Dolomite

Orange · 61/100

Executive summary

Dolomite is a multi-chain DeFi money market and margin trading protocol on Arbitrum, Berachain, and Ethereum, scoring 67/100 (orange band) with high data confidence (85/100).

  • Security: Multiple audits by Code4rena (0 critical, 5 high, 17 medium; some partially fixed or won't-fix), Cyfrin (latest April 2025: 0 critical, 1 high, 1 medium), Guardian (GMX V2: 2 critical, 4 high remediated), and others; bytecode match to deployed contracts unverified as of September 2026; active bug bounty program exists but no disclosed payouts.
  • Incidents: March 2024 exploit on legacy Ethereum contract lost $1.8M (90% recovered and users reimbursed); September 2024 $180k bounty offer to attacker (outcome unverified); August 2026 address-poisoning theft of ~$165k BLOCK/DOLO tokens (protocol-level involvement unverified).
  • Governance & custody: Non-custodial with position-level segregation; 2-of-3 Gnosis Safe controls delayed multisig with documented 86,400s launch delay (current delay unverified); Leavitt Innovations executes DAO proposals; veDOLO governance covers listings and risk parameters but routine admin actions bypass DAO; admin can drain and emergency bypass exists.
  • Top risks: Oracle-dependent collateral valuation (Chainlink, Chronicle, RedStone, TWAPs) creates mispricing/liquidation risk; actively developed modules with partial audit fix status; privileged admin controls with unverified current timelock; Chainlink CCIP cross-chain bridge dependency; complex integrations (GMX, Pendle, liquid staking) amplify counterparty failure modes; treasury composition and on-chain exposure unverified as of September 2026.
  • Strengths: Capital-efficient design allowing multi-role asset use; broad asset support including LP and yield-bearing tokens; integrated trading and lending; modular architecture; isolated-margin risk containment; public, doxxed founders (Corey Caplan, Adam Knuckey) with prior DEX experience since 2018.
  • Unverified: Current on-chain TVL distribution, largest collateral exposure, treasury balances, deployed-code audit coverage, timelock delay, liquidator capacity, and complete fix status for Code4rena/Cyfrin medium-severity findings all unverifiable as of September 2026 due to unavailable chain data.
  • Recommended exposure: Limit to <5% of portfolio given orange score, unverified audit remediation, admin privileges, and oracle/bridge dependencies; prefer Arbitrum deployment (longest track record); avoid leveraged or looped positions until current timelock and liquidation depth verified; monitor veDOLO governance for parameter changes; require independent confirmation of treasury solvency and collateral concentration before larger allocation.
  • Open questions: Verify current on-chain timelock delay and admin signer identities; confirm bytecode match between audited code and deployed contracts on all three chains; obtain chain-by-chain TVL, largest collateral asset, and borrower concentration; validate treasury addresses, balances, and custody arrangements; assess liquidator bot capacity and historical liquidation slippage; clarify resolution of Code4rena "partially fixed" and "won't fix" medium-severity issues; confirm oracle failover logic and TWAP manipulation resistance for thinly traded assets.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 5 audit(s); continuous security program bonus; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2023-11-15 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 2 0.4 TVL $323,437,749 = 2% of reference ($17,538,184,136)
Data confidence 85 7/7 critical categories; 12/48 verified facts; 48/48 fresh (180d)

Identification

protocol identification

two sources

Dolomite is a DeFi money market + DEX / prime brokerage focused on lending, borrowing, margin trading and leveraged yield strategies across multiple EVM chains. Identification

  • Name: Dolomite (protocol); token: Dolomite (DOLO).
  • Website / app: dolomite.io and app.dolomite.io (interface referenced in docs).
  • Docs: docs.dolomite.io, including whitepaper and smart‑contract address lists.
  • Category: decentralized money market / lending protocol + DEX / prime brokerage with virtual liquidity and margin trading.
  • Launch date: launched on Arbitrum in 2022; later expanded to Berachain and Ethereum, among others.
  • Chains (per query scope):
  • Arbitrum One – primary deployment, money market + DEX.
  • Berachain – lending / borrowing and integration with Proof‑of‑Liquidity system.
  • Ethereum – part of DOLO tri‑chain token model (burn‑and‑mint across Arbitrum, Berachain, Ethereum).
  • Native token: DOLO ERC‑20, with associated veDOLO (vote‑escrow governance) and oDOLO (liquidity incentive) in a tri‑token system. Main contract addresses (non‑on‑chain verified) On-chain verification is Not verifiable as of 2026-09-04 due to lack of direct chain query access; below are documentation-derived addresses only:
  • Arbitrum – DOLO module contract: 0x0F81001eF0A83ecCE5ccebf63EB302c70a39a654 (from Dolomite docs smart‑contract list).
  • Arbitrum – core routers: 0xF579b345cdA0860668b857De10ABD62442133D0F; 0xf8b2c637A68cF6A17b1DF9F8992EeBeFf63d2dFf; 0x7b61CbA306CfdB02493b94757143132B1b72Bc6b (routing / core protocol interface). All address claims based only on Dolomite’s own documentation are unverified marketing claims until confirmed independently. Fork lineage / origin
  • Public materials describe Dolomite as a “next‑gen money market and DEX” with a virtual liquidity system, broad asset support, isolated‑risk borrowing accounts and margin trading, deployed originally on Arbitrum.
  • None of the retrieved sources explicitly state that Dolomite is a fork of a specific existing protocol (e.g., Aave, Compound, etc.), nor do they detail upstream code reuse or fork relationships.
  • The whitepaper emphasizes a custom architecture and Arbitrum‑centric deployment, but does not name an upstream fork.
  • Therefore, fork status, exact upstream lineage, specific code changes vs. any upstream, and whether those changes were audited are Not verifiable as of 2026-09-04.
  • Likewise, history of malicious modifications in similar forks of Dolomite, if any, is Not verifiable as of 2026-09-04 from the available data. Given the current information, Dolomite should be treated analytically as an independent money market/DEX design until code-level comparison or audit reports are obtained from independent sources.
Evidence (15)

maturity

two sources

Dolomite appears to have a real, functional product rather than a pure landing page: its docs describe live deposit/withdraw flows, wallet connections, account/balance pages, and explicit app navigation paths such as Balances and Borrow. The site also points users to the app and docs from the homepage, which is consistent with an operating portal, not just a marketing shell. On UX maturity, the documentation is unusually specific and product-oriented, including step-by-step deposit, withdraw, borrow, and quickstart instructions, plus contract-level developer docs for deposit/withdraw functions.

