Orca DEX

Orange · 51/100

Executive summary

Orca is a Solana-based decentralized exchange (DEX) and automated market maker (AMM) with concentrated liquidity (Whirlpools), scoring 58/100 (orange band) with high data confidence (87/100) and a -10 penalty for unresolved incident remediation.

  • Security: Multiple independent audits by Neodyme, Kudelski, OtterSec, and Sec3 since 2022; Neodyme's May 2022 report identified 1 high and 1 medium finding, all resolved and verified. Active Immunefi bug bounty up to $500,000. However, deployed-bytecode equivalence for recent audits (2025–2026) is not verifiable as of September 2026, and several audit PDFs lack extractable findings details.
  • Incidents: Exposed to the April 2026 Vercel frontend-hosting breach; Orca rotated credentials with no reported on-chain impact or user-fund loss ($0 realized loss). Status remains "remediation in progress" because Vercel's broader investigation was ongoing, triggering the -10 penalty.
  • Governance & custody: Non-custodial protocol with DAO governance via ORCA/xORCA token holders and an elected Council. Upgrade authority is held by a Squads V4 multisig vault (GwH3Hiv5mACLX3ufTw1pFsrhSPon5tdw252DBs4Rx4PV), but signer threshold, independence, and governance linkage are not disclosed—creating a contradiction between stated token-holder control and operational multisig authority.
  • Top risks: Smart-contract exploit (high-impact tail risk despite audits); Solana infrastructure dependency (outages impair all functions); concentrated-liquidity economics (impermanent loss, out-of-range positions); MEV/execution loss; and governance/operational control opacity (multisig details unverified).
  • Strengths: Established Solana DEX since February 2021 with clean exploit history; user-friendly interface and fast, low-cost execution; capital-efficient Whirlpools design; mature ecosystem integration; publicly identified founders (Grace Kwan, Yutaro Mori); open REST API and verifiable-build repository.
  • Unverified: Current deployed-bytecode match for 2025–2026 audits; multisig signer set, threshold, and DAO linkage; treasury custody configuration; on-chain TVL/exposure breakdown (Dune unavailable); 30-day primary yield and protocol-wide fee metrics; exact legal entity, jurisdiction, and ToS geoblocking list.
  • Recommended exposure: Conservative position sizing (≤5% of Solana DeFi allocation) until multisig governance and bytecode verification are clarified. Suitable for users comfortable with Solana infrastructure risk, impermanent loss, and DAO operational control. Avoid concentrated positions until Vercel incident remediation is formally closed and recent audit coverage is independently confirmed.
  • Open questions: Verify current Squads multisig signers, threshold, and DAO oversight mechanism; confirm deployed program bytecode matches latest audited commits; obtain full Sec3 2025–2026 audit reports with findings/remediation tables; assess treasury custody and reserve composition on-chain; clarify legal entity, jurisdiction, and regulatory compliance posture; validate 30-day fee yield and LP economics across representative pools.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 10 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 30 6.0 last full audit 2025-08-22 is older than a year; auditor not in top-20 -20
Incidents 20% 100 20.0 1 open incident(s), $0 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 25 5.0 governance controls unknown
TVL 20% 1 0.2 TVL $256,780,267 = 1% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 17/49 verified facts; 48/49 fresh (180d)

Identification

protocol identification

two sources

Orca is a Solana-based decentralized exchange (DEX) and AMM with concentrated liquidity (Whirlpools) and a governance token ORCA, operating solely on Solana. Protocol identification

  • Name: Orca DEX (often just “Orca”).
  • Website: Public-facing app and info at the main Orca domain.
  • Docs: Technical and user documentation hosted on the Orca documentation site.
  • Category: Decentralized exchange (DEX) / AMM, with concentrated liquidity CLAMM/CLMM via Whirlpools.
  • Launch date (protocol): Orca launched as one of the first general‑purpose AMMs on Solana in February 2021.
  • Launch date (token): The ORCA token launched 9 August 2021 with a hard‑capped 100M supply.
  • Chains: Solana only (all references describe Orca explicitly as a Solana DEX; no credible mention of other chains).
  • Native token: ORCA SPL governance token. Main program / contract addresses (Solana) On‑chain verification via Dune is Not verifiable as of 2026‑09‑04.
  • Orca Whirlpool (concentrated liquidity): Program ID whirLbMiicVdio4qvUfM5KAg6Ct8VwpYzGff3uctyCc.
  • Cross‑check: Listed as “Orca Whirlpool” with CLMM pricing model on an independent Solana DEX program‑ID reference.
  • Orca v1 legacy AMM: Program ID 9W959DqEETiGZocYWCQPaJ6sBmUzgfxXfqGeTEdp3aQP.
  • Cross‑check: Appears as orca_swap_program for legacy pools in a separate router/program‑ID catalog.
  • ORCA SPL token mint: Not directly stated in retrieved sources; Not verifiable as of 2026‑09‑04.
  • Explorer verification status: Individual sources reference these as program IDs for Orca but do not explicitly state Solana explorer “verified” status; this is Not verifiable as of 2026‑09‑04. Fork lineage / originality
  • Multiple independent descriptions present Orca as one of the first general‑purpose AMMs on Solana, implying it is not a simple fork of another Solana DEX.
  • Whirlpools/CLAMM are described as Orca’s own concentrated liquidity design introduced after the initial constant‑product AMM.
  • No credible source identifies Orca as a fork of a specific upstream protocol (e.g., Uniswap v3 or Raydium), or documents direct fork lineage; this is therefore Not verifiable as of 2026‑09‑04.
  • Audit coverage and any “changes vs upstream audited” details are not specified in the retrieved sources; Not verifiable as of 2026‑09‑04.
  • Security history: one review and a project profile highlight a zero‑exploit record over years of operation, but this is an unverified marketing claim without direct audit/on‑chain confirmation.
  • No records were found of malicious‑modification incidents in Orca forks; presence or absence of such events is Not verifiable as of 2026‑09‑04.
Evidence (9)

maturity

two sources

Orca DEX looks like a real, live product rather than a placeholder landing page: its documentation includes a public REST API for Solana, and the docs show concrete endpoints for protocol stats, pool search, and token search with no authentication required for read access. That is a strong signal of operational maturity and developer usability, not a template site. The main user-facing site also presents Orca as an active product with code and protocol positioning, while the docs site links back to the main app.

