Gauntlet

Orange · 57/100

Executive summary

Gauntlet is a DeFi risk-management firm operating yield vaults across Arbitrum, Base, Ethereum, and OP Mainnet, scoring 38/100 (red band) due to active SEC enforcement and an unresolved incident.

  • Security: Multiple audits by Spearbit, OpenZeppelin, and Cantina (2022–2026) covering Aera V3 vault infrastructure; 1 high-severity finding fixed in May 2025 Spearbit audit, 1 high and 3 medium acknowledged in June 2025 Cantina competition; bytecode match to deployed contracts not verifiable; active Immunefi bug bounty program claimed but unverified.
  • Incidents: Two material losses: April 2024 ezETH depeg caused 7.12 WETH socialized loss (11 bps, no reimbursement); March 2026 Resolv USR key compromise led to ~$5.95M outflow from Gauntlet vaults, with $4.38M partial recovery via Merkl—remediation in progress, users not made whole.
  • Governance & custody: Company-controlled by Gauntlet Networks, Inc. (Delaware); no DAO governance verified; vaults are non-custodial with user-initiated withdrawals, but Gauntlet operates off-chain guardians and curators with privileged strategy control; withdrawal delays possible under market illiquidity.
  • Top risks: Underlying protocol failure (Morpho, Aera, Pendle dependencies); oracle/depeg exposure in stablecoin and RWA strategies; active SEC enforcement against Gauntlet Holdings, LLC with final judgments in July 2026; unresolved $1.57M shortfall from Resolv incident; no verified reserve or liability disclosure.
  • Strengths: Simulation-driven risk modeling with institutional credibility (Aave, Compound clients); continuous rebalancing and multi-chain reach; public founder team (Tarun Chitra, ex-D.E. Shaw) with venture backing; documented API and SDK for integrators.
  • Unverified: Exact TVL, chain-by-chain exposure, and vault composition not independently verified (Dune unavailable); OpenZeppelin June 2025 audit and Immunefi bounty details rely solely on Gauntlet claims; reserve assets, liabilities, and fee arrangements undisclosed.
  • Recommended exposure: Avoid or minimal allocation (<1% portfolio) until Resolv remediation completes and SEC enforcement impact clarifies; if allocating, limit to blue-chip collateral vaults (e.g., USDC Core) with documented audit coverage, and monitor withdrawal queue depth; require independent verification of deployed contract bytecode and reserve transparency before material exposure.
  • Open questions: Verify final Resolv reimbursement status and user claims process; confirm deployed contract addresses match audited code via bytecode comparison; obtain independent attestation of vault reserves and liabilities; clarify SEC enforcement scope and any ongoing restrictions; assess withdrawal processing times and liquidity under stress for target vaults; verify OpenZeppelin and Immunefi program details from primary sources.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 11 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-04-15)
Incidents 20% 100 20.0 1 open incident(s), $1,570,173 at risk = 0.1% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 9 1.8 TVL $1,600,653,582 = 9% of reference ($17,538,184,136)
Data confidence 86 7/7 critical categories; 12/41 verified facts; 40/41 fresh (180d)
  • Active regulatory enforcement (−15): legal fact records active enforcement or sanctions

Identification

protocol identification

one source

Gauntlet is primarily a DeFi risk and optimization service provider, not a typical on-chain yield protocol. It runs off‑chain models and posts risk recommendations to governance; there is no widely-recognized “Gauntlet yield protocol” with TVL and user deposits on Arbitrum/Base/Ethereum/OP. Because tools like Dune are disabled and I cannot find matching on-chain contracts for a Gauntlet yield protocol, all on‑chain verification is: Not verifiable as of 2026‑09‑04. ### 1.

Protocol Identification

  • Name: Gauntlet Network (commonly “Gauntlet”).
  • Category: Risk modeling / parameter optimization service for DeFi (e.g., Aave, Uniswap, Compound), not a deposit‑taking yield protocol.
  • Website: gauntlet.network (from multiple independent descriptions).
  • Docs: Public “research” and “risk frameworks,” but no canonical protocol docs like a typical DeFi app; documentation is fragmented across blog, governance posts, and whitepapers.
  • Launch date: Company founded around 2018–2019; it began DeFi risk work early in DeFi’s growth.
  • Chains: Gauntlet’s *clients* operate on Arbitrum, Base, Ethereum, OP Mainnet, etc., but Gauntlet itself does not expose a unified on-chain protocol across these chains.
  • Native token: No publicly-known Gauntlet protocol token; Gauntlet operates as an off‑chain firm paid by DAOs (often in governance tokens) rather than via its own token.
  • Main contract addresses:
  • Not verifiable as of 2026‑09‑04. Public sources describe Gauntlet’s governance and risk recommendations but do not reference a central “Gauntlet protocol” contract set; instead, Gauntlet interacts with client protocols’ contracts (Aave, Uniswap, etc.).
  • Explorer verification status for any hypothetical Gauntlet contracts: Not verifiable as of 2026‑09‑04. ### 2. Fork Lineage
  • Is it a fork?
  • Gauntlet is a service / modeling stack, not a fork of an on-chain protocol (e.g., not an Aave/Compound fork).
  • Changes vs upstream:
  • Not applicable: there is no upstream on-chain protocol Gauntlet forked; instead it builds proprietary risk models and simulations off-chain and publishes parameter recommendations (LTVs, caps, etc.) to DAOs.
  • Audits of changes:
  • For Gauntlet’s off‑chain modeling stack, no standard “smart contract audit” applies. Specific protocols that implement Gauntlet’s recommendations may audit their own contracts, but that is independent of Gauntlet.
  • Malicious‑modification history in similar forks:
  • Since Gauntlet is not a forked on-chain protocol, this category does not apply. Any malicious events would relate to client protocols’ contracts, not Gauntlet itself, and no such pattern is attributed to Gauntlet in public risk discussions. Key takeaway: Gauntlet should be treated as an external risk vendor to DeFi protocols, not as an on-chain yield protocol with its own TVL and contract risk surface. On-chain TVL, contract set, and fork lineage for a Gauntlet yield protocol are Not verifiable as of 2026‑09‑04.
Evidence (2)

maturity

two sources

Gauntlet appears to have a real developer-facing product, not just a marketing landing page: its docs describe a public REST API, a developer portal for app registration/API keys/payments, and an SDK that handles vault discovery plus deposit/withdrawal transaction building. The product also supports live on-chain interactions in documented form, including deposits, withdrawals, and balance/position queries, with multi-step async flows for some vaults. I could not verify a consumer-style web app with direct live deposits/withdrawals from the website itself, nor could I verify broken links, fake metrics, or template-site signs from the available material.

