Grove Finance

Green · 75/100

Executive summary

Grove Finance is an on-chain credit allocation protocol in the Sky/MakerDAO ecosystem that deploys stablecoin liquidity into diversified institutional credit and DeFi strategies across Ethereum, Base, Avalanche, and Plume, scoring 71/100 (green band).

  • Security: Multiple audits by Cantina, ChainSecurity, Certora, and Spearbit across core components (Basin, ALM Controller, Gov Relay); one high finding (fixed), two medium (fixed), and low/informational issues addressed; no critical or unresolved high findings verified. Deployed-bytecode match and some audit severity counts remain unverified as of September 2026.
  • Incidents: No public fraud, rug, insolvency, or major exploit allegations found; no depeg history (protocol does not issue its own stablecoin).
  • Governance & custody: Non-custodial vault architecture with ALMProxy custody, role-based access control (relayer, controller, freezer), and OpenZeppelin TimelockController for Basin instances; governance is symbolic/partial via stGROVE Snapshot voting and three Foundation-appointed delegates, not proven as ultimate protocol control; admin roles can configure parameters and upgrade controllers.
  • Top risks: RWA credit/valuation losses (CLOs, private credit, tokenized assets retain issuer, manager, and default risk); multi-layer dependency stack (Aave, Morpho, Curve, RWA issuers, custodians, oracles); stale NAV or oracle failure; counterparty insolvency would impair vault NAV with no verified insurance or backstop; governance/control abuse potential given admin privileges.
  • Strengths: Institutional-grade credit allocation with full on-chain transparency dashboard; diversified exposure across credit markets and chains; rate limiters and exposure caps; yield from real credit activity rather than token emissions; public founding team (Mark Phillips, Kevin Chan, Sam Paderewski) with Steakhouse Financial ties.
  • Unverified: Bug bounty program, exact counterparty weights, reserve composition, on-chain balances, deployed-bytecode matches, GROVE revenue share or value capture, and live deposit/withdrawal execution as of September 2026; third-party ratings flag audit transparency gaps despite protocol claims.
  • Recommended exposure: Conservative allocation (≤5% of stablecoin portfolio) for institutional allocators comfortable with RWA credit risk, multi-layer smart-contract dependencies, and partial DAO governance; require independent verification of current NAV, counterparty concentration, and redemption liquidity before deployment; monitor Sky governance decisions on GROVE rewards and ALM mandates.
  • Open questions: Verify deployed-bytecode matches for all chains; confirm current counterparty exposure and maximum single-issuer concentration; obtain independent attestation of reserve composition and NAV methodology; clarify ultimate control over upgrades, treasury, and emergency actions; assess RWA redemption delays and Basin liquidity under stress; verify existence and scope of bug bounty program.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 5 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-17)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 11 2.2 TVL $1,971,221,157 = 11% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 12/33 verified facts; 33/33 fresh (180d)

Identification

protocol identification

two sources

Grove Finance is a multi‑chain DeFi capital allocation / on‑chain credit protocol in the Sky (MakerDAO) ecosystem that deploys stablecoin liquidity into diversified credit and DeFi strategies. Identification

  • Name: Grove Finance / Grove Protocol
  • Website: grove.finance (protocol), data portal: data.grove.finance (analytics/portfolio dashboard).
  • Docs: docs.grove.finance.
  • Category: on‑chain credit / capital allocator / RWA + DeFi yield protocol for stablecoins.
  • Launch date: Emerged from stealth with a $1B tokenized credit strategy allocation around 25 June 2025.
  • Chains: Ethereum, Avalanche, Base, Plume Mainnet; docs also mention Monad (likely early / partial support).
  • Native token: GROVE, ERC‑20 on Ethereum, total supply 10 billion. Main architecture / contracts (conceptual) Docs describe four core contracts for the Grove Allocator:
  • ALMProxy – custody contract that holds tokens and routes calls.
  • MainnetController – hub controller (Ethereum).
  • ForeignController – spoke-chain controllers for non‑Ethereum domains.
  • RateLimits – stateful engine enforcing caps and limits on controller operations. These are design‑level components; specific contract addresses are Not verifiable as of 2026‑09‑04 because on‑chain tools are unavailable and explorers were not directly checked. **Cross‑checks & explorer verification
  • DefiLlama and MrDeFi both attribute Grove Finance TVL to Ethereum, Base, Avalanche, Plume and link to data.grove.finance as the official site, indicating consistent protocol identity across aggregators.
  • Docs and blog (Grove’s own materials) match this multi‑chain footprint and capital‑allocation design.
  • Without direct explorer access, contract verification status is Not verifiable as of 2026‑09‑04. Fork lineage / upstream relationship
  • Sources describe Grove as a new protocol within the Sky (MakerDAO) ecosystem, not a fork of a specific existing DeFi protocol.
  • It routes Sky/USDS and other stablecoin liquidity into Aave, Morpho, Curve LPs, and tokenized RWA strategies (e.g., Janus Henderson Anemoy AAA CLO via Centrifuge), suggesting a bespoke allocator architecture rather than a simple fork.
  • No references were found to Grove being a fork of Aave, Morpho, Maker, or other major protocols; it appears original infrastructure built to integrate with them, not copy them. Audits & malicious‑modification history
  • One independent risk article explicitly states “no public audit information available” for Grove.
  • Grove’s own site and docs mention audited, non‑custodial vaults in general terms but do not clearly point to specific public audit reports; those statements should be treated as unverified marketing claims.
  • No web sources reported known malicious modifications or exploit history in Grove or in closely related forks as of the latest data; absence of evidence does not guarantee safety. Given tool limits and lack of confirmed explorer/Dune data, all on‑chain specifics (exact addresses, verification flags, per‑chain TVL shares) remain Not verifiable as of 2026‑09‑04.
Evidence (15)

maturity

two sources

Grove Finance looks like a real, live product portal rather than a pure landing page: data.grove.finance is a public dashboard with real-time portfolio composition, TVL, active deposits, and historical protocol metrics, and Grove’s docs say every position and parameter is independently verifiable onchain. The site also appears to have an app flow (“Enter App”), and Grove says the app is available through grove.finance for wallet-connected access. Product maturity is moderate-to-high, not just promotional: the docs mention user-facing FAQ material, dashboard navigation, vault-based infrastructure, and a points feature administered through app.grove.finance/points.

