Spark Savings

Green · 76/100

Executive summary

Spark Savings is a multi-chain ERC-4626 savings vault protocol offering stablecoin and ETH yield, scoring 76/100 (green band) with high data confidence (88/100).

  • Security: Eight ChainSecurity audits (2024–2026) covering vaults, intents, and withdrawal modules found zero critical/high/medium findings; one low-severity issue (unbounded interest) was resolved. Active $5M-capped Immunefi bug bounty since November 2023. Bytecode verification for deployed contracts is not verifiable as of September 2026.
  • Incidents: No direct Spark Savings losses recorded. April 2026 KelpDAO rsETH bridge incident ($292M external exploit) triggered precautionary SparkLend freezes but caused zero realized Spark Savings user loss or bad debt; status resolved.
  • Governance & custody: Non-custodial ERC-4626 vaults with user-controlled deposits. Governance is Sky/Spark SubDAO-controlled (not independent DAO); DEFAULT_ADMIN can upgrade contracts and drain vaults via operational roles (TAKER_ROLE, ALM Proxy). 24-hour timelock exists. Withdrawals depend on idle liquidity; recovery mode can coordinate exits under stress.
  • Top risks: Material allocator/counterparty exposure across DeFi, institutional credit, RWAs, and CeFi (exact venues, limits, and concentrations not verifiable). Governance-dependent yield (Sky Savings Rate) can drop to zero. Cross-chain deployments (Ethereum 76.8% TVL, Arbitrum 19.1%, five other chains) introduce bridge and oracle risks; specific controls not verifiable. Admin compromise enables upgrade attacks and liquidity drains.
  • Strengths: Institutional-scale liquidity with documented tiered loss-absorption (junior capital, surplus buffer, SKY backstop before USDS socialization). Multi-chain availability and stablecoin-focused yield without leverage. Public team (Phoenix Labs/Sky ecosystem veterans Sam MacPherson, Lucas Manuel) with MakerDAO lineage.
  • Unverified: Underlying allocation breakdown, counterparty identities, per-chain exposure limits, oracle design, and on-chain reserve composition are not verifiable as of September 2026. Marketing claims of "no slippage" and "anytime withdrawal" lack independent stress-test evidence. Legal entity structure (Panama/Cayman/BVI) and KYC enforcement scope unclear.
  • Recommended exposure: Conservative allocation (≤5% of stablecoin portfolio) given governance centralization and opaque counterparty risk. Favor Ethereum deployment (highest liquidity). Require live Dune/on-chain verification of vault solvency, idle liquidity buffers (≥10% per vault), and allocator whitelist before larger positions. Monitor Sky governance votes for rate cuts and recovery-mode triggers. Avoid if unable to verify current collateral composition and loss-waterfall mechanics.
  • Open questions: Verify on-chain: vault solvency, idle vs. deployed ratios, and exact allocator addresses per chain. Confirm legal opinion on asset segregation and recovery-mode withdrawal rights. Obtain current Credora report (latest is stale, August 2024) and third-party counterparty due diligence. Clarify admin key custody (multisig threshold, signers) and timelock scope. Test withdrawal during market stress or rate-cut scenario.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 8 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-17)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 7 1.4 TVL $1,289,174,299 = 7% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 13/33 verified facts; 33/33 fresh (180d)

Identification

protocol identification

one source

Spark Savings is a DeFi yield/savings protocol centered on ERC-4626 vaults (“Spark Savings Vaults V2”) and branded as part of Spark/Sky’s savings product line. Official docs describe the app as savings via Spark Savings Vaults and list supported networks as Ethereum, Base, Arbitrum, Gnosis, Optimism, Unichain, Avalanche, and Robinhood. The native protocol token is SPK, while the savings vault receipts are sp* tokens such as spUSDC, spUSDT, spETH, spPYUSD, and spUSDG.

The docs and third-party integrations also point to canonical contract registries (Spark Address Registry / Sky Chainlog) as the source of truth for addresses. The docs snippet explicitly shows V2 vault addresses for Ethereum, Arbitrum, Avalanche, and Robinhood Chain, but without on-chain tooling in this run I cannot independently verify those addresses against explorers or Dune, so explorer verification status is Not verifiable as of 2026-09-03. Launch timing is partially verifiable: the Arbitrum rollout was announced on 2025-03-04, so Spark Savings was live by that date on Arbitrum; exact first deployment date for the whole multi-chain product is Not verifiable as of 2026-09-03.

Fork lineage: Spark Savings is best characterized as a Sky/Maker-derived savings vault system rather than a simple code fork of an unrelated yield protocol; the docs indicate a UUPS-upgradeable SparkVault implementation and receipt-token pattern. However, whether it is a “fork” in the strict sense, what changed versus any upstream implementation, and whether those changes were audited are Not verifiable as of 2026-09-03. Malicious-modification history in similar forks is also Not verifiable as of 2026-09-03.

Evidence (5)

maturity

one source

Spark Savings appears to be a real, working product rather than a pure landing page: the docs describe an app at app.spark.finance/savings, and the integration guide exposes live deposit/withdraw flows plus contract methods for deposit, withdraw, preview, maxDeposit, and maxWithdraw. The user guides also describe visible UI elements such as vault APY, TVL, liquidity, deposit caps, and a withdrawal flow that can complete on-chain and return assets to the wallet. An independent page likewise describes Spark Savings USDC as an active stablecoin-yield product, which is consistent with the docs but is not a primary source for functionality.

I did not find evidence of broken links, fake metrics, or template/clone signs in the material reviewed; however, that is only a limited web check, so a full site-health audit is Not verifiable as of 2026-09-03. An open API does exist: the integrator docs explicitly say the Savings Data API provides live and historical vault data, and the integration docs expose smart-contract interfaces for deposits and withdrawals. That said, the exact public endpoints, authentication model, and rate limits are Not verifiable as of 2026-09-03 from the available evidence.

