Concrete

Green · 76/100

Executive summary

Concrete is a multi-strategy DeFi vault protocol operating on Ethereum, Arbitrum, Berachain, and Stable with a score of 76/100 (green band), reflecting strong audit coverage but significant centralization and unverified operational details.

  • Security: Extensive audit program including Halborn (8+ reports), Zellic (2 reports), and Code4rena competition ($112.5k prize pool). Zellic found 2 high and 6 medium findings in June 2025; most remediated but some acknowledged/unfixed. Active Cantina bug bounty with $250k max payout. Current deployed-code bytecode match to audited commits is not verifiable as of September 2026.
  • Governance & custody: Company-controlled by Blueprint Finance, not a DAO. VaultManager and strategy owners can move assets via rescueFunds without token-holder votes. Royco documentation describes a 3-of-5 multisig with 48-hour timelock for allocation changes, but protocol-wide governance is symbolic/unverified. Admin can drain funds.
  • Counterparty & withdrawal risks: Vaults allocate to Aave, Morpho, Uniswap, and multisig-managed positions; underlying protocol failure directly impairs vault NAV. Withdrawal liquidity depends on strategy deallocation and can fail when lending protocols are illiquid. Audits identify withdrawal-queue inconsistencies and risks where early redeemers extract value at remaining holders' expense.
  • Top risks: Smart-contract logic vulnerabilities (2 high findings in Zellic review, remediation incomplete); centralized admin control with no verifiable DAO governance; strategy-counterparty insolvency propagating losses to vault holders; withdrawal liquidity stress during market dislocations; unverified deployed-code match to audited commits across all chains.
  • Strengths: $1.24B TVL across four chains with institutional backing (Polychain, YZi Labs, VanEck, BitGo); modular ERC-4626 architecture with automated allocation and withdrawal management; public, non-anonymous founding team (Nic Roberts-Huntley, Dillon Liang) with TradFi/Web3 experience; multiple independent audits and active bug bounty; no verified fraud, rug-pull, or regulatory enforcement incidents.
  • Unverified: Largest collateral asset and exposure by chain; exact withdrawal lock-ups, gates, and current liquidity limits; protocol treasury size, reserve policy, and signer details; bytecode match of deployed contracts to audited code; primary yield source and 30-day performance by chain; legal entity jurisdiction and KYC/AML policy; bridge usage and cross-chain custody model.
  • Recommended exposure: Conservative allocation (≤2–5% of portfolio) suitable only for institutional allocators with direct legal/technical diligence capacity. Require independent verification of: (1) deployed contract bytecode match to latest audits, (2) multisig signer identities and timelock enforcement, (3) vault-specific withdrawal liquidity and strategy exposure, (4) legal entity structure and custody arrangements. Avoid exposure until DAO governance claims are substantiated or replaced with transparent centralized-control documentation. Monitor withdrawal queue behavior and strategy-counterparty health continuously.
  • Open questions: What are the exact deployed contract addresses, proxy admins, and upgrade authorities for each chain? Who are the 5 multisig signers and what is their operational track record? What is the largest single-strategy exposure by USD value, and what is the withdrawal success rate under stress? What legal entity holds vault assets, under which jurisdiction, and with what segregation/bankruptcy-remote structure? Has any vault experienced a withdrawal gate, pause, or NAV impairment event? What is the protocol's response plan for underlying strategy insolvency or oracle failure?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 10 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2025-10-10)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 7 1.4 TVL $1,188,641,651 = 7% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 17/42 verified facts; 42/42 fresh (180d)

Identification

protocol identification

two sources

Concrete appears to be a very small / emerging protocol with multiple name collisions and limited independent coverage; key facts are therefore highly uncertain and mostly Not verifiable as of 2026‑09‑04. ### 1. Protocol Identification Name / category Multiple unrelated projects use the word “Concrete” (NFTs, DAOs, stablecoins, RWA concepts). I cannot reliably identify a single DeFi yield protocol named Concrete operating on Arbitrum, Berachain, Ethereum, Stable from independent sources. Website / docs Search results surface various “Concrete” web properties (NFT marketplace, design studios, DAOs, etc.), but none can be confidently matched to a yield-focused DeFi protocol across the specified chains with verifiable contract addresses. > Not verifiable as of 2026‑09‑04: canonical website, documentation URL, protocol category, or stablecoin/“Stable” chain mapping. Launch date / chains / native token No independent analytics (DeFiLlama, Token Terminal, L2Beat) show a protocol slugged “concrete” on Arbitrum, Berachain, Ethereum, or a chain named “Stable”. > Not verifiable as of 2026‑09‑04: launch date, chain deployment details, or native token (ticker, contract). Main contract addresses & explorer status Because I cannot reliably match any explorer contracts to a clearly identified Concrete DeFi protocol (risk of phishing clones and name collisions), listing addresses would be unsafe and speculative. > Not verifiable as of 2026‑09‑04: main contracts, proxy/implementation layout, explorer verification status. ### 2.

Fork Lineage / Code Origins No credible source (audits, GitHub, independent technical write‑ups) documents Concrete as a fork of a major upstream protocol (e.g., Aave, Compound, Curve, Pendle, GMX) or analyses its code changes. > Not verifiable as of 2026‑09‑04: >

  • Whether Concrete is a fork of an existing protocol. >
  • What was changed vs upstream. >
  • Whether those changes were audited. >
  • Any history of malicious modifications in Concrete or similarly branded forks. ### 3. Risk‑relevant implications Given the absence of:
  • identifiable contracts and TVL on major analytics platforms,
  • audit reports from recognized firms,
  • bug‑bounty listings or formal disclosures, this protocol currently falls into a high‑opacity / high‑information‑risk bucket for institutional purposes. Any engagement would require:
  • direct confirmation of correct contract addresses from multiple independent explorers;
  • obtaining audits from auditor websites;
  • manual review of GitHub repos and governance/forum records. Until those are obtained, all key protocol identification facts remain Not verifiable as of 2026‑09‑04 and should be treated as an unresolved due‑diligence gap.
Evidence (3)

maturity

two sources

Concrete appears to be a real, functioning DeFi product rather than a pure landing page: its docs describe ERC-4626 vaults, deposit/withdraw flows, and a quick-start wallet auth flow, while a dedicated app is linked from third-party coverage and the docs point to on-page vault actions such as Deposit and Withdraw. The available evidence supports live user interaction for deposits and withdrawals, but on-chain execution, current chain-by-chain TVL, and exact availability by Arbitrum, Berachain, Ethereum, and Stable are not verifiable as of 2026-09-04. The docs look more mature than a template site: they include product-specific pages for withdraws, fees, and getting started, which is consistent with an operating vault product rather than a static marketing shell.

