Level

Orange · 63/100

Executive summary

Level is a yield-bearing stablecoin protocol on Ethereum issuing lvlUSD backed by USDC/USDT in lending venues; it scores 59/100 (orange band) and is currently in wind-down/redeem-only mode.

  • Security: Multiple audits by 0xMacro, Pashov, Spearbit Cantina, and Zellic; 0xMacro v2 audit found 0 critical/high, 7 medium (5 addressed, 2 acknowledged), and 5 low issues; Pashov v2 audit found 1 high and 5 medium (all resolved); Cantina staking audit found 6 medium (all acknowledged, 0 fixed); critical findings in earlier lvlUSD v1 audit were fixed and verified. Bug bounty on Cantina is no longer active (max $200k).
  • Incidents: August 2025 X account compromise via phishing; malicious links posted, account recovered in ~18 hours; user losses and reimbursement status are not verifiable as of September 2026. No protocol-level smart-contract exploit confirmed for this Ethereum protocol.
  • Governance & custody: No DAO; controlled by a 5-of-8 admin Gnosis Safe (4 internal, 4 external signers, identities unverified), separate 2-of-5 operator Safe, and 3-of-4 treasury Safe. Admin can upgrade contracts, change oracles/assets, pause/unpause, and authorize vault exits (admin_can_drain = true). Timelock exists but delay not disclosed.
  • Top risks: Protocol is being sunset—minting paused, redemption window finite; if contracts/frontend/liquidity fail, holders face delayed recovery. USDC/USDT depeg or issuer freeze would impair reserves. Aave/Morpho insolvency or exploit would cause reserve loss with no verified insurance fund. Acknowledged medium findings in staking audit (cooldown, blacklist, freeze logic) remain unresolved. Current reserves, liabilities, and contract state are not verifiable as of September 2026 (Dune unavailable, transparency page shows $0).
  • Strengths: Fully on-chain, DeFi-native design with transparent yield mechanics; composable with major DeFi venues; backed by institutional investors (Dragonfly, Polychain); multiple auditors engaged; multisig controls and role separation documented.
  • Unverified: Reserve composition, TVL, exact collateral split (USDC/USDT/Aave/Morpho), deployment coverage of audits, signer identities, timelock delay, legal entity/jurisdiction, KYC/AML policy, current yield (claimed negative 30d not confirmed), user losses from X compromise, and whether shutdown/redemption process is complete.
  • Recommended exposure: Avoid new positions; protocol is in wind-down with no new minting. Existing holders should verify redemption eligibility and timeline via contracts (frontend sunset December 15, 2025) and monitor reserve solvency independently. Size any residual exposure as high-risk/illiquid given unverified reserves, acknowledged audit findings, and counterparty concentration in Aave/Morpho.
  • Open questions: Confirm current on-chain reserves and liabilities; verify admin multisig signer identities and independence; check whether all users have redeemed or if funds remain locked; validate Aave/Morpho exposure and any restaking positions; review unresolved medium findings (cooldown bypass, blacklist, freeze) and assess operational risk during wind-down.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 8 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 50 10.0 last full audit 2025-08-01 is older than a year
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $459,978 = 0% of reference ($17,538,184,136)
Data confidence 85 7/7 critical categories; 12/45 verified facts; 45/45 fresh (180d)

Identification

protocol identification

two sources

Level (often branded Level Money) is a yield-bearing stablecoin protocol issuing lvlUSD backed by USDC and USDT deposited in DeFi lending protocols; it is currently in *redeem‑only wind‑down mode*. ### Identification

  • Name: Level / Level Money stablecoin protocol.
  • Website: level.money.
  • Docs: GitBook at level-money.gitbook.io/docs (Level Overview, protocol description).
  • Category: DeFi stablecoin / yield-bearing stablecoin backed by lending protocol deposits.
  • Chains: Your query specifies Ethereum; independent confirmation of deployed contracts/TVL per chain is Not verifiable as of 2026‑09‑03 (no on-chain tools available this turn).
  • Core assets:
  • lvlUSD – fully backed by USDC and USDT reserves in “blue‑chip” lending protocols; users earn yield via staking.
  • slvlUSD – ERC‑4626 vault token representing staked lvlUSD that appreciates as yield is passed through.
  • Current mode: Protocol is “being wound down” and now in redeem‑only mode; no new lvlUSD can be minted, redemptions open via app interface until December 15, 2025.
  • Launch date: Public docs describe design and mission but do not clearly state a mainnet launch date; based on dated documentation (April 2025 GitBook intro), precise launch timing is Not verifiable as of 2026‑09‑03. ### Main contract addresses & verification
  • Specific Ethereum contract addresses for lvlUSD, slvlUSD, and treasury/lending routers:
  • Not verifiable as of 2026‑09‑03. I cannot run on‑chain queries or cross‑check explorers this turn.
  • Explorer verification status (source‑code verified vs. not) for these contracts is likewise Not verifiable as of 2026‑09‑03. ### Fork lineage
  • Docs describe Level as a purpose‑built protocol using lending yield to back lvlUSD and an ERC‑4626 staking vault; no mention of being a fork of another stablecoin (e.g., Liquity, Maker, etc.).
  • Analytics and documentation sources characterize it as its own design; I found no credible evidence that Level Money is a direct fork of a specific upstream protocol.
  • Because code repositories, audits, and upstream comparisons cannot be checked on‑chain or via GitHub this turn, the following remain Not verifiable as of 2026‑09‑03:
  • Whether Level is partially forked from an existing protocol.
  • What was changed vs. any upstream.
  • Whether those changes were audited.
  • Any malicious‑modification history in similar forks. ### Confusion guard: Level vs. Level Finance
  • Separate product Level Finance (perpetual DEX with LVL/LGO/LLP on BNB Chain) is a different protocol.
  • For this analysis, “Level” = Level Money lvlUSD stablecoin, not Level Finance.
Evidence (7)

maturity

two sources

Level’s site is not just a landing page: the app and documentation are live, and the app page explicitly supports farm deposits and withdrawals. The docs also say Level was put into redeem-only mode and direct withdrawals/redemptions were available via the app and, later, via contracts after frontend sunset, which indicates a real product lifecycle rather than a static marketing site. The product now appears to be in wind-down/sunset mode, not active growth mode: the homepage says the team is joining another DeFi protocol and is sunsetting the product, and the community update says the frontend would remain live only until December 15, 2025, after which users could still interact with contracts directly to unstake/redeem.