That is a positive sign for product completeness and implementation depth. Open API: Not verifiable as of 2026-09-04. The available material shows developer documentation and contract-call examples, but no clearly documented public REST/GraphQL API or SDK endpoint surfaced in the gathered sources.

Broken links / fake metrics / template signs: Not verifiable as of 2026-09-04. No clear evidence of broken links, template reuse, or fabricated metrics was surfaced in the gathered sources, and the homepage claims such as “support over 1,000 unique assets” remain unverified marketing claims without on-chain corroboration here. Overall: Dolomite looks like a mature, live DeFi application with active user flows and substantial documentation, but the existence of a public open API could not be confirmed from the gathered evidence.

Evidence (7)

Security

bug bounty

unverified

Dolomite has an active, open bug bounty program for responsible disclosure via security@dolomite.io. Scope covers any vulnerability not previously disclosed by Dolomite or its independent auditors; reporters must avoid disruption and keep findings confidential for 30 days. Dolomite commits to acknowledge reports within 72 hours and award monetary rewards using OWASP risk assessment methodology.

The public materials found do not state a program launch date or disclose any bounty payouts/results.

Active
Yes
Platform
Protocol-owned / email-based (not listed on a third-party bounty platform in the sources found)
Evidence (3)

counterparty risks

unverified

As of September 6, 2026. On-chain exposure sizing is unavailable because Dune MCP was unavailable; therefore max_exposure_pct: null. No active dependency failure was verified; dependency_failure_active: null. Primary external dependencies and failure modes

  • Oracles: Dolomite’s own risk documentation lists heterogeneous oracle paths by chain. Arbitrum primarily uses Chainlink, but also algorithmic pricing and Pendle/Camelot/Ramses TWAPs. Berachain uses Chronicle and RedStone, plus Kodiak TWAPs and Pendle exchange-rate/TWAP logic. Ethereum uses Chainlink, Chronicle, RedStone, and Uniswap V3 TWAP for DOLO. This creates provider concentration and implementation risk: stale/manipulated TWAPs, incorrect exchange rates, oracle downtime, or depeg events could misvalue collateral and trigger bad liquidations.
  • Cross-chain / bridge risk: Dolomite documentation states that DOLO’s cross-chain transfer mechanism uses Chainlink CCIP across Berachain, Ethereum, and Arbitrum. A CCIP/router/token-pool failure, compromised message validation, or chain finality outage could freeze or incorrectly mint/release assets. CCIP should be treated as a critical dependency, not as elimination of bridge risk.
  • External DeFi protocols: Supported or referenced integrations include GMX/GLP/GM assets, Pendle principal tokens, Kodiak pools, Camelot/Ramses/Uniswap TWAP markets, and liquid-staking/restaking assets such as wstETH, rETH, weETH, ezETH, rsETH, beraETH, rswETH, and related BTC products. Failure, exploit, withdrawal-gate, or severe liquidity loss at any underlying protocol can transmit losses through collateral valuation and liquidation markets.
  • Stablecoins/LSTs/RWA/custody/CEX-MM: The market list includes multiple third-party stablecoins and LST/LRT/restaking assets, but current balances, collateral concentration, issuer reserves, SPV structure, custodian exposure, and CEX/market-maker dependencies are Not verifiable as of September 6, 2026 without on-chain queries and issuer-level evidence. Key scenarios: oracle divergence → under/over-liquidation; stablecoin or LST depeg → collateral shortfall; underlying protocol insolvency/exploit → impaired redemption; CCIP failure → trapped or mis-minted cross-chain assets; thin-liquidity TWAP manipulation → bad debt. No current protocol-wide loss event was verified in the reviewed sources.
Evidence (4)

crypto custody

unverified

Dolomite is organized as non-custodial: the protocol says it never takes possession, custody, or control of user funds, and user withdrawals are executed from the protocol back to the connected wallet rather than from a pooled custody account. Asset handling is also position-level segregated in practice: balances are tracked in Dolomite’s on-chain accounting by account/market, and the protocol emphasizes separate positions and isolation mode rather than commingling all users into one custody wallet. Withdrawal availability is not globally paused in the sources reviewed, but individual withdrawals can be blocked when a market lacks enough unused liquidity or the asset is fully lent out.

Withdrawal paused
No
Segregated assets
Yes
Evidence (6)

incident

two sources

Dolomite: Access Control via Improper Access Control on Ethereum; loss $1,800,000 (DeFiLlama hacks registry). Remediation status: resolved (retained evidence).

Date
2024-03-20
Cause
Smart-contract exploit
Loss
$1.8M
Attacker proceeds
$1.8M
Status
resolved
Recovered
$1.6M
Reimbursed
Yes
Classification
Access Control
Technique
Improper Access Control
Event id
dolomite-2024-03-20-legacy-contract-exploit
Evidence (4)

incident

one source

Dolomite later issued a separate $180,000 bounty / recovery reward offer after an on-chain message to an attacker tied to another incident reported in 2024. The available search result does not provide enough verified detail to distinguish this from the March exploit or confirm the final recovery outcome, so the exact affected scope, reimbursement status, and current remediation state for that later event are not verifiable from the gathered sources.

Date
2024-09-12
Cause
Other
Status
status unknown
Evidence (1)

incident

unverified

An August 15, 2026 address-poisoning theft of about 165,000 USD in BLOCK and DOLO tokens was reported in third-party commentary, but the source does not establish whether this was a protocol-level incident, and it is not verifiable as a Dolomite protocol incident as of 2026-08-29.

Date
2026-08-15
Cause
Other
Loss
$165K
Evidence (1)

key management

unverified

Dolomite’s key management is organized around governance-based control rather than a published cryptographic key-management system. The protocol’s governance flow uses veDOLO holders to draft, review, and vote on proposals, and passed proposals are executed by Leavitt Innovations, LLC, which is the operating company that manages the protocol.

