Frax

Orange · 62/100

Executive summary

Frax is a multi-product DeFi protocol centered on the FRAX stablecoin, frxETH liquid staking, and Fraxlend, scoring 75/100 (green band) with high data confidence (89/100).

  • Security: Extensive audit history since 2020 (CertiK, Trail of Bits, ChainSecurity, Code4rena, Zellic, internal Frax Security Cartel); initial 2020 audit found 3 critical and 8 major issues, with criticals fixed but some majors reportedly unaddressed; recent audits show 0–2 critical findings per report, mostly remediated; bytecode-match to deployed contracts is not verifiable as of September 2026 across all chains; $10M bug bounty active.
  • Incidents: No direct protocol exploit causing user-fund loss; indirect exposure via Rari Fuse hack (April 2022, ~$13M Frax reserves affected, reimbursement status unverified), Float/Rari oracle manipulation (January 2022, Frax-specific loss unverified), and Harmony Horizon bridge compromise (June 2022, $6.2M canFRAX/canFXS stolen, not reimbursed, remediation in progress); November 2023 DNS hijacking resolved with no confirmed fund loss.
  • Governance & custody: Hybrid DAO governance via veFXS/veFRAX holders (Alpha track) and Safe multisig execution (Omega track with veto rights); Safe owners control >$1B and can execute protocol-wide changes; frxUSD custody delegated to Frax Inc. with regulated custodians (BitGo, others) holding segregated reserve sleeves (USDC, BUIDL, USTB, WTGXX); exact signer identities, thresholds, and chain-by-chain Safe configuration not verifiable; emergency 51% bypass exists.
  • Top risks: (1) Governance/admin concentration—compromised Safe signers or veFXS capture could drain treasury or destabilize peg; (2) RWA/custodian counterparty risk—frxUSD backed by tokenized Treasuries and stablecoins via third-party custodians; issuer, fund NAV, or custodian failure could impair redemptions and cause depeg; (3) Oracle/peg dependence—thin liquidity or stale oracles in Fraxlend and Curve AMOs can trigger cascading liquidations; (4) Cross-chain bridge risk—LayerZero OFT and custom bridges expose users to bridge exploits and asset stranding; (5) Validator/LST risk—frxETH depends on Ethereum validators, exit queues, and Beacon Oracle uptime; slashing or operator failure can break the ETH peg.
  • Strengths: Capital-efficient fractional-algorithmic stablecoin design with dynamic collateralization; AMO-driven balance-sheet management for peg stability and revenue; modular multi-chain ecosystem including Fraxtal L2; strong audit cadence and large bug bounty; governance/utility alignment via FXS; mature product with live APIs, cross-chain deployment, and active user base.
  • Unverified: Current collateral composition, chain-by-chain TVL, exact Safe signer identities/thresholds, deployed-code bytecode match for recent audits, RWA reserve allocations (protocol-reported only), exact veFXS voting concentration, and recovery amounts from Rari/Harmony incidents are not verifiable as of September 2026; frxUSD backing by BUIDL/USTB/WTGXX is an unverified marketing claim absent independent attestation.
  • Recommended exposure: Conservative position sizing (≤5% of portfolio) given governance concentration, RWA/custodian opacity, and unverified reserve composition; prefer FRAX over frxUSD for lower custodian/issuer risk; limit frxETH exposure due to validator/oracle dependencies; avoid leveraged or looped positions; monitor Safe signer changes, collateral-ratio updates, and custodian attestations; require independent reserve audit before scaling; suitable only for allocators comfortable with hybrid DAO/team control and material counterparty risk.
  • Open questions: (1) Verify current Safe signer identities, thresholds, and hardware-wallet usage across all chains; (2) obtain independent attestation of frxUSD reserves and custodian arrangements; (3) confirm bytecode match between audited code and deployed contracts for recent reports; (4) quantify exact Frax recovery from Rari and Harmony incidents; (5) assess veFXS voting concentration and top-holder influence; (6) verify LayerZero OFT security and bridge-loss insurance; (7) review Frax Inc. delegation terms and DAO revocation process for frxUSD; (8) confirm current collateral ratio, AMO exposure, and RWA allocation by chain.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 25 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2025-09-12 is older than a year
Incidents 20% 84 16.8 1 open incident(s), $6,181,000 at risk = 16.4% of TVL (threshold 10%); penalty proportional to assets at risk
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $37,620,040 = 0% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 31/68 verified facts; 68/68 fresh (180d)

Identification

protocol identification

two sources

Frax is a stablecoin and DeFi protocol suite centered on the FRAX stablecoin and related products (e.g., Fraxswap, Fraxlend, Frax Ether, Fraxchain/Fraxtal). It operates across multiple EVM chains and its own Fraxtal L2. ### Basic Identification

  • Name: Frax Finance / Frax Protocol
  • Website: frax.finance (landing and app)
  • Docs: docs.frax.finance and app.frax.finance/docs
  • Category: Algorithmic / partially collateralized stablecoin protocol, lending, AMM, L2 (Fraxtal)
  • Native tokens:
  • FRAX (USD stablecoin)
  • Frax Share (FXS) – governance / value-accrual token
  • Additional: frxETH/sfrxETH on Ethereum (ETH staking derivative)
  • Chains with material deployment: Ethereum, Arbitrum, Optimism, Polygon, BSC, Avalanche, Fantom, Fraxtal (Fraxchain), plus others via bridges/LPs. Precise on-chain distribution: Not verifiable as of 2026-09-04.
  • Launch date: FRAX/FXS initial launch around late 2020–January 2021 (public docs and historical articles converge on this window). ### Main Contract Addresses (cross‑checked by ≥2 non‑protocol sources) *(On‑chain/Dune verification explicitly unavailable; only explorer/analytics cross‑checks.)*
  • Ethereum (core tokens)
  • FRAX (ERC‑20): widely referenced Etherscan-verified contract as primary FRAX stablecoin.
  • FXS (ERC‑20): Etherscan-verified governance token contract.
  • frxETH / sfrxETH: staking/derivative contracts used by major aggregators and CEX listings.
  • Other chains (mirrored/bridge deployments)
  • FRAX and FXS exist as canonical or bridged tokens on Arbitrum, Avalanche, BSC, Fantom, Optimism, Polygon, with contract addresses matching across DeFiLlama, major explorers, and CEX/portfolio aggregators. Exact per-chain address lists: Not verifiable as of 2026-09-04 within the constraints. All cited core Ethereum contracts are marked *“Contract source code verified”* on Etherscan, giving explorer-level verification. ### Fork Lineage & Code Origin
  • Stablecoin design: Frax is *not* a simple fork of a single upstream project. It introduced a hybrid algorithmic–collateralized model distinct from MakerDAO’s DAI or empty-set-style algo coins.
  • AMM/lending components: Fraxswap and Fraxlend take inspiration from Uniswap/Curve and lending protocols but are implemented as custom systems rather than straight-line forks according to independent technical reviews and audits.
  • Audits: Multiple audits by firms such as Trail of Bits, Certora, and others are reported by third-party audit platforms and media, covering core protocol, Fraxswap, and frxETH/sfrxETH. Individual audit scope per component Not fully verifiable as of 2026-09-04.
  • Malicious‑modification history in forks: Independent media and analytics do not report a history of malicious code modifications in popular Frax forks; issues discussed are primarily economic/stability risks, not overt backdoors. On-chain contract lineage and exact fork trees: Not verifiable as of 2026-09-04 without Dune/primary-code diffing.
Evidence (5)

maturity

two sources

Frax looks like a mature, live product rather than a simple landing page: the public site points to a dedicated app at app.frax.finance, and the docs include direct product links plus multiple API endpoints, including Swagger docs and REST endpoints that do not require authentication. The documentation surface is reasonably developed and split across product areas, with Fraxtal/Frax docs exposing API pages and link directories rather than marketing-only pages. There is evidence of active user-facing functionality for bridging and withdrawals: frax.com has a live withdraw flow for frxUSD, described as “Seamlessly receive frxUSD directly in your crypto wallet,” which indicates an operational product path rather than a placeholder.

The docs also describe cross-chain redemption and deposit processing via the FraxNet orchestration API, including deposit address retrieval and redemption endpoints. Open API: yes. Frax publishes public REST APIs and Swagger documentation, with documented base URLs, combined data endpoints, pool APR endpoints, and no-authentication access for the FraxNet orchestration API.

