Midas RWA

Green · 75/100

Executive summary

Midas RWA is a regulated asset-tokenization protocol issuing ERC-20 "mTokens" backed by real-world strategies (Treasuries, credit, DeFi), scoring 64/100 (orange band) with high data confidence (89/100) and a -10 penalty for unresolved incident remediation.

  • Security: Multiple audits by Côme du Crest, Hacken, and Sherlock (2023–2025) with one unresolved high-severity finding (storage-layout incompatibility in max-supply update); active bug bounty up to $500k USDC launched March 2026; no protocol-originated exploits verified, though one high finding from the max-supply audit remains documented as unresolved in structured data.
  • Incidents: mF-ONE liquidity crisis (Nov 2025) created redemption queue with ~$37M pending as of Feb 2026; no principal loss but remediation incomplete; KelpDAO bridge pause (Apr 2026) caused temporary service halt, resolved with upgraded DVN config; status: remediation_in_progress for mF-ONE, resolved for KelpDAO dependency event.
  • Governance & custody: Company-controlled (Midas Software GmbH, Germany; sole shareholder Midas Protocol Limited, UK); no DAO or token-holder governance verified; upgradeable proxies with timelock and role-based access; MPC custody via Fireblocks/Fordefi with policy controls; admin can drain, pause, blacklist, and upgrade contracts.
  • Top risks: Issuer insolvency and legal enforceability (qualified subordination can delay recovery); redemption liquidity stress (instant mode can queue 1–7 days); oracle/NAV dependence on off-chain data (Ankura verification does not guarantee redemption at oracle price); bridge/cross-chain risk (LayerZero, Axelar); regulatory access restrictions (non-US/UK only, unverified marketing claim).
  • Strengths: EU-regulated positioning with institutional custody (Maerki Baumann, OZL, ATG); DeFi-composable ERC-20 design; multi-layer transparency (Ankura daily verification, Attestation Engine with LlamaRisk/Canary); $8.75M seed from Framework, BlockTower, Coinbase Ventures; ~2.1 years operational with no protocol-originated hacks; instant redemption mode when liquidity available.
  • Unverified: On-chain TVL, exposure by chain, reserve wallet addresses, live collateral balances, deployed-code bytecode match to audited commits, complete remediation status for all audit findings, fraud/sanctions enforcement history, and whether audit scope covers all nine listed chains (Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, XRPL EVM) are not verifiable as of 2026-09-06.
  • Recommended exposure: Limit to <5% of portfolio; treat as credit/legal exposure to Midas Software GmbH and custodians, not pure on-chain DeFi; verify redemption queue status and instant-mode capacity before entry; suitable only for non-US/UK allocators comfortable with 1–7 day redemption risk, qualified subordination, and dependence on issuer solvency and off-chain attestations; avoid if instant liquidity or DAO governance is required.
  • Open questions: Verify current mF-ONE redemption queue clearance and buffer rebuild; confirm bytecode match between audited commits and live deployments on all chains; obtain independent legal opinion on bankruptcy-remoteness and qualified-subordination enforceability; check live reserve addresses and collateral balances; validate whether all high/critical audit findings are remediated on deployed code; assess custodian and security-agent failure scenarios with legal counsel.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 13 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-03-20)
Incidents 20% 100 20.0 1 open incident(s), $0 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 1 0.2 TVL $154,543,842 = 1% of reference ($17,538,184,136)
Data confidence 89 7/7 critical categories; 21/47 verified facts; 47/47 fresh (180d)

Identification

protocol identification

two sources

Identification — Midas RWA (midas-rwa). Name: Midas Protocol / Midas RWA. Website: midas.app; documentation: docs.midas.app. Category: RWA/tokenized-yield protocol issuing ERC-20 “mTokens” backed by or referencing real-world and crypto strategies (e.g., mTBILL, mBASIS, mMEV).

The earliest independently corroborated product inception is December 1, 2023 (mTBILL); CertiK lists estimated protocol launch as December 2, 2023. User-specified supported chains: Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK/Rootstock, TAC and XRPL EVM. The nine-chain footprint is corroborated by DIA, but current deployments beyond the addresses below were not independently address-verified in this run.

Native token: No separate protocol/governance token identified. mTBILL, mBASIS, mMEV and other mTokens are products, not native protocol tokens. Contract cross-check / explorer status. Dune MCP was unavailable; therefore Dune cross-checks and on-chain verification are Not verifiable as of September 4, 2026. Documentation lists the following principal mTBILL contracts: Ethereum token 0xdd629e5241cbc5919847783e6c96b2de4754e438, issuance vault 0x99361435420711723aF805F08187c9E6bF796683; Base token 0xDD629E5241CbC5919847783e6C96B2De4754e438, issuance vault 0x8978e327FE7C72Fa4eaF4649C23147E279ae1470. Ethereum’s token address is independently present on Etherscan, with verified proxy/implementation source and upgrade history.

Base explorer verification status and principal addresses for Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC and XRPL EVM: Not verifiable as of September 4, 2026. Fork lineage. No evidence found that Midas is a fork of Compound, Aave or another named DeFi protocol; its public repository is presented as Midas-owned EVM contracts. Exact upstream lineage and change-set: Not verifiable as of September 4, 2026. Midas’s 2024 Sherlock contest audited Midas-specific vault, access-control, oracle and mTBILL code; it explicitly disclosed upgradeability, privileged mint/burn, blacklist and pause powers, plus centralization risk.

Similar-name Midas Capital was a separate Compound/Aave-style fork that suffered an exploit; this is relevant fork-risk context, not evidence of a Midas RWA incident.

Evidence (8)

maturity

two sources

Midas RWA appears to be a real product, not just a marketing landing page: its official site and docs are referenced by third-party API directory data, and external ecosystem pages link to a live portal plus documentation. The clearest maturity signal is that independent sources describe functional user flows such as deposits, redemptions, and asset issuance, while an audit write-up notes the system includes DepositVault and RedemptionVault components and that USDC deposits are converted to mTBILL off-chain. That said, some claims remain only partly verifiable without on-chain checks, so live deposit/withdrawal status across Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, and XRPL EVM is Not verifiable as of 2026-09-04.

The strongest off-chain evidence suggests a working app and data/app layer, including a dedicated Midas RWA Data App with daily NAV, APY, deposits, withdrawals, holders, and performance views. ## UX / docs / template quality Independent references show the project has structured docs and API-style assets, which is a positive maturity sign. However, because the available evidence is mostly directory/listing data and ecosystem mentions rather than direct page inspection, broken links, fake metrics, or template-site signs are Not verifiable as of 2026-09-04. ## Open API Yes, an API appears to exist. The APIs.io listing explicitly points to Midas website and documentation endpoints and exposes an operations/evidence interface for the provider, while a separate Midas API documentation page describes REST and WebSocket endpoints, API keys, and SDKs.

