K3 Capital

Orange · 59/100

Executive summary

K3 Capital is an institutional DeFi asset and risk manager curating yield vaults across multiple protocols (Euler, Morpho, Liquity, IPOR) on nine chains; it scores 46/100 (orange band) with a 10-point penalty for an unresolved incident.

  • Security: Two audits (ChainSecurity, Dedaub) of the sBOLD vault in May 2025 found 2 critical, 3 high, 8 medium issues; all critical/high/medium were fixed, 2 low remain open. Audit coverage is limited to sBOLD; broader multi-chain contracts are not verified as of September 2026. No bug bounty program was found.
  • Incidents: In November 2025, K3 suffered a $2M loss when Elixir/deUSD depegged after Elixir secretly lent ~$68M to insolvent Stream Finance; K3 initiated legal action and Elixir later offered ~80% recovery, but final reimbursement to K3 vault depositors is unverified and remediation remains in progress (penalty applied).
  • Governance & custody: Non-custodial vault model with assets held on-chain; governance is team-controlled (no DAO or token), with "intentionally minimal" public input. Multisig signers, timelock enforcement, and admin key custody are not verifiable as of September 2026. One Unichain vault has a 3-day timelock; others unverified.
  • Top risks: High privileged-owner control (curator can set fees, oracles, allocations); counterparty/protocol dependency (Euler, Morpho, Liquity, stablecoin issuers); collateral depeg exposure (USDT0, BOLD, rsETH, wstETH); incomplete audit coverage beyond sBOLD; liquidity and chain concentration (72% Monad per analytics, unverified on-chain).
  • Strengths: Institutional positioning since 2021 with public team (co-founder, CIO, CTO, General Counsel); transparent on-chain parameters; multi-protocol yield routing; two independent audits of core sBOLD product; U.S.-registered entity (K3 Capital LLC, Kansas, LEI active, no sanctions).
  • Unverified: Bytecode match of audited code to deployed contracts; exact multisig setup, signer identities, and timelock coverage across all chains; current TVL, vault allocations, and counterparty exposures; treasury reserves and liquidity buffers; withdrawal queue mechanics and emergency controls.
  • Recommended exposure: Conservative allocation only (≤2–5% of portfolio) given orange score, unresolved $2M incident, and high curator trust; limit to audited sBOLD vault on Ethereum if verifiable, or avoid until incident remediation and full multi-chain audit are confirmed; monitor legal recovery and depositor reimbursement status.
  • Open questions: Verify on-chain that deployed contracts match audited commits; confirm multisig signers, threshold, and independence; obtain current vault-by-vault TVL, collateral breakdown, and counterparty exposures; verify final Elixir recovery amounts and whether all affected users were made whole; assess withdrawal queue, utilization caps, and emergency pause authority across all chains.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 3 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 50 10.0 last full audit 2025-05-19 is older than a year
Incidents 20% 100 20.0 2 open incident(s), $4,000,000 at risk = 0.8% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 3 0.6 TVL $502,755,306 = 3% of reference ($17,538,184,136)
Data confidence 94 7/7 critical categories; 25/35 verified facts; 35/35 fresh (180d)

Identification

protocol identification

two sources

K3 Capital is an institutional DeFi asset and risk manager that curates yield and lending vaults across multiple underlying protocols, rather than a single monolithic DeFi app. It is positioned as a risk curator / yield aggregator with institutional underwriting on top of lending markets. ### Identification

  • Name: K3 Capital
  • Website: k3.capital (plus marketing/front-end mirrors k3-capital.net and k3capital.org)
  • Docs: Not clearly exposed as a separate technical docs site; public information is mainly via marketing pages and FAQs on k3-capital.net.
  • Category: Institutional DeFi asset & risk manager / risk curator, running curated vault strategies on top of lending and yield protocols (Euler, Morpho, IPOR, Liquity, Term Finance, Midas, Accountable).
  • Launch date: The firm and on-chain operations trace back to 2021.
  • Chains: External analytics and marketing describe activity across 9 chains, explicitly including Monad, Ethereum, Optimism, Plasma, Arbitrum, Binance, Unichain, BOB (plus at least Avalanche) as venues where K3-curated vaults exist. Exact per-chain TVL split is Not verifiable as of 2026-09-04.
  • Native token: No credible source indicates a protocol-native ERC‑20 “K3” token; K3 operates as a manager/curator, not a token-based protocol. ### Main contract addresses (partial) Because direct on-chain querying is unavailable, all smart-contract details are Not verifiable as of 2026-09-04.
  • A specific K3‑curated vault on Avalanche (Term Finance) is reported at address 0x8fc260cd0a00cac30eb1f444b8f1511d71420af9, with share token tsvk3USDT. This is an aggregator-sourced address only; explorer verification and cross-check with a second independent source are Not verifiable as of 2026-09-04.
  • MrDeFi and DiaData track K3 as a risk curator with ~$380–400M assets and 3 vaults on 9 chains, but they do not expose canonical contract lists. As a result, a complete set of “main contracts” per chain is Not verifiable as of 2026-09-04. ### Fork lineage and code provenance
  • Public descriptions consistently present K3 as an original vault/risk-curation stack and fund manager, not a fork of a specific upstream protocol (e.g., Yearn, Morpho, Euler).
  • Its vaults are built on top of third-party protocols (Euler, Morpho Blue, Term Finance, etc.) rather than forking their core code.
  • No independent source documents:
  • a concrete upstream fork origin,
  • a catalogue of smart-contract changes vs any upstream,
  • audits of those changes, or
  • malicious-modification incidents in K3 forks. Accordingly, fork lineage, audit status of custom contracts, and any history of malicious forks are Not verifiable as of 2026-09-04 and should be treated as unknown pending direct access to audited code or on-chain data.
Evidence (15)

maturity

two sources

K3 Capital’s public site looks more like a limited landing page than a full product portal. The homepage text says it is “in the process of preparing its dedicated United States website” and that “no services are being offered to US residents through this site,” which is a strong signal of incomplete consumer-facing functionality. The site appears to have a separate Webflow-based mirror/marketing page, further suggesting a templated or pre-launch web presence rather than a mature app surface.

I could not verify live deposit/withdrawal flows, authenticated account features, or a functioning on-chain app from the available web evidence, so those capabilities are not verifiable as of 2026-09-04. I also could not verify an open API or public developer docs; no credible documentation or API reference surfaced in the search results, so open API availability is not verifiable as of 2026-09-04. No direct evidence of broken links or fake metrics was found in the retrieved material, but the website language and Webflow-like presentation indicate a lightweight marketing setup rather than a fully operational DeFi portal.

