Centrifuge Protocol

Green · 77/100

Executive summary

Centrifuge Protocol is a real-world asset (RWA) tokenization and structured-credit platform enabling onchain distribution of private credit, tokenized funds, and real estate across Ethereum, Base, Arbitrum, Avalanche, and other chains, scoring 74/100 (green band) with high data confidence (91/100).

  • Security: 24+ audits from tier-1 firms (Cantina, Code4rena, Spearbit, Sherlock, BurraSec, yAudit) covering liquidity pools, cross-chain messaging, and onchain portfolio management; October 2023 Cantina audit found 0 critical/high, 5 medium (fixed), 4 low (3 fixed, 1 acknowledged); July 2024 Cantina/Spearbit review found 1 critical, 1 high, 2 medium (all fixed); active $250k bug bounty on Cantina; bytecode-match to deployed contracts unverified as of September 2026.
  • Incidents: Zero exploits since 2019 mainnet launch per protocol disclosure; two bridge failures (August and October 2024) caused by runtime/rate-limiting issues affecting 1.33M CFG total across five wallets, fully reimbursed via governance; no attacker proceeds or user losses.
  • Governance & custody: Materially foundation-controlled; CP171 (November 2025) paused routine DAO governance, transferring treasury and operations to Centrifuge Network Foundation (CNF) under board oversight; CFG holders retain reinstatement rights (4M CFG quorum required); ProtocolGuardian multisig controls emergency pause, upgrades, and cross-chain operations with 48-hour timelock; pool managers control pricing, NAV, and redemptions, creating concentrated operational risk.
  • Top risks: Off-chain asset credit/valuation risk (pool tokens depend on borrower performance, servicer integrity, and NAV accuracy—all largely off-chain); privileged pool administration (hub managers can set oracles, accounting, and cross-chain security with limited real-time oversight); cross-chain messaging risk (hub-and-spoke architecture using LayerZero, Wormhole, Chainlink, Axelar exposes supply/redemption synchronization and bridge failure); liquidity execution (redemptions are request-based, subject to manager processing, available liquidity, and product cadence, with potential delays or partial fulfillment).
  • Strengths: Purpose-built RWA infrastructure with multi-chain deployment and chain abstraction; strong DeFi composability via ERC-4626/ERC-7540/ERC-7575 standards; modular, extensible design (immutable core plus configurable extensions); automated onchain double-entry accounting; reputable VC backing (Coinbase Ventures, Galaxy Digital, IOSG, BlockTower) and $15.8M raised; zero historical exploits.
  • Unverified: Circulating supply conflicts (CoinMarketCap: 577M CFG, $58M market cap; CoinGecko: 380M CFG, $39M market cap); treasury size, composition, custody arrangements, and current multisig signers unverified as of September 2026 (Dune unavailable); per-chain TVL breakdown, pool-level positions, and deployed-bytecode verification unverified; Chronicle oracle partnership is marketing claim, not independently confirmed.
  • Recommended exposure: Conservative position sizing (≤5% of portfolio) given off-chain asset dependence and concentrated governance; allocate only to pools with transparent NAV methodology, reputable managers, senior/junior tranching, and documented legal structure; verify manager multisig configuration, cross-chain adapter settings, and redemption terms before deposit; monitor NAV updates, pool liquidity, and governance proposals for operational changes; treat as credit/duration exposure, not market-neutral DeFi.
  • Open questions: Verify current treasury custody (signers, thresholds, legal arrangements); confirm bytecode match between audited code and deployed contracts on each chain; review specific pool legal structure (SPV jurisdiction, servicer agreements, custody, enforceability); assess manager key-management practices (multisig vs. EOA, signing policy); clarify CFG circulating supply and market cap discrepancy; evaluate cross-chain message confirmation settings and adapter failure modes; confirm withdrawal processing times and liquidity availability for target pools.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 35 audit(s); continuous security program bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-01)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 9 1.8 TVL $1,505,366,973 = 9% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 42/76 verified facts; 76/76 fresh (180d)

Identification

protocol identification

two sources

Identification. Name: Centrifuge Protocol. Website: centrifuge.io; docs: docs.centrifuge.io. Category: RWA/tokenized-asset infrastructure and on-chain asset management.

Lineage launch: Centrifuge originated in 2017; its first public mainnet generation launched in 2019, Tinlake/V1 followed in 2020, and current V3 launched July 24, 2025. Native token: CFG. The current token is Ethereum-native ERC-20 at 0xcccCCCcCCC33D538DBC2EE4fEab0a7A1FF4e8A94; legacy CFG from Centrifuge Chain and WCFG were consolidated 1:1 under CP149.

Chains. The supplied scope is incomplete versus current documentation: Ethereum, Base, Arbitrum, Avalanche, Plume, BNB Smart Chain, Optimism, HyperEVM, Monad, Pharos and X Layer are documented; Solana and Stellar are also assigned Centrifuge IDs. “OP Mainnet” corresponds to Optimism. Main contracts. Official V3 deployment addresses include Hub 0xA4A7Bb3831958463b3FE3E27A6a160F764341953, Hub Registry 0x19f46D8130e610C6C0f0116EA40Fb781dEFaDE93, Accounting 0x050206c38f06e4710C4a37D39F75Ddc5c16a7396, Holdings 0x3f0c8D8d2637881c3f6d8531F51a47c2094C918d, and Share Class Manager 0xaFFC269c8fe18EE9C7DDb22301AC2c2507d69BEf. Required two-source cross-check including Dune: Not verifiable as of September 4, 2026 (Dune MCP unavailable).

Explorer verification: CFG is explorer-labelled and source-listed on Routescan/BscScan; Hub activity is visible on Etherscan, but source-code verification status for the listed core contracts is Not verifiable as of September 4, 2026. Sherlock independently verified the deployment; this is not explorer verification. Fork lineage. No evidence that Centrifuge V3 is a fork of an external DeFi protocol; it is a first-party successor to Centrifuge V1/Tinlake and V2, with a new immutable, modular, hub-and-spoke EVM architecture.

V3/V3.1 received multiple reviews/audits. Malicious-modification history in similar forks: Not verifiable as of September 4, 2026.

Evidence (6)

maturity

unverified

Centrifuge appears to be a real production portal, not just a landing page: the official app site is live, and the docs describe an operating ecosystem with SDKs, API access, pools, vaults, and deposit/redemption flows. The protocol also exposes a public, read-only GraphQL API with no authentication required, so it does have an open API. The maturity signal is better than a static marketing site because the docs explicitly cover vault operations, ERC-4626/ERC-7540 flows, and developer integration, and the app site references product/documentation/security sections rather than placeholder content.

However, live withdrawal/deposit functionality cannot be independently verified here beyond the documentation claims, so that remains Not verifiable as of 2026-09-04. I did not see clear evidence of fake metrics, template-only behavior, or obviously broken-link issues in the material retrieved, but that is also Not verifiable as of 2026-09-04. The strongest verified conclusion is that Centrifuge operates a functional protocol portal with a public API and substantial developer documentation, while the exact live state of user-facing deposits/withdrawals should be treated as unverified from this pass.

Evidence (6)

Security

bug bounty

two sources

Centrifuge has an active bug bounty program hosted on Cantina. It started on 17 Jul 2025 and, per the program page, covers the protocol and the V3.1 upgrade. The stated reward structure is $250,000 maximum for critical issues, $50,000 for high severity, and $5,000 for medium severity.

Reported findings on the program page total 501. The Centrifuge security page also describes in-scope software/infrastructure only, first valid submission only, and rewards ranging from 100 DAI to 50,000 DAI, which appears to be an older or alternate disclosure description and is not fully consistent with the Cantina bounty page.