Evidence (5)

Security

bug bounty

two sources

Spark has an active bug bounty program managed on Immunefi. It started on 01 November 2023. The program’s critical smart-contract reward is 10% of funds directly affected, capped at $5,000,000, with a minimum critical reward of $50,000.

Web/app findings are capped at $50,000 max / $5,000 min. Reports require PoC and KYC for payout processing, and payments are denominated in USD but paid in DAI assuming 1:1 USD parity.

Active
Yes
Platform
Immunefi
Max payout
$5.0M
Since
2023-11-01
Evidence (3)

counterparty risks

two sources

Assessment date: September 5, 2026. Dune unavailable; on-chain checks skipped. > Contradiction / identity update: The prior finding that “Spark Savings” was primarily a Robinhood Crypto yield product is no longer supported. Spark’s current site presents Savings as a Spark product, “powered by Sky,” with programmatic allocation across DeFi, institutional financing, and RWA strategies.

This is an unverified marketing claim because underlying allocations and counterparties are not disclosed. Dependencies and counterparty risks

  • Core dependency: Sky ecosystem, including USDS/Savings infrastructure. Sky risk disclosures identify oracle dependency and governance-controlled Savings Rate variability; a governance, oracle, or USDS impairment could reduce yield or impair withdrawals.
  • External protocols/markets: Spark states that capital may be allocated across multiple credit markets, liquidity venues, institutional financing, and RWA strategies, and supports USDC, USDT, PYUSD, USDS, USDG, and ETH. Exact protocols, vaults, issuers, SPVs, custodians, borrowers, and allocation limits are Not verifiable as of September 5, 2026.
  • Oracle/manipulation risk: Oracle reliance is documented for the underlying Sky system; the specific oracle set, fallback design, price-manipulation controls, and per-asset exposure for Spark Savings are Not verifiable as of September 5, 2026.
  • Bridges / chain risk: DeFiLlama reports deployments across Ethereum, Arbitrum, Robinhood Chain, Avalanche, Base and other chains, but bridge contracts, canonical-vs-third-party bridge usage, and chain-level failure exposure are Not verifiable as of September 5, 2026. Its reported TVL is approximately $1.228B, with Ethereum the largest share (~76.8%); this is analytics-platform data, not raw-chain verification.
  • Custody/CEX/MM: Robinhood Crypto custody is omnibus, not FDIC/SIPC protected, and execution counterparties/venues are selected by Robinhood. This creates relevant custodian, liquidity, and platform-access risk only where Robinhood is an integration or distribution channel; direct Spark exposure is Not verifiable as of September 5, 2026. Failure scenarios: USDS/stablecoin depeg; oracle error or manipulation; Sky governance intervention; bridge/L2 outage; smart-contract exploit; borrower/RWA/SPV default; custodian or market-maker insolvency; withdrawal-gate or liquidity mismatch. Structured fields:
  • dependency_failure_active: null
  • max_exposure_pct: null
Evidence (4)

crypto custody

two sources

Spark Savings is organized as a non-custodial vault system: users deposit into permissionless ERC-4626 vaults and receive vault shares that represent a claim on the underlying assets, while the protocol’s liquidity layer coordinates deployment and redemptions rather than holding user funds as a custodian. The public docs also describe a separate institutional pathway where assets can remain in regulated custody with partners such as Anchorage or BitGo while being deployed into Spark markets, but that is an access arrangement for institutions, not the core retail vault model. On the withdrawal question, the best-supported answer is that withdrawals are not paused at the protocol level in the sources reviewed; however, some smart-contract components can be paused and certain requests may route through asynchronous liquidity-intent flows, so exact pause status for every vault is Not verifiable as of 2026-09-05.

For asset segregation, the evidence indicates vault assets are accounted for per vault and backed by corresponding USDS liquidity within the Spark Liquidity Layer, but a formal legal-segregation statement was not found, so segregated_assets is Not verifiable as of 2026-09-05.

Evidence (8)

incident

two sources

Corrected scope: this was an external KelpDAO rsETH bridge incident, not a Spark Savings vault loss. On April 18, 2026, a forged LayerZero cross-chain message released approximately 116,500 unbacked rsETH, valued at about $292 million, from KelpDAO’s Unichain-to-Ethereum route. SparkLend and other lending markets froze rsETH exposure as a precaution; available evidence does not identify direct Spark Savings exposure, depositor losses, or bad debt.

Spark Savings affected users: none verified. Response included emergency market freezes and exposure containment. LayerZero reported replacing compromised RPC infrastructure and restoring the DVN; Kelp later reported the rsETH backing restoration complete on May 26, 2026.

For Spark Savings, status is resolved: no realized protocol/user loss, no recovery or reimbursement was required. Broader ecosystem remediation was completed according to Kelp’s restoration update.

Date
2026-04-18
Cause
Bridge / third-party collateral failure
Loss
$0
Attacker proceeds
$292.0M
Status
resolved
Recovered
$0
Event id
kelpdao-rseth-bridge-2026-04-18
Evidence (4)

key management

unverified

Spark Savings is organized as a non-custodial savings product rather than a custodial key vault: users deposit stablecoins into permissionless vaults, remain in control of their on-chain finances, and the system is built around coordinated liquidity management and transparent capital allocation. The clearest published key-management detail is that Spark uses a threshold signature model for off-chain transfers, where users keep self-custody of their key shares while the Spark operator set holds complementary shares. Spark states that this design lets users unilaterally exit to Bitcoin’s base layer if operators become uncooperative.