Evidence (3)

Security

bug bounty

two sources

Not verifiable as of 2026-09-04. A web search found K3 Capital’s social and site presence, but no confirmable active bug bounty program page for this protocol; the only clear bounty listing surfaced was for an unrelated Capital.com program, not K3 Capital. The protocol’s own site content indicates its DeFi vault/product activity, but not a security bounty program.

Because no verifiable K3 Capital bug bounty program was found, start date, parameters, payout caps, and results remain unconfirmed.

Active
No
Evidence (3)

counterparty risks

two sources

Assessment date: September 6, 2026. dependency_failure_active: null max_exposure_pct: null Current dependency map / risk findings

  • Underlying protocols: K3 vaults currently show exposure to Euler, IPOR, Upshift, Liquity/BOLD, Kelp/rsETH, and stablecoins including USDT0, NUSD, BOLD, EUROP and USDT. These create protocol, issuer, liquidity, redemption and smart-contract contagion risk.
  • Morpho markets: K3’s Unichain markets use wBTC, wstETH, weETH and UNI as collateral against USDC. Listed dependencies include BitGo custody for wBTC, Lido/Ether.fi staking or restaking exposure, and RedStone price oracles. Oracle failure, stale pricing, manipulation or thin liquidity could trigger erroneous liquidations or bad debt.
  • Stablecoin/LST/restaking concentration: The visible product set is materially concentrated in stablecoins and yield-bearing ETH/BTC wrappers. A depeg in USDT0, USDT, BOLD, NUSD, EUROP, wstETH, weETH or rsETH could impair NAV, collateral values and withdrawals. Exact look-through percentages are Not verifiable as of September 6, 2026.
  • Bridge and cross-chain risk: K3 operates across multiple chains and uses cross-chain-compatible assets, but the specific bridges, messaging systems and bridge balances are Not verifiable as of September 6, 2026. Chain-level TVL is analytics data, not on-chain proof: DeFiLlama reports approximately $430.4M, with Monad 72.2%, Ethereum 25.5%, Optimism 1.4%, Plasma 0.5% and all others below 0.3%.
  • Institutional/MM exposure: A July 2026 release reported a K3/Accountable vault extending an AUSD-denominated credit facility to Galaxy on Monad. This introduces borrower, stablecoin and enforceability risk; facility size and current outstanding balance are Not verifiable as of September 6, 2026.
  • RWA issuer/SPV, CEX and custodians: No complete, current exposure register or verified per-counterparty limits was located. Not verifiable as of September 6, 2026. > Contradiction / data-quality note: DeFiLlama currently lists nine chains and includes Avalanche, while the supplied scope lists eight chains and Binance/BNB. Avalanche is shown at zero TVL, so the chain inventory requires reconciliation. Failure scenarios: oracle manipulation → mispricing/liquidations; stablecoin depeg → NAV loss/run risk; lending-protocol exploit → trapped or impaired assets; bridge/custodian failure → loss of wrapped-asset backing; borrower insolvency → credit loss. No active failure was confirmed, but comprehensive incident status is Not verifiable as of September 6, 2026.
Evidence (5)

crypto custody

one source

K3 Capital appears to organize custody as a non-custodial, on-chain vault model: the protocol states that user assets remain in on-chain vault contracts, the platform is a convenience layer rather than a custodian, and users retain access to the underlying contracts even if the interface is unavailable. Its Edge page says clients have full visibility over the on-chain addresses being managed via the Investor Portal, which is consistent with transparent contract-address-based control rather than off-chain custody accounts. A third-party data page also describes “segregated managed accounts” alongside three structured funds, but that source is not sufficient to verify whether assets are legally or operationally segregated in a custody sense. withdrawal_paused: null segregated_assets: null Not verifiable as of 2026-09-06 whether withdrawals are paused or whether assets are segregated in a custody/legal sense.

Evidence (3)

incident

two sources

Available external data shows one material incident affecting K3 Capital vault depositors; there is no evidence of smart-contract exploits or bridge hacks on K3 itself as of 2026‑09‑04. ### 1) Elixir / deUSD depeg – counterparty/strategy‑misrepresentation loss

  • Date: November 2024 (Elixir’s strategy change late October; Stream collapse disclosed November 3; deUSD depeg and lender losses days thereafter).
  • Cause: Off‑chain and protocol‑level counterparty risk – Elixir unilaterally changed its strategy from low‑risk basis trading to lending ~USDC 68M to Stream Finance via Morpho; Stream then lost ~USDC 93M and Elixir’s deUSD depegged after redemptions were suspended, impairing lenders including K3‑managed vaults.
  • Loss (size and affected): Hindenrank’s risk report states K3 “suffered a $2M loss in November 2024” on deUSD exposure when Elixir changed its mandate and subsequently collapsed. This is attributed to K3‑curated strategies that held deUSD; end‑users in those vaults are the economically affected parties (exact user count not independently quantified).
  • Technical nature: Not a smart‑contract exploit of K3; rather curator judgment / counterparty failure in an integrated collateral issuer (Elixir) and its lending relationship with Stream Finance.
  • Protocol response:
  • K3 publicly labeled the episode a “coordinated fraudulent scheme” by Elixir and Stream, and threatened/initiated legal action on behalf of affected lenders, retaining U.S. counsel and serving Elixir’s founder with a cease‑and‑desist while preparing a civil complaint.
  • Hindenrank’s report treats the incident as a key track‑record and curator‑risk data point, emphasizing that K3 tightened risk controls and now highlights cascading‑collateral scenarios (Euler multi‑chain cluster etc.) in its risk framework.
  • Recovered_USD / reimbursement: No independent source quantifies any recovery of principal or compensation to K3 vault depositors. Coverage focuses on prospective legal claims, not completed restitution. Not verifiable as of 2026‑09‑04 whether users were reimbursed or what portion of the ~$2M loss, if any, has been recovered.
  • Fix / mitigation: External analysis indicates K3 has treated this as curator‑risk and tightened collateral selection and scenario analysis processes, but specific on‑chain parameter changes (caps, whitelists, integrations removed) cannot be independently reconstructed from current public data. Not verifiable as of 2026‑09‑04 at a granular level.
  • Status: From risk‑report and media perspective, this loss is historical but unresolved economically – i.e., the event is over, but confirmed recovery/reimbursement has not been documented. Status: unresolved. ### Other incidents Across available analytics and media, there are no reported hacks, smart‑contract exploits, or major loss events tied to K3 Capital vault contracts or bridges themselves as of the current date. All other discussed issues relate to general risk scenarios rather than realized incidents.
Date
2024-11-01
Cause
Other
Loss
$2.0M
Status
unresolved
Evidence (3)

incident

two sources

Based on available public sources, K3 Capital has no known smart contract exploits or direct protocol hacks on its own vaults across Ethereum, Optimism, Arbitrum, BNB, Monad, Plasma, Unichain, or BOB. Not verifiable on-chain as of 2026-09-03. However, there is one material incident affecting K3 users via underlying collateral exposure: 1) Elixir / deUSD collapse impacting K3 Capital strategies