I did not find evidence in the gathered material of broken links, fake metrics, or obvious template reuse; however, those absence findings are limited to the pages reviewed and are not fully verifiable here. For live deposits/withdrawals: for a Solana DEX, user activity is mediated through swaps and liquidity provision rather than custodial deposits/withdrawals, and the available material confirms protocol data access and trade/pool surfaces but does not directly verify specific UI state for deposit/withdrawal flows. Not verifiable as of 2026-09-04.

Open API: yes. Orca documents a public read-only API at api.orca.so/v2/solana, explicitly described as open and not requiring authentication for read access. Overall: Orca’s website/docs indicate a mature, functioning Solana DEX with a real app surface and an open API, but direct verification of live UI transaction flows and any hidden broken-link/template issues is not complete from the sources gathered.

Evidence (4)

Security

bug bounty

two sources

Orca DEX has an active bug bounty program on Immunefi for its Solana deployment. It appears to have started on 19 May 2022, with scope centered on Orca’s Whirlpools and related in-scope assets. Reported rewards include up to $500,000 for critical smart-contract issues, with PoC required and payouts handled by the Orca team in USDC/ORCA, sometimes vested for larger awards.

Publicly documented results include at least one whitehat bounty outside the Immunefi scope: a 100,000 USDC payment approved by Orca governance in March 2023 for a critical legacy Solana spl-token-swap issue. Not verifiable as of 2026-09-04: a complete count of all Immunefi submissions, accepted reports, or total paid amounts.

Active
Yes
Platform
Immunefi
Max payout
$500K
Since
2022-05-19
Evidence (4)

counterparty risks

unverified

As of September 6, 2026 — Dependencies & Counterparty Risk

  • Core dependency: Orca Whirlpools is a Solana-native CLMM. Solana availability, congestion, transaction finality, RPC/wallet infrastructure, and SPL-token functionality are critical external dependencies. A Solana outage or severe congestion would impair swaps, LP management, and withdrawals.
  • Custody / insolvency: The protocol is designed as a non-custodial AMM: pool vaults are controlled by the Whirlpool program, not an operating custodian or CEX. No ordinary custodian, RWA issuer/SPV, or centralized counterparty was identified. However, wallet compromise and malicious token contracts remain user-level risks.
  • Oracles / manipulation: Adaptive-fee pools use an on-chain Whirlpool oracle account for volatility measurement; this is not documented as an external price oracle. Pool prices remain vulnerable to thin-liquidity manipulation, sandwiching, adverse selection, and impermanent loss, particularly for permissionless or newly created pools.
  • Aggregators / routing: Orca’s Smart Router can split trades across up to six routes, creating execution dependence on routing logic and the liquidity/availability of referenced Solana venues. This is an integration/execution risk, not evidence that Orca itself holds aggregator assets.
  • Bridges / wrapped assets: Bridge risk is conditional, arising when users bring ERC-20 or other cross-chain assets onto Solana as SPL or wrapped representations. Failure, censorship, or depeg of the bridge-backed asset can impair the relevant pool; this is not a uniform protocol-wide exposure.
  • Stablecoins, LSTs/restaking, CEX/MM, RWA/SPV: Pool composition is permissionless and changes over time. Protocol-wide exposure, concentration by asset/issuer, market-maker or CEX balances, and any active depeg/insolvency event are Not verifiable as of September 6, 2026 without raw on-chain analysis. Failure scenarios: Solana outage; Whirlpool-program exploit; token-mint freeze/blacklist or bridge depeg; manipulated thin pool price; router/transaction failure; wallet or frontend compromise. On-chain verification: Dune MCP was unavailable; no query ID or execution ID exists. TVL/exposure percentages are therefore Not verifiable as of September 6, 2026. dependency_failure_active: null max_exposure_pct: null
Evidence (5)

crypto custody

one source

Orca DEX is organized as a non-custodial protocol on Solana: users connect their own wallet, keep control of their assets, and sign transactions themselves rather than depositing funds into an Orca-controlled account. Orca’s terms state that it does not act as an intermediary, custodian, or counterparty for swaps and that it does not take custody or control of user funds. Liquidity withdrawals are initiated by the user from their wallet, so there is no evidence of an Orca-level custody layer or withdrawal freeze in the material reviewed; withdrawal_paused is Not verifiable as of 2026-09-06.

Segregated_assets is false in the practical sense that user assets remain in users’ personal wallets rather than being pooled into segregated Orca-held accounts, but formal asset-segregation language is Not verifiable as of 2026-09-06.

Segregated assets
No
Evidence (2)

incident

two sources

On April 19–20, 2026, Orca was exposed to the Vercel frontend-hosting security incident. Vercel reported unauthorized access to internal systems and possible exposure of certain customer deployment/environment credentials. Orca stated that its frontend was hosted on Vercel, rotated potentially exposed keys and deployment credentials, and found no impact to Orca’s on-chain programs or user funds.

Affected: frontend deployment infrastructure and potentially exposed credentials; no protocol contracts, liquidity pools, or user balances were reported affected. Response/fix: credential rotation, environment review, continued monitoring, and migration away from Vercel was reported. Realised loss was $0; attacker proceeds affecting Orca were not reported and are Not verifiable as of 2026-09-06.

No recovery or reimbursement was required. Current status: remediation_in_progress because Vercel’s broader incident investigation remained active, although Orca’s identified exposure was mitigated. The April 2, 2026 Drift incident was not an Orca incident and is excluded.

