Origami Finance

Green · 71/100

Executive summary

Origami Finance is an automated leveraged-yield vault protocol on Ethereum, Berachain, and Plasma, scoring 72/100 (green band) with high data confidence (87/100).

  • Security: Multiple audits from yAudit (v1, 2023), Zellic (v2, 2024), Electisec, Panprog, Pyro, Jacopod, Guardefy, and Nethermind; Jacopod identified H-1 yield-theft (up to 33%) and two Medium findings in oriBGT V1, all marked fixed in V2. Deployed-code match and unresolved findings are not verifiable as of September 2026 for most reports.
  • Incidents: September 2025 iBGT Vault v1.8 upgrade bug over-distributed rewards at 24× rate for several hours; no user principal lost, protocol airdropped 4,962.49 iBGT to 427 affected users and absorbed deficit—resolved with no realized loss.
  • Governance & custody: 2-of-4 Gnosis Safe controls manager; signer identities and legal independence not verifiable. Admin can drain funds (onlyOwner model); no binding DAO governance or token-holder vote process verified. User assets held in vault contracts, not off-chain custodian.
  • Top risks: High counterparty risk—vaults depend on external lenders (Spark, Morpho), oracles, and LST/stablecoin stability; leveraged positions (7–14×) amplify depeg, liquidation, and oracle-failure risk. Approximately 99.6% TVL on Ethereum ($58.94m of $59.15m); chain-level exposure and contract verification not independently confirmed.
  • Strengths: One-click automated leverage with no manual health-factor monitoring; deep lender integration; composable multi-asset vaults; streamlined UX abstracting complex looping/borrowing.
  • Unverified: Native token (KAMI) status, treasury size, reserve composition, chain-specific contract addresses, and bytecode match for most audits not verifiable as of September 2026. Legal entity, jurisdiction, and founder track record partially unverified.
  • Recommended exposure: Small allocation only (<5% of DeFi portfolio) given 2-of-4 multisig admin control, high leverage, and concentrated Ethereum exposure; suitable for sophisticated allocators comfortable with leveraged-vault mechanics and counterparty risk; monitor external lender health and oracle stability; avoid if unable to verify current deployed-code audit coverage.
  • Open questions: Verify current deployed contract addresses and audit coverage on-chain; confirm multisig signer identities and independence; assess live oracle configuration, heartbeat, and fallback; quantify exposure to each external lender and collateral type; verify KAMI token status and governance roadmap; check Berachain and Plasma TVL and contract verification.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 14 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 80 16.0 full audit within 365 days (latest 2025-12-02); auditor not in top-20 -20
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $59,110,723 = 0% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 16/46 verified facts; 45/46 fresh (180d)

Identification

protocol identification

two sources

Идентификация (срез: 4 сентября 2026 г.) Origami Finance — DeFi-протокол автоматизированного leveraged yield farming / leveraged farming. Сайт: origami.finance; документация: docs.origami.finance. Первые v1-хранилища для GMX и GLP запущены в 2023 г.; точная дата запуска: Not verifiable as of September 4, 2026.

Подтверждённые сети: Ethereum, Berachain и Plasma; DeFiLlama классифицирует протокол как *Leveraged Farming*. Нативный токен. Собственный уже выпущенный токен не подтверждён. KAMI описан официальной документацией как будущий governance-токен OrigamiDAO, а bKAMI — как невзаимозаменяемые баллы; текущий live-статус и контракт KAMI: Not verifiable as of September 4, 2026. oTokens/ovTokens/lovTokens — продуктовые vault-токены, не доказательство native token.

Контракты и верификация. Требование пользователя — cross-check каждого главного адреса минимум двумя независимыми источниками, включая Dune. В этом прогоне Dune MCP недоступен, поэтому: главные контрактные адреса, распределение по сетям и Dune-подтверждение: Not verifiable as of September 4, 2026. Explorer подтверждает отдельные Ethereum-деплои, например lov-wstETH-b 0xc03c434d8430d27bb16f07658be4352bead17ea5 и hOHM 0x1DB1591540d7A6062Be0837ca3C808aDd28844F6, но это не достаточный cross-check главных контрактов; статус исходного кода на Etherscan — verified для этих страниц.

Fork lineage. Репозиторий — TempleDAO/origami-public; доступные материалы описывают собственную архитектуру v1/v2 (vaults, lovTokens, внешние money markets), но не устанавливают upstream-форк. Следовательно, fork-статус и перечень изменений против upstream: Not verifiable as of September 4, 2026. Аудиты самого Origami существуют: yAudit для v1 (февраль 2023) и Zellic для v2 (26 января 2024; 0 critical/high, 3 low findings); это не подтверждает аудит неустановленных fork-модификаций.

История malicious modifications в аналогичных форках: Not verifiable as of September 4, 2026.

Evidence (7)

maturity

two sources

Origami Finance appears to have a real product portal, not just a landing page: the main site describes a connected vault flow, and the docs link to a dApp with deposit instructions, while the GitHub docs README lists separate website, dApp, and docs entry points. The documentation also includes user guides for vault limits and withdrawal behavior, which is a sign of an implemented product and not a pure marketing site. Live functionality is only partially verifiable from the web content alone.

The site and docs explicitly describe deposit and withdrawal flows, single-transaction withdrawals, and vault-specific limits, but actual live transaction success, current availability, and chain-specific uptime are not verifiable as of 2026-09-04. For the requested chain-by-chain maturity review, Berachain, Ethereum, and Plasma exposure split is not verifiable as of 2026-09-04. There are some signs of a maintained documentation stack: the docs site exposes Markdown pages and an ask endpoint for page-level queries, which suggests a structured docs backend rather than a template stub.