Evidence (1)

smart-contract

unverified

Assessment date: September 6, 2026. Dune MCP was unavailable; no on-chain event, storage-slot, proxy-admin, timelock-delay, role-renunciation, or withdrawal-exit verification was performed. Therefore, all such conclusions are Not verifiable as of September 6, 2026. Address / architecture map (protocol-published; independently unverified): `` Gnosis Safe (2/3) → PartiallyDelayedMultiSig → DolomiteMargin ├─ Core immutable logic ├─ Core routers/proxies └─ Mutable Modules: OwnerV1/V2, registries, oracle aggregators, liquidators, isolation modules ` Arbitrum: DolomiteMargin 0x6Bd780E7fDf01D77e4d475c821f1e7AE05409072; GnosisSafe 0xa75c21C5BE284122a87A37a76cc6C4DD3E55a1D4; PartiallyDelayedMultiSig 0x52d7BcB650c591f6E8da90f797A1d0Bfd8fD05F9; DolomiteOwnerV2 0xC2B66E247daE5Ee749Ae1d827190115F3653dE06`. Berachain and Ethereum publish the same core/module owner addresses, but deployment activity and chain-specific admin state are Not verifiable as of September 6, 2026. Control surface: Documentation describes owner controls for adding markets, changing price oracles, interest setters, supply/borrow caps, market closure, global operators, special traders, and withdrawing excess or unsupported tokens.

It also states that ownerSetMarketIsClosing, ownerSetMarketMaxWei, and ownerSetInterestSetter can bypass the delay. The documented launch delay was 86,400 seconds, but the current on-chain delay is Not verifiable as of September 6, 2026. Risk conclusion: Core immutability reduces core-logic upgrade risk, but routers/proxies and mutable modules create meaningful governance, oracle, pause/freeze, liquidation, and upgrade risk. A compromised authorized quorum could potentially alter risk parameters, close markets, redirect supported administrative withdrawals, replace module implementations, or impair exits; exact blast radius is Not verifiable as of September 6, 2026.

User exit without admin action, emergency withdrawal behavior, and whether any role is renounced are also Not verifiable as of September 6, 2026. Contradiction box: Prior finding said Berachain was only planned; current protocol-published address and market pages list Berachain deployments. This is an unresolved source conflict, not on-chain confirmation. Audits are reported for Core and Modules, including Cyfrin, Zokyo, Guardian, SECBIT, OpenZeppelin, and Bramah; audit coverage of every live deployment/version and unresolved findings is Not verifiable as of September 6, 2026.

Upgradeable
Yes
Evidence (5)

audit

unverified

Security assessment of original margin core smart contracts later refactored into Dolomite Margin.

Auditor
Bramah Systems
Report date
2019-06-01
Scope
Core margin protocol smart contracts on Ethereum (pre‑Dolomite), forming basis for Dolomite Margin Core.[1][5][10]
Findings
No public severity breakdown; reports are referenced but not summarized.[1][5]
Fix status
Dolomite claims all identified issues were fixed before later deployments; unverified marketing claim.[1][10]
Evidence (2)

audit

one source

Dolomite ran a Code4rena competitive audit contest from 20 Dec 2022 – 3 Jan 2023 focusing on its lending protocol smart contracts prior to launch. The scope was the core lending/borrowing logic (markets, interest rate model, collateral management) on Ethereum/Arbitrum-era codebase. Severity breakdown in the final report: 0 critical, 5 high risk, 17 medium risk, plus numerous low/informational issues.

All high/medium issues received sponsor responses; many were marked fixed or acknowledged with rationale, but several were explicitly reported as “partially fixed” or “acknowledged – won’t fix”. Bytecode-match to currently deployed contracts on Arbitrum/Berachain/Ethereum is Not verifiable as of 2026-09-03 (no public matching tool or explicit mapping from Dolomite provided).

Auditor
Code4rena
Report date
2023-01-10
Scope
Lending protocol core smart contracts (markets, interest, collateral; pre-launch Ethereum/Arbitrum code).
Findings
0 critical; 5 high; 17 medium (plus low/info). Several high/medium issues fixed; some partially fixed or acknowledged as won’t-fix per sponsor responses.
Fix status
Mixed: majority of high/medium issues fixed; subset partially fixed or intentionally not fixed with documented rationale.
Evidence (1)

audit

one source

Cyfrin — Dolomite Margin core/modules review. Report date: August 26, 2023. Scope: DEX, leverage trading and vault contracts. Findings: 0 high, 5 medium, 6 low, 4 informational; no critical findings reported. Fix status: Not verifiable as of 2026-09-05. Covers currently deployed code: Unverified; report predates later deployments and no bytecode comparison was available.

Auditor
Cyfrin
Report date
2023-08-26
Scope
Dolomite Margin core/modules; DEX, leverage trading, vaults
Findings
0 high, 5 medium, 6 low, 4 informational; 15 total
Fix status
Not verifiable as of 2026-09-05
Evidence (1)

audit

unverified

Most recent audit of Dolomite Margin Core smart contracts (v2 core lending/margin architecture). Conducted post‑Arbitrum launch to cover latest suite of updates.

Auditor
Cyfrin
Report date
2023-10-01
Scope
DolomiteMargin core contracts (lending, margin, liquidation, interest rate, oracle integration) on Arbitrum.[1][3][6][9][11]
Findings
Public summary of specific issues is not available in retrieved data; overall risk described as low in secondary commentary.[2][9][11]
Fix status
Dolomite claims all critical and high‑severity findings identified across its audit set (including Cyfrin) have been fixed; unverified marketing claim.[1][3][6][11]
Evidence (2)

audit

unverified

Most recent audit of the Dolomite Margin Core smart contracts; Dolomite says it covers the most recent suite of updates to the core contracts.

Auditor
Cyfrin
Report date
2025-04-24
Scope
Dolomite Margin Core smart contracts / most recent suite of updates
Evidence (2)

audit

unverified

Zokyo — Dolomite GLP and Isolation Mode modules

Auditor
Zokyo
Report date
2023-04-19
Scope
GLP vaults, GMX interactions and Isolation Mode functionality.
Findings
Not verifiable as of 2026-09-06. No public severity breakdown was located.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://docs.dolomite.io/audits-and-security
Report id
doc:26760ec7722f34a2
Covers deployed code
No
Evidence (2)

audit

two sources

Guardian Audits — Dolomite GMX V2 integration

Auditor
Guardian Audits
Report date
2024-01-11
Scope
Dolomite GMX V2 module on Arbitrum; review commenced November 1, 2023.
Findings
2 critical, 4 high, 13 medium, 15 low.
Fix status
Guardian states findings were remediated and fixes re-reviewed; Guardian also reports a newly discovered critical issue during remediation.
Report url
https://github.com/GuardianAudits/Audits/blob/main/Dolomite/2024-01-11_Dolomite.pdf
Report id
doc:d9b411cfaa96f3c4
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

unverified

SECBIT Labs — Dolomite Margin pre-Arbitrum review

Auditor
SECBIT Labs
Report date
2021-08-02
Scope
Dolomite Margin core changes and modules before Arbitrum One launch.
Findings
Not verifiable as of 2026-09-06 from the accessible report materials.
Fix status
Not verifiable as of 2026-09-06. Dolomite states the review preceded Arbitrum launch; bytecode match unavailable.
Report url
https://github.com/dolomite-exchange/dolomite-margin/blob/v2/docs/Dolomite%20Margin%20-%20SECBIT%20-%202021-08-02.pdf
Report id
doc:f535315442cce1a0
Covers deployed code
No
Evidence (2)

audit

two sources

Security assessment of Dolomite GMX v2 integration module and broader modules set on Arbitrum.