Active
Yes
Platform
Cantina
Max payout
$250K
Since
2025-07-17
Evidence (4)

counterparty risks

unverified

Assessment (as of September 6, 2026): Centrifuge’s principal counterparty risk is at the pool/product level, not the base token. Each pool is operated by a manager and can represent an off-chain fund or credit strategy; investors’ claims depend on the issuer, SPV/legal structure, servicer, bank/custody arrangements, valuation process, and redemption terms. Historical Centrifuge onboarding materials explicitly require an SPV, bank accounts, on/off-ramps, and service agreements. Oracle/NAV risk: Pool managers control pricing and settlement decisions.

The current architecture supports identity pricing and oracle-based valuation; non-1:1 deposit assets require a hub-chain oracle. A bad NAV, stale valuation, oracle compromise, or manager key compromise could cause mispriced issuance/redemptions or unbacked shares. Chronicle is described by Centrifuge as its primary oracle partner, but this is an unverified marketing claim rather than an independent confirmation. Bridge/messaging risk: Cross-chain pools use hub-and-spoke messaging and configurable adapters including LayerZero, Wormhole, Chainlink, and Axelar; share tokens use native mint-and-burn bridging.

Adapter failure, message replay/censorship, chain halt, or incorrect configuration could desynchronize supply, freeze redemptions, or create unbacked representation on a spoke chain. DeFi/stablecoin exposure: Documented integrations/workflows include Sky/USDS, Aave, Morpho, Circle CCTP/USDC, and USDT0. These create secondary dependencies on stablecoin reserves/depegs, lending-market liquidity, collateral parameters, and bridge infrastructure. Current balances, concentration, CEX/market-maker exposure, LST/restaking exposure, named custodians, and pool-by-pool issuer/SPV exposure are Not verifiable as of September 6, 2026 because on-chain verification is unavailable in this run. Failure scenarios: issuer/SPV insolvency or fraud; loan-servicer default; custodian/bank failure; oracle/NAV manipulation; stablecoin depeg; bridge/message failure; or illiquidity during queued redemptions.

Protocol audits and a stated bug bounty reduce smart-contract risk but do not eliminate legal, operational, valuation, or asset-level losses. On-chain concentration / maximum exposure: Not verifiable as of September 6, 2026. dependency_failure_active: null max_exposure_pct: null

Evidence (7)

crypto custody

unverified

Centrifuge’s crypto custody appears organized in two layers: protocol-level custody is handled by open-source smart contracts that users interact with directly, while institutional custody for tokenized RWA pool investments is offered through Finoa, a regulated crypto custodian, for supported users. Centrifuge’s pool structure also uses a separate SPV per pool, with legal ownership of the underlying assets transferred to that SPV to keep pool assets bankruptcy-remote from the originator. Withdrawal status is not verifiable as of 2026-09-06.

Segregation is supported at the pool/legal-entity level via separate SPVs, but asset segregation for all crypto holdings is not fully verifiable as of 2026-09-06.

Segregated assets
Yes
Evidence (3)

incident

one source

Since mainnet launch in 2019, Centrifuge states it has had 0 exploits; I found no independently verified incident report showing a loss, affected users, reimbursement, or post-incident fix. The closest corroboration is an independent media writeup repeating the zero-exploit claim and noting 480 bounty findings to date.

Date
2019-01-01
Cause
Other
Evidence (2)

incident

unverified

Reported August 19, 2024; four failed bridge transactions occurred during the preceding ~30 days. Cause: CFG↔wCFG bridge execution/runtime failure; source-chain tokens were deducted but destination tokens were not minted or wrapped. Affected: four wallets; 705,001.01 CFG total, including bridge fees.

USD loss: Not verifiable as of September 6, 2026. No attacker or exploit proceeds were reported. Response/fix: the bridge issue was identified and fixed; CP126 authorized minting and force-transferring replacement CFG to all affected wallets.

Reimbursement: yes; governance reported all funds distributed on September 2, 2024. Recovered USD: Not verifiable as of September 6, 2026. Current status: resolved.

Date
2024-08-19
Cause
Bridge / third-party collateral failure
Attacker proceeds
$0
Status
resolved
Reimbursed
Yes
Event id
centrifuge-cp126-bridge-failures-2024-08
Evidence (2)

incident

unverified

Incident occurred October 3, 2024 at 04:56:54 UTC. Cause: CFG→wCFG bridge transfer failed because Infura endpoint rate limiting prevented the Ethereum-side query; source tokens were deducted but destination wCFG was not minted. Affected: one wallet; 626,170.8929 CFG including the 100 CFG bridge fee.

USD loss: Not verifiable as of September 6, 2026. No attacker or exploit proceeds were reported. Response/fix: Centrifuge switched the bridge integration to Tenderly endpoints; CP131 authorized minting and force-transferring the missing amount.

Reimbursement: yes; referendum 65 passed and funds were minted and transferred on October 18, 2024. Recovered USD: Not verifiable as of September 6, 2026. Current status: resolved.

Date
2024-10-03
Cause
Bridge / third-party collateral failure
Attacker proceeds
$0
Status
resolved
Reimbursed
Yes
Event id
centrifuge-cp131-bridge-failure-2024-10-03
Evidence (2)

incident

unverified

Centrifuge runs an active bug bounty program with a $250,000 maximum reward on Cantina; the program page indicates it is in scope for protocol security issues and excludes current/former contributors from eligibility.

Date
2025-07-17
Cause
Other
Evidence (2)

key management

unverified

Key-management organization — Centrifuge Protocol

  • Protocol-wide administration: An immutable Root contract holds administrative authority, but has no direct external access. Control is mediated through two separate Safe multisig guardians: ProtocolGuardian for emergency response, upgrades, pausing, and cross-chain operations; and OpsGuardian for routine operational tasks such as adapter initialization, network wiring, and pool creation. OpsGuardian does not have pause authority.
  • Delay and emergency controls: Privilege escalation through Root is subject to a 48-hour timelock. The ProtocolGuardian can respond to emergencies immediately, while full resumption requires multisig consensus. A global pause stops cross-chain messaging but does not stop local vault deposits, redemptions, or withdrawals.
  • Pool-level keys: Centrifuge uses scoped roles rather than one universal pool administrator. The hub manager controls pool configuration, pricing, accounting, cross-chain deployment, and appointment of other roles. Documentation recommends a multisig or institutional-grade MPC wallet; a single EOA is discouraged. A compromised hub manager represents near-total pool-level compromise because it can appoint other managers and reconfigure cross-chain security.
  • Segregation of duties: Asset movement is assigned separately to balance-sheet managers, generally per chain. Centrifuge recommends purpose-built manager contracts or multisigs. Request managers are contract roles, while relayers and Onchain PM strategists may use hot keys/bots whose permissions are constrained by approved destinations, policy roots, and guards. Gateway managers provide pool-specific cross-chain circuit breakers.
  • Operational controls: Administrative access reportedly requires hardware-based 2FA; sensitive deployments/configuration changes require multisignature authorization. Credentials are managed through password managers and cloud KMS, with least privilege, quarterly access reviews, and credential rotation. These are protocol-reported controls and therefore unverified marketing claims absent independent evidence. Not verifiable as of September 4, 2026: Safe signer identities, signer counts/thresholds, individual key-custody arrangements, backup/recovery procedures, key-ceremony evidence, and actual MPC usage. Dune/on-chain verification was unavailable for this assessment.
Evidence (4)