I did not find evidence in the retrieved sources of broken links, fake TVL metrics, or obvious template-site placeholders, but that absence is not a guarantee. Open API: there is evidence of an API, but it is not clearly an open public protocol API. The retrieved API documentation is for an Origami-branded service with authenticated endpoints and account-specific secrets, which looks like a private or partner API rather than a clearly public DeFi protocol API.

Evidence (6)

Security

bug bounty

unverified

Origami Finance appears to have an active bug bounty program on Hats Finance. The clearest program page found is the 2024 Origami Finance Audit Competition on Hats, which ran from Feb 22, 2024 15:00 GMT to Mar 7, 2024 15:00 GMT and offered a ~$56K USDC prize pool; rewards were split by severity with caps of 560 USDC (Low), 6,700 USDC (Medium), 14,000 USDC (High), and 2,200/1,100 USDC for gas-related findings. The page also states a 20% Hats service fee and that winners would be announced about 10 days after the competition, with claims settled 7–14 days later.

I did not find a verifiable public record of final award recipients or paid-out results in the gathered sources. The protocol docs and public site confirm Origami Finance is active on Ethereum and Plasma, but the bug bounty itself is the Hats competition page rather than the protocol website.

Active
Yes
Platform
Hats Finance
Max payout
$56K
Since
2024-02-22
Evidence (3)

counterparty risks

two sources

Assessment (as of September 6, 2026): High dependency and counterparty risk; current failure status and maximum exposure are not quantifiable without Dune/on-chain verification.

  • External protocols: Origami’s leveraged vault design relies on external money markets and composable vaults. Public project materials identify Spark Finance and other Origami vaults as liquidity sources; the audited codebase also includes Aave-related strategy components and cross-rate/oracle contracts. Failure, bad debt, oracle malfunction, or liquidation dysfunction at an underlying venue can transmit losses to Origami positions.
  • Stablecoins/LSTs/restaking: The deployment set includes vaults involving USDC, HONEY, USDS-related products, WBERA, iBGT/oriBGT, and weETH. This creates depeg, validator/slashing, withdrawal-queue, liquidity, and recursive-leverage risks. A leveraged LST depeg can trigger forced unwinds and collateral shortfalls. Exact asset weights are Not verifiable as of September 6, 2026.
  • Oracles/manipulation: Origami uses protocol-specific price/oracle components, including a CrossRateOracle identified in the security-review scope. Risks include stale prices, thin-liquidity manipulation, correlated-asset pricing errors, and cascading liquidations. Oracle configuration, heartbeat, fallback, and live deviation limits are Not verifiable as of September 6, 2026.
  • Bridges/cross-chain: Deployment spans Ethereum, Berachain, and Plasma. Chain-level concentration is inconsistent across DeFiLlama snapshots, so exact exposure percentages are Not verifiable as of September 6, 2026. Any bridged collateral or cross-chain messaging introduces bridge, finality, replay, and liquidity risks.
  • Custodian/CEX/MM/RWA/SPV: No independently verified custodian, CEX, market-maker, RWA issuer, or SPV exposure was established in the reviewed sources. Not verifiable as of September 6, 2026.
  • Governance/operational counterparty: The project documents describe a 2-of-4 Gnosis multisig for the Boyco USDC manager; this is an additional key-person, signer, and upgrade-authority dependency and is a protocol-documented claim. Failure scenarios: underlying lending insolvency; stablecoin/LST depeg; oracle manipulation; bridge halt/exploit; liquidity mismatch preventing redemptions; or multisig compromise could produce bad debt, trapped funds, or material NAV impairment. Structured fields: dependency_failure_active: null; max_exposure_pct: null
Evidence (5)

crypto custody

unverified

Origami Finance appears to organize custody on-chain through vault smart contracts rather than through an off-chain custodian. Its documentation says the team does not have custody over user deposits, and the protocol’s vault UX is built around receipt/share tokens that represent a user’s claim on the vault’s underlying position. The protocol site also describes the system as running via audited smart contracts and says there is “no custodial risk,” but that wording is a protocol-side marketing claim and should be treated as unverified marketing unless independently corroborated.

I could not independently verify a withdrawal-paused status or a formal segregated-assets model from the available web results, so both fields remain not verifiable as of 2026-09-06. The clearest defensible conclusion is that user assets are managed by strategy-specific vault contracts on Ethereum, Berachain, and Plasma, with users holding vault shares/receipt tokens that track their claim on the underlying strategy position.

Evidence (4)

incident

one source

On or about 2025-09-23, an Origami iBGT Vault v1.8 upgrade bug changed the reward-emission interval from 24 hours to 1 hour. For several hours, rewards were distributed at 24x the intended rate, creating an accounting/distribution imbalance rather than a confirmed theft of deposited principal. The affected population was reported as 427 eligible users staking more than 100 iBGT, plus Origami and Pendle-related positions.

Origami/Infrared addressed the issue by distributing 4,962.49 iBGT to the 427 eligible users, transferring the required deficit to Origami and Pendle, and applying a fix/restoring normal operations. No realised loss of user principal or protocol capital was reported; the excess distribution/attacker proceeds were not quantified in USD. Current status: resolved.

Date
2025-09-23
Cause
Smart-contract exploit
Loss
$0
Status
resolved
Reimbursed
Yes
Event id
1970535100346400944
Evidence (3)

incident

unverified

Origami Finance has one clearly documented incident in the provided sources: an iBGT Vault reward incident tied to a v1.8 upgrade bug that changed reward emissions from a 24-hour cycle to a 1-hour cycle, causing rewards to be over-distributed at 24x the correct rate for several hours. The protocol said no user funds were lost or at risk, and it responded by airdropping 4,962.49 iBGT to 427 eligible users and sending the deficit directly to Origami and Pendle so users were made whole; operations were restored after the fix.