Not verifiable as of 2026-09-04. Open API: yes — the docs and API listings explicitly reference a Gauntlet REST API and a developer portal/API keys flow, indicating an available API surface for integrators. Overall maturity: moderate-to-high for an institutional integration stack, but the web evidence here supports “developer platform + docs” more strongly than a polished end-user portal.

Evidence (5)

Security

bug bounty

unverified

Gauntlet appears to have an active bug bounty program hosted on Immunefi for its Aera vault infrastructure / Aera V3 vault protocol. The program announcement says reports cover smart contracts, web applications, API, and infrastructure; KYC is required; PoC is required for all severities; rewards are paid in USDC; and researchers must follow a 90-day disclosure window. The only explicit result visible in the gathered material is the live program listing, but no disclosed payout history or resolved bounty count was surfaced in the available sources.

The start date is not verifiable as of 2026-09-04 from the gathered sources.

Active
Yes
Platform
Immunefi
Evidence (2)

counterparty risks

unverified

dependency_failure_active: false — на 5 сентября 2026 г. активная авария у проверенных ключевых зависимостей не выявлена; Morpho показывает operational, а инциденты сентября отсутствуют. max_exposure_pct: null — точная доля экспозиции по протоколам/активам не подтверждена: Dune MCP недоступен. Not verifiable as of September 5, 2026. Основные контрагенты и зависимости:

  • Aera V3 — vault/custody-инфраструктура и механизм guardian/solver; хранение средств заявлено как non-custodial, но операции зависят от off-chain guardian, accountant и solver. Ошибки данных или алгоритма могут привести к неверной оценке/ребалансировке; выводы могут задерживаться.
  • Morpho — базовая кредитная зависимость для gtUSDa и других стратегий. Риски: дефолт/эксплойт рынка, bad debt, ликвидации залога и временная неликвидность. Gauntlet указывает использование Morpho на Ethereum, Base, Arbitrum и OP Mainnet.
  • Pendle — добавляет PT/SY и риск смарт-контрактов, underlying-актива, срока погашения и недостаточной ликвидационной ликвидности. Linear Discount Oracle снижает манипуляционный риск; TWAP-оракулы сохраняют AMM/liquidity manipulation surface.
  • Оракулы и исполнение: Aera прямо признаёт риски oracle failure, depeg, front-running/sandwiching, ошибок ETL и невозможности быстро реагировать на рыночный шок. Hooks, whitelists и slippage limits снижают, но не устраняют риск.
  • Stablecoin/bridge exposure: gtUSDa принимает USDC на четырёх сетях; возможны USDC depeg, bridge delay/failure и cross-chain liquidity mismatch. Конкретные bridge-провайдеры и суммы не подтверждены. Not verifiable as of September 5, 2026.
  • CEX/MM, RWA/SPV, LST/restaking, внешние кастодианы: в проверенных источниках прямая экспозиция не установлена. Not verifiable as of September 5, 2026. Сценарии потерь: эксплойт Morpho/Pendle/Aera, оракульная манипуляция, depeg USDC/underlying, массовые redemptions с недостаточной ликвидностью, задержка solver/bridge или ошибочный guardian rebalance. Точные TVL- и chain-level проценты — Not verifiable as of September 5, 2026.
Dependency failure active
No
Evidence (5)

crypto custody

unverified

Gauntlet does not publicly document a protocol-level custody model in a way that lets custody be verified for Arbitrum, Base, Ethereum, or OP Mainnet; the available evidence points to user funds remaining in the user’s self-custody wallet or in smart-contract vaults rather than being held by Gauntlet itself. Gauntlet’s vault documentation says users supply from self-custody wallets, can withdraw to their own wallets, and that partners do not need to custody user assets because interactions are direct with the smart contracts. Separate documentation also says Gauntlet can sign and submit transactions in the user’s own wallet, MPC, or custody stack, which indicates Gauntlet can integrate with multiple custody setups but does not disclose a single standardized custody arrangement.

Withdrawal status is not verifiable as of 2026-09-06, and segregated-assets status is not verifiable as of 2026-09-06.

Evidence (2)

incident

one source

Ethereum — Gauntlet LRT Core/LRT Balanced vaults. On April 24, 2024, Renzo’s ezETH suffered a liquidity-driven depeg, triggering liquidations in Morpho’s ezETH/WETH 0.86 LLTV market. The market incurred 10.96 WETH insolvencies; 7.12 WETH was socialized to Gauntlet depositors (11 bps).

Users who entered shortly before the event and withdrew afterward realized a slight loss; longer-held users were generally net positive from accrued yield. USD loss: Not verifiable as of September 4, 2026. Gauntlet reallocated exposure toward lower-LLTV markets.

No reimbursement was reported. Status: resolved; the affected allocation was remediated, but the loss was socialized rather than reimbursed.

Date
2024-04-24
Cause
Depeg / collateral
Attacker proceeds
$0
Status
resolved
Recovered
$0
Reimbursed
No
Evidence (2)

incident

two sources

Ethereum/Base — Correction/update to the previously recorded Resolv USR incident. On March 22, 2026, a compromised Resolv service key minted approximately 80 million unbacked USR, causing USR/wstUSR to collapse. Morpho’s hardcoded oracle continued valuing collateral near par, while Public Allocator flows supplied additional USDC into the impaired market.

Gauntlet-curated Core/Frontier vaults were the primary affected products; approximately $5.95 million flowed from Gauntlet vaults, versus approximately $6.2 million total additional USDC supplied across affected Morpho vaults. Broader estimates of Gauntlet-related exposure near $7.5 million remain disputed. Attacker proceeds were reported at approximately $25 million.

Gauntlet removed affected markets, disabled/reduced allocation exposure, and reviewed Public Allocator controls. Gauntlet and Resolv subsequently made 4,379,827 USDC available through Merkl across affected Gauntlet-curated vaults, including Ethereum and Base products. This is partial recovery, not evidence that users were made whole; eligible claims remain remediation rather than full reimbursement.

Current status as of September 5, 2026: remediation_in_progress. On-chain verification via Dune: Not verifiable as of September 5, 2026.

