BitFi Basis

Red · 12/100 Data confidence 81/100

Missing critical evidence: incident. The score is capped until coverage improves.

Executive summary

BitFi Basis is a CeDeFi basis-trading protocol offering BTC and stablecoin yield via delta-neutral strategies across 7 chains (Binance, Ethereum, Base, Bitlayer, CORE, Hemi, Pharos), scoring 64/100 (orange band).

  • Security & audits: SlowMist audit for bfUSD (Dec 2025) found 2 medium-risk issues, 5 suggestions, 1 informational; no recorded security incidents to date, but one analytics source contradicts BitFi's claim of published audits. Audit coverage for bfBTC and full scope remain unverified as of 2026-08-29.
  • Custody & counterparty risk: Hybrid CeDeFi model with BTC held under BitFi's custody and routed through Ceffu's MirrorX infrastructure; users receive on-chain receipt tokens (bfBTC, bfUSD). Independent risk reports flag centralized custody at Ceffu as a single point of failure for insolvency, breach, or regulatory action. Exact custody split, cold storage, and multisig controls are unverified.
  • Governance & control: Founder/company-controlled with upgradeable contracts; bfUSD contract has an Owner role that can set parameters, minters, and upgrade via UUPS with no verified timelock or DAO sovereignty. BFI governance token exists but appears limited to parameter votes, not core protocol control.
  • Top risks: (1) Centralized custody/counterparty risk via Ceffu; (2) funding-rate inversion risk—sustained negative funding can erase yield and force redemptions with potential 10–30% losses; (3) off-chain execution opacity; (4) token interdependence (bfBTC/bfUSD/BFI cascade risk); (5) limited ~1.5-year track record and novel stablecoin mechanics.
  • Stress scenarios: BTC crash below $10k or 30-day negative funding can trigger yield collapse, redemption pressure, and bfUSD depeg risk; 20% collateral depeg impact and counterparty insolvency loss paths are unverified due to missing TVL, reserves, and collateral composition data.
  • Strengths: Institutional-style delta-neutral BTC yield, cross-chain reach, composability (especially on Core), segregated custody with yield-bearing tokens, and no recorded hacks.
  • Unverified: TVL, reserves, treasury addresses, legal entity/jurisdiction, exact collateral composition, bug bounty program, public API, historical depeg events, and detailed insolvency waterfall all remain unverified as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 10 2.5 0 audit(s); no fresh audit; no qualifying bug bounty
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 71 10.7 0 onchain, 12 two-source, 6 one-source of 21 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL unavailable; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

BitFi Basis is a CeDeFi basis‑trading protocol within the BitFi ecosystem, offering BTC and stablecoin yield via delta‑neutral strategies and synthetic assets across multiple chains. Protocol identification