For Spark Savings specifically, the available sources describe the product’s custody and liquidity structure, but they do not disclose a separate chain-by-chain key-management architecture for Arbitrum, Avalanche, Base, Ethereum, or Robinhood Chain. Based on the published material, the safest characterization is that key control is user-led and non-custodial, with protocol operators coordinating liquidity and transfers under a threshold-signature scheme where applicable. Any finer operational details for each listed chain are Not verifiable as of 2026-09-03.

Evidence (3)

smart-contract

two sources

Scope/as-of: 5 September 2026. Dune MCP was unavailable; therefore no on-chain claims, proxy-admin classification, role state, timelock delay, or deployment-wide address matrix are asserted. Not verifiable as of September 5, 2026 for those items. Verified design evidence (not deployment-state evidence): Spark Vaults V2 uses ERC-1967/UUPS proxies. DEFAULT_ADMIN_ROLE can upgrade implementations, assign roles, set VSR bounds and deposit caps; SETTER_ROLE sets VSR within bounds; TAKER_ROLE calls take() and can fully drain vault-held liquidity, subject to the intended repayment/liquidity model. No renounced roles or timelock delay were verified. Exit risk: ERC-4626 withdrawal/redemption is permissionless when sufficient idle liquidity exists. Withdrawals can revert or be limited when assets are deployed.

Spark documents separate intent-based and permissionless-withdrawal paths; the latter is a backup route for selected assets and venues, not proof of universal, admin-independent exit on all five chains. Worst case if privileged keys are compromised: the admin can upgrade the vault to malicious logic, grant/reassign roles, alter rate bounds/caps, and potentially redirect or impair withdrawals. A compromised TAKER_ROLE can remove vault liquidity; users may face delayed, partial, or failed exits. This is a material centralization and freeze/drain risk even though the audited reference code does not expose an ordinary user-authorized arbitrary withdrawal function. > Contradiction / evidence gap: Spark’s canonical registry claims to contain all ecosystem addresses, but a complete, chain-by-chain Savings-vault matrix and live role/admin state could not be independently verified here. Not verifiable as of September 5, 2026. One independently cited Ethereum example is spUSDC at 0x28b3…96a43d; Robinhood ALM infrastructure includes ALM Proxy Freezable 0xAEa9…2cE41, but this is not a complete vault inventory. Architecture: User → ERC-1967/UUPS SparkVault → underlying asset ↑ DEFAULT_ADMIN / SETTER └── TAKER → ALM Controller/strategies → liquidity return Optional: User → Intent/Permissionless Withdrawal → Controller/ALMProxy → Vault Audit report: ChainSecurity recorded 0 open critical and 0 open high findings for the reviewed V2 code, but deployment equivalence and current configuration remain unverified. Structured assessment: deployment-specific values are null where unknown.

Admin can drain
Yes
Upgradeable
Yes
Evidence (7)

audit

one source

Report: Spark User Actions; auditor: ChainSecurity; publication date: 2024-09-04; scope: PSMVariant1Actions and MigrationActions; link: https://reports.chainsecurity.com/Spark/ChainSecurity_Spark_SparkUserActions_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2024-09-04
Scope
Batching PSM/ savings-token actions and migration helpers.
Findings
Critical 0; high 0; medium 0; low 0.
Fix status
No severity-rated findings; deployed-code status not verifiable.
Evidence (1)

audit

one source

Report: Savings USDS; auditor: ChainSecurity; publication date: 2024-09-30; scope: SUsds/ISUsds and deployment scripts, including L2 SUsds; link: https://reports.chainsecurity.com/MakerDAO/ChainSecurity_MakerDAO_SavingsUSDS_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04 (bytecode match not performed).

Auditor
ChainSecurity
Report date
2024-09-30
Scope
Savings USDS ERC-4626 token, upgradeability and deployment scripts; L2 token added in final version.
Findings
Critical 0; high 0; medium 0; low 0. Informational: 1 discrepancy with NST, code corrected; 2 informational items acknowledged.
Fix status
One informational issue corrected; two acknowledged. No critical/high/medium/low findings.
Evidence (1)

audit

one source

Report: Spark Vaults; auditor: ChainSecurity; publication date: 2025-01-24; scope: USDC ERC-4626 vault and L2 deployment; link: https://www.chainsecurity.com/reports/Spark/ChainSecurity_Spark_SparkVaults_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2025-01-24
Scope
UsdcVault.sol, deployment scripts and UsdcVaultL2.sol/L2 deployment.
Findings
Critical 0; high 0; medium 0; low 0. Informational findings/notes were reported.
Fix status
No severity-rated findings; deployed-code status not verifiable.
Evidence (1)

audit

one source

Report: Spark Vaults V2; auditor: ChainSecurity; publication date: 2025-10-01; scope: SparkVault ERC-4626 contract; link: https://www.chainsecurity.com/reports/Spark/ChainSecurity_Spark_SparkVaultsV2_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2025-10-01
Scope
ISparkVault.sol and SparkVault.sol, compiler 0.8.29; proxy deployment and dependencies excluded.
Findings
Critical 0; high 0; medium 0; low 1 resolved: Unbounded Interest Obligations. Informational issues and notes included.
Fix status
Low finding code-corrected by adding a deposit cap; some informational interface items partially corrected.
Evidence (1)

audit

one source

Report: Spark Savings Intents; auditor: ChainSecurity; publication date: 2026-03-11; scope: SavingsVaultIntents.sol and interfaces; link: https://reports.chainsecurity.com/Spark/ChainSecurity_SparkDAO_SparkSavingsIntents_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2026-03-11
Scope
Spark Savings Vault Intents withdrawal-request system; vault contracts excluded.
Findings
Critical 0; high 0; medium 0; low 0. Five informational/design findings acknowledged; additional operational notes.
Fix status
No severity-rated findings; informational findings acknowledged, not code-corrected.
Evidence (1)

audit

two sources

Spark DAO – Spark Savings Intents / Savings Vaults (including boosted vaults) smart‑contract audits.

