Meteora DLMM

Orange · 45/100

Executive summary

Meteora DLMM is a Solana-native concentrated-liquidity AMM using discrete price bins and dynamic fees, scoring 43/100 (orange band) with high data confidence but significant unresolved incident and governance concerns.

  • Security: Multiple audits by Offside Labs (Jan 2024, Nov 2024), OtterSec (Feb 2024), Sec3, and Zenith (v0.11.0, v0.12.0); Jan 2024 report found 1 critical, 2 high, 2 medium issues but fix status is not verifiable as of Sep 2026. Active bug bounty via OOO Security ($10k max, $8.6k paid). Upgradeable program with unverified upgrade-authority controls; admin can drain via upgrade compromise.
  • Incidents: Three major unresolved events: M3M3 pump-and-dump (Dec 2024, $69M claimed losses), LIBRA insider liquidity removal (Feb 2025, $280M claimed, $110M to insiders), and OTC scam loss (Jan 2026, $1.5M USDC). All remain unresolved with no confirmed reimbursement or completed remediation. Additional MEV extraction event (May 2026, $1.32M ANB arbitrage) with unknown status.
  • Governance & custody: Company-controlled, not DAO-governed; MET holders have no voting rights. Solaris Labs (BVI) owns IP, Meteora Foundation (Cayman) controls treasury. Team multisig (4-of-7 cold, 3-of-5 hot) holds upgrade authority; signer identities and independence not verifiable. No on-chain governance or timelock. Non-custodial at user level; LP positions are on-chain.
  • Legal & regulatory: Operated by Meteora Nova Limited (BVI); Terms prohibit U.S. persons and sanctioned jurisdictions, select BVI law and arbitration. Pending SDNY class action (*Hurlock v. Kelsier Ventures*) names Meteora and former CEO Ben Chow, alleging manipulation and fraud. Co-founder Ben Chow resigned Feb 2025 amid LIBRA controversy; current co-leads are Zhen Hoe Yong and Soju.
  • Top risks: Upgrade-key compromise could freeze withdrawals or alter fees/logic; concentrated-liquidity mechanics expose LPs to impermanent loss and range-exit risk; permissionless pools allow low-quality or adversarial tokens; unresolved incidents and litigation create reputational and regulatory overhang; Solana execution dependency (network outages, congestion).
  • Strengths: Capital-efficient bin-based liquidity; dynamic fees adjust to volatility; flexible LP strategies (Curve, Spot, Bid-Ask); major Solana DEX integration and routing; public SDK, API, and audit repository; active bug bounty.
  • Recommended exposure: Limit to <5% of portfolio given orange score and unresolved incidents; use only for short-duration, actively managed LP positions in high-volume pairs; avoid exposure to unaudited or low-liquidity pools; monitor upgrade-authority activity and litigation developments; verify current program version matches audited scope before deposit.
  • Open questions: Verify current upgrade-authority multisig signers and independence; confirm whether Jan 2024 critical/high findings were fixed in deployed code; obtain on-chain proof of reserve balances and treasury custody; assess litigation risk and potential settlement exposure; validate that v0.12.0 audit (Sep 2026) covers live program; check for any emergency-pause or withdrawal restrictions in current contracts.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 3 audit(s); continuous security program bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2024-02-01 is older than a year
Incidents 20% 0 0.0 3 open incident(s), $350,500,000 at risk = 187.0% of TVL (threshold 10%); penalty proportional to assets at risk
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 1 0.2 TVL $187,457,709 = 1% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 17/37 verified facts; 37/37 fresh (180d)

Identification

protocol identification

two sources

Meteora DLMM (Dynamic Liquidity Market Maker) is a Solana‑native concentrated‑liquidity AMM program that organizes liquidity into price bins and powers a major share of Solana DEX volume. Identification

  • Name: Meteora DLMM (Dynamic Liquidity Market Maker)
  • Website / App: app.meteora.ag (front‑end for DLMM pools)
  • Docs: docs.meteora.ag, core DLMM section and developer guide.
  • Category: Solana DEX / liquidity infrastructure; concentrated‑liquidity AMM with dynamic fees.
  • Chains: Solana only for DLMM.
  • Native token: Protocol‑level token is MET (mentioned in DLMM PnL tooling and points system).
  • Launch date (DLMM): Not explicitly stated; external reviews describe Meteora DLMM as part of a 2023 rebuild of Mercurial Finance into Meteora. Exact program launch block/time is Not verifiable as of 2026‑09‑04. Main program / contract addresses (Solana)
  • DLMM Program ID (Solana mainnet beta & devnet): LBUZKhRxPF3XUpBCjp4YzTKgLccjZhTSDM9YuVaPwxo.
  • Cross‑check 1: Meteora official docs list this Program ID for mainnet and devnet.
  • Cross‑check 2: Bitquery Solana DLMM API documentation filters DLMM trades by the same program address, explicitly labeling it “Meteora Dynamic Liquidity Market Maker on Solana.”
  • Explorer‑level verification status (e.g., program name, source code): Not verifiable as of 2026‑09‑04 without direct explorer access.
  • Other DLMM‑related accounts (position accounts, pool accounts, etc.) are described conceptually in docs but not enumerated as fixed addresses; these are derived per‑pool. Fork lineage & design origin
  • Meteora as a protocol is described as a rebuild of the earlier Mercurial Finance project on Solana. That is project‑level lineage, not a claim that DLMM is a direct code fork of another DEX.
  • DLMM is consistently described as Meteora’s own concentrated‑liquidity design using price bins and dynamic fees, not as a fork of Uniswap v3 or other CLMMs. No source identifies a specific upstream codebase.
  • Therefore, whether DLMM is a strict fork vs. original implementation is Not verifiable as of 2026‑09‑04; available sources frame it as Meteora‑native design. Audits & modifications
  • Meteora docs list multiple DLMM audit reports (e.g., OffsideLabs and OtterSec) and an “Overview – DLMM Audits” page, indicating repeated security reviews of DLMM program versions.
  • Zenith‑labeled audit reports under DLMM resources suggest ongoing iterations (v0.10.x, v0.11.0) with audits tied to specific versions.
  • No public reports of malicious modifications in third‑party forks of DLMM were found; this absence is Not verifiable as of 2026‑09‑04 and should not be taken as proof none exist. Contradiction check callout
  • On‑chain TVL, usage and exact deployment timestamps for DLMM Not verifiable as of 2026‑09‑04 under current constraints; any metrics from analytics or marketing materials must be treated as aggregator data or unverified marketing claims rather than on‑chain‑verified facts.
Evidence (15)

