as the market-maker counterparty; this explains the pool’s role, but not how operational or signing keys are organized. So, for key management, the answer is: Not verifiable as of 2026-09-04 from the available sources.

What is verifiable is that Aster presents ALP as a pool-based liquidity layer rather than a custody product, which suggests user funds are used in protocol interactions rather than through an explicit key-management workflow; however, that is an inference, not a documented key-management design, and should not be treated as confirmed.

Evidence (2)

smart-contract

two sources

As of 2026-09-06 — BNB Chain Address / verification. The identified BNB trading core used by Simple Mode/ALP is 0x1b6F2d3844C6ae7D56ceb3C3643b9060ba28FEb0. Its source is explorer-verified and identifies an EIP-2535 Diamond-style architecture with LibDiamond, IDiamondCut, IDiamondLoupe, and role-based access control. No separate ALP token/vault address is published in the reviewed official registry. Upgradeability / admin. upgradeable: true.

The contract contains a diamondCut entry point and supports adding, replacing, and removing facets; therefore implementation logic can change without changing the main address. Louper identifies a DiamondCutFacet at 0x61595c597fB5b00067507d8850E5c9161406Ae9c. The deployment source initializes DEFAULT_ADMIN_ROLE and DEPLOYER_ROLE, but the current role holders, whether the admin is an EOA/multisig/timelock, and whether any role was renounced are Not verifiable as of 2026-09-06. Privileged functions / exit risk. The Diamond pattern creates potential privileged control over upgrades and, depending on facet authorization, pause state, withdrawals, fees, oracle configuration, trading parameters, and liquidity accounting.

Current authorization for these functions, emergency powers, withdrawal limits, and on-chain timelock delay are Not verifiable as of 2026-09-06 because Dune was unavailable. The documented ALP burn path is constrained by a 48-hour lock, pool liquidity, and users’ position exposure; this is a protocol-level exit constraint, not evidence of an admin-free exit. Worst case. If the effective upgrade/admin key is compromised, an attacker could replace facets, introduce malicious accounting or oracle logic, freeze withdrawals/trading, redirect fees, or potentially transfer pool-controlled assets—subject to the actual facet permissions, which are unverified. Rug/freeze risk is therefore material and unresolved. Architecture: User → ALP mint/burn + Simple Mode calls → Diamond proxy/core → facets (trading, oracle, pricing, access control, DiamondCut) → pool assets Admin/deployer role → DiamondCutFacet → facet replacement / initialization Contradiction / evidence gap: Official documentation describes ALP as a liquidity pool and publishes user burn rules, but does not publish a distinct ALP vault address or current admin/timelock configuration.

On-chain measurements: Not verifiable as of 2026-09-06. Assessment: upgrade/admin centralization risk: High; withdrawal freeze risk: Unquantified but material. No verified evidence supports “renounced” or “timelocked” administration.

Upgradeable
Yes
Evidence (5)

audit

two sources

A CertiK project page for Aster indicates an ongoing audit with a final report delivered in July 2026 and a high remediation rate, but no detailed report is publicly available, and the snippet does not specify contract coverage. Another risk listing claims a “CertiK 2025-05-15 pass report” for the ASTER token, again without ALP detail.

Auditor
CertiK
Report date
2025-05-15
Scope
Likely focused on the ASTER token and possibly core protocol contracts; there is no explicit evidence that ALP on BSC was part of the audited set or that its deployed bytecode corresponds to the audited version.[9][15]
Findings
Not verifiable as of 2026-09-04 (no public CertiK report for ALP; third-party listings only summarize that no critical issues were found for the token contract, which may not cover ALP’s yield/strategy contracts).
Fix status
Not verifiable as of 2026-09-04 (remediation percentage is stated for the overall project on CertiK, but ALP-specific fix status is not disclosed).
Evidence (2)

audit

one source

Salus Security — “Astherus - earn” audit report, published September 12, 2024. Corrected detailed record. The report covers EVM-compatible Solidity repository commit edeb7de: Earn.sol, Timelock.sol, WithdrawVault.sol, oft/AssXXX.sol, and oft/TransferLimiter.sol. This is related to Aster’s yield infrastructure; ALP-specific deployed-contract coverage is not established.