Auditor
ChainSecurity
Report date
2026-04-27
Scope
Core Spark Savings ERC‑4626 vault implementation and intents module: functional correctness, access control, asset solvency, proxy/upgradability pattern, arithmetic precision; files in scope include src/, interfaces/, IERC4626Like.sol, ISavingsVaultIntents.sol.[1][2][13]
Evidence (3)

audit

one source

Boosted Spark Savings Vault audit.

Auditor
ChainSecurity
Report date
2026-06-13
Scope
Boosted Spark Savings vault logic layered on top of the base Spark Savings vaults: functional correctness, asset solvency (including circular re‑investing risks), access control, upgradeability, operational considerations.[2]
Evidence (1)

audit

one source

Report: Permissionless SLL Withdrawals; auditor: ChainSecurity; publication date: 2026-08-17; scope: permissionless withdrawal contracts; link: https://reports.chainsecurity.com/Spark/ChainSecurity_SparkDAO_PermissionlessSLLWithdrawals_Audit.pdf; covers deployed code: Not verifiable as of 2026-09-04.

Auditor
ChainSecurity
Report date
2026-08-17
Scope
PermissionlessWithdrawals.sol, DiamondPAU/LegacyPAU variants and interface; vaults, controllers and governance configuration excluded.
Findings
Critical 0; high 0; medium 0; low 0; informational 7.
Fix status
All 7 informational findings resolved through code corrections or specification changes; no open issues.
Evidence (1)

Team & Reputation

founders

two sources

Spark Savings appears to be a public, non-anonymous team built around Phoenix Labs, the core development team in the Sky/MakerDAO ecosystem. Publicly identified leads include Sam MacPherson (CEO/co-founder), Lucas Manuel (head of smart contracts/co-founder), and other named executives such as Nadia Alvarez and Kris Kaczor; Blockworks says the Phoenix Labs team has no anonymous contributors. The strongest recurring credibility signal is prior MakerDAO/Sky work: multiple sources describe Spark as incubated by MakerDAO/Sky or developed by Phoenix Labs under that ecosystem, and several team members are said to have long-standing DeFi backgrounds rather than first-time founders.

Sam MacPherson is repeatedly described as a veteran Maker developer, and Lucas Manuel is described as having held prior smart-contract roles at MakerDAO and Maple Finance. Reality check: I could not verify a real office, onshore/offshore corporate structure, or any independent evidence of a physical business footprint from the available sources; those items are Not verifiable as of 2026-09-03. The protocol itself is the weakest source for business-form claims, so anything about “headquarters” or corporate domicile should be treated as unverified marketing unless confirmed independently.

There is also a source-quality caveat: several search hits are secondary media or crypto-press articles, so the team disclosure is credible but not fully independently audited here.

Evidence (7)

general reputation

two sources

Spark Savings currently has a moderately positive, institutional-leaning reputation, but with non‑trivial governance, concentration, and regulatory perception risks that institutional allocators should factor in. Founders / backing / ecosystem Most sources frame Spark Savings as part of the Spark / Sky (formerly Maker) ecosystem, positioning it as a yield and liquidity layer that routes stablecoins (DAI, USDS, USDC, etc.) into the Sky Savings Rate / DAI Savings Rate modules. This ties its credibility to the long‑running Maker/Sky stack rather than an anonymous standalone project. Public materials emphasize “institutional‑grade tokenized savings” and “onchain capital allocator” branding, targeting professional users.

Specific founder names and investor cap table are not detailed in independent sources, so these are Not verifiable as of 2026‑09‑03. Audits / security posture Independent risk commentary (Hindenrank) describes Spark Savings as a “lower risk” simple yield‑bearing wrapper backed by a battle‑tested stablecoin protocol, but explicitly flags that yield is governance‑dependent and subject to significant rate changes. Concrete audit firm names, audit dates, or reports for the savings vault contracts are Not verifiable as of 2026‑09‑03 from independent sources; protocol documentation describes non‑custodial ERC‑4626 vaults and integration with Sky/DSR modules but this is an unverified marketing claim until matched to third‑party audits. Sentiment & institutional perception Coverage from Binance Academy, Bybit Learn, IQ.wiki, Yield.xyz, and media like Cryptobriefing and Hindenrank is generally favourable, emphasizing:

  • Large scale of deposits (figures around $1–3B+ TVL across chains are repeatedly mentioned).
  • Composability and standardized ERC‑4626 vault design.
  • Positioning as a backbone liquidity/savings layer for DeFi and institutional users. Risk reports grade it around “B / lower risk”, not risk‑free. Commentary stresses rate risk, governance reliance on Sky, and concentration in specific stablecoins and RWA‑backed yields as key concerns rather than smart‑contract novelty. Criticisms, fraud / rug / insolvency, legal / regulatory Across independent descriptions and risk reports, there are no documented accusations of fraud, rug pull, or insolvency tied specifically to Spark Savings as of the latest coverage. There is also no mention of regulatory enforcement actions or sanctions directly against Spark Savings or its operators in these sources — Not verifiable as of 2026‑09‑03 beyond that. Unresolved risk themes for institutional allocators
  • Governance dependence: Savings rates and underlying allocation are set via Sky governance, introducing policy/change risk distinct from purely algorithmic money markets.
  • RWA / issuer and stablecoin concentration risk: Yields rely heavily on DAI/USDS and real‑world asset collateral, which embeds counterparty, regulatory, and macro risk at the Sky/Maker layer rather than at Spark alone.
  • Cross‑chain deployment risk: Spark Savings is live across multiple chains including Arbitrum, Avalanche, Base, Ethereum, Robinhood Chain and others, expanding the operational and bridge/sync risk surface, though independent commentary highlights its dominance on Arbitrum stablecoin supply. These themes are actively discussed in risk write‑ups rather than hidden, which slightly improves the protocol’s reputational standing but also underscores that risk is structural and ongoing, not fully resolved.
Evidence (15)

Economy

TVL: $1.3B

model

two sources

Economic model (review date: September 5, 2026). Spark Savings issues yield-bearing vault shares (sUSDS/spUSDC/spUSDT/spUSDG/PYUSD and spETH). Stablecoin deposits are pooled, commonly converted into USDS, and allocated through Spark Liquidity Layer/SubDAOs across on-chain lending, tokenized T-bills/RWAs, stablecoin liquidity and OTC/private-credit exposures. ETH is primarily supplied to SparkLend; Credora reports 90.23% deployed and 9.77% idle for redemptions. Yield and risk. Yield is strategy-generated/Sky Savings Rate-linked, not clearly liquidity-mining funded.