What cannot be verified from the available evidence is whether this API is public/open to all users versus partner-gated or account-gated, so that part is Not verifiable as of 2026-09-04.

Evidence (4)

Security

bug bounty

two sources

Midas RWA has an active dual-platform bug bounty program. It launched on 23 Mar 2026 and was announced publicly on 7 Apr 2026. The program is run in partnership with Sherlock and Cantina, with critical rewards up to $500,000 USDC.

Scope covers the full Midas contract suite across Ethereum and Solana, including mToken contracts, access control, deposit/redemption vaults, data feeds, LayerZero OFT, Axelar vault, contract configuration, and the web interface. Reward rules: critical findings are paid at 10% of funds directly at risk, capped at the program maximum; high severity rewards are capped up to 100% of funds directly affected; total rewards for a given scope are subject to hard caps, and the program states total rewards paid will not exceed $1,000,000. Reported results include 349 findings submitted on Cantina.

There is no separately verifiable on-chain result set available in this run.

Active
Yes
Platform
Sherlock and Cantina
Max payout
$500K
Since
2026-03-23
Evidence (4)

counterparty risks

one source

As of September 6, 2026, no dependency failure, exploit, depeg, or insolvency event was verified from available sources. On-chain verification was skipped: Not verifiable as of September 6, 2026. Primary counterparty stack: Midas Software GmbH is the issuer/SPV. For mTBILL, disclosed dependencies include short-duration U.S.

Treasuries, Maerki Baumann as custodian, OZL as crypto custodian/broker, and ATG Azimut Treuhandgesellschaft as security agent. Custody segregation and secured claims are described in the legal structure, but recovery remains exposed to legal enforcement, custodian failure, fraud, sanctions, settlement delays, and asset/liability mismatch. Oracle / NAV manipulation: Pricing depends on issuer reference values and off-chain collateral/NAV data. Ankura is described as an independent verifier for mTBILL; the broader attestation stack uses Chainlink, vLayer, LlamaRisk, and Canary.

These attestations improve auditability but do not guarantee asset ownership, liquidity, valuation accuracy, or redemption at oracle price. Midas explicitly states redemption value may differ from oracle reference. Bridges and smart contracts: Published contracts use LayerZero and Axelar for cross-chain functionality; bridge/message-layer compromise, mint/burn accounting errors, privileged-key compromise, or chain finality failure could create wrapped-token insolvency or cross-chain price divergence. Audits exist, but audit coverage is not equivalent to proof of safety. Liquidity / failure scenarios: Instant redemption is not guaranteed for 100% of collateral; fallback redemption can take 1–7 business days.

Stress could therefore produce discounts, queues, oracle/redemption divergence, or forced liquidation. Stablecoin, LST/restaking, CEX/MM exposure: No reliable source verified portfolio percentages or material exposure for the supplied chains. Not verifiable as of September 6, 2026. > Contradiction: Prior notes called Midas a “stablecoin stack.” Current Midas documentation says mTokens are financial instruments, not stablecoins or DeFi vaults; the stablecoin characterization should be removed or limited to marketing analogy.

Evidence (5)

crypto custody

one source

Midas’ crypto custody appears to use a split model: operational on-chain keys are managed through institutional MPC custody with policy controls, while the underlying product collateral is held under a separate off-chain legal custody structure. Third-party sources indicate Midas uses Fireblocks and Fordefi for MPC wallet custody, with tri-party/quorum approvals and an admin share so routine actions can be executed under policy while exceptions require multi-party approval. The prospectus names a custodian and a security agent, which indicates the program’s collateral is not held directly by the token contract but is ring-fenced in a governed custody arrangement.

Withdrawal pausing is not verifiable as of 2026-09-06. Segregation of assets is partially supported by the prospectus/custody structure, but the exact legal segregation level across all products is not fully verifiable as of 2026-09-06.

Segregated assets
Yes
Evidence (3)

incident

unverified

Correction: the June 17, 2023 exploit previously associated with this review belongs to Midas Capital, a separate BNB Chain lending protocol, not Midas RWA. It is excluded from Midas RWA's incident history because of the name collision. No Midas RWA-specific exploit is verifiable from the reviewed sources as of 2026-09-06.

Date
2023-06-17
Cause
Smart-contract exploit
Loss
$340K
Status
status unknown
Event id
excluded-midas-capital-name-collision-2023-06-17
Evidence (1)

incident

one source

mF-ONE liquidity/settlement incident began on November 14, 2025, when the instant-redemption buffer reached zero and a redemption queue formed. Affected mF-ONE holders lost immediate exit capacity but available evidence indicates no realised principal or NAV loss. By December 31, the buffer had been substantially rebuilt.

As of February 28, 2026, approximately $37 million of mF-ONE remained in eight pending redemption requests. Midas subsequently offered a fee-free standard redemption mode advertised to settle within 48 hours. Full queue clearance, user reimbursement, and final remediation are Not verifiable as of 2026-09-06.

Current status: remediation_in_progress.

Date
2025-11-14
Cause
Liquidity issue
Loss
$0
Status
remediation in progress
Recovered
$0
Reimbursed
No
Event id
midas-mf-one-redemption-liquidity-2025-11-14
Evidence (2)

incident

two sources

Bug bounty coverage is active and public. In March 2026, Midas launched a dual-platform bug bounty with Sherlock and Cantina, advertising up to $500,000 USDC for critical findings; the policy says critical rewards can be 10% of affected funds, capped at the program maximum. That indicates a formal security disclosure process and a material incentive for researchers.

Date
2026-03-24
Cause
Other
Evidence (2)

incident

one source

External dependency incident, not a Midas-originated exploit. On April 18, 2026, KelpDAO's rsETH bridge was exploited through a forged cross-chain message accepted under a single-DVN LayerZero configuration. Midas paused mToken minting/redemptions and LayerZero OFT bridging as a precaution.

No Midas asset or user loss was reported; the affected users experienced temporary transaction unavailability. Standard services resumed progressively on April 19 and April 21, and bridging resumed on April 28 after Midas upgraded its DVN configuration from 3/3 to 4/4 and reviewed monitoring and incident-response controls. Current status: resolved.

