Steakhouse Financial

Green · 76/100

Executive summary

Steakhouse Financial is an Ethereum-based DeFi vault curator offering risk-curated yield strategies through Morpho and Aave lending markets, scoring 64/100 (orange band) with high data confidence (88/100).

  • Security: Multiple audits by Cantina and ChainSecurity identified and fixed all critical and high-severity findings, including share-price manipulation, read-only reentrancy, and fund-locking risks; two medium-severity findings were risk-accepted; deployed-code coverage and bytecode matching are not independently verifiable as of September 2026.
  • Incidents: March 2026 DNS hijacking via social engineering exposed users to phishing but did not affect vault contracts or depositor funds ($0 loss); August 2026 Pendle PT-reUSD oracle event triggered $36M Morpho liquidations with $920k attacker profit but zero confirmed protocol or lender loss; both incidents resolved with no reimbursements required.
  • Governance & custody: Non-custodial vault model with split governance—Steakhouse-controlled Owner/Curator/Allocator roles manage strategy, while depositor-controlled Aragon Guardian DAOs can veto changes and trigger shutdowns; 5-of-N multisig for owner operations; 7-day (Prime) and 3-day (High Yield) timelocks for material changes; no verified unrestricted admin drain function.
  • Top risks: Oracle manipulation and thin liquidity (August 2026 event demonstrated vulnerability); privileged governance compromise could alter strategy or fees; Morpho/Aave integration failures or collateral depegs could lock or lose funds; two medium audit findings remain risk-accepted; withdrawal liquidity depends on Morpho market depth (~10% immediately available).
  • Counterparty exposure: Heavy dependence on Morpho V2 infrastructure, USDC/USDT/PYUSD stablecoin issuers, Lido wstETH, Coinbase custody/distribution, and third-party oracles; collateral includes cbBTC, cbETH, WETH, wstETH, and tokenized RWA/credit assets; cascading liquidation and correlated collateral risks during market stress.
  • Strengths: Institutional-grade noncustodial architecture with modular whitelists, slippage limits, and permissionless winddown; transparent risk curation with public documentation and audits; blue-chip collateral focus in Prime products; multi-chain reach (Ethereum, Base, Arbitrum, Solana); real founders (Mark Phillips, Sébastien Derivaux, Adrian Cachinero Vasiljevic) with MakerDAO/Sky advisory track record; Cayman Islands legal entity (LEI 254900E5M86PI4TIPQ04, active); no sanctions or fraud allegations verified.
  • Unverified: Exact deployed-code bytecode matches, on-chain TVL breakdown by vault, current collateral composition and leverage ratios, live withdrawal liquidity and API health, bug bounty program existence, precise multisig signer identities, and stress-test outcomes for BTC <$10k or 20% collateral depeg scenarios cannot be confirmed from available sources as of September 2026.
  • Recommended exposure: Conservative allocation (≤5% of DeFi portfolio) given orange score, oracle/liquidation incident history, and unverified deployed-code coverage; limit to Prime USDC/ETH strategies with liquid collateral; avoid High Yield or exotic RWA vaults until stress performance is proven; monitor Morpho market utilization and Guardian DAO activity; set internal withdrawal limits recognizing ~10% immediate liquidity and timelock delays; diversify across multiple vault curators to mitigate single-protocol risk.
  • Open questions: Verify deployed vault addresses match audited commits via bytecode comparison; confirm current multisig signers and key-rotation procedures; quantify exact collateral breakdown and LLTV settings for each Ethereum vault; test live withdrawal execution and measure actual liquidity depth; review Guardian DAO participation rates and veto history; assess oracle feed quality and MetaOracle switching logic; clarify two risk-accepted medium findings from ChainSecurity; obtain independent stress-test results for stablecoin depeg and correlated liquidation scenarios; confirm insurance or backstop mechanisms, if any.

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 10 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-30)
Incidents 20% 100 20.0 no open incidents
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 17 3.4 TVL $3,056,343,088 = 17% of reference ($17,538,184,136)
Data confidence 88 7/7 critical categories; 17/40 verified facts; 40/40 fresh (180d)

Identification

protocol identification

two sources

Steakhouse Financial is an Ethereum-based DeFi vault curator / risk curator focused on stablecoin and ETH yield vaults, with official docs at steakhouse.financial/docs and public site at steakhouse.financial. The available web evidence supports Ethereum support and also mentions Base, Arbitrum, and Solana in some materials, but for this request the Ethereum scope is verified; a native token for Steakhouse Financial itself is not verifiable from the gathered sources, while Grove is described as a separate protocol/token in one source. The exact launch date of Steakhouse Financial is not verifiable as of 2026-09-04 from the gathered sources.