I did not find reliable evidence of broken links, fake metrics, or template reuse in the sources reviewed; those issues are not verifiable as of 2026-09-04. An open API is not clearly documented in the sources reviewed. The docs show user-facing web flows, but no public developer API reference, endpoint list, or authenticated integration spec for the protocol itself was found, so open API status is not verifiable as of 2026-09-04.

One caution: third-party TVL pages disagree materially on scale, which suggests aggregator-level inconsistency and means any headline numbers should be treated carefully.

Evidence (6)

Security

bug bounty

two sources

Concrete appears to have an active bug bounty program hosted on Cantina, launched on 5 Nov 2025, with a maximum reward of $250,000. Program rules visible in the listing include: first-to-report only, sufficient reproduction details required, no malicious exploitation or prior disclosure, compliance with laws and KYC/legal verification if requested, and exclusion of current/former contributors to the affected code. The reward schedule shown is Critical up to $250,000 and High up to $100,000, with a stated cap of 10% of direct funds at risk at report time.

Publicly available results in the gathered sources only show that findings have been submitted; no verified payout or incident result was disclosed. Not verifiable as of 2026-09-04.

Active
Yes
Platform
Cantina
Max payout
$250K
Since
2025-11-05
Evidence (2)

counterparty risks

one source

Assessment date: September 6, 2026. Dependency map / risks

  • Concrete is an allocation and vault-infrastructure layer, not a self-contained yield source. Its stated strategy set includes lending, DEX liquidity, restaking, delta-neutral trading, incentive farming and cross-chain routing; failure of an underlying protocol, market maker, oracle, bridge or strategist can impair NAV or withdrawals. These descriptions are unverified marketing claims.
  • Named external dependencies include TRES (accounting), Hypernative (monitoring/policy controls), Fordefi (policy-controlled vault wallets), and potentially Fireblocks trading/multisig wallets. These controls reduce operational risk but do not eliminate custodian, signer, vendor or execution risk.
  • Protocol and asset exposure: Concrete publicly references Morpho, Compound, Silo, Radiant, Renzo/EigenLayer, WBTC/BitGo, wstETH, weETH, USD1, USDT/frxUSD and Royco. This creates lending-market, LST/LRT/restaking, stablecoin, issuer/reserve, bridge and liquidity risks. Audit material confirms external strategy contracts and an oracle plug; it also records risks involving withdrawal liquidity and strategy-reported withdrawal values.
  • Bridge risk: Arbitrum’s canonical bridge relies on Ethereum escrow, paired gateways and cross-domain messaging; withdrawal finality and gateway/message failures are relevant. Non-canonical bridges carry separate trust assumptions. Concrete’s chain-by-chain bridge usage is Not verifiable as of September 6, 2026.
  • RWA / CEX / MM: The app shows an RWA USD1 vault and describes AssetCX products where assets may remain with centralized custodians; specific issuer, SPV, exchange, market-maker and concentration exposures are Not verifiable as of September 6, 2026. > Contradiction / data-quality callout: Concrete’s app headline reports $1.254B of deposits, while the visible live-vault figures and historical campaign figures are not reconciled to that total. Because Dune/on-chain verification is unavailable, treat all platform-reported balances and exposure percentages as unverified marketing claims. Failure scenarios: underlying lending insolvency or oracle manipulation; stablecoin/RWA depeg or issuer failure; LST/LRT slashing or restaking loss; bridge exploit or messaging halt; custodian/key-policy failure; market-maker liquidity withdrawal; strategy accounting error; withdrawal queues during stressed liquidity. Structured fields:
  • dependency_failure_active: null
  • max_exposure_pct: null No active dependency failure or maximum exposure percentage is verifiable without raw on-chain data as of September 6, 2026.
Evidence (5)

crypto custody

unverified

Concrete’s custody model is only partially verifiable from the available sources. The strongest evidence says assets can remain in qualified/centralized custody while Concrete routes them into on-chain yield products, with deposits forwarded to a MultisigStrategy backed by a Gnosis Safe or Fordefi MPC wallet and a pre-delegated pause authority for ZeroShadow. Concrete also describes withdrawal requests as delayed and epoch-based, with assets reserved and then claimed, which indicates protocol-controlled settlement rather than instant self-custody at the user level.

There is no independently verified evidence here that Concrete uses fully segregated customer assets in the legal-banking sense, so segregated_assets is Not verifiable as of 2026-09-06. Withdrawal pauses are also Not verifiable as of 2026-09-06; the docs mention pause authority and withdrawal restrictions, but do not establish an active, protocol-wide pause state.

Evidence (6)

key management

unverified

For Concrete, I could not verify a protocol-specific key-management design from the provided sources, and I did not find chain-specific documentation for Arbitrum, Berachain, Ethereum, or Stable that confirms how keys are operationally managed. Not verifiable as of 2026-09-04. What can be stated from the available material is only the general standard for key management: it covers the full lifecycle of cryptographic keys, including generation, storage, distribution, use, rotation/replacement, and destruction. Best practice guidance also emphasizes storing keys in protected cryptographic modules or vaults, restricting access, avoiding plaintext storage, and applying audit logging and rotation policies.

Because no Concrete-specific source was provided, any claim about whether the protocol uses a centralized key server, multisig, MPC, hardware security modules, or chain-specific admin wallets would be speculation. If you want, I can next look for Concrete’s docs, governance posts, audits, or explorer-verified admin contracts and map the key-management setup by chain.

