Case Study

Babylon x Sherlock: Hardening the ZK Infra Behind Native Bitcoin DeFi

8
High Severity Vulnerabilities
55
Medium Severity Vulnerabilities
Babylon x Sherlock: Hardening the ZK Infra Behind Native Bitcoin DeFi
Case Study

Babylon x Sherlock: Hardening the ZK Infra Behind Native Bitcoin DeFi

8
High Severity Vulnerabilities
55
Medium Severity Vulnerabilities
Table of Content

About Babylon

Babylon Labs is building the infrastructure that turns Bitcoin into programmable capital. Its work in Bitcoin staking has helped define a new category of Bitcoin-native utility, giving holders ways to put BTC to work while preserving the security properties that make the asset distinctive.

Trustless Bitcoin Vaults extend that vision into DeFi. The protocol enables Bitcoin holders to use native BTC as collateral in applications on Ethereum while the underlying asset remains secured on Bitcoin. Custody stays with the user, and cryptographic proofs carry verified state between the two networks.

This places Babylon at the center of one of the most ambitious opportunities in crypto: connecting Bitcoin liquidity to onchain financial markets through verifiable computation. It also places the protocol at a frontier where Bitcoin architecture, ZK systems, and DeFi accounting must operate as one coherent system.

What Trustless Bitcoin Vaults change

Trustless Bitcoin Vaults advance a simple user promise through a highly sophisticated architecture. A Bitcoin holder can access DeFi utility while the underlying BTC remains secured on Bitcoin.

One user promise, three systems

  1. Secure native BTC on Bitcoin. The holder locks BTC in a user-controlled Bitcoin vault.
  2. Activate collateral on Ethereum. The vault connects to a bespoke Aave V4 integration, where the position can support lending activity.
  3. Prove and enforce redemption. An SP1 zkVM program proves the corresponding Ethereum event, and Babylon's BaBe protocol makes that proof enforceable through Bitcoin-native primitives and a pre-signed transaction graph.

Every layer must preserve the same meaning as state moves through the system.

Bitcoin, Ethereum, ZK proof generation, Bitcoin Script, and offchain participant software each carry part of the same transition. Babylon is helping set the technical direction for this vertical by showing how native BTC can participate in DeFi while remaining anchored to Bitcoin. Trustless Bitcoin Vaults offer a blueprint for a broader Bitcoin economy built around cryptographic enforcement.

Security goals for a category-defining system

Babylon approached security at the level of the complete protocol. From March to May 2026, Sherlock reviewed six repositories across the complete TBV stack.

The scope covered the SP1 program, BaBe cryptography, the Bitcoin transaction graph, Ethereum contracts, and the offchain services responsible for proving, indexing, monitoring, and orchestration. It also included the front-end web application through which users interact with TBV and its Aave V4 integration.

Does every layer enforce the same rule under adversarial conditions?

The engagement followed that question across three recurring security goals:

  • Proof statements and public inputs that preserve the intended state.
  • Agreement between Rust logic, Bitcoin Script, and onchain verification.
  • Challenge, recovery, and operational paths that remain dependable under unexpected inputs.

These goals carry special weight in ZK architecture. A valid proof establishes that a witness satisfies an encoded statement. End-to-end security also depends on the circuit expressing the intended statement, each verifier authenticating the correct inputs, Bitcoin Script enforcing compatible constraints, and the surrounding software remaining able to respond when behavior departs from the expected flow.

Babylon understood that the highest-value review would follow those properties across repository and language boundaries. Sherlock structured the engagement around that goal, tracing assumptions from Ethereum events through proof generation and into the Bitcoin challenge flow.

An audit built around the architecture

Following the guarantee across every boundary

Sherlock and our elite auditing group Blackthorn structured the security review as an architecture-first collaborative audit. Researchers began with the protocol's intended guarantees, then followed each guarantee through code, constraints, scripts, transactions, and operational services. They compared implementations of the same rule, tested adversarial inputs, and examined the recovery paths that protect the system when participants deviate from the expected flow.

This approach was especially valuable at the boundaries between protocol components. Researchers examined whether shared validation rules were enforced consistently across implementations, including under unexpected inputs and during recovery. The review reinforced a defining principle of ZK security: cross-system agreement deserves the same rigor as the underlying cryptography.

The same reasoning extended through BaBe, the Bitcoin transaction graph, prover services, and the Ethereum integration. On the Aave V4 side, the team examined how indivisible Bitcoin UTXOs interact with fungible DeFi accounting, including collateral activation, withdrawal, and liquidation behavior.

Babylon worked closely with researchers as the review progressed. The team hardened the cryptographic library, strengthened validation across system boundaries, and expanded testing around malformed inputs, recovery behavior, cut-and-choose selection, signature validation, and serialization. Sherlock then completed a dedicated post-audit review of the hardened library and verified the remediation work.

Outcomes and what Babylon strengthened

Across six repositories, the engagement identified 8 High and 55 Medium-severity findings, alongside roughly 100 lower-severity and informational issues. The results reflected the breadth and complexity of securing a system spanning Bitcoin, ZK, Ethereum, and offchain infrastructure. All High and Medium findings were resolved or formally acknowledged, and Sherlock verified the submitted fixes through remediation and a dedicated hardening review.

The outcome extended well beyond individual fixes. Babylon emerged with a stronger cryptographic library, tighter agreement across Bitcoin and Rust implementations, more defensive recovery logic, and a broader adversarial test suite. Protocol assumptions moved into enforceable code paths and repeatable tests, creating a stronger foundation for continued development.

Babylon is defining how native Bitcoin can participate in a cryptographically enforced DeFi economy. The work with Sherlock reflects the standard required to lead that category: ambitious architecture, specialized review, close technical collaboration, and a commitment to strengthening the system before broader use.

ZK security is usually invisible. Babylon made the work visible, testable, and stronger.

Sherlock helps leading protocols prepare for production - work with us when your system demands the same depth of review.

How Babylon and Sherlock strengthened the proof systems, Bitcoin logic, and DeFi integration behind Trustless Bitcoin Vaults.
Categories
  • Bitcoin Infrastructure
  • Bitcoin-Native DeFi
  • ZK Infrastructure
Services & Solutions
  • Native BTC Staking
  • Self-Custodial BTC Vaults
  • Ethereum DeFi Access
Learn More