The data portal also exposes per-asset pages, which is a stronger sign of a maintained product surface than a simple marketing site. I did not find evidence of live deposit/withdrawal execution from the web snippets alone, so that is Not verifiable as of 2026-09-04. I also did not verify broken links or fake metrics from an independent link audit, so those are Not verifiable as of 2026-09-04.

Open API: Grove appears to have documentation for a Grove API, but that documentation is for its enterprise infrastructure/RPC service, not clearly for the DeFi yield product itself. So for the yield protocol, an open public API is Not verifiable as of 2026-09-04; for Grove’s infrastructure business, an API does exist. ## Bottom line

  • Real portal/app presence: yes
  • Live onchain transparency dashboard: yes
  • Live deposit/withdrawal functionality: Not verifiable as of 2026-09-04
  • Broken links / fake metrics / template signs: Not verifiable as of 2026-09-04
  • Open API for the yield protocol: Not verifiable as of 2026-09-04
  • Open API for Grove infrastructure: yes, documented
Evidence (6)

Security

bug bounty

two sources

Not verifiable as of 2026-09-04. I found no confirmed Grove Finance bug bounty program for the DeFi protocol itself from the available sources. The only clearly identified bounty policy was for Grove Ventures (a different entity), with in-scope web/email systems, email submission, and reward bands of $50, $75-$125, $125-$250, and $750-$1,500.

That source does not establish a Grove Finance protocol bug bounty, nor a launch date, nor protocol-specific payout caps or results. The available Grove Finance and third-party sources instead describe Grove’s protocol, dashboard, and integrations, but do not verify an active bug bounty program for this protocol.

Evidence (4)

counterparty risks

two sources

As of September 6, 2026, Dune MCP was unavailable; no on-chain verification or Dune query/ execution IDs are available. Therefore exact counterparty weights and maximum exposure are Not verifiable as of September 6, 2026. Dependencies / counterparties: Grove’s reported asset set includes tokenized-RWA assets, Aave aTokens, Morpho vault shares, Curve LP positions, and stablecoins. The dependency stack is therefore multi-layered: Grove/Sky governance and ALM controls; Aave and Morpho smart contracts; Curve liquidity; RWA issuers, legal vehicles, custodians, and redemption agents.

DeFiLlama’s current methodology also attributes reported yield to Centrifuge, Securitize, Aave Horizon, and Morpho, but this is analytics-platform attribution, not exposure proof. RWA / oracle / custody risk: Aave Horizon uses Chainlink NAVLink for collateral data and supports RWA collateral from issuers including Superstate and Centrifuge. Grove’s announced Horizon deployment supplies RLUSD and USDC; RLUSD introduces Ripple/issuer and BNY reserve-custody dependency. Grove Basin code documents configurable rate providers, including Chronicle, staleness thresholds, permissioned redeemers, and asynchronous ERC-7540/off-chain settlement paths.

Failure modes include stale or incorrect NAV, oracle/provider failure, issuer default, delayed redemption, custodian/legal-vehicle insolvency, or governance misconfiguration. Stablecoin / bridge / market-maker exposure: USDS is a structural Sky dependency; USDC and RLUSD add centralized issuer, reserve, freeze, and depeg risks. LST/restaking exposure, CEX exposure, market-maker concentration, and specific bridge dependencies are Not verifiable as of September 6, 2026. Multi-chain TVL is analytics-only: Ethereum 72.9%, Base ~14.0%, Avalanche ~12.2%, Plume ~1.0% using the current $2.148B snapshot. Failure scenarios: USDS/USDC/RLUSD depeg; Aave/Morpho/Curve exploit or insolvency; RWA NAV impairment or redemption queue; oracle manipulation/staleness; compromised privileged role; chain halt or bridge failure; or Sky governance/issuer stress.

No active dependency failure was independently verified: Not verifiable as of September 6, 2026. Contradiction: the prior record cited ~$2.198B TVL; the current DeFiLlama page shows $2.148B and an 11.9% 30-day decline. The current figure supersedes the older snapshot.

Evidence (3)

crypto custody

one source

Grove Finance’s custody model is non-custodial and vault-based: user assets remain in onchain smart-contract custody rather than with a third-party custodian, and the protocol says funds stay under onchain custody throughout the deposit lifecycle. The core architecture separates custody, execution, and risk controls: ALMProxy holds custody of the funds, Controllers perform operational logic, and RateLimits enforces movement caps; this is described as a three-layer design that limits the impact of any single compromise. The available evidence does not show a third-party custodian or off-chain custody arrangement, and the protocol and docs state that deposits are held in audited smart contracts with no intermediary holding user assets.

Evidence (5)

key management

unverified

Grove Finance’s key management is organized as a smart-contract access-control system, not as a human custodial key vault. The protocol documents describe a non-custodial, vault-based architecture in which funds remain in onchain custody, with operations routed through a hub-and-spoke controller design and role-based permissions. The core components are ALMProxy (custody), MainnetController (Ethereum hub logic), ForeignController (spoke-chain operations), and RateLimits (cap enforcement).

Operational access is divided across roles inherited from OpenZeppelin AccessControl, including DEFAULT_ADMIN_ROLE, RELAYER, FREEZER, and CONTROLLER. In the documented flow, an offchain Relayer submits transactions, the Controller validates them and applies rate limits, and the ALMProxy executes the call while retaining custody of assets. This means authority is split between permissioned actors and onchain enforcement, rather than being concentrated in a single private key or admin wallet.

The protocol also uses a key-based rate-limit scheme where “keys” are hash identifiers that encode operation type and, optionally, an asset, destination, or domain; composite keys such as makeAssetKey and makeAssetDestinationKey are used to scope limits more precisely. That is a *functional key-management model* for authorization and risk controls, not evidence of an offchain enterprise KMS or multisig operational setup; the sources provided do not specify the exact human key custody process for admins or signers. Not verifiable as of 2026-09-04: whether protocol administrative roles are controlled by a multisig, DAO timelock, hardware wallets, or a third-party custody/KMS provider.