Evidence (4)

smart-contract

two sources

Assessment date: September 6, 2026. Dune MCP was unavailable; therefore deployment-wide on-chain checks, proxy-admin event analysis, role state, timelock delay, and current withdrawal behavior are Not verifiable as of September 6, 2026. Identified addresses / verification

  • Ethereum: 0x6503de9FE77d256d9d823f2D335Ce83EcE9E153f — Concrete ctStableUSDT, verified VaultProxy; explorer identifies an implementation, confirming proxy-style architecture for this deployment.
  • Stable: 0xB417A7C43a7a8aa27BBa2b2bB4639878532F9D0C — verified ConcreteBridgedAsyncVaultImpl; explorer heuristics suggest proxy usage, but the proxy/admin relationship is not established.
  • Arbitrum and Berachain core vault/router/strategy addresses: Not verifiable as of September 6, 2026. Architecture (best-supported, not deployment-complete) User → VaultProxy → implementation → WithdrawalQueue / ParkingLot → Strategies → external protocols/oracles └→ owner/admin-controlled configuration, emergency removal, fees, oracle/strategy parameters The reviewed code includes upgradeable vault variants, factories, withdrawal queues, strategies, managers, and oracle contracts. The Zellic assessment reports 25 findings, including 0 critical and 2 high-impact findings; however, it also states that key custody and infrastructure were out of scope, and remediation/current deployment matching was not independently verified. Admin-risk findings
  • Owner-controlled emergencyRemoveStrategy, fee/configuration functions, parking-lot configuration, and strategy rescue capabilities are present in the reviewed code. The audit specifically notes that MultiSigStrategyV1 owner functions can rescue assets, including the underlying asset.
  • Whether these roles are renounced, multisig-controlled, timelocked, or currently able to drain/freeze live user funds: Not verifiable as of September 6, 2026.
  • Worst case if privileged keys are compromised: malicious upgrades or configuration, oracle/strategy manipulation, emergency strategy removal, fee changes, withdrawal disruption, or transfer of assets reachable by rescue/admin paths. Contradiction / limitation: an audit confirms reviewed code, not every live chain deployment; current addresses, implementation versions, admins, and role states remain unverified.
Upgradeable
Yes
Evidence (4)

audit

two sources

Concrete ran a Code4rena audit competition in November 2024 with a prize pool of $112,500 USDC. This is a competitive audit rather than a traditional single-firm report.

Auditor
Code4rena
Report date
2024-11-29
Scope
Code4rena audit contest for Concrete, starting 2024-11-15 and ending 2024-11-29; scope covers core protocol contracts (vaults, strategies, managers, registries, withdrawal queues, etc.) per independent commentary.[2][9] Exact chain coverage not stated; Not verifiable as of 2026-09-04.
Findings
The public contest repo describes an audit scope including Concrete vaults and associated contracts, but detailed vulnerability list and severities are organized in Code4rena’s findings, not summarized in the snippet available.[2] Critical/High/Medium counts are Not verifiable as of 2026-09-04.
Fix status
Contest outcomes (issues found and fixes applied) are not summarized in the accessible snippet; post-contest remediation and whether fixes were deployed on Arbitrum/Berachain/Ethereum are Not verifiable as of 2026-09-04.
Evidence (2)

audit

one source

New report: Rewards Distribution

Auditor
Halborn
Report date
2025-03-17
Scope
vault-rewards-distribution-contracts, commit 9d7e4eb; RewardsDistributorFactory, VaultRewardsDistributor, errors and events libraries.
Findings
Critical 0; High 0; Medium 0; Low 2; Informational 0. Low: missing two-step ownership transfer and centralization risk from unrestricted rescueFunds.
Fix status
Two-step ownership solved 2025-03-13; centralization risk acknowledged 2025-03-15. Remediation commit decbdb0.
Report url
https://docs.concrete.xyz/assets/files/Rewards-Distribution-3246c5b6379dceae29f2e615c257dfe9.pdf
Report id
doc:52f27ce26c293a05
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report: Upgradable Multisig and Queue Changes

Auditor
Halborn
Report date
2025-10-06
Scope
sc_earn-v1, commit 51248b8; MultiSigStrategy, StrategyBase, and ConcreteMultiStrategyVault.
Findings
Critical 0; High 0; Medium 1; Low 3; Informational 6. Medium: burned shares cause reward loss during pending withdrawals. Low: previewWithdraw rounding, reward sniping, and missing rate-change validation. Six additional informational findings.
Fix status
1 solved; 2 not applicable; 1 risk accepted; 6 acknowledged. Not fully remediated.
Report url
https://docs.concrete.xyz/assets/files/Upgradable-Multisig-and-Queue-Changes-140d08a81b2b4164f47d38a3227ebae9.pdf
Report id
doc:adee5979604f3b41
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report: VaultManager

Auditor
Halborn
Report date
2025-03-13
Scope
sc_earn-v1, commit f730ab1; src/managers/VaultManager.sol.
Findings
Critical 0; High 0; Medium 0; Low 1; Informational 1. Low: missing upgradeable-contract storage gap. Informational: unused import.
Fix status
Both findings solved on 2025-03-07; remediation commit e49a382.
Report url
https://docs.concrete.xyz/assets/files/Vault-Manager-427118e172ce1b2defda8836e4bac880.pdf
Report id
doc:c174dd63fb0f8ede
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report: Withdrawal Pause

Auditor
Halborn
Report date
2025-03-11
Scope
sc_earn-v1, commit 94eecfe; Errors interface, vault interface, and ConcreteMultiStrategyVault withdrawal-pausing changes.
Findings
Critical 0; High 0; Medium 0; Low 1; Informational 3. Low: incorrect event values. Informational: upgradeability concern, missing NatSpec, and function visibility.
Fix status
All 4 findings solved on 2025-03-07; remediation commits 04cc962 and 160244a.
Report url
https://docs.concrete.xyz/assets/files/Preview-Withdrawal-Pause-SSC-38644c89eda9ffbbfbe459e7292ba1ce.pdf
Report id
doc:ede9e4489b90514d
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report: Earn V2 Core – Async Implementation

Auditor
Halborn
Report date
2025-10-10
Scope
earn-v2-core, commit c02454d; async/standard vault implementations, withdrawal helpers, fee splitter, accounting libraries, and strategy modules.
Findings
Critical 0; High 0; Medium 0; Low 1; Informational 10. Low: unfollowed checks-effects-interactions pattern. Informational issues included input validation, accounting/cooldown margins, admin accounting bypass, rounding, storage slot, fee-splitter validation, stale epoch state, initializer, typo, and redundant code.
Fix status
100% addressed: 8 solved, 1 partially solved, 2 acknowledged.
Report url
https://docs.concrete.xyz/assets/files/Async-Implementation-8515203dee5f879ea6f626a7f8f5ac72.pdf
Report id
doc:eecd61a3df119e6a
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Halborn published a Concrete HUB v1 audit for the protocol. Scope covers core hub logic, config and registry handlers, ERC721 logic, packet ID generation, and cross-chain handling (chainId/eid).