  • Date: November 2024 (deUSD depeg after Elixir suspended redemptions). Bankless coverage cites fallout “just days later” after Stream’s Nov 3, 2024 disclosure of a ~$93M loss; Hindenrank references this as November 2024.
  • Cause: Underlying collateral/strategy failure, not a K3 smart contract bug. Elixir secretly changed deUSD’s mandate from advertised low-risk basis trading to lending ~USDC 68M to Stream Finance via Morpho; Stream then suffered major losses and insolvency, triggering deUSD depeg and loss for lenders including K3-managed positions.
  • Loss (estimated): Hindenrank reports K3 “suffered a $2M loss in November 2024” tied to the Elixir/deUSD incident.
  • Who was affected: K3 vault depositors with exposure to the deUSD strategy curated by K3 (indirect exposure to Elixir/Stream). Exact user vs. treasury split is Not verifiable as of 2026-09-03.
  • Protocol response: K3 publicly attributes the loss to misrepresentation and unilateral mandate change by Elixir, calls it a “coordinated fraudulent scheme,” and states it has retained a top U.S. attorney, served Elixir’s founder with a cease-and-desist, and is preparing a civil complaint on behalf of affected lenders.
  • Reimbursement: No clear evidence that K3 has fully reimbursed affected users from its own balance sheet; coverage frames recovery as being pursued via legal action against Elixir/Stream. Not verifiable as of 2026-09-03 whether partial or full reimbursements occurred.
  • Recovered_usd: Dependent on ongoing or future legal outcomes; Not verifiable as of 2026-09-03.
  • Current status: Incident is not a live technical vulnerability in K3’s contracts but an unresolved counterparty/credit dispute. From a risk lens: remediation_in_progress via legal action and tightened integration/security processes, but the financial shortfall from the original ~$2M loss appears unresolved for full user recovery. No other credible reports describe hacks, oracle manipulations, key compromises, or governance attacks specifically on K3’s own contracts; audit summaries from ChainSecurity and Dedaub note issues being resolved and no critical open vulnerabilities, which supports the absence of contract-level incidents but does not prove completeness.
Date
2024-11
Cause
Depeg / collateral
Loss
$2.0M
Status
remediation in progress
Evidence (4)

incident

two sources

Corrected prior dating: this event occurred November 3–7, 2025, not November 2024. Stream Finance disclosed an approximately $93M loss on November 3, 2025; Elixir had reportedly changed strategy in late October and lent approximately $68M USDC to Stream. deUSD then depegged and redemptions were suspended. K3-managed Euler vaults on Avalanche had deUSD exposure; K3 reportedly liquidated on November 4, leaving approximately $2M of deUSD unredeemed.

Affected parties were K3-curated Euler vault depositors/lenders and K3 as curator. This was an underlying counterparty/collateral failure, not a K3 smart-contract exploit. K3 demanded 1:1 redemption, retained U.S. counsel, issued a cease-and-desist, and prepared civil action.

Elixir later shut down deUSD and launched a recovery portal on March 17, 2026, offering an approximately 80% pro-rata recovery to eligible Euler/Morpho lenders in exchange for a broad release. K3-specific acceptance, payments, exact net realized loss, and exact recovered amount are Not verifiable as of 2026-09-06. No evidence was found that all affected K3 users were reimbursed.

Current status remains remediation_in_progress.

Date
2025-11-03
Cause
Depeg / collateral
Loss
$2.0M
Status
remediation in progress
Event id
k3-capital-elixir-deusd-stream-2025
Evidence (4)

incident

unverified

Not verifiable as of 2026-08-29. I found no independently confirmed incident report for K3 Capital in the available web results. The only K3 Capital-specific source located is the project’s own page, which claims the platform does not hold custody of assets in any off-chain system and that material parameters, fee recipients, strategy allocations, and pause-guardian addresses are publicly readable on-chain; it also says the team will publish incident post-mortems within 72 hours if something goes wrong.

These are unverified marketing claims because they come from the protocol itself. No external evidence of an exploit, loss, reimbursement, or fix was verifiable from the gathered sources.

Date
2026-08-29
Cause
Other
Evidence (2)

key management

one source

K3 Capital presents key management as on-chain and transparent rather than custodial/off-chain: it says the platform does not hold assets in any off-chain custody system and that material parameters such as fee recipients, strategy allocations, and pause-guardian addresses are readable on-chain. Its operating model also indicates institutional role separation: clients can see the on-chain addresses being managed, while K3 itself monitors, allocates, rebalances, and can withdraw capital at risk using real-time on-chain monitoring and automated response systems. In other words, key control appears to be organized around publicly visible protocol roles and on-chain addresses, not hidden admin keys; however, the exact signing setup, multisig structure, or hardware key custody is Not verifiable as of 2026-09-04 from the available sources.

The materials also show that K3’s vault interactions are standard ERC-20 deposit/redeem flows, which implies users interact with share tokens rather than a custodial account operated by K3. A related announcement on Monad describes K3 managing LP supply and Galaxy borrowing demand through the vault infrastructure, reinforcing that K3 acts as allocator/operator at the strategy layer rather than as an off-chain custodian of user funds.