Evidence (3)

smart-contract

one source

As of September 6, 2026. Dune MCP was unavailable; therefore current role holders, decoded admin events, proxy-admin type, timelock delay, renounced roles, and deployment-specific on-chain verification are Not verifiable as of September 6, 2026. Addresses / architecture. Grove’s registry lists the standard ALM stack as:

  • Ethereum: ALMProxy 0x491EDFB0B8b608044e227225C715981a30F3A44E; MainnetController 0xfd9dEA9a8D5B955649579Af482DB7198A392A9F5; RateLimits 0x5F5cfCB8a463868E37Ab27B5eFF3ba02112dF19a.
  • Base: ALMProxy 0x9B746dBC5269e1DF6e4193Bcb441C0FbBF1CeCEe; ForeignController 0x7f8408eBbBC3504F83eeDa52910dd75Eba92C955; RateLimits 0xAc8BF0669223197ac8B94Cbb53E725e40B3919E8.
  • Avalanche: ALMProxy 0x7107DD8F56642327945294a18A4280C78e153644; ForeignController 0x4236B772BEeEAFF57550Aa392A0f227C0b908Ce7; RateLimits 0x6ba2e6bCCe3d2A31F1e3e1d3e11CDffBaA002A21.
  • Plume: ALMProxy 0x1DB91ad50446a671e2231f77e00948E68876F812; ForeignController 0x0C462Fff7Cc975bC9F2B0aEB8270febA5FD71e1B; RateLimits 0x7f8408eBbBC3504F83eeDa52910dd75Eba92C955. Relayer → Controller → RateLimits → ALMProxy → external protocol. The standard ALMProxy is a non-upgradeable, stateless AccessControl custody contract; controllers can be replaced by granting a new CONTROLLER role. The newer Ethereum Diamond PAU adds Beacon-controlled facet/selector upgrades, materially increasing governance and delegatecall risk. Authority and worst case. DEFAULT_ADMIN_ROLE can configure parameters and grant/revoke roles; RELAYER can execute deposits, withdrawals, swaps, bridges and ERC20 transfers; FREEZER can revoke relayers. A compromised admin could grant a malicious controller/relayer, set permissive limits, redirect transfers or configure malicious integrations—potentially draining ALMProxy-held assets. Users do not have a documented permissionless emergency exit from ALMProxy custody; withdrawals are operational/controller-mediated and may depend on asynchronous integrations. Audit. ChainSecurity’s December 23, 2025 review reported 0 critical and 0 high open findings; five low findings remained risk-accepted/acknowledged. This is code-level evidence, not proof that every current deployment is audited. Contradiction / change: the September 4, 2026 record treated foreign-chain addresses as independently unconfirmed; Grove’s current registry now publishes them, but explorer/Dune confirmation remains unavailable. Risk conclusion: high admin/key and governance risk; medium freeze/DoS risk; upgrade risk is low for standard ALMProxy but high for the Diamond PAU.
Admin can drain
Yes
Upgradeable
Yes
Unresolved critical
0
Unresolved high
0
Evidence (5)

audit

one source

Grove Basin — Cantina security report.

Auditor
Cantina
Report date
2026-04-26
Scope
Grove Basin repository; review period 2026-04-06–2026-04-26.
Findings
Critical/high: Not verifiable as of September 4, 2026. Medium: 1; low: 10; informational: 12.
Fix status
Medium 1 fixed; low 6 fixed/4 acknowledged; informational 7 fixed/5 acknowledged. Deployed-bytecode match: Not verifiable as of September 4, 2026.
Evidence (1)

audit

unverified

Grove Finance’s security page lists Cantina audits for Grove Basin and the Token Contract, plus a Cantina audit for Grove ALM Controller v1.6.0 and Grove Gov Relay v1.1.0. The snippet does not expose the severity counts or whether specific findings remain open.

Auditor
Cantina
Report date
2026-07-28
Scope
Grove Basin; Grove ALM Controller v1.6.0; Grove Gov Relay v1.1.0; Token Contract
Evidence (1)

audit

unverified

The security page lists Certora audits for Grove ALM Controller v1.8.0, Grove Gov Relay v1.2.0, and Grove X-Chain Helpers v1.2.0. The snippet does not state whether any critical/high/medium issues were found or remediated.

Auditor
Certora
Report date
2026-07-28
Scope
Grove ALM Controller v1.8.0; Grove Gov Relay v1.2.0; Grove X-Chain Helpers v1.2.0
Evidence (1)

audit

unverified

Grove Finance’s security page lists a ChainSecurity audit for multiple components, including Grove Basin, Grove ALM Controller v1.6.0, Grove ALM Controller v1.8.0, Grove Gov Relay v1.2.0, Grove X-Chain Helpers v1.2.0, and the Token Contract. The public page does not include the report PDFs themselves in the snippet, only the audit names/versions and linked report labels.

Auditor
ChainSecurity
Report date
2026-07-28
Scope
Grove Basin; Grove ALM Controller v1.6.0 and v1.8.0; Grove Gov Relay v1.2.0; Grove X-Chain Helpers v1.2.0; Token Contract
Evidence (1)

audit

one source

Grove Basin — ChainSecurity code assessment.

Auditor
ChainSecurity
Report date
2026-08-17
Scope
Basin smart contracts, versions 1–9; deployment scripts and validation for two deployments; external integrations excluded.
Findings
Critical/high: none reported. Medium: 1 correctness issue in Version 2. Low: 1 correctness issue in Version 7. Informational: 1.
Fix status
Medium fixed in Version 3; low and all significant findings addressed; informational acknowledged. Deployed-bytecode match: Not verifiable as of September 4, 2026.
Evidence (1)

audit

one source

Corrected published report: ChainSecurity — Grove ALM Controller v1.8.0.