Auditor
Salus Security
Report date
2024-09-12
Scope
EVM-compatible Solidity contracts at repository commit edeb7de; Earn.sol, Timelock.sol, WithdrawVault.sol, oft/AssXXX.sol, and oft/TransferLimiter.sol. ALP/BSC deployed-code equivalence not established.
Findings
Critical: n/a under Salus’s severity scale; high: 0; medium: 1 — centralization risk; low: 1 — missing fee-on-transfer token support; informational: 2 — redundant code and floating pragma.
Fix status
Centralization finding marked Mitigated; the report states permissions were reallocated but does not verify deployed multisig/timelock controls. The low and two informational findings were marked Resolved with commits f4b622a, 7fdb462, and 668c0e8. Bytecode match to deployed BSC ALP contracts: Not verifiable as of September 6, 2026.
Report url
https://skynet.certik.com/third-party-audit-reports/jqfm0se0f03r/3cn4rBr34Oe3gP7Lc27Lqj/2ca151f9a174f4a5478680a0b861a2d2/Aster-earn_audit_report_2024-09-12.pdf
Report id
doc:3cfcee5426a86b17
Unresolved high
0
Evidence (2)

audit

one source

PeckShield — “Smart Contract Audit Report for Apollox,” Report #2023-101, published May 10, 2023. The report explicitly states that Apollox V2 trades execute against the ALP pool on BNB Smart Chain. It reviewed repository commit a38e3b5 and checked post-fix commit e56cc7a.

Auditor
PeckShield
Report date
2023-05-10
Scope
Apollox V2 perpetual-contract system; repository commit a38e3b5; ALP pool on BNB Smart Chain explicitly described as the trading liquidity pool.
Findings
Critical: 0; high: 1 — incorrect pair slippage update logic; medium: 2 in the severity summary, including admin-key trust; low: 3 in the severity summary. The report is internally inconsistent: its key-findings table lists one medium and four low findings.
Fix status
Five code findings marked Resolved, with post-fix commits referenced in the report; admin-key trust marked Mitigated, with planned multisig/timelock controls. Bytecode match to current deployed BSC ALP contracts: Not verifiable as of September 6, 2026.
Report url
https://res.apxstatic.com/cloud-futures/static/docs/PeckShield-Audit-Report-Apollox-v1.0.pdf
Report id
doc:7e27c4e03e6cf26f
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Salus Security — “Asterdex - Apx exchange V2” audit report, published June 24, 2025. Covers contracts/ApxExchange.sol at repository commit f5993b7. The report is for the APX exchange component and does not establish coverage of the deployed BSC ALP pool contracts.

Auditor
Salus Security
Report date
2025-06-24
Scope
Solidity repository asterdex/apx-exchange-contract, contracts/ApxExchange.sol at commit f5993b7; EVM-compatible chains.
Findings
Critical: n/a under Salus’s severity scale; high: 0; medium: 0; low: 1 — missing _disableInitializers(); informational: 1 — gas optimization suggestions.
Fix status
Both findings marked Acknowledged; no remediation commit or verification documented. Bytecode match to deployed BSC ALP contracts: Not verifiable as of September 6, 2026.
Report url
https://cert-api.salusec.io/api/v1/salus/contract/certificate/full/2025/Asterdex_Apx-exchange-V2_audit_report_2025-06-24.pdf
Report id
doc:c4586662f4b217f4
Unresolved high
0
Evidence (1)

audit

unverified

Non-primary automated pages exist for unrelated or potentially different Aster-named contracts on BSC, but they are not reliable enough here to use as evidence for the Aster ALP audit record because name-collision cannot be ruled out from the available information.

Auditor
Other/automated sources
Report date
2025-10-26
Scope
Unclear / name-collision risk; not used as authoritative audit evidence.[2][9]
Evidence (2)

audit

two sources

Multiple independent sources state that various Aster contracts, including the USDF stablecoin and asBNB, have been audited by PeckShield. However, none of the retrieved material directly identifies an ALP-specific audit by PeckShield for BSC.

Auditor
PeckShield
Report date
2024-01-01
Scope
Unverified marketing claim that PeckShield audited parts of Aster’s ecosystem (USDF, asBNB, possibly other tokens), but no direct evidence that the ALP yield product/strategy contract on BSC is within that scope or that deployed code matches audited versions.[3][8][10][12][14]
Findings
Not verifiable as of 2026-09-04 (no access to PeckShield’s original PDF reports for any ALP-related contract; third-party writeups only say that audits were completed and do not enumerate findings).
Fix status
Not verifiable as of 2026-09-04 (no public remediation matrix or confirmation that ALP’s deployed bytecode incorporates all recommended fixes).
Evidence (5)

audit

one source

Aster docs list separate audits for AsterVault and AsterEarn, with reports linked from the audit reports section of the documentation site. None of the sources explicitly state an audit dedicated to the ALP yield product smart contracts; ALP is described as part of AsterEarn’s yield offering.