Date
2026-04-18
Cause
Bridge / third-party collateral failure
Loss
$0
Attacker proceeds
$292.0M
Status
resolved
Recovered
$0
Reimbursed
No
Event id
midas-kelpdao-rseth-dependency-2026-04-18
Evidence (2)

key management

two sources

Midas appears to organize key management through Fireblocks, using a shared Fireblocks workspace with Edge Capital and MPC-based custody for operational control of vaults. Fireblocks says Midas gets policy granularity across user groups and uses Fireblocks-connected vaults for 24/7 investment and redemption, which implies role-based access and approval policies around key use rather than single-party hot-wallet control. Midas also describes its stack as including regulated custody through licensed partners, but the exact internal key ownership model, signer quorum, and recovery procedures are Not verifiable as of 2026-09-04 from the available sources.

For risk review, the most defensible reading is that key management is institutionalized and outsourced to MPC custody infrastructure, with operational permissions separated between Midas and its counterparties via policy controls in the Fireblocks workspace. I could not verify whether this applies uniformly across Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, and XRPL EVM, or whether chain-specific keys are managed differently; that is Not verifiable as of 2026-09-04.

Evidence (2)

smart-contract

two sources

Assessment date: September 6, 2026. Dune is unavailable in this run; therefore proxy storage, implementation, admin ownership, role holders, event history, timelock delay, and current deployment verification are Not verifiable as of 2026-09-06. Address inventory (repository-declared, not on-chain verified): Ethereum — AccessControl 0x0312…9aFc919aC4B; Timelock 0xE3EE…e241852; mTBILL 0xDD629…54e438; DepositVault 0x9936…796683; RedemptionVault 0xF6e5…6d4517. Base — AccessControl 0x0312…9aFc919aC4B; Timelock 0x9230…9B8EB0cB; mTBILL 0xDD629…54e438; DepositVault 0x8978…9ae1470. Etherlink — AccessControl 0x0312…9aFc919aC4B; Timelock 0x852C…698F76; mTBILL 0xDD629…54e438; DepositVault 0xd65B…33a70.

Monad — AccessControl 0x9379…a4a75F; Timelock 0xfc8a…39B852c. OP Mainnet — AccessControl 0x08D0…17beF8; Timelock 0x5038…a9b68. Plasma — AccessControl 0x3eA3…4Fab72; Timelock 0xe4cc…fD3C2E.

TAC — AccessControl 0x2365…06A45; Timelock 0x1A0d…4c097. XRPL EVM — AccessControl 0x8311…3F4cAE; Timelock 0x737F…D46DB0. RSK: Not verifiable as of 2026-09-06. Architecture: AccessControl → roles → mToken / DepositVault / RedemptionVault / DataFeed; Timelock → upgrade/admin actions (claimed by repository); vaults → tokenReceiver/liquidity and users.

The repository states most contracts use OpenZeppelin TransparentUpgradeableProxy; the audit confirms mTBILL and vaults were upgradeable. ProxyAdmin contract/type and whether every production proxy is timelocked are Not verifiable as of 2026-09-06. Privileged powers: documented roles include default admin, minter/burner, pauser, blacklist/greenlist, feed admin, deposit-vault admin, and redemption-vault admin. Audit-documented actions include ERC20 withdrawals from vaults, payment-token allowlisting, fee changes, pausing deposits/redemptions, token mint/burn, and blacklist control.

A compromised admin could freeze transfers/redemptions, alter fees or pricing inputs, burn user tokens, redirect vault-held assets, or upgrade logic. Users may exit only through the configured redemption path; admin blacklisting, pause, liquidity shortage, or changed minimums can prevent or delay exit. Timelock delay, renounced roles, emergency bypasses, and current role holders: Not verifiable as of 2026-09-06. Contradiction: the audit covers 2023–2024 commits, while the current repository contains later deployments; audit applicability to current production is unproven.

The 2024 Hacken report lists one accepted High finding and two accepted Medium findings; no accepted Critical findings were listed. Risk conclusion: high administrative/key-compromise and freeze risk; not permissionless or trust-minimized.

Admin can drain
Yes
Upgradeable
Yes
Unresolved critical
0
Unresolved high
1
Evidence (4)

audit

one source

Multiple focused audits of the Midas contracts, performed as independent reviews for Midas Protocol / RedDuck‑Software. One report explicitly states that no security issues were found, only miscellaneous comments without security impact. Another covers a max‑supply update.

A broader earlier report covers the whole contracts directory (excluding mocks/testers) at a given private‑audit commit.

Auditor
Côme du Crest
Report date
2024-02-01
Scope
1) "Midas Audit" (full‑scope) – all contracts in RedDuck‑Software/midas-contracts/tree/private-audit/contracts at commit c235631, excluding mocks/testers.[14] 2) "Midas Update Audit" – selected pull requests (57, 59, 64, 65, 68) in midas-apps/contracts, branch feat/new-audit-scope, last commit 0x0694b9a.[10] 3) "Midas Max Supply Update Audit" – smart‑contract changes related to token max supply (exact commit not visible in snippet).[11] Chain coverage appears Ethereum-only in available text; extension to Base/OP/Etherlink/others is **Not verifiable as of 2026-08-30**.
Evidence (3)

audit

one source

Multiple private audits of the Midas contracts codebase.

Auditor
Côme du Crest
Report date
2024-06-29
Scope
Several rounds: (1) Full contracts in `edDuck-Software/midas-contracts` branch `private-audit` as of commit `c235631`, excluding mocks/testers.[4] (2) Update audit covering PRs 57, 59, 64, 65, 68 in `midas-apps/contracts`, branch `feat/new-audit-scope`, commit `0x0694b9a`.[3] (3) Max supply update audit covering PR 80 in `midas-apps/contracts`.[8] Bytecode-match / deployed coverage on listed chains Not verifiable as of 2026-09-04.
Findings
Latest “Midas Update Audit” reports no security issues; only miscellaneous comments without security concerns.[3] Earlier audit (“Midas Audit”) indicates issues were found and then fixed via pull request 55, but specific severities (critical/high/medium) are not visible in the snippet.[4] “Midas Max Supply Update Audit” scope is narrow (max‑supply change PR 80) with no issues reported in the snippet.[8] Detailed severity counts Not verifiable as of 2026-09-04.
Fix status
For the broader codebase audit, developers “implemented fixes in pull request 55” and “all issues” were addressed per the report.[4] For the update and max‑supply audits, no security issues found; thus no fixes required.[3][8]
Evidence (3)

audit

unverified

Côme du Crest — Minter/Redeemer Q2 2024, Audit 1

Auditor
Côme du Crest
Report date
2024-06
Scope
Minter/redeemer contracts; exact commit and file scope not independently retrievable.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Côme du Crest — Midas Update Audit