Date
2026-03-22
Cause
Key compromise
Loss
$6.0M
Attacker proceeds
$25.0M
Status
remediation in progress
Recovered
$4.4M
Reimbursed
No
Event id
gauntlet-resolv-usr-2026-03-22
Evidence (4)

key management

unverified

Gauntlet organizes key management for its vaults around a non-custodial, on-chain permission model, rather than a single party holding user assets. In Aera V3, which powers most of Gauntlet’s vault infrastructure, the vault contract enforces custody and validates operations onchain, while Gauntlet handles curation, strategy, and risk management offchain. Operationally, Gauntlet uses a guardian model: a Guardian is an off-chain agent operated by Gauntlet that submits operations to the vault, but every action must stay within pre-approved on-chain constraints such as allowlisted contracts, function signatures, and input parameters.

The docs also describe constrained roles and on-chain enforcement, meaning permissions are deliberately limited at the contract level. For vault configuration, Gauntlet separates control by vault type. In single-depositor vaults, one entity deposits directly and retains control over deposits and withdrawals; in multi-depositor vaults, users interact through a Provisioner contract that handles minting, redeeming, and async order fulfillment.

This is a form of role separation: the depositor owns funding rights, the provisioner handles share mechanics, and guardians execute strategy actions within constraints. For SDK/API access, Gauntlet explicitly states that signing stays entirely in your stack and the SDK never touches private keys. That indicates external integrations keep signing keys client-side, while Gauntlet’s infrastructure focuses on permissioned execution rather than custody of keys.

Not verifiable as of 2026-09-04: detailed internal controls for private-key storage, rotation, multisig threshold settings, or who specifically controls each operational key were not disclosed in the available sources.

Evidence (6)

smart-contract

two sources

Assessment date: September 5, 2026. Scope correction: the prior finding that Gauntlet had no user-facing contract system is outdated. Gauntlet now operates/curates Morpho vaults and the cross-chain gtUSDa strategy.

This is not one homogeneous “Gauntlet protocol”; each vault and chain must be assessed separately. Known deployment addresses include gtUSDa: Base 0x000000000001CdB57E58Fa75Fe420a0f4D6640D5; Ethereum 0x3bd9248048df95Db4fBD748C6CD99C1bAa40bAD0; Arbitrum and OP Mainnet 0x000000001DC8bd45d7E7829fb1c969cbe4D0D1eC. Provisioner contracts are separately deployed per chain.

Representative Morpho vaults include Arbitrum Gauntlet USDC Core 0x7e97fa6893871A2751B5fE961978DCCb2c201E65, Ethereum USDC Core 0x8eB67A509616cd6A7c1B3c8C21D48FF57df3d458, and Base USDC Prime 0xeE8F4eC5672F09119b96Ab6fB59C27E1b7e44b61. Architecture: users → ERC-4626 Gauntlet/Morpho vault or gtUSDa → Morpho vault adapters/markets → underlying lending markets. Morpho Vault V2 contracts are documented as immutable; Vault V1/MetaMorpho uses owner, curator, guardian and allocator roles, with timelocked risk-setting actions.

Curators cannot directly withdraw user funds; withdrawals are user-initiated, but may be delayed by market illiquidity. Performance fees and fee recipients remain privileged configuration surfaces. [CONTRADICTION] Current evidence contradicts the September 4, 2026 finding that Gauntlet was solely an off-chain service. The finding should be replaced with a vault-by-vault Morpho assessment.

Dune was unavailable; therefore proxy-admin type, exact owner/guardian/allocator addresses, upgrade events, renounced roles, on-chain timelock duration, pause/withdrawal/fee/oracle/strategy permissions, and chain-level exposure percentages are: Not verifiable as of September 5, 2026. No claim of admin drainability or audited deployment is made without deployment-specific verification. Worst case is malicious role action or compromised provisioner/strategy authority causing adverse allocation, fee extraction, frozen/delayed exits, or loss through an underlying Morpho market/oracle/adapter failure.

Users generally retain ERC-4626 withdrawal rights, subject to available liquidity.

Evidence (5)

audit

one source

05 audit report; file v3/audits/spearbit/2025-06-05.pdf in aera-finance/aera-contracts-public (protocol audit catalog).

Auditor
05
Report date
2025-06
Scope
protocol
File
2025-06-05.pdf
Catalog only
Yes
Evidence (1)

audit

one source

13 audit report; file v1/audits/spearbit/2022-06-13.pdf in aera-finance/aera-contracts-public (protocol audit catalog).

Auditor
13
Report date
2022-06
Scope
protocol
File
2022-06-13.pdf
Catalog only
Yes
Evidence (1)

audit

one source

15 audit report; file v2/audits/openzeppelin/2024-05-15.pdf in aera-finance/aera-contracts-public (protocol audit catalog).

Auditor
15
Report date
2024-05
Scope
protocol
File
2024-05-15.pdf
Catalog only
Yes
Evidence (1)

audit

one source

15 audit report; file v3/audits/spearbit/2026-04-15.pdf in aera-finance/aera-contracts-public (protocol audit catalog).

Auditor
15
Report date
2026-04
Scope
protocol
File
2026-04-15.pdf
Catalog only
Yes
Evidence (1)

audit

one source

22 audit report; file v2/audits/spearbit/2023-09-22.pdf in aera-finance/aera-contracts-public (protocol audit catalog).

Auditor
22
Report date
2023-09
Scope
protocol
File
2023-09-22.pdf
Catalog only
Yes
Evidence (1)

audit

unverified

Gauntlet / Aera V3 contracts – competitive audit

Auditor
Cantina
Report date
2025-07-01
Scope
Aera V3 contracts – same vault system that powers Gauntlet’s yield vaults; details beyond Gauntlet’s own marketing summary are Not verifiable as of 2026-09-04.[1]
Findings
Gauntlet’s security page states that Cantina ran a competitive audit (community security competition) over Aera V3 contracts.[1] No independent Cantina report or findings breakdown for Gauntlet was found, so counts of critical/high/medium issues and details of uncovered vulnerabilities are Not verifiable as of 2026-09-04.[1]
Fix status
Public data does not show a remediation table or confirm which findings were fixed in deployed contracts on Arbitrum, Base, Ethereum, or OP Mainnet. Fix status and bytecode match are Not verifiable as of 2026-09-04.[1]
Evidence (1)

audit

one source

Cantina Competition — Aera V3 security report; report/completion date June 25, 2025. Scope: Aera V3 contracts. Findings: 1 high, 3 medium, 2 low, and 1 informational; all were acknowledged and none were marked fixed.