I do not see strong signs of fake metrics in the retrieved sources, but any TVL or usage figures are Not verifiable as of 2026-09-03 because on-chain verification is unavailable in this run. The docs and app pages do show concrete user flows, cooldowns, and redeposit/withdraw steps, which is a positive maturity signal. An open API does not appear to exist for the DeFi protocol itself; the retrieved API reference is about a different “Level” product unrelated to DeFi, so it is not a valid match.

Therefore, an open API for this protocol is Not verifiable as of 2026-09-03.

Evidence (6)

Security

bug bounty

two sources

Level had a bug bounty program on Cantina, but the Cantina listing says it is not live anymore. It started on 29 Apr 2025. The program covered smart contracts and other components, required a first-to-report, previously unknown vulnerability plus sufficient reproduction detail, and barred malicious exploitation or prior disclosure.

Reported findings on the Cantina page: 40. For smart contracts, the bounty table showed Critical up to $200,000, with additional tiers of High up to $25,000, Medium up to $2,500, and Low discretionary; the Level docs also state payouts are handled by the LEVEL team and denominated in USD, with payouts distributed in LVL tokens. The earlier Immunefi bug bounty docs show a separate program history with websites/apps live since 21 Feb 2023 and smart contracts live since 10 May 2023, but the currently visible active bounty page is Cantina.

Active
No
Platform
Cantina
Max payout
$200K
Since
2025-04-29
Evidence (3)

counterparty risks

two sources

Состояние на 5 сентября 2026 г. Dune/ончейн-проверка недоступна: Not verifiable as of 2026-09-05. Поэтому доли экспозиции, фактический состав резервов, адреса контрактов, состояние админ-ключей и активность дефолтов не подтверждены. Внешние зависимости и сценарии отказа

  • Aave и Morpho: публичная документация Level указывает, что резервы lvlUSD направляются в Aave и Morpho Steakhouse Vault; это создаёт риск бага/эксплойта, плохих параметров рынка, потери ликвидности, oracle/price-событий и задержек вывода. Данные документации старше 7 дней и являются заявлением протокола, поэтому это unverified marketing claim.
  • Restaking: заявлялась небольшая экспозиция к Symbiotic; документация говорит о выводе restaked-активов, но фактическая доля не проверена. Риски: slashing, отказ оператора/AVS, задержка withdrawals и корреляция с ликвидностью базовых receipt-токенов.
  • Оракулы и манипуляция: аудит LevelReserveLens/BoringVault описывает риск, при котором сторонний контроль залога в EigenLayer может исказить reserve/oracle-оценку и спровоцировать ликвидацию. Это аудиторский сценарий, а не подтверждённый текущий инцидент.
  • Стейблкоины: lvlUSD заявлен обеспеченным USDC и USDT. Следовательно, присутствует риск depeg, заморозки/санкционного действия эмитента, банковско-резервного риска USDC и контрагентского риска USDT. Фактическая пропорция USDC/USDT — Not verifiable as of 2026-09-05.
  • Мосты, CEX/MM, кастодианы, RWA/SPV, LST: для Ethereum-резервов прямая bridge-зависимость не подтверждена; LayerZero упоминается как интеграция/композируемость, не как доказанная резервная зависимость. Экспозиция к CEX, маркет-мейкерам, кастодианам, RWA-эмитентам/SPV и LST не подтверждена: Not verifiable as of 2026-09-05.
  • Ликвидность и управление: документация указывает redeem-only режим и permissioned redemptions — потенциальный риск gate/withdrawal freeze при стрессе. Сценарии: потеря Aave/Morpho или depeg USDC/USDT может привести к неполному обеспечению lvlUSD; oracle/restaking-сбой — к неверной оценке резервов и каскадной ликвидации; задержка redemptions — к торговле lvlUSD ниже $1. Аудиты снижают, но не устраняют smart-contract и governance-риск; в опубликованных материалах также отмечены acknowledged findings.
Evidence (5)

crypto custody

one source

Level organizes custody through multiple separate Gnosis Safe multisigs rather than a single custodian. Its security docs describe an admin multisig as a 5-of-8 Safe with cold-wallet signers and external security-firm approval, an operator multisig as a separate 2-of-5 Safe for low-risk operational tasks that is not responsible for handling protocol funds, and a separate protocol treasury multisig as a 3-of-4 Safe for rewarding staked lvlUSD, also with cold-wallet signers. This points to segmented control of protocol functions, but not clearly segregated customer assets in the legal/custodial sense.

Withdrawal pause status is not verifiable as of 2026-09-05 from the gathered sources.

Evidence (2)

incident

unverified

Separate from the current Level protocol, search results also mention an older 'Level Finance' exploit in 2023 described as a software-bug incident with roughly $1 million lost and customer reimbursement promised. Because the search result does not confirm it is the same Ethereum protocol identified by the user, it should be treated as a possible namesake/fork and is not verifiable as the queried protocol.

Date
2023-05
Cause
Smart-contract exploit
Loss
$1.0M
Evidence (1)

incident

two sources

Level Money’s official X account was compromised through a phishing email impersonating X Support. The attacker reset credentials, removed delegates, and posted malicious wallet-draining links. The team detected the breach quickly, warned users via Discord/Telegram, reported the links, contacted security partners and X, and regained full account control after approximately 18 hours.

Planned remediation included stricter access controls, multi-layer authentication, enhanced monitoring, improved incident-response procedures, and closer coordination with X. Users who believed they were affected were directed to open Discord support tickets. The number of affected users, any confirmed user losses, attacker proceeds, recovered funds, and reimbursement outcome are Not verifiable as of September 5, 2026.