  • Name: BitFi Basis
  • Website: bitfi.one (BitFi’s main site; Basis is a sub‑product rather than a separate site).
  • Docs: Hosted under BitFi Docs (bfBTC/bfUSD, CeDeFi architecture, FAQs, deployed contracts).
  • Category: Basis trading / CeDeFi yield on BTC and stablecoins.
  • Launch date / age: DIAData states BitFi Basis has been operational for ~1.5 years; precise launch date is Not verifiable as of 2026‑08‑29.
  • Chains: Independent aggregators concur on 7 chains:
  • Binance, Ethereum, Base, Bitlayer, CORE, Hemi, Pharos.
  • Some sources list “6 chains” but enumerate the same set excluding Pharos; that is a minor reporting discrepancy. Native & related tokens
  • bfBTC: Native yield‑bearing Bitcoin liquid staking token, ERC‑20/OFT across multiple chains (Binance, Ethereum, Base, Bitlayer, Hemi, CORE).
  • bfUSD: Yield‑bearing stablecoin, fully collateralized against USDT/USDC with Chainlink‑secured pricing; used in Basis trading and vaults (Horizon, Pulsar).
  • BFI: BitFi ecosystem’s native governance/utility token (governance, staking, incentives, liquidity pairing). Main contract addresses & verification status BitFi’s own docs list bfBTC contracts on multiple chains:
  • Binance Smart Chain bfBTC: 0x623F2774d9f27B59bc6b954544487532CE79d9DF
  • Bitlayer bfBTC: 0xcdfb58c8c859cb3f62ebe9cf2767f9e036c7fb15
  • Hemi bfBTC: 0x623F2774d9f27B59bc6b954544487532CE79d9DF
  • Ethereum bfBTC: 0xCdFb58c8C859Cb3F62ebe9Cf2767F9e036C7fb15
  • Base bfBTC: 0x623F2774d9f27B59bc6b954544487532CE79d9DF
  • CORE bfBTC: 0xCdFb58c8C859Cb3F62ebe9Cf2767F9e036C7fb15 Cross‑checking these addresses against independent explorers would normally be required to confirm contract verification status and code, but this is Not verifiable as of 2026‑08‑29 due to lack of on‑chain tool access. Fork lineage & code provenance
  • Independent risk/analytics profiles describe BitFi Basis as a CeDeFi platform using proprietary basis‑trading strategies, centralized BTC custody (Ceffu), and synthetic stablecoin mechanics, not as a direct fork of a specific DeFi protocol such as Liquity, Maker, or GMX.
  • No external source identifies BitFi Basis as a fork of an existing open‑source protocol; lineage is therefore Not verifiable as of 2026‑08‑29.
  • DIAData explicitly notes “BitFi Basis has not published audit reports”, implying that any code changes vs. upstream inspirations (if any exist) have no publicly disclosed audits.
  • No documented history of malicious modifications in related forks of BitFi Basis or bfBTC/bfUSD is available in independent sources; this is Not verifiable as of 2026‑08‑29. Marketing-claim flagging
  • All architectural claims (e.g., “unique CeDeFi hybrid approach,” “institutional‑grade yields,” “on‑chain asset management with $480M AUM”) originating only from BitFi’s docs or website are unverified marketing claims, pending corroboration from on‑chain data or independent technical audits.
Evidence (15)

maturity

two sources

BitFi Basis appears to have a real product portal, not just a static landing page: the main site exists, there is a documentation portal, and the docs expose product guides plus developer references such as deployed contracts, FAQs, and oracle/fee pages. That said, the web evidence does not prove live deposit/withdraw execution from the portal itself, so live user-flow functionality is only partially verifiable from the available sources. The strongest maturity signal is documentation depth: the docs include chain-specific deployments across Binance, Ethereum, Base, Bitlayer, CORE, Hemi, and testnets, which suggests an active multi-chain product surface rather than a template shell. The site and docs also reference audits and a price oracle integration, which are more consistent with an operating DeFi stack than a placeholder site. I did not find independent evidence of broken links, fake metrics, or template reuse in the retrieved sources, so those concerns are Not verifiable as of 2026-08-29. The same applies to whether deposits and withdrawals are currently live for end users; the docs mention unstake/withdraw concepts, but I could not confirm real-time execution from the available web evidence. No open public API was verifiable from the retrieved materials. The documentation portal shows developer pages and contract references, but there is no clearly evidenced unauthenticated public API endpoint or open developer API portal for BitFi Basis in the sources reviewed. Overall: BitFi Basis looks like an established, documented DeFi application with a real app/docs stack, but live operational maturity and open API availability remain only partially verified from the web evidence available today.

Evidence (7)

Security

audit

unverified

BitFi’s docs state there is also a SlowMist audit report for BitFi Bitcoin (bfBTC). The search result confirms the report exists, but the underlying PDF content was not available in the retrieved snippet, so the exact findings and fix status are not verifiable here.

Auditor
SlowMist Security Team
Report Date
2025-12-01
Scope
BitFi Bitcoin (bfBTC) smart contracts
Evidence (1)

audit

unverified

BitFi’s docs publish a SlowMist report for BitFi USD (bfUSD) and a separate report for BitFi Bitcoin (bfBTC). The bfUSD PDF states the audit was a manual review plus tool-assisted analysis, and concludes with 2 medium-risk findings, 5 suggestions, and 1 informational issue.

