Fusion by IPOR

Orange · 52/100

Executive summary

Fusion by IPOR is a modular on-chain vault infrastructure protocol enabling institutional-grade yield strategies across Ethereum, Base, and Arbitrum, scoring 66/100 (orange band) with $61.9M TVL as of September 2026.

  • Security: Three audits by Protofire (Sept 2024), BlockSec (Feb 2025), and Ackee Blockchain (Dec 2023) cover current contracts, though detailed findings and bytecode verification are not available; active Immunefi bug bounty with $20K max payout; January 2026 Arbitrum exploit caused $336K loss via access-control vulnerability in legacy vault, fully reimbursed by DAO treasury.
  • Incidents: Single confirmed exploit (Jan 6, 2026) on older Arbitrum vault; $336K stolen and recovered; DAO covered shortfall; newer vaults reportedly have stricter validation, but remediation coverage by vault is unverified.
  • Governance & custody: Transitional governance; IPOR Labs AG (Swiss entity, Zug) controls frontend and development; legacy on-chain control via 4-of-6 multisig and 10-minute timelock; FUSN token not yet launched; each vault is isolated ERC-4626 with role-based access (Owner, Atomist, Alpha, Guardian); no shared pool risk.
  • Top risks: Legacy vault exploitability (demonstrated Jan 2026); privileged-role abuse (Atomists/Alphas control strategy execution, timelocks may be zero); external protocol dependency failures (Aave, Morpho, Compound, etc.) can impair NAV; oracle manipulation or stale feeds could enable loss; counterparty/venue insolvency absorbed by affected vault LPs, not socialized.
  • Strengths: Modular fuse architecture isolates risk per vault; transparent on-chain mechanics for allocations and fees; single integration to multiple yield venues; automated risk controls (deposit caps, pause, deleveraging); composable upgrades without fund migration.
  • Unverified: Exact vault-level allocations, leverage ratios, and dependency weights unavailable without on-chain tools; treasury size, reserve composition, and addresses not independently verified; FUSN token launch status contradictory (docs say not launched, one post claims launched); feed-by-feed oracle validation and deployment-specific admin controls unverified; formal regulatory classification (Swiss/EU/US) and KYC/AML enforcement not established.
  • Recommended exposure: Conservative allocation (≤2–5% of portfolio) until vault-specific controls, oracle feeds, and admin key holders are verified on-chain; prioritize newer vaults with post-Jan-2026 validation; confirm timelock >24h and multisig threshold ≥4-of-6; avoid vaults with zero timelock or single-admin control; monitor DAO treasury adequacy (stated <1% of secured funds post-exploit); suitable for allocators comfortable with modular vault risk and willing to perform per-vault due diligence.
  • Open questions: Verify current admin/owner addresses, timelock delays, and role holders for target vaults; confirm oracle feed sources and staleness checks; obtain vault-level allocation breakdown and leverage caps; validate bytecode match to audit scope; clarify FUSN launch status and tokenomics; assess DAO treasury reserves and compensation policy; confirm regulatory status and KYC obligations for institutional mandates; review post-exploit remediation across all vaults.

Score

Component Weight Raw Points Reason
Security 20% 80 16.0 2 audit(s); no fresh audit; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2025-02-28 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 no open incidents
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL $63,815,815 = 0% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 15/33 verified facts; 33/33 fresh (180d)

Identification

protocol identification

two sources

Protocol identification Fusion by IPOR (often Fusion or Fusion by IPOR) is an institutional-grade on-chain asset‑management / yield protocol built around modular vaults and adapter contracts (“Fuses”).

  • Website / App: app.ipor.io/fusion (linked from IPOR site and external analytics).
  • Docs: docs.ipor.io, sections *Fusion for Institutions* and *Build on Fusion*.
  • Category: Yield / yield aggregator / vault infrastructure.
  • Chains: Ethereum, Base, Arbitrum are confirmed; several aggregators list additional chains (Avalanche, Unichain, Ink, TAC, Plasma, Katana, Hyperliquid L1, Robinhood Chain), but these are not verifiable as of 2026‑09‑04 without on‑chain tools.
  • Launch timing: Fusion blog and GitHub suggest Fusion went live in 2024; exact mainnet launch date is not verifiable as of 2026‑09‑04.
  • Native token: IPOR ecosystem has an IPOR token audited previously, but Fusion vaults are positioned as infrastructure; whether Fusion has a *distinct* native token beyond IPOR is not verifiable as of 2026‑09‑04. Main contracts (high level, ≥2‑source cross‑check) Without on‑chain/Dune access, contract addresses cannot be safely reproduced; all addresses are Not verifiable as of 2026‑09‑04. Explorer verification status and exact addresses referenced in docs (e.g., “Fusion Vault”, “Base Fuses”, “Rewards Manager”, access control contracts, oracle middleware, prehooks, context and withdraw managers) are described in audits and documentation but cannot be cross‑checked on-chain in this run. Architecture / role
  • Fusion uses modular vaults that route assets via standardized adapter contracts called Fuses, enabling multi‑protocol strategies and atomic execution.
  • Off‑chain agents (“Alphas”) execute strategies configured by vault managers (“Atomists”), with on‑chain enforcement of risk limits and accounting. Fork lineage
  • Documentation and GitHub describe Fusion as a bespoke “prime brokerage” / meta‑aggregation layer, not a simple fork of a single upstream protocol.
  • No credible source identifies Fusion as a direct fork of a specific existing yield aggregator (e.g., Yearn, Enzyme); fork status is therefore Not verifiable as of 2026‑09‑04.
  • IPOR core protocol and IPOR token/mining contracts have multiple audits (Ackee, Zokyo); recent audits explicitly cover “Updated IPOR Fusion: Fusion Vault, Base Fuses, Rewards Manager, Access Management, Price Oracle Middleware, Prehooks, Context Manager, Withdraw Manager”, indicating that Fusion‑specific changes are audited.
  • No documented history of malicious modifications in third‑party forks of Fusion was found; this absence is Not verifiable as of 2026‑09‑04 and should not be assumed as proof of safety. Key risk‑analysis notes
  • Heavy reliance on off‑chain agents (Alphas) and complex multi‑chain deployment increases operational and governance risk versus simpler single‑venue yield protocols.
  • Independent ratings (e.g., DeFi Sentinel score 76/100, “low‑to‑moderate risk”) are analytics‑platform opinions, not on‑chain facts.
Evidence (15)