maturity

two sources

Meteora DLMM is a real, functional product portal rather than a pure landing page: the app exposes pool lists, portfolio views, positions, swaps/limits, protocol stats, and documented DLMM APIs, including Swagger-backed production and development endpoints. The documentation also shows a TypeScript SDK and examples, which is consistent with a mature integration surface rather than a template site. Live user actions appear supported: the docs explicitly describe open-position portfolios, historical position events, PnL, and claims endpoints, and third-party walkthroughs describe adding liquidity and withdrawing/closing positions in the app.

However, live on-chain verification of deposits/withdrawals is not verifiable as of 2026-09-04, so those flows should be treated as documented functionality rather than independently confirmed execution. Open API: yes. Meteora documents a DLMM Data API with production and development base URLs, rate limits, and a Swagger UI, and the API reference is publicly indexed.

The API is read-oriented/indexed data, not an arbitrary write API. I did not find strong evidence of fake metrics or obvious template scaffolding in the surfaced materials; the app and docs look purpose-built. Broken links were not systematically checked, so that is not verifiable as of 2026-09-04.

Evidence (6)

Security

bug bounty

one source

Meteora has an active bug bounty program managed through OOO Security. It covers vulnerabilities across Meteora’s on-chain programs and protocol infrastructure, including DLMM, DAMM v1/v2, DBC, Alpha Vault, and other Meteora programs. The program page reports 4 resolved reports and $8,600 total paid, with a $10,000 maximum bounty for critical vulnerabilities.

The program page was last updated on 2026-05-11. The exact start date is not verifiable as of 2026-09-04 from the gathered sources.

Active
Yes
Platform
OOO Security
Max payout
$10K
Since
2026-05-11
Evidence (2)

counterparty risks

one source

Assessment (as of September 6, 2026; Solana only). Meteora DLMM is a Solana-native concentrated-liquidity AMM. Its core swap path uses pool bins/reserves and a protocol oracle account that supports observations/TWAP; it is not documented as depending on Pyth or Switchboard for ordinary swaps. Oracle-manipulation risk therefore remains primarily pool-market/liquidity risk: thin or adversarial pools can be moved, while downstream protocols may apply their own external oracle and liquidation logic. External protocols / composability. DLMM liquidity is integrated into Solana aggregators and strategy/lending products, including Kamino-related vaults; this creates indirect smart-contract, liquidation, and contagion risk for users who deposit receipt tokens or use vault products.

Meteora Dynamic Vaults are a separate higher-dependency product that has historically allocated idle capital across Solana lending venues such as Solend, Marginfi and Kamino; do not attribute that exposure automatically to a direct DLMM LP position. Bridges / custodians / CEX or market-maker exposure. DLMM itself is single-chain and non-custodial at the pool level. Meteora’s broader interface advertises bridging through Wormhole and deBridge, but this is an external integration rather than an inherent DLMM swap dependency. No reliable public source identified a required custodian, CEX, named market maker, or RWA issuer/SPV for the core DLMM program. Not verifiable as of September 6, 2026 for aggregate bridge, CEX/MM, RWA, or treasury exposure. Asset-specific failure modes. LPs bear issuer/depeg risk for USDC/USDT and other stablecoins, LST discount/depeg risk for assets such as mSOL/stSOL/Jito-related tokens, and severe idiosyncratic/token-contract risk in permissionless or memecoin pools.

A pool can become one-sided or illiquid after a sharp price move; fees do not guarantee protection against impermanent loss. Aggregate stablecoin/LST/restaking/RWA exposure by value is Not verifiable as of September 6, 2026 without on-chain aggregation. Contradiction / data gap. Previously recorded claims about integrations are directionally supported, but no current raw on-chain exposure percentages were available in this run. On-chain verification was skipped; no exposure percentage is inferred.

Evidence (5)

crypto custody

unverified

Meteora DLMM is organized as a non-custodial Solana protocol: users keep control of assets in their own wallet, and the app/terms state that Meteora does not hold, control, store, send, or receive user digital assets. Liquidity is deposited into on-chain pool accounts governed by the DLMM smart contracts, so custody is programmatic/on-chain rather than Meteora-operated custody. On the evidence reviewed, withdrawal_paused = null and segregated_assets = null because no independent source verified a current withdrawal pause status or an explicit segregation regime beyond the on-chain per-position/pool accounting described in the documentation.

Evidence (2)

incident

two sources

Affected retail buyers and liquidity participants in the M3M3 ecosystem. Plaintiffs allege a coordinated insider pump-and-dump beginning with the December 4, 2024 launch and collapse shortly afterward, causing at least $69M in claimed damages. This is a litigation allegation, not a confirmed protocol-funds exploit or adjudicated loss.

Meteora allegedly promised to pay stakers in full and later excluded M3M3 pools and related wallets from incentive calculations. Actual repayment, recovery, and a completed technical fix are Not verifiable as of 2026-09-06. Current status: unresolved.