I did not find strong evidence of broken links, fake metrics, or obvious template-site signs in the retrieved material, but that specific quality check is only partially verifiable from the available sources. Not verifiable as of 2026-09-04.

Evidence (5)

Security

bug bounty

two sources

Frax Finance appears to have an active internal bug bounty program. The program scope covers smart contracts deployed by Frax Deployer addresses, including Fraxswap AMM, Fraxlend, frxETH, frxUSD, and sfrxUSD, on any chain managing Frax Protocol value or user-deposited value. It explicitly excludes front-end/UI and server-side web bugs.

Rewards are described as the lower of 10% of the total possible exploit or $10 million, paid in FRAX+FXS (later language also references frxUSD+FRAX), with a base compensation of 50,000 FRAX for slow-arbitrage/value-extraction issues. Submission is via private GitHub gist, and the policy is “no questions asked” for disclosures or immediate return of funds. Public third-party coverage also says the program is active via Immunefi, but the most directly supported source here is Frax’s own bug bounty page.

A 2022 governance proposal to use Hats Finance suggests the program was discussed then, but the current program language is present by 2024-2026. Reported results visible in the gathered sources are limited; one public example mentions a GMX exploiter returning FRAX in exchange for a white-hat bounty, but that is not a Frax bounty payout record. Overall bounty outcome statistics are not verifiable as of 2026-09-04.

Active
Yes
Platform
Internal / Immunefi-referenced
Max payout
$10.0M
Since
2024-01-27
Evidence (4)

counterparty risks

two sources

Assessment (as of September 5, 2026): HIGH dependency complexity; no confirmed active failure. Dune/on-chain verification was unavailable: Not verifiable as of September 5, 2026 for exact collateral, bridge balances, oracle exposure, custodian concentration, CEX/MM exposure, and chain-by-chain percentages.

  • Stablecoin/RWA/custodian risk: Current frxUSD documentation describes 1:1 backing by permitted cash-equivalent/tokenized Treasury assets, including BUIDL, USTB, JTRSY, WTGXX and AUSD, with regulated custodians and Frax Inc. managing collateral/redemptions. This creates issuer, fund NAV, custodian, banking, KYC/compliance and redemption-gate risk. Named RWA allocations are protocol-reported and therefore unverified marketing claims. A failure or freeze at a custodian, fund, issuer, or Frax Inc. could impair redemptions and cause frxUSD/sfrxUSD depeg or insolvency losses.
  • External DeFi dependencies: Legacy FRAX stability mechanisms use Curve, while Fraxlend pairs depend on asset/collateral oracles. Thin liquidity, stale prices, oracle manipulation, bad debt or Curve contagion could trigger liquidations and destabilize FRAX-related markets.
  • LST/validator risk: frxETH/sfrxETH depend on Ethereum validators, exit queues, the Beacon Oracle service/bot, and a 2% insurance allocation. Validator slashing, operator failure, oracle downtime or delayed exits can break the ETH peg or create redemption queues.
  • Bridge risk: Cross-chain Frax assets rely on LayerZero OFTs, Frax Mesh/Hub routing, chain-specific adapters, 3/6 multisigs, and the Fraxtal OP Stack bridge. A compromised endpoint, multisig, mint/burn adapter, sequencer, or message-routing layer could create unauthorized supply or trapped liquidity.
  • Failure scenarios: RWA/custodian insolvency → redemption impairment; US-dollar stablecoin depeg → collateral NAV loss; oracle/Curve failure → liquidations/bad debt; validator slashing → frxETH loss; bridge exploit → cross-chain insolvency; governance or multisig compromise → unauthorized minting. Contradiction / data gap: DeFiLlama reports combined Frax Finance TVL of approximately $294.8m, while its narrower Frax page reports approximately $41.4m; these are different scopes, not reconciled on-chain. Current frxUSD market data shows approximately $0.9999, so no active market depeg was identified; this is not an on-chain solvency verification.
Dependency failure active
No
Evidence (6)

crypto custody

two sources

Frax’s crypto custody is organized in a hybrid, role-separated model rather than a single protocol-controlled pool. For frxUSD, governance delegated issuer-level compliance and collateral management to Frax Inc., which handles custodian oversight, reserve composition, audits/attestations, KYC/KYB, and redemption operations; the reserves themselves are held with regulated custodians through approved, asset-specific custodian contracts with mint/redeem caps. The best-supported reading is that custody is segregated by custodian and reserve sleeve, not pooled across all assets: each frxUSD custodian contract holds a specific backing asset such as USDC, USDB, BUIDL, USTB, or WTGXX, and Frax’s documentation describes these as non-custodial mint/redeem vaults tied to particular reserves.

Public reporting and third-party research also describe institutional custody arrangements involving regulated providers such as BitGo and others for the reserve assets. withdrawal_paused: Not verifiable as of 2026-09-06 segregated_assets: true

Segregated assets
Yes
Evidence (6)

incident

two sources

On January 30, 2022, a price-manipulation attack targeted Float Protocol’s Rari Fuse Pool 90 on Ethereum. The attacker manipulated the thin FLOAT/USDC Uniswap V3 oracle, deposited overvalued FLOAT, and borrowed approximately 350 ETH (about $1.1 million at incident-time prices). FRAX AMO funds were identified among the affected depositors, but the Frax-specific realised loss is Not verifiable as of 2026-09-05.

Approximately $250,000 was reportedly returned or remained in the attacker contract; attribution to Frax is Not verifiable as of 2026-09-05. Response included investigation and oracle-risk remediation by Float/Rari. Frax-user reimbursement is Not verifiable as of 2026-09-05.

Current status: resolved for the historical exploit; no ongoing loss was identified.

Date
2022-01-30
Cause
Oracle manipulation
Status
resolved
Event id
frax-2022-01-30-float-rari-oracle
Evidence (2)

incident

two sources

On April 30, 2022, the Rari Capital Fuse lending pools on Ethereum were exploited through a reentrancy flaw in the Compound-derived pool logic. The attack drained roughly $80 million across several pools, including approximately 13.1 million FRAX; independent risk reporting attributes about $13 million of realised loss to Frax reserves. Affected parties included Frax’s AMO/treasury exposure and other Fuse depositors.

Rari/Fei paused activity, offered a $10 million bounty, and later patched/wound down Fuse. Tribe DAO ultimately approved and executed a reimbursement plan for hack victims in September 2022, but the exact amount reimbursed to Frax and whether it fully covered Frax’s approximately $13 million loss are Not verifiable as of 2026-09-05. Current status: resolved technically and at the ecosystem wind-down level; Frax-specific recovery remains unverified.

Date
2022-04-30
Cause
Smart-contract exploit
Loss
$13.0M
Status
resolved
Event id
frax-2022-04-30-rari-fuse
Evidence (4)

incident

one source

Since launch, I found no verified on-chain loss incident for Frax in the retrieved sources; Frax’s own governance states it had “0 critical vulnerabilities where the protocol or any user has lost funds to a vulnerability/bug,” and a later independent assessment also says there has not been a substantial security incident causing user-fund loss.

Date
2022-06-08
Cause
Other
Evidence (2)

incident

two sources

June 23–24, 2022 — Harmony Horizon Bridge compromise, affecting Frax-backed canFRAX/canFXS on Harmony (outside the user-specified chain set). Attackers compromised bridge signing keys and drained approximately 5.62m FRAX ($5.609m) and 110,000 FXS ($0.572m); estimated realised loss: $6.181m at incident-time prices. Attacker proceeds: $6.181m stolen-value estimate; actual liquidation proceeds are Not verifiable as of 2026-09-04.

Frax’s response was to treat Harmony as responsible, retire the outstanding canFRAX/canFXS, and direct holders to Harmony’s recovery process. Frax did not reimburse holders. Recovered: $0 confirmed for Frax holders; reimbursement status: not confirmed.

Outstanding canFRAX/canFXS were later recorded by Frax governance at 8.139m and 123,959.834 respectively. Recovery/buyback efforts continued through 2025, but full restitution was not evidenced; current status: remediation_in_progress.

Date
2022-06-24
Cause
Key compromise
Loss
$6.2M
Attacker proceeds
$6.2M
Status
remediation in progress
Recovered
$0
Reimbursed
No
Evidence (4)

incident

two sources

Key-management / custody is materially centralized: an independent risk assessment says the Frax core-team multisig controls over $1B of assets and, if compromised, would give an attacker control of the protocol and those assets; another governance post notes that, historically, a core-team 3/6 Safe multisig had admin control over Frax contracts and assets.

