Overview
Bullbit engaged Hacken to assess the full path of user funds through its cross-chain trading system: the Cosmos appchain that settles deposits, the Solidity contracts on Base that hold them, and the governance router that controls both.
Hacken conducted three linked audits between 4 and 28 September 2026. None recorded a Critical-severity finding.
About Bullbit
Bullbit is a trading protocol that connects a Cosmos-based settlement chain with liquidity on Base. Users deposit USDC or BUBI into a vault contract on Base and receive a matching credit on the Bullbit chain. Withdrawals are paid out on the source chain once the chain's validators attest to them.
Because validators decide which deposits settle, the security of user funds depends on how they observe Base as much as on the contracts that hold the assets.
Audit Approach
Hacken assessed the system in three reports, each scoped to fixed commits and re-verified against remediation commits before the final report:
- Blockchain protocol: bridge, asset and admin modules, deposit worker and vote-extension settlement path
- EVM bridge contracts: vault, deposit factory, forwarder and digest library
- Bridge governance: the router that owns the bridge contracts
Hacken applied its blockchain protocol methodology to the appchain and its smart contract methodology to the Solidity code. Reviewing chain and contracts in one engagement allowed issues at the boundary between them to be traced end to end. Both High-severity findings were spotted in the protocol layer.
Key Findings
The most significant finding concerned how validators verified deposits. Source-chain remote procedure call (RPC) endpoints were stored in shared chain state, and verification accepted the first endpoint that responded. Honest validators therefore, relied on the same data source, so the quorum did not represent independent observations. Deposits were changed to settle only when a supermajority of configured endpoints return matching decisions, and the residual risk of correlated providers was documented.
The second High-severity finding concerned consensus determinism. A cache shared across the asset module's components could let a historical query on one validator change how a later update was applied, leaving validators with different state. Hacken demonstrated the issue with a regression test. The cache was removed, and consensus reads now come from the current block's state.
A third group of findings concerned consistency between documentation and code. A governance upgrade path accepted arbitrary instructions outside the router's whitelist, published documentation described forwarder deployment as permissionless where the code restricted it, and a signature helper substituted its own chain identifier for the one supplied. The upgrade path was removed, the documentation corrected, and the helper changed to reject mismatches.

Audit Results
The final reports record 20 findings across three audits:
Following remediation, 19 findings were resolved and 1 was mitigated. The mitigated finding concerned the handling of RPC URLs that contain secrets.
“Validator-attested bridges hold user funds on one chain on the strength of decisions made on another, so security has to cover the whole path. Independent review of the protocol, the contracts and the governance that controls them is how we test that path before users rely on it. Working with Hacken is part of our commitment to Bullbit's users.” – George Anthony, CEO at Bullbit
Key changes delivered:
- Deposit settlement was placed behind matching decisions from a supermajority of configured RPC endpoints
- The shared asset cache was removed from consensus reads
- The arbitrary-calldata upgrade route was removed from the governance router
- Withdrawal signature handling was changed to reject chain identifier mismatches and non-standard signature encodings
Read the full Hacken audit reports: https://hacken.io/audits/bullbit/
Request a Smart Contract Audit
Hacken provides blockchain protocol and smart contract security audits for bridges, appchains and the governance systems that control them.
Each engagement combines automated analysis, manual security review and proof-of-concept development, performed by Hacken's in-house security team.