Date
2024-12-04
Cause
Other
Loss
$69.0M
Status
unresolved
Event id
meteora-m3m3-2024-12-04
Evidence (3)

incident

two sources

Affected retail buyers and liquidity participants in LIBRA DLMM pools. Plaintiffs and a court declaration allege that insiders deliberately removed liquidity on February 14, 2025, collapsing LIBRA; this was alleged insider extraction/market manipulation, not a confirmed DLMM code exploit. Claimed retail losses exceed $280M; court materials identify at least $110M removed to insider-controlled wallets.

Meteora/Jupiter denied insider trading, engaged Fenwick & West for an investigation, and Ben Chow resigned in February 2025. LIBRA pools and related wallets were subsequently blacklisted/excluded from incentive calculations. Reimbursement or recovery is Not verifiable as of 2026-09-06; no confirmed user reimbursement or protocol fix beyond blacklist/control changes.

Current status: unresolved.

Date
2025-02-14
Cause
Other
Loss
$280.0M
Attacker proceeds
$110.0M
Status
unresolved
Event id
meteora-libra-2025-02-14
Evidence (3)

incident

two sources

Meteora lost approximately $1.5M in USDC on January 17, 2026 through a fake OTC escrow deal during an attempted MET buyback. Cause was social engineering and impersonation in an off-chain escrow workflow, not a DLMM/DAMM smart-contract exploit. The protocol filed a police report.

No recovery or reimbursement has been reported; a technical/process fix is Not verifiable as of 2026-09-06. Current status: remediation_in_progress.

Date
2026-01-17
Cause
Other
Loss
$1.5M
Attacker proceeds
$1.5M
Status
remediation in progress
Recovered
$0
Reimbursed
No
Event id
meteora-otc-scam-2026-01-17
Evidence (3)

incident

two sources

Meteora DLMM has no clearly verifiable protocol-level exploit affecting core DLMM funds in the sources reviewed; one web source states there were “No prior exploits as of 2026-02-03.” A separate 2026 incident involved a suspected MEV/manipulation event around an ANB pool on Meteora, but the reports describe token-price/arbitrage effects rather than a confirmed DLMM protocol loss or reimbursement program. A different 2026 report says Meteora lost $1.5M in a fake OTC escrow scam while attempting to buy back MET; that appears to be a social-engineering loss, not a DLMM smart-contract exploit.

Date
2026-02-03
Cause
Other
Loss
$1.5M
Status
resolved
Recovered
$0
Reimbursed
No
Evidence (3)

incident

one source

On May 2, 2026, MEV bots reportedly extracted approximately $1.32M through an ANB price dislocation between Meteora DAMM v2 and DLMM pools after a large swap caused extreme price impact. The reports describe arbitrage/manipulation affecting ANB traders and liquidity counterparties, but do not establish a realized Meteora protocol loss, user compensation, or a formal Meteora response/fix. Current status: unknown.

Date
2026-05-02
Cause
Oracle manipulation
Loss
$1.3M
Attacker proceeds
$1.3M
Status
status unknown
Recovered
$0
Reimbursed
No
Event id
meteora-anb-mev-2026-05-02
Evidence (1)

key management

two sources

Meteora DLMM is organized as a self-custody protocol: users keep control of their own Solana wallets and sign transactions locally, rather than handing keys to Meteora. The SDK docs show DLMM is accessed through a wallet-connected client (AnchorProvider, Wallet, Keypair) and that the protocol exposes on-chain program accounts and PDAs for pools, positions, and oracles, which indicates key-dependent actions are executed by the user’s wallet against the program rather than by a custodial intermediary. In practical terms, LP management is wallet-based: adding liquidity, collecting fees, and withdrawing/closing positions are transaction actions the user signs with their own key material, while the protocol state lives in on-chain accounts managed by the program.

I could not verify any protocol-managed custody, shared admin key scheme, or multisig/key-rotation policy from the provided sources. Not verifiable as of 2026-09-04.

Evidence (4)

smart-contract

two sources

Scope: Solana mainnet; as-of September 6, 2026. Addresses / architecture

  • Core DLMM program (lb_clmm): LBUZKhRxPF3XUpBCjp4YzTKgLccjZhTSDM9YuVaPwxo; the same ID is documented for mainnet and devnet. The account is owned by Solana’s BPFLoaderUpgradeab1e11111111111111111111111, therefore this is an upgradeable Solana program—not an EVM proxy.
  • Reported upgrade authority: JADaUV8kvDpDbJr55wxXJHVaBS3VCj8thZZHjfeuCVLd. A February 14, 2026 public observation reported the authority as dormant (0.23 SOL; no recent transactions), but did not establish multisig or timelock control.
  • Public documentation states the deployed lb_clmm source is not open-sourced; integrations rely on the IDL, SDK, account data, and API. Admin controls / exit risk
  • Exact owner, fee-owner, operator, oracle, emergency-pause, withdrawal, strategy, and role-renunciation state: Not verifiable as of September 6, 2026.
  • Proxy-admin type, multisig configuration, and on-chain timelock delay: Not verifiable as of September 6, 2026. Dune MCP was unavailable; no reliable public evidence establishes a delay.
  • Normal LP removal and fee-related instructions exist in the published interface/audit scope, but whether every position can exit during a pause, upgrade, or account-level failure is Not verifiable as of September 6, 2026.
  • Worst case: compromise of the upgrade authority could replace program logic, potentially freezing swaps/withdrawals, altering fees/oracle/strategy behavior, or redirecting assets controlled by the program. This is the principal rug/freeze risk; dormant activity is not equivalent to renunciation. Contradiction / limitation: public audits cover identified code revisions, while the exact production binary/commit and current authority governance are not independently proven. Otter reported 0 critical and 2 high findings, all marked resolved, but this does not prove the current deployment is identical. Architecture: User → DLMM SDK/IDL → lb_clmm program → pool/bin-array/position PDAs → SPL Token programs; upgrade authority → Solana upgradeable loader → replaceable lb_clmm binary. Assessment: material centralized upgrade risk; no verified timelock/multisig evidence; user exit protection against a malicious upgrade is unverified.
Admin can drain
Yes
Upgradeable
Yes
Unresolved critical
0
Unresolved high
0
Evidence (5)

audit

one source

Corrected split: Offside Labs DLMM January 2024 report.