Covers deployed code: Not verifiable as of September 4, 2026; no bytecode-match evidence was available.

Auditor
Cantina Competition
Report date
2025-06-25
Scope
Aera V3 contracts
Findings
1 high, 3 medium, 2 low, 1 informational; no critical finding listed.
Fix status
0 fixed; 1 high, 3 medium, 2 low, and 1 informational acknowledged.
Evidence (1)

audit

one source

Corrected prior record: Spearbit’s Aera V3 security report is listed by Gauntlet with publication date May 6, 2025; Cantina records the engagement period as April 16–May 7, 2025. Scope: Aera V3 contracts. No critical finding is listed.

Findings: 1 high risk (fixed); 13 medium risk (12 fixed, 1 acknowledged); 22 low risk (14 fixed, 8 acknowledged); 30 informational (21 fixed, 9 acknowledged); 1 gas optimization (fixed). Fix status: High: fixed. Medium: 12 fixed, 1 acknowledged.

Low: 14 fixed, 8 acknowledged. Informational: 21 fixed, 9 acknowledged. Gas optimization: fixed.

Covers deployed code: Not verifiable as of September 6, 2026; the public evidence identifies the reviewed repository/engagement but does not establish a bytecode match for deployed contracts on Arbitrum, Base, Ethereum, or OP Mainnet.

Auditor
Spearbit
Report date
2025-05-06
Scope
Aera V3 contracts
Findings
No critical; 1 high fixed; 13 medium (12 fixed, 1 acknowledged); 22 low (14 fixed, 8 acknowledged); 30 informational (21 fixed, 9 acknowledged); 1 gas optimization fixed.
Fix status
High fixed; medium 12 fixed and 1 acknowledged; low 14 fixed and 8 acknowledged; informational 21 fixed and 9 acknowledged; gas optimization fixed.
Report url
https://cantina.xyz/portfolio/0dd974f2-aed8-4a06-a50e-881286e5d4bd
Report id
doc:d6d99df0f8bcbfdd
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

unverified

Bug bounty program for Gauntlet / Aera

Auditor
Immunefi
Report date
2025-08-01
Scope
Ongoing bug bounty over Aera/Gauntlet vault contracts; scope and reward structure rely solely on Gauntlet’s self‑description and are therefore unverified marketing claims.[1]
Findings
Gauntlet security documentation lists an ongoing Immunefi bug bounty for Aera/Gauntlet vaults.[1] No public Immunefi program page specific to Gauntlet was located in the retrieved data, and there is no disclosure of submitted or paid vulnerabilities, so bounty findings (if any) and their severities are Not verifiable as of 2026-09-04.[1]
Fix status
Whether reported bugs from Immunefi (if any) have been patched in live contracts, and on which chains, is Not verifiable as of 2026-09-04.[1]
Evidence (1)

audit

unverified

Gauntlet / Aera V3 contracts

Auditor
OpenZeppelin
Report date
2025-06-01
Scope
Aera V3 contracts – core vault and access-control logic, per Gauntlet’s security docs; this is an unverified marketing claim pending a primary report from OpenZeppelin.[1]
Findings
Gauntlet’s security documentation states that OpenZeppelin audited Aera V3 contracts (core vault and access-control logic).[1] No publicly accessible OpenZeppelin report specific to Gauntlet/Aera was located; number and severity of findings, and any chain‑specific coverage for Arbitrum, Base, Ethereum, or OP Mainnet, are Not verifiable as of 2026-09-04.[1]
Fix status
Without a public audit PDF or issue list, remediation status and whether deployed bytecode matches the audited version are Not verifiable as of 2026-09-04.[1]
Evidence (1)

audit

one source

Gauntlet / Aera V3 core contracts

Auditor
Spearbit
Report date
2022-05-16
Scope
Aera / Gauntlet vaults – Aera V3 core contracts (BaseVault, hooks, provisioner, guardian patterns) powering Gauntlet yield vault product.[1][12] Coverage of Arbitrum, Base, Ethereum, OP Mainnet deployments specifically is Not verifiable as of 2026-09-04.
Findings
Security review of Aera contracts (treasury re‑insurance, DeFi) for Gauntlet vaults. Audit timeline May 2–16, 2022. Methods: manual review.[12] Findings: 2 critical, 8 high, 8 medium, 9 low, 6 gas, 22 informational, total 55 issues.[12] Scope stated as Aera core contracts (vaults, hooks, provisioner, guardian patterns) that power Gauntlet vaults, but chain coverage (Ethereum / Arbitrum / Base / OP) and exact deployed addresses are not disclosed in the public summary, so bytecode match to current deployments is Not verifiable as of 2026-09-04.[1][12]
Fix status
Report text indicates issues were categorized but does not provide a public, issue‑by‑issue remediation matrix. Whether each critical/high/medium finding is fixed in currently deployed contracts, or which chains’ bytecode corresponds to the audited version, is Not verifiable as of 2026-09-04.[12]
Evidence (2)

audit

two sources

Gauntlet’s Aera Contracts audit (Project Name: Gauntlet; Repository: Aera Contracts; Commit: d48ddedf1dc70b9...) covered the treasury re-insurance / DeFi contracts reviewed between May 2 and May 16, 2022. The report records 55 issues total: 2 critical, 8 high, 8 medium, 9 low, 6 gas optimizations, and 22 informational. The report explicitly says the critical finding on overwritable Balancer fields had its recommendation implemented in PR #145, and other findings include high-severity sandwich-attack exposure in deposit/withdraw flows.

The PDF is the audit report itself; it is not enough to prove deployed-code bytecode matching, so coverage of deployed code is Not verifiable as of 2026-08-29.

Auditor
Spearbit
Report date
2022-10-16
Scope
Aera Contracts / treasury re-insurance, DeFi; review period May 2–16, 2022
Evidence (2)

audit

one source

Spearbit — Aera V2 security audit; report dated September 22, 2023. Scope: Aera V2 smart contracts. Critical/high/medium findings and remediation status: Not verifiable as of September 4, 2026.

Covers deployed code: Not verifiable as of September 4, 2026; no bytecode-match evidence was available.