smart-contract

one source

Assessment date: September 6, 2026. Known addresses. Official deployment documentation lists v3.1.0 commit 6b9d36e…c555, with core addresses including Hub 0xA4A7Bb3831958463b3FE3E27A6a160F764341953, Spoke 0xEC3582fcDc34078a4B7a8c75a5a3AE46f48525aB, Balance Sheet 0x12a110cE5f0FC871cC72Bc7ECaF35cf39DD0f43e, Gateway 0x19a524D03aA94ECEe41a80341537BCFCb47D3172, Contract Updater 0x3B150B19245D2C366bc8f18c775b725DFB298F71, Root 0x7Ed48C31f2fdC40d37407cBaBf0870B2b688368f / 0xdc9456e7e20f15029C8231Ec433a20F404b7235E, and Protocol/Ops Guardians 0xCEb7…35c6 / 0x0555…0dE. The page does not map every address to each requested chain; Pharos is absent from the Guardian address table. Per-chain address verification: Not verifiable as of September 6, 2026. Architecture. Protocol/Ops Safe → Guardian → Root (immutable ward registry) → Hub/Spoke/Gateway/Factories Hub → ContractUpdater → trusted cross-chain parameter updates Spoke → BalanceSheet/escrow → vaults/share tokens The core is described as immutable, non-proxy/monolithic; extensions are modular and pool-configurable. No proxy implementation/admin was identified in the reviewed materials. Admin powers and failure modes. ProtocolGuardian controls emergency response, pausing, protocol-level changes and cross-chain operations; OpsGuardian handles pool creation, wiring and adapter initialization but reportedly cannot pause.

Pool hub managers can set prices/oracles, accounting, vaults, adapters, managers and investor-request settlement. Balance-sheet managers can move escrow assets and issue/revoke shares. A compromised hub manager can appoint roles; a compromised balance-sheet manager can lose assets on its assigned chain.

Local deposit/redeem/withdraw functions are reportedly unaffected by the global cross-chain pause, so users may exit where liquidity and pool rules permit. A compromised protocol admin could nevertheless freeze cross-chain activity, manipulate configuration/pricing, appoint asset-moving managers, or cause cross-chain accounting/issuance failures. Timelock / renouncement / proxy-admin type / decoded events. On-chain verification was unavailable: Not verifiable as of September 6, 2026. Documentation claims a 48-hour Root timelock and separate Safe guardians, but does not prove current signer thresholds or delay state. Contradiction: documentation calls the core “fully immutable,” while also describing ProtocolGuardian authority over “upgrades.” Treat upgrade scope as unresolved until bytecode/proxy slots and Root events are checked on-chain. Audits include Sherlock deployment verification and multiple v3.1 reviews; unresolved severity counts were not established from the available reports.

Admin can drain
Yes
Audited deployment
Yes
Upgradeable
No
Evidence (5)

audit

one source

out-of-scope audit report — v3.3.0; file docs/audits/out-of-scope/v3.3.0.md in centrifuge/protocol (protocol audit catalog).

Auditor
out-of-scope
Scope
v3.3.0
File
v3.3.0.md
Catalog only
Yes
Evidence (1)

audit

one source

burraSec audit report; file docs/audits/2025-05-burraSec.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec
Report date
2025-05
Scope
protocol
File
2025-05-burraSec.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec audit report; file docs/audits/2025-08-burraSec.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec
Report date
2025-08
Scope
protocol
File
2025-08-burraSec.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec audit report; file docs/audits/2025-09-burraSec.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec
Report date
2025-09
Scope
protocol
File
2025-09-burraSec.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec audit report; file docs/audits/2025-10-burraSec.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec
Report date
2025-10
Scope
protocol
File
2025-10-burraSec.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec 1 audit report; file docs/audits/2025-04-burraSec-1.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec 1
Report date
2025-04
Scope
protocol
File
2025-04-burraSec-1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec 2 audit report; file docs/audits/2025-04-burraSec-2.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec 2
Report date
2025-04
Scope
protocol
File
2025-04-burraSec-2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec bridge audit report; file docs/audits/2026-07-burraSec-bridge.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec bridge
Report date
2026-07
Scope
protocol
File
2026-07-burraSec-bridge.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec onchain pm audit report; file docs/audits/2026-04-burraSec-onchain-pm.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec onchain pm
Report date
2026-04
Scope
protocol
File
2026-04-burraSec-onchain-pm.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec ShareManager audit report; file docs/audits/2026-08-burraSec-ShareManager.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec ShareManager
Report date
2026-08
Scope
protocol
File
2026-08-burraSec-ShareManager.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec v3.3 audit report; file docs/audits/2026-07-burraSec-v3.3.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec v3.3
Report date
2026-07
Scope
protocol
File
2026-07-burraSec-v3.3.pdf
Catalog only
Yes
Evidence (1)

audit

one source

burraSec v3.3 audit report; file docs/audits/2026-08-burraSec-v3.3.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
burraSec v3.3
Report date
2026-08
Scope
protocol
File
2026-08-burraSec-v3.3.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Cantina audit report; file docs/audits/2023-10-Cantina.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Cantina
Report date
2023-10
Scope
protocol
File
2023-10-Cantina.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Cantina audit report; file docs/audits/2025-02-Cantina.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Cantina
Report date
2025-02
Scope
protocol
File
2025-02-Cantina.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Cantina audit report; file docs/audits/2025-05-Cantina.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Cantina
Report date
2025-05
Scope
protocol
File
2025-05-Cantina.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Cantina audit report; file docs/audits/2025-08-Cantina.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Cantina
Report date
2025-08
Scope
protocol
File
2025-08-Cantina.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Centrifuge RWA Protocol / liquidity-pools security review. Findings shown in the summary: 1 critical, 1 high, 2 medium, 25 low, 60 informational, 8 gas findings. Fix status in the summary: critical/high/medium were fixed; low had 16 fixed and 9 acknowledged; informational had 36 fixed and 24 acknowledged; gas had 7 fixed and 1 acknowledged.

Bytecode-match/deployed-code coverage: Not verifiable as of 2026-08-30 from the surfaced summary.

Auditor
Cantina / Spearbit
Report date
2024-07-28
Scope
liquidity-pools / core components, operator controls, tranche safety, gateway messaging, asset recovery
Evidence (1)

audit

one source

Code4rena audit report; file docs/audits/2023-09-Code4rena.md in centrifuge/protocol (protocol audit catalog).

Auditor
Code4rena
Report date
2023-09
Scope
protocol
File
2023-09-Code4rena.md
Catalog only
Yes
Evidence (1)

audit

unverified

The December 2025 V3.1 audit competition report is attributed to two auditors; split into separate auditor items per instruction.

Auditor
Sherlock
Report date
2025-11-12
Scope
V3.1
Findings
Critical: Not verifiable as of 2026-09-06; High: Not verifiable as of 2026-09-06; Medium: Not verifiable as of 2026-09-06
Fix status
Not verifiable as of 2026-09-06
Report url
https://github.com/centrifuge/protocol/blob/main/docs/audits/2025-12-Sherlock-Blackthorn.pdf
Report id
doc:c990e1a10272a01a
Evidence (1)

audit

one source

Remediation status corrected; bytecode match to deployed contracts remains unverified.

Auditor
Sherlock
Report date
2026-04
Scope
Onchain PM
Findings
Critical: Not verifiable as of 2026-09-06; High: Not verifiable as of 2026-09-06; Medium: Not verifiable as of 2026-09-06
Fix status
Protocol release states all reported findings resolved in v3.2.0; issue-level verification not verifiable as of 2026-09-06
Report url
https://github.com/centrifuge/protocol/blob/main/docs/audits/2026-04-Sherlock-onchain-pm.pdf
Report id
doc:dd700621fc2a8bb9
Evidence (1)

audit

one source

Centrifuge Chain audit of the Parity Substrate-based Centrifuge Chain (not the EVM deployment set). Scope: chain/security review of the Centrifuge Chain design and implementation. Findings in the report included document-consensus enforcement, fee-update, DoS, and block-proposer issues; the snippet does not provide a critical/high/medium count.