Credora’s latest report is dated August 24, 2026—stale under the ≤7-day rule—and shows USDS collateral of 33.33% stablecoins, 40.46% on-chain lending, 10.24% OTC lending, 11.58% T-bills and 4.39% private credit. External exposure is therefore material; this is not market-neutral in the strict sense. ETH vaults have directional ETH price risk.

No evidence supports leverage, looping or restaking in the savings vaults. Organic yield share: Not verifiable as of September 5, 2026. Leverage ratio: Not verifiable as of September 5, 2026. Withdrawals/fees. Vaults use ERC-4626-style deposit, withdraw and redeem mechanics.

Spark advertises withdrawal at any time with no platform fee/slippage (an unverified marketing claim); Credora confirms idle-liquidity buffers for several vaults. No lock-up was identified. Exact gates, per-chain limits and stress-period withdrawal behavior: Not verifiable as of September 5, 2026. TVL/APY. DeFiLlama reports $1.228B Savings TVL: Ethereum $943.85M (76.8%), Arbitrum $234.77M (19.1%), Robinhood $31.01M (2.5%), Avalanche $9.53M (0.8%), Base $5.78M (0.5%); +8.5% over 30 days.

Eight pools average 3.29% APY; spUSDT is 3.25%. APY history, volatility and sustainability: Not verifiable as of September 5, 2026. Dune TVL/trend reconciliation: Not verifiable as of September 5, 2026. Contradiction: Spark’s website displays Savings TVL of $2.359B, versus DeFiLlama’s $1.228B.

The gap is unresolved; use DeFiLlama only as the externally tracked figure. Savings-specific protocol revenue and collateralization ratio: Not verifiable as of September 5, 2026.

Evidence (4)

reserves

one source

Assessment — as of September 5, 2026

  • Reported size: Spark’s Q2 2026 financial report states treasury capital of $48.5M at June 30, 2026, serving as junior/first-loss capital. This is an internal, unaudited figure: the report says its data were not independently verified and were not prepared by a professional accounting service provider. Contradiction / verification gap: the reported $48.5M cannot be independently reconciled here because Dune is unavailable; on-chain balance and composition are Not verifiable as of 2026-09-05.
  • Known addresses: Spark Treasury 0x3300f198988e4C9C63F75dF86De36421f06af8c4; Spark Treasury (SAF) 0xEabCb8C0346Ac072437362f1692706BA5768A911; SparkLend reserve-factor collector 0xb137E7d16564c81ae2b0C8ee6B55De81dd46ECe5; Spark operations 0x2e1b01adabb8d4981863394bea23a1263cbaedfc; and Spark Liquidity Layer controllers on Ethereum, Base, Arbitrum and Avalanche.
  • Composition: Disclosures describe stablecoin liquidity, on-chain overcollateralized lending, RWA/short-duration Treasury exposure, and institutional credit/custody-supported allocations. Spark Savings V2 documentation says USD vaults are backed by USDS; spETH is backed by Spark’s balance sheet and insurance. These are protocol disclosures and should be treated as unverified marketing claims absent independent reconciliation.
  • Custody and control: Vaults use non-custodial smart contracts. Governance controls the Treasury/SubDAO proxy; operations and ALM multisig/controller roles execute strategy and liquidity movements. Governance records show reserve transfers from the SparkLend collector to the Spark ALM Proxy and identify the Treasury proxy as owner/admin for Savings V2 contracts.
  • Reserve policy: Junior capital, liquidity buffers, rate limits, recovery mode, and Sky/Spark surplus-backstop layers are described; large withdrawals may be fulfilled through the ALM/liquidity-intents system.
  • Attestations: No independent financial-reserve attestation or full audit was located. Published “audits” primarily cover smart-contract code. Not verifiable as of 2026-09-05.
  • Liabilities: Q2 reports a $6.36M accrued depositor-yield liability, but total liabilities are not disclosed/reconciled. Not verifiable as of 2026-09-05. Multi-chain exposure: Chain-by-chain reserve balances and percentages are Not verifiable as of 2026-09-05.
Evidence (4)

tokenomics

one source

Spark Savings does not appear to have a native token as of the latest available data. All token-related metrics requested are therefore either not applicable or not verifiable. ### 1. Existence of a native token