Auditor
Côme du Crest
Report date
2025-07-27
Scope
PRs 57, 59, 64, 65 and 68; deposit/redemption vault changes, batch approvals, growth price feed, payment-token allowance and role cleanup; commit 0x0694b9a.
Findings
Critical/high/medium: none. Miscellaneous comments only; no security issues found.
Fix status
Acknowledged by the core developer. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Côme du Crest — Midas Max Supply Update Audit

Auditor
Côme du Crest
Report date
2025-08-30
Scope
PR 80; DepositVault maxSupplyCap and upgradeability; initial review commit 0xe508039, final reviewed commit 0xba85967.
Findings
1 high: storage-layout incompatibility could break existing proxy state. No medium/critical findings reported.
Fix status
Fixed and reviewed; no issues remaining. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Minter/Redeemer Q2 2024, Audit 1

Auditor
Sherlock
Report date
2024-05
Scope
Midas token, access-control, deposit-vault and redemption-vault code in the 2024-05 contest repository.
Findings
Not verifiable as of 2026-09-06.
Fix status
At least one medium storage-gap issue was reported and the protocol stated it was fixed in PR 47; complete severity counts and remediation status are Not verifiable as of 2026-09-06. Covers deployed code: Not verifiable as of 2026-09-06.
Report url
https://github.com/sherlock-audit/2024-05-midas-judging
Report id
doc:6921cd18b364503f
Evidence (1)

audit

unverified

Layer Zero and Axelar Bridge audit

Auditor
Côme du Crest
Report date
2025-11
Scope
Midas LayerZero and Axelar bridge contracts; exact repository, commit, and file-level scope not independently retrievable.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06. Covers deployed code: Not verifiable as of 2026-09-06.
Report url
https://docs.midas.app/resources/audits
Report id
doc:79f6fc87a8b52bdf
Evidence (1)

audit

one source

Minter/Redeemer Q2 2024, Audit 2

Auditor
Sherlock
Report date
2024-08
Scope
Midas minter/redeemer contracts in the 2024-08 Sherlock repository; Ethereum or EVM-compatible deployment context; whitelisted payment and output tokens.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06. Covers deployed code: Not verifiable as of 2026-09-06.
Report url
https://github.com/sherlock-audit/2024-08-midas-minter-redeemer
Report id
doc:7b0c6813d6fb9b1e
Evidence (1)

audit

two sources

Instant Issuance and Redemption Vaults contest audit

Auditor
Sherlock
Report date
2024-09-24
Scope
DepositVault.sol, RedemptionVault.sol, RedemptionVaultWithBUIDL.sol, ManageableVault.sol, WithSanctionsList.sol and related access/initializable contracts; audited and final commits are listed in the contest repository.
Findings
0 critical, 0 high, 6 medium reported by an independent analytics summary; additional low/informational counts are Not verifiable as of 2026-09-06.
Fix status
The public evidence shows issue-level remediation activity, including fixed and excluded findings. Complete per-finding remediation status is Not verifiable as of 2026-09-06. Covers deployed code: Not verifiable as of 2026-09-06.
Report url
https://audits.sherlock.xyz/contests/332/report
Report id
doc:d5187ff9ea0eed4c
Unresolved critical
0
Unresolved high
0
Evidence (3)

audit

two sources

Two smart-contract audits of the core Midas RWA contracts (USDC/mTBILL vault system). The Sherlock May 2024 contest repository lists Hacken #1 (25 Sep 2023) and Hacken #2 (18 Jan 2024) as prior audits of the same midas‑contracts codebase. Public summaries indicate a 10/10 score with all identified issues resolved or accepted.

Auditor
Hacken
Report date
2023-09-25
Scope
Initial and follow‑up audits of the Midas vault and tokenization contracts (USDC, mTBILL) on Ethereum; exact contract list not fully reproduced in public secondary sources.[6][13]
Evidence (3)

audit

one source

Hacken — Smart Contract Code Review and Security Analysis Report for Midas

Auditor
Hacken OÜ
Report date
2023-09-25
Scope
ERC20 token and associated EVM Solidity contracts; initial review 2023-09-06 and second review 2023-09-25.
Findings
Initial review: 5 critical, 2 high, 4 medium, 4 low. Second review: zero remaining issues across those severities.
Fix status
Post-remediation report; all listed issues resolved. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Hacken — Midas Vault Audit

Auditor
Hacken OÜ
Report date
2024-01-18
Scope
DepositVault, RedemptionVault and supporting access-control/oracle components; commit d84b0ed; remediation commit 2004f60.
Findings
1 high, 2 medium, 1 low and 4 observations; 8 total findings.
Fix status
4 resolved, 4 accepted, none mitigated. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Audit of Strata Markets’ Discrete Accounting vault strategy integrating Midas as an underlying protocol.

Auditor
Quantstamp (Strata integration audit)
Report date
2026-03-20
Scope
Strata Markets contracts interacting with Midas: `DiscreteAccounting.sol` and several `strategies/midas/*` files including `MidasStrategy.sol` and `IDepositVault` interface.[13] This is an integration audit, not a direct audit of all Midas RWA deployments. Bytecode-match / coverage of Midas contracts Not verifiable as of 2026-09-04.
Findings
Total 5 findings: 4 fixed, 1 acknowledged.[13] The medium‑severity issue STR‑1 relates to optimistic assumptions about the amount of mHYPER minted during deposits vs. actual `mintAmount`, tied to the way Strata integrates Midas.[13] High‑severity findings exist but are in Strata’s code; not necessarily Midas core contracts.[13]
Fix status
Report states 4 findings fixed and 1 acknowledged, indicating remaining risk is documented but accepted.[13] Changes are in Strata’s contracts, not necessarily Midas’ own code.
Evidence (1)

audit

two sources

Two public audit contests: May 2024 Midas contest and Aug 19–27, 2024 Midas Minter/Redeemer contest. The May 2024 contest covered the main mTBILL/USDC vault system; the August 2024 contest focused on new minter/redeemer vaults and oracle upgrades. CertiK Skynet lists four total audits for MidasRWA and surfaces these two Sherlock reports (publish dates May 31, 2024 and Sep 24, 2024).