Fix status: some issues were reported as needing mitigation; exact closure status is Not verifiable as of 2026-08-30. Bytecode-match/deployed-code coverage: Not verifiable as of 2026-08-30.

Auditor
Least Authority
Report date
2020-04-03
Scope
Centrifuge Chain
Evidence (2)

audit

one source

Centrifuge docs list additional reviews for V3.1 and related components in 2025-2026, including yAudit, Sherlock, Blackthorn, BurraSec, xmxanuel, Macro, and others. The surfaced snippets confirm audit existence and rough scope labels, but not the detailed findings counts or bytecode-match/deployed-code coverage for each. Not verifiable as of 2026-08-30.

Auditor
Multiple (Centrifuge docs listing)
Report date
2025-01-01
Scope
V3.1 / gateway / spoke-vaults / adapters / deployment verification
Evidence (2)

audit

one source

Recon audit report; file docs/audits/2025-04-Recon.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Recon
Report date
2025-04
Scope
protocol
File
2025-04-Recon.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Sherlock — Feb 2026 — V3.1 deployment verification. Covers deployed code: Not verifiable as of 2026-09-05.

Auditor
Sherlock
Report date
2026-02
Scope
V3.1 deployment verification
Findings
Not verifiable as of 2026-09-05
Fix status
Not verifiable as of 2026-09-05
Evidence (1)

audit

one source

Sherlock Blackthorn audit report; file docs/audits/2025-12-Sherlock-Blackthorn.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Sherlock Blackthorn
Report date
2025-12
Scope
protocol
File
2025-12-Sherlock-Blackthorn.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Sherlock deployment audit report; file docs/audits/2026-02-Sherlock-deployment.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Sherlock deployment
Report date
2026-02
Scope
protocol
File
2026-02-Sherlock-deployment.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Sherlock onchain pm audit report; file docs/audits/2026-04-Sherlock-onchain-pm.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Sherlock onchain pm
Report date
2026-04
Scope
protocol
File
2026-04-Sherlock-onchain-pm.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Spearbit audit report; file docs/audits/2024-08-Spearbit.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
Spearbit
Report date
2024-08
Scope
protocol
File
2024-08-Spearbit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Centrifuge protocol security review listing a July 2024 Spearbit engagement for the protocol. The surfaced snippet confirms the review exists but does not expose severity counts, remediation status, or bytecode-match/deployed-code coverage. Not verifiable as of 2026-08-30.

Auditor
Spearbit / Centrifuge docs listing
Report date
2024-07
Scope
protocol security review
Evidence (1)

audit

one source

SRLabs audit report; file docs/audits/2023-09-SRLabs.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
SRLabs
Report date
2023-09
Scope
protocol
File
2023-09-SRLabs.pdf
Catalog only
Yes
Evidence (1)

audit

one source

xmxanuel audit report; file docs/audits/2025-03-xmxanuel.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
xmxanuel
Report date
2025-03
Scope
protocol
File
2025-03-xmxanuel.pdf
Catalog only
Yes
Evidence (1)

audit

one source

xmxanuel audit report; file docs/audits/2025-07-xmxanuel.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
xmxanuel
Report date
2025-07
Scope
protocol
File
2025-07-xmxanuel.pdf
Catalog only
Yes
Evidence (1)

audit

one source

xmxanuel audit report; file docs/audits/2025-12-xmxanuel.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
xmxanuel
Report date
2025-12
Scope
protocol
File
2025-12-xmxanuel.pdf
Catalog only
Yes
Evidence (1)

audit

one source

xmxanuel onchain pm audit report; file docs/audits/2026-03-xmxanuel-onchain-pm.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
xmxanuel onchain pm
Report date
2026-03
Scope
protocol
File
2026-03-xmxanuel-onchain-pm.pdf
Catalog only
Yes
Evidence (1)

audit

one source

yAudit audit report; file docs/audits/2025-07-yAudit.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
yAudit
Report date
2025-07
Scope
protocol
File
2025-07-yAudit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

yAudit audit report; file docs/audits/2025-10-yAudit.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
yAudit
Report date
2025-10
Scope
protocol
File
2025-10-yAudit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

yAudit audit report; file docs/audits/2026-01-yAudit.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
yAudit
Report date
2026-01
Scope
protocol
File
2026-01-yAudit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

yAudit v3.3 audit report; file docs/audits/2026-06-yAudit-v3.3.pdf in centrifuge/protocol (protocol audit catalog).

Auditor
yAudit v3.3
Report date
2026-06
Scope
protocol
File
2026-06-yAudit-v3.3.pdf
Catalog only
Yes
Evidence (1)

Team & Reputation

founders

two sources

Centrifuge appears to be a real, publicly identifiable team-led protocol rather than an anonymous web-front project. Independent coverage and ecosystem sources consistently identify the core founders as Lucas Vogelsang, Martin Quensel, and Maex Ament, with later leadership also naming Bhaji Illuminati, Anil Sood, Jeroen Offerijns, and others in public governance/docs. Founders / prior projects. Lucas Vogelsang is described as the CEO/founding engineer and is repeatedly linked to founding DeinDeal, which he sold, and to earlier work at Taulia; Martin Quensel is described as a co-founder/executive with prior SAP and Taulia background; Maex Ament is also listed among the founders in multiple third-party sources. The strongest repeated pre-Centrifuge outcome is Taulia, a working-capital / supply-chain-finance business that the team co-created before Centrifuge. Public vs anon / credibility. The team is materially public: named executives, role histories, and governance participants are visible in docs and third-party profiles, and there is no evidence in the gathered material of an anonymous founder set.

The team’s credibility is strengthened by repeat mentions of prior venture-backed startups and enterprise-fintech experience, but those are still off-chain, web-sourced claims rather than on-chain proof. Office / real business vs web front. I found evidence of a real operating company structure and governance stack, including a Centrifuge Labs/ Foundation-style organization, named officers, and governance roles, which is consistent with a bona fide business rather than a purely anonymous token website. However, a specific real-world office location or onshore/offshore incorporation structure was not verifiable as of 2026-09-04 from the gathered sources. Reality check. The main contradiction risk is that some pages present a polished institutional narrative, but the verifiable evidence here is limited to public team identities, prior startup history, and organizational references; the exact legal domicile and office footprint remain unconfirmed. That means the project looks like a real company with a public team, but jurisdictional substance is not verifiable as of 2026-09-04.

Evidence (7)

general reputation

two sources

Centrifuge currently has a mixed but generally positive institutional reputation, with strong investor backing and audit coverage, but some emerging AML-related scrutiny and the usual RWA/DeFi structural risks. Founders, investors, track record