Date
2026-04-19
Cause
Frontend / infrastructure hack
Loss
$0
Status
remediation in progress
Recovered
$0
Reimbursed
No
Event id
orca-vercel-2026-04
Evidence (3)

incident

one source

A 2026 report says Orca rotated potentially leaked deployment credentials after a possible cloud-hosting/provider issue, with no impact on funds and no on-chain protocol compromise described.

Date
2026-04-20
Cause
Frontend / infrastructure hack
Evidence (1)

key management

two sources

Orca is non-custodial: users keep assets in their own Solana wallet, and Orca only reads the public address and submits transactions the user explicitly approves. For protocol-level control, Orca uses ORCA token governance via the Orca DAO: token holders participate in decisions, with an elected council plus a veto mechanism described in third-party coverage and review material. In practice, that means key management is split between user wallet keys (self-custodied by the trader or LP) and governance/admin keys used to run the DAO and protocol operations; the exact signer setup for operational keys is not fully verifiable from the provided sources, so that part is Not verifiable as of 2026-09-04.

Evidence (4)

smart-contract

unverified

Scope/identity. Official Orca Whirlpools deployment is Solana program whirLbMiicVdio4qvUfM5KAg6Ct8VwpYzGff3uctyCc; the repository describes it as verifiable-build and lists multiple audits. Legacy Orca components may exist, but this review is anchored to the current Whirlpool program. Architecture map ``text User wallet │ swap / add-liquidity / withdraw ▼ Whirlpool program (PDA pools, positions, tick arrays) ├─ SPL Token / Token-2022 programs ├─ WhirlpoolConfig authorities │ ├─ fee authority │ ├─ protocol-fee collection authority │ └─ reward-emissions super-authority └─ Solana BPF Upgradeable Loader → upgrade authority (?) `` The source exposes user-controlled withdrawal/fee-collection instructions and config-admin functions for fee rates, protocol fees, reward authorities, feature flags, and adaptive-fee parameters. Protocol-fee collection is distinct from withdrawing LP liquidity. Admin / upgrade risk. Solana programs can remain upgradeable until the upgrade authority is removed; finalization makes the program immutable.

Current Whirlpool upgrade-authority address, whether it is revoked, its signer type (EOA/multisig/DAO), any timelock delay, and decoded admin-event history: Not verifiable as of 2026-09-06. Dune was unavailable, so no on-chain verification or query/execution IDs are available. Controls and user exit. No externally documented pause, oracle, strategy, or emergency-withdraw function was verified. The AMM uses pool state and tick arrays rather than a separately verified price-oracle administrator.

Users can generally withdraw their own positions through the program, subject to normal transaction/runtime conditions; however, a compromised live upgrade authority could deploy malicious logic, freeze interactions, alter fees, or redirect assets. A compromised fee/protocol-fee authority appears limited by program-level account checks to fee/config powers, not arbitrary LP withdrawal; this conclusion is source-based, not current-state on-chain verified. Audit status. Audits are documented, but complete deployment-to-audit-version matching and unresolved finding counts are Not verifiable as of 2026-09-06. Risk conclusion: material governance/upgrade-key risk remains unresolved; rug/freeze risk depends primarily on whether upgrade authority is still live and how it is controlled.

Audited deployment
Yes
Evidence (5)

audit

one source

New published report: Sec3 review of Whirlpools updates, published August 18, 2026. The report is listed in Orca’s public audit repository, but the PDF contents and detailed scope/severity table were not extractable through the available web paths. Deployed-bytecode equivalence is Not verifiable as of 2026-09-06.

Auditor
Sec3
Report date
2026-08-18
Scope
Not verifiable as of 2026-09-06.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/orca-so/whirlpools/blob/main/.audits/2026-08-18.pdf
Report id
doc:016734420ce194b4
Covers deployed code
No
Evidence (2)

audit

unverified

Corrected split of the previously merged January 14, 2026 Sec3 entries: Orca’s security-audit index lists two distinct Sec3 reports for that date, covering separate PR groups. The detailed findings, remediation status, and deployed-code coverage for each report are Not verifiable as of 2026-09-06.

Auditor
Sec3
Report date
2026-01-14
Scope
Two separate reports are listed: PRs 99–1189 and PRs 94–95–96; detailed scope is Not verifiable as of 2026-09-06.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://docs.orca.so/audits/whirlpools/2026-01-14-prs-99-1189.pdf
Report id
doc:6edbab12f6ede9b0
Covers deployed code
No
Evidence (3)

audit

one source

Corrected record: Neodyme audit of Orca Whirlpools, published May 5, 2022. The report covers the Whirlpools Solana smart contract and custom U256 math. It identifies one High finding, one Medium finding, and one Informational finding; all were marked Resolved, and Neodyme verified the fixes.

The audited source commit matched the subsequently open-sourced commit, but deployed-bytecode equivalence as of September 6, 2026 is Not verifiable as of 2026-09-06.

Auditor
Neodyme AG
Report date
2022-05-05
Scope
Orca Whirlpools Solana smart contract, including custom U256 math used for swap calculations; audited source commit c55588a6eae1144be58bd348992f693e8b5ddc01.
Findings
1 High: lower tick could be larger than upper tick; 1 Medium: integer overflow when swapping; 1 Informational: overflow in checked_mul_shift_right_round_up_if. No Critical finding reported.
Fix status
All three findings marked Resolved; Neodyme verified the fixes. Current deployed-program equivalence is Not verifiable as of 2026-09-06.
Report url
https://neodyme.io/reports/Orca-Whirpools.pdf
Report id
doc:b4d242557ccea6f8
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

New published report: Sec3 review of Whirlpools updates, published August 11, 2026. The report is listed in Orca’s public audit repository, but the PDF contents and detailed scope/severity table were not extractable through the available web paths. Deployed-bytecode equivalence is Not verifiable as of 2026-09-06.

Auditor
Sec3
Report date
2026-08-11
Scope
Not verifiable as of 2026-09-06.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/orca-so/whirlpools/blob/main/.audits/2026-08-11.pdf
Report id
doc:b68276d0db0e616e
Covers deployed code
No
Evidence (2)

audit

one source

Audit of Shared Memory and Token Swap program for Orca on Solana.