  • Web search for “Spark Savings token”, “Spark Savings spark-savings Arbitrum token”, and chain-specific contract addresses does not return any credible evidence of a protocol-native governance or utility token associated with Spark Savings on Arbitrum, Avalanche, Base, Ethereum, or Robinhood Chain.
  • Results instead surface unrelated “Spark” or “Spark Protocol” tokens (e.g., Maker-associated Spark Protocol on Ethereum), which are distinct products and cannot be matched to the spark-savings slug or the listed chains by contracts, branding, or documentation.
  • Because no contract address, ticker, or official docs can be reliably tied to “Spark Savings” specifically, token existence is Not verifiable as of 2026-09-03. ### 2. Tokenomics fields (N/A or not verifiable) Given the above, the following items are not applicable / not verifiable for Spark Savings as of 2026-09-03:
  • Native token name/ticker and contract address: Not verifiable as of 2026-09-03.
  • Total vs circulating supply; market cap and FDV: Not verifiable as of 2026-09-03.
  • Token utility and governance role; revenue share; buybacks; burns; staking rewards: No evidence of a native token, fee/revenue token, or governance token tied to Spark Savings.
  • Emissions schedule and unlock schedule; on-chain verification of unlocks: Not verifiable as of 2026-09-03.
  • Allocations (team/investors/treasury/community): Not verifiable as of 2026-09-03.
  • Top-holder concentration and insider wallets: Not verifiable as of 2026-09-03.
  • Mint/blacklist/fee-switch functions and controllers: Not verifiable as of 2026-09-03.
  • DEX liquidity depth and main listings: No credible DEX listing can be tied to a Spark Savings native token across the specified chains. ### 3. Name-collision / protocol identity
  • Multiple “Spark” projects exist in DeFi (e.g., Spark Protocol by MakerDAO, other tokens called SPARK). The lack of matching contract addresses, chain deployments, or documentation for “Spark Savings” means any attempt to attribute those tokens here would risk conflating distinct protocols.
  • Under the name-collision guard and missing data rule, all tokenomics for Spark Savings must be treated as Not verifiable as of 2026-09-03 unless the protocol later discloses verifiable on-chain or audited information.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 is not a direct asset-level risk factor for Spark Savings, because Spark Savings is a stablecoin yield product built around USDS/USDC/USDT-style deposits and not a Bitcoin-denominated vault. The relevant stress path is indirect: a sharp BTC crash could pressure crypto liquidity, stablecoin demand, and collateral markets, which may tighten Spark’s liquidity management and trigger higher withdrawal coordination or recovery-mode protections if system stress becomes severe. For Spark Savings, the disclosed stress design is a tiered liquidity and loss-absorption framework.

Spark says it keeps enough idle liquidity to absorb large withdrawals, withdraws first from junior venues when liquidity tightens, and can shift funds out of Morpho or other overflow venues before borrowers are affected. Spark’s security framework also states that losses are intended to be absorbed first by protocol-level buffers and recapitalization layers before reaching broader depositor exposure, and that recovery mode can be activated in severe stress to manage withdrawals orderly. What is *not* verifiable from the provided sources is a quantitative estimate of how much a BTC move below $10,000 would reduce Spark Savings TVL, impair specific venues, or change depositor loss probability.

Not verifiable as of 2026-09-03. Practical risk reading: the main concerns under a BTC crash are second-order market stress, faster withdrawals, possible liquidity reallocation away from longer-lag venues, and—only in extreme system impairment—potential activation of recovery mode or broader loss-sharing mechanisms.

Evidence (3)

stress scenario - largest collateral depegs 20%,

unverified

For a 20% depeg in the largest collateral asset, Spark Savings’ public materials do not provide enough information to quantify the loss, so the impact is Not verifiable as of 2026-09-03. The key reason is that the query depends on the current collateral composition and the exact largest-collateral exposure by chain, and those figures are not available in the provided sources. What can be stated is the protocol’s documented stress handling: Spark says Savings vaults can enter recovery mode during severe stress, withdrawals may be coordinated or temporarily adjusted, and residual losses are intended to be absorbed first by layers of risk capital and a SKY token backstop before any socialized loss reaches USDS holders.

Spark also describes a tiered liquidity model in which junior venues are withdrawn first under stress and rate changes are used to manage liquidity. Relevant collateral-stress context from Credora shows that Spark’s rated vault exposures include ETH, PYUSD, USDC, USDT, USDS, and stUSDS, with the stUSDS vault carrying the highest listed stress exposure in the provided rating snapshot. However, the sources do not identify which asset is the current largest collateral position, nor do they quantify the resulting bad debt or NAV impact from a 20% depeg scenario.

So, the only defensible answer is:

  • Estimated loss from a 20% depeg: Not verifiable as of 2026-09-03.
  • Likely protocol response: liquidity rebalancing, possible recovery mode, and first-loss absorption through risk-capital layers before any residual socialized loss.
  • Chain split / exposure share: Not verifiable as of 2026-09-03.
Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Spark Savings appears to sit inside the Sky/Spark loss-waterfall, so a top-counterparty insolvency is not absorbed first by depositors. The documented path is: losses hit the relevant vault or allocation first, then junior risk capital at the Prime level, then broader Sky risk-capital layers and surplus buffers, then token backstop recapitalization, and only if those are exhausted do residual losses reach USDS holders, including Spark Savings vaults. For the specific stress case of a counterparty becoming insolvent, the expected loss path is:

  • Primary impact: the affected Spark Savings vault / underlying exposure takes the loss first.
  • First absorber: Prime-level internal junior risk capital; Spark docs say this is the first capital to absorb losses on investments under the allocation system.
  • Next absorbers: protocol surplus / surplus buffer and additional backstop layers described in the framework material.
  • Final resort: SKY token backstop; only after that can residual losses be socialized across USDS holders, which includes Spark Savings vault balances because they are fully backed by USDS. Who compensates depends on where the waterfall is exhausted. If the loss is contained within the early layers, depositors are compensated through the protocol’s risk-capital stack and the vault should remain whole. If the waterfall is exhausted, compensation comes from recapitalization steps and ultimately falls on USDS holders through socialized loss rather than on a single external counterparty. Impact through the smart contracts: Spark Savings vaults are ERC-4626 vaults, so depositors hold shares against an underlying asset balance; stress would show up as reduced underlying backing / halted yield / possible recovery-mode behavior rather than a direct “counterparty default” payment flow from the vault itself. Spark docs also say vaults can enter recovery mode during severe market stress, and some vault states can reject deposits and accrue no yield. Chain-specific exposure is not verifiable as of 2026-09-04 because on-chain tooling was unavailable in this run, so I cannot confirm the per-chain loss exposure or TVL split on Arbitrum, Avalanche, Base, Ethereum, or Robinhood Chain.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

one source

For the stress scenario of committed fraud by the DAO or owners, I found no verifiable evidence in the supplied sources that Spark Savings’ DAO or owners have committed fraud. The available material only shows that Spark describes Savings as open-source and audited, and that its documented risks are smart-contract failure and USDS depeg risk—not DAO fraud. The strongest source on protocol design is Spark’s Savings documentation, which states that losses are expected to be handled through layered risk capital, token backstops, and, only in extreme cases, socialized loss across USDS holders; it also notes a recovery mode that can temporarily halt withdrawals.

