KETJU Research

← The Register

other

Aster Bridge

Rejected
Max sleeve
Reviewed
2026-08-17 · v1
Next review
2026-11-17
Research basis
Individual research
Chains
Ethereum · sovereign

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED ON TWO STANDING FACTS THIS REVIEW COULD NOT VERIFY AROUND, NOT ON A CONFIRMED EXPLOIT. Aster Bridge moves collateral into Aster, a perpetuals exchange whose team CZ has publicly confirmed includes former Binance staff. No named multisig, security council, or specific admin, pause, or upgrade authority for the bridge or core contracts was found in this review despite a direct search of Aster’s own documentation — a disclosure gap in the same category this registry has rejected other bridges over. More decisively, DefiLlama, the same data source this registry relies on for TVL figures throughout, has itself flagged Aster’s self-reported trading-volume data as unverifiable amid wash-trading concerns. A registry that trusts DefiLlama’s numbers elsewhere should not wave off DefiLlama’s own credibility warning about this specific protocol.

The research file

Mechanism

A user connects a self-custody wallet on a supported chain — BNB Chain, Ethereum, Arbitrum, or Solana — and deposits collateral into Aster’s smart contracts, recorded against that wallet address for margin trading; Aster’s docs describe the platform as now running on its own L1. Aster describes itself as non-custodial, with user funds staying wallet-controlled rather than held by a central intermediary, and states that withdrawing collateral requires no approval. Ceffu, formerly Binance Custody, provides MPC-based custody specifically for the USDF stablecoin backing, separated from the trading engine. DefiLlama tracks Aster Bridge alongside several related Aster-family products — Aster asBNB, Aster asBTC, Aster USDF, and APX Bridge — raising the same kind of double-counting question flagged elsewhere in this backlog, unresolved in this review.

Control and governance

No named multisig, security council, or specific admin, pause, or upgrade-key structure for the bridge or core contracts was found in this pass despite checking Aster’s own documentation directly. YZi Labs, a venture vehicle associated with CZ and managing funds for early Binance executives, holds a minority stake; CZ states his own role is advisory only. The absence of any disclosed control structure is a real, unresolved gap, not merely an unfavorable one.

Incident record and data-integrity concerns

No confirmed smart-contract exploit of Aster or Aster Bridge was identified. The material concerns instead center on data integrity and concentration: DefiLlama briefly delisted Aster’s self-reported perpetuals volume data over unverifiable wash-trading concerns, with DefiLlama’s own head citing an inability to verify the figures; reporting describes six wallets holding more than 96% of ASTER token supply; and a CZ endorsement post triggered a roughly 400% price spike that drew insider-trading speculation Aster’s CEO has denied, with no independent confirmation found either way. A separate competitive dispute — OKX’s founder calling Aster a Binance-backed copy of Hyperliquid — is reputational, not a security finding, and is noted only for completeness.

Exit

Aster states withdrawals require no approval and users retain key control throughout, a better-disclosed exit story on paper than several already-rejected bridges in this registry. This claim was not independently stress-tested in this review; no confirmed report of withdrawal delay or failure was found, but no third-party verification was found either.

Comparison

Against Hyperliquid Bridge and Unit, both rejected in this registry for unverifiable or thin trust models, Aster’s stated non-custodial, no-approval-withdrawal design is a better-disclosed mechanism on paper, but it substitutes a different unresolved risk: no disclosed admin or pause authority, unverifiable self-reported volume data flagged by this registry’s own trusted data source, and extreme token-holder concentration tied to a team under active reputational scrutiny for unconfirmed insider-dealing allegations.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.