Evidence (3)

smart-contract

two sources

As of September 6, 2026 — confidence: low-to-medium; Dune unavailable. Contract-level role, proxy, and event verification is Not verifiable as of 2026-09-06. No Dune query/execution IDs are available; do not treat the following as on-chain verified. Known addresses / architecture

  • Unichain K3USDC MetaMorpho vault: 0xCfecBf93dEc86316F106712767828ACB5065C441; published timelock: 3 days.
  • Unichain K3 Capital ETH Maxi vault: 0xfA355999c12C63c465c591daf9C462e14ACf470b; Morpho UI reports Vault V1.1, deployment May 28, 2025, 3-day timelock, 10% performance fee.
  • No verified K3-specific addresses were located for Ethereum, Monad, Optimism, Plasma, Arbitrum, BSC, or BOB. Not verifiable as of 2026-09-06. Architecture map Depositors → MetaMorpho ERC-4626 vault → Morpho markets / approved strategies → underlying collateral and oracles Owner → Curator → Allocator(s) Guardian/Sentinel This is a curator-controlled vault model rather than one monolithic K3 lending contract. Morpho documentation describes Owner, Curator, Allocator, and Guardian/Sentinel powers, including strategy selection, caps, allocation, fees, and timelocked changes. Admin / user-risk assessment
  • Proxy implementation, proxy-admin type, owner/curator/allocator/sentinel addresses, renounced roles, pause functions, withdrawal gates, emergency withdrawal, upgrade authority, fee recipient, oracle/strategy setters, and measured timelock execution history: Not verifiable as of 2026-09-06.
  • Users generally do not require admin permission to redeem vault shares, but withdrawals depend on available idle/underlying liquidity; deployment-specific exit capacity is Not verifiable as of 2026-09-06.
  • Worst case if privileged keys are compromised: replacement of curator/allocators, risk-limit or strategy changes, fee-recipient changes, malicious allocation, liquidity impairment, or governance capture. Direct arbitrary draining is Not verifiable.
  • Audit evidence: Dedaub audited the sBOLD repository at a 2025 commit and identified “Owner is a trusted party”; this does not establish coverage of every K3 deployment. Contradiction / scope warning: DeFiLlama currently reports nine chains and includes Avalanche, while the supplied scope lists eight chains and omits Avalanche. The discrepancy is unresolved; aggregator data is not raw on-chain proof.
Evidence (5)

audit

two sources

Identified ChainSecurity audit of K3 Capital’s sBOLD smart contracts (Liquity-based ERC‑4626 vault). The report is hosted on ChainSecurity’s domain and clearly labeled for K3Capital / sBOLD. The scope focuses on accounting correctness, reentrancy risks, interactions with Liquity Stability Pools, price conversions, fees, and ERC‑4626 compliance.

A secondary independent aggregator (DefiCare) summarizes this audit as covering sBOLD Version 3, not the full K3 Capital platform. Date (as-of): DefiCare lists the ChainSecurity audit date as 19‑05‑2025. This is off-chain, aggregator-sourced data. Findings and severities:

  • DefiCare summary: 2 Critical, 3 High, 8 Medium, 11 Low, 3 Informational initially identified.
  • It states that all Critical, High, and Medium findings were resolved, with 2 Low-severity issues remaining open ("SP cannot be emptied" and "slippage tolerance extraction"), both described as unlikely to materialize or mitigated by Liquity’s design. Fix status: According to DefiCare, all Critical, High, Medium issues were fixed; two Low issues remain by design/mitigation rationale. This is not on-chain verified; status depends on the audit report and aggregator interpretation. Not verifiable as of 2026‑08‑29. Bytecode / deployed-code coverage:
  • The ChainSecurity PDF itself is a source-level review; none of the retrieved content explicitly confirms a formal bytecode match check against deployed contracts.
  • No explorer-based confirmation (contract verification plus matching commit hash) was retrieved in this run.
  • Therefore whether this audit fully covers the currently deployed sBOLD bytecode across Monad, Ethereum, Optimism, Plasma, Arbitrum, Binance, Unichain, BOB is Not verifiable as of 2026‑08‑29. Scope vs. protocol: All evidence points to this audit covering sBOLD, a specific yield strategy vault using Liquity/BOLD, not the entire K3 Capital protocol on all chains.
Auditor
ChainSecurity
Report date
2025-05-19
Scope
sBOLD ERC‑4626 Liquity yield vault; accounting, reentrancy, Stability Pools, price, fees, ERC‑4626 compliance
Evidence (2)

audit

two sources

Identified Dedaub smart contract audit of sBOLD, commissioned by K3 Capital. The report describes sBOLD as an ERC‑4626 implementation aggregating yield from interest accrual and liquidation penalties in Liquity. Date (as-of): DefiCare lists the Dedaub audit date as 19‑05‑2025. Dedaub’s own page is consistent with a 2025 report but the exact calendar date is taken from the aggregator, not from the PDF itself. Scope:

  • Dedaub states the audit covers contracts in the then-private GitHub repository https://github.com/K3Capital/sBOLD at commit 3630c7f6247b8fc8a709a9cfd036a90028fe0064.
  • Scope is limited to core sBOLD vault contracts, including ERC‑4626 behavior and interactions with Liquity (oracle pricing and BOLD liquidity are highlighted as design-level risks). Findings and severities:
  • DefiCare summary: 0 Critical, 0 High, 0 Medium, 1 Low, 0 Informational issues identified.
  • The single low‑severity issue was acknowledged by the team; the summary states the contract appears safe for deployment from a smart-contract perspective, while emphasizing remaining protocol-level risks (liquidity, oracles). Fix status:
  • DefiCare notes the low-severity issue was acknowledged; it does not clearly confirm if it was fully remediated in code.
  • Dedaub’s own narrative emphasizes that the audit cannot guarantee correctness and focuses on remaining design risks.
  • Specific fix status and post-audit code changes are Not verifiable as of 2026‑08‑29. Bytecode / deployed-code coverage:
  • Dedaub explicitly ties the audit to a source-code commit hash in the private repository.
  • There is no publicly retrieved evidence in this run that the deployed contracts on any chain were verified to match that commit byte-for-byte (e.g., via explorer verification or separate "bytecode match" section in the report).
  • Multi-chain deployment status (Monad, Ethereum, Optimism, Plasma, Arbitrum, Binance, Unichain, BOB) and whether all instances match the audited commit is Not verifiable as of 2026‑08‑29. Scope vs. protocol: Like ChainSecurity, Dedaub’s audit appears strategy-specific (sBOLD) and does not constitute a full-platform audit of all K3 Capital vaults and integrations.
Auditor
Dedaub
Report date
2025-05-19
Scope
sBOLD core ERC‑4626 contracts at GitHub commit 3630c7f6…; Liquity-based yield aggregation
Evidence (2)

audit

one source

ChainSecurity (Decentralized Security AG) — “Code Assessment of the sBOLD Smart Contracts.” Published May 19, 2025. Scope: sBOLD repository source files across Versions 1–3, with final reviewed Version 3 commit e52e34078faa2238846a637cbf6263396e7363e6. Liquity V2, third-party libraries, scripts, and tests were excluded.

Bytecode match to deployed contracts: Not verifiable as of September 6, 2026.