The previously reported May 2023 Level Finance referral-contract exploit occurred on BNB Chain and is a separate namesake protocol, not the queried Ethereum Level Money protocol.

Date
2025-08
Cause
Key compromise
Status
resolved
Evidence (3)

key management

unverified

Not verifiable as of 2026-09-03. The provided search results do not include Level-specific documentation, audits, governance records, or explorer evidence that describes how key management is organized for the Level protocol on Ethereum. The results only cover generic key-management concepts and unrelated products, so any claim about Level’s custody model, signer setup, multisig/MPC/HSM use, role separation, or key-rotation process would be unverified marketing or speculation.

If you want, I can still help by checking for Level’s public docs, audits, or governance posts once a source set specific to the protocol is available.

Evidence (3)

smart-contract

one source

Assessment date: September 5, 2026. Dune MCP was unavailable; therefore proxy-admin event history, role state, timelock delay, renunciation, pause state, and deployment-specific withdrawal/upgrade permissions are Not verifiable as of 2026-09-05. Ethereum addresses documented by Level: lvlUSD 0x7C1156E515aA1A2E851674120074968C905aAF37; slvlUSD 0x4737D9b4592B40d51e110b94c9C043c6654067Ae; MintingV2 0x9136aB0294986267b71BeED86A75eeb3336d09E1; Vault 0x834D9c7688ca1C10479931dE906bCC44879A0446; VaultManager 0x5f432430C515964C299bb4F277CdAb0fCC074E25; RewardsManager 0xBD05B8B22fE4ccf093a6206C63Cc39f02345E0DA; PauserGuard 0x9f3328E60Cb9418dBde038B54d588dFEA2C0B6f9; RolesAuthority 0xc8425ACE617acA1dDcB09Cb7784b67403440098A; Admin Timelock 0x0798880E772009DDf6eF062F2Ef32c738119d086; Admin Safe 0x343ACce723339D5A417411D8Ff57fde8886E91dc; Operator Safe 0xcEa14C3e9Afc5822d44ADe8d006fCFBAb60f7a21; Treasury Safe 0xDf95bb71581B224BD42eB19ceaff5E92816e181E. Control model: Level documents a 5-of-8 admin Gnosis Safe, separate 2-of-5 operator Safe, and 3-of-4 treasury Safe. The operator can deploy reserve collateral but reportedly cannot change destinations or handle protocol funds; the admin Safe controls those changes.

Roles documentation states the admin controls implementation upgrades and role assignment/removal. Upgradeability / timelock: The documentation states contracts are owned by OpenZeppelin TimelockControllers controlled by the admin Safe, indicating upgradeable, delayed administration. Exact proxy pattern, proxy-admin contract type, and delay are Not verifiable as of 2026-09-05. No role is confirmed renounced. Emergency and user-exit risk: Permissioned emergency collateral-rescue, pausing, strategy/operator, oracle/address-management, and upgrade functions are documented or implied, but exact callable functions and whether withdrawals bypass pause are Not verifiable as of 2026-09-05.

A compromised admin quorum could upgrade contracts, assign privileged roles, redirect strategies/collateral, or freeze exits; a compromised operator quorum appears more constrained. Users cannot be assumed able to exit during a global pause or collateral-rescue event. Architecture: Admin Safe (5/8) → TimelockController → protocol owners/upgrades/roles → MintingV2, Vault, VaultManager, RewardsManager, PauserGuard; Operator Safe (2/5) → strategist operations; Treasury Safe (3/4) → staking rewards.

Monitoring documentation says automatic monitoring was intended to turn off beginning October 2025 as part of shutdown; current operational status is Not verifiable as of 2026-09-05. Audit coverage is documented for Level v2 by Pashov and 0xMacro, but audited-deployment matching and unresolved severity counts are Not verifiable as of 2026-09-05.

Upgradeable
Yes
Evidence (6)

audit

unverified

Level v2 audit.

Auditor
0xMacro
Report date
2025-04
Scope
Level v2
Evidence (1)

audit

one source

Auditor: 0xMacro. Report: Level A-1 / Level v2 Security Audit. Publication date: 2025-05-01.

Scope: selected Level v2 Solidity contracts at commit 5065d156, plus deployment scripts. Findings: 0 critical/high; 7 medium and 5 low; also 8 code-quality and 2 informational issues. Fix status: 5 medium and 3 low addressed; 2 medium and 2 low acknowledged; all code-quality items addressed.

Covers deployed code: Not verifiable as of September 4, 2026.

Auditor
0xMacro
Report date
2025-05-01
Scope
Selected Level v2 Solidity contracts and deployment scripts; commit 5065d156
Findings
0 critical, 0 high, 7 medium, 5 low; 8 code-quality, 2 informational.
Fix status
5 medium and 3 low addressed; 2 medium and 2 low acknowledged; code-quality items addressed.
Evidence (1)

audit

one source

Security audit for Level Money staking contracts. Findings reported: 6 medium, 3 low, 2 informational, 1 gas optimization. Report states 0 fixed and 6 acknowledged for medium findings, 0 fixed for low/informational/gas findings.

Auditor
Cantina Security
Report date
2025-08
Scope
Staking contracts; cooldown enforcement, blacklisting logic, minimum share supply protections, fund freezing mechanisms
Evidence (1)

audit

one source

Previously recorded report rechecked; remediation details remain unavailable in the accessible evidence.

Auditor
Spearbit Cantina
Report date
2024-11-12
Scope
lvlUSD v1.1 and Staked lvlUSD contracts.
Findings
Not verifiable as of September 5, 2026.
Fix status
Not verifiable as of September 5, 2026.
Report url
https://storage.googleapis.com/level-public/audits/lvlUSD%20v1.1%20%2B%20Staked%20lvlUSD%20-%20Spearbit%20Cantina.pdf
Report id
doc:0b96842a46a2261b
Evidence (1)

audit

one source

Previously recorded report rechecked; no complete finding-by-finding remediation update was located.

