Mole

Orange · 69/100

Executive summary

Mole is a leveraged yield farming and savings protocol on Sui and Aptos with a 66/100 score (orange band), penalized for an unresolved withdrawal incident and limited current assurance.

  • Security: One 2023 MoveBit audit of Aptos code found 10 issues (0 critical, 0 high, 2 medium, 8 minor); Sui deployment audit coverage is not verifiable as of September 2026. A Beosin audit announcement cannot be confidently tied to Mole.fi due to name collision. No bug bounty program was found.
  • Incidents: March 2026 public report of unanswered Sui withdrawal requests; cause, loss, and resolution remain unverified as of September 2026, and the incident is classified as unresolved.
  • Governance & custody: The audited Aptos code grants a Protocol Admin authority to withdraw/deposit vaults, update configuration, and manage reserves. Current admin identity, multisig status, timelock, and whether Sui deployment shares this design are not verifiable. No DAO governance or token-holder voting process was found. Custody model and withdrawal controls are unverified.
  • Top risks: Privileged administrative control with unverified mitigation (high residual); leveraged strategy execution risk amplified by unverified collateral ratios, liquidation thresholds, and oracle design; material counterparty/venue exposure (DeFiLlama reports ~96% TVL on Sui) with unverified composition; effectively anonymous team with no legal entity or founder disclosure.
  • Strengths: Multi-product suite (savings, leveraged farms, funds); cross-chain deployment (Sui and Aptos); AMM and CLMM compatibility on Sui; automation/AI-assisted strategy claims; ZARQ assigns 64/100 trust score with no known security incidents.
  • Unverified: Live contract addresses, on-chain TVL, collateral composition, oracle providers, reserve size, native token existence, legal entity, terms of service, withdrawal mechanics, leverage limits, and current admin controls all remain unverified as of September 2026.
  • Recommended exposure: Avoid or limit to <1% of portfolio until the March 2026 withdrawal incident is resolved, current admin controls and multisig/timelock are verified, Sui deployment receives an independent audit with bytecode match, and on-chain TVL/collateral composition can be confirmed. If allocating, use only the Savings product (lower leverage) and monitor withdrawal execution closely.
  • Open questions: Verify resolution of March 2026 withdrawal incident and current withdrawal functionality; confirm Sui contract addresses, admin key holders, multisig threshold, and timelock delay; obtain Sui-specific audit with deployed bytecode verification; identify legal entity, jurisdiction, and terms of service; quantify top-5 counterparty exposures, collateral composition, liquidation thresholds, and oracle design; confirm team identity and prior track record.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 3 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 80 16.0 full audit within 365 days (latest 2025-10-29); auditor not in top-20 -20
Incidents 20% 100 20.0 1 open incident(s), $0 at risk (1 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $8,672,158 = 0% of reference ($17,538,184,136)
Data confidence 94 7/7 critical categories; 20/29 verified facts; 29/29 fresh (180d)

Identification

protocol identification

two sources

Protocol identification

  • Name: Mole (often styled Mole DeFi).
  • Website: mole.fi.
  • Docs: English docs at doc-en.mole.fi (e.g. “What is Mole”). Chinese docs at doc-cn.mole.fi.
  • Category: Leveraged yield / savings / fund management DeFi protocol (liquidity mining / yield farming).
  • Core products: savings pools (lending), leveraged yield farming, and funds/hedge-fund style strategies, integrating with Cetus DEX on Sui.
  • Chains: Sui and Aptos (multi-chain deployment).
  • Launch timing: Media coverage right after Sui mainnet (May 2023) describes Mole as already live on mainnet; one article and a Binance note list it as an Aptos + Sui liquidity mining protocol online within a week of Sui mainnet launch. A precise mainnet launch date is Not verifiable as of 2026-09-04.
  • Native token: Several listings mention “MOLE” in a different BSC context that clearly does not match this protocol (payment network narrative, BSC chain). The Mole DeFi docs and audits for Sui/Aptos do not clearly specify a native ERC‑20/SPL‑style governance token. A canonical Mole native token for Sui/Aptos is Not verifiable as of 2026-09-04. Main contract addresses & verification
  • GitHub repos include mole-protocol and mole-contract-integrate-sui, with config files such as .sui_mainnet.json indicating Sui mainnet deployments. Exact on-chain addresses and explorer verification status are Not verifiable as of 2026-09-04.
  • Audit report for Mole Aptos references repository Mole-Fi/mole-protocol-aptos-dev, confirming Aptos smart contracts used for yield farming and savings. Again, individual contract addresses are Not verifiable as of 2026-09-04. Fork lineage / upstream design
  • The Mole GitHub org notes it was “Forked from aptos-foundation/ecosystem-projects”, which is a general collection of Aptos ecosystem code examples, not a specific DeFi protocol like Alpaca or Tulip. This suggests Mole used ecosystem templates rather than forking a well-known leveraged‑yield protocol directly. The exact upstream contracts and deltas are Not verifiable as of 2026-09-04.
  • Docs claim Mole is “Sui’s first asset management protocol fully compatible with AMM Uni V2 and CLMM Uni V3 algorithms”, implying design inspiration from Uniswap V2/V3 concentrated liquidity, but not a direct fork of those Solidity implementations (different Move-based environment). This is an unverified marketing claim. Audits / malicious-fork history
  • MoveBit publishes an Aptos audit report titled “Mole Aptos” for Mole’s yield farming contracts. This confirms at least one professional audit on Aptos.
  • ZARQ intelligence notes “No known security incidents” for Mole as of April 2026. This is aggregator data, not on-chain proof.
  • No evidence in independent media or audit notes of malicious modifications in forks of Mole or Mole itself is found; the existence or absence of such incidents beyond these sources is Not verifiable as of 2026-09-04.
Evidence (15)

maturity

two sources

Mole looks like a real project portal with a live developer docs site and a public GitHub org, not just a static landing page: the docs explicitly describe REST APIs and webhooks, and the GitHub org contains Mole protocol repositories. However, the available web evidence does not verify live user-facing deposit/withdrawal flows on Sui or Aptos, so that remains Not verifiable as of 2026-09-04. The clearest maturity signal is the documentation footprint: the docs site exposes an API-oriented product surface, while GitHub activity shows active code and chain-specific integration work for Sui.