Auditor
SlowMist Security Team
Report Date
2025-12-01
Scope
BitFi USD (bfUSD) smart contracts; separate bfBTC report also published by BitFi docs
Evidence (2)

bug bounty

two sources

BitFi Basis does not show a verifiable active bug bounty program in the sources reviewed as of 2026-08-29. The only clearly documented bounty material found was for Bitfi’s older wallet project, not BitFi Basis: it had a controversial in-house bounty in 2018, including a $250,000 challenge and a later $10,000 bounty, with program language stating that successful reports had to demonstrate specific exploit conditions; the company then said the bounty programs were closed. That means for BitFi Basis, the start date, parameters, and results are not verifiable as of 2026-08-29.

Evidence (3)

crypto custody

one source

BitFi Basis appears to use a hybrid CeDeFi custody model: user BTC is described as being held under BitFi’s custody solution and routed through Ceffu’s MirrorX-powered execution and arbitrage infrastructure, while users receive on-chain tokens (bfBTC, bfUSD) that circulate in DeFi. The available sources do not provide a full legal or technical custody diagram, so the exact split between BitFi, Ceffu, and any sub-custodians is Not verifiable as of 2026-08-29. What is supported is that custody is not purely self-custody: the protocol explicitly says BTC is “locked under BitFi’s custody,” and independent analysis reports that the model relies on Ceffu as a centralized custodian for BTC deposits, which introduces counterparty risk. In practice, this means the custody of the underlying BTC is organized around a custodial layer plus on-chain receipt tokens, rather than users directly controlling the private keys themselves. BitFi also says it supports BTC on multiple chains and accepts USDT/USDC on Ethereum for bfUSD minting, but those statements do not clarify who holds the keys at each chain level or whether any assets are segregated by chain. Any detailed claims about cold storage, multi-signature controls, approval workflows, or recovery procedures are Not verifiable as of 2026-08-29 based on the available sources.

Evidence (4)

key management

two sources

BitFi Basis appears to organize key management around a non-custodial, passphrase-based model rather than storing private keys on the device. Bitfi’s own security and FAQ pages say users enter a SALT plus SECRET PASSPHRASE, the device calculates the private key on demand for each transaction, and then the key is instantly wiped/overwritten from memory. The implication is that access is controlled by the secret inputs, not by a persistent key file or seed stored on the wallet. For operationally relevant risk analysis, that means key control is effectively organized as follows:

  • User-held credentials: the salt and passphrase are the only recovery/control inputs described.
  • Ephemeral signing: keys exist only briefly during transaction signing and are then erased from RAM.
  • Device independence: Bitfi states funds are not tied to one physical device, so loss or seizure of the device should not reveal the keys. There is an important limitation: the available sources are Bitfi’s own materials and third-party writeups about the wallet design, not protocol-specific documentation for BitFi Basis on the listed chains. So the exact institutional setup for BitFi Basis—such as whether a custodian, multisig committee, or MPC operator is involved—is not verifiable as of 2026-08-29 from the provided sources.
Evidence (5)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

BitFi Basis appears to be a small, U.S.-based team rather than a fully transparent, long-established institution, but the evidence is thin and mostly third-party. The strongest public identity match is Han Liu, who is listed on LinkedIn as Founder/CEO of BitFi.one in New York and as former CTO/co-founder of AscendEX; a GlobeNewswire seed-round notice says BitFi was founded by Liu Han, former co-founder and CTO of AscendEX. A separate company profile also lists a New York HQ and suggests only 1–10 employees, which is consistent with an early-stage startup, not a large operating business. Credibility-wise, the main positive signal is Han Liu’s claimed prior role at AscendEX, but that is still an *off-protocol* reputation claim rather than on-chain proof. I did not find independently verifiable evidence of a real office beyond directory-style listings; the New York headquarters claim is not well substantiated. I also did not find credible evidence of prior hacks or incidents involving BitFi Basis specifically; the only major “BitFi hack” result surfaced was about John McAfee’s unrelated Bitfi wallet, which is a name collision and should not be attributed to BitFi Basis. On anonymity, the visible leadership is *not anonymous* in the sources found: Han Liu is public, and a LinkedIn result also shows Yujie Rao in a “CEO office” role. However, the broader team remains opaque, and some company-data sources look sales/lead-gen oriented rather than independently confirmed. As a reality check, this looks more like a web-fronted, venture-backed crypto startup with a public founder than a mature onshore operating institution; whether it has substantial real business activity beyond its online presence is Not verifiable as of 2026-08-29.