maturity

one source

Fusion by IPOR appears to be a real, working product portal rather than a pure landing page: the official site routes users to a live app at app.ipor.io and separately hosts product docs at docs.ipor.io. The docs are substantial, including build/developer guides, vault architecture, depositor guidance, and explicit references to ERC-4626 vault interfaces, which is consistent with a mature product surface rather than marketing-only content. The available web evidence supports active app functionality, but not every operational claim can be verified here.

The product pages indicate that users can “launch app,” browse available vaults, and access the Fusion frontend, while the terms page says the interface provides access to the decentralized protocol. Live deposits/withdrawals are not directly verifiable as of 2026-09-04 from the gathered web sources alone, so that operational detail is Not verifiable as of 2026-09-04. There are no obvious template-site red flags in the retrieved material: the documentation is specific to Fusion, the site uses protocol-specific terminology (Plasma Vaults, Fuses, atomists), and the docs expose developer-oriented paths rather than a generic brochure site.

Broken links or fake metrics were not demonstrated in the gathered sources, so those concerns are Not verifiable as of 2026-09-04. An open API is indicated: the documentation explicitly references a “developer guide,” “smart contracts,” and an “offchain metadata accessor,” and an external technical write-up describes an IPOR vault API and offchain metadata fields used by scanners. That said, a public, fully documented REST/API surface is only partially evidenced from the sources available, so the safest conclusion is that an API exists for integration/developer use, but the exact public openness and completeness of the API are Not verifiable as of 2026-09-04.

Evidence (9)

Security

bug bounty

two sources

Fusion by IPOR has an active bug bounty program hosted on Immunefi. It started on 11 April 2023. The public Immunefi program page lists rewards in USDC and IPOR, denominated in USD, with a maximum bounty currently shown as $20,000 and live since 11 April 2023.

The older IPOR announcement said the initial scope covered 30 smart contracts and rewards ranged from $1,000 to $100,000, with critical impacts including direct theft of user funds, permanent freezing of funds, and protocol insolvency. The Immunefi page also specifies payout rules by severity and notes payouts are handled directly by the IPOR team; critical rewards are split 50% USDC and 50% IPOR. The public announcement page does not show verified incident results; not verifiable as of 2026-09-04 whether any bounty has been paid or how many reports were accepted.

Active
Yes
Platform
Immunefi
Max payout
$20K
Since
2023-04-11
Evidence (2)

counterparty risks

two sources

Assessment — Dependencies & Counterparty Risk (as of September 6, 2026) Dependency failure active: null Max exposure: null% — Not verifiable as of September 6, 2026. Dune/on-chain verification was unavailable, and public sources do not disclose vault-level allocation caps or current dependency weights. External DeFi protocols: Fusion is a modular vault layer that can route funds to Aave V3, Compound V3, Morpho/Morpho Blue, Moonwell, Euler, ERC-4626 vaults, Uniswap/Ramses liquidity venues, and other configured markets through “Fuses.” A failure, bad debt event, oracle error, liquidity freeze, or exploit in any enabled venue can impair NAV or withdrawals. The actual protocols and percentages for the selected vaults are Not verifiable as of September 6, 2026. Oracle and manipulation risk: Fusion balance accounting relies on a Price Oracle middleware; documentation identifies Chainlink feeds as a standard source but permits additional/custom middleware. Wrong, stale, manipulated, or misconfigured feeds could overstate NAV, trigger incorrect liquidations, or enable loss through swaps/withdrawals.

Feed-by-feed validation is Not verifiable as of September 6, 2026. Privileged/operator risk: Atomists and Alpha managers can control configured strategy actions, while fuses and substrates constrain destinations. Timelocks may be set to zero. This is a material governance and operational counterparty risk. Incident / contradiction callout: On January 6, 2026, a legacy Arbitrum Fusion vault reportedly lost approximately $336,000 through an access-control/arbitrary-call exploit.

This contradicts any blanket assumption that Fusion’s modular controls eliminate execution risk; the incident was reportedly limited to a legacy vault, but remediation scope is Not verifiable as of September 6, 2026. Bridges, custodians, CEX/MM, RWA/SPV: No required bridge, centralized custodian, CEX market-maker, or RWA issuer/SPV dependency was identified in reviewed materials. Current exposure is Not verifiable as of September 6, 2026. Stablecoin/LST/restaking: Fusion can support stablecoins and externally issued assets, but current vault-level USDC/USDT/DAI, LST, or restaking exposure is Not verifiable as of September 6, 2026. A depeg or issuer insolvency could produce losses, withdrawal shortfalls, or inaccurate NAV. Chain-scope contradiction: DeFiLlama currently reports Fusion on more chains than the supplied Ethereum, Arbitrum, and Base scope; chain-by-chain exposure for the requested scope is therefore Not verifiable as of September 6, 2026.