I did not find reliable evidence of template-site artifacts, broken-link issues, or fake TVL/metric claims in the retrieved material, so those are Not verifiable as of 2026-09-04. Open API: yes, the docs state that Mole offers a REST API and webhooks. What is not verifiable from the retrieved sources is whether that API is public/open for any user versus partner-gated or authenticated-only in practice.

Overall maturity assessment: moderate-to-high for documentation and developer accessibility, but product functionality and live on-chain user flows are not verifiable from the gathered web evidence alone.

Evidence (3)

Security

bug bounty

one source

Not verifiable as of 2026-09-04. The available search results did not confirm a Mole-specific active bug bounty program, its start date, scope/parameters, or any payout history. The only relevant result was Immunefi’s general platform page and unrelated program pages for other protocols, so a Mole-specific program cannot be established from the gathered evidence.

Evidence (2)

counterparty risks

two sources

Assessment as of September 6, 2026: material dependency risk; exposure is not quantifiable from available evidence. Mole is described as a yield protocol on Sui and Aptos offering savings, leveraged farming and funds. This creates potential reliance on underlying farms, DEX liquidity, pricing inputs, and strategy operators, but the exact venues, allocation limits, withdrawal controls, oracle providers, bridge rails, custodians, CEXs/MMs, and stablecoin/LST composition are not disclosed in verifiable public sources. Chain concentration: DeFiLlama reports approximately $8.67m TVL, with $8.34m on Sui (~96.2%) and $332k on Aptos (~3.8%); this is aggregator data and was crawled last month, not a raw on-chain verification. External protocols / oracle manipulation: Any leveraged strategy is exposed to smart-contract exploits, liquidity withdrawal, liquidation cascades, stale/manipulated prices, and correlated Sui/Aptos ecosystem liquidity shocks. Specific Mole oracle design and venue-level exposure: Not verifiable as of September 6, 2026. Bridges / custodians / CEX-MM / RWA: No reliable evidence was found identifying a Mole-specific bridge, custodian, RWA issuer/SPV, named CEX, or market maker.

These categories and associated balances are Not verifiable as of September 6, 2026. The previously recorded statement that Mole uses CEXs/institutional market makers was not independently reverified in this check. Stablecoins / LSTs / restaking: Asset composition, issuer concentration, and depeg exposure are Not verifiable as of September 6, 2026. Failure scenarios include underlying protocol exploit, oracle failure, bridge halt, stablecoin depeg, custodian/CEX insolvency, or forced liquidation; loss severity could approach the affected strategy allocation. Contradiction: Mole’s website displayed $0 TVL in the captured page, while DeFiLlama reported $8.67m.

The discrepancy is unresolved; the aggregator figure is not treated as on-chain verified.

Evidence (3)

crypto custody

one source

Not verifiable as of 2026-09-06. The available web evidence does not identify Mole’s actual custody setup on Sui or Aptos. The Mole Aptos audit describes Mole as a DeFi protocol but does not state whether user assets are self-custodied, held in protocol-controlled smart contracts, or governed by an admin/MPC/multisig arrangement.

The only relevant Sui source found is Sui’s general asset-custody documentation, which explains custody models at the chain level rather than Mole’s specific design. No source located in this pass verifies whether withdrawals are paused or whether assets are segregated, so both fields remain unconfirmed.

Evidence (2)

incident

one source

Publicly reported operational incident on Sui: on March 21, 2026, a user stated that withdrawal requests submitted through Mole.fi had been unanswered for several days, with the latest request reportedly submitted March 16, 2026. Affected: at least one Sui user attempting to close a Mole position and withdraw funds; broader user impact was not established. Cause: other / undetermined; no exploit, key compromise, or smart-contract failure was confirmed.

Protocol response: no documented response or remediation was found. Fix: Not verifiable as of September 6, 2026. Realised protocol/user loss: Not verifiable as of September 6, 2026; no dollar amount or transaction evidence was available.

Attacker proceeds: Not verifiable as of September 6, 2026. Recovered: Not verifiable as of September 6, 2026. Reimbursement: Not verifiable as of September 6, 2026.

Current status: unresolved based on the public record; the report received follow-up comments suggesting continued concern, but no verified resolution. No separate confirmed incident was identified for Aptos.

Date
2026-03-21
Cause
Other
Status
unresolved
Event id
mole-sui-withdrawal-2026-03
Evidence (1)

key management

two sources

Key management for Mole is not verifiable from the provided sources. The search results mostly refer to unrelated projects named “Mole” or to general key-management best practices, and none confirm how the Mole protocol on Sui/Aptos organizes signing keys, admin keys, multisigs, or upgrade authority. The protocol website was not usable as a primary source here, and no explorer, audit, governance, or GitHub source in the results establishes the actual key-control model for this protocol.