Evidence (5)

general reputation

two sources

BitFi Basis currently has a mixed but generally non-toxic reputation, with notable elevated risk flags around centralized custody and novel stablecoin mechanics, but no publicly recorded hacks, rugs, or insolvency/regulatory cases as of 2026-08-29. Security, audits, and incidents

  • Multiple independent trackers (DiaData, ZARQ) state no recorded security incidents for BitFi Basis so far.
  • BitFi’s docs host a SlowMist audit for bfUSD, dated 2025-12-01–05, with an overall medium risk rating and several findings (2 medium, 5 suggestions, 1 informational).
  • BitFi docs list an audit section for bfBTC and bfUSD. DiaData simultaneously claims BitFi Basis “has not published audit reports,” which contradicts BitFi’s own documentation and SlowMist’s published audit. > Contradiction callout: One analytics source says no audits published while BitFi’s own docs and an independent audit firm show at least one audit (bfUSD, SlowMist). On-chain verification of audit coverage and scope is Not verifiable as of 2026-08-29. Risk ratings and third‑party views
  • Hindenrank assigns BitFi Basis a C+ risk grade (41/100), “elevated risk”, citing centralized custody (Ceffu), synthetic stablecoin backing, and limited track record through full market cycles.
  • DefiSentinel rates BitFi (broader platform) C, 49/100 safety score, noting two SlowMist audits (bfBTC 2024-12, bfUSD 2025-12).
  • ZARQ gives BitFi Basis a B trust score (68/100), with TVL ~228–229M USD and no known security incidents.
  • Several data platforms (DefiLlama, Bathymark, DiaData, MrDeFi) list BitFi Basis with ~190–230M TVL across 6–7 chains, consistent with a mid-sized CeDeFi protocol. Model and structural concerns
  • Independent risk analysis (Hindenrank) classifies BitFi Basis as a CeDeFi platform where user assets are custodied by Ceffu and yields come from delta‑neutral BTC basis trading and a tri‑token system (bfBTC, bfUSD, BFI).
  • Key concerns raised:
  • Centralized custody dependency (Ceffu) → counterparty risk and potential regulatory exposure.
  • Novel synthetic stablecoin (bfUSD) mechanics with limited cycle-tested history. Founders, investors, and legal/regulatory
  • Public sources focus on the protocol mechanics and TVL; named founders, major investors, and any formal regulatory filings are not clearly documented in the independent datasets checked. Not verifiable as of 2026-08-29.
  • No credible sources report fraud, rug pull, sanctions, or insolvency proceedings against BitFi Basis or BitFi more broadly as of 2026-08-29. Overall, the reputation is that of a growing CeDeFi basis‑trading platform with material centralized‑custody and design risks, but no confirmed major security or legal failures to date; risk ratings consistently place it in a mid‑tier (B/C) risk band rather than high‑safety.
Evidence (15)

Economy

model

one source

BitFi Basis is a multi-chain yield protocol and yield-bearing stablecoin system built around “Basis Points” vaults and the BTFi ecosystem; however, most core economic metrics are Not verifiable as of 2026-08-29 due to limited independent coverage and missing on-chain dashboards. ### Strategy & Assets BitFi positions itself as a DeFi yield aggregator that routes user deposits into external protocols across multiple chains (Binance, Ethereum, Base, Pharos, Hemi, Bitlayer, CORE). It focuses on stablecoin and blue-chip assets (e.g., USDT/USDC-like, BTC/ETH-like) but precise supported tokens per chain are Not verifiable as of 2026-08-29. The protocol introduces concepts such as Basis Points vaults and a yield-bearing stablecoin, suggesting:

  • Users deposit stablecoins or majors into vaults.
  • Vaults allocate to external lending/LP/restaking strategies to generate yield. Exactly which external protocols and their weights are Not verifiable as of 2026-08-29. ### Yield Source & Risk Profile Yield appears to be a mix of:
  • Organic yield from lending/LP/restaking on partner protocols.
  • Subsidized incentives via BTFi ecosystem rewards, points, and potential airdrop allocations. Given use of external DeFi and restaking narratives, the model is partly market-neutral (lending/borrowing, stablecoin strategies) but includes directional risk through exposure to underlying protocols, smart-contract risk, and possible impermanent loss where LP is used. BitFi mentions leveraged yield and “basis” strategies in marketing language, implying:
  • Potential looping (collateral → borrow → redeposit) on lending markets.
  • External exposure to restaking and partner yield platforms. Exact leverage ratios and risk parameters are Not verifiable as of 2026-08-29. ### Lock-ups, Withdrawals, Fees Documentation implies vault-style deposits with on-demand withdrawals, possibly subject to:
  • Strategy exit time and chain-specific gas costs.
  • Performance/management fees at vault level. However, fee schedules, gates, withdrawal timeframes, and any exit penalties are Not verifiable as of 2026-08-29 beyond high-level marketing statements. ### Protocol Revenue & Collateral Protocol revenue likely comes from:
  • A share of strategy yield.
  • Potential token incentives or BTFi-related emissions. Collateral appears to be user-deposited stablecoins and blue-chip assets; details on collateral segregation, insurance funds, or backstops are Not verifiable as of 2026-08-29. ### TVL, Chain Split, APY History Independent analytics (e.g., DeFiLlama) list BitFi/BTFi-related entries but:
  • TVL by product and by chain, and trends over time are Not verifiable as of 2026-08-29 due to unclear mapping of entries to BitFi Basis specifically and lack of cross-checked dashboards.
  • APY history, volatility, and sustainability are Not verifiable as of 2026-08-29, as no consistent third-party yield time series are available. Overall, BitFi Basis currently operates as a multi-chain yield aggregator with subsidized components and non-trivial external protocol exposure, but key economic variables (TVL, APY, fee structure, leverage) lack independent, reproducible verification.
Evidence (3)

reserves

two sources

Not verifiable as of 2026-08-29. Public web results locate BitFi Basis as an on-chain asset management/stablecoin platform and show protocol-level TVL and chain distribution, but they do not provide a verifiable reserves/treasury disclosure with treasury addresses, composition, custody structure, reserve policy, or third-party attestations. The only directly relevant disclosures found are product- and contract-level docs for bfBTC/bfUSD deployments across Binance Smart Chain, Ethereum, Base, Bitlayer, Hemi, CORE, and related testnets, plus a third-party risk note that characterizes the system as involving centralized custody dependency; however, that does not establish audited treasury balances or control. In the absence of on-chain verification and a dedicated reserve attestation, the reserves/treasury size, addresses, composition, custody, and control remain unconfirmed. Any protocol-website claims about AUM or yields are unverified marketing claims unless independently corroborated.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

BitFi Basis is exposed to a severe Bitcoin drawdown because its strategy depends on basis/funding economics remaining supportive; in a prolonged bear market, negative funding can erase yield and force redemptions or position unwinds. Hindenrank specifically flags that sustained negative funding could push bfBTC yield to zero or negative, with cascade risk into bfUSD and potential 10–30% losses for remaining holders in a liquidity crisis. For a BTC move below $10,000, the main stress channels are:

  • Funding-rate inversion: if perpetual funding stays negative for an extended period, the protocol pays instead of earns funding, undermining the delta-neutral trade and reducing returns below zero.
  • Redemption pressure: lower or negative yield can trigger exits, forcing the protocol to unwind hedge legs at unfavorable prices and realize losses.
  • bfUSD backing stress: because bfUSD is backed by the same basis-trading machinery, a simultaneous selloff can weaken confidence in the token’s backing and increase depeg risk.
  • Custodian/counterparty risk: the protocol’s BTC deposit model relies on Ceffu; a market crash can amplify concerns about centralized custody and operational resilience. What is not verifiable as of 2026-08-29 from the available sources:
  • The exact chain-by-chain exposure across Binance, Ethereum, Base, Pharos, Hemi, Bitlayer, and CORE.
  • Current TVL, reserves, liquidation thresholds, or hard loss estimates under a BTC sub-$10,000 scenario. So, the best-supported conclusion is that a BTC crash below $10,000 would likely be a high-stress event for BitFi Basis, with the risk concentrated in negative funding economics, forced unwinds, and possible bfUSD instability, but the precise balance-sheet impact is not verifiable from the available sources.
Evidence (3)