Evidence (5)

crypto custody

unverified

Custody is organized as separate, isolated ERC-4626 vaults rather than a shared pool. Fusion’s documentation says each Fusion Vault is an independent mandate vehicle with dedicated custody, assets are owned by the specific vault contract, and assets cannot be commingled across vaults. The architecture also separates duties across roles such as Owner, Atomist, Fuse Manager, Alpha, and Guardian, with the Guardian able to pause or unpause a vault.

Withdrawal handling is vault-specific: some vaults support instant withdrawals, while others require a scheduled two-step withdrawal process; all vaults are described as having hybrid withdrawals, but a paused state is not verifiable as of 2026-09-06.

Segregated assets
Yes
Evidence (4)

incident

two sources

IPOR’s stated response was to work with Blockaid and Hexagate for detection, SEAL for recovery, and other security firms to trace the funds; IPOR also said the DAO treasury would cover the shortfall and all affected depositors would be made whole. Reported reimbursement was full repayment from the treasury, with DefiLlama marking the returned funds as $336,000.

Date
2026-01-06
Cause
Other
Loss
$336K
Evidence (2)

incident

two sources

Fusion by IPOR: Access Control via Arbitrary External Call on Arbitrum; loss $336,000 (DeFiLlama hacks registry). Remediation status: resolved (retained evidence).

Date
2026-01-06
Cause
Smart-contract exploit
Loss
$336K
Attacker proceeds
$336K
Status
resolved
Recovered
$336K
Reimbursed
Yes
Classification
Access Control
Technique
Arbitrary External Call
Event id
fusion-by-ipor-arbitrum-2026-01-06
Evidence (5)

key management

unverified

Fusion by IPOR organizes key management as a hierarchical role-based access control (RBAC) system built on OpenZeppelin AccessManager. The docs say the highest authority is the ADMIN_ROLE for bootstrapping, followed by OWNER_ROLE for general governance, with ATOMIST_ROLE handling vault configuration and strategy guardrails, ALPHA_ROLE handling operational execution, and GUARDIAN_ROLE for emergency pause/cancel actions.

Evidence (3)

smart-contract

one source

Assessment (as of September 6, 2026): High governance/key risk; deployment-specific controls remain unverified. Addresses. Confirmed adjacent IPOR infrastructure—not verified Fusion vault addresses: Ethereum Router 0x16d104009964e694761C0bf09d7Be49B7E3C26fd, Oracle 0x421C69EAa54646294Db30026aeE80D01988a6876; Arbitrum Router 0x760Fa0aB719c4067D3A8d4727Cf07E8f3Bf118db, Oracle 0x70DdDE503edf4816B5991Ca5E2f9DE79e295F2D0; Base Router 0x21d337eBF86E584e614ecC18A2B1144D3C375918, Oracle 0x85564fb392e18A84A64343A3FB65839206936C0f. Specific Fusion PlasmaVault, AccessManager, WithdrawManager, FeeManager and per-chain proxy-admin addresses: Not verifiable as of September 6, 2026. Architecture. Factory (UUPS) → PlasmaVault (ERC-4626 asset container) → AccessManager / ContextManager / WithdrawManager / RewardsManager / FeeManager / PriceOracleMiddleware → Fuse adapters → external markets. The vault is designed to extend strategies through registered Fuses rather than upgrading core vault logic; factories and some middleware are upgradeable. Admin and exit controls. Documented roles include ADMIN, OWNER, ATOMIST, and ALPHA; privileged functions can configure markets/fuses, oracle and prehooks, fees, withdrawals, pauses/target closure, and execution routing.

Actual role holders, renounced roles, proxy-admin type, timelock delay, and whether withdrawal remains permissionless are Not verifiable as of September 6, 2026 because Dune/on-chain decoding is unavailable. IPOR documentation claims upgrades use timelock plus multisig, but the live deployment and delay are unverified. Security history. Fusion had a January 6, 2026 Arbitrum legacy-vault exploit of approximately $336,000 involving delegated admin authority, EIP-7702 and insufficient Fuse validation. This demonstrates that “audited” does not eliminate configuration/access-control risk.

Audits by Protofire (September 6, 2024) and BlockSec (February 28, 2025) reportedly covered Fusion Vault, Fuses, access management, oracle and withdrawal components; exact bytecode-to-deployment matching is Not verifiable as of September 6, 2026. Worst case: compromised privileged keys could freeze exits, alter accounting/oracle or Fuse configuration, route vault assets through malicious external calls, or upgrade factory-controlled components. User exit without administrators is therefore Not verifiable as of September 6, 2026. Risk diagram: Admin/multisig → AccessManager/timelock → Vault + managers → Fuse execution → external protocols/assets. Contradiction: current marketing claims “0 admin keys over depositor funds” and “immutable vault & Fuse contracts,” while the documented UUPS factory, privileged role model, and 2026 access-control exploit show that this cannot be treated as proof of zero administrative or configuration risk.

Evidence (8)

audit

unverified

Ackee Blockchain audited prior IPOR protocol versions; the docs indicate the audit covered the currently live contracts for the cited version, but the listing provided here does not include the detailed findings table.

