ZEROBASE CeDeFi

Green · 73/100

Executive summary

ZEROBASE CeDeFi is a multi-chain stablecoin yield protocol combining on-chain vault contracts with off-chain basis trading/arbitrage through Binance/Ceffu custody, scored 59/100 (orange band) with high data confidence but a -10 penalty for unresolved incident remediation.

  • Security: Six audits by OpenZeppelin, Salus, and PeckShield covering vault, token, and staking contracts; no unresolved critical/high findings, but medium-severity admin-key trust and supply-cap issues were only partially mitigated via multisig (signer details unverified); bytecode matching to deployed contracts across six chains (Arbitrum, BSC, Base, Ethereum, OP, Polygon) remains unverified as of September 2026.
  • Incidents: December 2025 BSC phishing/frontend compromise affected 270+ wallets with ~$250k loss; malicious approvals were blacklisted and deposits/withdrawals auto-blocked for affected users, but fund recovery and reimbursement status remain unverified; remediation is incomplete.
  • Governance & custody: Operated by Vortex Tech Ltd. (Cayman Islands, LEI 8755005ACR10IAZXKF10); DAO governance via Snapshot is procedural and does not control contracts, funds, or legal entity; vault admin holds emergencyWithdraw powers (can drain idle tokens) and pause authority, mitigated only by unverified multisig; user deposits flow to Ceffu custody and Binance for funding-rate arbitrage, creating concentrated counterparty exposure.
  • Top risks: (1) CeFi counterparty failure—Ceffu/Binance insolvency, withdrawal freeze, or regulatory action could impair principal and yield with no insurance or guaranteed recovery; (2) privileged-admin compromise—unverified multisig controlling drain/pause functions; (3) prolonged negative funding rates (>30 days) can erode yield to zero and force lossy unwinds with estimated 5–15% drawdowns; (4) stablecoin (USDT/USDC) issuer freeze or depeg; (5) cross-chain/operational complexity with unverified deployment status.
  • Strengths: ZK proofs verify strategy constraints (leverage, hedging) without exposing positions; multi-chain presence (six EVM chains) with $62.5M TVL; institutional/compliance positioning with privacy-preserving design; clear basis-trading value proposition for stablecoin yield; fast proof generation and low costs claimed.
  • Unverified: On-chain bytecode matching, multisig signer identities/threshold, reserve composition and custody addresses, largest counterparty exposure by dollar amount, actual 30-day drawdown history, incident fund recovery, DAO treasury control, and whether all chains use audited code.
  • Recommended exposure: Limit to <2% of portfolio as satellite/opportunistic allocation; treat as high-counterparty-risk CeFi product despite on-chain wrapper; size for total-loss tolerance given Ceffu/Binance concentration, unverified admin keys, and incomplete incident remediation; avoid during periods of persistently negative BTC/ETH perpetual funding or broader CEX stress; require independent verification of multisig signers, reserve addresses, and bytecode before larger commitment.
  • Open questions: (1) Verify multisig signer identities, threshold, and timelock on-chain for vault admin and treasury; (2) confirm bytecode of deployed vaults on all six chains matches audited commits; (3) obtain independent attestation of Ceffu/Binance custody balances and MirrorX segregation; (4) clarify December 2025 incident: total recovered amount, reimbursement plan, and permanent remediation status; (5) verify DAO treasury address, current balance, and governance execution authority; (6) assess actual 30-day yield volatility and worst-case drawdown during negative funding periods; (7) confirm legal recourse and liability cap enforceability under Cayman law for U.S./EU allocators.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 11 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 100 20.0 full audit within 365 days (latest 2026-01-15)
Incidents 20% 100 20.0 1 open incident(s), $250,000 at risk = 0.4% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $62,732,853 = 0% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 19/50 verified facts; 49/50 fresh (180d)

Identification

protocol identification

two sources

ZEROBASE CeDeFi is a multi-chain CeDeFi/basis-trading yield protocol built on top of the ZEROBASE ZK infrastructure network, offering stablecoin staking with off-chain arbitrage strategies and ZK attestation of activity on centralized exchanges. Identification

  • Name: ZEROBASE CeDeFi (often branded simply ZEROBASE).
  • Website / App: Main site at a zerobase.pro domain; CeDeFi yield product appears as “zkStaking / ProofYield” style stablecoin staking.
  • Docs: Not clearly surfaced in independent sources; detailed technical docs are Not verifiable as of 2026-09-04.
  • Category: Basis trading / CeDeFi stablecoin yield protocol, using ZK proofs plus centralized exchange (Binance) arbitrage strategies.
  • Launch timing: External articles and exchange listings place the ZBT token debut around October 2025, and CeDeFi staking in beta with TVL >$300k and total staking >$55m by early 2026. Precise protocol launch block/date is Not verifiable as of 2026-09-04.
  • Supported chains (for CeDeFi pools): Independent yield aggregators show pools on Base, Arbitrum, BNB Chain, Ethereum, Optimism, Polygon, totaling 6 chains.
  • Native token: ZBT (ZEROBASE Token) – infrastructure/governance token for the prover network, primarily issued on BNB Chain (BSC). Token & contract references (cross-checked without on-chain tools)
  • ZBT main contract (BNB Chain): Multiple independent sources give 0xfab99fcf605fd8f4593edb70a43ba56542777777 as the ZBT contract on BSC. CertiK’s token scan and an exchange-oriented wiki both reference this address, providing ≥2-source confirmation. Explorer verification status for this contract is Not verifiable as of 2026-09-04 from current data.
  • Other tickers (e.g., ZB on BSC) appear in price-trackers, but these look like separate/legacy contracts and not the current infrastructure token.
  • Main CeDeFi pool contracts per chain (Arbitrum, Base, BSC, Ethereum, OP, Polygon) are Not verifiable as of 2026-09-04; independent tools do not list specific staking contract addresses. Fork lineage / code provenance
  • Public descriptions frame ZEROBASE as a bespoke ZK infrastructure plus CeDeFi staking design, not as a fork of a known DeFi protocol (e.g., Aave, GMX, etc.). No independent source identifies a clear upstream fork.
  • The CeDeFi product uses zero-knowledge proofs + TEEs to attest Binance basis-trading strategies, which is functionally distinct from typical on-chain-only yield protocols.
  • Audits: CertiK provides a token security scan for ZBT but this is not a full protocol audit. No publicly cited, independent smart-contract audits of the CeDeFi pool contracts are visible; therefore Not verifiable as of 2026-09-04.
  • Malicious-modification history / exploit lineage: No independent reports of ZEROBASE CeDeFi being a malicious fork or suffering fork-related code tampering were found; any such history is Not verifiable as of 2026-09-04. Given missing on-chain querying, all contract- and chain-specific implementation details should be treated as aggregator-only, not on-chain verified at this stage.
Evidence (15)

maturity

two sources

ZEROBASE CeDeFi appears to have a live product site and separate documentation, not just a static landing page: the main site is an active portal, the docs include an API section, and a proof/network interface is exposed on a dedicated subdomain. The documentation and third-party yield pages indicate an operational staking/yield product across multiple chains, but live deposits/withdrawals, full app UX quality, and whether all flows are actually functioning at present are not verifiable as of 2026-09-04 from the available sources. The clearest maturity signals are:

  • Real portal: the main site and docs are live, and the docs describe product mechanics and API integration rather than only marketing copy.
  • App/API presence: docs reference proof-generation requests, gRPC usage, and API endpoints, which indicates an exposed technical interface.
  • Multi-chain product footprint: an external yield aggregator tracks ZEROBASE CeDeFi across six chains (Ethereum, Polygon, Arbitrum, Base, BSC, Optimism), suggesting the protocol is not a single-page mockup. Open API: yes, an API is documented publicly in the docs, including endpoint examples and gRPC integration details. What is not verifiable as of 2026-09-04:
  • Whether deposits and withdrawals are currently live on every listed chain.
  • Whether the front-end has broken links, template artifacts, or fake metrics.
  • Whether the documented API is production-stable versus partially intended for developers only. No trustworthy source in the gathered set proves fake metrics or a template clone, but that absence is not confirmation.
Evidence (4)

Security

bug bounty

one source

Not verifiable as of 2026-09-04. The web result set did not confirm a bug bounty program for ZEROBASE CeDeFi; the only relevant hits were a possible marketing site for the protocol and unrelated/likely mismatched pages, so no trustworthy start date, scope, payout ladder, or disclosed results could be established. A third-party article even states there is no active bug bounty program for critical infrastructure, but that is not sufficient to confirm the program status for this protocol.

Evidence (2)

counterparty risks

two sources

Assessment: High counterparty concentration; material off-chain dependency remains unchanged. ZEROBASE documentation and the public ZKFi repository state that user USDC/USDT deposits are transferred to Ceffu (Binance Custody) and mirrored to Binance through MirrorX for funding-rate/arbitrage strategies. This creates concentrated exposure to Ceffu custody, Binance exchange and futures-market operations, withdrawal freezes, sanctions/compliance actions, liquidation, trading losses, operational failure and insolvency. MirrorX improves asset segregation but does not eliminate counterparty risk: Ceffu’s terms contemplate Binance insolvency, account freezes exceeding 14 days, write-downs or unavailable assets, with recovery limited to the final balance recognized by Binance; any shortfall remains a claim against the Binance operator.

ZEROBASE’s ZK proofs validate stated strategy constraints, not independent ownership, reserve sufficiency, exchange balances, trade execution, Ceffu/Binance solvency or recoverability. Stablecoin exposure: USDC and USDT are the identified deposit assets; failure, issuer freeze, blacklist, depeg or liquidity impairment can impair withdrawals and NAV. The protocol’s terms expressly disclaim responsibility for stablecoin issuers, custodians, exchanges, bridges, oracles and other third parties. Bridges/oracles/LST/restaking/RWA: No named bridge, oracle, LST, restaking protocol, RWA issuer/SPV or independent market maker was verifiable as of September 6, 2026. The whitepaper contains general statements about evaluating oracles/bridges and a roadmap reference to RWA scenarios, but these are not evidence of current deployed exposure. Not verifiable as of September 6, 2026. Multi-chain concentration: DeFiLlama reports approximately $62.75m TVL across BSC, Ethereum, Base, Arbitrum, OP Mainnet, Polygon and Avalanche; the user-specified six-chain scope excludes Avalanche.

This is aggregator data, not on-chain verified, and no reliable chain-by-chain counterparty exposure split is available. Not verifiable as of September 6, 2026. Failure scenarios: Ceffu/Binance freeze or insolvency; exchange liquidation or strategy loss; USDC/USDT depeg or blacklist; delayed seven-day redemptions; insufficient vault liquidity; bridge/oracle failure if later deployed; or smart-contract/admin failure. The July 2026 terms expressly state that withdrawals may be delayed or unavailable and assets are not insured. Contradiction / data gap: The app displays $54.82m total stake on BNB Chain, while DeFiLlama reports $62.75m aggregate TVL including seven chains. The figures have different scope and are not reconciled by raw on-chain verification. Not verifiable as of September 6, 2026. Dune MCP was unavailable; on-chain balances, transfers, exposure percentages and active-failure status were not verified.

Evidence (5)

crypto custody

one source

ZEROBASE CeDeFi custody is organized in a centralized way rather than as user self-custody. ZEROBASE docs say user deposits into the vault are automatically transferred to a custodial account and then allocated across liquidity strategies, and the white paper says participant funds are collected through a distribution platform such as Binance, which applies its own KYC/custody controls and does not directly custody the proceeds. Independent coverage also describes the staking flow as using centralized custody and exchange-linked execution, but this remains web-verified rather than on-chain verified.

Withdrawal_paused is not verifiable as of 2026-09-06. Segregated_assets is not verifiable as of 2026-09-06; the available sources describe custodial handling but do not clearly establish legally or operationally segregated customer asset accounts.

Evidence (3)

incident

two sources

On December 12, 2025, a BSC/BNB Chain phishing incident used a malicious contract impersonating the ZEROBASE staking interface. Public reporting described this as a frontend compromise or traffic-hijacking issue involving an external middleware provider, rather than an exploit of ZEROBASE’s core staking contracts. More than 270 user wallets were affected; reported losses exceeded $240,000 USDT and are commonly rounded to $250,000.

The largest reported individual loss was approximately $123,597 USDT. ZEROBASE implemented malicious-approval detection, blacklisted the malicious contract, and automatically blocked deposits and withdrawals for wallets that had interacted with it until users revoked approvals. Users were directed to revoke approvals through revoke.cash or equivalent tools.

No later public evidence was found confirming a completed permanent fix, recovery of funds, or reimbursement program. Recovered amount and reimbursement status: Not verifiable as of September 6, 2026. Current status: remediation_in_progress.