Auditor
Zellic
Report date
2024-09-11
Scope
Stablecoin Points Farm; Ethereum-compatible EVM code.
Findings
Not verifiable as of September 5, 2026.
Fix status
Level disclosed that migrate would not be used and, if retained, would be gated by the admin multisig. Complete remediation status is Not verifiable as of September 5, 2026.
Report url
https://reports.zellic.io/
Report id
doc:5df93eed2085ab17
Evidence (1)

audit

one source

Previously recorded report rechecked; remediation was verified in the report for the critical findings and most lower-severity issues.

Auditor
Spearbit Cantina
Report date
2024-09
Scope
lvlUSD v1; LevelMinting and LevelReserveManager contracts, reviewed September 9–16, 2024.
Findings
2 critical, 0 high, 6 medium, 6 low, and 5 informational.
Fix status
Critical findings fixed and verified. Medium and low findings were predominantly fixed and verified; at least one medium finding was acknowledged. Informational findings were mixed fixed/acknowledged.
Report url
https://cdn.cantina.xyz/reports/cantina_level_money_sep2024.pdf
Report id
doc:69509ce7d32f729e
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected/confirmed published report.

Auditor
Cantina Security
Report date
2024-06-24
Scope
Level Money staking and yield contracts; cooldown enforcement, blacklisting, minimum share supply, and fund-freezing mechanisms. Review period: June 24–27, 2024.
Findings
0 critical, 0 high; 6 medium, 3 low, 2 informational, and 1 gas optimization.
Fix status
0 fixed and all findings acknowledged: 6 medium, 3 low, 2 informational, and 1 gas optimization.
Report url
https://cantina.xyz/portfolio/131241f5-7399-476e-acd1-dc57c8f00e39
Report id
doc:69fcea58f33b2490
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Previously recorded report rechecked; no correction identified.

Auditor
Pashov
Report date
2025-04
Scope
Level v2 core contracts, including LevelMintingV2, RewardsManager, VaultManager, oracle components, BoringVault, and deployment scripts.
Findings
0 critical, 1 high, 5 medium, and 8 low.
Fix status
1 high, all 5 medium, and 7 low findings resolved; 1 low acknowledged.
Report url
https://storage.googleapis.com/level-public/audits/%5BPashov%5D%20Level%20v2%20Security%20Review.pdf
Report id
doc:9de8d211ba933c22
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Previously recorded report rechecked; no correction identified.

Auditor
Spearbit Cantina
Report date
2025-02-13
Scope
LevelReserveLens and BoringVault-related v2 contracts.
Findings
0 critical, 0 high, 0 medium; 1 low and 5 informational.
Fix status
Low finding fixed; 3 informational findings fixed and 2 acknowledged.
Report url
https://cantina.xyz/portfolio/42d871ad-b0b6-4060-a059-ea6b2324c569
Report id
doc:d74809f15dcde25e
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

unverified

lvlUSD v1.1 and Staked lvlUSD audit.

Auditor
Spearbit Cantina
Report date
2024-10
Scope
lvlUSD v1.1, Staked lvlUSD
Evidence (1)

audit

unverified

LevelReserveLens and BoringVault audit.

Auditor
Spearbit Cantina
Report date
2025-02
Scope
LevelReserveLens, BoringVault
Evidence (1)

audit

unverified

Stablecoin Points Farm audit.

Auditor
Zellic
Report date
2024-09
Scope
Stablecoin Points Farm
Evidence (1)

Team & Reputation

founders

two sources

Level (level.money) is a USDC/USDT‑backed yield stablecoin protocol on Ethereum, developed by the company Peregrine Exploration, Inc.; it has been acquired and the product is being sunset, so you are assessing a now‑legacy protocol. ### Founders & background

  • Founders: Public, non‑anonymous.
  • Kedian Sun – Technology entrepreneur, co‑founder of Level.
  • David Lee – Tech entrepreneur, co‑founder of Level.
  • Prior experience:
  • Sun previously worked at Brex and co‑founded Peregrine Exploration, Inc. in Dec 2021 to develop Level.
  • Lee co‑founded Peregrine Exploration, Inc. in Dec 2021 and has broader tech/startup experience per his public profile.
  • Track record of hacks/issues: No credible reports of protocol‑level hacks or major security incidents specific to Level were found; this is Not verifiable as of 2026‑09‑03 for a full incident history. ### Corporate structure, funding, and location
  • Development company: Level was built by Peregrine Exploration, Inc., described as a “digital asset development company” focused on Level.
  • Funding & investors: Peregrine raised ~$6m total, including a $2.6m round led by Dragonfly Capital with participation from Polychain and others (Flowdesk, Echo Syndicates, Native Crypto, Feisty Collective, plus notable angels such as Frax founder Sam Kazemian and Injective co‑founder Albert Chon).
  • Additional investor lists (Dragonfly, Polychain, Balaji Srinivasan, etc.) are reported by third‑party analytics.
  • Jurisdiction/office: Public sources describe Peregrine Exploration, Inc. as a corporation but do not clearly state its registered jurisdiction, physical office address, or regulatory status. Not verifiable as of 2026‑09‑03.
  • Business status: Level’s own site states that “the Level team is joining a leading DeFi protocol, and we will be sunsetting the product,” implying an acquisition by Grove and discontinuation of the standalone product. ### Public vs anonymous; governance reality
  • Team publicity: Founders are fully doxxed (LinkedIn, IQ.wiki, press interviews), which is atypically transparent for DeFi.
  • Real business vs web‑front:
  • Existence of a C‑corp (Peregrine Exploration), named founders, and institutional VCs suggests a real corporate entity with off‑chain operations, not just a web front.
  • However, without on‑chain data tools and corporate registry checks, incorporation details and any licenses remain Not verifiable as of 2026‑09‑03. ### Reality check
  • Credibility positives:
  • Doxxed founders with prior fintech/startup experience.
  • Recognized crypto VCs (Dragonfly, Polychain) and named angels.
  • Coverage by independent media (CoinDesk, PANews).
  • Open questions / risk flags:
  • No independently verifiable data here on on‑chain behavior, incident history, or current liabilities.
  • Corporate domicile, regulatory posture, and detailed compliance framework Not verifiable as of 2026‑09‑03.
  • Product is being sunset post‑acquisition, so ongoing operational commitment as a standalone protocol is low. Given these factors, Level appears to have been a VC‑backed, real corporate DeFi business with public founders, now integrated into Grove / Sky ecosystem, but key regulatory and operational specifics remain unverified from available sources.
Evidence (9)

general reputation

two sources

Level is generally viewed as a serious, institutionally backed stablecoin protocol with credible investors and audits, but it is currently being wound down, which is a material reputational factor for risk assessment. Founders & team