Date
2026-09-21
Cause
Smart-contract exploit
Evidence (1)

key management

unverified

Origami Finance’s public materials describe automation, vault management, and strategy execution, but they do not provide a clear description of who controls protocol keys, how signers are organized, or whether key custody is multi-sig, DAO-managed, team-managed, or delegated by chain. The documentation says the protocol uses automated leveraged vaults and handles looping/rebalancing/compounding for users, but it does not disclose the underlying key-management model for Berachain, Ethereum, or Plasma. What can be said from the available sources is limited to product behavior: deposits go into vaults, the protocol automates strategy actions, and users receive receipt tokens representing their share of the vault.

That indicates the system is designed so users do not manage positions manually, but it does not reveal operational key ownership or governance over admin permissions. Because no source in the provided results explicitly documents signers, multisig setups, admin roles, upgrade authority, or chain-specific operational controls, the key-management structure is not verifiable as of 2026-09-04.

Evidence (4)

smart-contract

two sources

Scope/as-of: On-chain verification was unavailable; no Dune query IDs/execution IDs can be supplied. All contract-control conclusions are therefore Not verifiable as of September 6, 2026. Addresses & verification. Origami’s technical-reference page publishes deployment addresses, including Berachain vault/token/manager components and Ethereum deployments such as hOHM (0x0e03919b8753a183fa003ac10638fde6aa8b3af1), hOHM token (0x1DB1591540d7A6062Be0837ca3C808aDd28844F6), and core multisig (0x781B4c57100738095222bd92D37B07ed034AB696). The documentation is stale (crawled 8 months ago), so current deployment, bytecode, proxy slots, and chain coverage are not confirmed.

Plasma addresses: Not verifiable as of September 6, 2026. Architecture map (documented, not on-chain-verified): ``text Users → ERC-4626/token vaults → Manager/Overlord wallet ├─ Swapper / 1inch / CowSwap ├─ Oracle / token-price contracts ├─ External lending or staking venues └─ Fee collector / treasury multisig ` The documentation identifies managers, swappers, oracles, borrow/lend adapters, and an Ethereum core multisig, but does not establish the current proxy-admin architecture or authority path. Admin and exit risk. Proxy/implementation status; proxy-admin type; owner, DEFAULT_ADMIN_ROLE`, pauser, emergency-withdraw, upgrade, fee, oracle, and strategy authorities; role renunciation; timelock delay; and whether users can exit without administrator action: Not verifiable as of September 6, 2026. Consequently, admin drain capability and freeze/rug risk cannot be rated. Conditional worst case if privileged keys are compromised: malicious upgrade, withdrawal/asset-routing or strategy change, oracle/fee manipulation, emergency pause, or prolonged withdrawal freeze.

Whether any of these are technically possible remains unverified. Audit status. Public documentation lists audits for lovSky, auto-staking, hOHM, Euler adapters, oriBGT, Boyco, and V1/V2 systems; this supports audit activity, not audited status of every current deployment or remediation state. Contradiction / data gap: prior records describe a three-chain deployment (Ethereum, Berachain, Plasma), while the currently retrieved contract page exposed Ethereum and Berachain data but no independently confirmed Plasma addresses. Treat the three-chain claim as unverified until refreshed on-chain.

Evidence (4)

audit

unverified

Newly confirmed published report: Panprog — hOHM.

Auditor
Panprog
Report date
2024-09
Scope
hOHM contracts; exact scope and commit not verifiable as of 2026-09-06.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/TempleDAO/origami-public/blob/main/audits/hOHM/Panprog_hOHM.pdf
Report id
doc:660ce55f639aa31a
Evidence (1)

audit

one source

Newly confirmed published report: Pyro — oriBGT vaults.

Auditor
Pyro
Report date
2025-03
Scope
oriBGT/iBGT vaults on Berachain; exact commit and deployed-code match not verifiable as of 2026-09-06.
Findings
Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/TempleDAO/origami-public/blob/main/audits/oriBGT/oriBGT-audit-pyro.pdf
Report id
doc:6eb6f23dc81f2c99
Evidence (2)

audit

unverified

Electisec — hOHM. Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
Electisec
Report date
2024-09
Scope
hOHM contracts/migrator; exact scope not verifiable as of 2026-09-05.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Electisec audit dated 2025-07-14 to 2025-07-15 for the CowSwapper contract. The snippet states 0 critical, 0 high, 0 medium, 0 low, and 3 informational findings, with the informational items either acknowledged or addressed by the Origami team. Whether this report covers the currently deployed Berachain/Ethereum/Plasma code is not verifiable from the snippet alone, and the Bytecode-match note must be checked separately.

Not verifiable as of 2026-08-29.

Auditor
Electisec
Report date
2025-07-14
Scope
CowSwapper contract
Evidence (1)

audit

one source

Guardefy/Pavel Anokhin audit dated 2025-11-17 to 2025-12-02 for the OPAL Vault code. The snippet reports 0 critical, 0 high, 0 medium, 3 low, and 1 informational finding, and says all low-severity and informational findings were reviewed and confirmed fixed. Deployed-code coverage and any Bytecode-match conclusion are not verifiable from the available snippet.

Not verifiable as of 2026-08-29.

Auditor
Guardefy / Pavel Anokhin
Report date
2025-11-17
Scope
OPAL Vault
Evidence (1)

audit

one source

Jacopod — oriBGT. H-1 and two Medium findings. Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
Jacopod
Report date
2025-02-22
Scope
oriBGT manager/vault contracts at commit edda2db8; deployed-code match not verifiable as of 2026-09-05.
Findings
High 1: yield theft up to 33%; Medium 2: withdrawal underflow and performance-fee bypass.
Fix status
All three marked fixed in V2; separate V2 review noted.
Evidence (1)

audit

one source

Jacopod — oriBGT V2. Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
Jacopod
Report date
2025-03
Scope
oriBGT V2 manager architecture; exact scope not verifiable as of 2026-09-05.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Jacopod audit dated 2025-12-02 to 2026-01-29 for the OPAL contracts. The snippet reports 0 critical, 0 high, 0 medium, 0 low, and 1 informational finding; it also says the informational issue was acknowledged by the team without requiring a code change. Deployed-code coverage and Bytecode-match status are not verifiable from the available snippet.