Characterization note: public sources differ between “frontend hack/compromise” and “third-party middleware vulnerability,” but agree the core staking contracts were not reported as exploited.

Date
2025-12-12
Cause
Frontend / infrastructure hack
Loss
$250K
Attacker proceeds
$250K
Status
remediation in progress
Event id
zerobase-bsc-2025-12-12
Evidence (4)

key management

unverified

ZEROBASE’s key management is organized around a TEE-based trust model rather than a fully public key-handling system. According to the docs, provers run inside AMD SEV enclaves, where the hypervisor cannot access the memory encryption keys; the SEV firmware inside AMD-SP exposes a secure key-management interface, and during migration it transmits the memory encryption key only after the destination platform is authenticated. The whitepaper says ZEROBASE combines off-chain TEEs with on-chain ZKPs, so sensitive execution and cryptographic handling happen inside the TEE while proofs make outcomes verifiable on-chain.

For the CeDeFi side, the publicly available materials describe a vault-and-node structure: staked funds go into a vault, prover nodes must stake stablecoins as collateral, and HUB nodes route work while Prover nodes generate proofs. That means operational control is split between the vault/custody layer and the proving network, but the exact signing-key workflow for user funds, multi-sig setup, or who controls treasury keys is Not verifiable as of 2026-09-04 from the available sources. In short, ZEROBASE appears to keep hardware-encrypted enclave keys inside TEEs for proof generation and migration, while broader protocol custody and treasury key governance are not clearly documented in the sources provided.

Evidence (5)

smart-contract

two sources

Assessment date: September 6, 2026. High admin/key risk; deployment-specific verification remains incomplete. Addresses / verification. The project repository publishes V1 Vault 0x59f6E226a1055D05a9BD07f40AC2aa87e303CC33 for Ethereum, BSC, Polygon and Arbitrum; the same address is source-verified as Vault on Etherscan and is heuristically flagged as possibly proxy-related. The repository’s V2 address field is blank, despite listing OP Mainnet and Base. Current chain-by-chain deployment, implementation, proxy-admin, and bytecode matching: Not verifiable as of September 6, 2026. Privileged functions. The PeckShield-reviewed Vault gives DEFAULT_ADMIN_ROLE an emergencyWithdraw(token, receiver) function that transfers the contract’s entire balance of any ERC-20 to an arbitrary receiver; PAUSER_ROLE can pause/unpause.

Therefore, if the reviewed authority model is live, a compromised admin/multisig can drain idle Vault-held tokens and freeze staking operations. PeckShield classified this as a medium-severity admin-key trust issue and said mitigation was use of a multisig; signer threshold, signers, and current role holders are Not verifiable as of September 6, 2026. Upgradeability, roles, timelock, oracle/strategy/fee controls. Proxy architecture, implementation slot, proxy-admin type, upgrade functions, timelock delay measured on-chain, role renunciation, oracle setters, strategy controls, fee setters, and current emergency permissions: Not verifiable as of September 6, 2026. No Dune query/execution evidence is available in this run.

The terms explicitly contemplate admin, upgrade, pause, allowlist, parameter-management, withdrawal-queue and compliance-freeze powers. Exit / worst case. The repository describes automated emergency withdrawal in V2 with a 0.5% fee, but V2 deployment is not identified; whether users can exit directly without admin on each supplied chain is Not verifiable as of September 6, 2026. Worst case: admin key compromise drains Vault balances, changes operational parameters or pauses exits; custodian/strategy/bridge failure can additionally impair redemption. Architecture: User → Vault/LP token → strategy/custodian/CEFFU → returns → Vault → user; admin roles sit across Vault controls. Contradiction: claimed multi-chain V2 support conflicts with the repository’s blank V2 address field; the gap is unresolved.

Fields reflect current-deployment uncertainty, not the reviewed source alone.

Admin can drain
Yes
Evidence (4)

audit

one source

Previously recorded report; remediation statuses rechecked.

Auditor
OpenZeppelin Security
Report date
2025-09-08
Scope
Economics repository commit 3c55c3f; ZEROBASE.sol and LayerZero deployment/configuration scripts
Findings
Critical: 0; High: 0; Medium: 0; Low: 3; Notes: 10.
Fix status
10 issues resolved and 2 partially resolved; one low issue and one note remained partially resolved.
Report url
https://www.openzeppelin.com/news/zerobase-token-audit
Report id
doc:3595924ba5405373
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published audit; remediation statuses verified from the report.

Auditor
Salus Security
Report date
2025-09-16
Scope
ZeroBase V2; ZKFi repository, commit 3391353; Vault, WithdrawVault, interfaces, utilities and zkToken
Findings
Critical: 0; High: 0; Medium: 0; Low: 3; Informational: 2.
Fix status
All three low and two informational findings were acknowledged, not marked resolved.
Report url
https://cert-api.salusec.io/api/v1/salus/contract/certificate/full/2025/ZeroBase_V2_audit_report_2025-09-16.pdf
Report id
doc:83e1c9cd5458b91e
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Previously recorded report; finding statuses rechecked.

Auditor
Salus Security
Report date
2025-09-17
Scope
ZEROBASE ZBT v2; Economics repository, src/ZEROBASE.sol, commit cdb2a73
Findings
Critical: 0; High: 0; Medium: 1; Low: 1; Informational: 4.
Fix status
Medium supply-cap bypass resolved in commit be1bedd. Low and all informational findings acknowledged.
Report url
https://cert-api.salusec.io/api/v1/salus/contract/certificate/full/2025/ZEROBASE-ZBT_audit_report_2025-09-17.pdf
Report id
doc:91b2598c549eaf67
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Previously recorded report; remediation statuses rechecked.

Auditor
Salus Security
Report date
2024-12-24
Scope
ZeroBase Vault v1; Vault.sol and utils.sol; commit acc403f; reported address 0x59f6e226a1055d05a9bd07f40ac2aa87e303cc33
Findings
Critical: 0; High: 0; Medium: 1; Low: 0; Informational: 1.
Fix status
Medium centralization finding mitigated through multisig administration; floating-pragma informational finding resolved in commit 05d5a9f.
Report url
https://cert-api.salusec.io/api/v1/salus/contract/certificate/full/2024/ZeroBase_report_2024-12-24.pdf
Report id
doc:a39208904b534d7b
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Previously recorded report; finding statuses rechecked.