  • Co-founded by Kedian Sun and David Lee.
  • Developed under Peregrine Exploration, a blockchain development and research company. Investors & backing
  • Funding rounds include $3.6m seed/early funding and an additional $2.6m strategic round.
  • Lead/major investors: Dragonfly, Polychain Capital, Robot Ventures, Flowdesk, Native Crypto, Feisty Collective, plus well-known angels such as Balaji Srinivasan, Sam Kazemian (Frax), Albert Chon (Injective) and others.
  • This investor set is consistent with institutional/deep‑crypto backing rather than retail-focused or anonymous capital. Audits & security reputation
  • A security review of Level v2 was performed by Pashov Audit Group, identifying and addressing 23 issues; this is presented as a formal security audit.
  • Cantina lists a DeFi protocol security audit for Level Money, describing solvency-protection mechanics (first‑loss protection, cooldowns, freeze mechanics). Operational status and sentiment
  • The protocol has publicly announced that the Level team is joining a leading DeFi protocol and Level is being sunset.
  • Documentation and third‑party analytics state the protocol is in “redeem‑only mode”: users can redeem lvlUSD for underlying collateral but cannot mint new lvlUSD.
  • Frontend support is scheduled to end December 15, 2025, after which users must interact directly with contracts to redeem.
  • A press piece notes Level has been acquired by a major DeFi entity and operations will cease, consistent with an orderly wind‑down rather than an abrupt failure. Criticisms, fraud/rug, insolvency, legal issues
  • No credible allegations of fraud, rug pull, or insolvency were found in independent coverage as of the latest available data. Not verifiable as of 2026-09-03.
  • No evidence of regulatory actions or sanctions targeting Level, its team, or corporate entity was identified in accessible public sources. Not verifiable as of 2026-09-03. Unresolved concerns
  • Key ongoing risks are wind‑down execution quality (users needing to redeem before/after frontend sunset) and smart‑contract interaction risk post‑UI shutdown.
  • The acquisition and team migration reduce long‑term protocol continuity, which is negative for ongoing institutional exposure but does not, based on current data, imply misconduct.
Evidence (14)

Economy

TVL: $460K

model

one source

Status (as of September 6, 2026): Level is an Ethereum-only, redeem-only/sunset protocol. Minting is paused; lvlUSD and slvlUSD are being unwound.

  • Strategy/assets: USDC and USDT reserves were supplied to Aave and Morpho Steakhouse USDC; receipt assets were wrapped into reserve positions. A small historical sleeve used restaking (Symbiotic), but documentation says it was being withdrawn. Users received lvlUSD; staking lvlUSD produced ERC-4626 slvlUSD.
  • Yield/exposure: Base yield was lending interest and was passed to slvlUSD; Level retained Morpho token rewards. This is primarily market-neutral stablecoin lending, but carries USDC/USDT issuer, Aave/Morpho, curator, smart-contract, liquidity and oracle/governance risks.
  • Organic vs subsidized: The base yield appears organic (borrower-paid lending interest). XP, partner points, Curve/Pendle/Spectra incentives and historical restaking rewards were subsidies/marketing incentives, not durable base yield. Exact organic-yield share: Not verifiable as of September 6, 2026.
  • Leverage/looping/external exposure: Level’s reserve strategy was not described as leveraged or looped. Users could create external leverage by posting lvlUSD as Morpho collateral or buying YT/PT products; that is user-level exposure, not necessarily Level reserve leverage.
  • Withdrawals/lock-ups: Normal staking historically had a 7-day cooldown; the sunset notice reduced new unstaking/redemption cooldowns to 2 seconds, while in-flight redemptions retain 3 days. Redemptions are two-step and capped at 1m lvlUSD per block.
  • Fees/gates/revenue: No fee schedule or withdrawal fee was verifiable. U.S. persons were excluded from APY access. DeFiLlama reports $460,307 TVL, 100% Ethereum, $0 fees in the last 30 days, and $0 cumulative protocol revenue; these are aggregator figures, not on-chain verification.
  • TVL/trend/APY: Dune comparison, product-level TVL, APY history/volatility and sustainability are Not verifiable as of September 6, 2026. The reported historical peak market cap of $185m and average APY above 7% are unverified marketing claims. Contradiction: documentation reports both a 7-day normal cooldown and a 2-second sunset cooldown; the sunset terms are the later, applicable rule.
Evidence (4)

reserves

unverified

As of September 5, 2026, no Dune/on-chain verification was available in this run. Not verifiable as of September 5, 2026 for the reserve-wallet addresses, current balances, exact composition, custody locations, liabilities, or independent attestations. Observed disclosure: Level’s transparency page currently displays Total Reserves: $0, lvlUSD market cap $0, and slvlUSD market cap $0; it also states that the product is being sunset. Contradiction: Level’s documentation describes lvlUSD as fully backed by USDC and USDT, with collateral deployed to lending protocols. The documentation specifically states that reserves were deployed to Aave and Morpho Steakhouse Vault, with some historical restaking exposure. This conflicts with the transparency page’s current $0 reserve display.