Auditor
Salus Security
Report date
2024-09-01
Scope
Unverified marketing claim that AsterEarn and other core contracts (AsterVault, asBNB, asCAKE) underwent full smart-contract security review; no explicit statement that the deployed ALP contracts on BSC are covered or that bytecode exactly matches the audited versions.[1][3][8][10]
Findings
Not verifiable as of 2026-09-04 (full reports and severity breakdown for ALP-specific contracts are not accessible in retrieved data; available summaries only state that Aster contracts were audited, without enumerating critical/high/medium issues).
Fix status
Not verifiable as of 2026-09-04 (public sources refer to audits being completed and issues addressed in general, but do not confirm remediation status for ALP-related contracts).
Evidence (5)

audit

unverified

Aster’s audit-reports page lists separate audit reports for asBNB and asCAKE by Salus Security, indicating audited components related to the Aster ecosystem on BSC.

Auditor
Salus Security
Report date
2024-09-13
Scope
AstherusVault contract review; the linked Salus PDF states it evaluated repository security, code quality, and best practices, with files in scope including `contracts/AstherusVault.sol` in commit `98606bc`.[8]
Evidence (2)

Team & Reputation

founders

two sources

Aster ALP is part of the Aster DEX ecosystem, whose team structure is only partially disclosed and appears largely pseudonymous, with strong institutional backers but limited traditional corporate transparency. ### Founders & Team

  • Public content references a CEO named “Leonard” and a BD lead “Ember” in an AMA, but no surnames, bios, or verifiable identities are provided.
  • A token listing description states that “the founding team is not publicly identified and its spokespeople are pseudonymous.”
  • The project is described as descending from APX Finance and Astherus, with many team members said to be “past team members from APX and Astherus,” but there is no cross‑linked founder/employee registry or formal org chart.
  • LinkedIn shows Aster as a privately held company with 1–10 employees and a generic description, but no clearly identified founders or C‑suite profiles that can be tied on-chain or via other independent records. ### Backers, Prior Projects & Credibility Signals
  • Multiple posts state Aster is backed by YZi Labs, described as the family office of Binance co‑founders Changpeng Zhao and Yi He, with investment in Aster’s seed round in November 2024.
  • Binance content claims CZ personally tested the platform and publicly endorsed Aster DEX as a “game changer.”
  • Aster is presented as the result of a merger between Astherus (yield protocol) and APX (perp DEX on BNB Chain), which gives it lineage to prior live products but does not, on its own, evidence track record quality (no consolidated record of hacks/incidents, audited outcomes, or formal performance history is provided).
  • Not verifiable as of 2026‑09‑04: whether APX or Astherus suffered major smart‑contract exploits or insolvency events; independent incident databases are not clearly linked. ### Public vs. Anonymous; Office, Jurisdiction, Business Reality
  • The combination of pseudonymous spokespeople, lack of legal entity disclosure on official or third‑party pages, and absence of regulator filings indicates the team is effectively anon/pseudo-anon from an institutional KYC standpoint.
  • No registered office address, country of incorporation, or licensing status is visible in the accessible materials; this fits an offshore / undefined-jurisdiction profile typical of DeFi rather than a regulated onshore broker or exchange.
  • LinkedIn and marketing copy position Aster as a real operating business (live perp DEX with significant TVL), but this is still a web‑front DeFi entity without the transparency expected of a traditional financial institution. ### Reality Check for Institutional Risk
  • Founders are not verifiably identified; corporate structure and jurisdiction not verifiable as of 2026‑09‑04.
  • Positive credibility signals: backing by YZi Labs and public promotion via Binance‑adjacent channels.
  • Negative/neutral signals: no doxxed leadership, no clear office, no regulatory footprint, and limited disclosure on prior project risk outcomes. For an institutional allocator, Aster ALP should be treated as high governance-transparency risk despite strong ecosystem backing, pending independent confirmation of entity, management, and legal status.
Evidence (9)

general reputation

two sources

Aster ALP currently presents as a high‑growth, heavily marketed perps DEX liquidity product with multiple audits and a formal bug bounty, but also with extreme leverage and complexity that warrant institutional caution. No fraud, rug, insolvency, sanctions, or active regulatory actions are reported as of 2026‑09‑04. Protocol & product reputation