Auditor
PeckShield
Report date
2025-02-24
Scope
Zerobase Staking ZKFi repository commit 564867b; contracts under V2/src
Findings
Critical: 0; High: 0; Medium: 3; Low: 0.
Fix status
PVE-001 confirmed and tolerated; PVE-002 resolved; PVE-003 mitigated with multisig admin.
Report url
https://skynet.certik.com/third-party-audit-reports/jqfm0se0f03r/1gXCwcO7V2CJlaS6yAsTxa/93109f83e825f7299ef08585bf910220/PeckShield-Audit-Report-ZKFI-v1.0.pdf
Report id
doc:a9315f18a3da026f
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published audit; corrected publication/remediation record.

Auditor
OpenZeppelin Security
Report date
2026-01-15
Scope
ZeroBase-Pro/ZKFi commit 3413ed5; claim/src/ClaimVault.sol
Findings
Critical: 0; High: 0; Medium: 1; Low: 1; Notes: 8.
Fix status
All 10 issues resolved, including the medium cross-contract signature-replay issue; all 8 notes resolved.
Report url
https://www.openzeppelin.com/news/claimvault-security-audit-1
Report id
doc:f40965ee36649aca
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

OpenZeppelin audited a ZeroBase token / cross‑chain economics codebase. The public summary states audit type cross-chain, language Solidity, timeline Aug 6 2025 → Aug 6 2025. Scope: the ZeroBase-Pro/Economics repository at commit 3c55c3f; the set of in‑scope files is listed in the report.

Findings summary: total 13 issues (10 resolved, 2 partially resolved), with severity split: 0 critical, 0 high, 0 medium, 3 low (2 resolved, 1 partially resolved); plus 10 notes (8 resolved, 1 partially resolved). By OpenZeppelin’s own summary, all significant severity levels (critical, high, medium) are absent, but several low‑severity and informational issues remain only partially remediated. This audit focuses on the token/economics code, not explicitly on the vault contracts that hold user assets on Arbitrum, BSC, Base, Ethereum, OP, Polygon.

Whether all current token/economic contracts on those chains match the audited 3c55c3f commit is Not verifiable as of 2026-08-29 without bytecode comparison.

Auditor
OpenZeppelin
Report date
2025-08-06
Scope
ZeroBase-Pro/Economics repository at commit 3c55c3f (cross‑chain token/economics contracts) audited by OpenZeppelin.[4]
Evidence (1)

audit

one source

Security audit of ZeroBase‑Pro/ZKFi (ClaimVault / ZKFi component).

Auditor
OpenZeppelin
Report date
2025-10-31
Scope
ZeroBase‑Pro/ZKFi repository at commit 3413ed5; DeFi smart contract (ClaimVault‑related) with specified file(s) in scope.[14] Bytecode-match vs deployed contracts: Not verifiable as of 2026-09-04.
Findings
Total issues 10, all resolved; severities: 0 critical, 0 high, 1 medium, 1 low, remaining informational/notes.[14]
Fix status
All 10 issues reported as resolved in the audit summary.[14]
Evidence (1)

audit

one source

ZeroBase - Vault v1 Solidity audit.

Auditor
Salus
Report date
2024-12-24
Scope
ZeroBase - Vault v1, Solidity contracts at commit acc403f; appendix lists files and SHA-1 hashes.[12] Bytecode-match vs deployed contracts: Not verifiable as of 2026-09-04.
Findings
0 critical, 0 high, 1 medium, 0 low, 1 informational.[12]
Fix status
Medium and informational issues discussed; detailed resolution status per issue not fully visible in snippet.[12]
Evidence (1)

audit

two sources

ZeroBase - V2 Solidity audit.

Auditor
Salus
Report date
2025-09-16
Scope
ZeroBase - V2, Solidity contracts; scope defined in Appendix 1 referencing GitHub repo ZeroBase-Pro/ZKFi.[5] Bytecode-match vs deployed contracts: Not verifiable as of 2026-09-04.
Findings
0 critical, 0 high, 0 medium, 3 low, 2 informational (total 5 issues). Example listed: a low‑severity “Centralization risk”.[5]
Fix status
Per summary, issues identified with recommendations; explicit per‑issue fix status not present in snippet, overall remediation Not verifiable as of 2026-09-04.[5]
Evidence (2)

audit

one source

ZEROBASE - ZBT v2 Solidity audit.

Auditor
Salus
Report date
2025-09-17
Scope
ZEROBASE - ZBT v2, EVM‑compatible chains, Solidity contracts in ZeroBase-Pro/Economics repository at commit cdb2a73; files in scope listed in Appendix 1.[10] Bytecode-match vs deployed contracts: Not verifiable as of 2026-09-04.
Findings
0 critical, 0 high, 1 medium, 1 low, 4 informational (total 6 issues).[10]
Fix status
Audit notes objectives and lists issues; specific confirmation that medium/low issues have been fully fixed Not verifiable as of 2026-09-04.[10]
Evidence (1)

audit

unverified

The MiCA White Paper states that zkStaking v1 and v2 were audited by PeckShield and Salus, and the ZEROBASE token by OpenZeppelin and Salus, with no critical vulnerabilities identified.

Auditor
Unknown / project claim
Report date
2026-08-10
Scope
zkStaking v1, zkStaking v2, and ZEROBASE Token (ZBT).
Findings
Claimed: no critical vulnerabilities; minor and medium-level findings were fully addressed prior to deployment.
Fix status
Unverified marketing claim; not independently confirmed in the gathered evidence.
Evidence (1)

Team & Reputation

founders

two sources

Available public information on ZEROBASE CeDeFi’s founders and team is extremely limited and largely absent from independent sources. As of 2026‑09‑04, key aspects of its corporate reality are Not verifiable as of 2026‑09‑04. ### Founders & Team