Auditor
Kudelski Security
Report date
2022-01-28
Scope
Core AMM contracts (Token Swap / shared memory program) on Solana.[1][2][9]
Findings
Report describes security analysis, architecture review, and code–documentation compliance.[9] Specific issue severities are not enumerated in the publicly visible snippet, and the PDF does not provide a simple Critical/High/Medium summary table; one or more issues were identified and remediated but exact counts by severity are Not verifiable as of 2026-09-04.[9]
Fix status
Report indicates recommendations and fixes were applied, but detailed per‑finding remediation status and post‑deployment verification are Not verifiable as of 2026-09-04.[9]
Evidence (2)

audit

two sources

Orca DEX (Solana AMM and Whirlpools concentrated liquidity) has undergone at least one formal security audit by Neodyme, a Solana‑focused security firm. According to public summaries, this engagement covered core AMM contracts and associated Solana program logic, including swap, liquidity provision, and fee mechanisms. Detailed information on the exact modules and whether the audit covered the currently deployed program bytecode is Not verifiable as of 2026-09-03.

Findings and severities (critical/high/medium) from the Neodyme audit, as well as exact fix status per issue, are Not verifiable as of 2026-09-03, because the full report is not publicly accessible via Neodyme’s or Orca’s official channels in indexed form. Several secondary sources and listings (e.g., DeFi aggregators and security overviews) state that Orca is "audited by Neodyme" but do not reproduce or link an underlying PDF or GitHub report with issue lists, severities, or remediation notes. Because the original report and its hash/bytecode mapping are not available, whether the audit covers the exact deployed Solana program IDs and current versions of Orca’s contracts (AMM pools, Whirlpools, router, and peripheral programs) is Not verifiable as of 2026-09-03.

Any claims that the audit fully covers live code must therefore be treated as unverified marketing claim.

Auditor
Neodyme
Report date
2021-10-01
Scope
Core AMM and Whirlpools Solana programs (swap, liquidity, fee logic) — detailed module list Not verifiable as of 2026-09-03
Findings
Not verifiable as of 2026-09-03
Fix status
Not verifiable as of 2026-09-03
Evidence (2)

audit

one source

Security audit of Orca Whirlpools concentrated liquidity smart contract on Solana.

Auditor
Neodyme
Report date
2022-05-05
Scope
Orca Whirlpools smart contract program on Solana, including custom U256 math used for swap calculations.[1][13]
Findings
Neodyme reports **one severe vulnerability** plus **medium and low‑priority findings**, all resolved by the Orca team before launch.[13] The exact counts of medium and low issues, and detailed descriptions per issue, are contained in the full report but structured Critical/High/Medium categorization is not explicitly mapped to traditional CVSS terminology; therefore explicit counts by category beyond “one severe” are Not verifiable as of 2026-09-04.[13]
Fix status
Neodyme states all reported bugs were fixed and the audited commit hash `c55588a6eae1144be58bd348992f693e8b5ddc01` matches the open‑sourced code, indicating coverage of deployed Whirlpools code at launch.[13] Later upgrades and current on-chain bytecode equivalence with the audited commit are Not verifiable as of 2026-09-04.
Evidence (2)

audit

two sources

Multiple audits of Orca Whirlpools and broader protocol components on Solana.

Auditor
OtterSec
Report date
2024-08-21
Scope
Whirlpools and potentially full protocol (AMM + CLMM + fee management) on Solana, based on scope summary in secondary security reviews.[1][2][5]
Findings
Public secondary sources state that Orca has been audited several times by OtterSec, covering the core AMM, Whirlpools CLMM pools, and fee‑management contracts, but they do not quote detailed issue lists or severities; specific Critical/High/Medium issue counts and descriptions are Not verifiable as of 2026-09-04.[1][5]
Fix status
Protocol documentation and independent reviews assert that OtterSec audits were completed and issues addressed, but granular per‑finding remediation status and on-chain verification (bytecode match to deployed programs) are Not verifiable as of 2026-09-04.[1][2][5]
Evidence (3)

audit

one source

Whirlpools audit; covers deployed code: No—release source only; deployed-bytecode match: Not verifiable as of 2026-09-05.

Auditor
Sec3
Report date
2025-02-28
Scope
Liquidity Locking feature; commit 26057c46; tests excluded.
Findings
No critical/high/medium findings; 2 informational findings and 2 questions.
Fix status
Questions resolved; informational findings acknowledged.
Evidence (1)

audit

one source

Whirlpools audit; covers deployed code: No—PR source only; deployed-bytecode match: Not verifiable as of 2026-09-05.

Auditor
Sec3
Report date
2025-06-23
Scope
PR918, PR902, PR903, PR904, PR970; tests excluded.
Findings
1 medium, 2 low, 3 informational findings, plus 7 questions; no critical/high findings.
Fix status
All 13 findings/questions reported resolved.
Evidence (1)

audit

one source

Whirlpools audit; covers deployed code: No—PR source only; deployed-bytecode match: Not verifiable as of 2026-09-05.

Auditor
Sec3
Report date
2025-08-22
Scope
PR974, PR1010, PR1038; tests excluded.
Findings
1 question and 1 informational finding; no critical/high/medium findings reported.
Fix status
Question resolved; informational issue acknowledged.
Evidence (1)

Team & Reputation

founders

two sources

Orca’s founders are publicly identified as Grace “Ori” Kwan and Yutaro Mori; multiple independent writeups describe them as the co-founders, and Orca later doxxed from pseudonyms to real names in 2021. Kwan’s background is product/design-heavy (Google internship, Button, IDEO), while Mori is described as coming from engineering/blockchain work, including Ethereum-related and smart-contract experience. Reality check: Orca appears to be a real operating business, not just a web front. Independent sources describe a team expansion beyond the founders, a remote culture, and an outside hiring footprint; LinkedIn lists the company as privately held with 11–50 employees, which is consistent with a small venture-backed protocol team.