  • Aster is a merged entity of Astherus (yield protocol) and APX, a major BNB Chain perp DEX, rebranded in 2025.
  • ALP is the multi‑asset liquidity pool token backing Aster’s on‑chain perps; ALP holders act as market‑making counterparties, with NAV driven by trading PnL, fees, funding and liquidations.
  • Dune’s own blog highlights Aster as a leading perps DEX on BNB Chain with very high reported TVL (~$1.44B) and large volumes, and ALP APY ~25% on BSC, boosting its reputation among DeFi users. Founders / investors
  • Aster is reported to be backed by YZi Labs, described as the family office of Binance co‑founders Changpeng Zhao and Yi He, with seed investment in November 2024 and personal platform testing by CZ. This is a strong *perceived* reputational signal but remains off‑chain and should be independently validated for institutional due diligence.
  • Public founder identities and corporate structure are not detailed in the retrieved docs; this is a gap for KYC/ML assessments. Not verifiable as of 2026‑09‑04. Audits, bug bounty, and security posture
  • Multiple audits are cited: Salus Security (AsterVault, AsterEarn, asBNB, asCAKE), PeckShield (asBNB, USDF), and Halborn (USDF & asUSDF).
  • Aster maintains a bug bounty program on Immunefi; the listing references completed audits and links back to official reports.
  • Third‑party articles and reviews emphasize “security by design,” multi‑auditor coverage, and non‑custodial architecture, but these are still secondary sources, not on‑chain verification. Sentiment, criticisms, and risk concerns
  • Public sentiment in reviews and guides is broadly positive, focusing on capital efficiency, deep ALP liquidity, and “real yield.”
  • No explicit fraud, rug‑pull, or insolvency allegations surfaced; no sanctions or enforcement actions mentioned. Not verifiable as of 2026‑09‑04 from primary regulatory sources.
  • Key unresolved risk concerns for an institutional allocator:
  • Counterparty PnL risk in ALP: LPs bear trader PnL; large directional flows or volatility can materially impair ALP NAV.
  • Extreme leverage (up to 1001x) in Simple mode increases tail‑risk and the chance of non‑intuitive loss profiles for ALP providers.
  • Hybrid architecture (on‑chain settlement + off‑chain matching) and cross‑chain deployment introduce additional operational and smart‑contract risk. Given the strong marketing, very high reported TVL, and complex risk profile, institutions should treat Aster ALP as a high‑risk, reputationally promising but unproven venue pending direct review of audits, legal structure, and on‑chain metrics.
Evidence (15)

Economy

model

one source

Economic model (BSC focus; reviewed September 6, 2026)

  • Strategy/assets: ALP is a multi-asset liquidity token and counterparty to Aster Simple/ALP perpetual markets—not a lending, restaking, or external-farming vault. Users mint with supported pool assets and burn ALP for available underlying assets. The exact current BSC basket, target weights, and asset balances are Not verifiable as of September 6, 2026.
  • Yield source: NAV/APY reflects pool PnL, trading fees, funding fees, liquidations, and other platform fees. Returns accrue through NAV, not a fixed coupon. This is economically directional/short-volatility counterparty exposure, not demonstrably market-neutral: ALP NAV can rise or fall with pool PnL, and the documentation does not disclose a delta-hedging policy.
  • Organic vs subsidized: The documented core yield is trading-economics-based. The former Au-points incentive ended with a June 13, 2025 snapshot. Current ALP-specific emissions, rebates, or subsidy share are Not verifiable as of September 6, 2026; therefore organic_yield_pct is null.
  • Leverage/external exposure: ALP itself is not documented as looping, restaking, or borrowing. It is exposed to leveraged perpetual traders through Simple Mode; underlying product leverage can reach very high levels, but an ALP pool leverage ratio is Not verifiable as of September 6, 2026.
  • Liquidity mechanics: ALP cannot be burned for 48 hours after minting. Burn capacity is capped by pool liquidity and a formula incorporating pool value minus the user’s position exposure; withdrawals in a requested asset cannot exceed that asset’s pool balance.
  • Fees/gates: Mint/burn fees are dynamic and composition-dependent; the current page shows a 0.25% base parameter and 0.05% tax parameter. Contradiction: the same documentation’s worked example refers to a 0.45% tax parameter; exact transaction fees must be checked in the UI.
  • Revenue/collateral: ALP captures trading-related pool income; protocol-level revenue allocation to ALP holders versus treasury/token holders is not separately disclosed.
  • TVL/APY: Dune on-chain TVL, product split, chain split, trend, and APY history are Not verifiable as of September 6, 2026. DeFiLlama reports parent Aster TVL of $765.3m, including $535.13m on BSC (69.9%), +0.4% over 30 days; this is not ALP-specific and should not be treated as ALP TVL. Risk view: variable NAV, trader-PnL/opposite-side risk, liquidity mismatch during stressed withdrawals, dynamic exit fees, and limited transparency on pool composition and historical APY sustainability.
Evidence (4)