Main-contract identification is only partially verifiable: Etherscan shows Steakhouse Financial deployer addresses, but without on-chain query access here I cannot confirm the full main contract set or provide a Dune-verified cross-check, so those addresses are not fully verifiable as of 2026-09-04. Fork lineage is also not fully verifiable as of 2026-09-04 from the gathered sources; the docs indicate Steakhouse runs vaults on Morpho, which suggests integration rather than a clear fork of the protocol itself. No reliable evidence of malicious-modification history in similar forks was established from the gathered sources.

Evidence (5)

maturity

one source

Steakhouse Financial appears to be a real product portal, not just a marketing landing page: the main app is live at app.steakhouse.financial, and the site includes documentation with a full docs index, Markdown renditions, and dynamic Q&A endpoints. The docs also describe active product families and provide product-specific vault pages, which is a strong sign of a maintained user-facing product rather than a template site. The app page shows actual vault interfaces and wallet-connect flows, and product docs say deposits are deployed into onchain lending markets with withdrawal liquidity mechanics explained, indicating live deposit/withdrawal functionality is intended and operational at least at the interface level.

The documentation also references dashboards, APIs, and direct onchain integrations for yield services, so an API is at least documented as part of the product stack. What is not fully verifiable from the web results alone is whether the API is openly public, whether every withdrawal path is currently working without issues, and whether any links are broken today; those specifics are Not verifiable as of 2026-09-04. Overall, this looks like a mature, real DeFi product with a functioning app and documentation rather than a fake/templated site, but the exact openness of the API and current live UX health cannot be fully confirmed from the available sources.

Evidence (5)

Security

bug bounty

one source

Not verifiable as of 2026-09-04. No independently confirmable bug bounty program for Steakhouse Financial was found in the retrieved sources. The only security-related items surfaced were general references to audits and a March 2026 DNS/phishing incident post-mortem, neither of which establishes an active bug bounty program, its launch date, scope, or outcomes.

The protocol’s own site mentions a security posture, but that is unverified marketing claim unless corroborated externally.

Active
No
Evidence (2)

counterparty risks

two sources

Assessment — Ethereum scope (as of September 6, 2026): Steakhouse is an active vault curator, not merely an advisory firm. Ethereum products depend primarily on Morpho V2 lending infrastructure, vault governance/sentinel controls, and the issuers/liquidity venues of deposited assets. Current Ethereum product listings include USDC, USDT, PYUSD, ETH and wstETH strategies; High-Yield and Term products may add longer-tail collateral, fixed-term markets, Pendle PTs and tokenized credit/RWA assets. Oracle/manipulation risk: Market solvency depends on Morpho market oracles and Steakhouse’s MetaOracle controls.

Steakhouse states that its MetaOracle can switch between feeds after deviations, but oracle quality, stale NAVs, thin liquidity, bad LLTV settings or correlated collateral liquidation remain material loss vectors. Stablecoin/LST/restaking exposure: Direct asset risk includes USDC/Circle, USDT/Tether, PYUSD/Paxos, ETH and wstETH/Lido. Failure scenarios include stablecoin freeze/depeg, Lido or validator/slashing failure, wstETH liquidity discount, Morpho bad debt, or cascading liquidations. Steakhouse’s Prime USDC Coinbase strategy explicitly allocates among Morpho markets collateralized by cbBTC, cbETH, WETH and wstETH. Custodians, CEX/MMs and bridges: Coinbase is an important distribution/integration counterparty, while Safe, institutional partners and third-party frontends are operational dependencies.

The design is intended to be non-custodial, but frontend, domain, governance and integration failures remain possible. A March 30, 2026 domain/DNS phishing incident was reported as resolved with no vault-contract or depositor-fund loss; this was an operational dependency failure, not an active solvency event. No Ethereum bridge dependency was identified in the reviewed product documentation.

Actual Ethereum allocation by issuer, market, custodian, bridge or RWA SPV is Not verifiable as of September 6, 2026 because Dune/on-chain verification is unavailable. Maximum counterparty concentration is therefore also Not verifiable as of September 6, 2026. Failure scenarios: Morpho/oracle exploit; stablecoin issuer freeze or depeg; wstETH/LST liquidity shock; RWA issuer/SPV default, NAV delay or redemption suspension; curator/governance compromise; or liquidity mismatch causing withdrawals to pause even without principal loss. No active Ethereum dependency failure was found in the reviewed sources.

Dependency failure active
No
Evidence (5)

crypto custody

unverified

Steakhouse Financial’s custody model is presented as noncustodial: users deposit into onchain vault contracts, and Steakhouse says it cannot move user assets or withdraw funds on behalf of depositors. The available sources also describe the strategy layer as risk curation and execution only, with users retaining custody in their own wallet or in a dedicated noncustodial vault structure, including partnership and institutional setups where the client keeps custody through vault shares or wallet-controlled flows.