  • Centrifuge (Tinlake / Centrifuge Chain) has been building since around 2019 and is positioned as a real‑world asset (RWA) DeFi lending protocol bridging TradFi and DeFi.
  • It has raised multiple rounds from reputable VCs and individuals, including Galaxy Digital and IOSG in a $4.3m SAFT round in 2021, Crane Venture Partners, Atlantic Labs, Mosaic Ventures, BlueYard Capital and others in earlier rounds, and a $4m strategic round in 2022 led by Coinbase Ventures, BlockTower, Scytale and L1 Digital.
  • Overall funding reported at about $15.8m across four rounds as of 2022. This backing from established investors is a positive reputational signal. Security posture, audits, bug bounty
  • Centrifuge reports 24+ security reviews across protocol and chain, including tier‑1 firms Spearbit, Blackthorn, SRLabs, Least Authority, ConsenSys Diligence, Cantina, Code4rena, Recon, and others.
  • A Cantina RWA protocol audit lists 5 findings, all fixed, none outstanding, with overall low risk findings. Code4rena’s contest found no high‑severity issues and 8 medium‑severity issues, plus lower‑severity items, which were subsequently triaged.
  • Centrifuge advertises 0 exploits since mainnet launch in 2019 and a bug bounty up to $250k on Cantina; these claims rely on project self‑reporting and should be treated as *unverified marketing claims* despite corroborating absence of reported exploits in major media. Legal / regulatory, AML, sanctions
  • A watchdog AML database reports allegations that Centrifuge’s Tinlake pools were used to facilitate money laundering via tokenized invoices and other RWAs. This indicates heightened AML/TF risk perception and potential future regulatory interest; no publicly documented enforcement actions or sanctions are evident in the retrieved data.
  • Kraken’s 2023 crypto‑asset statement profiles Centrifuge as a DeFi credit protocol with RWA pools and notes the funding history; listing by a regulated exchange implies at least some internal risk assessment, but is not a regulatory endorsement. Sentiment, criticisms, open concerns
  • Industry sentiment among DeFi/RWA participants is broadly constructive, emphasizing Centrifuge as an early RWA bridge with institutional partners; however, RWAs introduce off‑chain credit, legal‑enforceability, and KYC/AML dependencies that can fail outside of smart‑contract security.
  • Key unresolved concerns for an institutional risk memo:
  • AML/ML allegations around Tinlake pools and KYC/onboarding controls.
  • Jurisdictional and regulatory risk from operating structured credit–like pools across multiple chains.
  • Heavy reliance on off‑chain asset originators and legal structures, which are not fully transparent in publicly available documentation. On‑chain metrics, exploit history, and TVL by chain are Not verifiable as of 2026-09-05 under the current data‑source constraints.
Evidence (11)

Economy

TVL: $1.5B

model

one source

Assessment (checked September 6, 2026). Centrifuge is primarily an RWA tokenization and structured-credit platform, not a market-neutral trading strategy. Capital enters pools/vaults through stablecoins or other accepted investment assets; capital is deployed into tokenized private credit, Treasury/public securities, real estate and similar off-chain assets. Yield is mainly borrower interest, securities income and/or asset appreciation, less losses and manager/service fees—not DEX fees, liquidation income, restaking or recursive leverage.

Investor exposure is therefore directional to credit, duration, liquidity, valuation, legal-structure, issuer/servicer and underlying-asset risks. Tranching/collateral. Products may use senior and junior share classes; junior capital absorbs losses before senior capital. The collateral is the pool’s underlying RWA balance sheet, with valuation and pricing set by the manager/product methodology. Protocol-wide leverage, looping, restaking and external DeFi leverage are Not verifiable as of September 6, 2026; no such mechanism was identified in the reviewed documentation. Liquidity and gates. Redemptions are request-based for both synchronous and asynchronous vaults; fulfillment depends on manager processing, valuation, available liquidity and product cadence.

Deposit capacity can be capped. Legacy Tinlake used epochs, priority rules and potentially delayed/partial redemptions when liquidity was insufficient. Fees/revenue. Governance materials describe pool-level protocol fees, historically varying by pool type, including proposed/approved rates around 2–50 bps and legacy 40 bps structures. DeFiLlama currently reports 30-day fees of $6.09M, revenue of $481K, zero incentives and average supply APY of 9.12%; these are analytics-platform figures, not on-chain-verified results. TVL. DeFiLlama snapshot: $1.576B total; Ethereum $1.216B (77.2%), Avalanche $262.0M (16.6%), Base $55.1M (3.5%), Plume $21.4M, Monad $15.1M, Pharos $4.5M, BSC $1.0M and OP Mainnet $0.2M.

Reported 30-day trend: -3.3%. Dune total/by-product/by-chain TVL, historical trend, APY volatility and sustainability are Not verifiable as of September 6, 2026. Prior example.com links are placeholders and not usable evidence. Economic conclusion: yield appears predominantly organic asset yield, but the organic percentage is not measurable from available evidence; liquidity gates and off-chain credit risks are the primary constraints.

Evidence (6)

reserves

unverified

As of September 6, 2026

  • Liquid reserves / treasury size: Not verifiable as of September 6, 2026. Dune MCP was unavailable, so no latest-block balances, valuation, chain-by-chain exposure, or execution/query IDs can be supplied. Historical disclosures are stale: 23.725M CFG was reported for H2 2024, while a 2025 migration proposal described a 17.48M CFG transfer from the Polkadot DAO treasury to an Ethereum CNF wallet. These figures are not a current reserve balance.
  • Treasury addresses: Not verifiable as of September 6, 2026. The historical Polkadot treasury address was reported as 4dpEcgqJRyJK3J8Es6v8ZfVntV7c64Ysgcjd4hYwyGoFPWbg; the TAG funding wallet 4g2JJ7Lq56WgSvPdzsGuLQRbmU3EAQmYK8SH23JmWmi2j1iX is an advisory-group beneficiary, not proof of the treasury’s current custody.
  • Composition: A July 2025 governance discussion stated that approximately 99% of treasury assets were CFG, but this is an undated/uncorroborated forum statement and cannot establish current composition. Not verifiable as of September 6, 2026.
  • Custody and control: Current governance documentation says active DAO governance was paused after CP171 and that the Centrifuge Network Foundation (CNF), under board-led oversight, manages the treasury; CFG holders retain a process to reinstate DAO governance. This indicates concentrated administrative control, but does not identify signing thresholds, multisig signers, legal custody arrangements, or current wallet controls.
  • Reserve policy: CP107 required conservative treasury spending, consideration of treasury balance, and clearer objectives/reporting. No current minimum-reserve, liquidity, diversification, or asset-allocation policy was located. Not verifiable as of September 6, 2026.
  • Attestations / proof of reserves: Not verifiable as of September 6, 2026. No independent reserve attestation or current treasury assurance report was located. Contradiction / data-quality finding: CP166 labels 0xcccCCCcCCC33D538DBC2EE4fEab0a7A1FF4e8A94 as an “Ethereum CNF Treasury Wallet,” while Centrifuge’s token documentation identifies the same address as the CFG ERC-20 token contract. Treat that address as unverified treasury custody pending independent explorer/on-chain confirmation.
Evidence (5)

tokenomics

two sources

Native token: Centrifuge’s native token is CFG. The current token is an Ethereum ERC-20 at 0xcccccccccc33d538dbc2ee4feab0a7a1ff4e8a94; CP149 consolidated legacy CFG and WCFG 1:1. No canonical CFG contract is documented for Avalanche, BSC, Base, Monad, OP Mainnet, Pharos, or Plume.

Supply/valuation (web snapshot, September 4, 2026): Protocol documentation reports 697,164,473 total CFG. Market-data providers conflict: CoinMarketCap reports 577.15M circulating, $58.2M market cap and $69.5M FDV; CoinGecko reports 380M circulating and $39.5M market cap. > Contradiction: circulating supply and market cap differ materially across aggregators.

On-chain verification is unavailable in this run; Not verifiable as of September 4, 2026 which figure is correct. Utility/governance: CFG is the ecosystem/governance token. Legacy documentation also described transaction-fee use; current V3 documentation emphasizes governance and EVM composability. Governance oversight was assigned to the Centrifuge Network Foundation under CP171, while the DAO retains a possible future reassumption right.

Value accrual: CFG has 3% annual inflation, accruing to the treasury. No holder revenue share, staking yield, buyback, or burn program is documented. The protocol fee switch was reported on in Q4 2025, but fee proceeds are not specified as CFG distributions.