Auditor
Sherlock
Report date
2024-05-31
Scope
May 2024 contest: midas-contracts @ 0b1644f5, including DepositVault, RedemptionVault, ManageableVault, MidasInitializable, Blacklistable, Greenlistable, with USDC and mTBILL as ERC‑20s used by the protocol.[6] Aug 2024 contest: minter/redeemer upgrade (DepositVault, RedemptionVault, RedemptionVaultWithBUIDL, ManageableVault, WithSanctionsList) at commit 4abcc5b2 / final 21ab5ffa of RedDuck‑Software/midas-contracts.[4][5] Both are Ethereum-focused; deployment to other chains (Base, OP, etc.) is not explicitly covered in available summaries.
Evidence (4)

audit

one source

Sherlock — Contest Audit

Auditor
Sherlock
Report date
2024
Scope
Midas contest audit; exact scope and final report metadata not independently retrievable.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05. Covers deployed code: Not verifiable as of 2026-09-05.
Evidence (1)

Team & Reputation

founders

two sources

Midas RWA appears to be a real Berlin-based business rather than an anonymous web-front: public sources identify it as Midas Software GmbH, headquartered at Kurfürstendamm 15, Berlin, and describe the team as led by Dennis Dinkelmeyer (CEO) and Fabrice Grinda (Executive Chairman), with Romain Bourgois as CPO. The strongest external cross-check is the Arbitrum governance forum, which lists the same headquarters, primary contact, and team roles, and states there were no known enforcement or legal actions against team members. Founders / backgrounds

  • Dennis Dinkelmeyer is publicly named as founder/CEO; sources say he previously worked at Goldman Sachs and Capital Group.
  • Fabrice Grinda is publicly named as co-founder/executive chairman; sources describe him as a longtime venture investor and founder of FJ Labs, with a large angel-investing track record.
  • Romain Bourgois is publicly named as co-founder/CPO; sources say he previously led product at Ondo Finance, including tokenized-asset work. Reality check
  • This is *not* an anonymous team; multiple independent sources identify named executives and a physical HQ.
  • The business looks operational, with public company listings and ecosystem participation, but the protocol itself still markets regulatory-compliant RWA exposure, so any compliance claims sourced only from its own materials remain *unverified marketing claims* unless independently checked.
  • I did not find verifiable evidence, in the sources reviewed, of prior hacks, enforcement actions, or a hidden/offshore-only structure; however, absence of evidence is not proof, and a deeper corporate/registry review would be needed for a hard conclusion. Onshore/offshore
  • Publicly, the company is presented as German/onshore: Berlin HQ and Midas Software GmbH.
  • Not verifiable as of 2026-09-04: whether any material operating entities, IP holders, or treasury structures sit offshore.
Evidence (4)

general reputation

two sources

Midas RWA currently has a moderately positive, institution-friendly reputation, with regulatory credentials and Tier-1 investors, and no public record of hacks, fraud or insolvency tied to this protocol. No sanctions or major enforcement actions against Midas RWA specifically are evident as of 2026-09-04. ### Team, company, regulation

  • Operates as Midas Software GmbH, an asset tokenization/RWA protocol headquartered in Berlin, Germany.
  • Founded in 2023 by Dennis Dinkelmeyer, Fabrice Grinda, and Romain Bourgois.
  • Reported as regulated in Germany and MiCA-compliant, serving clients outside the US and sanctioned jurisdictions.
  • Separate analysis notes a crypto custody license from Germany’s BaFin, enabling operation across 27 EU countries and use of Coinfirm for sanctions-screening and AML monitoring. ### Investors and external trust markers
  • Raised $8.75m seed in March 2024 led by Framework Ventures, BlockTower, HV Capital, with participation from Coinbase Ventures, FJ Labs, and others—all materially reputable funds in the crypto/VC space.
  • An issuer-trust service gives Midas an aggregate trust rating of 55/100, weighted by outstanding supply across two instruments (mid-range but above many peers). ### Security/operational track record
  • A DeFi risk dashboard reports Midas RWA has been operational for ~2.1 years across nine chains, independently audited and with no recorded security incidents to date.
  • Another independent risk rating service ranks Midas RWA #22 of 73 RWA protocols, with a risk score of 34/100, slightly safer than the sector average, and characterizes its operational history as “fairly clean” with only minor incidents on record.
  • Multiple analytics platforms list it among leading RWA/tokenization protocols by TVL/liquidity, with no mention of user losses due to protocol failure. ### Compliance, sanctions, legal
  • Portals.fi and JU analyses emphasize regulatory-compliant tokenization, on-chain KYC/AML, and integration of sanction-list screening (Coinfirm) as core to the design, reinforcing a compliance-focused brand.
  • No evidence of OFAC/EU sanctions, nor of major regulatory enforcement actions specifically targeting Midas RWA, is visible as of 2026-09-04.
  • Important distinction: a US enforcement document describes “Midas” interest-bearing accounts run by Iakov Levin, which shut in 2022 under a large asset deficit and regulatory action. Name collision risk is high; this appears to be a different, unrelated CeFi platform, not Midas RWA (different founder, history, model). This older Midas carries negative history, but there is no direct link to Midas Software GmbH. ### Market sentiment & criticisms
  • Independent write‑ups frame Midas RWA as compliance-heavy, institution‑oriented, but flag risks: large multi-chain footprint increases smart‑contract attack surface; RWA/issuer risk and secondary market liquidity remain structural concerns.
  • Some ratings position its risk as above low‑risk but below sector average, implying non‑negligible protocol and issuer risk despite a clean incident record. ### Unresolved concerns / monitoring lines
  • On-chain verification of TVL, asset backing, and per-chain exposure is not verifiable as of 2026-09-04.
  • Key ongoing risk themes to monitor: issuer solvency and custody arrangements, legal treatment of tokenized claims under EU/MiCA, and concentration of TVL on Ethereum vs smaller chains noted by analytics platforms.
Evidence (13)

Economy

TVL: $154.5M

model

one source

Economic model (as of September 6, 2026)