Evidence (3)

incident

two sources

March 30, 2026 — Social engineering of Steakhouse Financial's OVH/domain-management provider enabled DNS takeover of the website and app, which served a phishing frontend containing a wallet-drainer flow. Affected: site visitors and potentially new users attempting to interact through Steakhouse domains. Existing vault contracts, deposits and depositors were reported unaffected.

Realised loss was $0; attacker proceeds: Not verifiable as of September 6, 2026. Response: Steakhouse warned users not to interact, took the domains/frontend offline, reverted malicious DNS changes, cancelled an attempted transfer and restored access. Fix: registrar/domain-management migration, credential rotation, hardware-key and stricter domain controls, continuous DNS monitoring and broader vendor-security review.

Current status: resolved. No reimbursement was required or reported; recovered_usd is 0.

Date
2026-03-30
Cause
Frontend / infrastructure hack
Loss
$0
Status
resolved
Recovered
$0
Event id
steakhouse-dns-phishing-2026-03-30
Evidence (3)

incident

unverified

Fix: Steakhouse said it secured the registrar account, audited adjacent services, and restored/validated DNS control; the architectural separation between domain layer and onchain vaults was cited as the design that prevented fund impact.

Date
2026-04-01
Cause
Frontend / infrastructure hack
Loss
$0
Evidence (1)

incident

two sources

August 25, 2026 — A thin Pendle PT-reUSD market move, reportedly triggered by approximately $320,000 of rapid YT-reUSD trades, caused about $36.14 million of automated liquidations in Morpho markets curated by Steakhouse Financial. The event was market/oracle manipulation or stress rather than a confirmed smart-contract exploit: the oracle reportedly operated as configured, reUSD did not depeg, and no Steakhouse-curated lender incurred bad debt. Affected parties were leveraged borrowers and liquidated positions; lender funds were made whole.

Response included withdrawing liquidity from affected markets while reviewing the incident, then restoring liquidity. Fix/remediation: review of oracle parameters, liquidity depth, leverage and LLTV settings; no confirmed contract bug. DeFiLlama records $920,000, but that figure conflicts with reports of zero realised lender/protocol loss.

A third-party/officially attributed report gives attacker net profit of $920,781; this is not protocol loss. Current status: resolved, with no confirmed outstanding loss. Reimbursement: no reimbursement was required because lenders were reportedly whole; recovered_usd is therefore 0.

Date
2026-08-25
Cause
Oracle manipulation
Loss
$0
Attacker proceeds
$921K
Status
resolved
Recovered
$0
Event id
steakhouse-morpho-pt-reusd-2026-08-25
Evidence (4)

incident

one source

Steakhouse Financial: Market Manipulation via Risk Parameter Abuse on Ethereum; loss $920,000 (DeFiLlama hacks registry).

Date
2026-08-25
Cause
Other
Loss
$920K
Status
status unknown
Classification
Market Manipulation
Technique
Risk Parameter Abuse
Evidence (1)

key management

two sources

Steakhouse Financial appears to organize key management around a non-custodial, smart-contract-based vault model rather than a single custodian holding user assets. Its public materials describe it as an onchain vault curator that allocates and rebalances deposits across lending markets, while emphasizing that it does not take custody of assets and does not exercise direct discretion over user funds. For strategy changes, the operational control is structured with time delays/timelocks and a veto mechanism so users can review and block proposed updates before execution.

What is publicly verifiable is limited: the sources do not disclose a formal internal signing policy, multisig signers, hardware-wallet setup, or named key-rotation procedures. So the precise operational key-management arrangement is Not verifiable as of 2026-09-04 from the available sources. In practical terms, the available evidence suggests three layers of control: vault smart contracts for asset custody, curator permissions for proposing strategy updates, and user governance safeguards via timelock/veto before changes take effect.

Evidence (5)