Auditor
Halborn
Report date
2024-01-10
Scope
Concrete HUB v1 smart contracts (hub, config/registry handlers, ERC721 logic, packet ID / cross-chain messaging).[3] Chains supported by this deployment are not clearly enumerated; concrete chain coverage is Not verifiable as of 2026-09-04.
Findings
Findings (all severities reported as Medium/Low in the public summary, no Critical/High listed): - Missing check for response handler address – **Medium**, marked Solved 09/20/2024.[3] - Missing handling of DELETE and INCREMENT – **Medium**, Risk Accepted.[3] - Missing operations in config and registry pong handlers – **Medium**, Solved 09/20/2024.[3] - Missing name initialization in ERC721Logic constructor – **Low**, Solved 09/20/2024.[3] - Non-atomic packet ID may result in collisions – **Low**, Not Applicable.[3] - Missing underflow handling – **Low**, Risk Accepted.[3] - Missing validation for consistent chainId and eid – **Low**, Risk Accepted.[3] No explicit Critical or High severity items are shown in this summary page.[3]
Fix status
Mixed: several Medium/Low issues are marked **Solved** (09/20/2024), others **Risk Accepted**, one **Not Applicable**.[3] The page does not state whether this exact audited code matches all currently deployed Concrete contracts on Arbitrum/Berachain/Ethereum; bytecode match is Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Auditor: Halborn. Report: Earn V1 Audit. Report publication date: Not verifiable as of 2026-09-05; engagement ran April 22–July 19, 2024.

Scope: 19 Solidity files in sc_earn-v1, including ConcreteMultiStrategyVault, VaultFactory, managers, registries, withdrawal queue, ClaimRouter, Aave/Radiant/Silo strategies, ProtectStrategy, Swapper and OraclePlug; assessed commit 949c177. Findings: 0 critical, 0 high, 1 medium, 4 low, 19 informational. The medium finding was a vault-removal logic issue; low findings included withdrawal/strategy DoS and unchecked ERC-20 return values.

Fix status: 10 solved, 2 risk accepted, 12 acknowledged; Halborn reports 100% of reported findings addressed. Covers deployed code: audited code commit is identified, but bytecode match to Concrete deployments on Arbitrum, Berachain, Ethereum or Stable is Not verifiable as of 2026-09-05.

Auditor
Halborn
Report date
2024-07-19
Scope
Earn V1 / sc_earn-v1, commit 949c177; 19 Solidity files
Findings
Critical 0; High 0; Medium 1; Low 4; Informational 19. Medium: vault-removal logic issue. Overall: 24 findings.
Fix status
10 solved; 2 risk accepted; 12 acknowledged. Halborn states 100% addressed.
Evidence (1)

audit

unverified

Earn v2 - Whitelisting Hook. The Concrete docs list this audit as dated December 18, 2025. The public results surfaced here do not include the underlying report, so the auditor/date/scope are identifiable, but the critical/high/medium findings, fix status, and whether it covers deployed code are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2025-12-18
Scope
Earn v2 - Whitelisting Hook
Evidence (1)

audit

unverified

AssetCX. The Concrete docs list this audit as dated January 09, 2026. The surfaced sources do not expose the report contents, so findings and bytecode-match/deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-01-09
Scope
AssetCX
Evidence (1)

audit

unverified

Looping Strategy Swapper Contract. The Concrete docs list this audit as dated February 13, 2026. The report itself was not surfaced, so the severity breakdown, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-02-13
Scope
Looping Strategy Swapper Contract
Evidence (1)

audit

unverified

Earn V2 Core. The Concrete docs list this audit as dated February 20, 2026, and Halborn’s report page describes a security audit of Concrete’s smart contract ecosystem. The report page for a different Concrete audit also shows how Halborn reports scope, assessed commit IDs, and finding status, but the specific Earn V2 Core report text was not surfaced in the search results, so the exact critical/high/medium breakdown, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-02-20
Scope
Earn V2 Core
Evidence (2)

audit

unverified

Earn V2 - Improvements & priority withdrawal mechanism. The Concrete docs list this audit as dated March 2, 2026. The audit report content was not surfaced in the results, so findings/fix status and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-03-02
Scope
Earn V2 - Improvements & priority withdrawal mechanism
Evidence (1)

audit

unverified

Earn V2 - Position Management Helper. The Concrete docs list this audit as dated April 17, 2026. The report details were not surfaced, so findings, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-04-17
Scope
Earn V2 - Position Management Helper
Evidence (1)

audit

unverified

Earn v2 - Hurdle Rate. The Concrete docs list this audit as dated April 22, 2026. The underlying report was not available in the search results, so the requested severity and fix details are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-04-22
Scope
Earn v2 - Hurdle Rate
Evidence (1)

audit

unverified

Earn v2 v1.4 & AssetCx 1.2. The Concrete docs list this audit as dated May 19, 2026. The audit report was not surfaced, so critical/high/medium findings, remediation status, and bytecode-match coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report date
2026-05-19
Scope
Earn v2 1.4 & AssetCx 1.2
Evidence (1)

audit

one source

Concrete states that its vault system is audited by Zellic. However, no direct Zellic PDF/report link or public report page was surfaced in the available data.

Auditor
Zellic
Report date
2024-09-01
Scope
Described as covering Concrete vaults and modular smart‑contract system (vaults, strategies, managers, registries, withdrawal queues).[7][9] Exact report scope, chain coverage (Arbitrum/Berachain/Ethereum), and version are Not verifiable as of 2026-09-04.
Findings
Concrete and independent commentary mention Zellic as an auditor for vaults and related contracts, but do not provide a findings table.[1][7][9] Critical/High/Medium counts and specific issues are Not verifiable as of 2026-09-04.
Fix status
Whether findings were fully remediated, partially accepted, or left outstanding, and whether the audited code matches deployed bytecode on each chain, are Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Auditor: Zellic. Report: Concrete Smart Contract Security Assessment. Publication date: June 19, 2025.