Auditor
ChainSecurity
Report date
2025-12-23
Scope
Grove ALM Controller v1.8.0; source, deployment scripts, and differences from Spark ALM Controller v1.5.0. External integrations were excluded.
Findings
Critical: 0. High: 1, fixed. Medium: 2, both fixed. Low: 13; 8 corrected, 3 risk accepted, 2 acknowledged. Informational and notes are also documented.
Fix status
All high and medium findings fixed. Low findings were partly corrected, risk-accepted, or acknowledged. Deployed-bytecode match: Not verifiable as of September 6, 2026.
Report url
https://reports.chainsecurity.com/GroveLabs/ChainSecurity_GroveLabs_GroveALMController_2_Audit.pdf
Report id
doc:52ca0003fb72a98a
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected published report: Certora — Grove ALM Security Assessment Report.

Auditor
Certora
Report date
2025-12-24
Scope
Grove ALM Controller, Grove Xchain Helpers, and Grove Gov Relay; review work undertaken November 24–December 5, 2025; commits listed in report.
Findings
Critical: 0. High: 1. Medium: 2. Low: 4. Informational: 2. High H-01 fixed; Medium M-02 fixed and M-01 acknowledged; Low L-03 fixed and L-01/L-02/L-04 acknowledged; one informational fixed and one acknowledged.
Fix status
4 of 9 findings fixed; remaining findings acknowledged. Deployed-bytecode match: Not verifiable as of September 6, 2026.
Report url
https://certora.cdn.prismic.io/certora/aUvkTHNYClf9oob__CertoraGroveALMSecurityAssessmentReport.pdf
Report id
doc:647e1b7733ac7983
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected published report: Cantina — Sky: Grove ALM Controller Security Review.

Auditor
Cantina
Report date
2025-08-11
Scope
grove-alm-controller; review conducted July 28–August 8, 2025, principally against commit 1e12d824, with holistic confirmation against commit 1658e203.
Findings
Critical: 0. High: 0. Medium: 0. Low: 0. Gas: 0. Informational: 3.
Fix status
All 3 informational findings fixed; Cantina verified the fixes. Deployed-bytecode match: Not verifiable as of September 6, 2026.
Report url
https://cdn.cantina.xyz/reports/cantina_sky_grove_alm_controller_july2025.pdf
Report id
doc:f6f256050630288d
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

unverified

The same security page lists Spearbit audits for Grove ALM Controller v1.6.0, Grove Gov Relay v1.1.0, and Grove X-Chain Helpers v1.1.0. The available snippet does not provide finding counts or fix status.

Auditor
Spearbit
Report date
2026-07-28
Scope
Grove ALM Controller v1.6.0; Grove Gov Relay v1.1.0; Grove X-Chain Helpers v1.1.0
Evidence (1)

Team & Reputation

founders

two sources

Grove Finance appears to have a fully public founding team with institutional ties and a real-world corporate structure, but most of the hard facts come from the project’s own and partner-facing materials, so they are “unverified marketing claims” rather than independently on-chain–verified data. Founders & core team (public, not anon)

  • Grove Labs / Grove Protocol is co-founded by Mark Phillips (Product & Strategy), Kevin Chan (Product & Engineering) and Sam Paderewski (Structured Finance & Credit).
  • The public team page adds Keith Selover (Structured Finance & Credit), Daniel Clarke (Brand & Marketing), Bartek Rutkowski and Justyna Rutkowska (Development), and Gonçalo Afonso (Content & Community).
  • RootData independently lists Phillips and Paderewski as co‑founders, corroborating the identities but not providing deeper diligence.
  • These identities are fully named and role‑described, not pseudonymous; this is a positive for institutional credibility. Prior affiliations & track record
  • Grove Labs is described as a subsidiary of Steakhouse Financial, a DeFi-focused financial advisory firm, with the team claiming to have facilitated over $5B of onchain capital allocations; this is a self-reported figure in a BusinessWire release and counts as an unverified marketing claim.
  • Backgrounds are stated as structured finance, fixed income trading, and smart contract development, but no detailed CVs or prior employers are provided on public pages.
  • No independent public record of prior protocol hacks, insolvencies, or major controversies involving the founders was found; absence of evidence is not proof of clean history. Organizational reality: foundation, office, jurisdiction
  • Grove Finance materials describe Grove Foundation Ltd. as the entity managing protocol governance, security processes, and long‑term development.
  • Grove Labs is positioned as the development org; operations are framed within the Sky (formerly MakerDAO) ecosystem and Steakhouse Financial partnership, rather than a standalone startup.
  • Exact registered jurisdiction, physical office address, and onshore/offshore tax status are Not verifiable as of 2026-09-04. No regulator registry or court filings surfaced in the gathered data. Reality check: business substance vs. web front
  • Evidence of a real operating business includes:
  • Named team and corporate entities (Grove Labs, Grove Foundation, Steakhouse Financial).
  • Launch announcements in mainstream PR (BusinessWire).
  • Integration into the Sky governance ecosystem and RWA partners (e.g., Janus Henderson, Centrifuge), though those relationships are presented in Grove/partner materials and should be treated as unverified marketing claims.
  • However, without on-chain tooling and corporate registries, key items remain Not verifiable as of 2026-09-04: legal registration details, audited financials, and independent confirmation of the stated $5B allocations and institutional partnerships. Net: team is public and institutionally positioned, with credible signalling via Steakhouse/BusinessWire, but much of the narrative is self-reported and should be treated as marketing until cross-checked with formal corporate and regulatory records.
Evidence (15)

general reputation

two sources

Grove Finance currently has a mixed but generally cautious reputation: no public fraud/rug/insolvency allegations or major incidents have been reported, but third‑party risk ratings flag elevated technical and structural risk, largely due to audit transparency gaps and protocol novelty. ### Protocol & team positioning