Auditor
Ackee Blockchain
Report date
2023-12-13
Scope
IPOR Protocol Core V2 updates, including Stake Rate Swaps (SRS), refactor of liquidity mining, refactor of the IPOR oracle related to SRS, and minor bug fixes
Evidence (2)

audit

one source

BlockSec — IPOR Fusion audit, version 1.0, published February 28, 2025.

Auditor
BlockSec
Report date
2025-02-28
Scope
Fusion Vault; Base Fuses; Rewards Manager; Access Management; Price Oracle Middleware; Prehooks; Context Manager; Withdraw Manager. IPOR documentation states the review covers the currently live contracts. Independent bytecode/deployment matching to the audited report: Not verifiable as of 2026-09-05.
Findings
Critical: Not verifiable as of 2026-09-05. High: Not verifiable as of 2026-09-05. Medium: Not verifiable as of 2026-09-05. The published report was not independently retrievable in this review; no severity or finding count is inferred.
Fix status
Not verifiable as of 2026-09-05. The available protocol index does not provide a finding-by-finding remediation table or final fix-review status.
Evidence (2)

audit

unverified

BlocSec audited the updated IPOR Fusion stack; IPOR docs say this report covers the currently live contracts.

Auditor
BlocSec
Report date
2025-02-28
Scope
Fusion Vault, Base Fuses, Rewards Manager, Access Management, Price Oracle Middleware, Prehooks, Context Manager, Withdraw Manager
Evidence (2)

audit

one source

Published Protofire audit, version 1.1, dated September 6, 2024. The current Fusion security index still lists it and states that it covers the currently live contracts. Independent bytecode/deployment matching to the audited report is Not verifiable as of 2026-09-06.

Auditor
Protofire
Report date
2024-09-06
Scope
IPOR Fusion: Fusion Vault, Base Fuses, Rewards Manager, Access Management, and Price Oracle Middleware.
Findings
Critical: None publicly identified in the available Protofire announcement. High: None publicly identified in the available announcement. Medium: None publicly identified in the available announcement. The complete report/finding table was not independently retrievable; therefore zero findings are not treated as verified.
Fix status
Not verifiable as of 2026-09-06. Public messaging describes the result as complete/all good, but no finding-by-finding remediation matrix or final re-audit evidence was located.
Report url
https://drive.google.com/file/d/1UZE7J-pTfHY-XtgZtVYMAOh4tHXTCCN2/view
Report id
doc:578048ca60bb79cb
Evidence (3)

Team & Reputation

founders

two sources

Fusion is built by IPOR Labs AG, a Zug, Switzerland–registered company that develops the IPOR protocol and Fusion vault infrastructure. ### Founders & senior team

  • Darren Camas – Co‑founder & CEO: Public, long‑tenured crypto founder. According to a research report, he has been active since 2011 (early exchange TradeHill), later involved in brokerage, payments, data, L1s, and was an early advisor to Cardano. His profile appears consistently across IPOR’s site, media interviews, and Arbitrum governance disclosures.
  • Dimitar Dinev – Co‑founder & CSO: Public. Arbitrum governance and team page describe him as co‑founder and Chief Strategy Officer with background in financial markets and crypto.
  • Other visible team members include Mauricio Hernandes, PhD (Chief Scientist), Lukasz/Wookash Muzyka (Head of Product), marketing lead Vlad Dramaliev, and several named engineers with PhDs. These are real‑name, public profiles, not pseudonyms. ### Public vs. anonymous, prior track record
  • Governance and external research list founders and key contributors with full names and roles; Fusion/IPOR is therefore a fully public team, not anon.
  • Darren’s prior projects include early centralized exchange work (TradeHill) and advisory roles in major L1 ecosystems (Cardano), plus multiple crypto ventures in brokerage, payments, and data infrastructure. Outcomes are mixed but there is no public record of major project‑level hacks attributed to him or Dimitar; this is based on absence of such mentions in independent research and partner write‑ups, not on-chain evidence. ### Corporate reality: office, jurisdiction, business substance
  • Legal entity: IPOR Labs AG is explicitly described as a company incorporated in Zug, Switzerland.
  • Office / HQ: LinkedIn lists a physical address in Zug (Baarerstrasse 82, 6302 Zug, Switzerland) as headquarters. This supports onshore Swiss corporate status, not an offshore shell.
  • Business activity: Multiple independent sources describe Fusion as institutional‑grade on‑chain vault and asset‑management infrastructure for professional allocators, DAOs, and structured products. Presence of a maintained open‑source GitHub repo and official Python SDK maintained by IPOR Labs AG further indicates an active software business, not a pure web front. ### Reality check / credibility assessment
  • Pros:
  • Public founders with >10 years in crypto, repeated across governance, research, and media.
  • Swiss AG entity and physical HQ address; consistent description as institutional infrastructure.
  • Active ecosystem partnerships (e.g., Blockaid threat monitoring), suggesting third‑party technical diligence.
  • Gaps / Not verifiable as of 2026-09-04:
  • On-chain evidence for founder holdings, vesting, and detailed incident history.
  • Full regulatory status (licenses, approvals) beyond Swiss incorporation. Overall, Fusion by IPOR appears to be a real, onshore Swiss software company with public founders and a credible, institution‑oriented DeFi product, though some regulatory and on-chain details remain Not verifiable as of 2026-09-04.
Evidence (15)

general reputation

two sources

Fusion by IPOR appears to have a generally positive reputation in public sources, with multiple security reviews and no clear public evidence in the gathered material of fraud, rug-pull, insolvency, or sanctions issues. The strongest verifiable points here are that the protocol states it has been audited by Protofire (September 2024) and BlockSec (February 2025), and a third-party review site also lists two audits on record. The most concrete team/institutional signals in the gathered sources are that Fusion is associated with IPOR Labs, and public profiles describe the organization as founded in 2021; one company profile also lists Darren Camas and Dimitar Dinev as co-founders.