Auditor
Spearbit
Report date
2023-09-22
Scope
Aera V2 smart contracts
Findings
Critical/high/medium findings: Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

audit

unverified

Gauntlet’s Aera documentation says Aera V3 core contracts powering Gauntlet vaults were reviewed by multiple independent firms, including Spearbit (June 2025) for BaseVault, hooks, provisioner, and guardian patterns; OpenZeppelin for core vault and access control logic; Cantina via competitive audit; and Immunefi for an ongoing bug bounty. The doc is a protocol-maintained summary and does not itself provide detailed finding counts or bytecode-match evidence for deployed contracts, so those are Not verifiable as of 2026-08-29.

Auditor
Spearbit
Report date
2025-06
Scope
Aera V3 core contracts: BaseVault, hooks, provisioner, guardian patterns
Evidence (1)

audit

one source

Spearbit — Aera V3 Provisioner Upgrade report; dated April 15, 2026. Scope: V3 Provisioner upgrade. Critical/high/medium findings and remediation status: Not verifiable as of September 4, 2026.

Covers deployed code: Not verifiable as of September 4, 2026; no bytecode-match evidence was available.

Auditor
Spearbit
Report date
2026-04-15
Scope
Aera V3 Provisioner upgrade
Findings
Critical/high/medium findings: Not verifiable as of September 4, 2026.
Fix status
Not verifiable as of September 4, 2026.
Evidence (1)

Team & Reputation

founders

two sources

Gauntlet is a real, onshore, New York–based DeFi risk firm, not an anon yield protocol, with a visible executive team and venture-backed corporate footprint. Founders & key team

  • Founder & CEO: Tarun Chitra, ex-quant researcher at D.E. Shaw Research and Vatic Labs; widely profiled as a leading DeFi risk expert and frequent conference speaker.
  • Co‑founders: Rei Chiang (CTO) and John Morrow (COO), both with prior high‑frequency trading and Uber/tech experience.
  • Public team pages and third‑party profiles list a broad senior staff (CFO, General Counsel, DeFi Lead, Head of Structured Yield, etc.), indicating a mid‑size firm (~50–75 employees). Prior projects / track record
  • Gauntlet is known as a risk modeling and optimization provider to major DeFi protocols, with claims (via independent project reviews) of models supporting a large share of DeFi TVL and published research (>40 papers, ~1,000 citations).
  • The founders’ prior work is in traditional quant trading and simulation; no major founder‑linked protocol hacks or blow‑ups are reported in mainstream crypto profiles as of available data.
  • They have raised multiple funding rounds, with at least ~$28m disclosed and a reported unicorn valuation, consistent with institutional investor diligence. Public vs. anon; credibility
  • Founders and executives are fully public with LinkedIn profiles, conference appearances (Consensus, Solana Breakpoint, etc.), and detailed bios on hiring platforms and company materials.
  • Multiple independent profiles (PitchBook, CB Insights, Coinpedia, CoinCarp, IQ.wiki) corroborate the same founding story, date (2018), and leadership, suggesting a high‑credibility, doxxed team rather than pseudonymous operators. Legal entity, office, onshore/offshore
  • Third‑party company databases and job boards list headquarters in New York City, with specific street addresses in Tribeca / Vestry Street and another corporate address in Brooklyn.
  • The firm is described as US‑based, Series B, remote‑first with a New York home base, implying incorporation in the US and operation under US jurisdiction.
  • No evidence of offshore shell jurisdiction or PO‑box‑only presence is visible in the profiles reviewed. Reality check for a DeFi risk lens
  • Gauntlet looks like a traditional venture‑backed quant/R&D company that has expanded into curated yield vaults, not a fly‑by‑night yield protocol.
  • However, without direct on‑chain inspection of their vault contracts on Arbitrum/Base/Ethereum/OP, specific exposure, TVL, and incident history are Not verifiable as of 2026‑09‑04.
  • Any performance or safety claims coming only from Gauntlet’s own marketing pages should be treated as unverified marketing claims unless cross‑checked against independent protocol‑level data.
Evidence (15)

general reputation

one source

Gauntlet is primarily known as a risk management and simulation firm in DeFi (especially for Aave, dYdX, MakerDAO, Uniswap), not as a standalone yield protocol with user deposits. Its reputation is generally strong but not controversy‑free. Founders & investors

  • Founded by Tarun Chitra, ex‑D. E. Shaw and Cornell‑trained computer scientist, widely cited in DeFi research and conference circuits.
  • Gauntlet raised venture funding (e.g., Paradigm‑led round announced in 2022) and is backed by major crypto VCs, signaling institutional confidence. Role in DeFi & audits
  • Gauntlet is usually hired as risk consultant/parameter optimizer by protocols like Aave, Compound, dYdX, Uniswap, MakerDAO, and others.
  • It does not function as a traditional TVL‑holding protocol on Arbitrum/Base/Ethereum/OP in the same way as lending/AMM platforms; instead, its work affects risk parameters, incentives, and simulations used by those protocols.
  • As a service provider, Gauntlet itself is not typically “audited” like a smart‑contract protocol; rather, its models and recommendations are scrutinized in governance forums. Sentiment & criticisms
  • Many governance posts show positive sentiment about Gauntlet’s quantitative rigor and long‑term contributions, particularly for Aave and dYdX.
  • Key criticisms:
  • Opacity of models: Some Aave and Uniswap community members complain that Gauntlet’s risk models and assumptions are not fully transparent or easily reproducible.
  • Cost vs value: There have been debates about the size of Gauntlet’s compensation relative to perceived benefits, leading to tense renegotiations or non‑renewals of contracts in some DAOs.
  • Conservative parameter choices: Traders/liquidators sometimes argue Gauntlet’s recommendations are overly conservative, limiting capital efficiency. Controversies, fraud/rug/insolvency allegations
  • As of 2026‑09‑05, there are no credible fraud, rug‑pull, or insolvency allegations against Gauntlet or its founder in major crypto media, governance records, or regulator databases.
  • No reports of user fund losses attributable to Gauntlet‑controlled contracts, since Gauntlet mainly advises rather than custodying funds. Legal / regulatory / sanctions
  • No evidence of sanctions, enforcement actions, or lawsuits specifically targeting Gauntlet or Tarun Chitra in U.S. or major jurisdictions, as of 2026‑09‑05. Unresolved concerns
  • Ongoing community discussion about:
  • Model transparency and auditability.
  • Potential conflicts of interest when a single risk vendor advises multiple large protocols.
  • Vendor dependency: DAOs’ reliance on Gauntlet for critical risk decisions. Overall, Gauntlet’s reputation is technically respected but politically debated in DAO governance, with no major legal or fraud red flags identified as of 2026‑09‑05.
Evidence (3)

Economy

TVL: $1.6B

model

one source

Assessment (as of September 5, 2026): Previous findings are materially outdated. Gauntlet is now both a risk curator and operator of non-custodial yield vaults; the prior “no native yield product/TVL/APY” conclusion is contradicted by current vault documentation and DeFiLlama data. Strategy/assets/yield: Users deposit stablecoins or selected RWA/crypto assets and receive vault shares. Core strategies allocate across Morpho lending markets and other DeFi venues; yield is primarily borrower-paid lending interest, with some incentive rewards converted/reinvested.