smart-contract

two sources

Assessment date: September 6, 2026. The prior identification finding is outdated: Steakhouse now operates branded Ethereum vaults, although the legal operator is Carniceria Tropical Inc., not Steakhouse Financial Ltd. Ethereum addresses identified (not exhaustive): legacy Steakhouse USDC 0xBEEF01735c132Ada46AA9aA4c54623cAA92A64CB; legacy Smokehouse USDC 0xBEeFFF209270748ddd194831b3fa287a5386f5bC; current Safe x Steakhouse ETH 0xBeEFB45B6F9acB175e70acF16dC20D6120044c70; current Safe x Steakhouse USDC 0xbEeFCe6c76C7D7A8066562Fe9FF0e343a52dD92F; and the oracle factory 0xeC34e4e892061f368F915aDb9467B656ae5C42e8. Architecture: ``text User wallet │ ERC-4626 deposit/redeem ▼ Morpho Vault V2 / Steakhouse vault │ adapter registry ▼ Box sub-vault (ERC-4626) ├─ whitelisted tokens/oracles ├─ Morpho Blue / Aave funding modules ├─ curator (timelocked changes) ├─ owner (curator, ownership, skim recipient) └─ guardian / Aragon DAO (veto, shutdown) `` Box is described as non-proxy modular infrastructure; however, proxy implementation/admin status for each deployed Ethereum vault is Not verifiable as of 2026-09-06 because Dune/on-chain inspection is unavailable. The same applies to exact owner, curator, guardian, allocator, fee recipient, emergency permissions, renounced roles, and measured timelock execution history. Controls and failure modes: Owner can replace the curator; curator can add allocators, feeders, tokens/oracles, funding modules, facilities, and change slippage/timelock parameters, generally subject to timelocks. Allocators can move capital, borrow, pledge collateral, and invoke flash operations within contract constraints.

Guardian can veto queued actions and trigger shutdown. Users can redeem without administrator cooperation only to available liquidity in normal operation; during winddown, unwinding is permissionless. Immediate full exit is therefore not guaranteed.

A compromised owner/curator/allocator could redirect strategy exposure, manipulate supported-oracle/configuration choices, borrow against assets, or freeze new deposits; a compromised guardian could trigger shutdown. Direct arbitrary treasury drainage is not established from published code; Not verifiable as of 2026-09-06 for deployed instances. Audit: ChainSecurity reported 0 critical and 3 high findings, all marked corrected, but deployment/version correspondence is not independently verified. Contradiction: Current Steakhouse documentation presents an active multi-vault platform, contradicting the prior “advisory firm/no user-facing contracts” finding; current evidence supersedes it. Architecture-level audit evidence exists, but deployment-level admin and proxy verification remains unavailable.

Evidence (6)

audit

unverified

Cantina — Box audit report dated 2026-01-06. Scope and findings: Not verifiable as of 2026-09-05 because the referenced PDF was not retrievable independently. The protocol documentation lists this as a separate Cantina audit. Deployed-code coverage: Not verifiable as of 2026-09-05.

Auditor
Cantina
Report date
2026-01-06
Scope
Box vault infrastructure; exact reviewed commit not verifiable as of 2026-09-05
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Cantina — “Steakhouse Financial: Vault v2 Supervisor”. Publication date: Not verifiable as of 2026-09-05; engagement: 2026-02-10–2026-02-11. Scope: vault-v2-supervisor at commit 34b2ec2. Deployed-code coverage: Not verifiable as of 2026-09-05; no independent bytecode match performed.

Auditor
Cantina (Alireza Arjmand)
Report date
2026-02-11
Scope
Steakhouse-Financial/vault-v2-supervisor; commit 34b2ec2
Findings
Summary: Critical 0; High 0; Medium 0; Low 3; Informational 8. Low findings included calldata canonicalization, one-by-one guardian revocation, and vault-tracking DoS. The page later states 13 informational findings, a report-internal count contradiction.
Fix status
Low: 2 fixed, 1 acknowledged. Informational summary: 7 fixed, 1 acknowledged; detailed page count is inconsistent.
Evidence (1)

audit

one source

Cantina — “Steakhouse: Leveraged Lending ERC4626 Yield Vault”. Publication date: Not verifiable as of 2026-09-05; engagement: 2025-11-03–2025-11-14. Scope: Box repository. Deployed-code coverage: Not verifiable as of 2026-09-05; reviewed commit-to-deployment bytecode was not independently matched.

Auditor
Cantina (Jonatas Martins, r0bert, Eric Wang)
Report date
2025-11-14
Scope
Steakhouse-Financial/box; leveraged-lending ERC-4626 vault
Findings
Critical 0; High 1; Medium 0; Low 13; Informational 14; Gas 7. High finding: share-price manipulation through Box.flash() callbacks.
Fix status
High finding fixed and Cantina-verified. Low: 5 fixed, 8 acknowledged. Informational: 8 fixed, 6 acknowledged. Gas: 7 fixed.
Evidence (1)

audit

one source

Cantina — “Web3 Security Review: Steakhouse Oracles Audit”. Publication date: Not verifiable as of 2026-09-05; engagement: 2025-03-20–2025-03-21. Scope: Steakhouse-Financial/steakhouse-oracles. Deployed-code coverage: Not verifiable as of 2026-09-05; reviewed repository/commit-to-deployment bytecode was not independently matched.