  • Grove describes itself as the onchain credit layer for stablecoins, deploying USDC/USDS into DeFi lending and tokenized real‑world credit strategies across Ethereum, Base, Avalanche, and Plume.
  • It is characterized as a Sky/MakerDAO ecosystem protocol, focused on institutional‑style credit allocation.
  • Grove emphasizes transparency via Grove Data, a public dashboard of positions, venues, and transactions with links to on‑chain records; this is positively noted by independent reviewers as a strength.
  • Specific founder names and investor lists are not independently verifiable as of 2026‑09‑04; available material is protocol‑level only. ### Auditors & security reputation
  • Grove’s own documentation claims a multi‑auditor model: ChainSecurity, Spearbit (Cantina), Certora and Cantina are listed as audit partners across components like Grove Basin and tooling, with multiple versions and formal verification.
  • Independent rating sites (Hindenrank, Crypto Almanac Daily) state that no public audit reports were retrievable/linked at their checks, and note this as a material concern given Grove’s multi‑billion TVL.
  • Under the marketing rule, Grove’s security claims from its docs are “unverified marketing claims” until cross‑checked with publicly accessible reports. ### Third‑party risk ratings & sentiment
  • Hindenrank assigns Grove Finance a C‑ risk grade (54/100), placing it in the bottom quartile of yield protocols by safety and ranking it #115 of 119.
  • Key concerns: rapid scale to ~2.6–2.7B TVL, mechanism novelty, interaction complexity, oracle and documentation gaps, regulatory and scale exposure, and lack of public audits.
  • Track record is scored 5/15, suggesting no major incidents but short history.
  • Crypto Almanac Daily scores Grove 7.2/10, citing strong transparency and accounting methodology but again highlighting no publicly linked audit report as the main downside.
  • Overall sentiment in independent analyses is “innovative but elevated‑risk; suitable only for sophisticated users with ongoing monitoring.” ### Legal / regulatory / sanctions / fraud
  • No independent sources report fraud, rug pulls, insolvency, sanctions, or active regulatory enforcement actions against Grove Finance as of 2026‑09‑04.
  • Regulatory risk is still scored as non‑trivial (7/10) in Hindenrank’s framework, mainly due to RWAs and institutional credit exposure, not specific cases. ### Unresolved concerns
  • Public audit accessibility gap vs. Grove’s claimed multi‑auditor program.
  • Rapid scale, complex cross‑chain credit structures, and RWA exposure with limited historical track record.
  • Lack of independently confirmed information on founders and investors. For institutional risk purposes, Grove screens as operationally clean but structurally high‑beta, with transparency strong, audit verification weak, and ongoing monitoring strongly warranted.
Evidence (6)

Economy

TVL: $2.0B

model

one source

Economic model (reviewed September 6, 2026)

  • Strategy/assets in: Stablecoin capital is allocated through Sky/Grove mandates into tokenized institutional credit and RWA assets (including AAA CLO tranches, private credit and Treasury products), plus selected on-chain venues such as Aave, Morpho and Curve. Grove’s Sky Prime balance sheet shows approximately $2.7B earning a current 3.70% APY.
  • Yield source: Primarily credit interest, RWA distributions and DeFi lending/LP income. This is fundamentally a stablecoin credit-allocation strategy, not directional trading. Underlying yield appears economically organic; however, GROVE Ecosystem Rewards are externally subsidized/governance-controlled by Sky, variable, and not guaranteed.
  • Risk characterization: Mostly market-neutral/yield-seeking, but with material external RWA issuer, manager, legal, settlement, smart-contract and stablecoin risks. No evidence found that leverage, recursive looping or restaking is the core mechanism. Exact leverage cannot be verified.
  • Lock-ups/withdrawals: Grove Savings and Ecosystem Rewards state no lock-up or withdrawal delay; sUSDS is an ERC-4626 position and GROVE rewards are claimed separately. RWA redemptions can have traditional settlement/liquidity constraints; Basin is intended to bridge that timing gap for eligible transactions.
  • Fees/gates/limits: Grove Savings is described as having no fees. USDC entry through Sky’s PSM may incur the PSM fee. Basin access is eligibility-, liquidity-, platform- and jurisdiction-dependent. Product-specific limits and withdrawal gates: Not verifiable as of September 6, 2026.
  • Protocol revenue: DeFiLlama reports $5.43M fees over 30 days, but $0 protocol revenue; fees represent allocated-asset yield rather than retained Grove earnings.
  • TVL: DeFiLlama reports $2.198B, down 1.31%/7 days, 6.04%/14 days and 9.52%/30 days: Ethereum $1.614B (73.4%), Base $300.37M (13.7%), Avalanche $262.04M (11.9%), Plume $20.69M (0.9%). Product-level TVL and historical APY volatility are Not verifiable as of September 6, 2026. Dune was unavailable; therefore Dune-vs-DeFiLlama reconciliation and on-chain verification are Not verifiable as of September 6, 2026. Structured fields: organic_yield_pct: null; leverage_ratio: null
Evidence (4)

reserves

unverified

As of 2026-09-06, Dune/on-chain verification is unavailable in this run. Therefore: Not verifiable as of 2026-09-06 for total liquid reserves, treasury size, reserve composition, chain-by-chain balances, reserve addresses, liabilities, and any reconciliation between dashboard figures and contract balances. Custody and control — protocol-documented, not independently verified here: Grove states that its Allocator uses a non-custodial architecture in which the ALMProxy holds funds, authorized Controllers can call it, and RateLimits constrain capital movements. A FREEZER role can revoke relayer access and halt automated operations.

Basin instances are issuer-owned through a TimelockController: the issuer controls the proposer role, Grove Governance executes, and the Grove Freezer multisig can cancel queued actions. Basin liquidity may come from the Grove Allocator, an issuer treasury, or third-party liquidity providers. These are protocol documentation claims, not reserve attestations. Composition: Grove documentation describes exposure to stablecoins deployed into institutional credit strategies, including AAA-rated CLO tranches, private credit, tokenized Treasury bills, lending markets, RWA vaults, DEX liquidity, and cross-chain bridging.

Exact current composition and valuation are Not verifiable as of 2026-09-06. Reserve policy / attestations: The available materials describe smart-contract controls, audits, timelocks, and rate limits, but I found no independent reserve attestation, proof-of-reserves report, liability report, or policy specifying minimum reserve ratios. Not verifiable as of 2026-09-06. Security audits are not equivalent to financial reserve attestations. Update/contradiction: Grove’s current FAQ lists Ethereum, Avalanche, Base, Plume, Monad, and Robinhood as live networks, whereas the prior scope covered four chains. This does not establish reserves on the additional chains. Structured fields: liquid_reserves_usd: null; liabilities_usd: null.