reserves

one source

As of September 6, 2026:

  • ALP scope: ALP is a liquidity/market-making pool for Aster Simple Mode. Its NAV reflects pool PnL, trading/funding/liquidation fees, and pool asset values; it is not described as a separate treasury or proof-of-reserves vehicle. ALP minting is supported on BNB Chain and Arbitrum, so a BNB-only assessment is incomplete.
  • Published treasury size/policy: Aster’s tokenomics disclose a Foundation Treasury allocation of 560,000,000 ASTER (7% of the 8B initial supply), intended for strategic growth, operational reserves, and governance. It is stated to remain locked until used through governance-approved mechanisms. This is an allocation disclosure, not a verified current reserve balance.
  • BSC address: Aster’s official contract list identifies 0x128463A60784c4D3f46c23Af3f65Ed859Ba87974 as the BNB Chain Aster Treasury Contract. Explorer evidence confirms ASTER transfers into this address, but does not establish that it contains the full 560M allocation or that it is the sole ALP-reserve address.
  • Composition / balances / NAV: Current token quantities, stablecoin and other asset composition, USD valuation, and ALP pool NAV are Not verifiable as of September 6, 2026. Dune MCP was unavailable in this run, so no Dune query ID/execution ID can be provided; do not treat aggregator dashboards as on-chain verification.
  • Custody and control: The public materials identify treasury contracts but do not disclose a complete custody map, multisig signers, quorum, timelock, or contract-admin thresholds. Independent reporting states that protocol decisions and contract administration currently sit with the core team, while no legal foundation recipient is publicly identified.
  • Liabilities / attestations: No public ALP liabilities schedule, reserve attestation, or independent proof-of-reserves covering ALP was located. Not verifiable as of September 6, 2026. Contradiction / update: Earlier findings said no BSC treasury address was verifiable. That is superseded: an official address is now published. The remaining gap is balance, composition, custody control, and ALP-specific reserve attribution—not address existence.
Evidence (4)

tokenomics

two sources

Scope clarification: Aster ALP is not a native governance token. It is a pool-share/LP receipt token for Aster Simple Mode’s on-chain perpetual liquidity pool. ALP is minted against supported assets and burned for redemption; its NAV varies with pool PnL, trading/funding/liquidation income and fees.

It provides revenue exposure, not voting rights.

  • Ticker/address: ALP. Aster’s public documentation does not provide a verified BNB Chain ALP token contract address. Not verifiable as of September 4, 2026.
  • Supply/valuation: ALP is dynamically issued/redeemed; total supply, circulating supply, market cap and FDV are not published in a verifiable market-data source. Not verifiable as of September 4, 2026.
  • Utility/rewards: LP exposure to the ALP pool and its market-making income; historical Au-point incentives are over. ALP cannot be sold/burned during the first 48 hours after minting. Documented mint/burn fees use a 0.25% base rate plus a dynamic 0.05% weight-deviation adjustment.
  • Governance, emissions, unlocks, allocations: ALP has no stated governance role, team/investor/treasury/community allocation, fixed emissions schedule or vesting/unlock schedule. Announced unlocks and on-chain execution: Not verifiable as of September 4, 2026.
  • Mint/blacklist/fee-switch control: The ALP pool’s privileged administrators, pause controls, blacklist capability and fee-switch authority are not established by the available public sources. Not verifiable as of September 4, 2026.
  • Holder concentration/liquidity/listings: No reliable ALP holder-concentration dataset, DEX liquidity-depth series or principal ALP listings was identified. Not verifiable as of September 4, 2026. Important distinction — Aster’s actual native token: Aster separately has ASTER, BEP-20 contract 0x000Ae314E2A2172a039B26378814C252734f556A, maximum supply 8B. Current market data shows approximately 2.7B circulating, ~$1.98B market cap and ~$5.87B FDV. Official allocations are airdrop 53.5%, ecosystem/community 30%, treasury 7%, team 5%, liquidity/listing 4.5%; revenue buybacks and governance rewards are announced for ASTER, not ALP.
Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 would likely create severe stress for Aster ALP because the pool is the market-maker counterparty for perp trades and its NAV rises or falls with the pool’s overall P&L. In that kind of shock, ALP would likely face a combination of adverse trader flows, higher liquidation activity, and potentially worse realized P&L; however, the exact loss magnitude is Not verifiable as of 2026-09-04 from the available sources. What can be said from the protocol docs is limited: ALP provides liquidity across all trading pairs on Aster perps, ALP holders act as the counterparty to perp trades, and ALP’s NAV moves with the pool’s overall profit and loss.