Auditor
Cantina (researchers Om Parikh, Eric Wang)
Report date
2025-03-21
Scope
Steakhouse-Financial/steakhouse-oracles; review period 2025-03-20–2025-03-21
Findings
Critical 0; High 0; Medium 0; Low 1; Informational 2. Low finding: unsafe uint256-to-int256 cast.
Fix status
Low finding fixed and Cantina-verified. Both informational findings acknowledged.
Evidence (1)

audit

one source

A separate Cantina report exists for Steakhouse Oracles, not the vault contracts. It records 1 low-severity finding (fixed) and 2 informational findings (acknowledged), but it does not provide the requested vault-contract audit coverage for Steakhouse Financial. The report states the low-risk issue was fixed in commit 39b5ad5bc9444377c459486e920865b32d2518fd.

Because the provided results do not include the deployed address, the audited commit range, or a bytecode-match confirmation against live Ethereum deployments, coverage of deployed code is not verifiable as of 2026-08-30.

Auditor
Cantina Security / reviewers Om Parikh and Eric Wang
Report date
2026-08-30
Scope
Steakhouse Oracles (not the vault contracts); exact deployed-code coverage not verifiable
Evidence (2)

audit

two sources

Smart Contract Audit

  • Steakhouse Box Smart Contracts. As-of data: 2026-09-04 (web, not on-chain). Bytecode / deployed-code match: Not verifiable as of 2026-09-04. Report date & scope
  • Report page lists an audit of Steakhouse Box smart contracts; focus areas include access control, integration with lending protocols, permissionless winddown functions, slippage protection, timelock mechanics, shutdown procedure, and functional correctness.
  • No explicit chain listing in the snippet, but Steakhouse core products are on Ethereum; chain attribution beyond that is Not verifiable as of 2026-09-04. Severity & findings (from public summary)
  • Critical: 0 mentioned in the summary.
  • High: issues related to read-only reentrancy in swapper selection during winddown, allowing value extraction from the Box; fixed in second version.
  • Medium: insufficient input validation in funding modules, including potential locked funds in FundingAave during winddown and unsanitized collateralToken in FundingMorpho.depledge().
  • Low / Informational: at least one correctness issue (Box cannot receive native currency) and other “correctness improvable” topics; remaining topics rated high security. Fix status
  • ChainSecurity states the identified high- and medium-severity issues “were addressed and fixed in the second version of the codebase”; security regarding the covered subjects is assessed as good.
  • Residual risk: at least one correctness-related limitation is explicitly noted as improvable (Box cannot receive native currency). Coverage of deployed code (bytecode-match)
  • Whether this exact audited version corresponds to currently deployed Ethereum contracts cannot be verified without on-chain comparison. Status: Not verifiable as of 2026-09-04. Independence note
  • This audit is an external, independent security review published on ChainSecurity’s own site, not a marketing-only claim from Steakhouse. Other audits (context, not fully structured here)
  • DefiCare lists multiple audits for “Steakhouse Financial” (ChainSecurity 01‑12‑2025; several Cantina audits with dates and severity tallies). These entries confirm existence of additional audits but do not, in the snippet, tie specific reports to exact contract addresses or chains; bytecode-match and deployed-coverage for those is Not verifiable as of 2026-09-04.
  • Steakhouse marketing materials claim Spearbit audits of vault contracts and Cantina audits of Supervisor v2, but these are unverified marketing claims until cross-checked against primary auditor publications and on-chain data.
Auditor
ChainSecurity
Report date
2025-12-01
Scope
Steakhouse Box smart contracts: access control; integration with lending protocols; permissionless winddown functions; slippage protection; timelock mechanics; shutdown procedure; functional correctness[7].
Findings
ChainSecurity Steakhouse Box audit: Critical 0; High ≥1 (read-only reentrancy in swapper selection during winddown enabling value extraction); Medium ≥2 (insufficient input validation causing possible fund lock in FundingAave during winddown; FundingMorpho.depledge() not sanitizing collateralToken); Low/Info: at least one correctness issue (Box cannot receive native currency) plus other minor topics with high overall security ratings[7][1].
Fix status
High and medium issues reported as fixed in the second version of the codebase; low/informational correctness limitation (Box cannot receive native currency) remains acknowledged as improvable but not necessarily fully remediated[7].
Evidence (4)

audit

one source

ChainSecurity — “Code Assessment of the Box Smart Contracts”. Published 2025-12-15. Scope: Box contracts, factories, adapters, FundingAave and FundingMorpho at reviewed commits through final version 80a5779f; Morpho/Aave third-party code and oracle implementation excluded. Deployed-code coverage: Not verifiable as of 2026-09-05; no independent bytecode match performed.