Auditor
Offside Labs
Report date
2024-01-01
Scope
DLMM LB-clmm Solana program; assessed Dec. 6, 2023 code.
Findings
Critical: 1; High: 2; Medium: 2; Low: 2; Informational: 4.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/MeteoraAg/audits/blob/main/dlmm/offside-labs-dlmm-audit-jan-2024.pdf
Report id
doc:332c0fce9ddd07f1
Evidence (1)

audit

unverified

Offside Labs DLMM v0.8.2 report.

Auditor
Offside Labs
Report date
2024-11-01
Scope
DLMM program v0.8.2 on Solana.
Findings
Critical/High/Medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/MeteoraAg/audits/blob/main/dlmm/offside-labs-dlmm-audit-0.8.2.pdf
Report id
doc:c73388d95d2b23ff
Evidence (1)

audit

one source

OtterSec DLMM February 2024 report.

Auditor
OtterSec
Report date
2024-02-01
Scope
DLMM program on Solana; February 2024 assessment.
Findings
The report produced 9 findings; Critical/High/Medium breakdown not exposed in retrieved content.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/MeteoraAg/audits/blob/main/dlmm/ottersec-dlmm-audit-feb-2024.pdf
Report id
doc:daab41235d766875
Evidence (1)

audit

unverified

Multiple audits of Meteora DLMM Solana program (Meteora-DLMM-Jan24.pdf and Meteora-DLMM0.8.2-Nov-2024-OffsideLabs.pdf).

Auditor
Offside Labs
Report date
2024-01-15
Scope
DLMM Solana program, including at least version 0.8.2 as of Nov 2024; covers core liquidity logic for DLMM pools.[2][3]
Findings
The Jan 2024 and Nov 2024 Offside Labs DLMM reports are listed, but detailed vulnerability severities (critical/high/medium) and counts are not visible here.[2] Not verifiable as of 2026-09-04
Fix status
Given DLMM is live and marketed as audited, it is implied that identified issues were addressed, but without direct access to issue tables and remediation notes this cannot be confirmed.[2][6] Not verifiable as of 2026-09-04
Evidence (3)

audit

one source

Meteora DLMM Solana program audit (dlmm_final_report.pdf).

Auditor
Sec3
Report date
2024-02-01
Scope
DLMM pools / core Solana program; listed specifically as DLMM audit in the Meteora audits index.[2][3]
Findings
A secondary source claims Sec3’s DLMM audit found no critical issues and minor ones resolved, but this is not directly verifiable against the original report here and must be treated as unverified.[7] Not verifiable as of 2026-09-04
Fix status
Secondary commentary states minor issues were resolved, but without direct access to the Sec3 PDF, remediation status cannot be independently confirmed.[2][7] Not verifiable as of 2026-09-04
Evidence (2)

audit

unverified

Zenith audit of Meteora DLMM program version 0.11.0 on Solana (Zenith v0.11.0 audit report).

Auditor
Zenith
Report date
2025-03-01
Scope
DLMM program v0.11.0 on Solana; documentation labels this specifically as a DLMM audit, implying coverage of the deployed program version at that time.[1]
Findings
The Zenith DLMM v0.11.0 audit is referenced by the docs, but the actual report content (issue list and severities) is not accessible here.[1] Not verifiable as of 2026-09-04
Fix status
No public summary of issue remediation is visible in the accessible materials, so fix status versus deployed DLMM bytecode cannot be determined.[1] Not verifiable as of 2026-09-04
Evidence (2)

audit

unverified

Meteora DLMM — Zenith audit v0.12.0

Auditor
Zenith
Report date
2026-09-04
Scope
DLMM program v0.12.0
Findings
Critical: Not verifiable as of 2026-09-04. High: Not verifiable as of 2026-09-04. Medium: Not verifiable as of 2026-09-04. The official index confirms the report but does not expose its finding summary in the retrieved content.
Fix status
Not verifiable as of 2026-09-04. Covers deployed code: Not verifiable as of 2026-09-04; no bytecode/version match was performed (Dune unavailable).
Evidence (1)

Team & Reputation

founders

two sources

Meteora DLMM on Solana is built by a non-anonymous, multi-founder team, with a history in earlier Solana DeFi and at least one significant controversy around a key co-founder. Founders & key team

  • Multiple sources link Meteora to the Mercurial Finance stablecoin DEX on Solana, describing Meteora as its rebrand/evolution.
  • Early and core founders/co-leads repeatedly cited include Ben Chow, Meow, Zhen Hoe Yong (often “Zen/Zhen”), Siong, Soju, and technical lead TRAV.
  • Roles described off-site: Zhen Hoe Yong as co-founder/project lead; TRAV as CTO and DLMM/dynamic fee designer; ROOK as COO with investment banking background; Ben Chow as co-founder/former CEO; 0xM as advisor/founder.
  • Recent coverage notes that after Ben Chow resigned in Feb 2025, Meteora is co-led by Zhen Hoe Yong and Soju. Prior projects & track record
  • Meteora is portrayed as the successor to Mercurial Finance, one of Solana’s first stablecoin DEXs.
  • Several sources link Ben Chow and Meow to Jupiter, a leading Solana DEX aggregator, implying shared founding DNA and ecosystem credibility. Legal / reputational issues
  • An IQ.wiki entry reports that in February 2025 a federal class-action lawsuit was filed against co-founder Ben Chow, alleging pump‑and‑dump schemes around LIBRA, M3M3, and TRUST tokens using celebrity endorsements to defraud retail investors.
  • Independent articles also reference a "Phoenix Rising Plan" and Ben stepping down, consistent with a reputational restructuring.
  • Outcome of the lawsuit and any regulatory findings: Not verifiable as of 2026-09-04. Public vs. anon; office; jurisdiction
  • Founders are partially doxxed: most sources use real names (e.g., Zhen Hoe Yong, Ben Chow) mixed with pseudonyms (Meow, TRAV, ROOK, Soju, 0xM).
  • A business-profile site lists Meteora.ag with a named co-founder contact (Ben Chow) and email-format info, suggesting some level of corporate structuring but not clearly stating jurisdiction, registered entity number, or physical office.
  • No independent confirmation of a registered corporate entity, onshore/offshore status, or physical office address beyond marketing-style profiles: Not verifiable as of 2026-09-04. Reality check (institutional lens)
  • Positives: veteran Solana DeFi builders, track record with Mercurial & Jupiter; semi-public leadership; broad ecosystem coverage.
  • Negatives/flags: unresolved class-action allegations against a key founder; heavy use of pseudonyms; lack of independently verified corporate registration and office information.
  • Overall, Meteora appears to be a real ongoing DeFi business with substantial technical output and ecosystem integration, but with material founder legal risk and incomplete corporate transparency by institutional standards.
Evidence (15)