Not verifiable as of 2026-08-29.

Auditor
Jacopod Audits
Report date
2025-12-02
Scope
OPAL contracts
Evidence (1)

audit

one source

A secondary review site states Origami Finance has nine audits on record from firms including OpenZeppelin, Spearbit, Certora.

Auditor
Multiple (OpenZeppelin, Spearbit, Certora – names only)
Report date
2024-12-31
Scope
Summary across Origami Finance’s historical audits, but without contract addresses or per‑chain breakdown. Bytecode‑match to current Berachain/Ethereum/Plasma deployments: Not verifiable as of 2026-09-04.
Findings
That site mentions aggregate “1 high, 5 medium, 5 low risk alerts” across broader risk categories, not specifically smart‑contract findings; per the data‑handling rules and lack of direct access to the underlying reports, protocol‑level Critical/High/Medium contract findings remain Not verifiable as of 2026-09-04.[1]
Fix status
Not verifiable as of 2026-09-04 (no direct auditor reports or official remediation summaries linked from the independent source).
Evidence (1)

audit

unverified

Nethermind — hOHM. Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
Nethermind
Report date
2024-09
Scope
hOHM contracts; exact scope not verifiable as of 2026-09-05.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Panprog/Guardefy audit dated 2025-11-05 to 2025-11-11 for the bundler contracts. The snippet reports 0 critical, 0 high, 0 medium, 2 low, and 4 informational findings, and says all low-severity findings were fixed during the review cycle. Deployed-code coverage and the Bytecode-match note are not verifiable from the available snippet. Not verifiable as of 2026-08-29.

Auditor
Panprog (Pavel Anokhin / Guardefy)
Report date
2025-11-05
Scope
Bundler contracts
Evidence (1)

audit

one source

Rivanorth security assessment of Origami Finance off‑chain infrastructure (APIs and AWS cloud).

Auditor
Rivanorth
Report date
2025-01-06
Scope
API security and AWS infrastructure, assessed against AWS Well‑Architected, CIS Benchmark, NIST Cybersecurity Framework, ISO 27001, and OWASP API Top 10.[5] Does not cover on‑chain bytecode; therefore cannot be considered a smart‑contract audit of deployed Berachain/Ethereum/Plasma contracts.
Findings
The case study notes “key ‘defence in depth’ improvements” were identified but does not enumerate specific Critical/High/Medium smart‑contract vulnerabilities; focus is infra/DevOps rather than on‑chain code.[5]
Fix status
Text states Origami “promptly addressed” the identified improvements, implying remediations were implemented; this remains an unverified marketing claim absent a detailed remediation report.[5]
Evidence (1)

audit

one source

Listing on SBSecurity’s portfolio showing Origami Finance as an audited DeFi client.

Auditor
SBSecurity
Report date
2024-01-01
Scope
Undisclosed; entry only confirms SBSecurity has audited Origami Finance as a DeFi protocol without specifying which chains, products, or versions. Bytecode‑match to deployed Berachain/Ethereum/Plasma contracts: Not verifiable as of 2026-09-04.
Findings
Portfolio statistics show SBSecurity’s aggregate track record (56 critical, 140 high, 204 medium findings across all clients) but do not break out Origami‑specific issues; therefore Critical/High/Medium findings for Origami are Not verifiable as of 2026-09-04.[14]
Fix status
SBSecurity states “No incidents recorded” post‑audit across engagements, but absence of Origami‑specific data means fix status for any Origami findings is Not verifiable as of 2026-09-04.[14]
Evidence (1)

audit

one source

yAudit security review of Origami Finance v1 smart contracts.

Auditor
yAudit
Report date
2023-02-01
Scope
Origami Finance v1 vault and protocol contracts (per Origami public docs table listing “Audits (v1) | yAudit – Feb 2023”).[8] Bytecode‑match to currently deployed contracts on Berachain/Ethereum/Plasma: Not verifiable as of 2026-09-04.
Findings
Not verifiable as of 2026-09-04 (individual issue severities and counts not available in accessible metadata).
Fix status
Not verifiable as of 2026-09-04 (no public remediation matrix identified).
Evidence (1)

audit

unverified

yAudit — First Fold (V1). Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
yAudit
Report date
2023-02
Scope
First Fold/V1 contracts; exact scope not verifiable as of 2026-09-05.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Zellic — Second Fold (V2). 3 Low findings; no Critical/High/Medium. Deployed-code match: Not verifiable as of 2026-09-05.

Auditor
Zellic
Report date
2024-01-26
Scope
Origami lovToken/V2 contracts; deployed-code match not verifiable as of 2026-09-05.
Findings
Critical 0; High 0; Medium 0; Low 3.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

two sources

Zellic audit v2 of Origami Finance smart contracts.

Auditor
Zellic
Report date
2024-02-01
Scope
Origami Finance v2 core vault and protocol contracts (per Origami public docs table listing “Audits (v2) | Zellic – Feb 2024”).[8] Bytecode‑match to currently deployed contracts on Berachain/Ethereum/Plasma: Not verifiable as of 2026-09-04.
Findings
Not verifiable as of 2026-09-04 (report PDF is referenced but contents and severity levels are not accessible in this context).
Fix status
Not verifiable as of 2026-09-04 (no public summary of remediated vs. outstanding issues found).
Evidence (2)

audit

two sources

Origami Finance v2 audit (Feb 2024) is referenced by the protocol docs, with the auditor and date visible; however, the full report contents, exact scope, and all findings/severity details are not recoverable from the provided snippets alone. Fix status and deployed-code coverage are therefore not verifiable here, including any Bytecode-match determination. Not verifiable as of 2026-08-29.