That means ALP is structurally exposed to market stress, but the docs do not publish a stress-test for BTC below $10,000, a drawdown cap, or downside loss limits. The strongest public evidence of current vulnerability is indirect market commentary: third-party coverage describes Aster as weak in recent price action, but those articles are about the ASTER token, not ALP economics, so they do not verify ALP’s stress loss under a BTC crash. The Binance Square post also discusses ASTER token downside under BTC stress, but it is analysis content, not protocol risk disclosure. Bottom line: a BTC collapse below $10,000 would be a high-stress scenario for Aster ALP, and the direction of impact is clearly negative for pool NAV, but the actual percentage loss, insolvency risk, or recovery capacity is Not verifiable as of 2026-09-04 from the sources available here.

Evidence (5)

stress scenario - largest collateral depegs 20%,

unverified

For Aster ALP, a 20% depeg in the largest collateral would create a direct NAV hit only to the extent that ALP is exposed to that asset; the docs state that ALP NAV is correlated with the pool’s profit and loss, so a collateral loss flows through to ALP price/NAV. However, the exact stress loss is Not verifiable as of 2026-09-04 because the protocol docs provided here do not disclose ALP’s current collateral composition, largest-collateral share, or liquidation/haircut mechanics needed to quantify the impact. What can be said from the available docs is that Aster explicitly warns that yield-bearing collateral can face depeg, redemption delay, and strategy loss.

That means a 20% depeg is a recognized risk factor, but the magnitude of ALP damage depends on whether the depegged asset is in ALP’s backing set and how concentrated that backing is; those inputs are not visible in the supplied sources. If you want a numeric stress result, I would need the current ALP asset breakdown (or an on-chain vault snapshot) and the collateral haircut/LTV rules for each asset.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

Stress case: largest profitable 1001x trader becomes insolvent (BNB Chain). Counterparty identification: The largest trader/position and its share of BNB-chain ALP exposure are Not verifiable as of September 5, 2026 because Dune/on-chain execution is unavailable. In ALP mode, the economically relevant counterparty is the trader cohort: ALP provides liquidity and its NAV reflects pool PnL. Expected loss path 1. Margin exhaustion: The trader’s isolated position reaches its liquidation price.

Mark/oracle pricing, funding, leverage and the platform-defined liquidation-loss rate determine the trigger. 2. Liquidation gap: If execution occurs below the trader’s bankruptcy-equivalent value—or the trader cannot pay a positive balance—the shortfall is an ALP pool loss. Expected loss is approximately: unpaid trader obligation + adverse liquidation slippage − collateral recovered − liquidation/funding fees.

3. Residual loss: The loss reduces ALP pool equity/NAV and therefore the redemption value of every ALP holder. There is no documented principal guarantee or explicit ALP-specific compensation scheme. Who absorbs it / compensation

  • First absorber: ALP LPs collectively through lower NAV; fees, funding and liquidation income provide only partial offset.
  • Insurance fund: Aster documents an insurance fund for Pro mode, including limited negative-balance settlement, but applicability, balance and seniority for ALP/1001x on BNB Chain are Not verifiable as of September 5, 2026.
  • If losses exceed available protections: Aster documents ADL for Pro mode; an ALP-specific ADL or socialized-loss rule is Not verifiable as of September 5, 2026. Smart-contract impact path Trader position → oracle/mark-price liquidation logic → position closure and collateral accounting in the 1001x contract → ALP pool equity/PnL update → lower ALP NAV → constrained redemptions. Burns are limited by pool assets and a stated 50% liquidity/position formula, so a run can create exit delays or in-kind/partial recovery rather than guaranteed USDT payment. Risk conclusion: ALP is effectively senior-unsecured exposure to trader bad debt after collateral and any applicable risk fund; the dominant loss transmission is direct NAV impairment, not a separate insured claim.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

I found no verifiable evidence that the Aster ALP DAO or its owners committed fraud. The available results instead point to separate phishing/scam activity impersonating Aster, which is not evidence of misconduct by the protocol itself. The protocol docs describe ALP staking and reward-claim flows, but those are protocol self-descriptions and do not establish fraud or innocence on their own.