The project’s public materials also reference institutional adoption, including Tesseract selecting Fusion as onchain vault infrastructure and naming it a MiCA-authorized CASP. Investor backing is less cleanly verifiable from the gathered sources: one review article names Arrington Capital as lead investor and lists several other funds, but this is not independently confirmed in the provided material, so I would treat those investor claims as *not fully verifiable* from this pass. Criticism and unresolved concerns are mostly operational rather than allegation-based.

A third-party risk review flagged one high, four medium, and six low risk alerts across smart-contract, economic, governance, sustainability, and reputation categories. That suggests there are still open risk considerations despite the audit history. Another unresolved issue is that several reputation claims in the protocol’s own materials, including broad statements about being “audited by the best in Web3,” remain unverified marketing claims without external corroboration in this pass.

I did not find credible public evidence in the gathered sources of legal/regulatory enforcement, sanctions, or insolvency allegations against Fusion by IPOR. Not verifiable as of 2026-09-04.

Evidence (6)

Economy

TVL: $63.8M

model

one source

Assessment (as of September 6, 2026): Fusion is an infrastructure/platform for multiple Plasma Vault strategies, not one protocol-wide economic strategy. Current public vaults include lending optimizers, leveraged looping, carry trades, yield optimizers, staking/restaking-like products, and bond/ETF strategies. Therefore the prior description of Fusion as primarily a delta-neutral CeFi/OTC basis trade is not supported as a protocol-wide characterization; CeFi/OTC execution is Not verifiable as of September 6, 2026. Assets and yield: Vault assets are vault-specific; current examples include USDC, USDT, ETH/WETH, cbETH, wstETH, WBTC, USDe, and wsrUSD.

Yield can derive from lending interest, borrowing/looping spreads, carry trades, staking/restaking, derivatives, DEX liquidity, and external incentives. Fusion supports deposits, borrowing against collateral, swaps, derivatives, reward claiming, and external ERC-4626 vaults. Risk profile: Market neutrality is not universal. Some products are carry-oriented or potentially hedged, while leveraged loops and ETH/BTC products retain liquidation, basis, oracle, and directional/market risk.

Leverage is configurable per vault; public examples display up to 12x TVM/multipliers, but a protocol-wide leverage ratio is Not verifiable as of September 6, 2026. Withdrawals and controls: Vaults may support instant, scheduled, or hybrid withdrawals. Scheduled withdrawals can have request windows and request/withdrawal fees; instant withdrawals depend on configured liquid markets. Deposits and withdrawals may be whitelist-gated, and configuration changes may have timelocks, including zero-second timelocks.

Fees include configurable performance and management fees. TVL / revenue: Dune was unavailable, so on-chain TVL, exposure, collateral, and trend are Not verifiable as of September 6, 2026. DeFiLlama reports approximately $62.17m TVL: Base $33.09m (53.2%), Ethereum $28.59m (46.0%), Arbitrum $0.48m (0.8%); it also lists additional chains, contradicting the supplied three-chain scope. DeFiLlama reports 63 pools, average APY 5.6%, and $105k 30-day fees, but these are analytics-platform figures, not raw on-chain verification.

APY history, volatility, and sustainability are Not verifiable as of September 6, 2026. Contradiction: The supplied “delta-neutral leveraged basis trade” finding is narrower than the currently documented/public Fusion product set and should not be reused as a platform-wide conclusion. Structured fields: organic_yield_pct: null; leverage_ratio: null

Evidence (5)

reserves

two sources

Assessment as of September 6, 2026

  • Liquid reserves (USD): null — Not verifiable as of September 6, 2026. Dune MCP was unavailable, so treasury-wallet balances, token composition, and cross-chain reserve totals cannot be independently verified on-chain.
  • Liabilities (USD): null — Not verifiable as of September 6, 2026. No audited balance sheet, proof-of-liabilities statement, or explicit depositor-liability schedule was located.
  • Treasury size: IPOR publicly stated after the January 6, 2026 Arbitrum exploit that affected users would be fully reimbursed from treasury reserves and that reserves represented less than 1% of Fusion funds secured. This is a management statement, not an independently verified reserve amount. The exploit loss was reported at approximately $336,000 USDC.
  • Addresses / custody / composition: Not verifiable as of September 6, 2026. The public IPOR ABI repository lists protocol and fuse contracts, but does not establish a dedicated treasury address, balances, custody arrangement, or reserve asset mix.
  • Control: For a proposed Reserve/USD3 deployment, Reserve DAO—not IPOR—was described as sole vault owner/admin, with IPOR’s automation constrained by whitelisted fuses and limits. This documents a vault-control model, not Fusion treasury control.
  • Reserve policy / attestations: No formal, independently attested reserve policy, recurring treasury report, multisig signatory disclosure, or proof-of-reserves report was located. The full-refund commitment is the only directly identified reserve-policy evidence. Chain context (aggregator, not reserves): DeFiLlama reports Fusion TVL of $62.17m: Base $33.09m (53.23%), Ethereum $28.59m (45.99%), and Arbitrum $0.482m (0.77%). These figures represent vault TVL, not treasury reserves or liabilities. Contradiction / limitation: IPOR’s current site displays $148.9m “TVM,” while DeFiLlama reports $62.17m TVL; definitions and coverage differ, and neither figure proves reserves. On-chain reconciliation is Not verifiable as of September 6, 2026.
Evidence (5)

tokenomics

one source

Assessment — as of September 4, 2026. Fusion currently has no verifiable live native token. The planned token is FUSN, but official documentation says it “has not yet been launched”; no FUSN contract address is published. A recent LinkedIn post claims “$FUSN token launched,” creating a direct contradiction; launch and address are Not verifiable as of September 4, 2026.