stress scenario - largest collateral depegs 20%,

one source

Under a 20% depeg of the largest collateral, the key risk is a direct loss in collateral value with possible secondary effects on peg stability and redemptions. Because BitFi Basis is presented as a delta-neutral / basis-trading protocol and Hindenrank says the same basis positions back both bfBTC and bfUSD, a large collateral shock can affect multiple products at once rather than being isolated to one token. What can be stated from the available sources: BitFi Basis reports a TVL of $213.83m, with $76.94m on BSC in the cited snapshot, and its public materials emphasize delta-neutrality for stability. Hindenrank flags centralized custody dependency through Ceffu and says bfUSD is backed by the same basis trading positions as bfBTC, which increases the chance that a collateral depeg propagates across the system. A precise loss amount from a 20% depeg is Not verifiable as of 2026-08-29 because the available results do not provide the chain-by-chain collateral composition, position sizing, or the largest-collateral notional needed to compute protocol-wide impact. The stressed exposure therefore cannot be quantified from the provided data alone. Stress interpretation: if the largest collateral is a dominant backing asset, a 20% drop would reduce the value of that sleeve by 20%, potentially forcing deleveraging, lower yields, or redemption pressure; if that collateral also backs bfUSD/bfBTC simultaneously, the effect could be broader than a simple NAV haircut.

Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

For BitFi Basis, the most likely stress case is that a top counterparty/strategy leg in the basis trade becomes insolvent, causing an immediate mark-to-market loss or principal impairment inside the relevant vault or settlement path. BitFi’s own docs say bfUSD is split into Horizon and Pulsar ERC-4626 vaults, with a coordinated risk perimeter where Horizon revenue can boost Pulsar and Pulsar capital plus a protocol buffer help protect Horizon; they also say multiple vaults, an on-chain buffer, and a project-funded insurance pool are intended to keep hbfUSD stable when conditions are stressed. The expected loss path is therefore: the insolvent counterparty defaults, the strategy leg realizes a shortfall, the vault’s exchange rate or epoch ratio absorbs the loss first, and only then do any insurance/buffer mechanisms get used. The smart-contract impact path is through the epoch-based ratio update and ERC-4626 vault accounting: losses should flow into the share price / ratio rather than into an immediate guarantee of par redemption, because BitFi states that ratios update each epoch for bfUSD, hbfUSD, and pbfUSD. Who absorbs the loss: first the affected vault shareholders (through lower share value or slower growth), then the protocol buffer / insurance pool if the loss is within their capacity, and finally any residual gap would remain with users if those buffers are exhausted. BitFi’s docs do not provide a detailed insolvency waterfall for a top counterparty, so the exact legal/entity-level compensation mechanism is Not verifiable as of 2026-08-29. Compensation path: based on the docs, compensation is not a hard guarantee; it is conditional on available buffers and revenue redistribution. If a loss is covered, users are compensated indirectly via maintained or restored vault ratio / redemption value rather than a separate claims process. If the buffer is insufficient, docs do not specify any backstop, issuer guarantee, or lender-of-last-resort arrangement; that is Not verifiable as of 2026-08-29.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

No evidence in the provided results shows committed fraud by BitFi Basis’s DAO or owners. The available sources instead describe general crypto-fraud patterns and an independent risk report that flags counterparty, custody, and strategy risks, but it does not allege fraud or misconduct by the protocol’s DAO/owners. The only fraud-related result involving “Basis” concerns a different, unrelated venture (“Basis Markets”) and therefore does not verify fraud for BitFi Basis. So, for the specific stress scenario of committed fraud by the DAO or owners, the status is Not verifiable as of 2026-08-29 based on the supplied sources.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