Auditor
ChainSecurity (Decentralized Security AG)
Report date
2025-05-19
Scope
sBOLD smart contracts, including BaseSBold, sBold, SwapLogic, SpLogic, QuoteLogic, oracle contracts, interfaces, and libraries listed in the report; final reviewed Version 3 commit e52e34078faa2238846a637cbf6263396e7363e6. Liquity V2, third-party libraries, scripts, and tests excluded.
Findings
Critical: 2; High: 3; Medium: 8; Low: 11; Informational: 2. At publication, open findings were: Critical 0, High 0, Medium 0, Low 2 — (1) withdrawals may fail because a Stability Pool cannot be emptied; (2) profit can be extracted through slippage tolerance. The remaining 9 Low findings and both Informational findings were code-corrected.
Fix status
All Critical, High, and Medium findings were code-corrected. Low findings: 9 corrected and 2 acknowledged/open. Informational findings: 2 corrected. The report states Version 3 provides a good level of security, but does not prove that deployed contracts on each listed chain match the reviewed commit.
Report url
https://www.chainsecurity.com/reports/K3Capital/ChainSecurity_K3Capital_SBOLD_Audit.pdf
Report id
doc:ae5e385e9d13cd0b
Unresolved critical
0
Unresolved high
0
Evidence (2)

Team & Reputation

founders

two sources

K3 Capital in DeFi appears to be a crypto-native institutional asset manager and risk curators protocol, not a typical anonymous retail DeFi project. ### Founders & Key People Independent aggregator DefiCare lists a detailed team for K3 Capital (DeFi):

  • Kiril Nikolov – Co-founder (public identity).
  • Simeon Rusanov, CFA – Chief Investment Officer (public, traditional finance credential).
  • Valentin Mihov – Chief Technology Officer.
  • Gryndamere – Head of Asset Management (pseudonym; suggests at least one semi-anon senior member).
  • Elena Sabkova, Esq. – General Counsel (public/legal professional).
  • Plus multiple operations and engineering staff with LinkedIn profiles. The presence of a co-founder, CIO with CFA, CTO, and General Counsel with professional profiles indicates a largely public, non-anonymous management structure with some pseudonymous contributors. ### Track Record & Prior Activity
  • DefiCare states K3 Capital has been deploying non-directional DeFi strategies since 2021 for crypto-native institutions and HNW investors.
  • Products cited include sBOLD, Gearbox credit accounts, rsUSDe, and Euler-based lending markets, indicating prior hands-on involvement with major DeFi primitives.
  • A risk report by Hindenrank describes K3 Capital as founded in 2021, managing over $250M in assets across curated vaults on Euler, Morpho Blue, and related protocols (aggregator claim). No evidence of a protocol-specific hack or rug involving K3 Capital itself was found; however they operate on top of protocols that have their own incident histories (e.g., Euler in 2023), so secondary exposure risk is structural rather than originating from K3. ### Public vs Anon, Office, Jurisdiction
  • Multiple executives have LinkedIn presences and job titles consistent with an institutional setup.
  • K3 Capital describes itself as an institutional-grade asset manager; jurisdiction, registered entity, and office address are not independently verifiable from the retrieved data.
  • As of 2026-09-04: Not verifiable as of 2026-09-04 whether the on-chain K3 Capital protocol is operated through a specific regulated entity, where its office is located, or whether it is onshore/offshore. ### Reality Check
  • Real business vs web front: presence on professional platforms, multi-person team with defined roles, and multi-year institutional strategy suggest a real operating business, not a pure front.
  • However, all of this is aggregator-sourced; without on-chain ownership traces or corporate registry data tied explicitly to the DeFi contracts, key aspects of control, legal structure, and physical office remain Not verifiable as of 2026-09-04. ### Name Collision Separate "K3 Capital Group" in UK corporate/finance media refers to a different, traditional corporate finance firm, not the DeFi protocol; this must not be conflated with the DeFi K3 Capital.
Evidence (10)

general reputation

two sources

K3 Capital currently has a generally positive, institutional-facing reputation, with multiple independent audits and no public fraud/rug/insolvency or sanctions allegations identified. Not verifiable as of 2026-09-04 whether *all* on-chain deployments across the listed chains match the web data. Team, history, positioning

  • Described by independent data providers as an institutional-grade asset and risk manager running non-directional DeFi strategies since 2021, serving crypto-native institutions and HNW investors.
  • Runs curated lending/yield vaults on protocols such as Euler, Morpho, Liquity, IPOR, Term Finance, and similar, with focus on risk underwriting and borrower screening.
  • A July 2026 article notes K3 Capital is a BVI-registered investment fund and spin-off from a large centralized digital-asset lender/asset manager, further reinforcing institutional positioning. Audits and security reputation
  • Smart contracts for the sBOLD ERC‑4626 vault have been audited by Dedaub and ChainSecurity, both recognized auditors in DeFi.
  • ChainSecurity’s latest report (Version 3) concludes security is “good,” with prior issues around Liquity V2 stability pools, price conversions, fees, and ERC‑4626 compliance remediated, leaving only a minor integration concern.
  • The protocol’s own materials emphasize audited vaults and economic/OpSec risk review, but these are self-descriptions and therefore “unverified marketing claims.” Investors, institutional relationships
  • K3 Capital manages structured funds (Absolute USD Return, Enhanced ETH, BTC Yield) and segregated managed accounts for institutional allocators.
  • It has launched a $30m on-chain credit facility for Galaxy on Monad, targeting $100m, via Accountable’s verification infrastructure and YieldApp marketplace, signalling acceptance among major institutional DeFi players. Sentiment, criticisms, risk flags
  • Coverage on specialist data/analysis sites (DefiLlama, DefiCare, TradingStrategy, MrDeFi, Hindenrank, DappDeFi) is neutral-to-positive, framing K3 as a risk-curating, non-custodial yield/credit manager; no major negative exposés are evident.
  • No public reports of rug pulls, insolvency events, or regulatory enforcement actions were found in recent news to date. Not verifiable as of 2026-09-04 whether any non-public regulatory inquiries exist.
  • Key unresolved concern: absence of transparent, verifiable on-chain aggregates for TVL across all claimed chains (Monad, Optimism, Arbitrum, BNB, Unichain, BOB, Plasma, Ethereum) in the current data set — "Not verifiable as of 2026-09-04."
Evidence (15)

Economy

TVL: $502.8M

model

two sources

Economic model (as of September 6, 2026)