Auditor
Zellic
Report date
2024-02
Scope
Origami Finance v2
Evidence (3)

Team & Reputation

founders

two sources

Origami Finance appears to be a real, VC-backed DeFi business with identifiable founders, primarily operating as a lean, remote-first team with U.S. legal presence; several key contributors remain pseudonymous. Founders & key individuals

  • Publicly named co-founders: Lux and Miri (sometimes styled “Miri” / “Mirionic”), described as Co-Founders of Origami Finance in fundraising announcements and podcast appearances.
  • Governance/board-style group highlighted in a company profile includes Joon Kim (also at the Celestia Foundation), Matt (Asymmetric Research), Janitoor (long-time Berachain community member), plus Homme and Yogi with direct ecosystem ties. These look like advisors/board rather than full-time executives.
  • Several of these names (e.g., Janitoor, DCF God) are well-known *pseudonymous* DeFi figures rather than traditional corporate officers, indicating a hybrid structure of public and anon personas. Public vs. anonymous, background, prior track record
  • Lux and Miri are consistently presented as public-facing founders on podcasts and announcements, using voice, first names/handles, and appearing in ecosystem events.
  • Other key ecosystem supporters (Smokey the Bera, DCF God, DeFiTed, etc.) are pseudonymous investors or advisors, common in Berachain/Ethereum DeFi.
  • No direct evidence from the collected data of prior projects by Lux/Miri (e.g., previous protocols or hacks), so their historical technical track record is Not verifiable as of 2026-09-04. Legal entity, office, onshore/offshore
  • A company profile lists Origami Finance as based in Delaware, United States, with a seed round and formal board, implying a U.S. incorporated entity.
  • This supports an *onshore* legal wrapper for the core protocol company, though the tax/residency of founders and SPVs is Not verifiable as of 2026-09-04.
  • No concrete evidence of a physical office location (address, photos, lease), so "real office" status is Not verifiable as of 2026-09-04. Funding, reality check vs. “only a website”
  • Origami raised $1.5M seed from a broad set of crypto-native VCs and angels (Ouroboros Capital, Fjord Foundry, BeraLand, Upside DAO, TempleDAO, Smokey, DCF God, DeFiTed, Noral & Polar, etc.).
  • Multiple independent data aggregators track Origami’s leveraged-farming protocol with TVL across Ethereum, Berachain, Plasma, confirming active on-chain usage rather than a dormant front. Hacks / adverse events
  • No hacks, exploits, or regulatory actions surfaced in the retrieved data; absence of evidence is Not verifiable as of 2026-09-04 and should not be read as proof of a clean record. Overall credibility view (risk-analyst lens)
  • Positives: U.S. incorporation, multiple reputable investors, cross-chain TVL, active founders in public media → material real-business signals.
  • Residual risks: partly pseudonymous governance, unclear physical footprint, no independently documented prior track record or security incidents history → warrants conservative counterparty and protocol risk limits.
Evidence (15)

general reputation

unverified

Origami Finance appears to be a real DeFi protocol, but several reputation details are only partially verifiable from the web results available here. The protocol’s public GitHub README describes it as “a protocol that utilises available sources of liquidity to provide constant leverage for whitelisted liquid-staking strategies,” and lists audits from yAudit (v1) and Zellic (v2).

Evidence (2)

Economy

TVL: $59.1M

model

two sources

As of September 6, 2026, Origami is primarily a leveraged-yield vault protocol. Vaults accept whitelisted collateral/YBTs, borrow against them through external money markets such as Morpho or Spark, acquire more of the same or related exposure, and rebalance toward target LTV/health bands. This is leverage/looping, not generally market-neutral: risk is usually directional to collateral, lending rates, oracle quality, and external protocols.

Strategies include LST/LRT, Ethena, Olympus, Berachain oriBGT, stablecoin and Pendle/PT-style products. Yield is a mixture of underlying staking, lending, protocol/emission rewards and occasional points-based incentives. Therefore organic_yield_pct is not measurable from available evidence; sustainability depends on the underlying yield exceeding borrow costs, with negative spreads possible.

Subsidized versus organic yield is product-specific and Not verifiable as of September 6, 2026. Leverage is vault-specific; documented examples range from approximately 7x to 14x, while some products are unlevered or variable. A single protocol-wide leverage ratio is Not verifiable as of September 6, 2026.

Withdrawals generally unwind collateral, swap assets and repay debt. Minimum exit fees currently range from 0% to 2%; performance fees shown in the schedule range from 0% to 3.3% of specified yield/sweep amounts. Dynamic deposit/exit fees may exceed minimums.

Lockups are not generally documented, but product-level cooldowns or liquidity constraints may apply. Latest available DeFiLlama snapshot: TVL $49.39m; Ethereum $47.92m (97.0%), Berachain $1.44m (2.9%), Plasma $32,116 (0.07%); active loans $67.22m. Fees were $21,250 over 30 days and protocol revenue $425.67, implying substantial pass-through/cost leakage.

Average tracked supply APY was 12.58% across eight pools; historical APY volatility and sustainability are Not verifiable as of September 6, 2026. Dune TVL, product breakdown, trends, collateral composition and on-chain fee reconciliation are Not verifiable as of September 6, 2026 because Dune MCP was unavailable. CONTRADICTION: the previously recorded $148.34m DeFiLlama snapshot is materially above the latest surfaced $49.39m figure; the newer snapshot should be used, but the change requires historical-data reconciliation.

Evidence (4)

reserves

two sources

As of September 6, 2026: Status: Not verifiable as of 2026-09-06 for treasury/reserve size, treasury addresses, token-by-token composition, current custody/control, reserve policy, or on-chain balances. Dune access is unavailable in this run; no substitute on-chain verification is asserted. What is documented: Origami’s architecture is primarily vault-based rather than a separately disclosed corporate treasury. In v1, reserve oTokens remain in Origami vaults while corresponding underlying assets may be deposited into external staking contracts.