That is a protocol risk framework, not evidence of fraud. The audit excerpt available here also supports a security-oriented reading, saying the codebase provides a high level of security. However, an audit is not a guarantee against misconduct, and it does not by itself rule out insider fraud.

Because the search results do not contain a credible regulator, court filing, investigation, or independent investigative report alleging DAO/owner fraud against Spark Savings, the correct status is: Not verifiable as of 2026-09-03. For an institutional risk memo, the appropriate stress assumption is therefore unproven fraud by DAO/owners, with loss outcomes driven instead by the documented smart-contract, depeg, and recovery-mode mechanics.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

Spark Savings’ primary yield source is Sky’s governance-set savings rate (SSR/DSR depending on vault), and Spark’s docs indicate that savings vault yield is derived from Sky-protocol rate mechanisms rather than a standalone market strategy. In a stress scenario where that primary yield source turns negative over 30 days, the protocol does not document a negative savings rate mechanism; the public materials describe rates that can be cut to zero or near-zero, not below zero. For the specific stress question, the practical result is a yield collapse, not a documented negative carry on the vault itself: Spark’s materials say governance can set the Sky Savings Rate to any non-negative value, including zero.

Hindenrank likewise states the rate is governance-controlled and could be cut to near-zero in a crisis. On the loss side, Spark’s documentation says the savings vaults are protected by layered loss-absorption features, and that if residual losses remain, they are socialized across all USDS holders only after other buffers are exhausted. Spark also says it can place savings vaults into recovery mode to manage withdrawals during stress.

For this question’s requested chain breakdown across Arbitrum, Avalanche, Base, Ethereum, and Robinhood Chain, the underlying yield source is not presented in the retrieved sources as chain-specific; Spark’s savings-rate mechanism is described at the protocol level, not separately by those chains. Not verifiable as of 2026-09-03 whether any of those chains contribute a distinct primary yield source share, or whether one chain dominates the 30d yield contribution. Operationally, the stress implication is: if the primary yield source is negative for 30 days, Spark Savings should be treated as facing yield failure / rate compression risk, while principal impairment would depend on whether the protocol’s backstops and recovery mechanisms are breached.

Evidence (5)

Governance & Legal

governance

two sources

As of September 13, 2026, Spark Savings is not an independent DAO. It operates as a Sky/Spark SubDAO product: Spark-related proposals use community/Snapshot authorization followed by Sky on-chain Executive Votes and spell execution. Governance therefore appears substantive at the Sky/Spark level, but token holders do not independently control Spark Savings.

Contract control: documented Spark Savings vaults assign DEFAULT_ADMIN to the Spark SubDAO Proxy on Ethereum and to Spark governance executors on some other chains. The ALM Proxy is the operational custodian/taker; ALM Proxy Freezable or an operations safe can set or freeze operational parameters. Spark’s ALM repository states that ALMProxy holds custody of funds and that DEFAULT_ADMIN is fully trusted and run by governance.

This creates a governance-controlled but materially centralized trust model. Funds: admin/governance-controlled operational contracts can move or route user assets without a fresh DAO vote for each transaction, subject to configured controls/rate limits; therefore admin_can_drain is assessed true. The available evidence does not establish an unrestricted arbitrary drain on every chain.

Frontend/development: the interface is open source, deployed commit-by-commit to IPFS, but the repository’s maintainers and deployment workflow control the release presented through the official domain. Proposal process: forum proposal → Snapshot/community poll where required → Sky Executive Vote → spell execution. Timelock evidence previously recorded for this category indicates a 24-hour delay.

Exact current executor, guardian, multisig signer set, threshold, signer independence, and top-holder/voting concentration require Dune or direct contract-state verification. Dune was unavailable in this run, so those items are not verifiable. Company entity, jurisdiction, registration number, directors, and applicable Terms of Service were not verifiable from the checked evidence.

Timelock
Yes
Timelock delay hours
24
Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

one source

Assessment (as of September 4, 2026):