Gauntlet also documents levered RWA loops: collateral is supplied, stablecoins are borrowed, and additional RWA exposure is purchased. This is directional collateral exposure, not market-neutral. External exposure includes Morpho, underlying borrowers, oracles, adapters, stablecoin depegs, liquidity, and—where applicable—perpetual strategies. Organic vs subsidized: Lending interest is organic protocol yield; rewards/incentives are subsidized.

The organic percentage cannot be reliably decomposed across all Gauntlet products: Not verifiable as of September 5, 2026. APY is variable and not guaranteed. DeFiLlama reports four tracked pools with average supply APY of 4.93%; historical APY volatility by product is Not verifiable as of September 5, 2026. Withdrawals, locks, controls: Deposits and withdrawals are non-custodial. gtUSDa documentation states typical processing of 6–12 hours; other Morpho vaults may be liquidity-constrained.

Vaults can impose supply caps, withdrawal gates, timelocks, and curator-controlled fees. Performance fees are documented in the 0–20% range, varying by vault. TVL / chains: DeFiLlama reports $1.486B total TVL across 13 chains, not only the four requested: Base $533.57M, Ethereum $340.59M, Arbitrum $2.15M, OP Mainnet $1.05M—approximately $877.36M or 59.0% combined. Dune comparison: Not verifiable as of September 5, 2026 (Dune unavailable).

DeFiLlama reports +5.6% 30-day TVL growth. Revenue: DeFiLlama reports $3.24M fees and $34,208 protocol revenue over 30 days; annualized figures are $32.23M and $801,443 respectively. Revenue is primarily curator/performance-fee capture from vault yield.

Evidence (5)

reserves

unverified

As of September 5, 2026, no distinct Gauntlet-owned corporate treasury/reserve, reserve wallet, reserve-size disclosure, liabilities schedule, reserve policy, or reserve attestation was verified. Dune/on-chain verification was unavailable in this run; therefore balances, composition, and chain-level exposure percentages are Not verifiable as of September 5, 2026. Gauntlet describes itself as a risk manager and curator of self-custodial vault strategies.

Its disclosed figures—$1.7B+ allocated to vaults and $42B+ of client assets monitored/protected—are client or strategy assets, not evidence of Gauntlet-owned reserves. Vault documentation states that products are non-custodial and assets are not guaranteed by Gauntlet. Several contract addresses are publicly documented for Gauntlet-branded vaults and provisioners on Base, Ethereum, Arbitrum, and OP Mainnet.

These are operational vault/provisioner contracts, not identified treasury addresses; ownership, custody, balances, and liabilities attributable to Gauntlet are Not verifiable as of September 5, 2026. The $42.87M reserve-pool figure in the Compound forum is Compound’s protocol reserve, discussed in Gauntlet’s parameter recommendations; it is not Gauntlet’s treasury. Assessment: no verified Gauntlet corporate reserve asset or liability base; custody appears non-custodial at the vault-user level, while Gauntlet’s strategy-control and fee/economic-interest arrangements are not sufficiently disclosed to establish a treasury claim.

Evidence (5)

tokenomics

two sources

Gauntlet does not appear to have a standalone native token for the risk-management protocol itself. The only clearly evidenced tokenized products in the sources are yield-bearing vault shares such as gtUSDC, gtUSDTB, and gtUSDa, which are described as non-custodial vault interest/share tokens rather than protocol governance tokens. Because no primary or independent source in this run verified a protocol-native token, the following items are Not verifiable as of 2026-09-04: native token name/ticker and contract address; total vs circulating supply; market cap and FDV; token utility and governance role; revenue share, buybacks, burns, staking rewards; emissions schedule; unlock schedule and whether announced unlocks happened on-chain; allocations to team/investors/treasury/community; top-holder concentration and insider wallets; mint/blacklist/fee-switch functions and who controls them; DEX liquidity depth and main listings.

The available evidence instead points to Gauntlet being an institutional DeFi risk/curation business whose products are vault shares on chains such as Base, Ethereum, and Arbitrum, with value accruing through share-price/NAV mechanics rather than a conventional emissions-driven token model. If you need a precise tokenomics memo, the current evidence base is insufficient to support one without on-chain verification.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Gauntlet’s published methodology indicates it stress-tests DeFi protocols with agent-based simulations under catastrophic market scenarios, including sharp price crashes and cascading liquidations, and it evaluates outcomes such as expected insolvencies and liquidations rather than giving a single universal “BTC below $10,000” result. For the specific query—Bitcoin falling below $10,000 across Arbitrum, Base, Ethereum, and OP Mainnet—there is no protocol-specific stress result in the provided sources that can be verified for Gauntlet’s current vaults or parameter sets, so the impact is Not verifiable as of 2026-09-04. What can be stated from the sources is limited to framework-level risk handling: Gauntlet models extreme downward price movement, low liquidity, and liquidation cascades; its vault documentation says blue-chip collateral such as BTC wrappers and ETH derivatives is used in lower-risk vaults; and Gauntlet reports zero bad debt in certain stress windows, but those reports are event-specific and do not quantify a BTC < $10,000 scenario.

Because the provided results do not include chain-by-chain exposures, TVL, or vault inventories for Arbitrum, Base, Ethereum, or OP Mainnet, the cross-chain exposure split is also Not verifiable as of 2026-09-04.

Evidence (7)

stress scenario - largest collateral depegs 20%,

unverified

Not verifiable as of 2026-09-04. The provided sources do not include a protocol-specific stress result for Gauntlet under a scenario where the largest collateral depegs 20% across Arbitrum, Base, Ethereum, and OP Mainnet. Gauntlet’s public materials confirm that it models spot shocks, drawdowns, and depeg behavior in general, but they do not publish the requested cross-chain stress output or the underlying portfolio composition needed to compute it reliably from the web results alone. What can be stated from the available sources is that Gauntlet uses agent-based simulations and depeg-aware risk controls, including deallocating from USDC-based markets during depeg events and halting new borrowing until stabilization.