Date
2022-09-27
Cause
Key compromise
Evidence (2)

incident

two sources

November 1, 2023 — Frax.com and frax.finance domain/DNS hijacking attempt. The incident affected users accessing Frax’s web front end and created phishing risk; no confirmed protocol or user fund loss was reported in the available sources. loss_usd and recovered_usd: Not verifiable as of 2026-09-04. Frax and registrar Name.com restored the domains and DNS settings; the registrar investigation outcome and any reimbursement are Not verifiable as of 2026-09-04.

Current status: resolved for domain control, with no confirmed financial loss.

Date
2023-11-01
Cause
Frontend / infrastructure hack
Status
resolved
Evidence (2)

incident

two sources

For frxUSD specifically, governance/delegated-operating responsibility was shifted to Frax Inc. under FIP-432, with responsibility for custodian oversight, reserve composition, audits, and attestations; that is a governance/operational custody concentration rather than a disclosed incident.

Date
2025-12-15
Cause
Other
Evidence (2)

incident

two sources

Frax maintains a public bug bounty program covering contracts deployed by FRAX-Deployer, including smart-contract exploits where user funds or protocol-controlled funds/collateral are at risk; the bounty is the lesser of 10% of the exploit value or $10m, paid in FRAX+FXS or frxUSD+FRAX depending on the source, with a no-questions-asked disclosure path and a stated turnaround of up to 5 days.

Date
2026-06-02
Cause
Other
Evidence (4)

key management

two sources

Frax’s key management appears to be split between *onchain governance* and *multisig/operator controls*. The strongest public evidence says the protocol is controlled by veFXS holders through a dual Governor system, FraxGovernorAlpha and FraxGovernorOmega, which governs the Gnosis Safes that hold protocol authority. Operationally, Frax also uses multisigs for sensitive non-governance actions: a Frax security post states that all multisig signers use hardware wallets, and all code pushes require authenticated hardware security keys.

For frxUSD lockboxes and OFT infrastructure, an independent review says they are managed by a 3/5 multisig on each supported chain. For validator-related operations in frxETH V2, key material is more specialized: users supply their own ETH plus public keys, signatures, and deposit data roots for validators, while an offchain Beacon Oracle service monitors validators and can trigger exits. That indicates validator key handling is partly user-provided and partly operator-oracle controlled, but the exact signing / custody split is not fully verifiable from the available sources.

Across the listed chains, the publicly documented pattern is therefore: governance keys are not held by a single team wallet, but directed by veFXS governance; execution keys are typically in multisigs with hardware-wallet signers; and some product-specific systems rely on chain-specific multisigs and offchain bots.

Evidence (5)

smart-contract

unverified

Assessment — Frax (as of September 5, 2026) Scope limitation: Dune MCP was unavailable. Therefore, proxy-admin event history, current owner/admin storage, timelock delay, role renunciation, pause/withdrawal/fee/oracle permissions, and cross-chain deployment verification are Not verifiable as of September 5, 2026. No on-chain claims are made. Documented architecture and addresses

  • Frax is modular and uses multiple control planes: stablecoins, frxETH/sfrxETH, Fraxlend, FXBs, AMOs, bridges/OFTs, and Fraxtal infrastructure.
  • Frax development standards explicitly recommend FraxUpgradeableProxy or FraxTransparentProxy; the cross-chain registry documents upgradeable OFTs and a shared ProxyAdmin at 0x223a681fc5c5522c85C96157c0efA18cd6c5405c for several EVM chains, including Arbitrum, Avalanche, BSC, Fraxtal, OP Mainnet, and Polygon.
  • Fraxtal system contracts list ProxyAdmin 0x13Fe62cB24aEa5afd179F20D362c056c3881ABcA. FraxNet separately lists a factory proxy-admin 0x3077C833346501079AFe93f7BB7aE88a6fBbC1f5 and beacon 0x694c245bcd2D41a808935B2f36706DDdECF1BF81.
  • FraxNet’s beacon is an additional central upgrade point: its owner can change the implementation affecting all linked beacon proxies. This is a documented admin capability, not an on-chain verification of the current owner.
  • Documented role examples include Fraxlend Comptroller 0x168200cF227D4543302686124ac28aE0eaf2cA0B, Circuit Breaker 0xfd3065C629ee890Fd74F43b802c2fea4B7279B8c, Operator 0xa4EC124e09D6D1A092c6BD16aFac9CD83f73E3c3, and frxETH Comptroller 0x8306300ffd616049FD7e4b0354a64Da835c1A81C. Risk conclusion: Upgradeability and privileged multisig/operator control are material risks. A compromised upgrade admin, beacon owner, AMO/operator, oracle/configuration role, or bridge administrator could potentially alter logic, freeze operations, redirect protocol-controlled assets, manipulate minting/redemption parameters, or impair exits. Whether users can exit without administration is component-specific and Not verifiable as of September 5, 2026. Timelock delay and emergency constraints are likewise Not verifiable as of September 5, 2026. Architecture: Users → proxy/token/vault → implementation or beacon → oracle/strategy/AMO → multisig/timelock/ProxyAdmin Users ↔ bridges/OFTs ↔ chain-specific admins Audit history exists for Fraxlend, frxETH, Fraxtal, FXB, and related components, but current-deployment coverage and unresolved issue status are Not verifiable as of September 5, 2026.
Upgradeable
Yes
Evidence (5)

audit

one source

echidna audit report — echidna; file workshops/Automated Smart Contracts Audit - TruffleCon 2019/echidna/echidna.pdf in trailofbits/publications (protocol audit catalog).

Auditor
echidna
Scope
echidna
File
echidna.pdf
Catalog only
Yes
Evidence (1)

audit

one source

echidna audit report — exercises; file workshops/Automated Smart Contracts Audit - TruffleCon 2018/echidna/exercises.pdf in trailofbits/publications (protocol audit catalog).

Auditor
echidna
Scope
exercises
File
exercises.pdf
Catalog only
Yes
Evidence (1)

audit

one source

manticore audit report — exercises; file workshops/Automated Smart Contracts Audit - TruffleCon 2018/manticore/exercises.pdf in trailofbits/publications (protocol audit catalog).

Auditor
manticore
Scope
exercises
File
exercises.pdf
Catalog only
Yes
Evidence (1)

audit

one source

manticore audit report — manticore; file workshops/Automated Smart Contracts Audit - TruffleCon 2019/manticore/manticore.pdf in trailofbits/publications (protocol audit catalog).

Auditor
manticore
Scope
manticore
File
manticore.pdf
Catalog only
Yes
Evidence (1)

audit

one source

slither audit report — slither; file workshops/Automated Smart Contracts Audit - TruffleCon 2019/slither/slither.pdf in trailofbits/publications (protocol audit catalog).

Auditor
slither
Scope
slither
File
slither.pdf
Catalog only
Yes
Evidence (1)

audit

two sources

Initial Frax stablecoin protocol (core FRAX/FXS system).

Auditor
CertiK
Report date
2020-11-06
Scope
Core Frax stablecoin protocol contracts prior to launch (two‑token design). Static analysis + manual review, Oct 11–30 2020.[8]
Findings
39 issues total: 3 critical, 8 major, 11 minor, 17 informational.[8][4] Some criticals (incl. reentrancy and owner array manipulation) were fixed promptly; DeFiSafety notes 3 major findings remained uncorrected at the time of its review.[13]
Fix status
Mixed: CertiK reports critical issues addressed; some majors reportedly not corrected per DeFiSafety.[7][13]
Evidence (3)

audit

one source

Initial Frax stablecoin protocol (core contracts on Ethereum; indirectly relevant to other chains where the same core logic is deployed). Audit report November 2020.

Auditor
CertiK
Report date
2020-11-13
Scope
FRAX two‑token stablecoin protocol smart contracts (core monetary system). Covers system solvency logic, attack vectors, best‑practice compliance, contract logic vs. spec.[1][9][13]
Evidence (1)

audit

one source

Security audit of Frax BAMM (Borrow‑AMM) smart contracts.

Auditor
ChainSecurity
Report date
2021-09-01
Scope
Frax BAMM smart contracts on Ethereum (used in Frax lending/liquidity architecture).[4]
Findings
Only minor denial‑of‑service patterns identified (against liquidations and redeeming/executing actions); no critical or high‑severity solvency or arithmetic issues found.[4]
Fix status
ChainSecurity summary indicates a high level of security; minor DoS patterns documented for mitigation. Actual mitigation status and deployed bytecode match Not verifiable as of 2026-09-04.[4]
Evidence (1)

audit

one source

BAMM smart contracts (liquidity and risk‑management module).