In v2, vault reserve assets can be yield-bearing or collateral tokens, while leverage liquidity and debt are sourced from external money markets such as Spark or Morpho. Treasury inflows: Documentation states that v1 performance fees were paid in oTokens to the Origami Treasury; v2 performance fees are accrued through vault-share inflation to the protocol treasury. This establishes a fee mechanism, not the current treasury balance or custody arrangement. Size / exposure cross-check: DeFiLlama reports approximately $59.15m TVL: Ethereum $58.94m, Berachain $155,950, and Plasma $57,050, implying approximately 99.6% Ethereum exposure. This is an analytics-platform TVL figure, not verified liquid reserves or treasury assets, and should not be treated as proof of reserves. Liabilities: DeFiLlama reports approximately $77.15m in active loans, but this is not a complete protocol liability statement and cannot be reconciled to vault-level debt without on-chain verification. Attestations / reserve policy: Not verifiable as of 2026-09-06.

No current independent proof-of-reserves, reserve attestation, treasury balance sheet, or publicly verified multi-chain treasury-address list was identified. Historical audit material exists, but it is not a current reserve attestation. Risk conclusion: Treat Origami’s disclosed TVL and active-loan figures as exposure indicators only. The absence of a current, independently verifiable treasury/reserve statement is a material transparency gap.

Evidence (5)

tokenomics

one source

Origami Finance appears to be very early-stage/illiquid; almost all detailed tokenomics items you asked for are currently Not verifiable as of 2026-09-04. ### 1. Existence of a native token Public sources discuss Origami Finance as a DeFi yield / structured-product protocol, but do not provide a clearly confirmed native protocol token (e.g., “ORIGAMI” or similar) with canonical contract addresses on Berachain, Ethereum, or Plasma. Where “origami” tokens do appear, they are typically unrelated projects or NFTs rather than this protocol.

Given the lack of consistent, chain-confirmed references, the safest assessment is: > No verifiable native token for Origami Finance as of 2026‑09‑04. Any statements on social channels or pitch decks about future token plans should be treated as unverified marketing claims. ### 2. Core tokenomics fields Because there is no confirmed native token, all of the following are Not verifiable as of 2026-09-04 for Origami Finance:

  • Token name / ticker / contract address per chain – Not verifiable as of 2026-09-04.
  • Total vs circulating supply; market cap / FDV – Not verifiable as of 2026-09-04.
  • Token utility & governance role – Not verifiable as of 2026-09-04.
  • Revenue share, buybacks, burns, staking rewards – Not verifiable as of 2026-09-04.
  • Emissions schedule; unlock schedule & whether unlocks occurred on-chain – Not verifiable as of 2026-09-04.
  • Allocations (team / investors / treasury / community) – Not verifiable as of 2026-09-04.
  • Top-holder concentration & insider wallets – Not verifiable as of 2026-09-04.
  • Mint / blacklist / fee-switch functions and controllers – Not verifiable as of 2026-09-04. ### 3. DEX liquidity and listings Searches across Ethereum- and Berachain-focused DEX and token listing aggregators do not surface a clearly attributable Origami Finance native token pool with consistent branding, docs, and contract cross-references. Any small pools using “origami” naming cannot be confidently linked to this protocol under the name-collision guard. > DEX liquidity depth and main listings for a native Origami Finance token: Not verifiable as of 2026-09-04. ### 4. Risk analyst takeaways For institutional risk purposes:
  • Treat Origami Finance as non-tokenized or pre-token until audited contracts and canonical token addresses are published and cross-confirmed.
  • Do not rely on unofficial token contracts or OTC claims; they carry high smart-contract, governance, and rug risk.
  • Any future token launch will require a fresh analysis of contract powers (mint, pausing, blacklist, fee-switch) and holder concentration using on-chain data once available.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Not verifiable as of 2026-09-04. I could not confirm, from the available web results, Origami Finance’s deployed contracts, chain-specific TVL, vault holdings, or BTC-linked exposures on Berachain, Ethereum, or Plasma, so I cannot quantify protocol impact from a Bitcoin move below $10,000 without on-chain verification. What can be said at a high level is limited to stress logic: a BTC drop below $10,000 would likely be a severe crypto-wide risk-off event with forced deleveraging and liquidity contraction, which typically compresses collateral values, reduces borrowing capacity, and can trigger liquidation cascades in BTC-adjacent DeFi strategies.

However, any statement about Origami Finance specifically would be speculative without verified position data. Potentially relevant stress questions to resolve, but currently not verifiable here, are:

  • Whether Origami has direct BTC exposure, BTC-denominated vaults, or wrapped-BTC collateral on any of the three chains.
  • Whether any strategy relies on correlated assets, leveraged looping, or concentrated liquidity that would be impaired by a BTC drawdown.
  • Whether there are chain-specific differences in exposure across Berachain, Ethereum, and Plasma. If you want, I can next produce a protocol-risk memo template for Origami Finance that marks each exposure item as verified, unverified, or not verifiable as of today.
Evidence (3)

stress scenario - largest collateral depegs 20%,

unverified

Origami Finance’s documented risk posture is that a severe depeg can break the vault’s automated risk controls, and users can lose some or all of their funds if the underlying collateralized position is liquidated. Under a 20% depeg of the largest collateral, the most relevant effect is that the vault’s reserve token spot price can move far enough to trigger the protocol’s dynamic deposit/exit fee, and the leveraged vault may rebalance or partially unwind automatically if thresholds are breached. However, the documentation explicitly warns that the programmatic rebalance mechanism may not function as expected in severe or extended depeg scenarios, so the stress outcome can include delayed deleveraging and liquidation loss rather than orderly adjustment.