For a stress scenario, the appropriate finding is: fraud by the DAO/owners is not verifiable as of 2026-09-04. The strongest independent items in the results are scam reports about fake Aster pages and malicious signatures targeting users, plus a rumor-denial article about token-dumping allegations; none of these substantiate that the DAO or owners actually committed fraud. I did find a general legal article about DAO member liability in another case, but it is unrelated to Aster ALP and cannot be used as evidence against this protocol.

Evidence (6)

stress scenario - primary yield source negative 30d,

unverified

For Aster ALP on BSC, the primary yield sources are trading P&L, trading fees, funding fees, liquidations, and platform fees; the docs state that all yield is reflected in ALP NAV. In a stress scenario where the primary yield source is negative over 30 days, the protocol’s own documentation implies NAV growth can slow, flatten, or decline because ALP’s value is driven by those yield streams rather than a fixed-rate coupon.

Evidence (2)

Governance & Legal

governance

two sources

As of September 13, 2026, governance is not demonstrably DAO-controlled for BNB Chain Aster ALP. Public disclosures state that protocol decisions currently sit with the core team; no live DAO or active on-chain governance mechanism controlling BNB ALP upgrades, parameters, treasury transfers, frontend deployment, or contract administration is evidenced. Therefore dao_governance=false.

Aster Chain has a Phase 1 validator-driven listing-vote process: proposals use stake-weighted approval plus validator-count approval. This is an Aster Chain mechanism and does not establish control over BNB Chain ALP contracts. No BNB ALP proposal process, executable governance contract, quorum, voting threshold, or execution authority was identified.

Development/frontend/contracts appear operationally core-team controlled, but the legal DevCo, named deployer, proxy admin, pause authority, upgrade authority, governance executor, and treasury controller are not publicly established. The current admin’s ability to drain user funds, any emergency bypass, timelock, multisig threshold, signer set, and signer independence are not verifiable as of September 13, 2026. Top-holder concentration and voting concentration via Dune are also not verifiable as of September 13, 2026 because the required on-chain query access is unavailable; no substitute estimate is provided.

Aster’s Terms identify only “Aster,” not a legal entity, registration number, directors, or jurisdiction. They select Hong Kong law and HKIAC arbitration. The Seychelles regulator states Aster Dex is not a Seychelles-registered company and has no Seychelles nexus.

Accordingly, no company entity or corporate control structure can be confirmed. The DAO is best assessed as symbolic/planned rather than presently controlling BNB ALP.

Dao governance
No
Evidence (4)

legal & regulatory

two sources

Scope: Aster ALP is the yield product of Aster, a BSC-connected platform whose broader offering includes perpetual and spot trading. Aster describes itself as decentralized/non-custodial, but its Terms also reserve unilateral control to monitor use, request identity verification, delay/refuse transfers, and suspend access. This creates meaningful operator/intermediary risk despite the DEX label.

Entity/jurisdiction: The current Terms do not identify a contracting legal entity or incorporation jurisdiction. They select Hong Kong law and Hong Kong-seated HKIAC arbitration. A Google Play listing identifies the developer as ZENITHRA LIMITED, with a Seychelles address, but Seychelles’ FSA expressly states that Aster DEX is not a Seychelles-registered company, has no VASP authorization, and has no Seychelles nexus.

Accordingly, the legal structure is opaque and the Seychelles listing should not be treated as proof of domicile. ToS/restrictions: Users must be 18+, comply with law, and are excluded if located in the United States, Canada, United Kingdom, China, North Korea, Russia, Ukraine, Cuba, Iran, Venezuela, Syria, or comprehensively sanctioned territories. Sanctioned persons and circumvention are prohibited.

The Terms include broad disclaimers, indemnity, liability caps, class-action/jury waivers, and mandatory arbitration. KYC/AML and classification: KYC is discretionary/feature-dependent (“limited identity verification”), not a clearly disclosed universal onboarding regime. No standalone AML policy or regulatory license was verified.