Scope: sc_earn-v1 commit c68890c; registries, managers, ParkingLot, StrategyBase, Aave/Morpho/MultiSig strategies, vaults, withdrawal queue, factory and oracle components. Findings: 0 critical, 2 high, 6 medium, 8 low, 9 informational (25 total). Notable high findings concerned uninitialized feesUpdatedAt and stale protectStrategy state; medium findings included Morpho withdrawal underflow and incorrectly finalized withdrawal requests.

Fix status: findings were generally acknowledged with remediation commits, but at least one informational issue was explicitly left unfixed; therefore not fully remediated. Covers deployed code: ConcreteMultiStrategyVault was deployed on Ethereum and Berachain at assessment time; other reviewed code was not deployed. Exact bytecode match to current Arbitrum, Berachain, Ethereum or Stable deployments is Not verifiable as of 2026-09-05.

Auditor
Zellic
Report date
2025-06-19
Scope
Concrete sc_earn-v1, commit c68890c; vault, strategy, queue, factory, oracle and supporting contracts
Findings
Critical 0; High 2; Medium 6; Low 8; Informational 9. Total 25.
Fix status
Most findings have remediation commits; some were acknowledged, and at least one informational finding was not planned to be fixed. Not fully remediated.
Evidence (1)

Team & Reputation

founders

two sources

Concrete is a Blueprint Finance–developed DeFi protocol with a fully public, non-anonymous founding team and institutional backers, but most operational details (jurisdiction, office, corporate structure) remain only partially documented and therefore require caution. Founders & core team (public, non-anon)

  • Nic Roberts‑Huntley – Co‑founder and CEO of Blueprint Finance, the core contributor behind Concrete.
  • Dillon Liang – Co‑founder (often CSO) of Blueprint Finance/Concrete; publicly active under his real name and LinkedIn profile.
  • Other named team members (non-anon) across Concrete/Blueprint include Graeme Barnes (Head of Product), Luke Hajdukiewicz (Chief Growth Officer), Steve Weidenbach (COO/Finance), Ryan/“oxgato” Turner (VP Engineering), Kareem Grant (Product Lead) and additional engineering/BD hires. Prior experience & credibility signals
  • Multiple sources state the team are “veterans from both traditional finance and Web3,” with prior roles at Point72, Morgan Stanley, Caxton, Galaxy Digital, Tala, Polkadot, Eco, Consensys, Coinbase, EigenLayer, Maple, Euler and similar institutions.
  • Blueprint/Concrete raised $7.5m initially and a later $9.5m round led by Polychain Capital with participation from YZi Labs (formerly Binance Labs) and other VCs, indicating institutional due diligence.
  • Concrete/Blueprint are described by independent listings (RootData, CryptoTotem, Coinstori, MrDeFi) as a multi‑chain DeFi infrastructure / yield / credit protocol targeting institutional allocators, with sizable reported TVL and presence on Ethereum, Arbitrum, Berachain and other chains. Hacks / adverse events
  • No credible reports of protocol‑level hacks, exploits or insolvencies surfaced in recent coverage or listings. Not verifiable as of 2026‑09‑04. Onshore/offshore, office, legal entity
  • Public materials emphasize “globally distributed team” rather than a specific headquarters; no clear, independently confirmed registered jurisdiction, onshore vs offshore status, or physical office address appears in independent data. Not verifiable as of 2026‑09‑04. Reality check: business vs mere web front
  • Presence of named founders, detailed team bios, active personal LinkedIn/X accounts, multi‑round VC funding, Berachain governance participation, and multiple third‑party listings all support Concrete as a real operating business, not a thin web front.
  • However, without direct on‑chain verification or corporate registries, claims about TVL scale, regulatory posture, and legal structure remain unverified marketing or aggregator claims and should be treated as such.
Evidence (11)

general reputation

two sources

Concrete appears to have a generally positive, institutional reputation: it is presented as a protocol developed by Blueprint Finance, whose founders include Nic Roberts-Huntley and Dillon Liang, and it has publicly reported backing from Hashed, Tribe Capital, Polychain Capital, YZi Labs, VanEck, BitGo, and other investors. Public-facing coverage also describes a 2026 partnership with BitGo on an institutional DeFi platform, which reinforces a more enterprise-oriented positioning. Concrete’s docs state it has been audited by Code4rena, Halborn, Zellic, and Cantina.

I did not find verified reports in the gathered material of fraud, rug-pull, insolvency, sanctions, or regulatory enforcement specifically tied to Concrete. However, that is not the same as a clean bill of health; it only means such claims were not verifiable from the sources reviewed. Not verifiable as of 2026-09-04.

The main unresolved reputational concern is that much of the available information is promotional or aggregator-based rather than independent due diligence. The protocol’s own audit page is a primary claim source for security posture, and the investment/launch narratives are largely drawn from media and data aggregators. I therefore treat the positive reputation as *plausible but not fully independently substantiated* from the material reviewed.

Bottom line: Concrete currently reads as a venture-backed, audit-aware institutional DeFi project with no verified public fraud/regulatory allegations in the available sources, but the absence of evidence here is not evidence of absence.

Evidence (6)

Economy

TVL: $1.2B

model

two sources

As of September 6, 2026, Concrete is best characterized as a multi-strategy vault and on-chain capital allocator, not a single market-neutral strategy. Audited strategy descriptions show exposure to Aave V3 lending, Morpho Vaults, Uniswap V3 swaps when assets differ, and multisig-managed positions; the multisig strategy itself produces no rewards and may restrict withdrawals. Assets / yield / risk profile: Current pools include ETH- and BTC-linked assets, liquid-staking assets, stablecoins, RWA-linked products, and Berachain assets. Yield sources therefore vary by vault: lending interest, external vault yield, trading/swapping, staking or RWA-linked returns, and potentially rewards.