Not verifiable as of 2026-09-04.

Evidence (3)

smart-contract

two sources

Assessment date: September 6, 2026. Dune MCP was unavailable; no on-chain claims, block heights, execution IDs, or decoded-admin-event results are available. Contract identification / addresses: Canonical live package, module, pool, treasury, oracle, strategy, and admin-capability addresses for Sui and Aptos are Not verifiable as of 2026-09-06. The protocol website/docs were inaccessible during this check. CertiK’s listing also shows “Token & Contracts: Not Available,” so it cannot close this gap. Audit evidence: A public MoveBit report exists for Mole Aptos.

It states that MoveBit reviewed the Aptos code, found 10 issues, and that developers addressed “most” issues; the report describes a “Protocol Admin” role. This confirms an audit report, not that the audited code equals the currently deployed Aptos or Sui deployments. Unresolved critical/high counts and remediation status are Not verifiable as of 2026-09-06. Upgradeability / admin controls: Sui and Aptos package-level upgrade mechanisms exist in principle, but Mole’s actual upgrade capability, package policy, proxy/facade design, multisig ownership, timelock delay, pause, withdrawal, fee, oracle, strategy, and emergency functions are Not verifiable as of 2026-09-06.

No role renunciation can be confirmed. Therefore, user exit without administrator action is also Not verifiable as of 2026-09-06. Architecture map (unverified deployment mapping): ``text User ├─> Mole frontend/SDK ├─> Sui Move packages ─> pools/vaults ─> strategies/oracles ─> external protocols └─> Aptos Move modules ─> savings/leveraged farms/funds ─> strategies/oracles ▲ Protocol Admin / upgrade capability (multisig, timelock, and powers unknown) `` Risk conclusion: If a privileged key or upgrade capability exists, worst case could include freezing deposits/withdrawals, changing fees/oracles/strategies, upgrading logic, or extracting assets—conditional threat scenarios, not verified Mole functions. Rug/freeze risk is therefore unresolved and cannot be rated low. Contradiction / evidence gap: Public audit evidence exists, but live contract addresses and deployment-to-audit matching are unavailable; on-chain verification would take precedence.

Structured fields: admin_can_drain=null, audited_deployment=null, upgradeable=null, unresolved_critical=null, unresolved_high=null

Evidence (4)

audit

one source

A Beosin security audit is referenced for “Molecular Protocol” associated with @molecular_fi, announced as successfully passed with an audit report link. Name collision risk is high: the branding in the announcement does not clearly match Mole.fi (Sui/Aptos yield protocol), and the linked PDF appears to target a different project; therefore this audit cannot be safely treated as belonging to Mole.fi. On‑chain scope/bytecode match for Mole.fi contracts is Not verifiable as of 2026-09-04.

Auditor
Beosin
Report date
2025-10-29
Scope
Unclear; the audit announcement references “Molecular Protocol” rather than Mole.fi, and the underlying report link cannot be confidently tied to Mole’s Sui/Aptos deployments.[1] Scope with respect to Mole.fi is Not verifiable as of 2026-09-04.
Findings
The Beosin social post states that the protocol “has successfully passed a security audit” but does not enumerate findings or severities in the publicly visible snippet.[1] Without confirmed project identity and direct access to the report contents, critical/high/medium issues and their remediation status are Not verifiable as of 2026-09-04.
Fix status
The post implies a passed status but provides no structured remediation data, and the protocol identity mismatch cannot be ruled out.[1] Fix status for any findings relevant to Mole.fi is Not verifiable as of 2026-09-04.
Evidence (1)

audit

two sources

Corrected record: the publicly available MoveBit report is titled “Mole Aptos Audit Report.” It covers Mole’s Aptos Move repository, not a demonstrated production deployment. The report’s audit timeline is February 7–March 9, 2023; an exact publication date is not stated, so report_date remains month-level February 2023.

Auditor
MoveBit
Report date
2023-02
Scope
Aptos Move yield-farming protocol code; repository https://github.com/Mole-Fi/mole-protocol-aptos-dev; received commit e28045f5aa3b5359d6f75ad9ffe117992a5ad9f8; last reviewed commit 53c832d7a597324ec571005b4688431fe4a894d7. Methods: architecture review, unit testing, formal verification, manual review, and Aptos test-network testing. Sui scope: Not verifiable as of September 6, 2026.
Findings
10 findings: 0 Critical, 0 Major/High, 2 Medium, and 8 Minor. Medium findings: missing strategy_type validation in add_collateral and unpinned third-party dependency revisions. Minor findings included assertion optimization, missing coin-amount validation, inconsistent error codes, TinyCoin upper-bound handling, token-registration checks, computational precision loss, repetitive code, and unfinished/TODO-style issues.
Fix status
The report records 7 findings Fixed and 3 Confirmed; 0 Pending. Both Medium findings were marked Fixed. The three Confirmed items were retained as designed, including TinyCoin residual-value handling, token-registration handling, and computational precision loss. No later independent retest or remediation report was identified; post-publication status is Not verifiable as of September 6, 2026.
Report url
https://movebit.xyz/file/Mole-Aptos-Audit-Report.pdf
Report id
doc:ce41821ffaa0bb92
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

MoveBit audited Mole’s Aptos smart contracts for a yield farming protocol implemented in Move, covering architecture review, unit testing, formal verification, and manual review. The report specifies the last reviewed commit hash (53c832d7a597324ec571005b4688431fe4a894d7) and includes a vulnerability summary table with severities and fix status. On‑chain bytecode/implementation match for current mainnet deployments is Not verifiable as of 2026-09-04.