Messari also says the team received one of the earliest Solana Foundation grants and built an early pure AMM DEX on Solana, which supports substantive product development rather than a thin marketing shell. Credibility signals: Orca has been portrayed as founder-led, technically credible, and user-experience focused, with later outside coverage noting multiple independent security audits and no confirmed exploits since inception for its Whirlpools CLMM product. However, these are mostly third-party and protocol-facing claims; I could not independently verify the team’s current legal domicile, office location, or onshore/offshore structure from the available sources. Not verifiable as of 2026-09-04. Prior projects / outcomes / hacks: The founders’ earlier work included a beginner-friendly crypto interface prototype built for the Mozilla Builders program and an attempt to improve accessibility for retail users on Ethereum before moving to Solana. No confirmed founder-linked hacks or major protocol exploits were surfaced in the provided sources; Orca’s own site and AVOID.NET both state there have been no confirmed exploits since launch, but the protocol-site claim is unverified marketing without on-chain corroboration here.

Evidence (9)

general reputation

two sources

Orca’s reputation is generally positive: it is widely described as a long-running, non-custodial Solana DEX with a clean security record, multiple independent audits, and an active bug bounty program. Independent reviews also characterize it as one of the safer Solana DEXs, while still noting normal DeFi risks such as smart-contract, wallet, token, and LP/impermanent-loss risk. On founders/team, the available results say the team is publicly disclosed/self-doxxed, and one source describes Orca as founded in 2021 by a small team in Tokyo; however, this is less directly authoritative than an official filing or team statement.

On audits, the results repeatedly mention reviews by firms such as Sec3, OtterSec, Neodyme, and Kudelski Security, plus an Immunefi bug bounty with a maximum payout of $500,000. For sentiment, the broad market framing is favorable: Orca is portrayed as established Solana infrastructure with no major exploit history and a user-friendly design. Some third-party risk frameworks still rate it as medium risk because of concentrated LP risk, dependence on aggregators, and governance/value-accrual concerns tied to the ORCA token.

On criticisms and unresolved concerns, the main recurring issues are not fraud allegations but standard DEX risks: impermanent loss, fake tokens, malicious links, smart-contract risk, and the possibility of governance being economically thin because the token is relatively small. I did not find credible evidence in the provided results of a rug pull, insolvency event, or protocol-level hack/exploit; multiple sources explicitly say there has been no major hack since launch. On legal/regulatory/sanctions, the provided results do not show any concrete sanctions designation, enforcement action, or insolvency/legal controversy tied to Orca. Not verifiable as of 2026-09-04 for any stronger legal/regulatory conclusion beyond the absence of reported actions in these results.

Evidence (7)

Economy

TVL: $256.8M

model

one source

Scope/as-of: Solana Orca DEX; web sources checked September 6, 2026. Dune MCP was unavailable, so every on-chain item requiring Dune is Not verifiable as of 2026-09-06.

  • Strategy/assets in-out: Non-custodial spot AMM: traders swap SPL assets; LPs deposit token pairs into Classic/Splash pools or concentrated-liquidity Whirlpools and withdraw the pair plus accrued fees. Whirlpools support fixed and adaptive fee tiers from 0.01%–2%.
  • Yield source: Primarily trading fees. Standard split is 87% LPs, 12% protocol treasury, 1% Climate Fund; protocol fees are further allocated to operations/treasury and ORCA buybacks/xORCA.
  • Organic vs subsidized: Fee yield is organic trading revenue. Separate pool-reward programs are externally funded token incentives and therefore subsidized; they can end and are not automatically compounded. organic_yield_pct: null.
  • Risk posture: Directional LP exposure and impermanent loss; concentrated positions stop earning fees when out of range and may become 100% one token. No native lending collateral, leverage loops, or restaking identified in reviewed sources; comprehensive exposure verification is Not verifiable as of 2026-09-06. leverage_ratio: null.
  • Lock-ups/withdrawals: Solana LPs may withdraw anytime; partial or full withdrawal returns assets after transaction confirmation and harvests uncollected fees. Position NFT custody is essential. No protocol-wide lock-up or gate identified.
  • Fees/limits: Pool-specific swap fees, adaptive fees, network fees, and user-set slippage thresholds. Pool-level liquidity and range constraints apply.
  • Revenue: DeFiLlama reports approximately $4.71m fees and $608.8k protocol revenue over the latest 30 days; this is aggregator data, not on-chain verified.
  • TVL: DeFiLlama reports $256.22m total TVL, +5.1% over 30 days, across Solana and Eclipse, with 100% currently attributed to Solana. Product-level TVL, Dune-vs-Llama reconciliation, and chain trend from raw data: Not verifiable as of 2026-09-06.
  • APY: DeFiLlama shows 790 tracked pools and 80.77% average supply APY, but APY history, volatility, and sustainability are Not verifiable as of 2026-09-06; the average is not a portfolio-return estimate.
Evidence (4)

reserves

unverified

As of September 6, 2026, Orca’s reserve position is only partially verifiable from web evidence. Dune/on-chain balance verification is unavailable in this run: Not verifiable as of September 6, 2026. Therefore, liquid_reserves_usd and liabilities_usd are null. Disclosed treasury addresses (Solana):