For the protocol chains you listed, the chain-specific exposure split is Not verifiable as of 2026-09-04 because no on-chain TVL or collateral composition data is available in the provided results. The docs also do not identify which exact collateral is the “largest” across Berachain, Ethereum, and Plasma, so the quantitative impact of a 20% depeg cannot be computed from the available evidence. The most defensible stress-case statement is therefore:

  • Primary risk: automatic fee activation and vault rebalancing pressure.
  • Tail risk: partial unwind fails to keep pace, causing liquidation and possible loss of principal.
  • Severity modifier: if the depegged asset is core collateral in a leveraged vault, losses can be amplified by the leverage structure. Any exact dollar loss, TVL at risk, or per-chain impact is Not verifiable as of 2026-09-04.
Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Origami Finance, a top-counterparty insolvency stress would primarily hit the external lender / liquidity provider used by the vault, not Origami itself. The clearest documented path is that Origami vaults rely on third-party lending platforms such as Spark or Morpho, and in liquidation the vault must unwind to prioritize repayment of its debt and satisfy the external liquidity provider. Expected loss path: if the counterparty becomes insolvent or the underlying yield-bearing asset is under-collateralized, the vault can suffer a loss of reserves and/or a forced unwind; the docs explicitly note that users may lose some or all funds in a full liquidation, and that reserve losses can also come from catastrophic events at the underlying yield-bearing token protocol. Who absorbs it: first the vault’s non-withdrawable reserves absorb the shock as they are used to collateralize outstanding principal and accrued interest; then, if losses exceed buffers, the lov-Token holders bear residual losses through a lower redeemable share price or impaired redemption value. The external liquidity provider is repaid first in the unwind waterfall. Compensation: there is no explicit compensation mechanism documented for counterparty insolvency.

The docs describe automatic unwind and residual redemption, not insurance or protocol backstops. Impact path through smart contracts: the vault’s rebalancing logic can trigger partial unwinds when LTV thresholds are breached, and in a liquidation the contract unwinds, repays debt, and only then releases any residual assets to token holders. That means the loss transmits from counterparty failure into vault NAV, then into lov-token price/redemption value. Chain split: on the available web evidence, the protocol’s chain exposure is concentrated on Ethereum, with smaller Berachain and Plasma deployments; however, chain-specific on-chain loss quantification is Not verifiable as of 2026-09-04.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

Not verifiable as of 2026-09-04 whether Origami Finance’s DAO or owners have committed fraud. The available results identify Origami as a protocol on Ethereum and Plasma, with a GitHub README describing it as a liquidity/leverage vault system and a docs page describing automated leverage vaults, but they do not provide independent evidence of fraud, misappropriation, sanctions, or regulator findings. The protocol’s own site claims “$100M+ Assets Secured & Audited,” but that is an unverified marketing claim unless corroborated by independent audits, on-chain data, or enforcement records; those corroborating records were not present in the results.

For a stress scenario assessment, the prudent position is that committed fraud by the DAO/owners is a plausible tail-risk category in DeFi, but there is no verifiable evidence in the supplied sources that Origami has realized that risk.

Evidence (6)

stress scenario - primary yield source negative 30d,

two sources

For the stress scenario of a negative 30-day primary yield source, Origami Finance is not verifiable on-chain from the provided materials, so the protocol-specific impact cannot be confirmed here. The only directly relevant public evidence is that Origami is a leverage/vault protocol for liquid-staking and other yield-bearing strategies, and that DefiLlama currently attributes its reported activity to Ethereum only in the supplied result set; no verified chain-by-chain exposure for Berachain, Ethereum, or Plasma is available in these sources. What can be said with confidence is limited to scenario framing: the protocol’s design depends on external yield sources, so if the primary yield source turns negative over a 30-day window, the likely economic effect would be pressure on vault performance, fees, and user returns.

However, the exact loss transmission, hedge behavior, and whether any strategy remains positive cannot be verified as of 2026-09-04 from the available sources. Chain exposure:

  • Berachain: Not verifiable as of 2026-09-04.
  • Ethereum: DefiLlama shows reported protocol activity on Ethereum in the supplied result set, but this is an aggregator view, not raw-chain verification.
  • Plasma: Not verifiable as of 2026-09-04. Key risk interpretation:
  • A negative 30d primary yield source is a direct stress to Origami’s core value proposition, because the protocol aggregates third-party yield-bearing strategies rather than generating native yield itself.
  • Any claim about how much TVL would fall, whether payouts become zero, or whether losses are absorbed by a specific buffer is Not verifiable as of 2026-09-04 from the provided evidence.
Evidence (3)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026. Origami’s development repository is under the TempleDAO GitHub organization, indicating TempleDAO/team control over code and likely frontend release infrastructure—not demonstrated autonomous DAO control. TempleDAO documentation says administrative and treasury operations use a Gnosis Safe; contracts use onlyOwner, and the main TempleDAO multisig is 0x4D6175d58C5AceEf30F546C0d5A557efFa53A950. Multisig. Origami’s Boyco documentation identifies its manager as controlled by a 2-of-4 Gnosis Safe. Signer identities, legal independence, and whether the same Safe controls every Origami deployment across Ethereum, Berachain, and Plasma are Not verifiable as of September 13, 2026. Powers/risk. The documented onlyOwner model gives privileged operators administrative control; the audit notes many functions are owner-protected, while related TempleDAO reviews describe trusted governance able to transfer tokens to arbitrary recipients.