Unlocks/allocations: CP149 minted 115M CFG: 15M unlocked in May 2025 and 100M vesting linearly through April 2029. Current allocations: ecosystem/treasury 14.3%, team 12% vesting through May 2030, locked incentives 10.5% vesting to the treasury through April 2029; remaining stakeholder allocation vests through March 2028. Whether announced unlocks actually occurred on-chain: Not verifiable as of September 4, 2026.

Controls/concentration: Mint, blacklist, burn, transfer-tax, fee-switch permissions, controlling wallets, top-holder concentration, insider wallets, and team/investor/community sub-allocations: Not verifiable as of September 4, 2026. Liquidity/listings: Major spot venues include Binance, Coinbase, OKX, Bybit, Gate, MEXC, and Bitvavo. Main identified DEX market is Uniswap v4 Ethereum; reported liquidity was approximately $1.1M, with about $354K 24h volume in the cited snapshot.

Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

If bitcoin falls below $10,000, Centrifuge’s direct protocol mechanics are unlikely to be the primary pressure point; instead, risk comes from its stablecoin- and RWA-based credit exposure, cross‑chain liquidity fragmentation, and off‑chain borrower/asset stress. 1. Market/liquidity impact across chains

  • Centrifuge liquidity (~$1.6B) is spread across Ethereum, Avalanche, BNB Chain, Base, Optimism, Plume, Monad, Pharos and others.
  • A BTC crash typically drives broad risk‑off behavior: stablecoin redemptions, wider credit spreads, and reduced demand for yield products.
  • Likely effects: lower deposits into RWA vaults, higher redemption requests, slippage and APY compression in USDC pools on Avalanche, Base, Plume, Pharos, Monad, etc.
  • Multi‑chain architecture (hub-and-spoke) adds operational complexity in stress: moving liquidity between chains is slower and more costly when bridges and DEXs are crowded or impaired. 2. RWA / credit risk amplification
  • Centrifuge is a private credit / RWA protocol, where tokenized loans and funds (e.g., Apollo, Janus Henderson products) sit behind the on-chain vaults.
  • In a deep BTC drawdown, correlated macro stress can:
  • Increase default risk and downgrade risk in underlying credit portfolios.
  • Widen spreads, making mark‑to‑market valuations of RWA pools more volatile.
  • Token holders are exposed to custodial and regulatory risk: if an off‑chain servicer or SPV fails or is restricted, on‑chain claims may be hard to enforce. 3. Oracle and valuation risks
  • Centrifuge vault valuations rely on off‑chain data and oracles for credit, FX and rate inputs.
  • In a systemic crypto shock, oracle outages, stale data or manipulation can misprice RWA tokens, leading to:
  • Misstated NAVs and yield.
  • Wrongful liquidations or blocked redemptions if governance slows reaction. 4. Governance / operational risk
  • The protocol uses human‑in‑the‑loop governance and has undergone many audits, but response times in a fast selloff may be limited.
  • Cross‑chain coordination of emergency actions (pausing vaults, changing parameters) is operationally heavy. 5. Chain‑specific exposure (high level)
  • Current data (Bathymark, Token Terminal, DeFiLlama) indicates material USDC pool depth on Avalanche, Base, Plume, Pharos, Monad, plus hub exposure on Ethereum and BNB Chain.
  • Precise TVL per chain and stress propagation paths are Not verifiable as of 2026-09-04 without direct on‑chain inspection. Risk‑focus for an institutional portfolio: prioritize analysis of (i) underlying credit portfolios and servicers, (ii) oracle resilience, (iii) redemption mechanics and cross‑chain bridging under stress, rather than BTC price alone.
Evidence (10)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of Centrifuge’s largest collateral pool/token is a severe but plausible stress, and would primarily hit: (1) senior tranche investors in that pool, (2) CFG stakers exposed via Tinlake incentives, and (3) overall protocol confidence and new issuance. Key constraint: detailed on-chain positions per pool and chain are Not verifiable as of 2026-09-04, because Dune MCP is unavailable and underlying pool-level positions are not transparently aggregated across all chains. ### 1. Structural impact channels

  • Centrifuge finances real-world assets (RWA) via pool-specific SPVs issuing on-chain tranches (often through Tinlake; now also via Centrifuge Prime/DAOs). This creates asset-backed tokens, not generic DeFi collateral.
  • A 20% depeg here means the net asset value (NAV) of the largest pool (or its senior token) is marked down 20% versus previously assumed par. Main effects:
  • Senior investors: 20% instantaneous loss on that pool’s token holdings; depending on waterfall, juniors could be fully wiped while seniors take the residual loss.
  • Liquidity: secondary liquidity for that pool’s tokens likely dries up; bid–ask widens sharply, forcing further discounts.
  • Cross-protocol exposure: any DeFi integrations (e.g. use of Centrifuge pool tokens as collateral in other protocols) face immediate LTV breaches and forced deleveraging. ### 2. Chain distribution Centrifuge TVL is multi-chain (Ethereum historically dominant, expansion to Base, OP, Avalanche, BSC, and others), but exact TVL share per chain is Not verifiable as of 2026-09-04 without on-chain queries. Risk reading under the multi-chain rule:
  • If the largest pool is on Ethereum or a major L2, the 20% depeg will hit the majority of protocol economic value.
  • On minor chains (Monad, Pharos, Plume), effects are more contained but can still damage overall confidence. ### 3. Forward-looking stress effects Under a 20% largest-pool depeg, a conservative institutional read:
  • New issuance / origination: expect sharp slowdown as investors re-price RWA credit and structure risk.
  • Spread widening: all Centrifuge pools likely face higher required yields; weaker originators may lose access.
  • Governance / CFG token: CFG could sell off on perceived structural weakness; staking incentives may no longer compensate perceived credit risk.
  • Counterparty / legal risk: if the depeg stems from default or fraud in the underlying assets/SPV, litigation and recovery uncertainty become central. With no on-chain visibility this run, all numeric impacts beyond “20% NAV hit on largest pool” are Not verifiable as of 2026-09-04 and must be treated as scenario logic, not measured loss.
Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Insolvency of a top asset-side counterparty (e.g., largest real‑world asset pool borrower) in Centrifuge leads primarily to credit losses on senior/junior investors, not to smart contract failure. On-chain verification is not possible in this run: Not verifiable as of 2026‑09‑04. ### 1. Loss path

  • Event: Borrower in a Centrifuge pool (TINlake‑style RWA pool) defaults; underlying assets become illiquid or insufficient to cover outstanding DROP/TIN tokens.
  • On-chain effect: NAV/oracle or off-chain administrator marks down asset values; pool liabilities exceed asset value.
  • Smart‑contract mechanics:
  • Redemptions of senior (DROP) may be throttled or halted when over‑redeemed relative to collateral.
  • Junior (TIN) tranche absorbs first loss via reduced claim on pool assets; senior may then take loss if TIN is wiped out. ### 2. Who absorbs losses
  • First loss: Junior/equity tranche investors (TIN) structurally designed as first-loss capital; they are compensated ex‑ante via higher yields.
  • Second loss: Senior (DROP) investors if default losses exceed TIN buffer; their token redemption value falls below par.
  • Service providers (asset originator, servicer) typically do *not* automatically absorb losses unless specific guarantees exist off-chain (side letters, insurance, overcollateralization). These are legal, not protocol-level, and are "Not verifiable as of 2026‑09‑04" for each pool.
  • Centrifuge treasury/protocol: No standard automatic bailout at smart-contract level; any backstop would be via governance and off-chain resources. ### 3. Compensation mechanisms
  • Structural:
  • Priority waterfall: senior gets paid before junior from recoveries.
  • Junior receives higher ongoing yield as compensation for bearing insolvency risk.
  • Legal/off-chain: bankruptcy/insolvency process on the underlying SPV/borrower; recoveries later distributed through the pool contracts per waterfall. Specific guarantees/insurance: Not verifiable as of 2026‑09‑04. ### 4. Impact path through smart contracts
  • Pool contracts:
  • Update of asset valuations/NAV → reduced pool asset value.
  • New issuance may be paused; redemptions limited to available liquidity.
  • Token level: DROP/TIN balances unchanged, but redeemable value per token falls; secondary market prices (DEX) may gap down.
  • Cross-chain deployments (Base, OP, Avalanche, BSC, etc.):
  • If using canonical Ethereum pools, bridged representations reflect loss via price/NAV; chain-level exposure split: Not verifiable as of 2026‑09‑04. Overall, the smart contracts enforce the predefined waterfall; they do not socialise losses beyond the pool’s investor base unless governance explicitly intervenes off-chain or via new contracts.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