  • None of the main aggregators tracking ZEROBASE CeDeFi (DeFiLlama protocol page, yield aggregators, analytics listings) provide named founders, core team members, or prior project histories.
  • The public-facing description focuses on the product (zk‑powered stablecoin staking, basis trading on Binance, “infrastructure network” with ZBT token) rather than individuals.
  • No independent media profiles, LinkedIn‑verified identities, or doxxed founders tied to the protocol could be confirmed. Not verifiable as of 2026‑09‑04. ### Public vs. Anonymous; Credibility
  • Given the absence of verifiable real‑name founders or a documented leadership team in independent sources, ZEROBASE CeDeFi should be treated as effectively anonymous / pseudonymous from a risk‑analysis standpoint.
  • Risk‑focused commentary (e.g., Hindenrank’s safety/risk analysis) discusses mechanisms and basis‑trading exposure but does not identify individuals or corporate entities behind the protocol.
  • Trackers describing ZEROBASE as a “crypto infrastructure project” or “zk‑powered staking” again omit any governance or ownership detail. ### Corporate Reality (office, jurisdiction, business substance)
  • No independently verified registered company name, jurisdiction, or physical office address associated with ZEROBASE CeDeFi could be found in analytics listings or third‑party write‑ups.
  • Marketing descriptions reference “institutional DeFi”, “compliance‑aligned staking” and interaction with Binance for arbitrage strategies, but these are unverified marketing claims unless backed by filings or audits, which are not visible in current independent data.
  • Onshore vs. offshore status, licensing, or regulatory registrations are Not verifiable as of 2026‑09‑04. ### Prior Projects / Hacks / Track Record
  • No confirmed prior projects, earlier protocols, or associated hacks involving named ZEROBASE founders are documented in the sources consulted.
  • There is no independently verified incident history (e.g., public exploit reports linked to the team) in the visible analytics and commentary. Not verifiable as of 2026‑09‑04. ### Reality Check
  • From an institutional risk lens, ZEROBASE CeDeFi currently presents as a web‑front protocol with opaque ownership and corporate structure, marketed as a zk‑based basis‑trading / yield infrastructure, without independently verifiable founders, office, or legal entity.
  • This opacity should be treated as a material governance and counterparty‑risk factor in any institutional exposure framework.
Evidence (13)

general reputation

two sources

ZEROBASE CeDeFi appears to have a generally positive but still *marketing-heavy* reputation: public materials and third-party profiles describe it as a ZK-based stablecoin yield/“basis trading” protocol, and independent coverage reports a $5M seed round with backers including Binance Labs/YZi Labs, Lightspeed Faction, dao5, IDG, Matrix Partners, and Symbolic Capital. Reported leadership includes Mirror Tang/Xueyan Tang (CEO/co-founder), with Shawn Chong also described as a co-founder; some profiles also name Koppany Smith as COO. The main auditor signal found is OpenZeppelin, while Salus-hosted certificates and a PeckShield/CertiK-hosted audit record also appear in public search results, but those sources should be treated as audit artifacts rather than proof of current security.

I did not find credible evidence of fraud, rug-pull, insolvency, sanctions, or active legal/regulatory enforcement specific to ZEROBASE CeDeFi in the retrieved sources. However, unresolved concerns remain: the protocol’s own and partner-published materials emphasize compliance and privacy-tech positioning, which is an area of regulatory sensitivity; the publicly visible reputation is still dominated by sponsored/partner announcements rather than deep independent technical analysis. A third-party risk blog labeled the protocol “moderate risk” / “Grade C,” but that is only one opinion and not a formal audit or regulatory finding.

On-chain exposure across the listed chains is not verifiable as of 2026-09-04 because on-chain checks were unavailable in this run; therefore I cannot confirm TVL, treasury, or chain split from raw chain data.

Evidence (5)

Economy

TVL: $62.7M

model

one source

Assessment (as of September 6, 2026; Dune unavailable).

  • Strategy/assets in: Users deposit primarily USDT/USDC and receive LP tokens representing vault equity. ZEROBASE claims returns derive mainly from Binance funding-rate/basis arbitrage through Ceffu/MirrorX, supplemented by hedge-fund strategies and ZK-proof service fees. These are unverified marketing claims; positions, counterparties, P&L and proof outputs were not independently verified.
  • Risk profile: Intended to be market-neutral/delta-neutral rather than directional. However, exposure is materially external: custodian/exchange, hedge-fund/operator, stablecoin and operational/counterparty risks remain. The terms explicitly disclaim guaranteed yield and solvency.
  • Leverage/looping/restaking: LP tokens may be pledged to borrow USDT/USDC up to a claimed 95% loan-to-value; the strategy documentation claims leverage of no more than 3×. Exact realized leverage and user-level looping are unknown. Restaking: Not verifiable as of September 6, 2026.
  • Lock-up/withdrawals: Standard withdrawal requires a 7-day redemption period and is described as fee-free; “Flash Withdraw” is claimed to be immediate with a 0.5% fee, subject to deposit-contract liquidity. Terms additionally allow queues, delays, compliance restrictions and third-party constraints.
  • Fees/gates/limits: Fees may include protocol, strategy, performance, custody, trading and withdrawal charges; exact schedule is not fully disclosed. U.S. persons are expressly restricted, with screening/KYC and transaction-blocking powers.
  • Protocol revenue: Claimed ZK-service fees and potentially strategy-related fees; actual revenue is Not verifiable as of September 6, 2026.
  • TVL: DeFiLlama reports $52.88m, but this is stale data (page crawl three weeks ago): BSC $21.21m (40.1%), Ethereum $14.48m (27.4%), Arbitrum $8.42m (15.9%), OP $8.10m (15.3%), Polygon $0.63m (1.2%), Base $0.043m (0.08%), and Avalanche $0.006m (0.01%). It reports a 3.4% 30-day decline and 8.54% average APY across nine pools. Contradiction: User supplied six chains, but DeFiLlama lists seven, including Avalanche. Dune-vs-DeFiLlama TVL, product-level TVL, APY history/volatility and sustainability: Not verifiable as of September 6, 2026. Fields: organic_yield_pct: null; leverage_ratio: null.
Evidence (3)

reserves

two sources

Status as of September 6, 2026: Reserve size, liabilities, reserve addresses, asset composition, custody arrangements, and independently verified balances are Not verifiable as of 2026-09-06. Dune on-chain verification was unavailable in this run; no on-chain balances or query/ execution IDs are therefore reported. Protocol disclosures: The October 2025 MiCA whitepaper claims Vortex Tech Ltd. held approximately 10 million USDT equivalent in treasury as of Q4 2025, plus a reserve of ZBT tokens. This is an unverified marketing claim: no reserve address, wallet statement, attestation, auditor confirmation, or independently verifiable composition was located.

ZEROBASE’s economic-model documentation states that 20% of network revenue is allocated to the ZEROBASE Foundation and the remainder to the ZEROBASE DAO treasury; governance may authorize ZBT buybacks and burns. This describes a policy framework, not a current reserve balance. A DAO proposal refers to a “ZEROBASE DAO Treasury multisig” and says purchases should be reported on-chain, but the proposal does not disclose the multisig address or provide executed transaction evidence.