general reputation

unverified

Meteora DLMM appears to be a legitimate Solana DeFi protocol operated under Meteora, with public documentation and a live app at app.meteora.ag. Public-facing materials indicate the project has been marketed as audited by Offside Labs, OtterSec, and Sec3, but I did not independently verify the underlying audit reports in this run, so auditor details remain *partly unverified* here. The reputation profile is generally mixed-positive: the protocol has an active developer presence and SDK documentation, and third-party commentary describes it as a major Solana liquidity venue with institutional backing from investors such as Delphi Ventures, Signum Capital, Alliance DAO, and HyperChain.

However, that investor list comes from a secondary source in this run and should be treated cautiously until cross-checked against primary disclosures. I did not find credible evidence in the retrieved material of fraud, rug-pull, insolvency, sanctions, or active legal/regulatory action specifically against Meteora DLMM. That said, unresolved concerns remain because the search results here are dominated by protocol and promotional materials rather than independent audits, court/regulatory records, or investigative reporting.

Not verifiable as of 2026-09-04: detailed founder identities, confirmed audit scope/findings, exact investor cap table, and any unresolved security incidents or formal allegations specific to Meteora DLMM.

Evidence (5)

Economy

TVL: $187.5M

model

one source

Assessment (as of September 6, 2026). Meteora DLMM is a Solana concentrated-liquidity market maker: users deposit one or both pair assets across discrete price bins and earn swap fees when trades use their liquidity. LPs may also receive pool-specific liquidity-mining rewards, so yield is not universally organic. The primary organic source is trading fees; reward emissions, where configured, are subsidized/incentive yield. Risk/economic profile. This is not inherently market-neutral: concentrated LPs bear inventory rebalancing and impermanent-loss/price risk; one-sided positions can be explicitly directional.

No required leverage, looping, restaking, lending, or external collateral exposure was identified. LP positions are the relevant collateral/economic claim, not borrow collateral. Exact leverage and external-exposure percentages: Not verifiable as of September 6, 2026. Entry/exit. Deposits can be strategy/range-based and withdrawals can be partial by bin range or 100% of liquidity; fees and rewards may be claimed during removal, with position closure optional.

No protocol lock-up is indicated. Transaction fees, account rent, slippage, out-of-range inventory, and token-specific transfer fees remain practical gates. Fees/revenue. DLMM standard pools currently document a 90% LP / 10% protocol-side split; launch pools use 80% / 20%; limit-order liquidity uses 50% / 50%. Host fees, when used, are carved from protocol-side fees.

Revenue is collected in the traded tokens, not automatically converted to stablecoins. TVL and trend. DefiLlama reports $207.58m TVL, 100% Solana, up 19.4% over 30 days; 30-day fees are $12.94m and protocol revenue $1.31m. By-product breakdown beyond DLMM: Not verifiable as of September 6, 2026. Dune comparison and block-level trend: Not verifiable as of September 6, 2026. Contradiction / sustainability. DefiLlama’s older DEX page reports a lower, stale 30-day volume snapshot than its current protocol page; this is a timestamp mismatch, not a reconciled on-chain result.

APY history, volatility, and the organic share of yield cannot be reliably quantified from the available sources: Not verifiable as of September 6, 2026.

Evidence (3)

reserves

two sources

As of September 6, 2026, no Dune MCP/on-chain verification was available; therefore balances, liabilities, full wallet ownership, and transaction-level custody controls are Not verifiable as of September 6, 2026. Current reserve size/composition: Meteora’s H1 2026 report explicitly stopped publishing treasury addresses and balances for security reasons. It states that earlier reports covered treasury cashflows, but the reserve position is no longer disclosed. A historical Q1 2026 report stated a $33.9M treasury position as of March 31, 2026, comprising $15.1M USDC/USDT, $11.7M SOL/WSOL, and approximately $3M of other tokens; this is stale and not a current balance. Addresses: Meteora’s investor-relations directory identifies a MET Buyback Wallet, Meteora Reserve Vault, Meteora Reserve Wallet, Meteora Ecosystem Wallet, Team Vault, and Team Wallet, but publishes only truncated addresses.

Full reserve addresses and balances are Not verifiable as of September 6, 2026. Reserve policy: The MET allocation includes a 34% Meteora Reserve (340M MET) and an 18% Team allocation; both are shown as non-circulating and vest linearly over 72 months. The H1 report states that 4.72M MET/month was unlocking to the Ecosystem Reserve, with 37.8M MET cumulatively unlocked by June 30, 2026; unlocked tokens had no specific earmark. Governance materials describe reserve use primarily for liquidity incentives and ecosystem growth. Custody/control/attestations: No current primary-source confirmation of multisig signers, threshold, legal custody, reserve segregation, liabilities, or third-party reserve attestation was found.