In a stress scenario where the Centrifuge DAO or foundation commits fraud, the main risks are concentrated governance, control over off‑chain real‑world assets (RWAs), and treasury custody, rather than purely on‑chain mechanics. 1. Governance & centralization risk

  • Active DAO governance is paused, with execution and treasury management shifted to the Centrifuge Network Foundation (CNF) and Centrifuge Labs under CP171.
  • Day‑to‑day protocol operations and treasury are “controlled unilaterally” by CNF/Centrifuge Labs, explicitly identified as a centralization vector.
  • Token holder “ultimate control” is *theoretical*: reactivating the DAO requires a 4m CFG quorum and off‑chain Snapshot process. In a fraud stress case (e.g., CNF/Labs misappropriating funds, manipulating pool approvals, or misleading disclosures), current structure means:
  • Operational decisions and treasury reallocation could be executed off‑chain or via controlled multisigs with limited real‑time community veto.
  • Token holders face coordination and quorum risk to reverse actions or re‑assert DAO control. 2. RWA structure & investor exposure
  • Centrifuge is an RWA protocol where asset managers tokenize and distribute funds on‑chain, investors get exposure through protocol pools.
  • CFG is a governance/coordination token, not a direct claim on underlying assets or revenues. If the DAO/foundation commits fraud (e.g., misrepresenting asset quality, side‑letter arrangements, or treasury support):
  • On‑chain positions (pools, tokens) may remain valid while off‑chain legal/regulatory processes determine recoveries.
  • CFG holders mainly suffer via token price, loss of protocol viability, and impaired governance credibility, not guaranteed asset recovery rights. 3. Chain / TVL distribution & systemic impact
  • Centrifuge runs EVM‑native smart contracts (current canonical CFG on Ethereum) following migration from a legacy chain.
  • Multi‑chain presence is recorded (Avalanche, BSC, Base, Ethereum, OP, etc.), but precise TVL split across chains is Not verifiable as of 2026‑09‑04 without direct on‑chain queries. In a fraud scenario, Ethereum‑based contracts and CNF‑controlled treasuries are the primary contagion channel; secondary exposures on other chains depend on bridged assets and mirrored pools, which are likewise Not verifiable as of 2026‑09‑04. 4. Regulatory / enforcement angle
  • No public records of fraud or enforcement actions specifically against Centrifuge’s DAO or foundation were identified in the gathered data; absence of evidence is not evidence of safety. Any such event would likely trigger:
  • Freezing or restructuring of off‑chain asset vehicles and custodial accounts.
  • Potential governance overhaul and CFG dilution or recapitalization. From an institutional risk lens, the key structural vulnerability is the paused, centralized governance and foundation‑controlled treasury, which amplifies downside if those actors themselves are the source of fraud.
Evidence (15)

stress scenario - primary yield source negative 30d,

two sources

Primary yield source for Centrifuge Protocol is fixed‑income real‑world assets (RWA) tokenized into onchain vaults and tranched pools, where depositors earn interest from underlying loans, credit products, and tokenized funds rather than purely crypto-native lending or trading fees. Any 30‑day negative move in this yield is therefore a reflection of underlying credit/interest‑rate dynamics, not just DeFi market volatility. Because Dune/on-chain queries are not available in this run, key on-chain metrics (per-chain TVL, realized APY, cashflows) are Not verifiable as of 2026-09-05. ### 1.

What “primary yield source negative 30d” likely means

  • Centrifuge’s main pools (e.g., USDS, AUSD, USDC stablecoin pools across Ethereum, Avalanche, Base, Plume, Pharos) earn yield from off-chain asset income (loan interest, fund coupons, etc.), structured into senior/mezzanine/junior tranches.
  • A negative 30‑day move could be:
  • APY compression (e.g., from ~4–5% toward 0–1%).
  • Net negative real yield after fees or losses (defaults, write‑downs, delayed repayments). ### 2. Stress transmission in this protocol design
  • Senior tranches: lower, more stable returns; cushioned by mezzanine/junior capital.
  • In stress, senior yields may fall but remain positive unless losses pierce subordination.
  • Mezzanine/junior tranches: take first loss; yields can flip negative when:
  • Asset cashflows drop (rate cuts, prepayments, non‑performing loans).
  • Collections are delayed while fees and servicing costs continue.
  • Multi-chain deployment (Ethereum, Base, Avalanche, BNB, Plume, Pharos, others): each chain’s pools face the *same off-chain asset stress*, but DeFi-side factors (stablecoin spreads, liquidity, incentives) can make per-chain APY different. ### 3. Institutional risk view if 30d primary yield turns negative If TVL‑weighted APY across the main RWA stablecoin pools slips below 0 over 30 days (not verifiable as of 2026-09-05):
  • Economic risk
  • Impaired asset quality or structural repricing of credit; need loan‑level default/arrears data (currently unavailable here).
  • Senior tranche protection may be eroding; junior capital may already be absorbing losses.
  • Liquidity risk
  • Investors may redeem, forcing asset sales or gating; protocol uses configurable vaults and async deposit/redemption flows, so exit frictions can rise in stress.
  • Chain-specific exposure (conceptual, not quantified):
  • Ethereum likely hosts the largest pools (USDS/AUSD).
  • Avalanche/Base/BNB, plus newer chains (Plume, Pharos, OP) add incremental but smaller TVL slices. ### 4. Monitoring priorities in this scenario Given current verification limits:
  • Track aggregator-reported TVL changes and APY paths per chain and pool for early outflow signals.
  • Cross-check against protocol disclosures on asset performance and tranche waterfalls, clearly marking them as *unverified marketing claims* if no independent corroboration.
  • Watch for governance or legal actions (amendments, workout processes) that indicate crystallizing credit losses.
Evidence (15)

Governance & Legal

governance

one source

As of September 6, 2026, Centrifuge is materially foundation-controlled rather than an active DAO. CP171, approved November 3, 2025, paused routine DAO governance. The Centrifuge Network Foundation (CNF) has board-led oversight and manages the treasury; Centrifuge Labs is CNF’s service provider for development, operations, growth, and adoption.

The frontend and application infrastructure are therefore operationally Labs-controlled, although exact deployment credentials are Not verifiable as of September 6, 2026. [Docs] Governance process: DAO reinstatement requires a forum RFC using CP0, at least 14 days of discussion, final submission through GitHub, a 7-day Snapshot vote, holder notification, and 4,000,000 CFG quorum. A reinstatement RFC was opened August 29, 2026 and remained RFC/status-pending as of the review date; it would restore limited holder approval over fundamental governance/economic matters, not day-to-day operations. > Contradiction / key finding: Documentation says CFG holders retain “ultimate control,” but active voting is paused and execution, treasury, and Labs oversight sit with CNF. The retained holder power is currently a reactivation right, making the DAO practically symbolic for routine control. Contract control: Root holds administrative access across protocol contracts.