The product set—perpetuals, leveraged trading, and crypto-asset derivatives—creates derivatives/VASP/securities-law exposure depending on jurisdiction; contractual “decentralization” does not eliminate that risk. Warnings/enforcement: France’s AMF placed www.asterdex.com on its crypto-assets-derivatives blacklist on February 27, 2026, stating it offers financial products/services without authorization. Seychelles FSA issued a public statement on November 20, 2025 denying authorization/registration.

This is active regulatory adverse action, not proof of criminal misconduct. Data protection: The Privacy Policy names “Aster” as controller but no legal entity, permits international transfers, third-party processing, legal-authority disclosure, and retention for legal/tax/dispute purposes. GDPR compliance is not independently established.

Court cases: Not verifiable as of September 4, 2026. Sanctions designation: Not verifiable as of September 4, 2026; no protocol/entity designation was identified in the searches performed.

Active enforcement
Yes
Jurisdiction
Hong Kong governing law; legal domicile not disclosed; Seychelles affiliation expressly denied by Seychelles FSA
Evidence (5)

Stability

stability

one source

Aster ALP does not appear to issue its own stablecoin; the protocol’s separate stablecoin product is USDF, while ALP is a liquidity-provider token. Historical depeg events for the stablecoin used with Aster ALP are not verifiable as of 2026-09-06, so depeg_count, last_depeg_date, and max_depeg_pct remain unknown. Public price trackers currently show USDF trading slightly below $1, but that is not enough to verify a historical depeg event count from the available evidence.

Own stablecoin
No
Stablecoin ids
  • USDF
Evidence (3)

Risks & Strengths

risks

two sources

Aster ALP is an on-chain liquidity pool that acts as counterparty to leveraged Simple Mode/1001x traders; its NAV therefore depends on trader PnL, liquidations, oracle integrity, and pool liquidity. The main risk-control weakness is that documented safeguards and historical audits do not independently establish the current deployed BSC implementation or privileged-key configuration. On-chain TVL, ownership, admin topology, and current contract-code comparison: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Leveraged trader lossesALP is the counterparty to leveraged positions. Fast markets, liquidation gaps, adverse funding, or concentrated winning traders can reduce NAV and impair depositor returns.HighMediumFunding rates, position limits, liquidation fees, slippage controls, and stated hedging strategies are used.High loss correlation with market volatility and trader positioning remains.
Smart-contract logic failureA bug in ALP, vault, trading, liquidation, or withdrawal logic could freeze exits or cause asset loss. Published audits do not prove safety of the current deployment.HighMediumHistorical third-party audits and ongoing monitoring are documented.High because current code and deployed BSC contracts are not independently verified here.
Privileged-admin compromiseThe vault audit reports admin powers to change signers and withdraw tokens, creating potential unilateral custody loss or withdrawal censorship.HighMediumThe audit recommended multisig and timelock governance; the team acknowledged this recommendation.High until current multisig, timelock, and role configuration are on-chain verified.
Oracle failure or manipulationIncorrect or stale prices can misvalue ALP NAV, trigger unfair liquidations, or permit under-collateralized withdrawals and trades.HighMediumAster documents Pyth, Chainlink, and Binance Oracle sources plus slippage and funding controls.Medium-High because historical audit findings included stale Chainlink data, and current oracle wiring is unverified.
Liquidity and exit lockALP cannot be burned during the first 48 hours after minting; thereafter, stressed markets or paused withdrawals could delay exits or force realization below expected NAV.MediumHighA documented mint lock, pool risk controls, and withdrawal procedures are in place.Medium-High: liquidity stress and administrative pauses remain possible.
Evidence (5)

strengths

two sources

Top 5 strengths of Aster ALP are: capital efficiency, because the ALP pool provides liquidity across all trading pairs on Aster perps and in Simple Mode; broad market coverage, since that same pool supports all trading pairs rather than a narrow subset; zero-slippage / low-friction execution, which several independent explainers describe as a core ALP benefit for trading execution quality; high leverage accessibility, with Aster’s ALP-based Simple Mode positioned around up to 1001x leverage; and yield-generation for liquidity providers, since ALP is designed as a pool users can stake/mint into to earn rewards.

Evidence (8)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 11 one source, 11 unverified.
  • Oldest fact verification date: 2026-08-29.