Evidence (4)

tokenomics

two sources

Native token: GROVE (Grove), ERC-20 on Ethereum: 0xB30FE1Cf884B48a22a50D22a9282004F2c5E9406. No separate native-token contracts on Base, Avalanche, or Plume were verifiable as of September 4, 2026. Supply/valuation: Genesis/maximum supply is 10.0B GROVE. DeFiLlama reports 710.36M circulating, ~$5.58M market cap and ~$78.54M FDV; token price was ~$0.0079.

> Contradiction: DEX Screener showed ~$5.6M market cap but ~$88.1M FDV and only ~$925 liquidity in its GROVE/USDC Uniswap v4 pool. The valuation gap likely reflects different price/supply snapshots; the discrepancy is unresolved. Utility/governance: GROVE can be staked into stGROVE through Symbiotic infrastructure; stGROVE supplies Snapshot voting power and delegation.

Staking carries no contractual right to yield, payments, or distributions. Seeds are non-transferable participation records, not economic or voting rights. Revenue/value capture: No documented revenue share, buyback, or burn mechanism.

DeFiLlama reports protocol revenue of $0 despite fees. Sky, not Grove, controls GROVE ecosystem-reward emissions to USDS suppliers; these are incentives, not protocol revenue sharing. Emissions/unlocks: Allocations: Sky Ecosystem 70% (7B), team/contributors 25% (2.5B), Grove Foundation 5% (500M).

Published years 1–10 schedule distributes 79% of total supply; the remaining 2.1B GROVE is unspecified and subject to future Sky governance. Team emissions are 625M/year for years 1–4; Sky rewards decline from 1.225B/year in years 1–2 to 153.125M/year in years 7–10. Whether announced releases occurred on-chain: Not verifiable as of September 4, 2026. Control/concentration: The docs state only Sky’s MCD_PAUSE_PROXY is authorized to administer the SDAO token contract.

Exact mint, blacklist, transfer-fee, and fee-switch behavior; top-holder concentration; insider-wallet attribution; and on-chain allocation movements: Not verifiable as of September 4, 2026. Listings/liquidity: Main identifiable markets are Bybit, Coinbase, and Uniswap; available DEX liquidity appears extremely shallow relative to FDV.

Evidence (7)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Grove Finance, a Bitcoin break below $10,000 is a macro stress scenario, but the protocol-level impact is not verifiable as of 2026-09-04 from the available sources because I do not have on-chain data access in this run. The only directly relevant web evidence here is market commentary that a BTC move to $10,000 would likely require severe liquidity stress, forced deleveraging, and a broader crypto confidence shock, not just a normal bear market. What this means for Grove Finance is scenario-based rather than proven:

  • If Grove has BTC exposure through collateral, treasury holdings, reserves, or yield strategies, a BTC collapse to $10,000 would likely increase liquidation risk, reduce collateral value, and pressure any NAV-linked or risk-managed products.
  • If Grove is primarily exposed to non-BTC assets, the main effect would be second-order: higher crypto volatility, risk-off behavior, lower inflows, and potentially weaker RWA/DeFi demand.
  • The protocol’s actual sensitivity cannot be confirmed from the provided sources, and I cannot verify chain-by-chain exposure on Ethereum, Base, Avalanche, or Plume Mainnet in this run. I can say only that Grove’s current price sources show it trading around the sub-$0.01 area, but those are market snapshots, not stress-test outputs, and they do not establish how Grove would perform under a BTC crash. Not verifiable as of 2026-09-04: BTC-denominated exposure, collateral composition, liquidations under a $10,000 BTC shock, and chain-level TVL impact for Grove Finance.
Evidence (8)

stress scenario - largest collateral depegs 20%,

two sources

For Grove Finance, a 20% depeg in the largest collateral asset would mechanically reduce the marked value of that collateral by 20%; the portfolio-level impact depends on that asset’s share of total deployed capital, but that share is not verifiable as of 2026-09-04 from the provided sources. Grove states it uses diversified credit strategies and institutional credit markets, and its FAQ says the two Instant vaults allow withdrawals subject to available liquidity, with large redemptions potentially facing brief delays if repo positions need to unwind. The main stress implication is NAV compression and liquidity stress, not an immediate protocol-wide loss unless the depegged collateral is large enough or cannot be rebalanced quickly.

Grove’s public materials also describe exposures to repo, tokenized credit, and RWA-style positions with redemption delays, which means a sharp collateral markdown could force either delayed withdrawals or asset sales at a discount if liquidity is insufficient. I cannot verify Grove’s live collateral composition, chain-by-chain exposure across Ethereum, Base, Avalanche, and Plume Mainnet, or the exact dollar impact of a 20% depeg without on-chain data. Therefore, the protocol-level loss estimate is Not verifiable as of 2026-09-04.

What can be stated from the available material is the stress logic:

  • if the largest collateral represents a modest share of assets, the loss is contained to NAV decline;
  • if it is concentrated, a 20% shock can create withdrawal gating pressure and forced selling;
  • if the asset is used inside a vault with delayed redemption, the stress can transmit into queue delays and secondary-market discounting. The dominant risk question is the concentration of the largest collateral, but that concentration is Not verifiable as of 2026-09-04.
Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Grove Finance, the specific *top-counterparty insolvent* stress path is not fully verifiable as of 2026-09-04 because the available web material does not disclose the exact top counterparties by exposure, the contractual loss waterfall, or any formal compensation mechanism tied to counterparty default. The protocol does state that it deploys capital into diversified credit opportunities across multiple chains, including Ethereum, Base, Avalanche, and Plume, and that its vaults are on Ethereum mainnet; third-party coverage also says Grove allocates into Aave, Morpho, Centrifuge, and tokenized RWA assets such as BUIDL and JAAA. Expected loss path: if the largest deployed counterparty becomes insolvent, the first loss is the mark-to-market or redemption loss on the affected position(s), then any liquidity shortfall propagates to Grove’s NAV and withdrawal capacity. Because some strategies use tokenized RWA assets with limited on-chain liquidity, the likely path is delayed redemption or below-par liquidation rather than immediate on-chain recovery. Who absorbs it: based on the available sources, the loss would be borne first by Grove’s vault equity / depositors through NAV impairment, not by an identified third-party insurer or guarantee fund.