A secondary analysis claims Squads multisigs, but this is not independently confirmed here. Meteora reports a 40/40 Blockworks transparency score, which is a disclosure assessment—not a reserve attestation. Contradiction: DeFiLlama currently displays a $21.63M tracked treasury, while Meteora’s latest report withholds current treasury balances. The DeFiLlama figure is an analytics estimate, not an on-chain-verified reserve balance.

Evidence (5)

tokenomics

two sources

MET is the native token of Meteora DLMM on Solana. Mint: METvsvVRapdj9cFLzq4Tr43xK4tAjQfwX76z3n6mWQL. Supply/valuation — analytics snapshot, not Dune-verified: total supply is ~997.73M MET; max supply 1B. CoinMarketCap reports 544.21M circulating (54.42%), price ~$0.201, market cap ~$109.4M and FDV ~$201.1M.

CoinGecko reports ~550.33M circulating and ~$100.9M market cap, so circulating figures conflict. [Contradiction] Meteora IR’s allocation dashboard still shows 48% circulating / 52% non-circulating. On-chain reconciliation is Not verifiable as of September 4, 2026 because Dune was unavailable. Allocation/unlocks: Community 54% (including 34% Meteora Reserve, 15% LP Stimulus, 3% Jupiter stakers, 2% off-chain contributors); Foundation 23% (15% Mercurial holders, 5% Mercurial Reserve, 3% TGE Reserve); insiders 20% (18% team, 2% M3M3); public investors 3%. The Reserve and Team allocations began linear unlocking one month after the October 23, 2025 TGE: 4.722M and 2.5M MET monthly, respectively, through October 2031.

Public reports confirm unlocks commenced, but whether every announced unlock occurred on-chain is Not verifiable as of September 4, 2026. Utility/governance: MET is used for ecosystem/launch access, liquidity incentives, LP-stimulus programs, staking/engagement points and pool pairing. Meteora publishes community proposals, but there is no formal on-chain governance mechanism for protocol upgrades; upgrades remain controlled by a team multisig. No direct fee/revenue entitlement is established.

Q1 2026 disclosures report $1M of MET buybacks and $13.67M cumulative USDC buyback expenditure; tokens are held in a buyback wallet. Burns and staking yield emissions are Not verifiable as of September 4, 2026. Contract controls/concentration: mint authority is disabled and freeze authority is disabled. Top-10 holders reportedly control ~80%; the largest wallets include ~30%, 14%, 14% and 8% of supply, largely consistent with reserve/team allocation wallets, but insider beneficial ownership is Not verifiable as of September 4, 2026.

Fee-switch authority and exact controller are Not verifiable as of September 4, 2026. Liquidity/listings: stale analytics show roughly $2.8M tracked DEX liquidity, mainly MET/USDC and MET/SOL Meteora pools; current depth is Not verifiable as of September 4, 2026. Main listings include Meteora DLMM, Binance, Bybit, Coinbase, HTX and WhiteBIT.

Evidence (7)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Meteora DLMM, a Bitcoin move below $10,000 is not a protocol-wide insolvency trigger by itself; the main effect is position-specific deactivation and impermanent loss for pools whose price ranges are tied to BTC or BTC-correlated assets. Meteora’s DLMM uses discrete bins, and when price moves outside a chosen range, the position becomes inactive and fee earning stops; positions can also become one-sided if price exits the range. In a BTC crash scenario, the risk depends on the pool composition:

  • BTC/USDC or BTC-stablecoin pools: LPs positioned above the new market price can be fully converted into the weaker side or into the stablecoin side, while LPs positioned below may end up holding mostly BTC if the crash overshoots their range; either way, out-of-range liquidity stops earning fees.
  • BTC-correlated volatile pairs: the same bin-based mechanics apply, but loss behavior is more path-dependent because both legs may fall together.
  • Non-BTC pools on Solana: direct exposure is limited unless the protocol’s overall activity or collateral demand is indirectly affected. Operationally, the stress outcome for LPs is usually range break + forced rebalance decision: close the position, move the range lower, or wait for price recovery. Several third-party guides describing Meteora DLMM explicitly note that once price leaves the chosen band, the position becomes inactive and users may need to close or rebuild the position. What is not verifiable as of 2026-09-04 from the provided sources is any protocol-level TVL drawdown, liquidation cascade, or Solana-wide spillover specifically caused by BTC falling below $10,000. The available sources only support the position mechanics, not a quantified systemwide impact.
Evidence (7)

stress scenario - largest collateral depegs 20%,

two sources

Meteora DLMM does not publish a protocol-level stress-test result for a 20% depeg in the largest collateral in the provided sources. What can be said is that DLMM is designed around discrete price bins, and Meteora recommends using *smaller bin steps* and *Curve or Spot-Concentrated strategies* when price is expected to stay near peg; if price moves away from the chosen range, LPs stop earning fees until they rebalance or reallocate. For a 20% collateral depeg, the relevant risk is range exit / adverse inventory exposure, not protocol insolvency.

The documentation explicitly states that DLMM pools support different modes and that active management is required when market price leaves the selected range; it also notes that DLMM still carries impermanent loss and strategy-related risk. Because Dune/on-chain verification is unavailable in this run, the pool-by-pool exposure, chain-level TVL, and any exact loss estimate for Meteora DLMM under a 20% depeg are Not verifiable as of 2026-09-04. The only defensible conclusion from the available sources is that a 20% depeg would materially increase LP losses and likely push many positions out of range, especially for tighter bin-step strategies.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

For Meteora DLMM on Solana, the main stress is a large LP or trader becoming insolvent or unable to meet obligations off-chain. On-chain, DLMM is a non-custodial AMM: assets are always held in pools and positions are fully collateralized, so insolvency is economic (price impact, bad debt elsewhere), not a failure to repay inside the AMM itself. 1. LP (liquidity provider) insolvency