Auditor
MoveBit
Report date
2023-03-09
Scope
Aptos chain only; Mole yield‑farming protocol smart contracts written in Move, reviewed between 2023‑02‑07 and 2023‑03‑09.[3] Scope covers contract architecture, logic correctness, formal verification checks, and manual code review of the specified commit.[3]
Findings
The report lists a total of 10 items, with 7 marked as fixed and 3 pending at the time of the audit.[3] Severity distribution includes 8 minor issues and 2 issues of higher severity (the PDF table is partly visible but clearly distinguishes Minor vs higher‑severity categories).[3] Exact labels for those 2 items (e.g., Medium vs High) and their detailed descriptions are Not verifiable as of 2026-09-04.
Fix status
As per the audit report’s summary table, 7 of 10 findings were fixed by Mole, with 3 remaining pending as of the audit’s completion.[3] The report does not clearly indicate post‑audit retesting, so whether all pending items have since been remediated is Not verifiable as of 2026-09-04.
Evidence (1)

Team & Reputation

founders

two sources

Based on available non-on-chain sources, Mole on Sui/Aptos appears to be run by an effectively anonymous team, with no clearly documented founders or real-world corporate footprint. Not verifiable as of 2026-09-04. ### 1. Founders & team identity

  • Official site, docs and ecosystem listings (Alchemy, Mantapex, DefiLlama, DoraHacks) describe Mole’s products but do not name any founder, CEO, or core team members.
  • The GitHub organization Mole-Fi hosts protocol code, but commit history uses pseudonymous handles (e.g., molefund) and provides no legal names or bios.
  • Bitget’s “Mole” profile describes a founder “Eric” and BSC activity since 2021, but the text clearly refers to a different Mole project on Binance Smart Chain with a reserve currency MOLE and payment network narrative, not the Sui/Aptos leveraged yield protocol. This is a name-collision and cannot be treated as relevant to mole.fi. Reality check: Identity of the founders and key team behind mole.fi on Sui/Aptos is not publicly verifiable from independent sources. Not verifiable as of 2026-09-04. ### 2. Prior track record, hacks, credibility
  • ZARQ intelligence assigns Mole a trust score of 64/100 (grade B) and notes “no known security incidents” for the Sui/Aptos deployment.
  • At least one third‑party audit exists: MoveBit published an audit report for Mole on Aptos, confirming it as a leveraged yield/savings protocol but again without naming founders or a legal entity.
  • No independent records of prior projects, personal track records, or historical hacks linked to named individuals behind mole.fi are available. Not verifiable as of 2026-09-04. ### 3. Public vs anon, office, jurisdiction, business reality
  • No corporate registry entries, physical office addresses, or jurisdictional disclosures (e.g., company in Singapore/BVI/Cayman) are found in independent profiles or audit reports. Not verifiable as of 2026-09-04.
  • Communications appear to be purely online (X/Twitter, Telegram, Discord) and the protocol is presented as a DeFi dApp, not as a regulated financial institution.
  • Given the lack of corporate and identity disclosure, Mole should be treated as offshore, anon DeFi from a risk perspective, despite having audits and multi‑platform listings. ### 4. Institutional risk takeaway
  • Key risk: No verifiable founders, no clear legal entity, and no physical office.
  • Mitigants: Recorded MoveBit audit, multi‑platform listing, and no publicly known incidents so far.
  • For institutional exposure, this is founder-anonymous, jurisdiction-opaque infrastructure; governance, recourse and accountability are effectively absent absent further private KYC or legal documentation.
Evidence (13)

general reputation

two sources

Mole currently has a moderate, generally clean reputation as a leveraged yield farming and savings protocol on Sui and Aptos, with no publicly documented hacks, rugs, or insolvency events as of 2026‑09‑04. Because on‑chain tools are unavailable in this run, any on‑chain verification (TVL, holders, incident history) is Not verifiable as of 2026‑09‑04. ### Overall protocol reputation

  • Mole is listed on multiple independent aggregators (DefiLlama, Mantapex, ZARQ, Bitget) as a DeFi protocol on Sui and Aptos, focused on leveraged yield farming, funds, and savings.
  • ZARQ assigns a Trust Score of 64/100 (grade B) and explicitly notes “No known security incidents” for Mole.
  • Ecosystem overviews from Binance and Sui-focused DeFi guides include Mole among mainnet‑live DeFi protocols, describing it as liquidity mining / AI‑powered DeFi asset management on Aptos + Sui.
  • DoraHacks lists Mole as an active “buidl” with public community links (X, Telegram, Discord), suggesting an ongoing development and community presence. ### Team, investors, and transparency
  • Public profiles (The Grid, DoraHacks) describe the product design and integrations (e.g., Cetus DEX, AI‑optimized liquidity), but do not provide clear founder identities or institutional investor lists.
  • I could not find credible disclosures of venture investors, fundraising rounds, or a formal company registration linked directly to Mole.
  • Not verifiable as of 2026‑09‑04 for: legal entity, jurisdiction, cap table, and institutional backers.
  • GitHub shows an active Mole-Fi/mole-protocol repository with updates through 2025, indicating at least some ongoing technical work. ### Audits and security
  • A direct audit report is found for Mole on Aptos by MoveBit, covering yield farming contracts on Aptos.
  • A Beosin audit tweet refers to “Molecular Protocol ($MOLE) on Arbitrum”, which appears to be a *different* protocol (different chain and positioning); this should not be treated as an audit of Mole on Sui/Aptos.
  • No evidence of audits for Mole’s Sui deployment was found from major auditors.
  • Sui-side audits therefore Not verifiable as of 2026‑09‑04. ### Incidents, criticisms, and legal/regulatory status
  • Searches for rug pull, scam, hack, insolvency, or sanctions related to Mole on Sui/Aptos returned no credible incident reports in independent media or analytics summaries.
  • No listings or actions were found in major sanctions/regulatory contexts specifically tied to Mole.
  • Regulatory/sanctions status thus remains Not verifiable as of 2026‑09‑04 beyond “no reported issues found.” ### Key unresolved concerns
  • Limited transparency on founders and governance structure.
  • Audit coverage appears partial (Aptos contracts audited; Sui coverage unclear).
  • Absence of documented institutional investors or formal compliance posture. For institutional risk framing: current external data supports a non‑scam, mid‑trust, small‑to‑mid‑size protocol with some audit coverage on Aptos, but meaningful unknowns around team identity, full-chain audits, and regulatory posture.
Evidence (13)