BitFi Basis’s primary yield source appears to be delta-neutral basis trading / funding-rate capture, not a directional beta strategy, so a 30-day negative funding-rate regime is a direct stress case for the core yield engine. In that scenario, the strategy can stop producing yield and may turn negative after hedge maintenance, execution, and financing costs; the protocol-specific risk analysis explicitly says sustained negative funding can reduce yields to zero or losses and may trigger redemptions and position unwinds. The most severe downstream effects are lower or negative bfBTC yield, possible forced unwinds, and simultaneous pressure on related tokens if backing depends on the same basis positions. What this means for risk assessment:

  • Income compression: expected carry from funding capture can disappear if funding stays negative for 30+ days.
  • Mark-to-market / unwind risk: closing or rebalancing hedges in an adverse tape can crystallize losses.
  • Redemption stress: if users exit after yield turns negative, liquidity management becomes the main operational risk.
  • Contagion to related products: any asset backed by the same strategy can be affected at the same time. A key limitation is that 30-day negative-yield statistics for BitFi Basis are not verifiable as of 2026-08-29 from the available sources; the web results provide qualitative risk assessment and general basis-trade mechanics, but not a confirmed protocol-level 30d realized return series.
Evidence (4)

Governance & Legal

governance

two sources

BitFi Basis appears to be founder/company-controlled CeDeFi, with upgradeable contracts governed by an owner role rather than a fully independent DAO, and no evidence of a community-controlled timelock or transparent on-chain governance across its supported chains. Because direct on-chain tools are unavailable, all governance details are Not verifiable as of 2026-08-29 beyond what follows from public docs and third‑party research. Contract & protocol control

  • The bfUSD SlowMist audit states that the BitFiStablecoin contract has an Owner role that can:
  • Set key parameters
  • Set minters and mint limits
  • Set redeemers
  • Upgrade the contract via UUPS. This concentrates control in whichever entity/wallet holds the owner role.
  • There is no mention of an on-chain timelock or of governance being bound to token-holder voting in this audit.
  • Hindenrank characterizes BitFi Basis as a CeDeFi platform with custodied BTC at Ceffu and notes a BFI governance token with standard token‑weighted voting for “protocol parameter decisions.” This suggests governance is limited to parameters, while core control remains with the owner/multisig. DAO vs symbolic governance
  • Public risk reports describe BitFi Basis as CeDeFi and emphasize centralized custody and owner powers, not a sovereign DAO.
  • Hindenrank highlights a governance‑incentive issue: during a bfUSD depeg, BFI holders may vote to protect their own interests at the expense of bfUSD holders, implying that governance is at least partially token‑weighted but potentially narrow in scope and crisis‑biased.
  • No independent evidence of:
  • A formal DAO charter
  • On-chain proposal execution contracts
  • Immutable or timelocked governance. Therefore, its DAO, if any, is best treated as advisory/symbolic until on-chain controls are proven. Not verifiable as of 2026-08-29. Multisig, timelock, and signers
  • Neither the docs nor the audit extracts show:
  • Multisig addresses or signer counts
  • Thresholds (e.g., 2/3, 3/5)
  • Any timelock configuration.
  • Without on-chain inspection, multisig structure and independence are Not verifiable as of 2026-08-29. Frontend & company control
  • The primary site is operated under the BitFi brand, with copyright held by “BitFi” and contact via a corporate email.
  • No legal entity name, jurisdiction, registration number, or directors are disclosed in the visible pages used here.
  • Terms of Service or legal pages describing user rights, governing law, or regulatory disclosures were not identified in the retrieved materials. Not verifiable as of 2026-08-29. Token distribution, top holders, and vote concentration
  • Without on-chain analytics, BFI holder distribution, top holders, and voting concentration are Not verifiable as of 2026-08-29. Overall governance assessment (provisional)
  • High centralization of power in an owner/multisig that can upgrade bfUSD contracts.
  • Governance token (BFI) used for some decisions but with unclear, likely limited on-chain enforcement.
  • No independently verified timelock, DAO treasury control, or transparent multisig configuration.
  • For institutional risk, BitFi Basis should be treated as company‑governed CeDeFi with centralized upgrade and parameter authority, not as a fully decentralized protocol.
Evidence (10)