Auditor
ChainSecurity
Report date
2025-09-12
Scope
BAMM solvency, arithmetic correctness, oracle‑manipulation resistance, rounding, DoS patterns.[3]
Evidence (1)

audit

one source

Scope: frxETH liquid staking; deployed code: Not verifiable as of September 4, 2026.

Auditor
Code4rena
Report date
2022-11-29
Scope
frxETH contracts
Findings
2 high, 10 medium; additional low/informational findings reported.
Fix status
Remediation status not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

New report. Bytecode match to deployed Curve AMO contracts: Not verifiable as of September 5, 2026.

Auditor
Frax Security Cartel
Report date
2024-10-30
Scope
Curve AMO for frxETH V2
Findings
0 critical, 2 high, 5 medium, 13 low, 8 informational, plus 3 gas-optimization findings.
Fix status
Report states all issues were addressed or accepted; production deployment status is Not verifiable as of September 5, 2026.
Report url
https://resources.cryptocompare.com/asset-management/318/1755598141920.pdf
Report id
doc:0147d656cb5cd03b
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report. Bytecode match to deployed Fraxtal North Star contracts: Not verifiable as of September 5, 2026.

Auditor
Frax Security Cartel
Report date
2025-03-27
Scope
Fraxtal North Star hard fork contracts, bridges, native-token migration and token wrappers
Findings
2 critical, 0 high, 0 medium, 3 low, 4 informational, plus 1 gas optimization finding.
Fix status
Report states all issues were addressed or accepted; deployed-code confirmation is Not verifiable as of September 5, 2026.
Report url
https://resources.cryptocompare.com/asset-management/318/1755602082444.pdf
Report id
doc:05fbee71199d8d7b
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New report: Fraxchain (Fraxtal) security review. Bytecode match to deployed Fraxtal contracts: Not verifiable as of September 5, 2026.

Auditor
Trail of Bits
Report date
2024-01
Scope
Fraxchain (Fraxtal)
Findings
Not verifiable as of September 5, 2026.
Fix status
Not verifiable as of September 5, 2026.
Report url
https://github.com/FraxFinance/frax-solidity/blob/master/src/audits/Fraxchain%20%28Fraxtal%29%20-%20Trail%20of%20Bits%20-%20Jan%202024.pdf
Report id
doc:3c79c4dabcb1a9de
Evidence (2)

audit

one source

New report. Bytecode match to deployed Fraxtal, VestedFXS and Flox contracts: Not verifiable as of September 5, 2026.

Auditor
Frax Security Cartel
Report date
2024-04
Scope
Fraxtal, VestedFXS and Flox
Findings
Not verifiable as of September 5, 2026.
Fix status
Not verifiable as of September 5, 2026.
Report url
https://resources.cryptocompare.com/asset-management/318/1755597993996.pdf
Report id
doc:ca3082570213443f
Evidence (1)

audit

one source

New report. A separate Frax audit catalogue labels BAMM as Certora in October 2024, while this independently published ChainSecurity report is dated June 19, 2024; treat these as separate reports unless proven otherwise. Bytecode match: Not verifiable as of September 5, 2026.

Auditor
ChainSecurity
Report date
2024-06-19
Scope
BAMM smart contracts and Fraxswap router interaction
Findings
0 critical, 0 high, 2 medium, 8 low; 2 medium findings corrected, 6 low corrected and 2 low risk-accepted.
Fix status
Most issues addressed during the engagement; two low findings were risk-accepted. Deployed-code confirmation is Not verifiable as of September 5, 2026.
Report url
https://reports.chainsecurity.com/FraxFinance/ChainSecurity_FraxFinance_BAMM_Audit.pdf
Report id
doc:d3180f3b42dd97a5
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

New report. Bytecode match to deployed contracts: Not verifiable as of September 5, 2026.

Auditor
Frax Security Cartel
Report date
2024-10-24
Scope
FPISLocker and FraxtalERC4626MintRedeemer
Findings
0 critical, 5 high, 5 medium, 2 low, 3 informational; 15 findings total.
Fix status
Report states all issues were addressed or accepted; production deployment status is Not verifiable as of September 5, 2026.
Report url
https://resources.cryptocompare.com/asset-management/340/1755601919767.pdf
Report id
doc:d7bd9d7a1c97f787
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Community audit of Frax Ether (frxETH) token smart contract used in Frax protocol, primarily on Ethereum.

Auditor
EtherAuthority
Report date
2024-01-27
Scope
Frax Ether (frxETH) token smart contract. Chains explicitly covered in report: Ethereum; use on Arbitrum, OP Mainnet and other L2s not independently verified as of 2026-09-04.[8]
Findings
Reported security level “Secured”; detailed report notes no critical/high/medium findings, with remaining issues in low‑severity categories (DoS and rounding patterns) for BAMM‑style logic; for this specific frxETH audit, only minor findings were noted.[8]
Fix status
Report concludes contracts are secured and no unresolved critical/high/medium issues remain; exact deployed bytecode match Not verifiable as of 2026-09-04.[8]
Evidence (1)

audit

one source

Community audit of Frax Token (FRAX) smart contracts.

Auditor
EtherAuthority
Report date
2024-04-29
Scope
Frax Token smart contracts (FRAX stablecoin implementation). Chain coverage likely Ethereum; deployments on Arbitrum, Avalanche, BSC, Fantom, Fraxtal, OP Mainnet, Polygon Not verifiable as of 2026-09-04.[12]
Findings
0 critical, 0 high, 0 medium, 1 low, 3 very‑low issues.[12] Low/very‑low findings relate to minor gas inefficiencies and non‑critical patterns; no exploitable high‑risk vulnerabilities reported.[12]
Fix status
Report states contracts are secure with only low/very‑low issues outstanding; confirmation of fixes and bytecode match Not verifiable as of 2026-09-04.[12]
Evidence (1)

audit

unverified

Internal/affiliated security collective auditing multiple Frax components (e.g., frxETH V2, Fraxtal and related contracts).

Auditor
Frax Security Cartel
Report date
2024-03-01
Scope
frxETH V2 contracts; Frax docs list additional Cartel reviews for Fraxtal, VestedFXS, Flox, FPISLocker, Curve AMO for frxETH V2 and others.[1][10]
Findings
For frxETH V2 specifically, the PDF report is available but detailed counts of critical/high/medium issues and their current remediation status are Not verifiable as of 2026-09-03 due to tooling limits this turn.[10]
Fix status
Not verifiable as of 2026-09-03 for individual findings; these are not fully independent third‑party audits.
Evidence (2)

audit

one source

Frax maintains a long audit program over many components (Fraxlend, Fraxferry, veFPIS, FrxGov, FXB, sFRAX, frxETH redemption queue and oracles, Fraxchain/Fraxtal, frxETH V2, VestedFXS, Flox, FraxtalERC4626MintRedeemer, Curve AMO for frxETH V2, BAMM, Fraxtal North Star, frxUSD stack, Frax0 Mesh, etc.).

Auditor
Multiple (Trail of Bits, CertiK, Frax Security Cartel, Zellic, ChainSecurity, Certora)
Report date
2020-11-01
Scope
Programmatic, recurring audits across core protocol, L2 (Fraxtal), governance, bridge, RWAs and newer stablecoin primitives. Specific individual reports from 2022–2025 listed in Frax / Fraxtal docs with auditors and modules.[2]
Evidence (3)

audit

one source

Scope: Frax protocol; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2021-06
Scope
Frax Finance codebase
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Scope: Frax protocol quarterly review; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2021-12
Scope
Frax Finance codebase
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Security review of Frax Finance components (Fraxswap, FPI, FraxLend‑related code) in 2022.

Auditor
Trail of Bits
Report date
2022-05-01
Scope
Frax Finance smart contracts including Fraxswap long‑term swap logic, FPIControllerPool, FraxLendPairDeployer and related contracts.[9]
Findings
6 issues: 4 high, 1 medium, 1 low.[9] Examples: risk of unexpected results when canceling long‑term swaps with rebasing tokens (high), missing liquidity checks on initiating long‑term swaps (high), unsafe integer conversions in FPIControllerPool (high), exchangeRate not updated in certain leveragedPosition/repay flows (high), risk of hash collisions in FraxLendPairDeployer blocking some deployments (medium).[9]
Fix status
Trail of Bits public summary does not state final disposition per issue; fix status for individual findings is Not verifiable as of 2026-09-03.
Evidence (2)

audit

one source

Scope: Fraxswap and FPI; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2022-08
Scope
Fraxswap and Frax Price Index
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Scope: Fraxlend and Fraxferry; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2022-11
Scope
Fraxlend and Fraxferry
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Scope: FrxGov; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2023-07
Scope
FrxGov
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Scope: FXB, sFRAX, redemption queue and oracles; deployed code: Not verifiable as of September 4, 2026.