ProtocolGuardian controls emergency pause, unpause, permission scheduling/cancellation, cross-chain upgrades, token recovery, and outbound-message blocking. OpsGuardian controls adapter initialization, network wiring, and pool creation, but cannot pause. Timelock: privilege escalation through Root has a 48-hour delay; emergency pause is immediate. Whether all token-recovery paths are economically drain-capable for user funds is Not verifiable as of September 6, 2026; the guardian does possess token-recovery authority over designated targets. Multisigs: separate Protocol Safe and Ops Safe are documented.

Public secondary reporting identifies the Protocol Safe as 4-of-9, but signer identities, current threshold, owner independence, and the Ops Safe configuration are Not verifiable as of September 6, 2026 without Dune/Safe-state verification. Legal entity: Centrifuge Network Foundation, a Cayman Islands foundation company, address Floor 4, Willow House, Cricket Square, Grand Cayman KY1-9010. Listed board: Bhaji Illuminati, Lucas Vogelsang, Kevin Chan, Nick Cherney, Glenn Kennedy, Laura Birrell. Registration number, constitutional documents, and formal director filings are Not verifiable as of September 6, 2026.

Terms disclaim licensing and investment representations. CFG top-holder concentration, voting concentration, treasury balances, and chain-by-chain exposure are Not verifiable as of September 6, 2026 because Dune was unavailable.

Timelock
Yes
Timelock delay hours
48
Admin can drain
Yes
Emergency bypass
Yes
Evidence (6)

legal & regulatory

one source

As of September 4, 2026, the identified legal steward is Centrifuge Network Foundation, Inc., a Cayman Islands foundation company with registered address at Floor 4, Willow House, Cricket Square, Grand Cayman, Cayman Islands. Centrifuge Labs is described as an operational/service provider; the protocol itself is open-source software, while individual tokenized pools, issuers, managers, custodians and fund vehicles may be separate legal arrangements. ToS/restrictions: The website disclaims that it offers securities, investment contracts, financial services, deposits or advice, and states that services may be unavailable or restricted by jurisdiction or investor category.

Product-level share tokens can impose whitelisting, freezing, clawback, minimum-investment, lock-up and jurisdictional restrictions. KYC/AML/sanctions: KYC/AML is documented for accounts and certain services, including transaction monitoring, suspicious-activity reporting, sanctions screening and restricted-jurisdiction controls. This does not establish that every permissionless interaction with the immutable core is KYC-gated.

Classification: Centrifuge states that CFG is not a security under Cayman law; Kraken separately assessed CFG as unlikely to be a security or derivative under Canadian securities law. These are jurisdiction-specific opinions, not a global safe harbor. Tokenized RWA fund/share interests are distinct products and may be securities.

Warnings/enforcement/sanctions: Not verifiable as of September 4, 2026. No regulator action, sanctions designation, or court case against Centrifuge Network Foundation itself was identified in the searches performed. A Delaware debt/breach-of-contract case names related CFG Services Ltd—not the Foundation—and should not be attributed to the protocol without proof of corporate identity.

Data protection: The privacy policy references GDPR-style access, correction, deletion, consent withdrawal, supervisory complaints, cookies/analytics, statutory retention and cross-border processing safeguards. Actual risk: Cayman foundation status limits direct token-holder ownership and does not eliminate U.S., EU, securities, AML, tax or product-level liability. The proposed conversion to a Cayman exempted company and equity issuance was a proposal, not verified as completed.

Entity
Centrifuge Network Foundation, Inc.
Jurisdiction
Cayman Islands
Evidence (6)

legal registries

two sources

No exact GLEIF LEI record for 'Centrifuge Network Foundation Inc', 'Centrifuge Protocol'. OFAC SDN screening of 'Centrifuge Network Foundation Inc', 'Centrifuge Protocol': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Centrifuge Network Foundation Inc
  • Centrifuge Protocol
Sanctioned
No
Evidence (4)

Stability

stability

one source

Centrifuge Protocol does not appear to issue its own stablecoin; the available evidence points to external stablecoins being used in pools and liquidity, especially USDC, DAI, and USDS. A depeg for a Centrifuge-issued stablecoin is not verifiable as of 2026-09-06, so the depeg count, last depeg date, and max depeg percentage cannot be confirmed from the available evidence. The conservative classification is: stable = true, own_stablecoin = false, depeg_count = 0, with stablecoin_ids listing the externally used stablecoins observed in the evidence.

Own stablecoin
No
Stable
Yes
Depeg count
0
Stablecoin ids
  • USDC
  • DAI
  • USDS
Evidence (3)

Risks & Strengths

risks

one source

Centrifuge’s principal risks are concentrated in the off-chain asset layer, privileged pool administration, cross-chain messaging, and liquidity execution. The protocol has audits, timelocks, pause controls, configurable message confirmations, and permissioning, but these controls reduce rather than eliminate dependence on managers, routers, asset valuations, and external legal infrastructure. On-chain exposure, TVL concentration, and chain-level percentages are Not verifiable as of September 5, 2026 because Dune MCP was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Underlying asset credit and valuationPool tokens depend on borrowers, servicers, collateral enforceability, recovery values, and accurate NAV/share-price reporting. Defaults or stale/manipulated valuations can transfer losses to investors and delay redemptions.HighHighTranching, pool-level permissions, manager controls, published pricing processes, asset documentation, and issuer/originator underwriting are in place.High residual risk remains because core credit performance and much valuation evidence are off-chain and pool-specific.
Cross-chain messaging compromiseA compromised router or message-passing adapter could inject malicious instructions, alter pool state, or transfer escrowed funds; the audit documentation states some malicious-router scenarios are not fully protected.HighMediumConfigurable GMP adapters and confirmation thresholds, gateway controls, timelocks, pause administration, and restricted escrow destinations.Medium-to-high residual risk, especially where pools select fewer adapters or lower confirmation requirements.
Privileged manager concentrationA compromised hub manager can appoint roles, set prices, settle investor requests, and reconfigure cross-chain security, creating a large blast radius.HighMediumRole separation, access controls, guardian/pause functions, multisig administration, and delayed administrative actions.Medium-high residual risk from trusted operators and key-management failure.
Liquidity and redemption mismatchDeposits and redemptions are asynchronous and depend on pool cash, repayments, cross-chain settlement, and operational execution; investors may face delayed or partial exits during stress.HighHighRequest-based vault flows, epochs, escrow accounting, tranche structure, and pool-specific liquidity controls.High residual risk because RWA liquidity is inherently slower and less fungible than liquid DeFi collateral.
Governance and regulatory centralizationDAO operations have been paused in favor of Foundation oversight and Labs execution, increasing execution speed but reducing decentralized checks. RWA legal, securities, AML, and jurisdictional outcomes remain pool-specific.HighMediumFoundation board oversight, public reporting commitments, permissioned access, legal structuring, and the ability to reactivate DAO governance.Medium-high residual risk from concentrated discretion, regulatory change, and uncertain cross-border enforceability.
Evidence (5)

strengths

unverified

Centrifuge’s top strengths are: 1) RWA tokenization leadership — it is built specifically to tokenize and distribute financial products and real-world assets onchain; 2) Multi-chain architecture — the protocol supports seamless deployment across networks and uses chain abstraction so issuers can manage liquidity from a single hub; 3) Strong composability — it supports standards like ERC-4626 and ERC-7575, making it easier to integrate with DeFi protocols and aggregators; 4) Modular, extensible design — an immutable core plus extension layer lets builders customize vaults, compliance hooks, pricing, and cross-chain adapters; 5) Automated onchain accounting — it maintains double-entry bookkeeping and ledger tracking across pools, which improves transparency and operational control.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 11 two independent sources, 54 one source, 11 unverified.
  • Oldest fact verification date: 2026-08-30.