  • Fee Treasury, various tokens: DWo8SNtdBDuebAEeVDf7cWBQ6DUvoDbS7K4QTrQvYS1S
  • Community ORCA Treasury: GwH3Hiv5mACLX3ufTw1pFsrhSPon5tdw252DBs4Rx4PV
  • Climate Fund, USDC: DrhE25wu3PRGtBCtzsry6ToiGjhwBzCnYGpvv53qxh9X
  • Undistributed Solana fees: CTgympSD3hkBhH2XYwFGCigrFh3ZHAvnxwAfm7nCbExY Composition and policy: Treasury assets comprise ORCA, SOL, USDC and other fee tokens. Current documentation states that 12% of pool trading fees go to the protocol, with 40% of that share used for ORCA buybacks/xORCA rewards and 60% sent to the Fee Treasury; 1% goes to the Climate Fund. Governance materials also describe treasury use for development, grants, operations, validator staking and buybacks. Control/custody: Governance documentation assigns treasury oversight to the elected DAO Council, subject to tokenholder-approved budgets and governance constraints. A 2025 proposal describes the Fee Treasury as a “multi-signature DAO Treasury Wallet,” but the signer set, threshold, wallet program, and current custody configuration are Not verifiable as of September 6, 2026. Reserve size: A May 2023 treasury report disclosed approximately $3.64 million in the Fee Treasury and $1.14 million in the Climate Fund, but these figures are stale and cannot be used as current balances. > Contradiction / transparency gap: Orca’s public materials describe changing fee allocations (including prior 20%/30%/50% and later 40%/60% structures), while a December 2025 governance post stated that buyback timing, amounts, and development spending remained insufficiently transparent. Current balances and liabilities remain unverified. No independent treasury attestation, audit, or current reserve statement was identified.
Evidence (5)

tokenomics

two sources

Orca is a Solana DEX with a native token ORCA. 1. Token identifiers

  • Name / ticker: Orca (ORCA)
  • Main Solana mint address: 6n6uK3zdhvWxYLwcs29DgP2RjL9CawXU9sGWGT4C67G
  • Chain: Solana only. On‑chain verification of any figures is Not verifiable as of 2026‑09‑04. 2. Supply, market cap, FDV
  • Multiple analytics sources state max / total supply ≈ 100M ORCA.
  • Reported circulating supply is ~25–30M ORCA depending on source and date (stale, varies).
  • Market cap and FDV differ across aggregators and change with price; treat all web numbers as indicative only (no on-chain check possible). Not verifiable as of 2026‑09‑04. 3. Token utility & governance
  • ORCA is primarily a governance / utility token for the DEX.
  • Historical docs and listings describe use for:
  • Protocol governance (voting on parameters and initiatives).
  • Liquidity incentives (rewards to LPs in selected pools).
  • General ecosystem utility, including integration with Solana DeFi. Any detailed governance powers, quorum rules, or council roles are Not verifiable as of 2026‑09‑04. 4. Revenue share, buybacks, burns, staking
  • Public sources do not provide a clear, current statement that swap fees are shared directly with ORCA holders via staking, buybacks, or dividends. Not verifiable as of 2026‑09‑04.
  • No reliable evidence of systematic token burns or a formal fee-switch to token holders can be confirmed from independent analytics. Not verifiable as of 2026‑09‑04. 5. Emissions & unlocks; allocations
  • Third‑party listings mention a classic allocation split (team, investors, community / liquidity mining, treasury), but exact % and the emission / unlock schedule are inconsistent across sources and often reference early‑2022 data.
  • Whether specific cliff/vesting unlocks actually executed on-chain for team/investor wallets is Not verifiable as of 2026‑09‑04. 6. Concentration & control features
  • Top‑holder concentration (team, investors, CEXs, LP vaults) and identification of “insider” wallets are Not verifiable as of 2026‑09‑04.
  • No independent confirmation of mint, blacklist, or fee‑switch admin functions for the ORCA mint; contract‑level powers are Not verifiable as of 2026‑09‑04. 7. Liquidity & listings
  • ORCA is listed on Solana DEXs (including Orca itself) and major CEXs like Coinbase and others according to token listing pages.
  • Exact DEX liquidity depth and pool composition are Not verifiable as of 2026‑09‑04.
Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would likely be a broad risk-off shock for Solana DeFi, and Orca would be exposed mainly through lower trading activity, thinner liquidity, and weaker speculative demand rather than direct Bitcoin-related protocol mechanics. Orca is a Solana DEX using concentrated liquidity via Whirlpools, so its revenue and token sentiment depend on swap volumes and ecosystem risk appetite. For Orca specifically, the most defensible stress view from the available sources is a sharp downside in ORCA price and volume, not a protocol-specific failure.

Independent forecast-style sources that explicitly model bearish conditions place ORCA in roughly the $0.30–$1.00 area under prolonged bear-market or adverse macro/regulatory scenarios, with some more conservative views citing $0.60–$1.00 as a retracement zone if Solana DEX volumes normalize and fee-growth assumptions fail. Because the available sources are mostly price-prediction and review content, the exact impact on Orca’s TVL, fees, and user retention under BTC < $10k is Not verifiable as of 2026-09-04. The best supported conclusion is that a BTC crash would be a negative cross-asset shock for ORCA, with likely compressed valuations and reduced on-chain activity across Solana DeFi.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

For Orca on Solana, a “largest collateral depeg 20%” stress scenario is not verifiable as of 2026-09-04 from the available web sources, because Orca is a DEX and the provided results do not expose any on-chain collateral set, lending market, or liquidation engine to quantify a depeg-driven loss channel. Orca’s documentation describes it as a Solana DEX for providing liquidity and swapping, not as a collateralized lending protocol. What can be said is that a 20% depeg is severe enough, in general DeFi terms, to trigger rapid liquidations where collateral is priced through an oracle and positions are marked against that feed.