  • Strategy/assets: Product-specific. mTBILL tracks short-dated U.S. Treasury bills (<3 months), with yield accruing through NAV appreciation. mBASIS targets crypto funding/basis returns and can use spot collateral to borrow stablecoins; mEDGE combines DeFi lending, liquidity provision, reward farming, restaking, mBASIS and mTBILL.
  • Return character: mTBILL is primarily rate/credit exposure; mBASIS and mEDGE are not purely market-neutral because they introduce funding, liquidation, manager, DeFi-protocol and counterparty risks. External exposure includes Treasuries, centralized-exchange basis positions, Aave/Morpho/Euler/Pendle and restaking venues.
  • Organic vs subsidized: Underlying yield is described as Treasury income, funding spreads and DeFi returns. The share attributable to incentives, liquidity subsidies or emissions is Not verifiable as of September 6, 2026; therefore organic_yield_pct: null.
  • Leverage/looping: mBASIS explicitly uses moderate leverage; mEDGE collateral may include leveraged DeFi positions. A consolidated protocol leverage ratio is Not verifiable as of September 6, 2026; leverage_ratio: null.
  • Liquidity/lock-ups: No minimum investment is stated for mTBILL. Redemptions are normally instant, but capacity is not guaranteed; standard-mode redemptions may enter a 1–7 business-day queue. NAV publication or redemptions can be paused during market-disruption events.
  • Fees, gates, limits: Tokenholder fees are deducted from redemption proceeds, but a current product-wide fee schedule and limits are Not verifiable as of September 6, 2026. KYC/AML and sanctions screening apply.
  • Collateral/revenue: mTBILL claims bankruptcy-remote, pledged Treasury collateral; issuer fees fund operating costs. Independent protocol revenue is Not verifiable as of September 6, 2026. TVL/APY — aggregator only, not on-chain verified: DeFiLlama reports $154.76m TVL, +34.1% over 30 days, Ethereum 67.2%, 31 tracked chains, 31 pools, average APY 4.2%; mTBILL is shown at about $73.4m with 3.64% APY. Dune TVL, chain/product splits, trend validation and APY history/volatility are Not verifiable as of September 6, 2026. > Contradiction: The supplied chain list contains 9 chains, while current DeFiLlama tracking reports 31 chains. This discrepancy is unresolved; the aggregator figure should not be treated as on-chain verified.
Evidence (6)

reserves

two sources

As of September 6, 2026, Midas RWA’s reserves and treasury are only partially verifiable. Observed asset backing / exposure: RWA.xyz reports mTBILL total asset value of $71.44M as of September 5, 2026, with 66.70M tokens outstanding. mTBILL is described as representing shares in a BlackRock fund holding short-dated U.S. government debt. This is product-level distributed asset value, not verified liquid treasury reserves. Composition and custody: For mTBILL, RWA.xyz identifies Maerki Baumann & Co. AG as custodian, OZL Offenes Zollager in Liechtenstein AG as crypto custodian/crypto broker, and ATG Azimut Treuhandgesellschaft mbH as paying agent.

These disclosures apply to mTBILL and cannot be extended to the entire Midas treasury without further evidence. Reserve policy / attestations: Midas documentation states that off-chain collateral is checked by an independent verification agent, with Ankura described as performing daily eligibility and reference-price verification for assets such as mTBILL. Midas’s Attestation Engine is designed to publish NAV, proof-of-reserves, collateralisation, and source-document verification checkpoints on-chain, with LlamaRisk and Canary participating in independent verification. However, the documentation also states that oracle/reference values do not create legal entitlement to the underlying assets or guarantee redemption value. Addresses, control, and on-chain balances: Reserve-wallet addresses, treasury control structure, multisig/signers, and chain-by-chain reserve balances are Not verifiable as of September 6, 2026.

Dune verification is unavailable in this run; no on-chain balance is inferred. The transparency dashboard is JavaScript-gated, and public aggregator pages do not expose sufficient reserve-address detail. Contradiction / metric warning: Midas/Oasis cites more than $1.7B in cumulative assets minted, while current platform-level figures are materially lower (e.g., mTBILL at $71.44M). This is likely a cumulative issuance versus current outstanding-value distinction, not proof of reserves. Liabilities: Not verifiable as of September 6, 2026; token supply or AUM cannot be treated as a complete balance-sheet liability figure.

Evidence (5)

tokenomics

one source

Midas RWA does not appear to have a live, tradable native token deployed on any of the listed chains (Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, XRPL EVM) as of the latest web data. Because Dune MCP is unavailable, all on‑chain verification is skipped and treated as: > Not verifiable as of 2026‑09‑04. ### 1. Existence of a native token

  • Web search returns references to “Midas RWA” primarily as an RWA/yield protocol brand, but no consistent, independently confirmed token contract (e.g., no clear “MIDAS” / “MRWA” token on major explorers or aggregators tied to this specific protocol slug and chain set.
  • No reliable listings on major data aggregators (CoinGecko, CoinMarketCap, DefiLlama) clearly associated with “Midas RWA” across the specified chains. Given the name‑collision risk with other “Midas” and “RWA” projects, and the absence of contract-level confirmation, any token information would be speculative. Under the research rules, this must be treated as: > "Not verifiable as of 2026‑09‑04" for: >
  • token name/ticker and contract addresses, >
  • total vs circulating supply, >
  • market cap and FDV, >
  • token utility and governance role, >
  • revenue share, buybacks, burns, staking rewards, >
  • emissions & unlock schedule (and whether unlocks occurred), >
  • allocator breakdown (team/investors/treasury/community), >
  • top-holder concentration and insider wallets, >
  • mint/blacklist/fee‑switch functions and controllers, >
  • DEX liquidity depth and listings. ### 2. Risk analyst assessment
  • Primary finding: As of the current data, there is no verifiable native token for the Midas RWA protocol under the provided slug and chain set.
  • If the team or marketing materials claim the existence of a token, all such information must be treated as unverified marketing claim until:
  • contract addresses are clearly disclosed and matched to explorers; and
  • on‑chain data (holders, supply, liquidity, governance rights) can be independently checked. For institutional risk purposes, treat Midas RWA as non‑tokenized (or pre‑token) until proper contract discovery and chain‑level confirmation are available. Any exposure framed as “Midas RWA token” should be considered operational and information‑risk high due to the current inability to verify even basic tokenomics.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Midas RWA, a Bitcoin crash below $10,000 is not directly verifiable as a protocol-specific stress trigger from the available web sources. The public material I found describes Midas as an RWA tokenization platform with products like tokenized Treasuries and redemption/liquidity mechanics, but it does not provide a documented exposure map showing that Midas’ assets, reserves, or redemption capacity are materially linked to Bitcoin price levels.

Evidence (3)

stress scenario - largest collateral depegs 20%,

one source

Not verifiable as of 2026-09-04. I could not confirm Midas RWA’s live collateral composition, chain-by-chain TVL, or protocol-specific liquidation/haircut parameters from independent sources, so the loss impact of a 20% depeg in the largest collateral cannot be computed reliably. The only protocol-adjacent stress evidence found is qualitative: Midas/Morpho materials show mTokens can be used as collateral, and Chaos Labs reported that mF-ONE already experienced stress with a borrower near a 1.04 health factor during a prior NAV decline, which implies some positions may be close to liquidation under adverse moves.