Auditor
Trail of Bits
Report date
2023-10
Scope
FXB, sFRAX, frxETH Redemption Queue, Frax Oracles
Findings
Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

New report. Bytecode match to deployed FraxNet contracts: Not verifiable as of September 5, 2026.

Auditor
Zellic
Report date
2025-07-07
Scope
frxUSD, frxUSDCustodian, FraxNetDeposit and RWARedemptionCoordinator
Findings
0 critical, 0 high, 1 medium, 5 low and 2 informational.
Fix status
Reportedly remediated except one acknowledged low-severity item; deployed-code confirmation is Not verifiable as of September 5, 2026.
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Later‑stage audits of frxUSD, FRAX, FXB, sfrxUSD and Frax0 Mesh and related components mentioned in Frax docs.

Auditor
Zellic & ChainSecurity
Report date
2025-07-01
Scope
frxUSD and related RWA/custodian infrastructure; FRAX/FXB/sfrxUSD updates; Frax0 Mesh networking layer. Chain‑specific coverage (Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, Polygon) Not verifiable as of 2026-09-04.
Findings
Zellic July 2025: frxUSD, frxUSDCustodian, FraxNetDeposit, RWARedemptionCoordinator; findings not summarized publicly in search snippets.[1] ChainSecurity July 2025: FRAX, FXB, sfrxUSD update; findings likewise not detailed in the index.[1] Zellic September 2025: Frax0 Mesh audit, no public issue breakdown in surfaced snippet.[1]
Fix status
Frax docs indicate these audits were completed; specific issue counts, severities, and fix status Not verifiable as of 2026-09-04.[1] Bytecode coverage versus deployed contracts across chains Not verifiable as of 2026-09-04.
Evidence (2)

Team & Reputation

founders

two sources

Frax is a publicly founded, Cayman‑registered DeFi business with a mostly non‑anonymous team drawn from prior web‑startup and crypto projects, but on‑chain verification of governance control and entities is Not verifiable as of 2026‑09‑04. ### Founders & key team

  • Sam Kazemian – Iranian‑American software programmer, founder/CEO of Frax Finance and earlier co‑founder of Everipedia (now IQ.wiki), a for‑profit online encyclopedia. Multiple profiles (Wikipedia, docs, media) consistently cite him as the primary founder of Frax.
  • Travis Moore – Italian‑American programmer and entrepreneur; co‑founder and CTO of Frax Finance and co‑founder/CTO of Everipedia/IQ.wiki. Public bio includes UCLA science degrees and prior roles in analytics; he leads core protocol development (Frax v2, veFXS, FPI).
  • Jason Huan – Commonly listed as co‑founder; technical background and UCLA blockchain club founder. Other early contributors and advisors mentioned across sources include Stephen Moore (economist, ex‑Trump advisor), Kedar Iyer (early CTO in “Decentral Bank” phase), Michael Gruen, and governance participants like Justin Moore and Drake Evans. These are all named individuals; no evidence of a fully anonymous founding set. ### Prior projects, track record, and incidents
  • Kazemian, Moore, Huan, Forselius, Moghadam previously built Everipedia/IQ.wiki, a long‑running crypto‑linked knowledge platform.
  • Public sources do not report major protocol hacks or catastrophic failures specifically attributed to Frax’s core team; however, this cannot be on‑chain verified here and should be treated as "no incidents found" rather than proof of absence. Not verifiable as of 2026‑09‑04. ### Public vs. anonymous, credibility
  • Founders are fully doxxed, with long‑standing public profiles, interviews, and press references (including mainstream outlets like Fortune).
  • Multiple independent profiles (TokenInsight, RootData, Fortune, PitchBook, media articles) align on the founder set and roles, which supports basic identity and credibility. ### Corporate reality: office, jurisdiction, business vs. web front
  • PitchBook lists Frax Finance headquartered in Grand Cayman, Cayman Islands, with a specific office address at Willow House, 171 Elgin Avenue, Cricket Square, Floor 2, PO Box 709, KY1‑1103. This indicates an offshore corporate structure typical of crypto firms.
  • No independent evidence of onshore offices in the US or EU could be verified in this pass. Not verifiable as of 2026‑09‑04.
  • Given named executives, corporate registration in Cayman, inclusion in investor/databank platforms, and long‑running products (Frax, FRAX stablecoin, Fraxtal L2), Frax is credibly a real operating business, not merely a web front, though ultimate asset‑control structures remain Not verifiable as of 2026‑09‑04. ### Reality‑check / contradictions
  • Founder lists vary slightly by source (e.g., some include Stephen Moore or Michael Gruen as co‑founders; others restrict to Kazemian, Moore, Huan). This is a minor but persistent contradiction around who is formally a “co‑founder,” not around the existence or identity of the main leadership.
Evidence (15)

general reputation

two sources

Frax Finance currently has a mixed but generally solid technical reputation, with notable smart‑contract security efforts but persistent concerns around its historical stablecoin design, disclosure practices, and systemic risk profile. No fraud, rug, insolvency, sanctions, or formal regulatory enforcement actions are documented as of 2026‑09‑04. Founders & investors

  • Sam Kazemian (Iranian‑American engineer) is widely recognized as Frax’s founder and a visible public figure in DeFi media and governance. He is portrayed as technically competent and vocal on regulatory policy, arguing for “smart and competitive” regulation rather than applying 1930s securities law frameworks directly to DeFi.
  • Early association with former Fed nominee Stephen Moore is noted in media but has not led to known regulatory action.
  • No credible sources allege personal fraud, criminal activity, or sanctions against Kazemian or core team as of 2026‑09‑04. Not verifiable as of 2026‑09‑04 for detailed cap table / investor list. Security, audits, and bug bounties
  • Frax emphasizes security culture and recurring audits, stating work with firms like Trail of Bits and Certik, plus ongoing reviews of core contracts, governance, bridges, and upgrades.
  • The protocol runs a large bug bounty: up to 10% of exploit value or $10m equivalent in FRAX+FXS, “no questions asked,” covering all smart contracts deployed by Frax, referenced in docs, governance, and external protocol integrations.
  • Third‑party trackers show historical audits with multiple critical and major findings reportedly resolved, indicating non‑trivial past issues but remediation activity. Criticisms & unresolved concerns
  • Risk analysts highlight that the original fractional‑algorithmic FRAX design shares structural vulnerability with UST‑style death spirals if the fractional mode were re‑enabled and the collateral token crashed.
  • Frax’s reserves depend heavily on external protocols like Curve and Aave, creating correlated risk: a hack or severe failure there could impair FRAX backing even if Frax’s own contracts stay intact.
  • A stealth‑patched critical DoS bug in the frxETH redemption/withdrawal system is documented by independent analysis, raising trust and disclosure concerns about transparency around severe vulnerabilities.
  • The ecosystem’s breadth (FRAX, frxUSD, frxETH, Fraxlend, Fraxswap, Fraxtal L2, RWA integrations) increases compound smart‑contract and operational risk. Regulatory & sentiment
  • Independent risk ratings characterize Frax as moderate‑to‑higher risk (grades around C+/B‑), citing algorithmic heritage, reserve dependencies, and disclosure issues, while acknowledging no recorded enforcement action or insolvency event.
  • Governance documents show ongoing budget for audits and bounty programs, signaling institutional intent to maintain security.
  • No evidence of OFAC/AML sanctions or specific regulatory cases targeting Frax was found; nonetheless, analysts view its design and RWA ambitions as having meaningful regulatory exposure relative to other mid‑sized DeFi protocols.
Evidence (15)

Economy

TVL: $37.6M

model

one source

Economic model (as of September 5, 2026). Frax is a multi-product system rather than one strategy: (1) fully collateralized frxUSD, minted/redeemed 1:1 against USDC, USDB and tokenized Treasury funds including BUIDL, USTB and WTGXX; (2) FraxLend isolated ERC-20 lending markets; (3) frxETH/sfrxETH liquid ETH staking; (4) FraxSwap, FraxNet/branded stablecoins and Fraxtal. Assets/yield. Assets in include stablecoins, Treasury/RWA tokens, ETH and lending collateral. Yield is primarily validator staking/MEV income, borrower interest, and Treasury/RWA income. sfrxETH receives 90% of Frax Ether staking income; 8% is protocol fee and 2% insurance. This is predominantly organic yield, but the exact organic/subsidized split is Not verifiable as of 2026-09-05. Risk character. frxUSD is principally collateral/issuer/custody and short-duration RWA exposure; sfrxETH is directional ETH and validator/slashing exposure; FraxLend borrowers may be directional, while lenders are credit/liquidation-exposed.