The evidence does not establish a portfolio-wide market-neutral profile. Leverage, looping, restaking, and external protocol exposure are vault-specific and not comprehensively verifiable. Not verifiable as of September 6, 2026 for aggregate leverage or organic-yield attribution. Withdrawals / lock-ups / gates: Standard withdrawals can require deallocation from underlying strategies and may fail when strategy or lending-protocol liquidity is insufficient. Audits identify withdrawal-queue mechanics, withdrawal limits, cooldown/async-vault controls, and inconsistencies between previewed and executable liquidity.

Exact lock-up periods, per-vault gates, and current limits: Not verifiable as of September 6, 2026. Fees / revenue: DeFiLlama reports approximately $1.161B TVL, $381K fees and $17.0K protocol revenue over 30 days, and $4.95M cumulative fees versus $394K cumulative revenue. These are analytics-platform figures, not raw on-chain verification. TVL by chain: Ethereum ~$1.08B (~93%); Stable ~$66.5M (~5.7%); Arbitrum ~$12.9M (~1.1%); Berachain ~$1.6M (~0.1%); Katana ~$1.1K. Contradiction: the supplied chain list omits Katana, while current DeFiLlama tracks five chains. Dune-vs-DeFiLlama comparison and historical trend: Not verifiable as of September 6, 2026. APY: DeFiLlama tracks 30 pools with average APY around 1.3%, but individual displayed yields range from 0% to unusually high levels, including 119% for one RWA-linked pool; sustainability and subsidy composition are not established.

Evidence (4)

reserves

one source

As of September 6, 2026, Concrete’s protocol treasury / reserve is not verifiable from available web evidence. Not verifiable as of September 6, 2026 for: reserve size, reserve-wallet addresses, asset composition, liabilities, reserve policy, attestations, or treasury-control/signatory details. Dune/on-chain verification was unavailable in this run; therefore no on-chain balances are reported. Concrete’s documentation describes vault-asset custody, not a separately disclosed treasury: deposits are reportedly transferred to a MultisigStrategy backed by Gnosis Safe or Fordefi MPC wallets, with separated governance and operational roles.

This is an unverified marketing claim for reserve analysis because the documentation does not identify the wallets, balances, Safe thresholds, signers, or legal ownership. DeFiLlama reports approximately $1.163 billion TVL, allocated across Ethereum ($1.082B), Stable ($66.51M), Arbitrum ($12.94M), Berachain ($1.63M), and Katana (~$1.1K). TVL represents assets in tracked protocol contracts and should not be treated as treasury reserves, liquid reserves, or net assets available to meet liabilities. Contradiction / change: the prior finding listed four chains—Ethereum, Stable, Berachain, and Arbitrum.

The current DeFiLlama page lists five, adding Katana. This is an analytics-platform update, not an on-chain verification, and does not establish a reserve balance. The 2024 funding announcement confirms a $7.5M raise for Blueprint Finance/Concrete, but fundraising is not evidence of current treasury cash or reserves. Bottom line: no defensible reserve figure, treasury address set, composition, custody-control map, reserve policy, or third-party reserve attestation was located. Not verifiable as of September 6, 2026.

Evidence (3)

tokenomics

two sources

Conclusion — no native Concrete token is publicly verifiable as of September 4, 2026. Concrete’s documented user incentives are non-transferable “Native Concrete Rewards,” Concrete Points, and “Bags”; its vault receipt tokens (e.g., ct[asset]) represent ERC-4626 deposit shares, not a protocol governance token.

  • Native name/ticker/contract: None publicly announced; no native token contract identified.
  • Total/circulating supply, market cap, FDV: N/A. Not verifiable as of September 4, 2026.
  • Utility/governance: No native-token utility, staking, or governance rights disclosed. Concrete Points/Bags have no confirmed token conversion, transferability, or redemption schedule; any future-token references remain an unverified marketing/campaign claim.
  • Revenue share, buybacks, burns, staking rewards: No native-token mechanism disclosed. Vault yields and partner-token incentives are product-level rewards, not tokenomics.
  • Emissions/unlocks/allocations: No token supply, emissions curve, vesting, unlock calendar, or team/investor/treasury/community allocation published. Whether announced unlocks occurred on-chain: Not verifiable as of September 4, 2026.
  • Top holders/insiders: No native token exists to analyze; holder concentration and insider wallets are therefore N/A. On-chain verification was unavailable in this run.
  • Mint/blacklist/fees/administration: N/A for a native token. Concrete vault contracts use operational roles such as Vault Manager, Allocator, and Strategy Managers, but these are product permissions, not native-token controls.
  • DEX liquidity/listings: No native-token pools or listings identified; liquidity depth is N/A. Vault-share tokens may have individual markets, but that is not native-token liquidity. Risk view: Treat Concrete Points/Bags and any prospective “future token” allocation as non-contractual until Concrete publishes a token address, audited token design, supply/allocation schedule, governance framework, and verifiable on-chain issuance.
Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Not verifiable as of 2026-09-04. I could not confirm Concrete’s deployed contracts, token set, or chain-specific TVL/exposure from reliable non-protocol sources in the provided results, so I cannot assess how a BTC sub-$10,000 shock would transmit to Concrete on Arbitrum, Berachain, Ethereum, or Stable. At a high level, a BTC collapse to $10,000 is consistently framed in the market sources as a tail-risk scenario that would likely require a broader macro/liquidity shock, forced deleveraging, and confidence collapse, rather than a base-case move.

That implies the main risks for a yield protocol would be indirect: collateral devaluation, correlated de-risking across DeFi, stablecoin/liquidity stress, and higher withdrawal/redemption pressure if users flee risk assets. Because Concrete-specific on-chain positions are not verifiable here, the stress outcome by chain cannot be quantified. The only defensible protocol-specific statement is that any BTC-linked or BTC-correlated exposure, if present, would likely face the greatest immediate stress, while non-BTC positions would still be exposed through market-wide liquidity contraction and potential stablecoin plumbing disruption.

If you want a chain-by-chain stress map, I need verifiable protocol data for Concrete’s vaults, collateral types, and TVL by chain; absent that, the correct answer remains: Not verifiable as of 2026-09-04.

Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-09-04. I could not confirm Concrete’s on-chain collateral composition, largest collateral asset by value, or protocol exposure on Arbitrum, Berachain, Ethereum, and Stable from the provided results, and Dune/on-chain verification is unavailable in this run. The only directly relevant material in the results is generic stress-testing methodology and unrelated depeg examples from other protocols, which do not establish Concrete’s loss under a 20% depeg of its largest collateral.