Auditor
ChainSecurity / Decentralized Security AG
Report date
2025-12-15
Scope
Box smart contracts; final reviewed commit 80a5779f326af2a99fb9ca617701c7057b2f70ff
Findings
Critical 0; High 3; Medium 7; Low 11.
Fix status
High: 3 corrected. Medium: 5 corrected, 2 risk-accepted. Low: 8 corrected, 1 specification changed, 2 risk-accepted.
Evidence (1)

audit

one source

Published report: Cantina — Steakhouse: Leveraged Lending ERC4626 Yield Vault. Engagement: 2025-11-03–2025-11-14. Scope repository: box. Deployed-code coverage: Not verifiable as of 2026-09-06; reviewed-code-to-deployment bytecode match not independently performed.

Auditor
Cantina
Report date
2025-11-14
Scope
Steakhouse-Financial/box; leveraged-lending ERC-4626 vault.
Findings
Critical 0; High 1; Medium 0; Low 13; Informational 14; Gas optimizations 7. High finding: share-price manipulation through Box.flash() callbacks.
Fix status
High: fixed and Cantina-verified. Low: 5 fixed, 8 acknowledged. Informational: 8 fixed, 6 acknowledged. Gas: 7 fixed.
Report url
https://cantina.xyz/portfolio/72386eb5-5b22-4f7f-b2c0-f0556904d95d
Report id
doc:4c631186d94cfaf9
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published report: Cantina — Web3 Security Review: Steakhouse Oracles Audit. Engagement: 2025-03-20–2025-03-21. Scope repository: steakhouse-oracles. Deployed-code coverage: Not verifiable as of 2026-09-06; no independent bytecode match performed.

Auditor
Cantina
Report date
2025-03-21
Scope
Steakhouse-Financial/steakhouse-oracles; review period 2025-03-20–2025-03-21.
Findings
Critical 0; High 0; Medium 0; Low 1; Informational 2. Low finding: unsafe uint256-to-int256 cast.
Fix status
Low finding fixed and Cantina-verified. Both informational findings acknowledged.
Report url
https://cantina.xyz/portfolio/715b51f9-d8a3-4a45-8b5e-41654af28c2f
Report id
doc:f8d91bdb3af8a253
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Published report: Cantina — Steakhouse Financial: Vault v2 Supervisor. Engagement: 2026-02-10–2026-02-11. Reviewed vault-v2-supervisor at commit 34b2ec2. Deployed-code coverage: Not verifiable as of 2026-09-06; no independent bytecode match performed.

Auditor
Cantina / Spearbit
Report date
2026-02-11
Scope
Steakhouse-Financial/vault-v2-supervisor; commit 34b2ec2
Findings
Critical 0; High 0; Medium 0; Low 3; Informational count is contradictory: summary states 8, while the detailed report states 13. Low findings concerned calldata canonicalization, one-by-one guardian revocation, and vault-tracking DoS.
Fix status
Low: 2 fixed, 1 acknowledged. Informational summary: 7 fixed, 1 acknowledged; detailed-count contradiction unresolved.
Report url
https://cantina.xyz/portfolio/bb64fc5b-8bb1-4c9c-ae4f-3ece633cdf4d
Report id
doc:ff33d4903705de74
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Steakhouse Financial states that its vault contracts were audited by Spearbit and that the reports are public. The protocol’s own site is the only source in the provided results that names the auditor for the vault contracts, so this should be treated as an unverified marketing claim until corroborated by an independent audit report. The provided results do not include the Spearbit report itself, so the audit date, exact scope, finding counts, fix status, and deployed-code bytecode match are not verifiable as of 2026-08-30.

Auditor
Spearbit
Report date
2026-08-30
Scope
Vault contracts (per protocol claim); exact audited code/deployments not verifiable from provided results
Evidence (2)

Team & Reputation

founders

two sources

Steakhouse Financial appears to be a small, public, crypto‑native advisory and vault curator, with identifiable founders and a mixed onshore/offshore footprint, rather than a purely anonymous web front. Founders & key people