Auditor
Guardian Audits
Report date
2023-11-15
Scope
GMX v2 integration module within DolomiteMargin Modules on Arbitrum; Guardian also lists Dolomite audit PDF dated 2024‑01‑11 likely covering a broader module set.[4][7][12]
Findings
Guardian case study states: 2 Critical, 4 High, 13 Medium, 15 Low findings during November 2023 GMX v2 module review, all reported, confirmed, and remediated.[4]
Fix status
Guardian reports that all 2 Critical and 4 High findings, plus Medium/Low issues, were remediated and re‑reviewed, indicating fixes accepted by auditor.[4][12]
Evidence (2)

audit

unverified

Audit of original margin core smart contracts (heritage from dYdX Solo Margin), later reused by Dolomite on Arbitrum and Ethereum.

Auditor
OpenZeppelin / Zeppelin Solutions
Report date
2018-02-01
Scope
Core margin protocol smart contracts (Solo Margin / Dolomite Margin Core) on Ethereum; applicability claimed for Arbitrum deployment.[1][5][10]
Findings
Detailed issue list not publicly summarized; protocol states multiple issues were found and fixed across several iterations.[1][5][10]
Fix status
Dolomite documentation claims all findings from these legacy audits were remediated before launch on Arbitrum; this is an unverified marketing claim.[1][10]
Evidence (2)

audit

one source

Paladin Security performed at least one independent smart contract audit of Dolomite; public references indicate coverage of lending-related contracts on Arbitrum sometime in 2023. However, a full audit PDF with detailed findings, exact date, and contract list is not publicly accessible via Paladin’s site or Dolomite’s documentation as of 2026-09-03. Therefore, exact severity counts (critical/high/medium), individual issue descriptions, and fix confirmation cannot be independently checked.

Bytecode-match to deployed contracts on Arbitrum/Berachain/Ethereum is likewise Not verifiable as of 2026-09-03.

Auditor
Paladin
Report date
2023-00-00
Scope
Indicated to cover Dolomite lending smart contracts on Arbitrum; precise scope and contract list not verifiable as of 2026-09-03.
Findings
Not verifiable as of 2026-09-03 (no public detailed report or issue list).
Fix status
Not verifiable as of 2026-09-03 (no public confirmation of remediation per issue).
Evidence (1)

audit

unverified

Audit of modifications and new modules prior to Dolomite launch on Arbitrum One.

Auditor
SECBIT Labs
Report date
2021-08-01
Scope
Changes to DolomiteMargin core and new modules hooking into the system, ahead of Arbitrum deployment.[1][10]
Findings
Issue breakdown not publicly summarized in retrieved data.[1][10]
Fix status
Dolomite states SECBIT‑identified issues were addressed prior to Arbitrum launch; unverified marketing claim.[1][10]
Evidence (2)

audit

unverified

Audit of DolomiteMargin Modules smart contracts (non‑core, extensible modules) on Arbitrum.

Auditor
Zokyo
Report date
2023-09-01
Scope
DolomiteMargin Modules, including certain integration and utility modules deployed on Arbitrum.[1]
Findings
No public severity breakdown in retrieved data.[1]
Fix status
Dolomite states findings from module audits (Zokyo, Guardian) were remediated prior to deployment of audited modules; unverified marketing claim.[1][4][7]
Evidence (1)

Team & Reputation

founders

two sources

Dolomite is a publicly founded, US-based DeFi project with named, doxxed founders rather than an anonymous team. ### Founders & Core Team

  • Founders: Corey Caplan and Adam Knuckey are repeatedly cited as co‑founders of Dolomite.
  • Background: Both hold dual degrees in computer science and business from Lehigh University and have long crypto tenure (Adam since ~2013; Corey since at least 2015).
  • Roles:
  • Corey Caplan – CEO/CTO of Leavitt Innovations, director of Dolomite Foundation, and commonly described as founder of Dolomite.
  • Adam Knuckey – COO and lead frontend engineer at Leavitt Innovations, co‑founder of Dolomite.
  • Team size: The core dev team at Leavitt Innovations is stated as 6 individuals, including Adam and Corey, plus identified engineers and growth lead.
  • Mix of public vs anon: Several team members (Corey, Adam, Josef Holm, others) are fully public; at least one smart contract engineer is pseudonymous (e.g., “Bowtied Oriole”), indicating a hybrid public/anon team structure. ### Prior Projects, Track Record & Credibility
  • The founders previously built one of the first DEXs on Loopring and have been active since the “open finance” era.
  • Dolomite’s origins go back to 2018–2019 as an Ethereum DEX, later migrating to Arbitrum in 2022.
  • Multiple independent pieces highlight Dolomite as a next‑gen money market on Arbitrum with integrations and substantial TVL, and mention no known protocol hacks; AMA and media coverage emphasize a “spotless track record over two years,” which is an *unverified marketing claim*.
  • Corey Caplan’s advisor/CTO roles at World Liberty Financial are covered by major media (The Block, Binance), supporting the view that he is a recognized industry participant, not an anonymous founder. ### Corporate Reality: Jurisdiction, Office, Business Substance
  • Startup profiles describe Dolomite.io as founded in 2018 and based in Dover, Delaware, suggesting a US corporate entity.
  • The Arbitrum governance application and F6S listing describe team members located in New York City, United States, and link Dolomite to Leavitt Innovations and the Dolomite Foundation, implying a structured corporate stack rather than a purely offshore shell.
  • No primary source confirming a physical office address or specific corporate registration details was found; this is Not verifiable as of 2026-09-04. ### Reality Check
  • Founders are real, public, and traceable, with consistent biographies across independent media, startup databases, and governance records—this supports high credibility.
  • The project operates as a commercial US-linked business (Delaware base, NY team, named investors like Draper Goren Holm, NGC, Coinbase Ventures), not just a web-only front.
  • Some contributors remain pseudonymous, and on‑chain corporate structuring or legal entity filings cannot be validated here: Not verifiable as of 2026-09-04.
Evidence (15)

general reputation

one source

Dolomite is a margin trading / lending protocol originally on Arbitrum, now expanding to Ethereum and Berachain. Reputation is niche but generally positive among DeFi users, with no major fraud or insolvency events reported. Not verifiable on-chain as of 2026-09-04. 1. Protocol & team reputation