Economy

TVL: $8.7M

model

two sources

As of September 6, 2026. Strategy: Mole combines Savings, leveraged Farms, and Funds. Savings users supply assets; Farm/Fund users borrow from Savings and deploy capital into DEX LP and managed strategies. Reported yield sources are borrower interest, LP trading fees/farming incentives, and strategy profits.

The lower-risk Savings product is described as market-neutral, while Farms support long/short exposure; therefore the protocol is not purely directional. Leverage/exposure: Leverage is embedded in Farm/Fund positions and is reportedly non-overcollateralized at the user level, with deployment restricted to protocol-controlled flows and liquidation risk if position value deteriorates. External exposure includes integrated Sui-native venues such as Cetus, Scallop, Bucket, and Haedal. Exact maximum leverage, leverage by product, collateral ratios, looping, restaking, and cross-protocol exposure are Not verifiable as of September 6, 2026. Liquidity mechanics: Savings/Fund deposits and withdrawals, lock-ups, cooldowns, withdrawal queues, gates, limits, withdrawal fees, and liquidation procedures are Not verifiable as of September 6, 2026.

The audit search result confirms deposit/withdrawal functionality for Funds but not the full terms. Yield sustainability: Organic yield appears to be borrower interest plus DEX/LP revenue; any token incentives or subsidies are not quantifiable from the available evidence. organic_yield_pct: null. APY history, volatility, reward-token composition, and sustainability are Not verifiable as of September 6, 2026. Fees/revenue: Protocol fee schedule, fee recipients, treasury revenue, and net protocol revenue are Not verifiable as of September 6, 2026. TVL: DeFiLlama reports $8.67m total: Sui $8.34m (96.2%) and Aptos $332,007 (3.8%); 30-day TVL change is -3.1%. Dune/on-chain verification is unavailable in this run, so product-level TVL, on-chain trend, and Dune-vs-DeFiLlama reconciliation are Not verifiable as of September 6, 2026. leverage_ratio: null

Evidence (5)

reserves

two sources

## Reserves / Treasury — Mole (Sui, Aptos) Assessment date: September 6, 2026.

  • Reserve size: Not verifiable as of 2026-09-06. No independently verifiable disclosure of treasury or reserve assets was found.
  • Reserve addresses: Not verifiable as of 2026-09-06. No official Sui or Aptos treasury/custody addresses were identified and matched to Mole.
  • Composition: Not verifiable as of 2026-09-06. The protocol’s documentation describes leveraged positions, liquidity deployment and fund strategies, but does not provide a treasury asset inventory or reserve composition. The Sui fund product is stated to be under development, not a disclosed reserve.
  • Custody and control: Not verifiable as of 2026-09-06. No evidence was found establishing whether reserves are held in protocol-controlled objects/accounts, multisig wallets, deployer-controlled wallets, or third-party custodians.
  • Reserve policy: Not verifiable as of 2026-09-06. No minimum-reserve, segregation, redemption-liquidity, or rebalancing policy was located.
  • Attestations: Not verifiable as of 2026-09-06. The available MoveBit report is a code-security audit, not a proof-of-reserves, financial-statement audit, or custody attestation. Mole’s documentation identifies the report as an Aptos security audit.
  • On-chain balances via Dune: Not verifiable as of 2026-09-06. Dune MCP was unavailable in this run; therefore no Dune query ID, execution ID, block height, asset balances, or chain-by-chain reserve split can be provided. > Contradiction / classification: DeFiLlama reports protocol TVL across Sui and Aptos, but TVL is an analytics-platform estimate of assets in protocol contracts—not evidence of a separate treasury or liquid reserve. It must not be treated as reserves or net assets. Structured fields
  • liquid_reserves_usd: null
  • liabilities_usd: null Sources reviewed: Mole docs, Mole security-audit page, MoveBit audit reference, and DeFiLlama protocol page. No reserve disclosure or independently verifiable reserve attestation was found.
Evidence (4)

tokenomics

two sources

Tokenomics assessment — Mole (Sui, Aptos), as of September 4, 2026 Native token: No publicly verifiable Mole-native governance or utility token was identified. Mole’s own site describes savings, leveraged farms, and funds, while CertiK lists “Token & Contracts: Not Available.” The “MOLE” label shown by DeFiLlama appears to be the protocol name/display label, not verified evidence of a tradable native token. No native-token contract address was found. Supply, valuation, and market data: Total supply, circulating supply, market capitalization, FDV, emissions, unlocks, allocations, and investor/team/treasury schedules: Not verifiable as of September 4, 2026.