  • Path: LP is levered elsewhere and forced to unwind; they withdraw liquidity or suffer adverse price moves on their DLMM position. DLMM pools reprice via trades; LP’s range orders can be left with large impermanent loss or concentrated exposure.
  • Who absorbs loss: The LP alone: pool accounting is token-based; there is no notion of margin or shared liability. Other LPs only bear normal AMM inventory and price risk.
  • Compensation: None at protocol level. Losses are market P&L, not protocol failure.
  • Contract impact path:
  • LP’s position NFTs record fewer assets or more of the depreciated token.
  • No pool insolvency: reserves must remain non-negative for swaps to execute.
  • If LP rage-quits and pulls liquidity, slippage and price impact for future traders rises; but smart contracts remain solvent. 2. Large trader / arb / market maker insolvency
  • Path: Trader is bankrupt elsewhere and cannot continue providing external liquidity. On-chain, trades that were executed on Meteora DLMM were already fully paid at the time of swap; there is no unsettled credit.
  • Who absorbs loss:
  • The trader’s off-chain creditors; DLMM pools have already received tokens in each swap.
  • LPs absorb any adverse selection (being picked off around oracle or CEX price moves), but again as normal AMM risk.
  • Compensation: None via protocol.
  • Contract impact path:
  • Lower traded volume and worse price linkage to CEX/other DEXs if key MM disappears.
  • Potentially wider spreads / worse execution, but no bad debt or frozen pools. 3. Meteora / program-level counterparty failure (operational insolvency)
  • Path: Protocol team fails financially, stops maintaining front-end, infra, or risk monitoring. Smart contracts on Solana remain deployed and non-custodial.
  • Who absorbs loss: Users bear *operational* and *governance* risk (e.g., no upgrades, slower response to exploits), but existing pool balances are untouched unless an upgrade authority is abused—Not verifiable as of 2026-09-04.
  • Compensation: Any backstop fund or insurance would be an unverified marketing claim unless documented independently—Not verifiable as of 2026-09-04.
  • Impact path: Degraded UX, potential security decay over time; on-chain positions remain, but practical access may require alternative UIs. 4. Systemic Solana / stablecoin counterparty stress If a major stablecoin or Solana venue becomes insolvent, DLMM pools holding that asset reprice sharply; LPs holding the depegged asset absorb losses, traders may profit or lose depending on timing, but smart contracts simply enforce swap math without socialization.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For the DAO/owner fraud stress scenario, I found no verifiable evidence in the provided sources that Meteora DLMM’s DAO or owners committed fraud against users. The available materials are mostly product documentation, which does not establish misconduct, and one independent media report about Meteora losing $1.5M in an OTC buyback scam—that report describes Meteora as the victim, not the perpetrator. The only potentially adverse item in the results is a Bitget summary mentioning that Meteora’s founder resigned in February 2025 after the Libra memecoin controversy, while maintaining that neither he nor Meteora engaged in financial misconduct; however, this is secondary reporting and does not prove fraud by the protocol’s DAO or owners.

There is also no on-chain verification available in this run, so treasury movements, governance actions, and owner-controlled contract behavior are Not verifiable as of 2026-09-04. Based on the evidence provided, the correct classification for “committed fraud by the DAO or owners” is not established rather than confirmed.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

For a 30-day negative-yield stress case, the key point is that Meteora DLMM’s primary yield sources are swap fees and, for some pools/modes, liquidity rewards; if 30-day trading activity is weak or the position spends much of the time out of range, realized yield can fall to zero or negative net PnL after impermanent loss and rebalancing costs. Meteora’s own docs describe DLMM as concentrating liquidity in discrete bins with dynamic, volatility-aware fees, and they note that liquidity mining and limit-order behavior are separate modes. The docs also recommend tighter, peg-focused strategies only when price is expected to stay near the peg, which implies that adverse price moves can materially reduce fee capture for a passive LP.

A negative 30-day stress outcome is therefore most consistent with: low swap volume, price moving away from the active bins, and a position that is not actively re-centered. Under that scenario, the LP still bears the usual AMM risks, including impermanent loss; the third-party guides in the search results explicitly state that DLMM returns mainly come from trading fees and liquidity rewards, and that impermanent loss remains a risk. I cannot verify any chain-level 30-day APY or pool-specific negative-yield figure from the provided sources, so the precise magnitude is Not verifiable as of 2026-09-04.

Evidence (5)

Governance & Legal

governance

one source

As of September 13, 2026, Meteora DLMM is company/foundation-controlled, not token-holder governed. The governance forum is active and accepts discussion/proposals, but current disclosures state there is no DAO and MET holders have no voting, governance, ownership, treasury, or profit-sharing rights. Governance is therefore symbolic/advisory rather than binding over parameters, upgrades, or treasury.

Control surface: Solaris Labs Ltd (BVI business company) owns the protocol software/IP and licenses it to Meteora Foundation, a Cayman Islands exempted limited-guarantee foundation company. The Foundation controls the treasury and may direct Solaris under a services agreement dated June 5, 2025. MeteoraAg controls the public SDK, documentation, integration tooling, and frontend ecosystem.

The deployed lb_clmm program is LBUZKhRxPF3XUpBCjp4YzTKgLccjZhTSDM9YuVaPwxo; its source is not open-source. Administrative powers: the team multisig reportedly holds program upgrade authority and controls protocol fee parameters, treasury operations, and the MET reserve. The filing describes Squads cold-wallet quorum as 4-of-7 and hot-wallet quorum as 3-of-5, but does not identify the current signer set or map each wallet to DLMM controls.

It states there is no formal on-chain governance or timelock for contract upgrades. Top-holder concentration, voting concentration, exact multisig addresses/signers, signer independence, emergency bypasses, and whether any admin can directly drain user LP funds: Not verifiable as of September 13, 2026. Dune MCP was unavailable, so no on-chain verification or Dune query/execution IDs exist.