  • Dolomite launched as a margin and spot trading platform on Arbitrum; community discussions frame it as a smaller but technically sophisticated competitor to GMX-style ecosystems.
  • Public materials highlight co‑founders with prior experience in crypto and software engineering, but there is limited mainstream media coverage; most references are in DeFi Twitter, forums, and podcasts.
  • No evidence in search results of the protocol or founders being associated with prior rugs, major hacks, or fraud allegations. 2. Audits, security & investors
  • Multiple audit mentions exist in secondary sources (Medium, forum posts), but the underlying audit PDFs and auditor names are not clearly surfaced in independent repositories in the last 7 days. Not verifiable as of 2026-09-04.
  • No Tier‑1 VC (e.g., a16z, Paradigm) involvement is clearly documented in independent sources; Dolomite appears more community/angel backed than headline VC backed. Not verifiable as of 2026-09-04. 3. Sentiment & criticisms
  • DeFi user sentiment on social platforms is moderately positive, focused on capital efficiency and margin features on Arbitrum, but with concerns about:
  • Smart‑contract risk relative to larger, more battle‑tested protocols.
  • Thin liquidity and lower volume vs. leading perp DEXs and lending markets, which amplifies liquidation and slippage risk.
  • No widely reported catastrophic exploit or insolvency event appears in recent search results. 4. Legal, regulatory, sanctions
  • No records in sanctions lists or major regulatory enforcement databases (OFAC, SEC, CFTC) mention Dolomite or its principals in the last 7 days.
  • There is no evidence of formal licensing as a regulated exchange or broker; the protocol operates as typical unregistered DeFi infrastructure. Not verifiable as of 2026-09-04. 5. Outstanding risk flags
  • Limited independent audit transparency (who, when, scope) in easily verifiable public sources.
  • Small protocol size and concentration on Arbitrum/Ethereum mean higher relative smart contract / liquidity / governance risk vs. blue‑chip DeFi.
  • Absence of clear, independent documentation of investor base, corporate entity structure, and insurance or backstop funds. Overall, Dolomite appears non‑fraudulent but under‑researched, with typical DeFi smart‑contract and liquidity risks and a thinner public record than major incumbents.
Evidence (3)

Economy

TVL: $323.4M

model

one source

As of September 6, 2026. Dolomite is a multi-product money market/DEX, not a single yield vault: overcollateralized lending, isolated borrow positions, spot trading, margin, looping, hedging, and curated strategies. Supported assets include ETH/WETH, BTC, stablecoins, yield-bearing tokens, LP/GM assets, and other listed markets; exact current asset inventory by chain is Not verifiable as of September 6, 2026. Yield and exposure. Base supplier yield is primarily borrower interest determined by utilization—organic but variable. Additional DOLO or external-protocol rewards are subsidized/incentive yield.

Yield-bearing collateral can stack underlying staking/savings yield with lending yield and incentives. Lending can be market-neutral; looping, leveraged LP/GMX/strategy positions, and directional borrowing create price, liquidation, oracle, wrapper, and external-protocol exposure. Dolomite explicitly supports looping and hedging. Leverage/collateral. Leverage is user- and asset-dependent; exact protocol-wide leverage ratio is Not verifiable as of September 6, 2026.

Global minimum collateralization is documented as 115% on Arbitrum/Berachain and 117.65% on Ethereum, before asset-specific premiums; supply caps and liquidation parameters limit risk. Withdrawals, locks, fees. Deposits enter a pooled/virtual Dolomite Balance. Borrow-position collateral generally must be debt-free before removal; withdrawal liquidity can tighten when utilization is high. Current withdrawal gates, limits, and fee schedules are Not verifiable as of September 6, 2026.

DOLO→veDOLO locks have a maximum two-year duration; early-exit fees are documented, including a 5% burn plus a declining recoup fee. Revenue. Revenue sources include the lending interest spread, liquidation-related fees, trading fees, and potentially strategy/integration economics. DeFiLlama reports $1.07m fees and $214k revenue over 30 days, but this is analytics data, not raw on-chain verification. TVL/APY contradiction. DeFiLlama reports $318.78m aggregate TVL, +36.7% over 30 days, with Ethereum at 92.1%; its Arbitrum chain page separately shows Dolomite at $19.71m. This inconsistency is unresolved.

Dune TVL, product splits, chain percentages, trend comparison, and APY history/volatility are Not verifiable as of September 6, 2026. DefiLlama currently lists seven chains, not only the three specified.

Evidence (5)

reserves

one source

As of September 6, 2026, Dolomite’s reserve/treasury position is only partially disclosed. Dune MCP was unavailable in this run, so treasury addresses, balances, composition, and cross-chain exposure were not independently verified on-chain: Not verifiable as of September 6, 2026. Disclosed evidence: Dolomite governance documentation describes a treasury multisig and states that, in a proposal dated August 29, 2025, the treasury held “several million dollars” of stablecoins on Berachain, specifically USDC.e, with a proposed $500,000 WBTC deployment to Arbitrum. This is a historical, protocol-authored disclosure and is stale for current balances.

A third-party-hosted Dolomite whitepaper states that 9.65% of DOLO was allocated to the Dolomite Foundation as a treasury reserve. This is a token-allocation claim, not evidence of current liquid reserves, custody, or realizable USD value. Addresses / custody / control: Dolomite publishes core protocol Gnosis Safe and delayed-multisig addresses, and documents a 2-of-3 Gnosis Safe controlling the delayed multisig for protocol administration. However, the sources reviewed do not establish that these are the treasury asset-holding wallets, nor do they disclose signer identities or a complete treasury address set for Arbitrum, Berachain, and Ethereum. Reserve policy / attestations: No formal minimum-reserve policy, regular proof-of-reserves, liabilities reconciliation, or independent treasury attestation was found.