Legacy token: IPOR (not a current Fusion token). Ethereum: 0x1e4746dc744503b53b4a082cb3607b169a289090; Arbitrum bridged: 0x34229B3f16fBCDfA8d8d9d17C0852F9496f4C7BB; Base bridged: 0xbd4e5C2f8dE5065993d29A9794E2B7cEfc41437A. Genesis supply was 100m; the mint function was removed. The legacy allocation was: DAO treasury 30%, liquidity mining 25%, operations 12.76%, core team 20%, investors 11.85%, retroactive rewards 0.39%.

Team and investor vesting was linear over three years; liquidity-mining emissions were governance-adjustable. FUSN proposal/tokenomics. Proposed maximum supply: 100m; 1:1 migration from IPOR and pwIPOR based on the May 9, 2025 snapshot. Planned utility: governance, fee rebates for locked FUSN, liquidity-mining power-up, and revenue-funded buybacks for burns or DEX liquidity.

Up to 100% of protocol revenue was proposed for buybacks. No final emissions, allocation chart, investor/team unlock schedule, or controlling addresses are published. Market data and controls. Current FUSN market cap, FDV, circulating supply, holders, insider concentration, DEX depth, and listings: Not verifiable as of September 4, 2026.

Legacy IPOR figures on Etherscan are stale and inconsistent with the announced withdrawal/private-token transition. Actual unlocks versus announced schedules and cross-chain holder concentration: Not verifiable as of September 4, 2026. Ethereum IPOR’s verified ABI shows no mint, burn, blacklist, fee, or fee-switch functions; bridged-token administrative controls were not independently verified.

Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin move below $10,000 would likely be a *severe stress event* for Fusion by IPOR, but the protocol’s public docs do not provide enough verified information to quantify specific losses, liquidations, or chain-by-chain exposure under that scenario. Not verifiable as of 2026-09-04. What can be stated from the available sources is limited to design implications.

Fusion vaults use price oracles to decide how share price and contributions react to market moves; the docs explicitly say that with market oracles, vaults should increase onboarding contributions during a depeg dip, while with fundamental oracles, vaults should increase offboarding contributions when market price deviates from the fundamental rate. The protocol also states that vault mechanics, allocations, performance, costs, and onchain activity are exposed for verification, but no vault-level stress test for BTC at $10k is provided in the retrieved material. For the requested chains — Arbitrum, Base, and Ethereum — the chain-specific TVL, asset exposure, and any BTC-linked allocation percentages are Not verifiable as of 2026-09-04.

I also cannot verify whether any live Fusion vaults on those chains hold BTC, BTC derivatives, or BTC-correlated strategies from the available sources. Most relevant risk interpretation: if a Fusion vault were benchmarked to BTC or held BTC-sensitive collateral, a collapse below $10,000 could trigger oracle-driven rebalancing, investor withdrawals, and possible share-price dislocations; if the vault is instead tied to non-BTC assets, the effect could be indirect via broader crypto-market contagion. That is an inference from the oracle and vault-design documentation, not a verified protocol-specific stress result.

No on-chain verification was possible in this run, so any precise statement about losses, insolvency risk, or unwind behavior would be speculative.

Evidence (4)

stress scenario - largest collateral depegs 20%,

unverified

Not verifiable as of 2026-09-04. The provided sources describe Fusion’s risk controls and stress-response behavior, including automated deleveraging, siloed vault risk, deposit caps, and the ability to withdraw liquidity during stress, but they do not provide the live collateral composition, collateral amounts, or vault-level leverage needed to model a 20% depeg shock quantitatively. The only numeric exposure clue in the results is a July 2026 news item stating that Fusion vaults hold around 30,500 cbETH on Base, but this is not enough to determine the total collateral stack across Arbitrum, Base, and Ethereum or the loss transmission under a 20% collateral depeg.

Because on-chain verification is unavailable in this run, the stress impact cannot be computed reliably; the correct risk conclusion is that the protocol’s maximum loss under this scenario is not verifiable from the available web evidence.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Fusion by IPOR, a “top counterparty insolvent” stress is not verifiable as of 2026-09-04 from the available web evidence alone. What is verifiable is the *loss-containment design*: Fusion uses isolated PlasmaVaults, so risk is siloed per vault and does not automatically socialize across vaults. Expected loss path: if an external venue or counterparty used by a vault becomes insolvent, the impairment should first hit the *specific vault* that has exposure to that venue, reducing that vault’s asset value and NAV rather than the whole system. Who absorbs it: the loss is absorbed by the affected vault’s LPs/shareholders, unless a separate compensation action is taken. Fusion’s public messaging explicitly says losses are siloed between vaults and “not socialised”. Compensation: a separate question of whether the DAO or treasury compensates users is not verifiable as of 2026-09-04 from the gathered sources.