The displayed on-site figure is not equivalent to an on-chain proof of zero assets; the discrepancy is unresolved. Control / custody: Level documentation describes a 5-of-8 admin Gnosis Safe, a separate 2-of-5 operator multisig able to deploy reserve-manager collateral, and a 3-of-4 treasury multisig for staking rewards. It states that the operator cannot directly handle protocol funds and that only the admin multisig can change permitted contract addresses. Multisig addresses and current signer sets were not verified here. Reserve policy: The stated policy was 1:1 backing with USDC/USDT and yield generation through lending protocols; redemptions were subsequently moved into a shutdown/redemption process.

This is documentation/marketing disclosure, not independently verified reserve evidence. Attestations: No current third-party reserve attestation or proof-of-reserves report was identified in the reviewed sources. Not verifiable as of September 5, 2026. Structured fields: liquid_reserves_usd = null; liabilities_usd = null.

Evidence (4)

tokenomics

one source

Level (level.money) is a tokenized private credit protocol on Ethereum. It uses a stablecoin-like asset called LVL; all information below is from analytics and media, not on-chain queries. Not verifiable as of 2026-09-03. ### Native token

  • Token name/ticker: LVL (Level Dollar).
  • Chain: Ethereum mainnet.
  • Contract address: Not verifiable as of 2026-09-03 (no reliable, cross-checked source that clearly matches level.money rather than similarly named assets).
  • Token type: ERC‑20 stablecoin designed to track USD exposure to private credit via tokenized RWAs (e.g., receivables and other credit assets). ### Supply, market cap, FDV
  • Total supply / circulating supply / market cap / FDV: Not verifiable as of 2026-09-03; major analytics (CoinGecko/CoinMarketCap/DeFiLlama) do not consistently list LVL or clearly disambiguate it from other “Level” tokens. ### Token utility and governance
  • Primary utility:
  • Represents a claim on a pool of tokenized private credit assets; used as the protocol’s core “stable value” asset.
  • Users deposit capital in Level and receive LVL or LVL‑linked positions exposing them to diversified credit portfolios.
  • Governance role: Not verifiable as of 2026-09-03; no reliable evidence of a separate governance token or of LVL having formal on-chain governance rights. ### Revenue share, buybacks, burns, staking
  • Revenue mechanics: Level charges origination/servicing fees on underlying credit deals; these fees fund the yield promised to depositors.
  • Whether protocol fees are used for buybacks, burns, or explicit revenue share to token holders is not verifiable as of 2026-09-03.
  • Staking or vault rewards: Users earn yield by holding LVL or vault tokens that are backed by private credit; detailed APR mechanics and whether this constitutes “staking” versus lending are not verifiable as of 2026-09-03. ### Emissions & unlocks; allocations
  • Emissions schedule, unlock schedule, team/investor/treasury/community allocations: Not verifiable as of 2026-09-03; no independent tokenomics breakdown found.
  • Whether any announced unlocks actually occurred on-chain: Not verifiable as of 2026-09-03. ### Holder concentration; control functions
  • Top-holder concentration / insider wallets: Not verifiable as of 2026-09-03.
  • Mint/burn/blacklist/fee‑switch functions and controllers: Not verifiable as of 2026-09-03; the specific LVL contract cannot be reliably confirmed. ### DEX liquidity & listings
  • Main listings and liquidity depth on Ethereum DEXs: Not verifiable as of 2026-09-03; LVL for level.money is not clearly surfaced as a distinct asset on major aggregators. Overall, the protocol’s tokenomics are insufficiently disclosed in independent sources, and key parameters (supply, governance, control rights) cannot be validated under the current tool constraints.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin price move below $10,000 would likely create a severe *risk-off* shock for Level on Ethereum, but the exact protocol-specific impact is Not verifiable as of 2026-09-03 from the available sources. What can be said with confidence is limited to market-structure context: research and market commentary consistently show that crypto assets, including Ethereum, tend to exhibit heightened stress and volatility during bearish periods, and that broader crypto market shocks can transmit into DeFi activity and collateral valuations. In an extreme downside scenario, DeFi protocols that rely on crypto collateral, leverage, or liquidity incentives typically face higher liquidation risk, lower borrowing demand, and potential TVL contraction; however, the specific exposure of Level to Bitcoin price is Not verifiable as of 2026-09-03 because I do not have confirmable on-chain or protocol-documentation evidence tying Level’s Ethereum deployments to BTC-linked collateral, reserves, or strategy positions.

For this protocol, the key unanswered stress-test items are:

  • whether Level has any BTC-denominated collateral or wrapped-BTC exposure on Ethereum;
  • whether user vaults, lending markets, or LP positions are indirectly exposed through correlated ETH/DeFi liquidations;
  • whether liquidity incentives or treasury assets would be impaired by a BTC-led market drawdown. Because those protocol-specific dependencies are not verifiable from the provided sources, the appropriate institutional conclusion is: treat a BTC sub-$10k event as a high-severity macro shock, but do not assume direct protocol insolvency or direct BTC exposure without further evidence. The direct exposure path for Level remains Not verifiable as of 2026-09-03.
Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

A 20% depeg in the largest collateral would be a severe stress event for Level because stablecoin and collateral depegs can rapidly push lending positions above liquidation thresholds and trigger liquidation cascades. In lending systems, the key risk is not the depeg itself but whether the depegged collateral falls far enough, and long enough, to breach the protocol’s liquidation parameters and oracle update cadence. For Level specifically, the exact impact is Not verifiable as of 2026-09-03 because the available sources here do not provide the protocol’s Ethereum collateral composition, oracle settings, liquidation thresholds, or position concentration.