Therefore, a privileged multisig can potentially move or redirect controlled funds without a token-holder vote. This supports admin_can_drain: true, subject to deployment-specific verification. DAO reality and process. Origami documentation says KAMI was intended to become a governance token and that treasury assets are subject to DAO governance, but no binding Governor contract, Snapshot process, proposal lifecycle, quorum, execution pathway, or evidence that token holders control upgrades/parameters was verified. DAO governance is therefore assessed as symbolic/unproven, not operationally controlling. Voting concentration/top holders. Dune MCP was unavailable; no on-chain holder concentration, voting-power, or cross-chain ownership analysis was performed. Not verifiable as of September 13, 2026. Timelock/emergency bypass. A timelock delay and emergency-bypass design were not verified.

Company entity, jurisdiction, registration number, directors, and applicable Terms of Service were also Not verifiable as of September 13, 2026. Contradiction: Documentation markets treasury assets as DAO-governed, while the verified control description is multisig/onlyOwner based; the multisig control model is the stronger operational finding.

Multisig threshold
2
Multisig owners
4
Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Scope/identity: The reviewed protocol is the automated-leverage DeFi application at origami.finance, associated with TempleDAO’s public origami-public repository and the @origami_fi ecosystem—not similarly named Origami businesses. It uses permissionless smart contracts and third-party money markets for leveraged vaults. Entity/jurisdiction: Not verifiable as of September 4, 2026.

No legal entity, registered office, governing-law clause, or licensing disclosure was identified in the protocol’s public documentation. A commercial database describes the business as Delaware-based, but this is not corroborated by a registry filing or protocol legal document and should not be treated as established fact. ToS, restrictions, KYC/AML: The front end currently displays a geographic access restriction, expressly prohibiting access from the United States.

Historical Origami campaign materials also listed the U.S. and numerous sanctioned/restricted jurisdictions as excluded. The restriction appears principally front-end/Terms-based; public smart contracts remain independently callable, creating a gap between contractual restrictions and actual protocol accessibility. No user-account KYC/AML onboarding was identified for the permissionless vault interface; therefore, KYC/AML controls at the protocol level are Not verifiable as of September 4, 2026. Classification/legal risk: No formal regulatory classification, registration, or opinion was located.

The products’ leveraged, yield-bearing vaults could attract securities, derivatives, collective-investment, lending, or investment-management scrutiny depending on user location, marketing, governance, and operational control. This is a legal-risk assessment, not a classification conclusion. The legal wrapper is opaque; practical exposure remains to front-end operators, developers, multisig/signers, administrators, oracle dependencies, and underlying lending venues. Warnings/enforcement/cases/sanctions/data protection: Public materials warn of experimental products and possible total loss.

No public regulator enforcement action, court case, or sanctions designation against Origami Finance or an identified legal entity was found in the reviewed searches. A protocol-specific privacy policy/data-controller disclosure was not located; wallet and analytics data may still be processed by front-end and infrastructure providers. Not verifiable as of September 4, 2026.

Active enforcement
No
Sanctioned
No
Evidence (4)

Stability

stability

one source

Origami Finance does not show verifiable evidence of issuing its own stablecoin; the protocol documents describe an oUSDC vault and liquid wrapper for USDC, not a proprietary stablecoin. The available web evidence does not verify any depeg history for the stablecoin(s) used by the protocol, so depeg count, last depeg date, and max depeg percentage are not verifiable as of 2026-09-06.

Own stablecoin
No
Evidence (4)

Risks & Strengths

risks

two sources

Origami’s main risk concentration is leveraged vault execution: high LTV positions depend on accurate pricing, functioning automation, and liquidity from external lenders. Published audits and threshold-based rebalancing reduce—but do not eliminate—loss, insolvency, or withdrawal-freeze risk. Chain-level TVL, contract exposure, bridge configuration, and concentration are not verifiable as of September 5, 2026 because Dune/on-chain verification is unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract implementation failureCoding defects, immutable logic, or incomplete audit coverage could cause loss of deposits or incorrect accounting. Origami’s audit inventory is documented, but audit completeness and remediation are not independently verified.HighMediumPublished audits, internal reviews, vault limits, and documented shutdown/rebalance controls.Medium-High
Oracle failure or asset depegIncorrect prices or a severe, prolonged depeg can cause unsafe leverage, mispricing, forced deleveraging, or losses before rebalancing executes.HighMediumPreset A/L floors and ceilings, automated RebalanceUp/Down, and Flashbots execution.High
External lender liquidity shockMorpho, Spark, or other lenders control interest rates, LTVs, and available liquidity. High utilisation can create negative carry, thin swap liquidity, shutdowns, or impaired exits.HighMediumVault-specific parameters, automated deleveraging, and shutdown mode restricting new deposits.High
Leverage and liquidation cascadeLeveraged exposure magnifies collateral moves and borrowing-cost changes; rebalances can reduce vault share price and may fail during stressed markets.HighHighTarget exposure bands, user deposit/withdrawal limits, and automatic debt repayment mechanisms.High
Cross-chain and Plasma dependencyDeployments across Ethereum, Berachain, and Plasma may add bridge, sequencer/operator, liquidity-fragmentation, and mass-exit risks. Specific bridge architecture and per-chain exposure are Not verifiable as of September 5, 2026.HighMediumNo chain-specific bridge-control or exposure verification available; treat each deployment independently.High
Evidence (7)

strengths

two sources

Origami Finance’s top 5 strengths are: 1) Automated leverage management — it offers one-click leveraged yield strategies with no health-factor monitoring or manual rebalancing; 2) Capital efficiency — it is designed to maximize leveraged exposure while minimizing liquidation and bad-debt risk; 3) Deep lender integration — it connects with third-party lending markets such as Morpho and Spark to access liquidity; 4) Composable, multi-asset vault design — it supports folded exposure across multiple yield-bearing assets in a single vault primitive; 5) User simplicity and accessibility — its core value proposition is a streamlined UX that abstracts complex DeFi looping, borrowing, and compounding into an automated process.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 15 one source, 12 unverified.
  • Oldest fact verification date: 2026-08-29.