Consequently, announced unlocks cannot be reconciled to on-chain events. Dune/on-chain verification was unavailable for this review. Utility and governance: No verified Mole token utility, governance right, revenue-sharing mechanism, buyback, burn, or token-based fee switch was found. The app references “mToken” receipt/staking assets, but their contract identities, economic rights, and whether they are chain-specific claims or protocol tokens are Not verifiable as of September 4, 2026.

Staking/rewards: Mole advertises deposit and staking-related yield products, but these appear to be product-level returns rather than rewards paid to a native Mole-token holder. The exact source, sustainability, and distribution of rewards are Not verifiable as of September 4, 2026. Control-risk functions: Mint, burn, blacklist, transfer restrictions, fee-switch functions, upgradeability, admin keys, and controlling wallets: Not verifiable as of September 4, 2026. Liquidity/listings: No verified Mole-native token DEX liquidity pools or principal listings were identified; therefore liquidity depth and market venues are Not verifiable as of September 4, 2026.

DeFiLlama reports protocol TVL—not token liquidity—of approximately $8.67m, with 96.2% on Sui and 3.8% on Aptos; this is an analytics-platform figure, not an on-chain-verified result. Bottom line: Treat Mole as a multi-chain yield protocol with no publicly verified native token, rather than as an investable tokenomics asset.

Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Under a BTC < $10,000 shock, Mole’s likely stress points are risk-off TVL contraction, lower demand for leveraged yield strategies, and potentially weaker collateral or incentive economics on both chains. Mole is a DeFi protocol on Sui and Aptos focused on savings, leveraged yield farms, and funds; its current reported TVL is $8.63m, with $8.32m on Sui and $306,958 on Aptos. A BTC crash to this level would not directly prove insolvency for Mole, but it would likely hit the protocol through the same channels that stress DeFi generally: users de-risk, leveraged positions become less attractive, and deposit balances can fall quickly.

Because the available sources do not provide Mole’s debt structure, liquidation thresholds, or chain-by-chain collateral composition, the severity of any protocol-specific impact is Not verifiable as of 2026-09-04. The exposure is also heavily concentrated on Sui rather than Aptos, so any chain-specific disruption, liquidity shock, or user-flight effect would likely be dominated by Sui conditions rather than Aptos. On the information available, Mole appears to be a relatively small protocol, so a broad crypto drawdown could materially reduce reported TVL even if the protocol itself remains operational.

What can be stated confidently is that a sub-$10,000 BTC environment would be a severe negative macro regime for yield protocols like Mole; what cannot be verified from the provided sources is whether Mole has buffers, hedges, or governance actions that would materially absorb that shock. That is Not verifiable as of 2026-09-04.

Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-09-04. I could not confirm Mole’s live collateral set, per-chain TVL, or the largest collateral position on Sui and Aptos from the provided web results, so I cannot compute the impact of a 20% depeg without risking a false estimate. In general, a 20% collateral depeg can trigger liquidations when the position’s health factor or liquidation threshold is close enough to the edge; DeFi lending protocols typically liquidate undercollateralized positions by repaying debt and seizing collateral at a discount, but the exact loss depends on the protocol’s oracle, liquidation threshold, and borrow utilization.

For Mole specifically, the required inputs are: the largest collateral asset by USD value, its liquidation threshold or max LTV, the borrower’s current leverage, and whether the oracle marks collateral at spot or delayed prices. Without those protocol-specific parameters, the stress result remains unverified as of 2026-09-04. A 20% depeg is materially larger than the mild deviations discussed in stablecoin risk references and is within the range that commonly produces forced deleveraging in lending systems.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Stress case — NAVI insolvency (Sui): NAVI is the most plausible *structural* top counterparty for Mole’s Sui leveraged-yield strategies: documented integrations show borrowing NAVX/CETUS from NAVI and depositing those assets into Mole farms. This is a scenario assumption, not a measured exposure.

  • Expected loss path: NAVI suffers bad debt, an exploit, or a run; withdrawals, collateral valuation, or liquidations are impaired. Any Mole strategy holding NAVI-linked receipts, borrowed assets, or positions dependent on NAVI liquidity can experience delayed redemption, forced liquidation, slippage, and a lower vault-share/NAV value. If the failure also depresses NAVX/CETUS prices, losses compound through the leveraged position.
  • Who absorbs it: First, affected Mole strategy investors through lower NAV and/or withdrawal haircuts. Liquidators and remaining pool liquidity absorb execution losses. Mole’s treasury or governance would absorb losses only if an applicable reserve or discretionary recapitalization exists; that is Not verifiable as of September 5, 2026. There is no verified depositor guarantee.
  • Compensation: A contractual insurance fund, loss backstop, or guaranteed reimbursement is Not verifiable as of September 5, 2026. Accordingly, base case is no automatic compensation; recovery would depend on residual collateral, liquidation proceeds, governance action, or an off-chain rescue.
  • Smart-contract impact path: NAVI market/price/oracle controls → borrower health factors and liquidation eligibility → liquidation of collateral or failed withdrawals → Mole strategy rebalance/harvest/redemption functions → vault accounting and share-price update → user withdrawal losses. A pause at NAVI or an illiquid market can strand assets even if Mole’s contracts remain correctly executable. Cross-chain containment: DeFiLlama reports approximately 96.2% of Mole TVL on Sui and 3.8% on Aptos. The Sui shock should not automatically transfer to Aptos because deployments and state are separate; contagion requires shared assets, bridges, strategy logic, or governance. Exact Mole contract-level exposure, reserves, and counterparty concentration are Not verifiable as of September 5, 2026 because Dune/on-chain verification is unavailable in this run.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For Mole (mole) on Sui and Aptos, I found no verifiable evidence in the provided results that the DAO or owners committed fraud. The available results are either about unrelated DAO/legal cases, unrelated scams, or Mole/Moledao’s general web presence, and none tie a confirmed fraud allegation to this specific protocol. Because I could not confirm the protocol’s on-chain state, governance structure, or any independent fraud findings for Mole from the available sources, the correct stress-scenario answer is: Not verifiable as of 2026-09-04.