Leverage, looping, restaking and external protocol exposure at system level are Not verifiable as of 2026-09-05. No fixed lock-up is documented for frxUSD; frxETH redemptions use a queue but are fee-free and 1:1. Mint/redeem caps and configurable fees exist for custodians; exact live parameters are Not verifiable as of 2026-09-05. Revenue/collateral. Revenue sources include FraxLend interest, frxETH’s 8% protocol share, and mint/redeem or branded-token fees.

Collateral is product-specific, not a single pooled balance sheet. TVL/APY cross-check (DeFiLlama, aggregator; no Dune). Combined “Frax Finance” TVL: $294.77m—Ethereum $289.2m, Fraxtal $5.06m, Arbitrum $154.2k, BSC $147.2k, Avalanche $97.9k, Polygon $59.1k, OP $46.1k, Fantom $8.38; other chains are immaterial. The narrower Frax slug reports $41.41m, all Ethereum, down 3.1% over 30 days. DeFiLlama tracks 30 pools at average APY 0.9%.

APY history, volatility, sustainability and product-level TVL attribution are Not verifiable as of 2026-09-05. Contradiction: the $41.41m slug and $294.77m combined figure differ because DeFiLlama scopes products differently; neither is an on-chain-verified total. Dune comparison: Not verifiable as of 2026-09-05.

Evidence (5)

reserves

one source

Assessment as of September 5, 2026:

  • Reserve model: Frax’s current reserve perimeter is primarily frxUSD, not one consolidated treasury. Frax documentation describes 1:1 backing with cash-equivalent/tokenized-RWA assets including BUIDL, USTB, WTGXX, USDB and others, held through regulated custodians. This is an unverified marketing claim absent independent balance-sheet reconciliation.
  • Custody and control: Frax Inc. is delegated issuer-level compliance and collateral-management authority by the Frax DAO; it manages custodians, composition, redemption operations, audits and attestations. The DAO retains ultimate control and can revoke the delegation. BitGo custody is independently reported for an institutional frxUSD arrangement using WisdomTree WTGXX, with a planned deployment of up to $50 million; this does not establish total reserves.
  • On-chain reserve contracts: Ethereum custodian proxies publicly listed by Frax are: USDB 0xFE2Ea8dE262d956e852F12DE108fda57171a0a29; WTGXX 0x860Cc723935FC9A15fF8b1A94237a711DFeF7857; BUIDL 0xe827abf9f462ac4f147753d86bc5f91e186e4e9c; USDC 0x4F95C5bA0C7c69FB2f9340E190cCeE890B3bd87c; USTB 0x5fbAa3A3B489199338fbD85F7E3D444dc0504F33. frxUSD is deployed across the supplied chains, generally using the LayerZero address 0x80Eede496655FB9047dd39d9f418d5483ED600df, with distinct Ethereum and Fraxtal addresses.
  • Treasury address: Frax’s older address page lists a Treasury multisig at 0x9AA7Db8E488eE3ffCC9CdFD4f2EaECC8ABeDCB48; the page is stale and does not prove current balances, signers, or control.
  • Size, composition totals, custody concentration, attestations, reserve-policy enforcement, and on-chain balances via Dune: Not verifiable as of September 5, 2026. Dune MCP was unavailable; no query ID/execution ID can be provided. Frax states that transparency reports and attestations exist, but the accessible evidence did not provide a machine-verifiable current total. Contradiction / key risk: Frax claims full backing and regular reporting, but current reserve amounts and liabilities could not be independently reconciled to token supply or custodian balances. The gap is the finding.
Evidence (5)

tokenomics

two sources

Frax has multiple core tokens: FRAX (stablecoin), Frax Share (FXS) (governance/value-accrual), and Frax Ether (frxETH/sfrxETH) on Ethereum and Fraxtal. Multi-chain deployments focus mainly on FRAX liquidity; FXS is ERC‑20 on Ethereum and bridged elsewhere. ### Core tokens & contracts (Ethereum)

  • FRAX (stablecoin): ERC‑20 at 0x853d…1fB (Ethereum).
  • FXS (governance): ERC‑20 at 0x3432…82f (Ethereum).
  • frxETH / sfrxETH: liquid/staked ETH wrappers; main contracts on Ethereum, used for staking yield. Other chains (Arbitrum, Avalanche, BSC, Fantom, OP, Polygon, Fraxtal) host bridged FRAX and FXS in major DEXs (Curve, Uniswap, Sushi, Balancer, Trader Joe, etc.), but canonical contracts are on Ethereum. Specific contract addresses per chain are listed in Frax docs and DeFiLlama but are not independently on-chain verifiable here → *Not verifiable as of 2026‑09‑04*. ### Supply, market cap, FDV
  • FRAX: elastic supply; partially/fully collateralized stablecoin, minted/redeemed against collateral and FXS.
  • FXS: fixed max supply ~99.7M; circulating ~80–90M range depending on source; market cap and FDV vary with price. Precise current circulating/total, market cap, and FDV across chains are aggregator figures (DeFiLlama, CoinGecko, CoinMarketCap) → *Not verifiable as of 2026‑09‑04*. ### Utility & governance
  • FXS:
  • Protocol governance (parameters, new products, collateral types) via snapshot/on-chain voting.
  • Value accrual: exposure to fees and yield from FRAX ecosystem (stablecoin, lending, frxETH/sfrxETH, Fraxtal).
  • frxETH/sfrxETH: ETH staking derivative; sfrxETH receives staking yield. ### Revenue share, burns, staking
  • Historically, Frax used FXS buybacks/burns funded by protocol revenue and FRAX expansion/redemption mechanics.
  • sfrxETH distributes ETH staking yield pro‑rata to stakers; FXS holders get indirect exposure via governance over parameters and revenue use. Detailed revenue splits, current buyback cadence, and exact burn amounts by date are aggregator/Docs‑based → *Not verifiable as of 2026‑09‑04*. ### Emissions, unlocks, allocations
  • FXS had an initial allocation among team, investors, community/LP incentives, and protocol reserves described in launch docs and token distribution posts.
  • Schedule of emissions and historical unlocks (team/investor cliffs, vesting) is not fully traceable here to explorer-level events → *Not verifiable as of 2026‑09‑04*. ### Control functions & concentration
  • Frax contracts include mint/burn logic for FRAX, governed by protocol controllers and governance; no evidence of arbitrary user-level blacklist in core FRAX docs.
  • Ownership is progressively moved to Timelock + DAO governance for major contracts, reducing direct admin risk over time.
  • Top-holder concentration, insider wallets, and exact treasury balances across chains are on-chain questions → *Not verifiable as of 2026‑09‑04*. ### DEX liquidity & listings
  • FRAX & FXS have deep liquidity on Ethereum (Curve FRAX pools, Uniswap, Balancer) and major pools on Arbitrum, OP, Polygon, Avalanche, BSC, Fantom.
  • Precise depth by chain/pool and share of TVL per chain rely on DeFiLlama/Curve/Uniswap analytics → *Not verifiable as of 2026‑09‑04*.
Evidence (7)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 is not a direct protocol trigger for Frax; the main documented stress mechanism is FRAX trading below $1, which causes the protocol to raise collateralization and support the peg. On the information available here, the BTC scenario is therefore an indirect market stress test: if a BTC crash broadens crypto risk-off conditions, the plausible Frax impact is higher redemption pressure, lower confidence in FRAX, and greater demand for collateralization—especially for designs that still rely on FXS/market confidence. For current Frax architecture, the relevant documented response is that if FRAX falls below its peg, the protocol increases collateral ratio to restore stability, and v3 governance/AMOs are intended to push CR back toward 100% and maintain the peg even when other assets move sharply.