Control, signer set, quorum, and timelock are therefore Not verifiable as of 2026-09-06. The project’s public GitHub identifies 0x59f6E226a1055D05a9BD07f40AC2aa87e303CC33 as a staking Vault address across supported chains. It is not identified as the treasury, and its balances cannot be treated as treasury reserves without chain-level verification. Contradiction / data-quality finding: Third-party analytics report approximately $62.8M TVL, while the protocol’s claimed corporate treasury is approximately $10M.

TVL is user or vault capital, not treasury equity or liquid reserves; the figures are not interchangeable. Liabilities: No public liability schedule, redemption obligation, debt statement, or reserve-liability reconciliation was found: Not verifiable as of 2026-09-06.

Evidence (5)

tokenomics

two sources

ZEROBASE has a native token: ZEROBASE (ZBT), an omnichain ERC-20/OFT. Canonical address: 0xfab99fcf605fd8f4593edb70a43ba56542777777 (verified on Ethereum; CoinGecko shows the same address on Base and BNB Chain). Supply and valuation (analytics, not on-chain verification): Total/max supply is 1,000,000,000 ZBT.

CoinGecko reports ~322.917M circulating, ~$27.1M market cap, and ~$83.8M FDV at its latest crawl. Contradiction: the published allocation table implies different release buckets than CoinGecko’s circulating-supply methodology; the discrepancy is unresolved. Utility/governance: ZBT is intended for network-service payments, node incentives, and protocol-parameter governance. HUB nodes receive ZBT emissions; proving nodes may receive ZBT or stablecoins.

Governance is described as procedural and does not confer equity, dividends, or revenue ownership. Revenue, buybacks, burns: Documentation proposes allocating 20% of network revenue to the Foundation, with remaining income to the DAO treasury; DAO-approved buybacks may be burned. A November 2025 governance proposal authorized buybacks using instant-withdrawal fees and treasury liquidity, but execution/burn completion is Not verifiable as of September 4, 2026 without on-chain querying.

Emissions/unlocks/allocation: Team/advisors 20% (1-year cliff + 48-month linear); investors 11.25% (1-year cliff + 24-month linear); liquidity 2% TGE; ecological fund 15% TGE; airdrop/early adopters 8% (5% TGE, 3% next month); node stake 43.75% linear from one month post-TGE. Whether announced unlocks actually occurred is Not verifiable as of September 4, 2026. Control and concentration: The verified ABI exposes mint, setMinter, whitelist controls, transfer-timing controls, LayerZero peer/configuration setters, and owner; OpenZeppelin identifies the owner as the privileged administrator.

No blacklist or fee-setting function is evident in the reviewed ABI. Current owner/minter identities, top-holder concentration, insider wallets, and allocation-wallet behavior are Not verifiable as of September 4, 2026. Liquidity/listings: Main reported listings include Binance, LBank, MEXC, Bitget, and KuCoin.

Latest surfaced CEX ±2% depth was roughly $104k/$108k on Binance and $78k/$14k on Bitget; DEX depth data is stale/not comprehensive.

Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 would be a severe risk-off shock for ZEROBASE CeDeFi because the protocol’s economics depend on market structure and yield conditions that can deteriorate sharply in crypto stress. However, the protocol-specific downside channel is not verifiable as of 2026-09-04 from the available sources, so the impact must be treated as a scenario-based risk assessment rather than a measured on-chain estimate. The most relevant stress mechanism in the retrieved material is prolonged negative funding-rate erosion: when BTC/ETH perpetual funding stays negative for an extended period, basis-trading-style yields can fall to zero or turn negative, staker withdrawals can rise, and forced unwinds can create slippage and capital loss risk.

A BTC collapse to $10,000 would be consistent with the kind of macro, liquidity, leverage, and confidence shock described in the Bitcoin sources, which would likely pressure funding, basis, and withdrawal behavior across the market. Key protocol implications under this scenario:

  • Yield compression: expected returns on BTC-linked or market-neutral strategies could decline materially if funding turns persistently negative.
  • Withdrawal pressure: higher redemptions could stress liquidity buffers and create queues if positions must be unwound before funds are returned.
  • Realized losses: if the protocol must exit positions into a stressed market, users may receive less than principal due to slippage and adverse execution. Because on-chain TVL, chain-by-chain exposure, reserve composition, and hedging parameters are Not verifiable as of 2026-09-04, I cannot quantify losses by chain (Arbitrum, BSC, Base, Ethereum, OP Mainnet, Polygon). The available secondary sources also do not provide a reliable, independently verified balance-sheet view of ZEROBASE CeDeFi under this stress case.
Evidence (6)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-09-04. Available sources identify ZEROBASE CeDeFi as a stablecoin-yield protocol with collateralized staking, but they do not provide a chain-by-chain collateral breakdown, oracle composition, or liquidation waterfall needed to model a 20% depeg shock on the largest collateral asset. DeFiLlama reports $56.03m TVL for the protocol, but that is an aggregate TVL snapshot rather than a stress-tested loss estimate, and it does not specify which collateral token is largest or how exposure is distributed across Arbitrum, BSC, Base, Ethereum, OP Mainnet, and Polygon.

The protocol’s own materials indicate a 14-day redemption waiting period and collateral posted by node operators, which implies depeg losses could transmit through delayed withdrawals and forced unwinds, but the magnitude of loss under a 20% depeg cannot be verified from the retrieved evidence.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Stress scenario: largest counterparty insolvency Counterparty identification. ZEROBASE describes deposits moving from the Vault to custodial accounts and four liquidity funds. Its V2 materials specifically identify Ceffu, using MirrorX to Binance, as the principal route for funding-rate arbitrage. However, the largest counterparty by actual dollar exposure is Not verifiable as of September 5, 2026; no on-chain verification is available in this run.

Expected loss path. Insolvency would create a recovery shortfall equal to assets trapped at the custodian/exchange, reduced by any liquid collateral, hedge proceeds, or bankruptcy recovery. The loss first appears economically in the Vault’s backing assets: LP-token claims remain outstanding while redeemable USDC/USDT falls. Risk-neutral ZK proofs do not prove solvency, custody, or recoverability.

Who absorbs it. In the documented structure, users bear the residual loss. ZEROBASE disclaims responsibility for custodian, exchange, strategy-operator, or insolvency losses; assets are not insured or government-protected. The company’s contractual liability is generally capped at the greater of $100 or fees paid directly to the company in the prior 12 months, subject to non-excludable liability.