The only Mole-specific result is the project’s own site/social presence, which is not enough to substantiate a fraud claim and would be treated as unverified marketing material. If you want, I can next assess adjacent risk signals that are still checkable off-chain, such as team identity, admin controls, code/audit history, or whether there are regulatory or litigation mentions tied specifically to Mole.

Evidence (6)

stress scenario - primary yield source negative 30d,

unverified

For Mole on Sui and Aptos, a negative 30-day primary yield source means the protocol’s main yield engine produced a net loss over the trailing month, so the yield contribution is below zero rather than merely low. In stress analysis, that is a red flag because it implies the strategy’s underlying carry, spread, fees, or incentive income did not offset costs, drag, or losses during the period. Mole’s docs describe the protocol as focused on leveraged yield farming, which means returns depend on borrowing against savings products and then deploying that capital into yield-generating positions.

If the primary source is negative over 30 days, the leveraged structure can amplify downside because borrow costs and position drag continue even when the underlying yield deteriorates. What this means for risk assessment:

  • Economic stress: the strategy is no longer covering its own financing or operating costs over the trailing window.
  • Higher liquidation / deleveraging risk: leverage makes a negative carry period more fragile, especially if collateral values move against the position.
  • Incentive dependence risk: if the strategy had been supported by emissions or temporary incentives, a negative 30-day reading can indicate those supports faded or were insufficient. I could not verify on-chain exposures, current vault composition, or chain-by-chain TVL for Mole because on-chain verification tools are unavailable in this run. Not verifiable as of 2026-09-04. If you want, I can next convert this into a short institutional-style risk note for Mole on Sui vs Aptos.
Evidence (1)

Governance & Legal

governance

two sources

Governance assessment — as of September 13, 2026 Control of dev/contracts/frontend/funds: Not verifiable as of September 13, 2026. CertiK lists Mole’s repository, smart contracts, token/contracts, and website monitoring as unavailable/not activated. The Mole Aptos audit is historical (reviewed February–March 2023), not proof of current deployment control. Contract powers: The MoveBit audit documents a Protocol Admin able to deposit/withdraw from Vaults and Funds, update Vault configuration, withdraw/reduce reserves, create farming positions, and reinvest.

This indicates material privileged power and potential fund-movement authority in the audited Aptos code. Current admin identity, deployment, and whether the role is multisig-controlled are unverified. Proposal process / DAO: No verifiable Mole-specific proposal forum, voting contract, token-holder voting process, or binding governance execution path was found. DAO governance is therefore assessed as not evidenced and not real/controlling on available evidence.

Voting concentration and top holders: Not verifiable as of September 13, 2026; Dune MCP was unavailable, so no on-chain holder analysis was performed. Timelock / multisig: Timelock status and delay, multisig threshold, signer set, signer independence, and emergency-bypass design: Not verifiable as of September 13, 2026. Company / legal control: A similarly named Mole entity was found at mole.is, but it is not confirmed to be the Mole DeFi protocol at mole.fi; it is excluded under the name-collision rule. Mole.fi’s operating entity, jurisdiction, registration number, directors, and Terms of Service: Not verifiable as of September 13, 2026. Risk conclusion: Governance is currently opaque and appears administratively centralized at the audited-code level; current custody and upgrade controls cannot be independently established. Treat the DAO, if advertised, as symbolic/unverified until executable governance, admin addresses, and multisig/timelock evidence are published.

Admin can drain
Yes
Dao governance
No
Evidence (3)

legal & regulatory

two sources

Legal & regulatory assessment (as of September 4, 2026): Mole is publicly described as a DeFi yield protocol offering savings, leveraged yield farming and funds on Sui, with historical Aptos leveraged-farming activity. Entity / jurisdiction: Not verifiable as of September 4, 2026. The publicly accessible Mole materials reviewed do not identify a legal entity, registered office, governing law, licensing entity, or corporate parent.

Do not confuse Mole.fi with unrelated “Mole” websites or entities. Terms, restrictions and compliance: No protocol-specific Terms of Service, restricted-jurisdiction policy, KYC/AML policy, sanctions policy, or licensing disclosures were located in the publicly indexed materials reviewed. Accordingly: Not verifiable as of September 4, 2026. The app appears wallet-connected and permissionless from its public interface, but this does not establish legal status or absence of backend screening.

Classification: The products’ economic profile—pooled savings, leveraged yield strategies and “funds”—could attract characterization as financial products, investment schemes, collective investment arrangements, lending/credit, derivatives, or managed assets depending on jurisdiction and implementation. No legal opinion, regulatory registration, or jurisdiction-specific classification was found. Not verifiable as of September 4, 2026. Warnings / enforcement / litigation / sanctions: No regulator warning, enforcement action, court case, or sanctions designation specifically naming Mole.fi, Mole Finance, or an identified Mole entity was located in the searches performed.