legal & regulatory

one source

BitFi Basis’s legal/regulatory posture is only partially verifiable from the web evidence gathered. The BitFi site itself exposes only a copyright/contact line and, in a sale page, states that regional restrictions apply and KYC/KYB/eligibility checks are required, but this is *unverified marketing claim* unless supported by independent legal documents. The strongest independent legal signal found is a Terms & Conditions page for a related Bitfi/Bitfia domain, which says the service is not available to users in prohibited or sanctioned jurisdictions, requires KYC/KYB to comply with AML/CFT, and is governed by Singapore law with disputes resolved in Singapore courts. However, because this page is on a different domain than bitfi.one, it cannot be safely treated as BitFi Basis’s governing legal document without further confirmation; the entity/jurisdiction linkage is therefore Not verifiable as of 2026-08-29. No independent evidence was found of public enforcement actions, court cases, or sanctions specifically naming BitFi Basis. The available results also did not verify a registered legal entity, corporate domicile, data-protection notice, or a clear risk-disclosure regime for the protocol itself; those items are Not verifiable as of 2026-08-29. From a risk perspective, the gap between a DeFi-facing brand and the absence of independently verified legal structure means user exposure may be materially higher than the website framing suggests: if regional restrictions/KYC are real, they likely indicate a centralized compliance perimeter; if they are only promotional, then users may face unresolved counterparty and jurisdictional uncertainty. Because the legal entity, jurisdiction, and privacy terms for BitFi Basis are not independently confirmed, the actual legal-risk profile remains Not verifiable as of 2026-08-29.

Evidence (3)

Stability

stability

one source

Not verifiable as of 2026-08-29. The available web results identify BitFi Basis’s stablecoin as bfUSD and describe it as USD-pegged, but they do not provide a reliable historical price series or an independent incident log showing whether it ever depegged, how many times, the last occurrence, or the maximum % deviation. The protocol’s own materials claim chainlink-secured pricing and mechanisms intended to prevent de-pegging, but that is unverified marketing absent on-chain or market-data confirmation. If a depeg occurred, it cannot be quantified from the gathered sources.

Evidence (2)

Risks & Strengths

risks

one source

The top 5 risks for BitFi Basis are: (1) centralized custody/counterparty risk from relying on Ceffu for BTC deposits, which creates a single point of failure if the custodian is breached, insolvent, or faces regulatory action; (2) strategy/funding-rate risk, because the protocol’s delta-neutral basis trades depend on persistently positive funding rates and can lose money in prolonged negative-funding regimes; (3) off-chain execution risk, since yield generation depends on centralized exchanges and custody operations that are opaque compared with fully on-chain strategies; (4) token interdependence risk, because bfBTC, bfUSD, and BFI are structurally linked, so stress in one part of the system can cascade to others; and (5) limited track-record/novelty risk, as the model has limited full-cycle history and its synthetic-stablecoin/basis-trading mechanics are relatively complex. These points are consistent across independent risk summaries, while the protocol’s own site mainly provides marketing claims and does not materially reduce the identified risks.

Evidence (3)

strengths

two sources

BitFi Basis’s main strengths are: (1) institutional-style BTC yield via delta-neutral basis/funding-rate strategies, which the project and CoreDAO describe as market-neutral and designed to preserve Bitcoin exposure; (2) segregated BTC custody with bfBTC issuance, giving users a yield-bearing receipt token while BTC stays in custody; (3) cross-chain reach, with the protocol listed across multiple chains in the provided data (Binance, Ethereum, Base, Pharos, Hemi, Bitlayer, CORE), which can broaden distribution and liquidity; (4) composability, especially on Core, where bfBTC can be used in additional DeFi strategies and liquidity venues for layered returns; and (5) no recorded security incidents in the supplied sources, which is a practical strength for user trust, though this is not the same as a formal audit guarantee.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 4 of 24 fact categories not yet collected.
  • Fact verifiability: 12 two independent sources, 6 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-29.