However, none of the retrieved sources quantify the effect of a 20% depeg in the largest collateral asset for this specific protocol deployment or provide chain-by-chain exposure percentages. Because on-chain verification tools are unavailable in this run, the required exposure and liquidation impact cannot be independently checked against raw chain data. The correct output for the requested stress scenario is therefore: Not verifiable as of 2026-09-04.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Gauntlet is not a yield protocol or counterparty, but a risk-parameter and simulation service used by protocols like Aave, Compound and others. It does not custody user assets or run its own lending pools, so there is no direct counterparty exposure to Gauntlet smart contracts in the sense of an insolvent borrower. Because Dune/on-chain is unavailable, all on-chain verification is: Not verifiable as of 2026-09-04. ### 1.

Role of Gauntlet in counterparty stress Gauntlet typically:

  • Runs stress tests and simulations on lending/AMM protocols (e.g., Aave) to calibrate risk parameters such as LTV, liquidation thresholds and reserve factors.
  • Provides recommendations via governance, which are then implemented by the underlying protocol. In a top borrower / counterparty insolvency scenario on a protocol using Gauntlet:
  • The insolvent counterparty is a user of Aave/Compound/etc., not Gauntlet.
  • Gauntlet’s models may have influenced:
  • Collateral factors (how much that counterparty could borrow)
  • Liquidation incentives and buffers
  • Interest rate curves and risk fees ### 2. Expected loss path (generic Gauntlet-integrated lending protocol)
  • Large borrower becomes under‑collateralized due to price move.
  • Liquidation bots/liquidators buy collateral at a discount, repaying debt.
  • If liquidations are insufficient and there is a shortfall, the protocol’s safety module / backstop / insurance fund absorbs loss (e.g., Aave Safety Module, Compound reserves). Who absorbs it:
  • First: liquidators (take market risk in closing positions).
  • Second: protocol reserves/insurance pools, funded by ongoing protocol fees.
  • Third: in extreme cases, token holders via mechanisms like recapitalization or governance-approved socialized loss. Compensation mechanics:
  • Liquidators receive a liquidation bonus on collateral.
  • Insurance/safety-module stakers receive yield for bearing tail risk; they may suffer losses when the module is used to cover insolvency. ### 3. Impact path through smart contracts (generic)
  • Insolvency triggers:
  • Price oracle update → health factor < 1 → liquidation function.
  • If bad debt remains, protocol may:
  • Draw from insurance module contracts.
  • Adjust interest rates or freeze markets via governance calls. Gauntlet’s impact is parameter-level only: it changes how quickly health factors breach and how much buffer/bonus exists; it does not route funds or define who legally absorbs losses. Given Gauntlet is a cross-protocol risk service, per‑chain TVL/exposure for “Gauntlet” contracts themselves is Not verifiable as of 2026-09-04 and likely economically immaterial versus the integrated protocols’ TVL.
Evidence (4)

stress scenario - committed fraud by the DAO or owners

unverified

For the “committed fraud by the DAO or owners” stress scenario, I found no verifiable evidence that Gauntlet DAO or its owners committed fraud. The available results are insufficient and mostly unrelated or promotional, so this scenario should be treated as Not verifiable as of 2026-09-04. The only directly relevant result is Gauntlet’s bug bounty announcement, which indicates a security reporting channel but does not evidence fraud.

The other results are about unrelated “Gauntlet” references or general DeFi/governance-attack examples and do not establish misconduct by this protocol.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

Gauntlet’s *primary yield source* is not verifiable as a negative 30d figure from the provided sources. The available materials say Gauntlet vault returns generally come from borrower interest, and some vaults may also earn rewards or points, but none of the supplied sources provides a 30-day negative yield measurement for Gauntlet itself across Arbitrum, Base, Ethereum, or OP Mainnet. What *is* supported is that Gauntlet’s yield products are marketed as risk-managed lending vaults whose APY can vary materially with supply/demand and market stress.

For example, Gauntlet states that APY can drop sharply when supply expands without matching borrow demand, and then recover as new collateral markets and borrowing demand develop. The sources also indicate that Gauntlet’s vaults on Morpho are deployed across multiple chains, including Ethereum mainnet and Base, with the broader USD Alpha strategy extending to Arbitrum and Optimism, but they do not break out 30d performance by chain in the provided results. So, for a stress scenario assessment, the correct conclusion from these results is: negative 30d primary yield is not verifiable as of 2026-09-04.

The chain-level exposure split and any 30-day negative yield claim would require chain-specific performance data that is not present here.

Evidence (5)

Governance & Legal

governance

two sources

Assessment — as of September 13, 2026. Gauntlet appears company-controlled rather than DAO-governed. Its Terms identify Gauntlet Networks, Inc. as the provider and state that Gauntlet owns the Products and their contents, may modify or remove Products without notice, and may suspend or terminate access at its sole discretion. The Terms also permit Gauntlet to modify the agreement unilaterally and use Delaware law/arbitration. Control surface. Frontend, product availability, IP, and contractual terms are controlled by Gauntlet Networks, Inc.

The site describes Gauntlet as a risk-management and self-custodial-vault business, not as a token-holder DAO. Its TVL and client-assets figures are unverified marketing claims. No public DAO constitution, token-voting process, or governance forum demonstrating token-holder control was identified.

Therefore, DAO governance is assessed as false, not merely symbolic. Proposal process. No company-wide public governance proposal process was verified. Product/service changes appear governed by company discretion and client-specific proposals. Morpho vaults use Owner, Curator, Allocator, and Sentinel roles; the Owner can appoint key roles, while Curator actions may be timelocked depending on vault configuration.

These are vault-level controls, not Gauntlet DAO governance. On-chain controls. Dune was unavailable in this run. Contract ownership, upgrade authority, treasury custody, emergency keys, voting concentration, top holders, multisig signers/threshold, timelock duration, and whether any administrator can directly drain user funds: Not verifiable as of September 13, 2026. The Terms’ reference to Gauntlet serving as a customer’s multisig user does not establish control of Gauntlet’s own funds or vault contracts. Company details. Gauntlet Networks, Inc. is a Delaware corporation, entity ID 6923803, created June 18, 2018; the LEI record lists active status but a lapsed LEI registration.

SEC Form D identifies Tarun Chitra as executive officer/director and Rei Chiang as executive officer; this is historical disclosure, not confirmation of current directors.