What can be stated from the available evidence is limited to structure, not a number: if the largest collateral is depegged by 20%, the result depends on that asset’s share of total collateral, its oracle response, any liquidation threshold/haircut, and whether redemptions or unwind mechanisms are available. Gearbox’s documentation for a different Midas product indicates that depegs below 13% can trigger liquidations and that an orderly wind-down may redeem at NAV, but this cannot be generalized to all Midas vaults or chains. For this protocol, the stress outcome is therefore: Not verifiable as of 2026-09-04.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Scope limitation. Dune was unavailable; therefore the largest counterparty, current exposure by chain, reserves, and live collateral balances are Not verifiable as of September 5, 2026. The scenario below treats Midas Software GmbH—the issuer and contractual obligor—as the top counterparty. | Counterparty failure | Expected loss path / absorber | Compensation | Smart-contract impact | |---|---|---|---| | Midas issuer insolvency | Tokenholders enforce claims against pledged collateral. Ankura is described as taking control, liquidating collateral, and distributing proceeds; any liquidation discount, missing collateral, fees, or timing gap is absorbed by tokenholders pro rata.

Qualified subordination can delay or restrict payment where enforcement could cause insolvency. | No protocol-funded guarantee, insurance, or explicit first-loss reserve was identified: Not verifiable as of September 5, 2026. | No automatic insolvency oracle is documented. Operations would likely move from instant redemption to request/queue processing; admin-controlled fulfillment, minting/burning, pausing, blacklisting, and upgradeability create execution and governance dependence.

| | Custodian / collateral-account failure | If assets are legally segregated and pledged, recovery should come from the account rather than Midas’s estate; shortfall from segregation failure, fraud, or liquidation loss is borne by tokenholders. Legal segregation and insurance limits are Not verifiable as of September 5, 2026. | No stated reimbursement mechanism identified. | Tokens may continue circulating while redemptions are frozen or delayed; the ERC-20 balance does not prove recoverable collateral. | | Underlying fund, security, or market counterparty failure | For mTBILL, the stated exposure is short-dated U.S. Treasury assets/funds; a failure or NAV impairment passes through to tokenholders, reducing redemption value.

Current asset composition and concentration are Not verifiable as of September 5, 2026. | No explicit Midas capital buffer or compensation promise identified. | The custom/Chainlink-linked price feed can update the token valuation, while vaults burn mTokens and pay available settlement assets; insufficient liquidity converts the event into delayed or partial redemption. | Cross-chain conclusion: the economic loss is shared by holders of the affected product, not by Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, or XRPL EVM as networks.

Per-chain exposure and any cross-chain bridge concentration are Not verifiable as of September 5, 2026.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For Midas RWA, a stress scenario involving committed fraud by the DAO or owners is not verifiable as of 2026-09-04 from the provided sources. The available web results describe Midas as a compliant RWA tokenization protocol and reference bankruptcy-protected structures, but they do not provide verified evidence of DAO/owner fraud, nor do they establish on-chain or governance facts needed to substantiate such a scenario. What can be said with confidence is limited:

  • Midas presents itself as a regulated/compliant RWA tokenization protocol.
  • Third-party RWA listings and ecosystem pages reference Midas products and network presence, but these are aggregator or ecosystem claims, not proof of misconduct.
  • The Arbitrum forum application discusses bankruptcy-remote design and custody arrangements, which is relevant to structural risk, but it does not evidence fraud. Because the question asks specifically about committed fraud by the DAO or owners, and no credible source in the provided set documents such an event, the correct risk assessment is: no verified fraud event found; fraud risk remains unconfirmed. If you need, I can next assess adjacent risks for Midas RWA such as custody failure, redemption stress, or governance/control concentration under the same evidence standard.
Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

For Midas RWA, a stress scenario with a negative 30-day primary yield source means the protocol’s headline yield can turn negative, so investors should treat the product as a *capital-preservation-plus-risk* exposure, not a stable income source. The strongest available evidence in the web results says Midas’ flagship mTBILL is marketed as exposure to short-dated U.S. Treasury securities, which are the relevant primary yield source here; if that source goes negative over 30 days, the position’s net carry can also go negative after fees and operational frictions.

The practical stress read-through is:

  • Yield compression / inversion risk: short-duration Treasury-linked products can underperform if the underlying yield falls below fees or if rate resets lag the market move.
  • Liquidity stress: under redemption pressure, the ability to exit depends on the liquidity of the underlying reserve and the redemption mechanics, which should be verified from legal documents and counterparty structure.
  • Counterparty concentration: the major risks are the issuer, custodian, servicer, and any asset manager in the chain; if any link fails, the negative-yield shock can be amplified by delay or gating risk. What is not verifiable as of 2026-09-04 from the available sources:
  • chain-by-chain TVL or exposure across Base, Ethereum, Etherlink, Monad, OP Mainnet, Plasma, RSK, TAC, and XRPL EVM
  • actual 30-day realized primary yield
  • whether the yield source is currently negative on-chain
  • any protocol-level loss allocation or fee-waiver policy under negative yield So the correct institutional stress verdict is: negative 30d primary yield is a credible downside scenario, and the key question is whether the product can preserve principal while simply passing through negative carry, or whether fees/redemption frictions convert that into NAV erosion.
Evidence (2)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026: company-controlled governance; no verifiable DAO control. Midas Software GmbH (Germany; Berlin-Charlottenburg HRB 254645) is the issuer and operates the Midas frontend/services. Its sole shareholder is Midas Protocol Limited (UK company 15217097).

Current Companies House officers are Dennis Klaus Dinkelmeyer, Fabrice Grinda, and Dhiraj Singh; Thomas Klocanas resigned October 21, 2025. Dinkelmeyer remains Midas Software GmbH’s managing director. Control surface: The published contracts describe centralized role-based access control. DEFAULT_ADMIN_ROLE administers roles covering minting, burning, pausing, feeds, vault administration, greenlist/blacklist, and related operational permissions. Vaults can redirect deposited assets to fee/proceeds wallets, while asynchronous mint/redemption requests require admin approval.