In stress-testing language, the relevant loss driver would be the amount of collateral that becomes liquidatable once the oracle reflects the 20% price drop, but that exposure size is not verifiable as of 2026-09-04 for Orca from the sources available here. If you want a protocol-specific number, the missing inputs are: the exact collateral asset set, oracle design, liquidation thresholds, and the amount of debt against each collateral type. Without those, any TVL-at-risk estimate would be speculative.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Orca DEX on Solana is a non-custodial AMM, so in a “top counterparty insolvent” stress scenario there is no traditional lending-style counterparty default waterfall to absorb losses. The main loss path is market/LP loss: if the largest liquidity provider or a routed trading venue becomes insolvent, users do not receive compensation from Orca smart contracts; they bear pool-price risk, slippage, and impermanent loss directly, while the protocol’s contracts continue to execute swaps and liquidity accounting as written. Expected loss path: insolvency at a major counterparty mostly shows up as failed external settlement, withdrawal stoppage, or a sharp price dislocation in the asset being traded; Orca itself does not extend unsecured credit or promise principal protection, so there is no contract-level recovery process documented in the protocol materials. The user-facing loss is therefore absorbed first by the affected trader or LP, then by the broader pool through adverse pricing if the insolvent asset becomes stale or non-redeemable. Who absorbs it:

  • LPs absorb impermanent loss and adverse rebalancing when prices move or one side becomes impaired.
  • Swappers absorb execution loss via slippage if liquidity thins or quotes move.
  • Orca governance/treasury is not documented as a backstop or insurer for insolvency losses in the sources reviewed. Compensation: Not verifiable as of 2026-09-04. No reviewed source states that Orca has an insolvency reserve, insurance fund, or automatic reimbursement mechanism for counterparty default. Impact path through smart contracts: the Whirlpool program continues to enforce pool math, position accounting, fee accrual, and swap execution; a counterparty insolvency affects the *inputs* (asset price, liquidity depth, token redeemability), not a special liquidation or recovery module inside Orca’s contracts. Audits indicate the protocol has undergone multiple reviews, but that speaks to code security rather than loss mutualization or default coverage.
Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For Orca DEX on Solana, I found no evidence of committed fraud by the DAO or owners in the sources provided. The strongest directly relevant materials instead describe Orca as a DAO-governed, non-custodial DEX and note a long operating history without a protocol-level exploit since launch. There is, however, a governance/audit finding showing that the Treasury can be set to the zero address, which could block both withdrawals and withdrawals-related actions if misused or misconfigured; that is a governance/control risk, not evidence of fraud.

Orca documentation also says the protocol is structured as a DAO with powers delegated to an elected DAO Council. Because no source here documents fraud, embezzlement, or malicious owner/DAO conduct, the appropriate stress-scenario assessment is: fraud by the DAO/owners is not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

Orca’s primary yield source on Solana is LP trading-fee income, and some pools also show additional rewards/incentives; Orca’s docs describe APY as an estimate that is *not guaranteed* and can change over time. For a stress scenario with negative 30d primary yield, the practical interpretation is that the protocol’s fee-based return is currently below zero over the last 30 days, so the primary yield source is *not supportive* of LP carry and would pressure net LP economics; however, a protocol-wide 30d negative primary-yield figure is Not verifiable as of 2026-09-04 from the available sources. What can be said with confidence is that Orca’s yield is pool-specific, especially for concentrated-liquidity positions, where returns depend on the exact price range and can differ materially between positions.

Aggregated yield pages show very different pool outcomes on Orca, with some pools still positive and others near flat, which confirms that a single protocol-level yield number can obscure real exposure. For risk analysis, the key implications of a negative 30d primary yield are:

  • Lower fee capture relative to volatility and rebalancing costs.
  • Higher chance of underperforming hold-only exposure after fees, slippage, and any impermanent loss.
  • Greater reliance on non-primary incentives if a pool is still attractive. If you need a strict protocol metric, the available web sources do not provide an on-chain verified 30d negative-yield calculation for Orca on Solana; that specific number is Not verifiable as of 2026-09-04.
Evidence (7)

Governance & Legal

governance

one source

As of September 13, 2026, Orca describes a delegated DAO: ORCA/xORCA holders propose and vote through Realms; an elected DAO Council handles routine parameters, emergency responses, treasury administration, and execution. The stated process is Discord idea → forum discussion/draft/review → Realms vote → Council/team implementation. These control claims are primarily protocol-authored and therefore unverified marketing claims. Control assessment: Contracts are not fully permissionless: independent Solana monitoring identifies a Squads V4 vault (GwH3Hiv5mACLX3ufTw1pFsrhSPon5tdw252DBs4Rx4PV) as the live Whirlpools upgrade authority, plus a separate legacy-AMM authority (23zF9Azpe9CN4iPeTsQndD1mQpcb5Gz1qFREL5gPTZvG).

This establishes a multisig-controlled upgrade surface, but its threshold, signers, signer independence, and governance linkage are not disclosed in the accessible sources. Contradiction / governance risk: Orca documentation says token holders control upgrades and treasury decisions, while current implementation is delegated to the Council/team and upgrade authority is held by external multisig vaults. The DAO is therefore operational rather than purely symbolic, but token-holder control over live contract authority is not independently verified. A July 2026 treasury thread also shows a 500,000-ORCA formal-submission threshold and limited forum engagement, indicating practical participation constraints. Voting concentration/top holders via Dune: Not verifiable as of September 13, 2026.

Dune MCP was unavailable; no on-chain query ID/execution snapshot can be provided. Frontend/company control: The frontend is presumed operated by the Orca team/site operator, but independent legal-entity, jurisdiction, registration number, directors, and binding Terms-of-Service attribution are Not verifiable as of September 13, 2026. Bottom line: delegated DAO with meaningful community voting, but material Council/team and multisig execution chokepoints; do not treat governance as fully token-holder-controlled without verifying current Realms authority assignments and Squads configuration.