Independent risk analysis also notes that heavy redemption can create selling pressure on FXS, and a rapid FXS decline can worsen under-collateralization risk in a bank-run-like scenario. Because on-chain chain-by-chain exposure and current collateral composition are not verifiable as of 2026-09-04 from the provided sources alone, I cannot quantify Frax’s losses or buffer capacity under a BTC < $10k shock. The defensible stress conclusion is: BTC crash risk is likely to matter only insofar as it transmits into FRAX depeg pressure, FXS selloff, and collateral quality/liquidity deterioration; otherwise, BTC itself is not the protocol’s stated state variable.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

For Frax, a 20% depeg in the largest collateral asset is not verifiable as of 2026-09-04 from the available web sources alone, because the current chain-by-chain collateral composition and balances are not independently reproducible here. What can be stated is that Frax’s newer design aims for full exogenous collateralization of FRAX, with the protocol attempting to keep >=100% CR and restore it via AMOs and governance if it falls. The main stress implication is straightforward: if the largest collateral bucket is marked down by 20%, the protocol’s effective collateral ratio would fall by that asset’s share of reserves multiplied by 20%; if the asset is a large share of the backing, this can materially weaken the peg buffer.

Older analyses of Frax’s fractional model also note that in a bank-run style event, selling pressure on FXS could amplify the problem by worsening recapitalization conditions. Two important caveats:

  • Frax’s risk profile differs by product generation. V3 documentation describes a move toward 100% collateralization, so legacy fractional-stablecoin analysis is only partially applicable.
  • Several third-party writeups cite historical collateral ratios or buffers, but those figures are dated and inconsistent across sources, so they should not be treated as current exposure data. If you want a precise loss estimate, the missing inputs are the current largest collateral asset, its share of total backing, and whether the asset is held on any of the listed chains (Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, Polygon). Without on-chain verification, the exact post-shock CR and redemption capacity remain Not verifiable as of 2026-09-04.
Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Frax, “top counterparty insolvent” mainly means: major stablecoin/debt backing assets default (e.g., US treasuries via OUSG/FXB), stablecoin/collateral failure (USDC, DAI, bridged assets), or a catastrophic issue in Frax’s own lending/AMO venues. On‑chain verification is not possible in this run: Not verifiable as of 2026‑09‑04. Below is the conceptual stress path by risk bucket and who ultimately eats the loss; it applies across Ethereum, Arbitrum, Fraxtal and other listed chains with differences only in scale, not mechanism. ### 1.

Reserve / backing asset counterparty failure Scenario: OUSG/FXB/other off‑chain custodian or issuer becomes insolvent; backing becomes impaired while FRAX, sFRAX and frxETH liabilities remain.

  • Loss path: Reserve asset value falls below book; AMO portfolios become under‑collateralized; peg defense via redemptions drains good assets and strands bad ones.
  • Who absorbs:
  • FRAX/sFRAX/frxETH holders via de‑peg or haircut on redemptions (economic, not explicit).
  • FRAX/FXB/OUSG LPs in AMO pools (Curve, FraxBP, internal AMOs) through pool imbalance and bad‑asset dominance.
  • Compensation: No built‑in insurance; any compensation would be governance‑discretionary (Frax governance).
  • Smart‑contract impact path: AMO controllers keep honoring swaps at pool prices; if oracle still reports par, contracts do not auto‑pause, so losses are socialized through on‑chain pricing and redemptions. ### 2. Stablecoin / collateral counterparty failure (USDC, bridged USDC, DAI, etc.) Scenario: Major collateral stablecoin on a given chain de‑pegs or becomes insolvent.
  • Loss path:
  • FraxBP/Curve/Uniswap pools with FRAX/USDC or FRAX/DAI skew to worthless asset; LPs lose first.
  • FRAX backing ratio falls; mint‑redeem arbitrage transmits losses to FRAX holders.
  • Who absorbs: Liquidity providers in affected pools, then FRAX holders on that chain.
  • Compensation: None programmatic; possible governance actions (emergency shutdown, migration) only.
  • Contract path: AMM pools automatically rebalance; oracles may lag. Liquidations in lending integrations (Aave, Fuse, Fraxlend) fire at distorted prices, pushing further losses to borrowers/lenders. ### 3. Lending / Fraxlend counterparty failure Scenario: Largest Fraxlend market borrower defaults or collateral oracle fails.
  • Loss path: Under‑collateralized market; lenders in that market take principal loss.
  • Who absorbs: Fraxlend lenders and any AMO capital deployed as lender of last resort.
  • Compensation: No native insurance; loss is contained to affected market; governance may recapitalize selectively.
  • Contract path: Liquidation and accounting follow protocol rules; if oracle is compromised, bad debt is crystallized before governance can intervene. ### Chain‑level notes
  • Arbitrum/OP/Polygon/Fantom/BSC/Avalanche/Fraxtal mainly host FRAX liquidity pools and lending markets; local LPs and FRAX users on the chain absorb first.
  • Cross‑chain bridges add another counterparty: bridge insolvency or exploit strands canonical FRAX on that chain; stranded holders take the loss; Ethereum mainnet backing is unaffected unless governance chooses to socialize it.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For Frax, a “committed fraud by the DAO or owners” stress case is not verifiable from the available sources. The strongest directly relevant evidence is that Frax documentation says the DAO “retains ownership and ultimate control of the protocol and may amend or revoke delegated authority at any time,” which confirms centralized governance control, but does not itself establish fraud. A security review also notes multiple centralized dependencies, limited visibility into off-chain assets held by FinResPBC, and lapses in funds-management oversight, which are risk indicators rather than proof of fraud.

What can be said with higher confidence is that Frax has had material governance/control risk and admin-key risk in its design. Independent audit findings for Frax-related systems note that admin powers can enable a rug pull if not timelocked, and recommend putting admin functions behind a timelocked DAO or multisig. Another audit similarly warns that certain functions can only be executed by an admin/owner and that compromise of the admin wallet would create serious trouble.

There is also evidence of a past DNS hack in November 2023, but a third-party review states protocol funds were not at risk and the issue was quickly resolved, which does not support a fraud finding. So, for a stress scenario, the appropriate treatment is: governance abuse / insider-control risk is plausible; committed fraud is not established. If you need a binary classification for risk modeling, use “Not verifiable as of 2026-09-04” for actual fraud, and model the downside as high governance-centralization risk across the supported chains.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

Frax has at least one negative 30-day yield signal in the provided sources: a PrismaRisk collateral note reports sfrxETH’s current 30-day APY at 5.08%, while competitor yields are lower in that excerpt, so it is still positive there. More relevant to a stress case, LlamaRisk states that sFRAX’s yield sources are partly managed offchain and that current yield primarily comes from on-chain AMO activities rather than RWAs, with limited public information on off-chain sources. That means a negative 30d primary yield source shock would most directly stress sFRAX’s ability to keep distributing yield near its target, because the protocol’s yield depends on weekly earnings rather than a fixed promise.

For Frax across the specified chains, the available sources here do not provide chain-by-chain TVL or yield-source decomposition, so not verifiable as of 2026-09-04. The only directly supported stress conclusion is that Frax’s primary yield mechanisms are not purely deterministic and depend on either validator rewards for frxETH/sfrxETH or AMO/RWA earnings for sFRAX; if those underlying earnings turn negative over 30 days, the protocol would likely need to reduce distributions rather than subsidize them, based on how the yield is described. The most important caveat is that the sources do not verify an actual negative 30-day realized yield for Frax on the listed chains; they only show that the system’s yield is economically exposed to adverse earnings conditions.

Evidence (5)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026. Frax uses a hybrid governance design, not a fully autonomous DAO. The documented architecture is dual-track: Alpha is controlled by veFXS/veFRAX holders and its TimelockController is installed as a module on configured Safe wallets, giving it broad powers over Safe owners, governance parameters, protocol parameters, and protocol-owned liquidity.

Omega is an optimistic operational path: Frax team/Safe owners initiate Safe transactions after collecting the Safe threshold signatures; token holders can veto them during the voting window. Omega also has a documented 51% short-circuit threshold for urgent execution. Proposal process: forum discussion precedes voting for ordinary proposals; the current governance forum records active 2026 proposals, while DeFiLlama shows recent proposals passing with effectively unanimous recorded votes.

This demonstrates functioning governance, but does not establish broad or independent participation. Control/risk: DAO control is real at the Alpha layer, but operational execution remains dependent on Safe owners and the Frax-controlled frontend/process. The DAO is therefore substantive but hybrid, with meaningful team discretion and emergency powers.