Compensation. No contractual make-whole, protocol insurance fund, senior-loss buffer, or ZBT-holder backstop was identified. Potential recovery would depend on Ceffu/Binance/counterparty liquidation or legal claims. Therefore, compensation is not guaranteed and is Not verifiable as of September 5, 2026.

Smart-contract impact path. (1) Vault deposits mint LP tokens; (2) off-chain deployment reduces liquid Vault balances; (3) insolvency prevents the robot/custodian from returning funds; (4) normal redemptions enter the documented 7-day queue and may fail or remain unpaid; (5) “Flash Withdraw” is available only if the deposit contract has sufficient liquidity and charges 0.5%; (6) administrators can pause operations and possess emergency/recovery privileges, but those powers do not create solvency or user compensation.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For the stress scenario committed fraud by the DAO or owners, ZEROBASE CeDeFi presents not verifiable as of 2026-09-04 evidence of DAO- or owner-committed fraud. The available material describes ZEROBASE as a zk-based, privacy/compliance protocol with partial-decryption and use-case documentation, but it does not provide independent proof of fraud, governance abuse, treasury misappropriation, or owner malfeasance. What *is* verifiable is that DeFi protocols can be exposed to administrative-key abuse in general, and that DAO structures have historically created legal and operational paths for losses when controllers or tokenholders exercise power improperly.

However, those sources are generic or about other protocols; they do not establish a fraud event for ZEROBASE CeDeFi itself. There is also a third-party risk writeup rating ZEROBASE CeDeFi as moderate risk and discussing collapse scenarios, but this is a private analytics opinion, not evidence of fraud. A separate media report alleges a frontend compromise and phishing-style theft from users, but that is not the same as committed fraud by the DAO or owners and does not verify internal misconduct by protocol controllers.

So the fraud stress case should be treated as a tail-risk governance/insider-risk assumption, not an observed incident, unless later independent evidence shows owner or DAO-controlled asset diversion.

Evidence (7)

stress scenario - primary yield source negative 30d,

one source

ZEROBASE CeDeFi’s primary yield source is basis trading / funding-rate arbitrage on Binance, so a 30-day period of negative perp funding is a direct stress case for the protocol’s core return engine. In that scenario, the expected outcome is not just lower APY: the trading book can move from earning carry to incurring losses, which would push staker yield toward zero and, if prolonged enough, erode principal. The protocol’s own materials describe returns as coming mainly from risk-neutral arbitrage and note a 14-day redemption waiting period, which makes rapid deleveraging harder during a funding shock.

The most relevant published failure mode is a “Prolonged Negative Funding Rate Erosion” scenario, described as funding rates staying negative for more than 30 consecutive days and exceeding the protocol’s buffer capacity. Under that stress case, withdrawals can queue while positions are unwound, and forced unwinds in an adverse market can add slippage and realized losses. One third-party risk write-up estimates possible losses of 5–15% in that unwind path, but that figure is an independent scenario estimate rather than verified on-chain performance.

Available public data does not let me verify the actual buffer size, loss absorption rules, or realized 30-day drawdowns for ZEROBASE across Arbitrum, BSC, Base, Ethereum, OP Mainnet, and Polygon. Not verifiable as of 2026-09-04. If you want, I can next turn this into a chain-by-chain stress memo using only public disclosures and third-party analytics, with clearly separated verified facts and unverified assumptions.

Evidence (5)

Governance & Legal

governance

one source

As of September 13, 2026, governance appears company-controlled with a procedural DAO layer; token-holder control over contracts, upgrades, frontend, or all user funds is not demonstrated.

  • Company / frontend / operations: The app Terms name Vortex Tech Ltd., a Cayman Islands company. The independently indexed LEI record gives company number 412048, incorporation date July 18, 2024, and Cayman address. The Terms let the Company modify, replace, suspend, or discontinue services; restrict access; and, where legally/technically possible, reject, delay, restrict, or freeze transactions. Proprietary interface/content is owned by the Company.
  • Legal entity / directors: Company identity and registration are cross-confirmed. Directors and the previously recorded management names were not independently reverified from a public registry in this run: Not verifiable as of September 13, 2026. Terms of service and dispute jurisdiction are Cayman-law/company-controlled terms; U.S. persons are expressly excluded.
  • DAO / proposal process: The DAO guidelines state that proposals use Snapshot; submission requires either more than $500,000 ZBT or authorization; voting lasts 7 days, requires $2,000,000 ZBT quorum, and passes above 50% of valid votes. Treasury allocation, incentives, partnerships, and priorities are listed as decidable, while certain pre-TGE/team matters are excluded.
  • DAO reality: This is not proven to control contracts or the legal entity. A treasury proposal states the team collects fees and the DAO treasury multisig executes purchases after a DAO vote—evidence of delegated execution, not necessarily binding protocol governance.
  • Contracts, timelock, multisig, powers, concentration/top holders: On-chain verification was unavailable because Dune MCP is unavailable in this run. Not verifiable as of September 13, 2026. The Terms acknowledge possible admin, upgrade, pause, allowlist, parameter-management, and emergency permissions, but do not identify addresses, thresholds, signers, independence, or effective powers. Risk conclusion: Frontend and operational control is clearly centralized in Vortex Tech Ltd.; DAO control is presently symbolic/limited for this assessment. Contract-level fund-drain and emergency authority remain unresolved. Structured fields: timelock=null; timelock_delay_hours=null; multisig_threshold=null; multisig_owners=null; admin_can_drain=null; emergency_bypass=null; dao_governance=false.
Dao governance
No
Evidence (4)

legal & regulatory

two sources

As of September 4, 2026, ZEROBASE identifies the operating entity as Vortex Tech Ltd., a Cayman Islands exempted company limited by shares, incorporated July 18, 2024; the MiCA white paper gives Cayman registration number CR-412048, registered/head-office address 3-212 Governors Square, Grand Cayman, and LEI 8755005ACR10IAZXKF10. Terms/restrictions. The July 2026 Terms select Cayman Islands law and ICC arbitration seated in Cayman, prohibit class proceedings, and exclude U.S. persons, Mainland China, Cuba, Iran, North Korea, Belarus, Syria, Crimea and Sevastopol, plus other restricted/sanctioned persons. The company reserves broad rights to screen wallets, request identity/beneficial-owner/source-of-funds information, block addresses, restrict transactions and disclose information to authorities.