Without those on-chain or protocol-specific parameters, it is not possible to quantify the share of vaults/borrows that would be liquidated under a 20% collateral depeg. What can be stated from the cited research is:

  • A depeg is a meaningful divergence from the reference price, and even short-lived moves can cause liquidations in DeFi lending systems.
  • Liquidation cascades occur when forced sales depress prices further, creating feedback loops that can amplify losses.
  • Stress severity depends on the size and duration of the price move, plus the protocol’s risk controls and collateral backing ratio. If you want a protocol-specific loss estimate, I would need Level’s Ethereum collateral list, oracle sources, and liquidation thresholds; absent that, the stress outcome remains Not verifiable as of 2026-09-03.
Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

Scope caveat. The largest Ethereum counterparty by current exposure is Not verifiable as of September 5, 2026: Dune/on-chain verification was unavailable, and accessible documentation is stale. Level’s documentation identifies Aave and Morpho Steakhouse Vault as reserve venues, while also stating the protocol is in shutdown/redeem-only mode. > Contradiction: One page says reserves are deployed to “Aave and Morpho Steakhouse Vault”; the FAQ says current yield is earned from Aave.

The allocation split is therefore Not verifiable as of September 5, 2026. ### Stress cases 1) Aave insolvency / bad debt — likely largest venue, but unverified.

  • Loss path: Level’s aUSDC/aUSDT or related reserve position loses value because Aave cannot return deposited assets in full.
  • Absorber: lvlUSD reserve holders first; slvlUSD holders are economically exposed through the staking vault’s reduced asset value. There is no evidence of a separate Level insurance fund or equity-like first-loss buffer.
  • Compensation: Not verifiable as of September 5, 2026.
  • Contract path: VaultManager/BoringVault withdrawal returns fewer assets; LevelReserveLens should show reserves below lvlUSD supply, enabling pause or mint/redeem-disable actions. Remaining users receive collateral pro rata, creating a haircut. 2) Morpho Steakhouse Vault / curator or market insolvency.
  • Loss path: The vault’s underlying Morpho market accrues unrecoverable bad debt or its receipt-token value falls.
  • Absorber: Level reserves, then lvlUSD/slvlUSD holders; Morpho or the curator is not documented as guaranteeing Level’s loss.
  • Compensation: Not verifiable as of September 5, 2026.
  • Contract path: Level’s vault records the impaired receipt token; withdrawals crystallize the loss. The operator may withdraw or reallocate funds, but cannot recover unavailable collateral. 3) USDC/USDT issuer insolvency, freeze, or depeg.
  • Loss path: Reserve tokens become impaired or non-redeemable.
  • Absorber: lvlUSD holders directly; Level has no documented ability to manufacture replacement dollars.
  • Contract path: redemption may transfer impaired tokens or be paused; the 1:1 redemption promise becomes economically ineffective. Bottom line: No verified third-party compensation or protocol backstop was found; losses are structurally socialized through reserve impairment and holder haircuts.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For Level, I could not verify any credible evidence that the DAO or its owners committed fraud. Based on the available web results, the only directly relevant source is the project website, which does not establish fraud, and the other results are general DAO-fraud discussions or unrelated examples, not evidence about Level specifically. Therefore the correct stress-scenario assessment is: Not verifiable as of 2026-09-03.

This means I did not find a confirmed allegation, enforcement action, court finding, audit finding, or independent investigation tying Level’s DAO or owners to committed fraud. I also could not validate on-chain allegations because on-chain verification is unavailable in this run. If you want, I can next assess adjacent stress scenarios for Level such as governance capture, owner-key abuse, treasury misappropriation, or protocol insolvency.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

Level’s primary yield source is not verifiable from the provided results, and I cannot confirm whether its 30-day yield is negative as of today. Because Dune/on-chain checks are unavailable in this run, the correct status is Not verifiable as of 2026-09-03. For the meaning of a negative 30-day yield, the standard 30-day SEC yield is based on income earned over the most recent 30-day period, net of expenses; if that figure is negative, it means expenses exceeded income over that window, not that investor value must fall one-for-one over the same period.

For a DeFi protocol stress scenario, the practical risk interpretation is:

  • Negative 30d yield usually indicates the current revenue/income stream is insufficient to cover costs or subsidies.
  • If the protocol is using incentives, the negative figure may reflect temporary emissions burn rather than core business profitability.
  • If the protocol’s main yield source is lending, staking, or LP fees, a negative 30d print can signal utilization decline, fee compression, or rising incentive expense. What I can confirm from the sources here is only the general yield concept, not Level-specific economics or chain activity. Not verifiable as of 2026-09-03: Level’s Ethereum-only TVL, revenue, user balances, and whether the protocol’s primary yield source is currently negative over 30 days.
Evidence (2)

Governance & Legal

governance

one source

Assessment — Ethereum (as of September 13, 2026). Level has no evidenced live, enforceable token-holder DAO or public proposal/voting process. Governance is therefore multisig/company-team controlled, not DAO-controlled. The project announced that Level was being sunset, with the frontend scheduled to remain live only through December 15, 2025; the current website still displays the shutdown announcement. Contract control. The admin multisig is a 5-of-8 Gnosis Safe and is described as the highest-authority entity: it can upgrade contracts, manage roles, change redeemable assets/oracles, pause/unpause, disable minting/redemptions, and control which destinations operators may use.

The operator multisig is 2-of-5 and the treasury multisig 3-of-4. Four admin signers are described as internal and four as trusted external parties/security firms; signer identities and independence cannot be independently verified without on-chain analysis. Funds/emergency powers. Admin privileges can ultimately authorize vault exits and alter asset/role configuration; this meets the stated definition of admin_can_drain. Separate operator/gatekeeper roles can pause or disable minting, creating an emergency path outside DAO governance.

The existence of a timelock is documented, but its delay is not disclosed in the reviewed sources. Voting concentration/top holders. Not verifiable as of September 13, 2026. Dune/on-chain verification was unavailable in this run; no substitute aggregator figure is treated as proof. Company/legal control. The Level team is stated to be joining the Sky/Grove ecosystem, but the controlling legal entity, jurisdiction, registration number, directors, and applicable Terms of Service party are Not verifiable as of September 13, 2026. The documentation links to Terms and Conditions but does not establish those corporate details in the reviewed material. Contradiction/finding: “decentralized protocol/community” language is inconsistent with the documented architecture: upgrades, role administration, emergency controls, and key fund-routing permissions remain concentrated in privileged multisigs.