  • Strategy/assets: K3 is a risk-curator layer, not a single lending market. Deposits appear to include stablecoins, ETH/LSTs and structured assets; displayed vaults route funds to Euler, IPOR, Upshift and Liquity. This is partly an unverified marketing claim where sourced only from K3-controlled interfaces. Current examples include rsETH, NUSD, BOLD, EUROP, USDT and USDT0 vaults.
  • Yield source: underlying lending interest, liquidity/credit-market spreads, structured-credit interest and, in some products, restaking or incentive income. Yield is therefore mixed: organic lending/borrower yield plus potentially subsidized emissions/points. organic_yield_pct: null; no independent decomposition was found.
  • Risk posture: generally market-neutral in stated intent for stablecoin/credit strategies, but not uniformly neutral. Vaults can carry collateral, borrower, stablecoin-depeg, smart-contract and external-protocol exposure. An IPOR syrupUSDT product explicitly uses looping/leverage; the portfolio-wide or product-specific maximum is Not verifiable as of September 6, 2026. leverage_ratio: null.
  • Restaking/external exposure: present in at least some ETH/LST strategies; external exposure includes Euler, IPOR, Liquity, Upshift/structured-credit venues and their collateral/borrowers. Lock-ups, withdrawal queues, utilization gates, caps and emergency redemption mechanics are product-specific; Not verifiable as of September 6, 2026.
  • Fees/revenue: DeFiLlama reports 30-day fees of $777,010, protocol revenue of $76,063, and cumulative revenue of $1.05m. This implies substantial pass-through to strategy providers/depositors rather than high fee capture.
  • TVL: DeFiLlama reports $430.82m, up 9.9% over 30 days: Monad $311.25m (72.2%), Ethereum $109.75m (25.5%), Optimism $6.16m, Plasma $2.05m, Arbitrum $1.25m, BSC $335.9k, Unichain $21.4k and BOB $11.3k. Avalanche is also listed at $0, creating a chain-scope discrepancy versus the user-provided list. Product-level TVL and APY history/volatility are Not verifiable as of September 6, 2026. Dune: unavailable in this run; Dune-vs-DeFiLlama reconciliation, on-chain TVL, collateral, leverage and withdrawal-flow checks are Not verifiable as of September 6, 2026.
Evidence (4)

reserves

two sources

Assessment — as of September 6, 2026 Liquid reserves / treasury size: Not verifiable as of 2026-09-06. No protocol-specific reserve wallet set, treasury balance, or reserve NAV was identified. K3 Capital’s reported approximately $400 million AUM is an asset-management figure, not evidence of liquid treasury reserves or proprietary capital. On-chain balances via Dune: Not verifiable as of 2026-09-06.

Dune MCP was unavailable for this run; no on-chain balances or block-height snapshot is asserted. Addresses and composition: Public third-party records identify K3-curated product/vault contracts, not a separate treasury. Examples include K3 Capital USDai Cluster vaults on Arbitrum—USDC 0x6aFB8d3F6D4A34e9cB2f217317f4dc8e05Aa673b, USDT0 0x482C3E2530FAc8FE2c63AE007AD2695C6d685E98, USDai 0x7D9790403FA53eF3E3a3389c259D244BDc61B785, and sUSDai 0xAABb9cbAC15a3D646dCdc6574bCFCfB989E1fDd8; Plasma product vaults are also listed. These are user-facing lending/strategy vaults and must not be treated as treasury wallets.

A separate Avalanche K3 Capital Cluster vault is listed at 0x6fc9b3a52944a577cd8971fd8fde0819001bc595, denominated in USDC, with third-party reported TVL of 47,877.771 USDC as of September 4, 2026. This is vault TVL—not liquid reserves—and is stale relative to this assessment date. Custody/control: Not verifiable as of 2026-09-06. Available records show K3 as curator/governor for some vaults, but do not establish treasury ownership, signer topology, multisig/security-module control, or withdrawal authority. Reserve policy / attestations: Not verifiable as of 2026-09-06.

No independent reserve attestation, proof-of-reserves, audited treasury statement, or binding reserve policy attributable to K3 Capital was located. Contradiction / risk note: Reported AUM and vault TVL should not be conflated with reserves. The evidence supports managed third-party/user capital, not a verified K3 treasury balance. Structured fields:

  • liquid_reserves_usd: null
  • liabilities_usd: null
Evidence (3)

tokenomics

two sources

K3 Capital currently operates without a native / governance token, so most of the requested tokenomics dimensions do not apply in the usual sense. ### Native token, supply, market cap

  • Multiple independent sources explicitly state that K3 Capital has no publicly traded governance token and no protocol-native token.
  • Because there is no native token, there is no contract address, ticker, total vs. circulating supply, market cap, or FDV for a K3 governance/utility asset.
  • A BEP‑20 token named k3_capital exists on BSC (address 0xD62833E793020C7AD17aE4b7bBD46779E62fA032), but it appears to be an unrelated generic token; its description and 2020 usage claims clearly do not match the K3 DeFi protocol founded later, so it should be treated as a namesake / non-official asset, not the K3 Capital protocol token. ### Token utility, governance, and revenue share
  • Governance: K3 Capital’s platform is described as operating without tokenized governance; decisions are made off-chain by the firm rather than token holders.
  • Utility: Users interact with existing ERC‑20 tokens (USDT, USDT0, NUSD, BOLD, EUROP, rsETH, etc.) as deposit and share tokens in vaults; these are not native K3 tokens, but underlying strategy assets or vault receipts.
  • Revenue: The business model is fee-based, with yield strategies generating fees for K3 as an asset manager; there is no token-based revenue share, buyback, or burn mechanism for a K3 native token. ### Emissions, unlocks, allocations, insider concentration
  • With no native token, there is:
  • No emissions schedule or vesting/unlock calendar.
  • No team/investor/treasury/community token allocation.
  • No insider token-holder concentration metrics.
  • Any unlock / vesting events claimed in marketing cannot be evaluated because there is no on-chain governance token. "Not verifiable as of 2026-09-04". ### Control functions (mint/blacklist/fee switch)
  • Since there is no protocol-native token, questions about minting, blacklisting, or fee-switch roles for such a token do not apply.
  • Risk assessments emphasize that all upside and control accrue to the private company, not to on-chain token holders. ### DEX liquidity and listings
  • There are no major DEX listings for a K3 governance token because none exists.
  • Liquidity depth is therefore evaluated at the vault asset level (USDT, rsETH, NUSD, BOLD, EUROP, etc.), not at a K3-native token level; detailed on-chain liquidity metrics are "Not verifiable as of 2026-09-04" under current tool constraints. Overall, K3 Capital should be treated as a tokenless, fee-based DeFi asset manager / yield platform, where risk and economics reside in off-chain corporate equity and vault fee structures, not in a tradable protocol token.
Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Not verifiable as of 2026-09-04. I could not confirm any K3 Capital on-chain positions, treasury balances, vault exposures, or liquidation mechanics from the available web results, so I cannot quantify protocol-specific losses if Bitcoin falls below $10,000. The only relevant external evidence indicates that a $10,000 BTC scenario is generally treated by market commentators as an extreme tail-risk outcome, not a base case, and would likely require a synchronized macro/liquidity shock and forced deleveraging regime.