A secondary source on a legacy Arbitrum incident claims full user compensation, but that is about a past exploit and should be treated as a case-specific report, not a general insolvency rule. Impact path through smart contracts: the architectural path is vault-centric: PlasmaVault is the core ERC-4626 vault, and external protocol interactions are executed through modular fuses via delegatecall, with access control and pause mechanisms layered around the vault. In an insolvency scenario, the damage path is therefore: external protocol failure → position-level valuation impairment inside the affected vault → lower redeemable vault value for that vault’s holders; other vaults remain isolated. Chain split: the same architectural logic applies on Arbitrum, Base, and Ethereum because the sources describe the protocol design, not chain-specific insolvency behavior; chain-by-chain exposure percentages are Not verifiable as of 2026-09-04.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For a stress scenario involving committed fraud by the DAO or owners, the key question is whether there is evidence the protocol’s governing parties could intentionally divert user funds or misrepresent the system. I found no credible source in the provided results alleging DAO- or owner-committed fraud at Fusion by IPOR; the available evidence instead describes a security exploit on a legacy Arbitrum vault, with the team publicly attributing the loss to a vulnerability and stating the DAO would cover the shortfall from treasury. What is verifiable is narrower: an Arbitrum legacy vault lost about $336K USDC, other vaults were said to be unaffected, and affected depositors were promised reimbursement from the DAO treasury.

That supports an operational/security incident, not proof of fraud by the DAO or owners. Because this query asks specifically about committed fraud by insiders, the proper risk conclusion is: Not verifiable as of 2026-09-04. The provided sources do not establish malicious intent, insider theft, or governance abuse by Fusion’s DAO/owners.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

Fusion by IPOR appears to be an onchain vault infrastructure / yield optimization protocol deployed across Ethereum, Base, and Arbitrum, with DefiLlama showing chain-level activity and fees across those networks. For the requested stress scenario, a negative 30-day primary yield source is not verifiable as of 2026-09-04 from the available web results because the results do not identify each vault’s current primary yield source, nor do they provide 30-day source-level performance by chain or vault. What can be stated with confidence is that Fusion is designed to route capital across multiple yield venues and supports configurable vault/fuse structures rather than a single fixed yield source.

The documentation also shows risk controls such as deposit caps and governance delays, which are relevant in a stress event because they can constrain exposure changes and withdrawals, but they do not by themselves establish what happens when a specific yield source turns negative over 30 days. So, the practical risk view is: if a Fusion vault’s primary yield source goes negative over 30 days, the likely operational consequence would be lower APY or outright loss on that sleeve, but the exact impact on any given vault on Arbitrum, Base, or Ethereum cannot be confirmed from the provided sources.

Evidence (5)

Governance & Legal

governance

one source

Assessment as of September 13, 2026. Governance is transitional and not presently a fully effective DAO. The documentation states that the legacy IPOR DAO is transitioning to Fusion DAO, while the future FUSN token has not yet launched. During transition, IPOR Labs and DAO workgroups act as guardians; proposed governance is initially Snapshot/workgroup-based, with long-term token-holder governance planned.

Therefore, DAO control is currently partly symbolic rather than effective control over upgrades and parameters. Control map. IPOR Labs AG controls the hosted frontend/interface, its intellectual property, and may restrict or terminate interface access. Its Terms disclaim ownership/control of the smart-contract Protocol. The protocol’s documented initial control path is: IPOR Core Team → 4-of-6 Gnosis Safe → 10-minute Timelock → contract executor.

Upgradeable contracts and admin functions such as pause are governed through this path. Multisig/timelock. Documented Safe: 0xF6a9…8d5569; six listed signers; threshold 4-of-6. Listed signers are engineering/business team addresses, so independence from IPOR Labs is not demonstrated. Timelock minimum is 10 minutes (0.1667 hours); executors are four listed addresses.

No separate emergency bypass is documented. Funds and concentration. Fusion vault administrators/Atomists/Alphas can configure and operate vault strategies within fuse and timelock permissions; this is vault-level control, not evidence of DAO control. Actual treasury custody, contract-level ability to drain user funds, voting concentration, and top holders across Ethereum, Arbitrum, and Base: Not verifiable as of September 13, 2026 (Dune unavailable; no on-chain inference made). Company. IPOR Labs AG is a Swiss Zug Aktiengesellschaft, commercial-register no. CH-170.3.045.959-4, UID CHE-207.667.850.

Moneyhouse lists Darren Camas as board member and Darren Camas/Tobias Pfütze as authorized signatories; this is a registry-aggregator result, not a primary extract. Terms are governed by Swiss law.

Timelock
Yes
Timelock delay hours
0.1667
Multisig threshold
4
Multisig owners
6
Dao governance
No
Evidence (5)

legal & regulatory

two sources

As of September 4, 2026, the identified operating entity is IPOR Labs AG, a Swiss Aktiengesellschaft registered in Zug (UID CHE-207.667.850; commercial purpose includes financial-market software). Fusion itself is presented as decentralized smart-contract infrastructure, not as a separately incorporated or licensed legal person. The Terms are governed by Swiss law. ToS/restrictions: Users must be 18+, comply with applicable law, and restricted-interface users represent that they are not U.S. or certain sanctioned/embargoed-country persons.