Timelock
Yes
Multisig threshold
5
Multisig owners
8
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

one source

Level is a DeFi yield protocol at level.money operating on Ethereum; its precise legal entity and jurisdiction are Not verifiable as of 2026-09-03 because there is no clearly identified corporate entity, registration number, or jurisdictional disclosure in public independent sources. Terms of Service / User Restrictions Independent sources do not reproduce or analyze Level’s own Terms of Service; details on eligibility, geographic restrictions (e.g. US persons), age limits, or prohibited users are therefore Not verifiable as of 2026-09-03 without relying solely on Level’s site (which must be treated as "unverified marketing claim"). KYC / AML There is no public evidence from regulators, CEX listings, or compliance provider announcements that Level requires KYC for use of its smart contracts; typical on‑chain interaction patterns (via wallets) suggest it functions as a non‑custodial protocol, but this is an inference rather than an independently documented compliance policy. As no independent compliance policy or audit focused on AML is available, Level’s KYC/AML framework is Not verifiable as of 2026-09-03. Regulatory Classification (securities, derivatives, etc.) No formal classification of Level by major regulators (SEC, CFTC, ESMA, FCA, MAS, etc.) appears in public databases or reputable legal commentary.

As a result, whether its tokens or products are deemed securities, collective investment schemes, or derivatives in any jurisdiction is Not verifiable as of 2026-09-03. Warnings, Enforcement, Court Cases, Sanctions Searches of regulatory warning lists, sanctions lists, and major enforcement databases did not return actions specifically naming Level or a clearly associated legal entity.

  • Regulatory warnings: Not verifiable as of 2026-09-03 (no independent hits tied unambiguously to this protocol).
  • Enforcement actions/court cases: Not verifiable as of 2026-09-03.
  • Sanctions status: No indication that Level or an associated entity is itself designated on major sanctions lists; therefore "sanctioned" is set to false as of the search date, subject to future changes. Data Protection / Privacy No independent privacy-policy analysis or data‑protection assessment is available; how user data (e.g. web analytics, support interactions) is handled is Not verifiable as of 2026-09-03 without relying solely on Level’s own web disclosures. Legal Structure vs. Actual Risk Given the absence of a clearly documented legal entity, users likely interact directly with smart contracts without contractual recourse, registered fund oversight, or deposit insurance; this increases counterparty/recourse risk despite any on‑chain transparency. This is an analytical inference based on the lack of identified corporate structure in independent sources.
Sanctioned
No
Evidence (2)

Stability

stability

two sources

Level issues its own stablecoin, lvlUSD, so own_stablecoin = true. The gathered web evidence shows lvlUSD is designed as a USD-referencing stablecoin, and third-party price pages show historical trading below and above $1, including an all-time low around $0.9641 and a 24-hour low near $0.9931, which indicates at least one depeg event in public market data. However, the sources available in this run do not provide a complete, independent time series sufficient to verify the total number of depeg events, the exact last depeg date, or the maximum depeg percentage with confidence, so those remain Not verifiable as of 2026-09-05.

Own stablecoin
Yes
Stablecoin ids
  • lvlUSD
Evidence (4)

Risks & Strengths

risks

one source

Level’s documented design concentrates risk in stablecoin collateral, external lending venues, smart contracts, privileged administration, and the protocol’s wind-down. Current Ethereum reserves, liabilities, redemptions, contract permissions, and shutdown completion are Not verifiable as of September 5, 2026 because Dune/on-chain verification was unavailable; cited documentation is stale relative to the assessment date.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Wind-down and redemption failureThe protocol announced sunsetting lvlUSD/slvlUSD and a finite redemption window. If contracts, frontend, liquidity, or operators are unavailable, holders may face delayed or impaired recovery.HighHighDocumented redemption process, reduced cooldowns, and planned public redemptions; current implementation and completion status are Not verifiable as of September 5, 2026.High
USDC/USDT collateral depeglvlUSD depends on centralized stablecoins; issuer insolvency, freezes, sanctions, or depeg can reduce reserve value and impair the $1 redemption objective.HighMediumCollateral is limited to USDC and USDT, with stated selection criteria.Medium-High
Lending venue bad debtReserves are deployed to external lending protocols and vaults. Exploits, oracle failures, insolvency, or withdrawal queues could create losses or undercollateralization.HighMediumProtocol states it selects venues based on liquidity, collateral quality, and stress history; independent audit material also flags strategy dependency risk.Medium-High
Smart-contract or integration exploitA vulnerability in minting, reserve management, staking, vault, oracle, or connected protocols could directly compromise collateral or accounting.HighMediumExternal audits, peer review, bug bounty, and monitoring were documented; audit coverage cannot eliminate undiscovered or post-audit risks.Medium-High
Privileged-key or monitoring failureAdmin, operator, treasury, and emergency functions depend on multisigs and trusted signers. Key compromise, collusion, execution error, or monitoring shutdown could delay containment.HighMediumDocumented 5/8 admin, 2/5 operator, and 3/4 treasury multisigs, timelock controls, cold wallets, and external signers; monitoring was scheduled for shutdown.Medium-High
Evidence (5)

strengths

one source

Level’s top five strengths are: (1) fully on-chain, DeFi-native design, because lvlUSD is issued and yield-bearing through lending protocols rather than a centralized custodian; (2) composability, since the protocol is designed to integrate with major DeFi venues and receipt-token ecosystems; (3) transparency, with on-chain yield and reserve mechanics instead of opaque off-chain management; (4) security posture, including multiple auditor relationships, a bug bounty program, multisig controls, and on-chain monitoring; and (5) yield competitiveness, with Level claiming strong APY performance relative to other yield-bearing stablecoins. The strongest support in the available sources is that Level is a fully backed stablecoin protocol using USDC/USDT and blue-chip lending protocols, and that it emphasizes permissionless access, transparency, and composability.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 13 two independent sources, 22 one source, 10 unverified.
  • Oldest fact verification date: 2026-08-28.