For K3 Capital specifically, the stress impact depends on whether it holds BTC directly, has BTC-collateralized debt, or writes structured products, but that exposure is not verifiable from the sources available here. Any claim about K3 Capital’s solvency, TVL, or liquidation thresholds would therefore be unverified marketing claim or speculation.

Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-09-04. No on-chain or protocol-specific data was provided to identify K3 Capital’s collateral set, chain-by-chain exposure, or largest collateral asset, so a 20% depeg stress cannot be quantified reliably. If you want a conservative framing, the only defensible statement is that a 20% depeg in the largest collateral would reduce the mark-to-market value of that collateral by 20%, but the resulting effect on protocol solvency, liquidation risk, or bad debt is not verifiable from the available sources.

Evidence (2)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

If K3 Capital’s top counterparty (borrower or underlying protocol) becomes insolvent, the expected loss is primarily borne by vault depositors; K3 absorbs losses only to the extent of any explicit guarantees or co-invested capital, which current public materials do not evidence clearly. ### 1. Loss path when the main borrower (e.g. Galaxy on Monad) defaults

  • Trigger: Galaxy fails to repay principal and interest on the AUSD credit facility managed by K3 via Accountable on Monad.
  • On‑chain effect:
  • Loan position in the Monad credit vault remains under‑collateralized or in default; interest stops accruing.
  • Vault’s claim on Galaxy is economically worthless or impaired, reducing the net asset value (NAV) per vault share.
  • Who absorbs loss:
  • Vault LPs (institutional allocators) holding the tokenized vault shares take a direct hit via lower redemption value.
  • K3, as manager, continues to earn fees only on remaining positive NAV; it does not automatically backstop principal – no public evidence of a capital guarantee.
  • Compensation:
  • Any recovery is via enforcement of loan terms (legal recourse against Galaxy) and potential on‑chain collateral realization if structured; details are Not verifiable as of 2026‑09‑04.
  • No disclosed insurance or protocol‑level compensation pool for LPs.
  • Smart‑contract impact path:
  • Vault share token contract continues to function; price per share (exchange rate) falls as bad debt is recognized in accounting feeds feeding the vault UI and oracle layers.
  • Redemption rules (e.g. max 30% monthly redemptions) can slow loss crystallization but cannot remove economic loss. ### 2. Loss path when an underlying lending venue (e.g. Euler / Morpho / Term Finance) is insolvent or exploited
  • Trigger: Major protocol K3 uses for lending becomes insolvent (bad debt or smart‑contract exploit).
  • On‑chain effect:
  • Assets supplied by K3‑curated vaults to that venue become unrecoverable or heavily impaired.
  • Strategy vaults on Ethereum, Avalanche, BNB and other chains mark down their asset value.
  • Who absorbs loss:
  • End‑user depositors in each K3‑curated vault (USDT, RSETH, NUSD, BOLD, etc.) lose proportionally to that vault’s exposure to the failed venue.
  • K3’s funds and segregated accounts holding the same strategies also absorb losses at the fund level.
  • Compensation:
  • Any protocol‑side rescue, governance‑fund payouts, or white‑hat recovery would flow first to creditors of the failed venue, indirectly benefitting K3 vaults; no guaranteed make‑whole.
  • Absence of explicit insurance / guarantee remains Not verifiable as of 2026‑09‑04.
  • Smart‑contract impact path:
  • K3 vault contracts keep operating; share tokens remain transferable.
  • Yield stream from the failed venue stops; vault accounting marks down NAV, making losses visible in APY and share‑price data on analytics platforms. ### 3. Cross‑chain propagation
  • Insolvency on one chain (e.g. Monad credit facility, Ethereum lending) does not mechanically affect other chains’ vault contracts, but multi‑chain portfolios and aggregated TVL drop, and K3’s overall fee income and perceived safety deteriorate.
  • Reputational shock can trigger redemptions across chains, forcing unwinds of otherwise healthy strategies and amplifying realized losses for remaining LPs.
Evidence (15)

stress scenario - committed fraud by the DAO or owners

two sources

Not verifiable as of 2026-09-04. I did not find credible evidence that K3 Capital’s DAO or owners committed fraud. The only directly relevant result is K3 Capital’s own social/profile claim that it is a DeFi risk-management firm, which is not sufficient to verify or disprove misconduct and should be treated as an *unverified marketing claim*. The other search results are generic DAO-fraud/exploit references or concerns about unrelated protocols and do not establish fraud by K3 Capital.

For a stress scenario, the prudent risk view is that a *credible fraud allegation* against the DAO or owners would likely cause immediate loss of trust, redemptions, counterparty de-risking, and possible legal/regulatory action. That conclusion is an inference from how DAO fraud and governance attacks can lead to asset loss, project disruption, and collapse, as described in investigative and regulatory materials on DAOs. I cannot verify K3 Capital’s on-chain treasury, governance control, or owner wallet relations in this run because on-chain checks are unavailable; those items remain Not verifiable as of 2026-09-04.

Evidence (7)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario, the key assumption is that K3 Capital’s primary yield source has a negative 30-day return. Because I could not verify K3 Capital’s on-chain yield composition or 30-day performance from the provided web results, the correct treatment is to mark the yield shock as Not verifiable as of 2026-09-04 and avoid assigning a numeric drawdown impact. Operationally, this means the portfolio should be analyzed as if its main carry engine is under pressure from a negative short-term yield realization, which can compress NAV, reduce fee income, and force rebalancing if the strategy depends on continuous positive accrual.

However, without verified protocol-level data, the size of the exposure, the specific chain mix, and whether the loss comes from lending APY compression, incentive decay, or mark-to-market losses remain Not verifiable as of 2026-09-04. If you want, I can next build a concise risk memo framework for K3 Capital covering downside channels, liquidity risk, and what evidence would be needed to confirm the stress case.