There is no verifiable evidence of a protocol-level backstop, indemnity, or insurance pool in the sources reviewed. Not verifiable as of 2026-09-04. Compensation: no public source reviewed documents an automatic compensation mechanism for counterparty insolvency. Any recovery would depend on the underlying counterparty’s own redemption, liquidation, or bankruptcy process, and on whatever residual value Grove can recover from the position. Not verifiable as of 2026-09-04. Impact path through smart contracts: the most plausible propagation is: counterparty insolvency -> affected strategy underperforms or becomes illiquid -> vault NAV declines -> withdrawals may slow, pause, or settle at impaired value depending on contract logic and available liquidity. The protocol description confirms a vault-based, multi-chain deployment, but does not publicly specify a detailed insolvency waterfall. Callout: contradiction/gap - Grove marketing/docs emphasize diversified cross-chain credit deployment, but the public materials reviewed do not specify how insolvent counterparty losses are contractually allocated.

The on-chain/contract-level waterfall therefore remains not verifiable from the available evidence.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

Not verifiable as of 2026-09-04. I did not find credible, protocol-specific evidence that Grove Finance’s DAO, owners, or controllers committed fraud. The available Grove documentation describes a three-layer architecture with custody, controls, rate limits, and emergency freezer powers, but that is a *design description*, not evidence of misconduct. Grove’s public materials also describe the protocol as institutional credit infrastructure, which again does not establish fraud.

For a stress scenario, the relevant risk is governance or control abuse: if a small set of insiders or authorized controllers could misuse upgrade, custody, or emergency privileges, that could in principle enable unauthorized transfers, harmful parameter changes, or treasury diversion. However, that is a generic DAO risk model, not a verified incident at Grove. No on-chain verification was possible in this run, so I cannot confirm ownership concentration, treasury control, multisig composition, or whether any chain-specific deployment on Ethereum, Base, Avalanche, or Plume Mainnet was exposed to insider fraud.

If you need a binary risk flag for screening, the correct label is: unverified / not evidenced rather than confirmed fraud.

Evidence (6)

stress scenario - primary yield source negative 30d,

two sources

A 30d negative primary yield source stress scenario for Grove Finance is not verifiable as of 2026-09-04 from the available web results. The provided sources are general stress-testing methodology references and do not contain Grove Finance’s chain-specific 30-day yield composition, so I cannot confirm whether the protocol’s primary yield source is negative over the last 30 days. What can be said is that “stress scenario” in financial testing usually means an extreme but plausible adverse condition, and regulators often require scenario analysis rather than forecasts.

However, none of the retrieved sources tie that framework to Grove Finance, nor do they provide on-chain or protocol-reporting evidence for Ethereum, Base, Avalanche, or Plume Mainnet. Because Dune/on-chain verification is unavailable in this run, the protocol-specific answer is limited to: Not verifiable as of 2026-09-04.

Evidence (4)

Governance & Legal

governance

unverified

As of September 13, 2026 — Governance finding Control map. Grove Labs develops/builds Grove Protocol and is described as a subsidiary of Steakhouse Financial. The public website is operated by Grove Foundation, stated to be incorporated in the Cayman Islands; its Terms also reserve unilateral rights to modify content and restrict/terminate website access. No Cayman registration number or directors were identified. DAO reality. GROVE holders stake into stGROVE and vote through Snapshot, directly or via three delegates appointed by Grove Foundation and the Operational Facilitator: DocGriffin, YvonPiPi, and northbridge.

This is a real participation mechanism, but the documentation does not demonstrate that token-holder votes control all production upgrades, treasury movements, frontend deployment, or every deployed chain. Therefore DAO governance is symbolic/partial for risk classification, not proven as ultimate control. Proposal process. Snapshot proposals use stGROVE voting power; delegation covers the full staked balance. No minimum stake is stated.

The enforceable proposal-to-execution path for the broader protocol is not documented independently. Contracts/funds. For Grove Basin specifically, each instance is issuer-owned and uses an OpenZeppelin TimelockController: issuer multisig = proposer, Grove Governance = executor, and Grove Freezer multisig = canceller. Issuers can claim accrued fees immediately without timelock authorization. The minimum delay, Freezer signers/threshold, and whether equivalent controls exist for Allocator, staking, treasury, and other chains are not disclosed in the reviewed sources. Concentration / top holders. Not verifiable as of September 13, 2026.

Dune MCP was unavailable, so voting concentration, top GROVE/stGROVE holders, multisig independence, and on-chain admin powers were not independently checked. Contradiction / key gap. Grove presents token-holder governance, while its own Basin design leaves issuer multisigs with proposal authority and permits immediate fee claims; the documentation does not prove that the DAO can override those powers. On-chain verification is required before treating governance as fully decentralized. Structured fields: timelock = true (Basin only); timelock_delay_hours = null; multisig_threshold = null; multisig_owners = null; admin_can_drain = null; emergency_bypass = null; dao_governance = false.

Timelock
Yes
Dao governance
No
Evidence (4)

legal & regulatory

one source

As of September 4, 2026, the identifiable operating entity is Grove Foundation, a Cayman Islands foundation company (LEI 254900L3J9N8Y2TSMX94; General Registry ID CR-421018; formerly Bloom Protocol Foundation). Grove’s public Terms identify this entity as the website operator and select Cayman Islands law and courts. The Terms expressly cover only the public website—not vaults, protocol interfaces, or other DeFi services, which are said to have separate in-app terms.

Those product terms were not publicly verifiable as of September 4, 2026. KYC/AML: No public protocol-level KYC/AML policy or universal onboarding requirement was verified. The website privacy policy describes wallet, IP, device, analytics, and transaction data processing, but does not establish licensing, customer due-diligence controls, AML registration, or a named compliance officer.