Legal terms: the frontend Terms use “Company” without clearly naming the legal entity in the retrieved text; governing law is BVI law, with BVI IAC arbitration in Road Town. Registration numbers for Solaris Labs Ltd and Meteora Foundation were not found.

Timelock
No
Dao governance
No
Evidence (5)

legal & regulatory

two sources

As of September 4, 2026, the identified operating entity is Meteora Nova Limited, with the Terms selecting British Virgin Islands (BVI) law and BVI IAC arbitration in Road Town. A third-party registry reports BVI incorporation number 2177850 dated May 28, 2025; registry verification is not independently confirmed. Terms/restrictions: The Terms describe Meteora as non-custodial, peer-to-peer smart contracts plus a UI, disclaiming status as an exchange, broker, dealer, fund manager, custodian, intermediary, or regulated service.

They prohibit use by U.S. persons and residents of numerous sanctioned/restricted territories, prohibit VPN circumvention, and reserve unilateral access suspension. KYC/AML: KYC/AML is discretionary rather than universally mandatory: the company may conduct identity and wallet screening, request documents, block access, and disclose information to authorities. Users warrant that assets are not linked to money laundering or terrorist financing.

Classification/legal risk: The contractual “software/UI only” position does not eliminate regulatory exposure. A pending SDNY putative class action, *Hurlock v. Kelsier Ventures*, names “Meteora” and former CEO Benjamin Chow, alleging manipulation and fraud connected with $M3M3 and $LIBRA launches.

These are allegations, not adjudicated findings. A court order recorded the dispute over whether Meteora is software or an unincorporated association; no final merits determination is shown in the reviewed materials. Do not confuse this protocol with unrelated “Meteora Capital” litigation.

Warnings/enforcement/sanctions: No regulator enforcement action against Meteora Nova Limited or the DLMM protocol was identified. No sanctions listing for the protocol/entity was located; this does not assess screened wallets. Privacy materials invoke BVI Data Protection Act 2021 and provide CCPA/EEA disclosures, with collection of wallet, IP, device, and usage data.

Risk conclusion: Formal structure is offshore, non-custodial, and liability-limited, but practical risk remains concentrated in interface control, eligibility enforcement, upgrade/operational personnel, token-launch relationships, and litigation/attribution risk.

Active enforcement
No
Sanctioned
No
Entity
Meteora Nova Limited
Jurisdiction
British Virgin Islands
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Meteora Nova Limited', 'Meteora DLMM'. OFAC SDN screening of 'Meteora Nova Limited', 'Meteora DLMM': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Meteora Nova Limited
  • Meteora DLMM
Sanctioned
No
Evidence (4)

Stability

stability

unverified

Meteora DLMM does not appear to issue its own stablecoin. The available evidence shows it is a Solana DEX/liquidity protocol that supports pools using external stablecoins such as USDC and USDT, and its documentation discusses stablecoin pairs and peg-oriented pool strategies rather than a Meteora-native stable asset. No reliable evidence was found that a Meteora-issued stablecoin ever depegged, so depeg_count, max_depeg_pct, and last_depeg_date are not verifiable as of 2026-09-06.

The stable flag is not applicable to protocol-issued stablecoin stability in this case.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

two sources

Meteora DLMM’s principal exposures are smart-contract failure, concentrated-liquidity economics, permissionless pool/token quality, upgrade-key governance, and Solana execution dependence. Audits and a bug bounty reduce—but do not eliminate—technical risk; precise current TVL, exposure concentration, and authority configuration are Not verifiable as of September 5, 2026 without Dune/on-chain validation.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract exploitA program bug, accounting error, or integration flaw could allow direct pool loss, mispriced swaps, or denial of withdrawals. Audits are point-in-time reviews and do not cover every economic or composability failure.HighMediumMultiple DLMM audit reports, public source/audit repository, and a bug bounty covering DLMM.High-impact unknown vulnerabilities and novel economic exploits remain possible.
Upgrade-key compromiseCompromise or misuse of upgrade authority could replace audited code and alter fund-handling logic without an exploit in the released version.HighLowReported multisignature control over critical operations; independent transparency disclosures.No formal on-chain timelock is documented in the reviewed filing; exact current authority state is Not verifiable as of September 5, 2026.
Concentrated-liquidity lossPrice movement can push liquidity out of active bins, create one-sided inventory, and produce impermanent/loss-versus-rebalancing losses that exceed fees.HighHighUser-selectable bin ranges, dynamic fees, position management, and user-defined slippage limits.LP strategy, volatility, adverse selection, and rebalancing timing remain user-borne risks.
Permissionless pool and token riskLPs may face rugged, manipulated, illiquid, frozen, transfer-taxed, or otherwise defective assets; audits do not validate every listed token or pool creator.HighHighPermissionless design is supplemented by UI/data screening and Token-2022 handling in current tooling.Asset-specific loss can be total; pool-level screening is not a guarantee.
Solana availability riskCongestion, validator incidents, or RPC degradation can prevent timely swaps, withdrawals, rebalancing, or liquidation during volatile markets.HighMediumDeployment on Solana’s high-throughput network and standard transaction slippage/confirmation controls.Single-chain dependence remains; current outage probability and DLMM exposure are Not verifiable as of September 5, 2026.
Evidence (5)

strengths

two sources

Meteora DLMM’s top strengths are: capital efficiency, because it concentrates liquidity into price bins around active trading ranges; lower slippage / better execution, because trades inside active bins face minimal price impact; dynamic fees, which adjust with volatility to better compensate LPs; strategy flexibility, since LPs can shape liquidity distribution and choose different volatility profiles; and Solana-native liquidity infrastructure / launch utility, including support for token launches and routing integrations that make the protocol useful beyond standard swapping. If you want, I can also rank these strengths by importance for LPs versus traders.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 9 one source, 9 unverified.
  • Oldest fact verification date: 2026-08-29.