KYC/AML and classification. KYC is expressly required for the Binance pre-TGE token offering, with AML/CTF and sanctions compliance delegated substantially to the distribution platform. For the staking interface, the Terms permit screening and verification but do not establish a publicly evidenced licensing status or comprehensive AML program. The company contractually characterizes itself as software/interface/technical/administrative provider—not a bank, broker, exchange, adviser, fund manager, custodian or fiduciary—while offering staking/yield strategies through smart contracts and third parties.

This disclaimer does not eliminate potential regulatory characterization based on actual functions. Warnings/enforcement. The MiCA white paper states it was not approved by an EU competent authority, provides no investor-compensation or deposit-guarantee protection, and warns that the token may lose value or liquidity. No regulator warning, enforcement action, court case, or sanctions designation against Vortex Tech Ltd./ZEROBASE was located in the reviewed sources. The December 2025 phishing incident concerned an impersonating BSC contract, not an identified regulator action against ZEROBASE.

Data protection. Terms state that wallet and transaction data may be collected, analyzed and combined for security, fraud prevention, sanctions screening and legal compliance, while blockchain data may be permanent. A standalone privacy policy’s controller, retention, transfer and data-subject rights are Not verifiable as of September 4, 2026. Legal structure vs. actual risk. Cayman incorporation provides a contractual counterparty but no evidence of prudential supervision, deposit insurance, segregated custody, or recovery protection.

Exposure remains to smart contracts, third-party strategies/custodians, sanctions blocks, offshore enforcement friction and arbitration costs. A UK company with the same name was dissolved January 20, 2026, but its registration/address differ; linkage to ZEROBASE is not established.

Active enforcement
No
Sanctioned
No
Entity
Vortex Tech Ltd.
Jurisdiction
Cayman Islands
Evidence (5)

legal registries

two sources

GLEIF LEI registry unavailable at scan time. OFAC SDN screening of 'Vortex Tech Ltd', 'ZEROBASE CeDeFi': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Vortex Tech Ltd
  • ZEROBASE CeDeFi
Entity
Vortex Tech Ltd
LEI
8755005ACR10IAZXKF10
Jurisdiction
KY
Entity status
ACTIVE
Sanctioned
No
Evidence (3)

Stability

stability

two sources

ZEROBASE CeDeFi does not appear to issue its own stablecoin; the protocol is presented as a stablecoin-yield product using USDT and USDC across multiple chains, so own_stablecoin is false. The stablecoin depeg history is not verifiable from the available sources, so stable, depeg_count, max_depeg_pct, and last_depeg_date remain Not verifiable as of 2026-09-06.

Own stablecoin
No
Stablecoin ids
  • USDT
  • USDC
Evidence (3)

Risks & Strengths

risks

two sources

ZEROBASE CeDeFi combines audited vault contracts with material CeFi, privileged-administration, and withdrawal dependencies. The most significant residual exposures are counterparty solvency, governance/key compromise, smart-contract business logic, liquidity constraints, and cross-chain/operational complexity. On-chain verification was unavailable: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
CeFi counterparty failureDeposited stablecoins are used in off-chain arbitrage through CEFFU and related counterparties. Default, insolvency, withdrawal suspension, fraud, or regulatory action could impair principal and yield.HighMediumProtocol-level vault accounting, staking constraints, and stated risk-neutral proof controls. Counterparty solvency and asset recovery are not guaranteed.High residual exposure to third-party custody, trading, and settlement.
Privileged-admin compromiseV2 admin can change reward rates, penalties, and the CEFFU address; compromise could redirect funds or manipulate economics. Salus also identified stale pause privileges.HighMediumRole-based access control and pausing exist. Salus recommended multisig plus timelock; implementation was only acknowledged, not independently verified.High until multisig, timelock, role revocation, and monitoring are verified.
Vault accounting defectsPeckShield found medium-severity share-minting rounding logic and claim-cancellation reward-accounting issues, potentially causing unfair minting or reward loss.MediumMediumPeckShield reports PVE-002 resolved and PVE-003 mitigated; PVE-001 was confirmed with minimal tolerated rounding impact. Audits cover specific commits only.Medium due to upgrade, deployment, and regression risk.
Withdrawal liquidity constraintsWithdrawals may face queues, lockups, available-liquidity limits, compliance reviews, or third-party restrictions; users may receive assets later or at a worse value.HighMediumV2 documents automated emergency withdrawal with a stated 0.5% fee, plus vault withdrawal controls.Medium-to-High; real-time liquidity and reserve coverage are Not verifiable as of September 5, 2026.
Cross-chain operational complexityDeployments across multiple EVM chains increase configuration, token-support, bridge, oracle, and chain-failure risk; inconsistent parameters could create isolated loss or withdrawal failures.HighMediumSeparate chain deployments, audited vault versions, and pause controls. Salus noted supported tokens cannot be removed once added.Medium-to-High because deployment parity and cross-chain exposure are Not verifiable as of September 5, 2026.
Evidence (4)

strengths

two sources

ZEROBASE CeDeFi’s main strengths are its zk-based verifiability, privacy-preserving design, institutional/compliance orientation, speed/cost efficiency, and cross-chain/stablecoin yield positioning. It is described as a basis-trading protocol that uses zero-knowledge proofs to verify trading activity while sharing arbitrage profits with stablecoin stakers, which is a relatively clear value proposition for yield users.

  • Verifiable strategy execution: the protocol uses custom ZK proofs to check that strategies do not use excessive leverage or hold unhedged positions, which strengthens trust in the yield process.
  • Privacy with compliance: ZEROBASE markets itself as privacy-preserving and compliant, combining ZKPs with TEEs and even “programmable compliance” concepts for institutional use cases.
  • Risk-controlled yield design: its CeDeFi staking model is presented as “risk-neutral,” with stablecoin staking and basis/arbitrage returns rather than purely speculative rewards.
  • Performance and efficiency: multiple sources claim very fast proof generation, low proof costs, and millisecond-level infrastructure, which supports high-frequency, production-style financial workflows.
  • Multi-chain accessibility: the protocol is listed across Arbitrum, BSC, Base, Ethereum, OP Mainnet, and Polygon, which suggests broad chain coverage for users and liquidity distribution. A practical caveat: most performance and product claims come from the project itself or secondary write-ups, so they should be treated as unverified marketing claims unless independently confirmed.
Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 29 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-29.