Public blockchain records are described as immutable; deletion is therefore limited in practice. Privacy rights are stated only “subject to local law,” with no clearly identified GDPR representative, controller details, retention schedule, or cross-border transfer framework. Classification: Grove’s MiCAR registry page shows a crypto-asset white paper dated June 29, 2026, with Ireland as home Member State and the Central Bank of Ireland as competent authority.

This evidences a MiCAR white-paper/notification pathway, not necessarily authorization as a CASP, investment firm, fund, or issuer. The definitive classification of GROVE, sUSDS, vault interests, and tokenized-credit exposures in the United States and other jurisdictions is Not verifiable as of September 4, 2026. Economic exposure to CLOs, private credit, and tokenized funds creates potentially higher securities, collective-investment, lending, and marketing-law risk than a simple governance token.

Warnings/enforcement/courts/sanctions: No matching public regulator enforcement action, sanctions designation, or court case against Grove Foundation or the Grove protocol was identified in the reviewed sources. This is not a legal clearance. Sanctions screening or address blocking would not itself mean Grove is sanctioned.

Legal structure is Cayman-based and foundation-form, while operations involve Grove Labs, Sky governance, off-chain credit managers, and EU-facing MiCAR materials; liability, licensing, insolvency-remoteness, and investor recourse across these layers remain Not verifiable as of September 4, 2026.

Active enforcement
No
Sanctioned
No
Entity
Grove Foundation
Jurisdiction
Cayman Islands
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Grove Foundation', 'Grove Finance'. OFAC SDN screening of 'Grove Foundation', 'Grove Finance': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Grove Foundation
  • Grove Finance
Sanctioned
No
Evidence (4)

Stability

stability

unverified

Grove Finance does not appear to issue its own stablecoin. The protocol’s documentation and site describe it as a credit layer that accepts and routes existing stablecoins, especially USDS and USDC, and identify USDS as the Sky-issued stablecoin rather than a Grove-issued asset. Because no Grove-native stablecoin is verifiable from the gathered sources, stablecoin depeg history for a protocol-issued stablecoin is not verifiable as of 2026-09-06.

Own stablecoin
No
Stablecoin ids
  • USDS
  • USDC
Evidence (3)

Risks & Strengths

risks

one source

Grove’s primary risks arise from the combination of off-chain institutional credit, tokenization and settlement dependencies, DeFi integrations, and cross-chain deployment. The protocol documents audits, governance review, diversified managers and liquidity tooling, but these reduce rather than eliminate principal-loss, liquidity and operational risks. On-chain verification through Dune was unavailable; therefore, contract balances, exposure concentration and latest block-level metrics are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
RWA credit and valuation lossesUnderlying CLOs, private credit, Treasury funds and other tokenized assets retain issuer, manager, borrower, duration, valuation and default risk. Tokenization does not make the underlying claims risk-free; losses or delayed write-downs can reduce vault value and depositor recoveries.HighMediumDiversification across managers and asset types; allocations subject to Sky governance mandates; institutional managers, issuers and custodians are used. These are protocol-documented controls, not independently verified here.High: senior or diversified credit can still suffer impairment, liquidity discounts or operational loss.
Liquidity and redemption mismatchUnderlying RWA redemptions may follow traditional settlement cycles lasting multiple days. Basin’s “instant” liquidity is conditional on eligibility, approved transactions, liquidity parameters, platform availability and legal terms; it is not a universal redemption guarantee.HighMediumGrove Basin provides conditional interim stablecoin liquidity, while vault and transaction parameters constrain availability.High: stressed withdrawals could exceed available liquid buffers or Basin capacity.
Smart-contract and integration failureGrove connects vault infrastructure with Sky, Aave, Morpho, Uniswap, Curve, ERC-4626/ERC-7540 components and tokenization platforms. A vulnerability, accounting error, oracle issue or dependency failure could impair assets or withdrawals.HighMediumGrove states that contracts and integrations undergo independent audits or security reviews, including work associated with Spearbit, ChainSecurity and Certora.Medium-High: audits reduce known-code risk but do not cover every upgrade, integration state or emergent exploit.
Cross-chain and bridge dependencyDeployment across Ethereum, Base, Avalanche and Plume increases operational and settlement complexity. Grove documents use of Circle CCTP V2 and LayerZero; bridge, messaging, chain-finality or chain-specific contract failures could isolate or impair assets.HighMediumUse of established cross-chain infrastructure and governance-controlled allocation processes is documented; chain-level exposure limits and current balances are **Not verifiable as of September 5, 2026**.Medium-High: correlated bridge or network incidents can remain outside Grove’s control.
Governance, admin and dependency concentrationGrove operates as a Sky Prime Agent, while Sky governance sets mandates and savings parameters. Basin also assigns administrative roles to issuer multisigs, Grove governance and a freezer multisig; governance, key compromise, counterparty failure or USDS/Sky stress could affect access and value.HighMediumGovernance approval, timelocks, proposer/executor separation and a cancellation multisig are documented for Basin; allocations rely on institutional counterparties and Sky oversight.Medium-High: concentration in Sky, issuers, custodians and key administrators creates non-technical failure modes.
Evidence (4)

strengths

two sources

Based on the available sources, Grove Finance’s top strengths are: institutional-grade credit allocation across stablecoin and credit markets; non-custodial, onchain transparency for vaults and allocations; multi-chain deployment across Ethereum, Base, Avalanche, and Plume; risk controls such as rate limiters, exposure caps, and governance-enforced parameters; and yield from real credit activity rather than token emissions. Grove describes itself as a credit protocol that routes stablecoin capital into institutional credit markets and offers transparent, scalable stablecoin yield. Its architecture emphasizes non-custodial vaults and full onchain visibility, with audited smart contracts and instant redemption or settlement features highlighted in the product materials.

The protocol also claims broad reach across several chains and venues, which increases distribution and capital-routing flexibility. Its risk framework is repeatedly described as including exposure caps, rate limiters, and governance-enforced parameters, which is a notable strength for institutional users. Finally, Grove positions its yield as being generated by actual borrowing demand in repo and structured credit markets, which supports sustainability relative to inflationary incentive models.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 14 two independent sources, 11 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-30.