This is not evidence of clearance. Not verifiable as of September 4, 2026. Data protection: No Mole.fi privacy notice, controller identity, retention policy, GDPR/CCPA notice, or data-subject contact was located. Not verifiable as of September 4, 2026. Legal structure vs. actual risk: The absence of an identifiable counterparty, jurisdiction, contractual framework, compliance perimeter, and dispute forum materially increases recovery, enforcement, and accountability risk.

Smart-contract decentralization would not eliminate potential operator, developer, front-end, treasury, or promoter liability; it may instead make attribution and remedies harder. The MoveBit audit confirms a technical audit existed for the Aptos project, but an audit is not legal, regulatory, solvency, or consumer-protection assurance.

Active enforcement
No
Sanctioned
No
Evidence (5)

Stability

stability

unverified

Mole does not appear to issue its own stablecoin; the protocol docs and site describe it as a DeFi protocol that uses stablecoins such as USDC, USDT, BUCK, and wUSDC in yield-farm strategies, while MOLE is described as a reserve currency rather than a stablecoin. Historical stablecoin depeg events for the stablecoins used by Mole are not verifiable as of 2026-09-06, so depeg count, last depeg date, and max depeg percentage remain unknown.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

two sources

Mole’s principal risks are concentrated in privileged control, leveraged strategy execution, and limited current assurance. The only located protocol-specific audit is a 2023 Aptos review; Sui deployment coverage, current admin controls, live TVL, and chain-level exposure are Not verifiable as of September 5, 2026 because on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Privileged administrative controlThe audited Aptos design gives the protocol admin authority to withdraw or deposit in vaults, update vault configuration, reduce reserves, create farming positions, reinvest, and rebalance funds. Compromise or misuse could directly affect deposited assets.HighMediumMove access controls and emergency checks are present in the reviewed code. Multisig ownership, timelocks, role separation, and current permissions are Not verifiable as of September 5, 2026.High: administrative trust remains material until current controls are independently verified.
Outdated audit coverageThe available MoveBit review covers an Aptos code snapshot from February–March 2023, not demonstrably the current Aptos deployment or Sui implementation. Audits are limited-scope assessments and do not eliminate undiscovered logic risk.HighMediumMoveBit performed architecture review, testing, manual review, and formal verification; several findings were fixed. Current release-to-audit diff and post-deployment monitoring are Not verifiable as of September 5, 2026.High: assurance may not transfer to current or cross-chain code.
Leverage and liquidation lossLeveraged farming can amplify losses during yield, collateral, liquidity, or execution shocks. The audit identified strategy-type, precision, token-registration, and residual-value issues in farming workers, including confirmed design assumptions.HighMediumPosition-management, kill, emergency, and strategy checks exist in the reviewed modules; live collateral ratios, liquidation parameters, and oracle design are Not verifiable as of September 5, 2026.High: tail losses and liquidations remain structurally possible.
Cross-chain deployment divergenceMole operates across Aptos and Sui, but the located protocol-specific audit is Aptos-only. A defect, upgrade, dependency failure, or configuration difference on one chain could create asymmetric losses or confuse risk monitoring.HighMediumSeparate Move-based deployments provide chain-level isolation; Sui audit scope, deployment equivalence, and cross-chain dependencies are Not verifiable as of September 5, 2026.High: weakest-chain and weakest-dependency risk remains unresolved.
Limited independent assuranceCertiK lists one third-party audit but no CertiK audit, KYC, or CertiK bug bounty. The existence, scope, payout terms, and responsiveness of any independent bounty program are Not verifiable as of September 5, 2026.MediumMediumA public MoveBit audit exists and reports remediation of identified issues. A current public bounty, incident-response policy, and continuous monitoring should be independently confirmed.Medium-High: vulnerability discovery and response capacity remain uncertain.
Evidence (3)

strengths

two sources

Mole’s top strengths are: multi-product breadth, cross-chain deployment, AMM/CLMM support, automation/AI-assisted strategy execution, and built-in risk controls for leveraged products. The strongest verifiable points from the available sources are that Mole offers savings, leveraged yield farming, and funds, is deployed on both Sui and Aptos, and positions itself as fully compatible with both AMM and CLMM liquidity models on Sui.

  • Broad product suite: Mole combines savings pools, leveraged yield farms, and managed funds, which gives users multiple risk/return profiles in one protocol.
  • Cross-chain presence: The protocol is deployed on Sui and Aptos, which can broaden distribution and reduce single-chain dependence.
  • Liquidity-model flexibility: Mole states that it supports both AMM and CLMM algorithms on Sui, which is useful for integrating with different DEX liquidity designs.
  • Automation/AI angle: Mole claims to use artificial intelligence to optimize fund revenue and liquidity strategies; independent coverage also describes machine-learning-based range management and automated position adjustment. The exact performance of these models is not verifiable as of 2026-09-04.
  • Risk-management features: The savings product documentation emphasizes non-withdrawable borrowed funds, liquidation mechanisms, and contract-enforced use of leverage, which are intended to reduce misuse and protect deposits. One important caveat: the available evidence is mostly protocol docs and secondary profile pages, so the first, third, fourth, and fifth points are best treated as unverified marketing claims unless independently confirmed by audits or on-chain analysis.
Evidence (4)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 21 two independent sources, 6 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-29.