Evidence (2)

Governance & Legal

governance

two sources

As of September 13, 2026, K3 Capital appears company-controlled rather than DAO-controlled. K3’s own company page says governance is “intentionally minimal”: major decisions are discussed publicly but implemented by the team; on-chain governance is only planned. Independent risk analysis likewise reports no governance token and says curator decisions and emergency actions remain with the internal team.

Therefore, DAO governance is symbolic/not operational, not a control layer. Control map: the K3/internal team appears to control risk parameters, vault allocations, integrations, frontend and operational decisions. K3 is described as non-custodial, so user assets are generally held in underlying protocol contracts rather than by K3 directly; however, exact admin, upgrade, curator, pause and emergency powers for every deployed contract across Monad, Ethereum, Optimism, Plasma, Arbitrum, BNB Chain, Unichain and BOB are Not verifiable as of September 13, 2026. Contradiction / gap: K3 markets transparency and public on-chain parameters, but the governance page expressly says implementation remains team-led and future on-chain governance is not yet deployed.

DIA’s aggregator reports 0% multisig use and 0% timelock coverage for its indexed vaults, but this does not establish governance for all contracts or chains. Exact multisig signers, threshold, independence, timelock delay, top holders and voting concentration via Dune: Not verifiable as of September 13, 2026. Dune was unavailable.

A public BVI record identifies K3 Capital Management Inc., registration number 2187294, incorporated September 15, 2025; director names were not available in the reviewed sources, and its contractual identity as the K3 DeFi operator is Not verifiable as of September 13, 2026. The referenced Terms of Service PDF was inaccessible and redirected to the JavaScript app.

Timelock
No
Dao governance
No
Evidence (5)

legal & regulatory

unverified

Not verifiable as of 2026-09-04. The web results did not surface any authoritative legal/disclosure page for K3 Capital that identifies a clear incorporated entity, governing jurisdiction, or formal customer terms/privacy policy. The only directly relevant protocol page found was an investor-portal/edge page describing onchain address visibility, which is not a legal disclosure.

No verified evidence was found of KYC/AML requirements, regulatory classifications, court cases, or sanctions against the protocol/entity itself. Because no confirmed legal entity was identified, sanctions status for the protocol/entity cannot be verified. Legal structure vs actual risk remains unverified: from the available evidence, K3 Capital appears to operate as a DeFi asset manager/protocol with onchain activity, but its formal legal wrapper, if any, is not established in the sourced material.

Evidence (1)

legal registries

two sources

Legal entity per GLEIF: K3 Capital LLC (LEI 254900JFH3TSH6YQ6309; jurisdiction US-KS; registration ACTIVE). OFAC SDN screening of 'K3 Capital': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • K3 Capital
Entity
K3 Capital LLC
LEI
254900JFH3TSH6YQ6309
Jurisdiction
US-KS
Entity status
ACTIVE
Sanctioned
No
Evidence (4)

Stability

stability

two sources

K3 Capital does not appear to issue its own native stablecoin; the available evidence shows it uses third-party stablecoins and wrappers such as BOLD/sBOLD, USDe, USDC, USDT, USDT0, EURC, AUSD, and related vault products. The only depeg event found in the available web evidence is deUSD, which was associated with Elixir and cited in K3-related coverage as a counterparty issue, not a K3-issued stablecoin. Therefore, a K3 Capital stablecoin depeg history is not verifiable as of 2026-09-06.

Own stablecoin
No
Depeg count
0
Evidence (3)

Risks & Strengths

risks

two sources

K3 Capital’s principal risks are privileged administration, dependency on underlying protocols, oracle/valuation failure, incomplete audit coverage, and liquidity or chain concentration. The public evidence is strongest for the audited sBOLD implementation; broader multi-chain exposure and current chain allocation are not fully independently verifiable as of September 5, 2026. Contradiction: the supplied scope lists 8 chains, while DeFiLlama currently reports 9 chains and includes Avalanche; the authoritative current allocation is Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Privileged owner controlThe audited sBOLD owner can configure oracle registries, swap adapters, fees, slippage, rewards, and allocation parameters. A compromised or malicious administrator could manipulate valuation, execute harmful external calls, or impair withdrawals.HighMediumParameter bounds, audit remediation, and documented owner controls are present.High residual trust and key-compromise risk; multisig, timelock, signer set, and monitoring are Not verifiable as of September 5, 2026.
Underlying protocol dependencysBOLD deposits into Liquity V2 Stability Pools; Liquity V2, third-party libraries, and external protocol behavior were outside ChainSecurity’s scope. A failure, insolvency, shutdown, or adverse collateral event can transmit losses.HighMediumDiversification across Stability Pools and collateral-exposure limits are implemented in sBOLD.High dependency risk remains; independent stress testing and loss backstops are Not verifiable as of September 5, 2026.
Oracle and valuation failureIncorrect, stale, manipulated, or unavailable collateral prices can misprice shares, trigger incorrect slippage controls, or block swaps and withdrawals. The audit explicitly treats accurate and timely oracle reporting as an assumption.HighMediumOracle registry architecture, price-validity/staleness checks, and multiple adapter types are documented.Medium-to-high residual risk from oracle governance, feed availability, and configuration changes.
Incomplete audit coverageThe public ChainSecurity assessment covers sBOLD code versions, not the complete K3 Capital multi-chain deployment, all vaults, integrations, bridges, or production configurations. Audit findings cannot establish whole-protocol safety.HighHighChainSecurity and Dedaub assessments exist for sBOLD; several identified critical, high, and medium findings were corrected.High: full deployment inventory, current bytecode matching, continuous monitoring, and a live bounty are Not verifiable as of September 5, 2026.
Liquidity and chain concentrationLarge TVL concentration on a small subset of networks or vaults could make exits, rebalancing, or incident containment difficult during congestion, bridge outages, oracle failure, or collateral liquidation.HighMediumMulti-chain deployment and collateral-exposure thresholds provide some diversification and operational controls.High: current per-chain and per-vault concentration is Not verifiable as of September 5, 2026; DeFiLlama’s chain count conflicts with the supplied scope.
Evidence (4)

strengths

unverified

K3 Capital’s top strengths are: (1) non-custodial design, since the platform says users keep control of assets and the protocol holds nothing off-chain; (2) multi-protocol yield routing, because it aggregates opportunities across venues like Euler, Morpho, IPOR, and Liquity to seek better rates from one interface; (3) transparency, with on-chain-readable parameters, fee schedules, and vault allocations; (4) capital-efficiency and gas optimization, including batch operations and calldata compression to reduce costs; and (5) institutional-grade risk curation, with a stated focus on underwriting risk, maintaining curated markets, and publishing research and dashboards.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 25 two independent sources, 7 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-29.