If you want, I can still help by outlining the exact calculation framework once the largest collateral asset and its USD exposure are known: loss ≈ 20% × USD value of that asset, then compare that shock to protocol equity, debt, and liquidation buffers per chain.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Scope / identification. Concrete’s “top counterparty” cannot be ranked from the available sources. Dune was unavailable, and no public, chain-by-chain exposure table was found. Not verifiable as of September 5, 2026 for Arbitrum, Berachain, Ethereum, or Stable. The reviewed Concrete strategy set includes Aave V3, Morpho vaults, and a multisig-wallet strategy.

Stress case: largest underlying counterparty becomes insolvent

  • Expected loss path: Assets are deposited from the Concrete ERC-4626 vault into its strategy, then into Aave/Morpho—or directly to a multisig. Insolvency produces a withdrawal shortfall, frozen liquidity, impaired collateral, or a worthless/illiquid receipt token. Morpho exposure can additionally include Uniswap conversion risk where the strategy’s asset differs from the Morpho vault asset.
  • Who absorbs it: Primarily holders of the affected Concrete vault shares. The economic loss should reduce vault net assets/share price once recognized. If the strategy is halted while its internal allocation remains overstated, early redeemers can extract excess value and remaining holders absorb the residual loss—a risk explicitly identified by the audit.
  • Compensation/backstop: No protocol-funded insurance, senior-loss tranche, or guaranteed reimbursement was identified. Concrete’s terms state that it is not responsible for counterparty solvency and that vault losses are borne by users; withdrawals may also be delayed, gated, or subject to slippage. Compensation: Not verifiable as of September 5, 2026.
  • Smart-contract impact path: Concrete vault → strategy withdrawal → underlying Aave/Morpho/multisig withdrawal → asset accounting/share redemption. If the counterparty cannot return funds, withdrawals may revert, return less than requested, or queue/park claims. Concrete’s audit also notes that withdrawal previews can overstate executable liquidity, and stale deallocationOrder entries can cause failures despite sufficient assets elsewhere. Risk conclusion: This is principally pass-through, first-loss risk to vault shareholders, with potential secondary dilution from stale accounting and withdrawal ordering—not a clearly documented Concrete treasury obligation.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For Concrete, I found no verified public evidence that the DAO or its owners committed fraud. Because on-chain verification is unavailable in this run, the correct risk-state answer is: Not verifiable as of 2026-09-04. What can be said from the available sources is only generic DAO risk: DAOs can be exposed to governance abuse, self-dealing proposals, or founder-led deception, and courts have sometimes treated DAO participants as potentially liable in organized misconduct contexts.

Those sources do not establish that Concrete specifically engaged in fraud. There is also a Concrete-specific GitHub repository for a Code4rena contest, which indicates the protocol existed and was being reviewed for smart-contract issues, but it does not evidence fraud by the DAO or owners. So for a stress scenario: committed fraud by the DAO or owners, the prudent institutional assumption is maximum governance/reputation risk with possible legal, liquidity, and counterparty withdrawal stress, but the fraud event itself is not proven from the provided material.

If you need a binary diligence flag: Unverified / Not enough evidence to confirm fraud.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For Concrete on Arbitrum, Berachain, Ethereum, and Stable, a stress case where the primary yield source is negative over the last 30 days means the protocol’s core earning leg is losing money or producing a net loss over that period. From the web results provided, I can verify only general Arbitrum yield-market context, but I cannot verify Concrete’s actual primary yield source, its chain deployment mix, or whether its 30d yield is negative on any chain. That is Not verifiable as of 2026-09-04.

The closest relevant datapoint is that third-party Arbitrum yield indexes show some strategies with negative 30d performance, such as a listed pool showing -6.28% last 30d, illustrating that negative trailing yield is possible in the Arbitrum environment. However, that is not evidence about Concrete itself. The Arbitrum forum materials also show that idle treasury assets can generate zero yield, which underscores the risk of yield shortfalls, but again this is not Concrete-specific.

Because no chain-specific Concrete data was verifiable from the supplied results, the required stress assessment is:

  • Primary yield source: Not verifiable as of 2026-09-04
  • 30d yield sign: Not verifiable as of 2026-09-04
  • Arbitrum / Berachain / Ethereum / Stable exposure split: Not verifiable as of 2026-09-04
  • Loss propagation under stress: Not verifiable as of 2026-09-04 If you want, I can do a follow-up focused on non-onchain web evidence only, but with the current result set the protocol-level answer cannot be established confidently.
Evidence (2)

Governance & Legal

governance

two sources

Assessment — Concrete governance (as of September 13, 2026). Concrete appears company-controlled by Blueprint Finance and associated Concrete entities, not by a demonstrably independent DAO. The site’s Terms identify Concrete Foundation as the service counterparty and Concrete Network, Ltd. as the entity seeking admission to trading for CT; the footer states © 2026 Blueprint Finance. Contract powers. Zellic documents VaultManager as owner of DeploymentManager, with authority over vault deployment, registries, configuration and upgrades. Vault owners/managers can control strategy composition, allocations, withdrawal processing and emergency strategy actions.

A strategy owner can also invoke rescueFunds; therefore an authorized admin/multisig can move assets without a token-holder governance vote. Governance/proposals. No publicly verifiable Governor contract, Snapshot space, proposal forum, quorum, execution module or token-holder process controlling upgrades/parameters was identified. DAO governance is therefore false (symbolic/unverified, not demonstrated as operational). Voting concentration and top CT holders: Not verifiable as of September 13, 2026 — Dune/on-chain verification was unavailable in this run. Multisig/timelock. Royco’s security documentation describes a Concrete integration using a separate 3-of-5 multisig and a 48-hour timelock for allocation changes, plus a Concrete 3-of-5 upgrade whitelist. This is not sufficient to establish that the same controls govern every Concrete chain, vault or admin role. Signer identities, signer independence and complete role coverage: Not verifiable as of September 13, 2026. Legal entities / ToS. Concrete Foundation is an active Cayman Islands foundation company, General Registry ID CR-416644; Concrete Network, Ltd. is an active BVI company limited by shares, Registry ID 2166437.