Dao governance
No
Evidence (5)

legal & regulatory

one source

Gauntlet is subject to active SEC enforcement: the SEC filed charges in March 2025 against Gauntlet Holdings, LLC and its managing member in federal court in California, and a July 2026 release says the court entered final judgments imposing injunctions, disgorgement, and civil penalties. The entity and jurisdiction that are directly identifiable from those records are Gauntlet Holdings, LLC in California, United States; however, the protocol’s exact operating entity for the DeFi product is not fully verifiable from the available sources. Gauntlet’s own Terms of Service state that some products may be unavailable or inappropriate in a user’s jurisdiction, which indicates geo-restrictions, but the specific restricted jurisdictions are not disclosed in the source we found.

I found no verifiable public source in this pass showing protocol-level KYC/AML requirements for the DeFi protocol itself, no confirmed sanctions designation of the protocol or entity, and no verified court case specifically about the DeFi protocol rather than the named Gauntlet Holdings defendants. Data-protection information is available only for Gauntlet’s privacy notice, which describes collection and use of personal information and cites California privacy rights, but it does not by itself establish the protocol’s legal structure or regulatory classification. Overall legal risk is elevated because there is confirmed U.S.

SEC enforcement against a Gauntlet entity and open-ended jurisdictional restrictions in the terms, while the on-chain/protocol-side compliance posture remains not verifiable as of 2026-09-04.

Active enforcement
Yes
Sanctioned
No
Entity
Gauntlet Holdings, LLC (identified in SEC action); exact DeFi operating entity not fully verifiable
Jurisdiction
United States (California federal action); exact protocol jurisdiction not fully verifiable
Evidence (4)

legal registries

two sources

GLEIF LEI registry unavailable at scan time. OFAC SDN screening of 'Gauntlet Holdings LLC', 'Gauntlet': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Gauntlet Holdings LLC
  • Gauntlet
Entity
GAUNTLET HOLDINGS LLC
LEI
894500AUXJN1YTQD8U95
Jurisdiction
US-DE
Entity status
ACTIVE
Sanctioned
No
Evidence (3)

Stability

stability

one source

Gauntlet does not appear to issue its own stablecoin, so the stablecoin depeg question is not directly measurable for a Gauntlet-native token. The only clearly documented depeg-related event connected to Gauntlet is its 2023 recommendation to deprecate MAI on Aave after MAI fell to about $0.72; that indicates one external stablecoin depeg event, but it is not a Gauntlet-issued stablecoin depeg. As a result, the protocol should be treated as not having a verified native stablecoin history, and the depeg statistics for a protocol-issued stablecoin are not verifiable as of 2026-09-06.

Own stablecoin
No
Stable
No
Depeg count
1
Max depeg pct
28%
Last depeg date
2023-10-14
Stablecoin ids
  • MAI
Evidence (3)

Risks & Strengths

risks

one source

Gauntlet is a multi-chain yield-vault manager whose primary risks arise from delegated strategy execution, external lending/vault dependencies, stablecoin composition, and liquidity under stress. Exact exposure, TVL concentration, and chain-by-chain percentages are Not verifiable as of September 5, 2026 because Dune on-chain verification was unavailable; therefore, no exposure figures are inferred.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Underlying protocol failureGauntlet allocates through Morpho, Aera adapters, vaults, and other DeFi integrations. A bug, insolvency, oracle failure, or adverse parameter change in an underlying venue can transmit losses to depositors.HighMediumCurated market selection, exposure caps, liquidity monitoring, approved-contract whitelists, hooks, audits, and active monitoring.Material correlated-loss risk remains because controls cannot protect against a compromised external protocol.
Stablecoin depeg and contagionThe strategy can hold multiple risk-on and blue-chip stablecoins; depegs, redemption freezes, or collateral contagion can impair NAV and exits.HighMediumA hard cap limits non-blue-chip stablecoin exposure to 40%, with liquidity and collateral monitoring.USDC and other blue-chip stablecoins retain issuer, reserve, banking, and market-liquidity risk.
Redemption and liquidity stressWithdrawals may be delayed by utilization spikes, solver capacity, bridge delays, paused vaults, or insufficient DEX liquidity; forced exits may incur slippage.HighMediumPosition sizing uses real-time vault/DEX liquidity, and Aera supports pausing, withdrawal controls, and solver-based settlement.Liquidity protections are dynamic and may fail during simultaneous withdrawals or market dislocation.
Privileged execution and oracle errorsGuardians, accountants, solvers, owners, and off-chain services influence operations, pricing, and settlement. Malicious action, collusion, bad data, or operational failure could cause value leakage or incorrect NAV.HighMediumRole separation, owner-approved hooks, Merkle/whitelist restrictions, timelocks, independent pricing bounds, pause authority, and guardian removal.Human, key-management, ETL, and governance failures remain trust assumptions.
Cross-chain and MEV executionDeployments across Ethereum, Arbitrum, Base, and OP Mainnet add bridge, message, liquidity, and chain-specific oracle risk; AMM rebalances can be front-run or sandwiched.MediumMediumPer-trade and daily slippage limits, approved routes/contracts, liquidity-aware sizing, and operation hooks.Bridge outages, sequencer/network incidents, and MEV cannot be fully eliminated; chain-by-chain exposure is Not verifiable as of September 5, 2026.
Evidence (4)

strengths

two sources

Gauntlet’s top strengths are: simulation-driven risk modeling, capital efficiency optimization, institutional credibility, continuous monitoring and rebalancing, and multi-chain / multi-protocol reach. Multiple sources describe Gauntlet as using agent-based simulations and quantitative research to stress-test DeFi systems and calibrate parameters, which is its core differentiator. Its work is explicitly framed around balancing risk with better capital efficiency and protocol performance, including optimizing parameters for safer returns.

Gauntlet’s credibility is reinforced by its long-running work with major DeFi protocols such as Aave, Compound, Maker, and Uniswap, which indicates that large protocols have trusted its modeling in production settings. Its vault and strategy products are described as continuously rebalancing and monitoring markets rather than relying on one-time analysis, which supports resilience in changing conditions. Finally, its products are positioned across multiple chains and markets, including Arbitrum, Base, Ethereum, and OP Mainnet, showing breadth of deployment rather than a single-chain focus.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 11 two independent sources, 19 one source, 11 unverified.
  • Oldest fact verification date: 2026-08-29.