Most contracts are upgradeable proxies; the repository documents a timelock address and says upgrades are typically routed through it. Governance/process: No token-holder DAO, public proposal framework, or binding token-voting mechanism was verified. Governance is therefore assessed as symbolic/nonexistent for control purposes: company/admin operators control frontend access, KYC/greenlisting, issuance/redemption operations, permissions, and contract administration. The issuer’s prospectus identifies Midas Software GmbH as the issuing entity and Midas Protocol Limited as its sole shareholder. Multisig/timelock: Previously recorded evidence indicates a 1-of-3 administrative multisig, with a timelock and emergency/admin bypass capability.

Signer identities, signer independence, and the exact timelock delay were not independently re-verified in this run. Top holders, voting concentration, and cross-chain administrative ownership: Not verifiable as of September 13, 2026 (Dune MCP unavailable; no Dune query or execution ID exists).

Timelock
Yes
Multisig threshold
1
Multisig owners
3
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Midas RWA is not verifiably tied, from the gathered sources, to a specific legal entity/jurisdiction pair beyond related Midas corporate materials indicating different entities in different contexts: Midas Software GmbH appears as an issuer in a Malta MFSA prospectus, while MDSCO Limited is listed for a UK website/terms page; a clean, protocol-specific entity map is not verifiable as of 2026-09-04. The strongest compliance signal found is a prospectus/terms framework requiring successful onboarding and completion of KYC/AML requirements before purchase/redemption, plus eligibility checks for investors. The issuer-side terms also say the tokens are governed by German law and disputes go to the issuer’s seat in Germany, while the UK website terms state English law/exclusive English courts for that site and that personal data is handled under UK data-protection law.

Public-facing Midas materials state Midas-issued tokens are not available to US and UK persons/entities or persons/entities from sanctioned jurisdictions, but this is only an unverified marketing restriction unless backed by a binding offering document for the specific protocol instance. No regulator action, court case, or sanctions designation against Midas RWA or a clearly identified controlling entity was verified in the gathered material; active enforcement is therefore not verifiable as of 2026-09-04, and sanctioned status is also not verifiable as of 2026-09-04.

Entity
Not verifiable as of 2026-09-04
Jurisdiction
Not verifiable as of 2026-09-04
Evidence (6)

Stability

stability

two sources

Midas RWA appears to issue its own yield-bearing stablecoin-like product, mUSD, so own_stablecoin = true. No reliable evidence was found here of any depeg event for Midas’s own stablecoin; depeg_count, last_depeg_date, and max_depeg_pct are not verifiable as of 2026-09-06. The protocol therefore cannot be marked definitively stable or unstable from the available evidence, so stable = null.\n\nThe one depeg report surfaced in search results was for a different protocol’s token, MSUSD / Main Street, not Midas mUSD, so it should not be attributed to Midas.

Own stablecoin
Yes
Stablecoin ids
  • mUSD
Evidence (4)

Risks & Strengths

risks

one source

Midas RWA’s principal risks are concentrated in issuer/legal enforceability, redemption liquidity, valuation/oracle dependence, smart-contract and cross-chain infrastructure, and regulatory access. Midas publishes audits, collateral-verification procedures, screening controls, and bankruptcy-remoteness structures, but these controls do not eliminate dependence on off-chain counterparties, issuer actions, third-party data, or legal enforcement. On-chain TVL, exposure by chain, holder concentration, and bridge balances: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Issuer insolvency and subordinationTokenholder claims may be delayed, unenforceable before insolvency, or subordinated to other creditors; collateral recovery may depend on enforcement and liquidation value.HighMediumMidas describes pledged, segregated collateral accounts, third-party verification, security enforcement, and bankruptcy-remoteness arrangements for relevant products.High legal and recovery uncertainty remains; documentation is product-specific and qualified subordination can materially weaken recovery.
Redemption liquidity mismatchInstant redemption is not guaranteed; stressed conditions can trigger a 1–7 business-day queue, fees, and best-efforts liquidation at a value below expectations.HighHighMidas discloses redemption mode before execution and publishes available instant capacity and pending queues.High during market stress, collateral liquidation, or rapid redemption demand.
Oracle and NAV divergenceThird-party data, estimates, or stale inputs can misstate NAV; oracle reference prices may differ from issuer-determined redemption amounts and market prices.HighMediumReference-value oracle, proof-of-reserve design, and daily independent collateral/reference-price verification are documented.Medium-High because verification is not a guarantee, and methodology or issuer pricing still controls settlement.
Smart-contract and bridge failureBugs, privileged-role compromise, oracle integration errors, chain outages, or LayerZero/Axelar bridge failures could freeze, misroute, or permanently lose tokens.HighMediumMultiple audits, public audit contests, and separate vault/oracle/bridge reviews are documented.Medium-High; audits reduce but do not remove exploit, upgrade, dependency, or cross-chain risks.
Regulatory access and enforcementChanging securities, fund, AML, sanctions, or jurisdictional rules could restrict issuance, transfers, redemption, or market access; accounts may be rejected or frozen.HighMediumKYC/AML, wallet screening, Chainalysis screening where available, geoblocking, greenlisting, and jurisdictional restrictions are documented.Medium-High due to evolving rules, discretionary compliance actions, and limited access for U.S. persons.
Evidence (5)

strengths

two sources

Midas RWA’s top strengths are: regulatory compliance, DeFi composability, instant liquidity/redemptions, institutional-grade asset design, and multi-layer transparency/verification. Public descriptions consistently frame it as a compliant asset-tokenization protocol that turns institutional strategies into ERC-20 tokens usable across DeFi, with fast redemption mechanics and independently verifiable pricing or attestations.

  • Regulatory compliance and institutional positioning: multiple sources describe Midas as EU-regulated or compliance-first, aimed at institutional and non-U.S./non-U.K. investors.
  • Native DeFi composability: its tokens are standard ERC-20s designed to integrate with protocols such as Morpho, Pendle, Aave, and broader DeFi infrastructure.
  • Instant liquidity and redemptions: Midas emphasizes redemption at NAV and “instant liquidity,” reducing the friction typically associated with RWA products.
  • Institutional-grade product architecture: Midas offers tokenized Treasury, credit, and strategy products, including curated or professionally managed yield strategies, which broadens its use case beyond a single asset.
  • Transparency and verification stack: sources highlight reserve proofs, independently verified pricing/oracles, and an attestation framework designed to make asset data verifiable onchain. A few claims in the web results are *unverified marketing claims* because they come primarily from Midas-owned channels or secondary commentary rather than independently confirmed chain data; examples include specific gas-savings percentages, TVL figures, and some custody/managerial details.
Evidence (9)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 23 two independent sources, 20 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-30.