Evidence (5)

legal & regulatory

two sources

Orca is a Solana-based AMM DEX launched in 2021 and operated by a core development team that has used the names Orca Foundation and “Orca team,” but there is no clearly documented, legally registered entity with a full corporate profile available from independent sources. Not verifiable as of [2026-09-04]. Jurisdiction / entity

  • Orca is described in documentation and interviews as an open-source, non-custodial protocol built on Solana, but public materials do not clearly state an incorporated operating company, registered jurisdiction, or corporate address. Not verifiable as of [2026-09-04].
  • The team has been associated with the Solana ecosystem and US/European presence through media coverage, but these are not formal legal disclosures. Not verifiable as of [2026-09-04]. Terms of Service / access restrictions
  • Orca’s web app includes front-end geoblocking and restrictions for certain jurisdictions (typical examples in DeFi include the US and sanctioned countries), but the precise list in Orca’s ToS cannot be independently reproduced without quoting the site, and there is no third‑party documentation confirming them. Not verifiable as of [2026-09-04].
  • As with many DEXs, the protocol smart contracts remain globally accessible; restrictions apply mainly at the UI level. KYC / AML
  • Orca is a non-custodial AMM; users interact directly with Solana smart contracts and do not create accounts with Orca, so no standard KYC onboarding is applied at the protocol level.
  • The front-end may integrate address screening or compliance vendors (e.g., to block OFAC-listed wallets), but independent confirmation of a specific provider or policy is not available. Not verifiable as of [2026-09-04]. Regulatory classification / guidance
  • There is no clear public statement by regulators (SEC, CFTC, EU, UK, MAS, etc.) formally classifying Orca itself (e.g., as an exchange, ATS, or VASP). Not verifiable as of [2026-09-04].
  • Orca is commonly classified by analytics platforms simply as a DEX / AMM on Solana, which is a functional, not legal, classification. Warnings, enforcement, court cases, sanctions
  • No record of regulatory enforcement actions directly targeting Orca or a known Orca entity could be found in regulator databases or reputable media. Not verifiable as of [2026-09-04].
  • No court cases specifically naming Orca as a defendant or subject of litigation were identified. Not verifiable as of [2026-09-04].
  • Orca (the protocol or team) is not listed on major sanctions lists (e.g., OFAC, EU) as an entity. Not verifiable as of [2026-09-04]. Data protection / privacy
  • As a non-custodial DEX using wallet-based access, Orca generally does not collect traditional personal identity data on-chain; any off-chain data collection (cookies, analytics, logs) would be governed by its website privacy policy, which is only available via Orca’s own site and therefore remains an unverified marketing claim. Risk implication
  • The absence of a clearly documented legal entity and jurisdiction increases counterparty, governance, and enforcement risk for institutional users, and makes regulatory recourse uncertain in case of disputes or technical failures.
Evidence (3)

Stability

stability

two sources

Orca DEX is a Solana decentralized exchange and does not issue its own stablecoin; therefore own_stablecoin is false. No verifiable evidence was found that an Orca-issued stablecoin ever depegged. The stablecoin-related fields are not verifiable as of 2026-09-06, including whether the protocol is stable in this category, the number of depegs, the last depeg date, and the maximum depeg percentage.

A separate Solana stablecoin event involving USX on Orca liquidity pools does not establish a depeg of an Orca-issued stablecoin.

Own stablecoin
No
Evidence (3)

Risks & Strengths

risks

one source

Orca’s principal risks are smart-contract failure, Solana infrastructure dependency, concentrated-liquidity economics, MEV-driven execution loss, and governance/operational control. Multiple audits and an active Immunefi bounty reduce—but do not eliminate—contract risk; on-chain exposure, TVL, and chain allocation are Not verifiable as of September 5, 2026 because Dune access is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract exploitA logic, arithmetic, account-validation, or upgrade defect could drain pools, freeze positions, or miscalculate swaps and fees. Audits identify historical findings, but coverage cannot prove absence of latent or newly introduced bugs.HighMediumMultiple independent audits, open-source Whirlpools code, continuous reviews, and an Immunefi bounty up to $500,000.High-impact tail risk remains, especially after contract changes or deployment of new features.
Solana availability failureA Solana halt, congestion event, validator/client fault, or RPC disruption could prevent swaps, exits, rebalancing, and timely liquidation of LP positions.HighMediumSolana status monitoring, ecosystem validator diversity, and user-side transaction/RPC redundancy.Medium; Orca cannot independently restore settlement while the base layer is impaired.
Concentrated-liquidity lossPrice movement can push LP positions out of range, stop fee generation, and create adverse inventory or impermanent loss; volatile or thin pools amplify losses.MediumHighConfigurable ranges, adaptive fees, position monitoring, wider-range strategies, and rebalancing guidance.Medium-High; mitigation requires active management and does not remove market risk.
MEV and execution lossJIT liquidity, arbitrage, sandwiching, latency, and shallow liquidity can worsen realized execution and transfer value from traders or LPs to searchers.MediumHighSlippage limits, pool selection, route monitoring, and prior audit review of front-running/sandwich attack surfaces.Medium-High, particularly for large or urgent trades.
Governance and operator riskThe DAO Council/team can execute approved upgrades, parameter changes, emergency actions, and treasury decisions; concentrated voting or process failure could harm users.HighMediumToken-holder voting, public proposal process, elected council, community oversight, and audit requirements for major code changes.Medium; governance capture, rushed changes, or key-person dependence remain possible.
Evidence (6)

strengths

two sources

Orca DEX’s top strengths are its simple, beginner-friendly interface, fast and low-cost trading on Solana, Whirlpools concentrated-liquidity design, strong capital efficiency for LPs, and broad ecosystem maturity/integration. CoinBureau highlights Orca’s clean swap UX, non-custodial Solana trading, and strong concentrated-liquidity tools, while Ju.com and OKX emphasize its user-first design, sub-second execution, and very low fees on Solana.

  • User-friendly UX: Orca is repeatedly described as clean, intuitive, and beginner-friendly, with a polished swap flow that lowers the barrier to entry for new DeFi users.
  • Fast, low-cost execution: Because it runs on Solana, Orca benefits from near-instant confirmations and very low transaction costs, making frequent trading practical.
  • Whirlpools / concentrated liquidity: Orca’s flagship pool design is its key technical strength, allowing liquidity to be placed in tighter price ranges for better execution and higher efficiency.
  • Capital efficiency for LPs: Concentrated liquidity is specifically cited as improving yield potential and liquidity utilization versus traditional AMMs.
  • Mature Solana ecosystem position: Orca is described as an established Solana DEX with pool creation, LP incentives, governance, and developer integrations, which supports durability beyond simple swaps.
Evidence (7)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 17 one source, 12 unverified.
  • Oldest fact verification date: 2026-08-29.