  • Multiple sources name Mark Phillips and Sébastien Derivaux as co‑founders, alongside Adrian Cachinero Vasiljevic.
  • A profile of Mark Phillips describes him as co‑founder of Steakhouse Financial and Grove Labs, and as an advisor to MakerDAO/Sky, indicating prior involvement in major DeFi credit and stablecoin infrastructure.
  • Derivaux is publicly active in DeFi research and MakerDAO governance; listings refer to him as “Chef & Co‑Founder”.
  • RootData and Steakhouse’s own “People” page list additional staff such as Alexis (DeFi Risk Manager), Kevin Chan, and other “Chefs”, plus regional leads like Jiyeon Park (APAC Lead). Public vs. anonymous; prior track record
  • Founders and several team members use real names, with public LinkedIn and media appearances (e.g., podcasts, conference keynotes).
  • They have prior history with MakerDAO/Sky and advisory work for major protocols and institutions (Coinbase, Lido, Ethena), suggesting sustained engagement in DeFi risk and treasury work rather than short‑lived yield schemes.
  • No credible reports of protocol‑level hacks or rug pulls related to Steakhouse itself were found. Not verifiable as of 2026‑09‑04. Jurisdiction, offices, onshore/offshore
  • Corporate and social profiles state Zug, Switzerland as the main location, with an HQ listing there and an additional corporate address in Grand Cayman, Cayman Islands.
  • This points to a Swiss‑based financial tech company with an offshore Cayman entity, consistent with typical DeFi/tokens structures.
  • Physical office details (exact premises, lease, staff on‑site) are not independently verifiable from current data. Not verifiable as of 2026‑09‑04. Real business vs. web front (reality check)
  • Steakhouse is described by third parties (Morpho, Binance report, LinkedIn article) as a vault curator and risk advisory managing or curating multi‑billion dollar non‑custodial stablecoin deposits on Morpho and across chains, with a team “less than 20 people”.
  • They publish detailed risk‑management documentation and rating frameworks, and maintain an insights site (“Kitchen”) with ongoing research output, which is atypical for purely marketing‑driven fronts.
  • The combination of named founders, visible staff, multi‑platform presence, and external partners (Morpho, MakerDAO/Sky, exchanges) supports the view that this is a functioning advisory/curation business, not just a website. That said, all operational claims (TVL, AUM, client list) rely on aggregators and protocol marketing, and thus remain unverified marketing claims unless checked on‑chain. Sources
Evidence (13)

general reputation

two sources

Steakhouse Financial appears to have a generally positive reputation in DeFi as an institutional vault curator and advisory firm focused on stablecoin infrastructure, with public positioning around non-custodial vault design, risk curation, and research. Publicly identified founders/co-founders include Sébastien Derivaux, Adrian Cachinero Vasiljevic, and Mark Phillips, and multiple third-party profiles and interviews corroborate this team composition. The firm also appears to work with prominent crypto protocols and organizations such as Maker/Sky, Coinbase, Lido, Ethena, and Morpho, which supports a credible industry standing.

On audits and security, Steakhouse states that its Supervisor v2 contracts were made public on GitHub and audited by Cantina, and third-party coverage from Ether.fi references a security upgrade audit and the associated contracts repository. I did not find credible reporting of fraud, rug-pull allegations, insolvency, sanctions, or formal regulatory actions tied to Steakhouse Financial itself. No sanctions or court/regulatory issues were surfaced in the gathered sources.

Key criticisms or unresolved concerns are more limited and mostly structural rather than allegation-driven: as an onchain curator, Steakhouse’s risk role depends on the soundness of its underwriting, governance design, and offchain judgment, and the web results do not provide an independent, exhaustive review of those controls. Some descriptions are self-published or promotional, so items like team bios, product claims, and operational scope should be treated as partially unverified marketing unless corroborated elsewhere. Not verifiable as of 2026-09-04: a complete independent assessment of reputational controversies, hidden liabilities, or the full audit history.

Evidence (9)

Economy

TVL: $3.1B

model

two sources

Economic model — Ethereum

  • Strategy/assets: Curated ERC-4626/Morpho vaults accept WETH, stablecoins and selected RWA/crypto assets. Capital is allocated primarily to Morpho lending markets against underwritten collateral; Prime targets liquid/blue-chip collateral, while High Yield accepts longer-tail or exotic collateral.
  • Yield source/profile: Lending interest and repo/carry spreads are the principal sources. Returns are predominantly organic market yield; incentives/subsidies cannot be quantified from the available evidence. The strategy is generally market-neutral/credit-oriented rather than directional, but collateral, oracle, liquidation and stablecoin risks create indirect market exposure.
  • Leverage/looping/restaking/external exposure: Some product documentation describes leveraged carry/looping as a possible Turbo strategy, but no Ethereum-wide deployed leverage ratio is verifiable. Restaking is not established by the reviewed evidence. External exposure includes Morpho and, for some products, RWA/tokenized-credit collateral.
  • Withdrawals/lock-ups: Withdrawals are vault-liquidity dependent. Morpho markets commonly maintain only approximately 10% immediately available liquidity, with reallocation systems intended to source liquidity during stress. Prime governance timelock: 7 days; High Yield: 3 days. These are strategy-change timelocks, not necessarily depositor withdrawal lock-ups.
  • Fees/gates/revenue: Fees vary by vault. A verified Ethereum ETH Prime Instant example shows a 5% performance fee and 0% management fee; some current High Yield vaults typically charge 10%. Protocol revenue is curator-permitted yield/fee capture, but Ethereum-only revenue is Not verifiable as of September 6, 2026.
  • TVL/APY: Dune on-chain verification is unavailable: Not verifiable as of September 6, 2026. DeFiLlama currently reports $3.014B total TVL, 3 pools and 5.89% average supply APY, but also reports 10 chains and Base as largest; this conflicts with the requested Ethereum-only scope and cannot be treated as Ethereum TVL. Product-level Ethereum TVL, historical APY volatility and sustainability are Not verifiable as of September 6, 2026. Contradiction: DeFiLlama’s current aggregate figures and chain attribution conflict with the supplied Ethereum scope; no Dune query is available to resolve the discrepancy. Prior example.com evidence is unusable. Fields: organic_yield_pct=null; leverage_ratio=null
Evidence (5)