Directors are not disclosed in the reviewed LEI records: Not verifiable as of September 13, 2026. Terms effective April 3, 2026 identify Concrete Foundation as the contracting party. CONTRADICTION / LIMITATION: Public documentation presents layered governance and a 3-of-5/48-hour control model, while the audit shows privileged VaultManager/owner powers and no verified DAO execution path. The on-chain/control-plane resolution cannot be confirmed without Dune.

Timelock
Yes
Timelock delay hours
48
Multisig threshold
3
Multisig owners
5
Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

unverified

Concrete’s public terms state it restricts access from certain jurisdictions, including jurisdictions subject to sanctions by the US, EU, UN, or other relevant authorities, and may add further restricted jurisdictions at its discretion. Its disclaimers say services are not available in all jurisdictions, may not be offered to all persons, and are subject to eligibility requirements, compliance review, and definitive agreements. On the information gathered, Concrete appears to operate with a compliance-gated, permissioned user model rather than a fully open, uncensored DeFi interface.

The legal entity and jurisdiction are Not verifiable as of 2026-09-04 from the gathered sources. The available materials identify “Concrete” as the service provider but do not clearly establish the controlling corporate entity or its governing law/jurisdiction in a way that can be confirmed here. KYC/AML: the gathered sources do not show a clear, protocol-level KYC/AML policy beyond eligibility and compliance review language.

Any stronger claim would be unverified marketing absent a clearer legal document. Classification/risk: the access restrictions and compliance review language indicate the protocol is likely designed for regulated/eligible counterparties, which increases the likelihood that legal risk is driven by the actual operating entity and user-facing agreements rather than by on-chain code alone. Data protection obligations are implied by the existence of compliance review, but a specific privacy/data-processing framework was not verifiable from the gathered sources.

Warnings/enforcement, court cases, and sanctions: Not verifiable as of 2026-09-04. No confirmed regulator action, court case, or sanctions designation specific to Concrete or its controlling entity was found in the gathered sources. Structured fields: active_enforcement = null; sanctioned = null; entity = null; jurisdiction = null.

Evidence (2)

Stability

stability

unverified

Concrete appears to issue its own stablecoin, concUSD, but a historical depeg for the stablecoin used in Concrete vaults is not verifiable from the available web sources as of 2026-09-06. The documented Stable vault assets are USDT and frxUSD, and no independent price-history evidence in the gathered sources confirms whether either ever depegged while used in Concrete. Concrete’s own materials describe concUSD as “a new stablecoin designed to be a dollar-denominated liquidity layer for the Concrete ecosystem.”

Own stablecoin
Yes
Stablecoin ids
  • concUSD
  • USDT
  • frxUSD
Evidence (3)

Risks & Strengths

risks

two sources

Concrete’s principal risks are concentrated in smart-contract correctness, withdrawal liquidity, strategy-counterparty exposure, oracle/valuation dependencies, and privileged administration across multiple deployments. Zellic reported 2 high- and 6 medium-severity findings and stated the reviewed code was not production-ready at the June 2025 assessment; current remediation and deployment status are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract logic failureVault, strategy, fee, or withdrawal logic bugs could misaccount shares, lock funds, or cause loss. Zellic found 2 high and 6 medium findings; several fixes were reported, while some issues were acknowledged or left unresolved.HighMediumExternal Zellic and Code4rena reviews, remediation commits for multiple findings, pause/withdrawal controls, and multisig ownership are documented.High: audits reduce but do not eliminate undiscovered logic, upgrade, or integration vulnerabilities; current deployed bytecode-to-fix mapping is Not verifiable as of September 5, 2026.
Withdrawal liquidity and queueInsufficient strategy liquidity, stale deallocation ordering, or queue processing can delay, reduce, or break legitimate withdrawals; audited findings include high-impact withdrawal-path issues and medium withdrawal-liquidity risk.HighMediumWithdrawal queues, strategy availability checks, parking-lot fallback, pausing, and audited withdrawal helpers are in place.High: the protocol’s own terms acknowledge delays, gating, slippage, and adverse liquidity conditions; live liquidity coverage is Not verifiable as of September 5, 2026.
Strategy counterparty contagionVaults can depend on lending markets, money markets, swaps, and other counterparties; a counterparty exploit, insolvency, oracle failure, or halted withdrawals can transmit losses to Concrete users.HighMediumStrategy-level allocation and withdrawal controls, multiple strategies, audits, and explicit user risk disclosure are documented.High: Concrete disclaims responsibility for counterparty solvency, performance, security, and availability; current exposure by strategy is Not verifiable as of September 5, 2026.
Oracle and valuation errorConcrete uses oracle and swap-related components; Zellic noted price-decimal normalization concerns, while incorrect prices could distort share values, withdrawals, fees, or strategy accounting.HighMediumDedicated oracle contracts, price-feed logic, validation, and external security review are present in the audited scope.Medium-High: audit observations remain relevant and live oracle configuration, fallback behavior, and feed freshness are Not verifiable as of September 5, 2026.
Privileged administration and deploymentThe audited architecture identifies an owner multisig, while upgradeable vaults and strategy-management functions create governance, signer-compromise, malicious-upgrade, or operational-error risk. Multi-chain deployment increases the operational surface.HighMediumMultisig ownership, pausing, access-controlled strategy management, and independent audits are documented.High: multisig threshold, signer independence, timelocks, upgrade policy, and per-chain admin parity are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Concrete’s top strengths are: automated risk management for borrowers via liquidation protection; yield optimization for liquidity providers; modular architecture that separates Protocol, Modules, Blueprints, and Actions for easier upgrades; automation of operational roles such as the Allocator and Withdrawal Manager, reducing manual overhead; and cross-chain / cross-VM design that is intended to work across EVM and SVM environments and integrate with multiple money markets and lenders. The clearest independently sourced signal is that Concrete is an on-chain credit market designed to shield borrowers from liquidation risk while offering yield opportunities to liquidity providers. Its docs also emphasize that high-frequency, low-impact operations are automated, which supports operational efficiency.

The modular design and multi-environment compatibility are presented as core architectural strengths rather than minor features.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 17 two independent sources, 13 one source, 12 unverified.
  • Oldest fact verification date: 2026-08-29.