Smart-contract audits exist, but they are not treasury attestations. Contradiction / data-quality callout: The prior finding referenced a 2% Protocol-Owned Liquidity allocation, while current DeFiLlama modeling shows 3.3% current liquidity and 2.5% final liquidity. This discrepancy concerns tokenomics modeling, not verified treasury balances. Protocol liabilities attributable to treasury borrowing or other obligations are Not verifiable as of September 6, 2026; user loans shown by aggregators should not be treated as treasury liabilities.

Evidence (6)

tokenomics

two sources

DOLO (Dolomite) — нативный governance/utility-токен; один адрес на Arbitrum, Berachain и Ethereum: 0x0F81001eF0A83ecCE5ccebf63EB302c70a39a654. TGE: 24 апреля 2025 года. Supply и оценка (срез 4 сентября 2026): максимальный supply — 1 млрд DOLO; CoinGecko показывает circulating 510.692 млн, total 998.431 млн, цену около $0.027, market cap $13.79 млн, FDV $26.96 млн.

Разница с 1 млрд отражает сожжённые токены. Utility/governance: DOLO используется для ликвидности и конвертации в veDOLO; veDOLO даёт voting power, зависящую от срока lock, и участвует в решениях по листингам, risk-параметрам, treasury, incentives и tokenomics. oDOLO распределяется еженедельно LP и должен быть спарен 1:1 с DOLO для покупки discounted veDOLO. Доходность, buybacks, burns, emissions: прямой revenue share veDOLO — только возможность, которую должен одобрить DAO; гарантированной выплаты нет.

Exit из lock включает базовый burn fee 5% (изменяемый governance). Запланирована инфляция 3% годовых после четвёртого года; DAO может направлять её на incentives или сжигать. oDOLO — основной programmatic incentive. Распределение: community 50.75% (включая liquidity mining 20%, airdrop 20%, Minerals 10%, retroactive usage 9%); core team 20.2075%; foundation 10.6511%; investors 15.1846%; service providers 3%; advisors 0.2068%.

Team: 3 года vesting с 1-летним cliff; инвесторы: 1.3933% в первые 12 месяцев и 13.7913% за 3 года с cliff. Unlocks/концентрация: следующий агрегаторный unlock — 14.25 млн DOLO 24 сентября 2026 года. Фактическое исполнение заявленных unlocks on-chain и текущая концентрация top-holder/insider wallets: Not verifiable as of September 4, 2026 (Dune недоступен). Контроль/риски: ABI ERC-20 содержит mint, burn, ownerSetMinter, ownerSetCCIPAdmin; blacklist и transfer-fee функции не обнаружены.

Текущий owner/minter control: Not verifiable as of September 4, 2026. Ликвидность/листинги: заявлены POL-пулы Kodiak (Berachain) и Uniswap (Ethereum); текущая DEX-глубина: Not verifiable as of September 4, 2026. Основные отслеживаемые рынки — Binance, LBank, MEXC, Coinbase и другие CEX.

Противоречие: официальная модель — 1 млрд max supply, тогда как агрегаторы показывают 998.431 млн total supply и 510.692 млн circulating; для оценки ликвидности и overhang следует использовать агрегаторные значения как текущий off-chain snapshot, но не как Dune on-chain verification.

Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would likely stress Dolomite mainly through market-wide collateral revaluation and increased liquidation frequency, not through any Bitcoin-specific protocol rule. Dolomite states that liquidations occur when an account’s collateralization falls below the minimum threshold for the debt assets owed, with a protocol liquidation threshold described as 115% in current docs and whitepaper materials. If BTC is used as collateral on Arbitrum, Berachain, or Ethereum, a sharp BTC drawdown would reduce account health and could push leveraged borrowers below threshold, triggering liquidations.

The severity depends on each chain’s actual BTC-collateral exposure, which is Not verifiable as of 2026-09-04 because no on-chain data was available in this run. Dolomite’s design is meant to reduce contagion: it uses isolated positions, asset-specific risk parameters, and partial/gradual liquidation mechanics to limit spillover and price impact. That means a BTC crash would more likely create a localized liquidation wave across affected accounts than a protocol-wide insolvency by itself, unless market depth and liquidator capacity failed at the same time.

There is also a broader tail-risk scenario where a BTC crash below $10,000 coincides with liquidity stress, forced deleveraging, and weak liquidator demand; under that combination, liquidation proceeds could be insufficient to cover debt, creating bad debt risk. That macro-path is consistent with external market commentary describing a sub-$10,000 BTC outcome as a multi-factor stress event rather than a base case. Key risk questions for this stress test:

  • How much BTC-denominated collateral sits on each chain?
  • What fraction of borrowers are near health factor 1?
  • Is liquidator inventory deep enough to absorb partial liquidations without large slippage?
  • Are any positions isolated in ways that limit cross-account contagion? The on-chain exposure split by Arbitrum / Berachain / Ethereum is Not verifiable as of 2026-09-04.
Evidence (10)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg of the largest collateral would reduce the USD value of that collateral by 20%; the direct effect is that every affected account’s health factor falls by the same 20% on the collateral side, which can push positions below Dolomite’s liquidation threshold and trigger liquidations or partial liquidations where enabled. Dolomite’s published risk docs say liquidations occur once collateralization falls below the minimum threshold, with a default minimum collateralization framework around 115%, and partial liquidations can apply for some markets when health factor is at least 0.95. If the depeg is severe enough that conventional liquidation cannot cover losses, Dolomite’s materials describe an emergency Vaporize-style backstop for undercapitalized accounts, but that mechanism’s real-world activation under this exact scenario is Not verifiable as of 2026-09-04.

For Arbitrum, Berachain, and Ethereum, the chain-specific exposure to the largest collateral and the protocol’s aggregate loss under a 20% depeg are Not verifiable as of 2026-09-04 because no on-chain position data was provided and on-chain verification is unavailable in this run. The most defensible stress result is therefore qualitative: the protocol would see the highest risk on whichever chain holds the largest share of that collateral’s borrows, while isolated-margin design means losses should be contained to the affected positions rather than the entire book.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Dolomite, “top counterparty insolvent” stress generally means a large margin borrower or LP position goes to zero. Exact paths are Not verifiable as of 2026-09-04 on-chain and depend on Dolomite’s implementation on each chain. ### 1. Arbitrum – core deployment Likely top counterparties: leveraged borrowers using GMX/GLP and major collateral assets (ETH, BTC, stablecoins) via Dolomite’s margin system. Loss path:

  • Counterparty’s collateral value falls below debt; margin calls and liquidations trigger via Dolomite’s risk engine.
  • If liquidations cannot fully cover debt (price gaps, oracle failure, MEV), the shortfall becomes protocol insolvency in that asset pool. Who absorbs it:
  • Remaining lenders in the affected pool via under-collateralized loss (their claim per unit of dToken/claim token falls).
  • If a backstop/insurance fund or treasury is configured for bad debt (not verifiable as of 2026-09-04), it would absorb first; otherwise loss is socialized to depositors. Compensation:
  • Any explicit insurance/backstop or grants from Dolomite treasury / DAO, if such mechanisms exist; otherwise depositors are uncompensated and bear the haircut. Smart-contract impact path:
  • Borrower position under-collateralized → liquidation bots call margin/liquidation functions → collateral sold/swapped on integrated DEXs (GMX, other venues).
  • If still insolvent, accounting in pool contract records bad debt and reduces total assets backing interest-bearing tokens. ### 2. Berachain Dolomite has announced intent to deploy on Berachain; full live design is Not verifiable as of 2026-09-04. Stress mechanics should mirror Arbitrum:
  • Same margin/borrow logic; Berachain-specific assets and DEXs as liquidation venues.
  • Losses again flow to lenders in affected pools; any Berachain-specific insurance or backstop is Not verifiable as of 2026-09-04. ### 3. Ethereum Dolomite’s historical presence on Ethereum (earlier iterations and integrations) is referenced but current main activity is Arbitrum. Exact active contracts, pool sizes and counterparties are Not verifiable as of 2026-09-04.
  • If lending/margin pools exist, insolvency would follow the same pattern: failed liquidation → pool bad debt → depositor haircut; compensation depends on any Ethereum-side backstop (Not verifiable as of 2026-09-04). ### Cross-cutting fragilities in this scenario
  • Oracle failure or manipulation for integrated perpetuals/DEXs increases gap between real and protocol prices, worsening bad debt risk.
  • Concentration: a single large leveraged GLP/GMX borrower on Arbitrum failing can create outsized loss in specific asset pools; impact is localized by asset but systemic for that chain.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

Dolomite does not have verifiable evidence of committed fraud by the DAO or owners in the provided sources. The only clearly documented adverse event is a 2024 smart-contract exploit that drained about $1.8 million from an old Ethereum contract; the reporting attributes this to a vulnerability and reentrancy-style abuse, not to DAO or owner fraud. The strongest directly relevant security source is Dolomite’s audits-and-security page, which states that the DolomiteMargin Modules were audited by Zokyo and Guardian Audits.

Independent audit material also reports no high-severity issues in a separate security audit of Dolomite smart contracts. For the stress scenario of committed fraud by the DAO or owners, the outcome is therefore Not verifiable as of 2026-09-04 based on the available sources. The existing evidence supports a technical exploit risk history, but not a substantiated fraud allegation against Dolomite’s DAO or owners.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

Dolomite’s primary yield source is borrower interest paid to suppliers; its docs say users earn yield from borrower interest, and some markets may also show a separate blue APR from outside sources or incentives. In a negative 30-day yield stress case, the supplied-asset yield would be below zero only if the borrower-interest component and any external/incentive APR together net negative, which is Not verifiable as of 2026-09-04 from the provided sources alone. For the three requested chains, I can confirm Dolomite is active on Ethereum, Arbitrum, and Berachain from the project’s own site and third-party protocol listings, but the chain-by-chain exposure shares and 30-day yield decomposition are Not verifiable as of 2026-09-04 without on-chain or dashboard data.

The relevant risk implication is straightforward: if primary yield turns negative while borrow costs remain positive, the position’s carry deteriorates and health factor can fall toward liquidation; Dolomite’s risk docs state liquidations occur when collateralization falls below the minimum threshold, with a global minimum collateralization of 115% referenced in the docs. So the stress outcome is: yield becomes negative, carry worsens, and liquidation risk rises materially; the exact magnitude is Not verifiable as of 2026-09-04.

Evidence (6)

Governance & Legal

governance

one source

As of September 13, 2026, Dolomite appears operationally team/company-controlled with a limited DAO layer, not demonstrably autonomous. Control map: Development and contract maintenance are attributed to Leavitt Innovations; the public repository identifies Corey Caplan and Adam Knuckey as maintainers. Dolomite Ltd is identified in the Terms as the site/interface provider. Treasury execution is assigned to treasury multisig signers, while passed governance proposals are implemented by Leavitt Innovations.

The legal materials also identify Dolomite DAO LLC (Marshall Islands), Dolomite Foundation (Cayman Islands), and Leavitt Innovations (Delaware, U.S.; documents inconsistently describe it as “Inc.” and “LLC”). Registration number and directors: Not verifiable as of September 13, 2026. Proposal process: veDOLO holders discuss proposals in Discord, undergo a temperature check, then vote quarterly on BeraVote; stated launch parameters are approximately a 7-day vote, 5% quorum, and a Discord-based proposal threshold. Governance covers listings, tokenomics, risk parameters, treasury allocations, and incentives.

However, operators may independently perform listings and risk updates, and Leavitt executes approved proposals. Therefore DAO governance is materially influential for selected matters but partly symbolic for routine administration and execution. Admin powers/risk: Documentation describes a 2-of-3 Gnosis Safe behind a delayed multisig wallet, with a launch delay of 86,400 seconds (24 hours). Current threshold, signer identities, signer independence, and current delay are Not verifiable as of September 13, 2026.

Certain market-closing, market-cap, and interest-setter functions can bypass the timelock. Admins can set global operators with account-level permissions; the documentation itself identifies this as a major user-fund risk. Thus admin_can_drain is assessed true, and emergency_bypass true. Concentration: Top veDOLO/DOLO holders and voting concentration via Dune are Not verifiable as of September 13, 2026 because Dune MCP is unavailable.

No concentration percentage is inferred. Contradiction callout: Current governance documentation describes a quarterly BeraVote/Discord process, while older admin documentation describes initial deployment controls; neither establishes that token holders directly control all upgrades or admin powers. On the available evidence, DAO governance is false rather than fully autonomous.

Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

one source

As of September 4, 2026, Dolomite presents a multi-entity structure: Dolomite DAO LLC (Marshall Islands) represents the DAO; Dolomite Ltd. (British Virgin Islands) is identified as the token issuer and interface provider; Dolomite Foundation is a Cayman Islands foundation steward; and Leavitt Innovations, Inc. (Delaware, US) is the originating/development entity.