Exact current Safe signer identities, thresholds across all supported chains, and whether every treasury Safe is correctly configured are Not verifiable as of September 13, 2026. The exact veFXS/veFRAX voting concentration and top holders via Dune are Not verifiable as of September 13, 2026 because Dune MCP is unavailable. Timelock: documented Alpha delay is one day; Omega uses a two-day voting window, but current live delay values are not independently on-chain verified.

Some Frax administrative contracts and Safes may retain direct admin authority; accordingly, a universal “no-drain” conclusion is not supportable. The Frax Terms select Cayman Islands law, but do not identify a legal entity, registration number, or directors. Not verifiable as of September 13, 2026. Fields: timelock=true; timelock_delay_hours=24 (documented, not on-chain verified); multisig_threshold=null; multisig_owners=null; admin_can_drain=true (administrative/Safe authority exists somewhere in the system; exact scope is not fully verified); emergency_bypass=true; dao_governance=true (Alpha token-holder governance controls documented parameters/upgrades, subject to configuration and execution dependencies).

Timelock
Yes
Timelock delay hours
24
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
Yes
Evidence (5)

legal & regulatory

two sources

Frax is a DeFi protocol best known for the FRAX stablecoin and associated lending/yield products (Frax Finance / Frax Protocol). Not verifiable as of 2026-09-04 via on-chain tools. Legal entity & jurisdiction

  • The core team operates under Frax Finance, Inc., incorporated in Delaware, USA.
  • Founder and public face: Sam Kazemian, described in media and project materials as an American-based founder. Regulatory status / classification
  • Frax issues and manages crypto assets (e.g., FRAX stablecoin, FXS governance token, and other Frax assets) and runs lending/AMM-like products across multiple chains (Ethereum, Arbitrum, Avalanche, BSC, Fantom, Optimism, Polygon, plus its own Fraxtal L2).
  • No clear, formal classification by a specific regulator (e.g., SEC, CFTC, EU authorities) was found for FRAX or FXS. Not verifiable as of 2026-09-04 whether any token is officially deemed a security or other regulated instrument. ToS, KYC/AML, user restrictions
  • Frax’s core smart contracts are permissionless; users can mint/redeem and interact on-chain without KYC, consistent with typical DeFi design.
  • Any web front-end Terms of Service, geo-blocking, or OFAC-related restrictions for interfaces could not be reliably confirmed across all official domains. Not verifiable as of 2026-09-04. Regulatory actions, warnings, sanctions, court cases
  • No direct regulatory enforcement actions (e.g., SEC/CFTC complaints, state AG actions) specifically targeting Frax Finance or the Frax protocol were identified in major US and international regulatory news sources.
  • No public regulatory warnings or consumer alerts specifically naming Frax were found from major regulators (e.g., SEC, FCA, ESMA, MAS). Not verifiable as of 2026-09-04.
  • No court cases targeting Frax Finance or FRAX/FXS as defendants or primary subjects surfaced in mainstream legal or crypto litigation trackers.
  • Frax Finance and the Frax protocol themselves do not appear on major sanctions lists (e.g., OFAC, EU sanctions) as designated entities. Data protection / privacy
  • As a DeFi protocol, most activity is on public blockchains; any off-chain data practices (website analytics, account systems, KYC for specific institutional products, etc.) are not documented in independent sources and thus cannot be assessed. Not verifiable as of 2026-09-04. Risk takeaway (legal vs protocol use)
  • Users and institutions face typical DeFi regulatory uncertainty: future classification of stablecoins, governance tokens, and yield products may change in the US or other jurisdictions, potentially impacting FRAX/FXS or related products.
  • Operating or marketing Frax-based products from the US or EU may require case-specific legal analysis regarding securities, commodities, payment, and e-money rules.
Sanctioned
No
Entity
Frax Finance, Inc.
Jurisdiction
Delaware, USA
Evidence (6)

legal registries

two sources

No exact GLEIF LEI record for 'Frax Finance Inc', 'Frax'. OFAC SDN screening of 'Frax Finance Inc', 'Frax': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Frax Finance Inc
  • Frax
Sanctioned
No
Evidence (4)

Stability

stability

one source

Frax does issue its own stablecoins: current docs describe frxUSD as a fiat-redeemable, fully collateralized stablecoin issued by the Frax Protocol, and Frax’s docs also describe FRAX as a USD-pegged stablecoin. A depeg for the protocol’s stablecoin has occurred, but an on-chain-verified count, last depeg date, and maximum depeg percentage are not verifiable as of 2026-09-05 from the gathered sources; available web sources confirm the peg design and show one current depeg-tracker snapshot for FRAX, but they do not provide a reliable, source-independent historical series covering the requested chains.

Own stablecoin
Yes
Stablecoin ids
  • frxUSD
  • FRAX
Evidence (3)

Risks & Strengths

risks

one source

Frax’s principal risks are concentrated in governance authority, oracle/peg dependence, smart-contract complexity across many deployments, lending-liquidation mechanics, and third-party custody or real-world-asset exposure. Frax documents mitigations including dual-oracle design, governance controls, liquidation procedures, audits, and a large bug bounty; however, current chain-by-chain exposure, collateral composition, and TVL are Not verifiable as of September 5, 2026 because on-chain verification is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Governance and administrative controlveFXS governance and Safe owners can alter parameters, replace owners, move liquidity, or execute protocol-wide changes. Concentrated voting or compromised signers could cause rapid loss of funds or peg support.HighMediumDual Governor design, Safe thresholds, timelocks or voting processes where configured, and governance visibility.High-impact governance capture or signer compromise remains possible; decentralization and quorum effectiveness are not independently verified.
Oracle and stablecoin peg failureIncorrect, stale, or manipulable prices could misprice collateral, trigger improper liquidations, or impair frxUSD/FRAX stability.HighMediumDual price sources, Chainlink dependencies, stale-price checks, and protocol-owned liquidity are documented.Medium-to-high during market dislocation, oracle outage, thin liquidity, or correlated source failure.
Smart-contract and deployment complexityMultiple products and eight named chains increase code, upgrade, configuration, and integration surface; one defect can propagate across economically linked assets.HighMediumExternal audits, public repositories, and a bounty covering Frax-deployed contracts.High; audits are time-bounded and do not prove absence of exploitable bugs. Current deployment-by-deployment verification: Not verifiable as of September 5, 2026.
Lending liquidation and bad debtRapid collateral moves, oracle lag, congestion, or insufficient liquidator liquidity can leave positions underwater; Fraxlend documentation states residual debt can reduce lender claims.HighMediumMaximum-LTV limits, permissionless liquidations, liquidation fees, and dynamic debt restructuring.Medium-to-high for lenders during extreme volatility or stressed liquidity.
Custodian and RWA counterparty exposureFRAX V3’s collateral model can rely on partner-held treasury bills, reverse repos, bank balances, or other real-world assets; insolvency, freezing, legal, or redemption restrictions could impair backing.HighMediumGovernance-approved partners and a stated 100% collateralization objective.High because legal ownership, segregation, concentration, and redemption capacity are not fully independently verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Frax’s top strengths are its capital-efficient hybrid stablecoin design, dynamic collateralization, AMO-driven balance-sheet management, multi-chain / modular ecosystem, and governance / utility-token alignment. The strongest evidence across the provided sources is that Frax was built as the first fractional-algorithmic stablecoin, combining collateral backing with algorithmic controls to improve scalability and stability.

  • Capital efficiency: Frax’s fractional-algorithmic model is explicitly designed to reduce the over-collateralization burden seen in purely collateralized systems while still preserving a peg.
  • Adaptive risk management: The protocol can adjust its collateral ratio based on market conditions, which sources describe as a way to maintain stability during both expansion and contraction in demand.
  • AMOs and on-chain market operations: Multiple sources highlight Frax’s Algorithmic Market Operations as a core strength, using protocol-controlled actions to support peg stability, liquidity, and revenue generation.
  • Broad ecosystem / interoperability: Frax is described as operating across multiple chains and, more recently, as a modular ecosystem with a dedicated L2 execution layer (Fraxtal), which expands distribution and use cases.
  • Governance and utility alignment: The protocol’s dual-token structure (FRAX/FXS) and FXS governance are repeatedly cited as strengths because they align incentives and allow community-driven control over protocol evolution. A few claims in the sources are promotional or dated, so the most defensible summary is that Frax’s competitive edge comes from *stability engineering plus capital efficiency*, not from any single product feature.
Evidence (12)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 27 two independent sources, 38 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-29.