VPN circumvention is prohibited. The Terms disclaim control, warranties, liability, and investment/legal/tax advice; users bear responsibility for securities, asset-management, AML/KYC, tax, and licensing compliance. Asset managers must perform suitability diligence, disclosures, and compliance monitoring. KYC/AML and classification: The Terms mention AML/KYC as user obligations but do not establish that IPOR Labs AG conducts customer onboarding, identity verification, or operates as a licensed financial intermediary.

Formal Swiss/EU/U.S. classification, licensing, or exemption status: Not verifiable as of September 4, 2026. The legal structure therefore reduces counterparty-identification ambiguity but does not eliminate regulatory-perimeter risk for vault operators, curators, tokenized-asset strategies, or users managing third-party assets. Data protection: The privacy policy says the operator may collect wallet/transaction data, IP/geolocation, device data, and cookies; it may disclose information to service providers or authorities. It does not clearly specify retention periods, detailed data-subject rights, international-transfer safeguards, or a separately identified data-protection establishment.

These omissions create privacy/compliance diligence items. Warnings/enforcement/cases/sanctions: Regulator warnings or enforcement against IPOR Labs AG/Fusion: Not verifiable as of September 4, 2026. Court cases: Not verifiable as of September 4, 2026. Sanctions targeting the protocol or entity itself: Not verifiable as of September 4, 2026.

Compliance blocking of sanctioned wallet addresses would not itself constitute entity sanctions. Contradiction/risk note: “Institutional-grade” and “compliance-friendly” are marketing descriptions, not evidence of licensing or regulatory approval.

Entity
IPOR Labs AG
Jurisdiction
Switzerland (Zug)
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'IPOR Labs AG', 'Fusion by IPOR'. OFAC SDN screening of 'IPOR Labs AG', 'Fusion by IPOR': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • IPOR Labs AG
  • Fusion by IPOR
Sanctioned
No
Evidence (4)

Stability

stability

one source

Fusion by IPOR does not appear to issue its own stablecoin. The available web evidence describes Fusion as a vault/yield infrastructure protocol that uses external assets such as USDC, USDT, DAI, and crvUSD, but there is no verifiable protocol-issued stablecoin to analyze for depeg history. A related June 2026 post says two Fusion vaults were being closed after a crvUSD depeg, but it does not provide a quantified depeg series for Fusion itself, so the number of depeg events, last depeg date, and maximum depeg percentage are not verifiable as of 2026-09-06.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

two sources

Fusion’s primary risks are smart-contract and privileged-control failures, amplified by its modular strategy architecture and external protocol dependencies. A January 6, 2026 Arbitrum exploit caused approximately $336,000 in losses, demonstrating that documented controls did not eliminate legacy-vault attack paths. On-chain verification is unavailable in this run: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Legacy vault exploitabilityThe January 2026 Arbitrum incident combined delegated admin execution with insufficient withdrawal-fuse validation, enabling approximately $336,000 of loss. Older vaults or inconsistent deployments may retain comparable attack surface.HighMediumNewer vaults reportedly add stricter fuse validation; fuses are intended to be stateless and non-upgradable, and vault owners can constrain actions and slippage.High residual risk for legacy or poorly configured vaults; remediation coverage by vault is Not verifiable as of September 5, 2026.
Privileged upgrade and admin riskUpgradeable routers/oracles and multisig-controlled administration create key-compromise, collusion, or malicious-upgrade risk. Timelock duration can be selected as zero for vault changes.HighMediumDocumented controls include multisig approval, timelocks, OpenZeppelin Defender, and role-based access management.Medium-High; signer independence, current thresholds, and effective delays are Not verifiable as of September 5, 2026.
External protocol composabilityVaults route funds through lending, liquidity, swapping, and other integrated markets; an exploit, insolvency, oracle failure, or parameter shock in any dependency can impair strategy assets.HighMediumFuse modules constrain permitted actions, markets, tokens, and balances; risk is intended to remain siloed by vault.Medium-High because siloing limits contagion but does not prevent losses within an affected vault.
Strategy leverage and liquidationFusion supports looping, carry trades, arbitrage, and leveraged farming; rapid price, rate, liquidity, or collateral-ratio changes can cause forced deleveraging and principal loss.HighMediumCurators configure market-specific fuses, balance checks, slippage limits, and rebalancing logic.Medium-High; strategy-specific leverage caps, stress tests, and liquidation buffers are Not verifiable as of September 5, 2026.
Oracle and chain availabilityShared price-oracle middleware and deployment across Ethereum, Arbitrum, and Base introduce feed, sequencer, RPC, congestion, and chain-specific execution risks.MediumMediumFusion uses oracle middleware, market-specific balance fuses, and chain-specific contract deployments.Medium; oracle fallback design, sequencer safeguards, and real-time monitoring are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Top 5 strengths of Fusion by IPOR are: modular on-chain vault infrastructure, which gives each vault explicit, transparent mechanics for allocations, performance, costs, and activity; intelligence-driven execution, supporting automation for strategies such as looping, carry trades, arbitrage, and leveraged farming; single integration into multiple yield venues, which reduces operational burden and improves capital deployment efficiency; automated risk management with siloed vault exposure, so losses are not socialized across vaults and exposure can be reduced during stress; and composable, upgradeable integrations via Fuses, allowing strategies to add or change protocol connections without moving funds to a new vault. These strengths are repeatedly described across IPOR’s docs and supported by independent commentary that emphasizes deterministic risk enforcement, vault isolation, and modular execution.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 17 two independent sources, 9 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-29.