The Foundation’s disclosed registered address is 10 Market Street, Unit #2476, Camana Bay, Cayman Islands. Terms/restrictions. The Terms describe the interface as informational/non-custodial and disclaim custody or control of user assets. Users must not be US Persons, except eligible contract participants for specified non-OTC contracts; must not be from US/UK/EU-sanctioned or embargoed territories; must not be sanctioned; and must not use VPNs or anonymization tools to bypass restrictions.

Disputes are subject to BVI law and BVI International Arbitration Centre arbitration. KYC/AML. No affirmative user KYC/AML onboarding process was identified in the reviewed Dolomite materials. The restrictions are primarily representations, sanctions screening obligations, and geofencing terms rather than a documented customer-identification program. Not verifiable as of September 4, 2026 whether any backend/interface-level screening or transaction monitoring is implemented. Classification. Dolomite offers lending, borrowing, margin trading, spot trading and other financial instruments.

Its Terms’ ECP requirement for certain US access indicates material derivatives/commodities-law perimeter risk, but no regulator has publicly classified the protocol or DOLO in the sources reviewed. This is not a legal classification. Enforcement, litigation, sanctions. No regulator enforcement action, court case, or sanctions designation against Dolomite, its identified entities, or DOLO was located in the reviewed searches.

This does not establish legal clearance. Data protection: no standalone privacy policy or detailed GDPR/CCPA framework was located; the interface states it uses strictly necessary cookies. Not verifiable as of September 4, 2026 whether broader data-processing disclosures exist. Actual-risk assessment. The offshore foundation/DAO wrappers and Delaware developer create entity-level separation, but do not eliminate potential exposure of identifiable operators, issuers, interface providers, or governance participants. The protocol remains permissionless at the smart-contract layer while the interface retains contractual restrictions and some administrative/governance control.

This structure reduces direct custody risk but does not remove regulatory-perimeter, sanctions, securities/derivatives, consumer-protection, or enforcement risk.

Active enforcement
No
Sanctioned
No
Entity
Dolomite DAO LLC (Marshall Islands); Dolomite Ltd. (British Virgin Islands); Dolomite Foundation (Cayman Islands); Leavitt Innovations, Inc. (Delaware, United States)
Jurisdiction
Marshall Islands, British Virgin Islands, Cayman Islands, and Delaware, United States
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Dolomite DAO LLC', 'Leavitt Innovations Inc'. OFAC SDN screening of 'Dolomite DAO LLC', 'Leavitt Innovations Inc': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Dolomite DAO LLC
  • Leavitt Innovations Inc
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Dolomite does not appear to issue its own stablecoin. The stablecoin used on Dolomite in the evidence gathered is USD1, which is described as World Liberty Financial’s stablecoin, not a Dolomite-issued asset. A USD1 depeg on Dolomite is not verifiable from the available evidence, so depeg_count, last_depeg_date, and max_depeg_pct are all Not verifiable as of 2026-09-06.

The web evidence instead shows USD1 being supplied, borrowed, and used in a tight-liquidity episode on Dolomite, but not a confirmed price depeg event on the protocol. Structured fields:

  • own_stablecoin: false
  • stable: null
  • depeg_count: null
  • max_depeg_pct: null
  • last_depeg_date: null
  • stablecoin_ids: ["USD1"]
Own stablecoin
No
Stablecoin ids
  • USD1
Evidence (3)

Risks & Strengths

risks

one source

Dolomite’s principal risks are concentrated in oracle-dependent collateral valuation, actively developed module/integration code, privileged administration, liquidation execution, and multi-chain operational fragmentation. Audits, coverage, risk limits, collateral-only modes, timelocks, and a bug bounty reduce—but do not eliminate—these risks; current TVL, exposure concentration, and live chain-by-chain balances are Not verifiable as of September 5, 2026 because Dune on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle and collateral valuationIncorrect, stale, manipulated, or economically non-redeemable prices can permit undercollateralized borrowing, wrongful liquidations, or protocol bad debt. Dolomite uses Chainlink where possible but also supports bespoke calculations for assets such as GLP.HighMediumChainlink feeds, asset-specific pricing logic, collateral-only mode, market caps, risk premiums, and segregated-risk features where supported.High-impact oracle or wrapper failure remains possible, particularly for complex or thinly traded collateral.
Smart-contract and integration bugsThe active Modules repository contains integrations and new features; a logic, accounting, authorization, or composability bug could cause direct loss or insolvency. Audit scope differs across releases and repositories.HighMediumSix reported audits, extensive tests, claimed 100% line/statement/branch coverage, separate Core/Modules architecture, and an open bug bounty.Medium-High; audits and coverage cannot prove absence of undiscovered economic or integration vulnerabilities.
Privileged administration and operatorsAdmins can change market oracles, interest setters, caps, market status, and global operators; a malicious, compromised, or erroneous operator could affect many user accounts. Some functions can bypass the timelock.HighMediumMultisig ownership, timelocked administration, immutable risk ceilings, role separation, and emergency bypass capability.Medium-High; governance/key compromise and trusted-operator concentration remain material.
Liquidation failure and bad debtSharp price gaps, thin liquidity, congestion, oracle delays, or insufficient liquidator capacity can leave underwater positions unresolved and socialize losses. Dolomite documents a 5% global liquidation penalty and currently emphasizes full liquidations.HighHighHealth factors, liquidation penalties, market risk premiums, supply/borrow limits, collateral-only mode, and liquidation infrastructure.High during correlated market stress or rapid collateral devaluation.
Multi-chain and bridge fragmentationSeparate Arbitrum, Berachain, and Ethereum deployments can fragment liquidity and monitoring; bridge, RPC, sequencer, or chain-specific integration failures may impair deposits, withdrawals, pricing, or liquidations. Network-specific liquidity and APRs differ.MediumMediumNetwork-specific market configuration, separate liquidity pools, backup RPC guidance, and asset capability restrictions by network.Medium-High; exact cross-chain exposure and concentration are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Dolomite’s top strengths are: capital efficiency through a design that lets assets serve multiple roles at once; broad asset support, including LP and yield-bearing assets; integrated trading + lending in one protocol for margin, spot, and borrowing workflows; modular architecture that can add features without redesigning the core; and risk isolation / portfolio control via isolated accounts and position management. These strengths are stated consistently across Dolomite’s docs and multiple independent explainers, though the protocol’s own claims should be treated as unverified marketing unless independently confirmed.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 15 one source, 18 unverified.
  • Oldest fact verification date: 2026-08-29.