  • Entity / jurisdiction: The Spark Savings front end is operated by Spark.fi Inc., incorporated in Panama, with a registered office in Panama City. The protocol’s legal documents separately identify Spark Foundation (Cayman Islands) and SPK Company Ltd. (British Virgin Islands) for SPK-token activities; these should not automatically be treated as the Savings product’s operating entity. Phoenix Labs is described as a contributor/developer, not the owner or operator of Spark or its treasury.
  • ToS / restrictions: Terms characterize Spark as decentralized smart-contract software and the site as informational/interface infrastructure, disclaiming custody, advice, warranties, capital preservation, yield, liquidity and losses from strategy contracts. Users must be adults, sophisticated users, comply with applicable law, and not use the service from prohibited or sanctioned jurisdictions/persons. Cayman Islands law governs, with confidential, binding arbitration seated in the Cayman Islands.
  • KYC / AML: The front-end privacy notice states that Spark.fi may conduct KYC and process identity, address, nationality, wallet, PEP, AML/CFT and sanctions information, and may restrict access if information is not provided. This establishes compliance obligations for the company/front end, not clearly for permissionless smart-contract interaction itself. Protocol-level KYC/AML coverage is Not verifiable as of September 4, 2026.
  • Classification / warnings: The Savings product is presented as yield-generating vaults, not a bank deposit or insured savings account. The Terms expressly warn of smart-contract, oracle, counterparty, allocation, withdrawal-delay, total-loss and regulatory risks. SPK has MiCA-related white papers, but the published notice states they were not approved by an EU competent authority; this concerns the token, not necessarily Savings-vault classification.
  • Enforcement, court cases, sanctions: No matching regulator action, sanctions designation, or court case against Spark.fi Inc., Spark Foundation, SPK Company Ltd., Phoenix Labs in its Spark role, or Spark Savings was identified in the reviewed public sources. Court-case and sanctions status are otherwise Not verifiable as of September 4, 2026. Do not confuse user/address screening or blocking with the entity itself being sanctioned.
  • Legal structure vs. actual risk: Offshore entities, disclaimers, arbitration and separation between front end, contributors, governance and immutable contracts may reduce contractual recourse but do not remove regulatory, insolvency, smart-contract, bridge, strategy-counterparty or cross-chain exposure.
Active enforcement
No
Sanctioned
No
Entity
Spark.fi Inc. (front-end/site operator); separate token entities: Spark Foundation and SPK Company Ltd.
Jurisdiction
Panama for Spark.fi Inc.; Cayman Islands for Spark Foundation; British Virgin Islands for SPK Company Ltd.
Evidence (4)

legal registries

two sources

No exact GLEIF LEI record for 'Spark.fi Inc', 'separate token entities: Spark Foundation', 'SPK Company Ltd', 'Spark Savings'. OFAC SDN screening of 'Spark.fi Inc', 'separate token entities: Spark Foundation', 'SPK Company Ltd', 'Spark Savings': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Spark.fi Inc
  • separate token entities: Spark Foundation
  • SPK Company Ltd
  • Spark Savings
Sanctioned
No
Evidence (4)

Stability

stability

one source

Spark Savings does not appear to issue its own stablecoin; it is a savings wrapper that accepts external stablecoins such as USDC, USDT, PYUSD, USDS, and ETH. The stablecoin most directly used in the product is USDS/USDC, but a protocol-specific historical depeg count for Spark Savings itself is not verifiable as of 2026-09-05. Therefore depeg_count, last_depeg_date, and max_depeg_pct are not verifiable as of 2026-09-05.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDS
  • USDT
  • PYUSD
Evidence (3)

Risks & Strengths

risks

two sources

Spark Savings has material exposure to allocator, liquidity, issuer, governance, and cross-chain risks. DeFiLlama currently reports Spark Savings on eight chains—not only the five specified—with approximately 76.8% of TVL on Ethereum, 19.1% on Arbitrum, 2.5% on Robinhood Chain, 0.8% on Avalanche, and 0.5% on Base; the remainder is on OP Mainnet and Unichain. Dune verification is unavailable: on-chain metrics and contract-state checks are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Allocator and counterparty exposureSavings yield depends on deployment across DeFi, institutional credit, CeFi, and RWAs. Losses, insolvency, oracle failures, or poor liquidity at an underlying venue can impair vault backing and redemption value.HighMediumWhitelisted takers, governance-set parameters, ALM controls, diversification, and operational monitoring are described. Exact exposure, limits, and counterparty concentrations are Not verifiable as of September 5, 2026.High-impact loss remains possible, especially where off-chain or credit counterparties are involved.
Liquidity and redemption mismatchCapital may be deployed rather than held idle, so large or stress-period withdrawals can be delayed; relayer orchestration and underlying-market liquidity may fail.HighMediumERC-4626 vault controls, withdrawal intents, min/max intent bounds, whitelisted vaults, and a relayer-based process are in place.Redemptions are not guaranteed to be immediate during synchronized withdrawals or market stress.
Stablecoin issuer and depeg riskUSDC, USDT, PYUSD/PayPal USD, and USDS introduce issuer, reserve, blacklist, pause, fee-switch, and depeg risks that can reduce usability or settlement proceeds.HighMediumSupported-asset restrictions, vault configuration, redemption checks, and governance controls exist; audited documentation explicitly identifies pause, blocklist, proxy, and fee-switch risks.Underlying issuer controls and solvency remain outside Spark’s direct control.
Privileged governance and upgrade riskAdmin, ALM, freeze, proxy-upgrade, and relayer authorities can change configuration, halt activity, or redirect operational flows; compromise or governance error could affect user funds.HighMediumGovernance authorization, audited access control, whitelisting, and freeze mechanisms are used.Trust in governance, multisigs, upgrade procedures, and key management remains material.
Smart-contract and cross-chain integrationVault, intent, token, messaging, bridge, and chain-specific integrations expand attack and failure surfaces; one defect or relay/bridge outage can cause loss, censorship, or inconsistent state.HighMediumIndependent audits, bug bounty coverage, whitelisting, and chain-specific deployment controls are in place.Audits are time-limited and do not eliminate undiscovered vulnerabilities or third-party infrastructure risk.
Evidence (5)

strengths

two sources

Spark Savings’ top strengths are: institutional-scale liquidity and fast withdrawals, because its vaults are designed for large deposits and 24/7 redemptions backed by Sky’s balance sheet; deep multi-protocol liquidity access, via the Spark Liquidity Layer and integrated protocols that help support efficient, low-slippage liquidity; stablecoin-focused yield, giving users a simple way to earn on stablecoins without active trading or leverage; multi-chain availability, with support across networks such as Ethereum, Base, Arbitrum, and others; and security/transparency, since the protocol emphasizes audited smart contracts, on-chain transparency, and constrained risk design.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 16 two independent sources, 14 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-27.