reserves

two sources

Assessment (as of September 6, 2026): Steakhouse Financial is a vault curator, not an issuer with a separately disclosed proprietary reserve or treasury. User assets are held in Morpho/related vault contracts; therefore protocol TVL should not be treated as Steakhouse-owned reserves. DefiLlama reports approximately $3.031B total TVL, including $866.61M on Ethereum; this is an analytics estimate, not a reserve attestation. Addresses / size: No single Steakhouse treasury address was identified.

Ethereum vault examples include Steakhouse Prime Instant USDC: 0xbeef088055857739C12CD3765F20b7679Def0f51, showing approximately $95.98M deposits on the Morpho interface, and legacy Steakhouse USDC Ethereum 0xBEEF01735c132Ada46AA9aA4c54623cAA92A64CB. These are depositor-vault addresses, not proprietary treasury wallets. Composition: Vault composition is strategy-specific and may include USDC, ETH/wstETH, tokenized BTC, and tokenized Treasury/RWA assets such as USYC or wUSDM. The precise aggregate composition across Ethereum vaults is Not verifiable as of September 6, 2026 without a reproducible on-chain query. Custody and control: Steakhouse documents the architecture as non-custodial: users retain economic ownership, while Morpho vaults and adapters hold or deploy assets.

Controls include timelocks, guardian vetoes, shutdown/unwind mechanisms, and role-based permissions. Steakhouse states that owner control commonly uses a five-key Safe multisig, but the specific signers and current role configuration require per-vault verification. Reserve policy / attestations: No dedicated reserve policy, proof-of-reserves report, balance-sheet liabilities disclosure, or financial attestation was located. Smart-contract audits exist, including ChainSecurity’s Box audit, but these assess code—not asset sufficiency or liabilities. > Contradiction / data-quality finding: The previously recorded $5.12B “noncustodial assets supplied” figure is not corroborated by the current DefiLlama snapshot of $3.031B TVL; methodology and timing differ.

The on-chain figure is unavailable in this run, so neither number should be treated as a verified reserve balance. Dune on-chain balances: Not verifiable as of September 6, 2026. Structured fields: liquid_reserves_usd: null; liabilities_usd: null

Evidence (5)

tokenomics

two sources

Steakhouse Financial does not appear to have a single native protocol token for the Ethereum vault-curation business described in the sources; the core product is a vault curator / yield infrastructure business, not a token-led governance protocol. The web results instead show vault share tokens such as steakcUSDC and vaults like Steakhouse ETH, which function as receipt tokens for specific vault positions rather than a general governance asset. Because no protocol-native governance token was verifiable from the gathered sources, the requested tokenomics fields are Not verifiable as of 2026-09-04: native token name/ticker and contract address, total vs circulating supply, market cap and FDV, token utility/governance role, revenue share/buybacks/burns/staking rewards, emissions schedule, unlock schedule, allocations to team/investors/treasury/community, top-holder concentration/insider wallets, and mint/blacklist/fee-switch controls.

The only token-like asset explicitly described in the results is steakcUSDC, which is a Morpho vault share token on Ethereum with vault-share dynamics rather than capped-supply tokenomics; the source says supply expands on deposit and contracts burn shares on redemption, and that it is a receipt token for yield-bearing cUSDC rather than a staking/governance token. That means there is no verifiable protocol-wide emissions or unlock schedule for Steakhouse Financial itself from the sources gathered. On listings and liquidity, the sources only support that Steakhouse’s Ethereum vaults are live on Morpho and are tracked by aggregators; there was no verifiable DEX liquidity depth or major exchange listing for a native Steakhouse token in the gathered material.

If you meant a specific vault share token rather than the Steakhouse Financial protocol itself, that would need to be assessed separately.

Evidence (7)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Steakhouse Financial on Ethereum, a Bitcoin drop below $10,000 would be a severe tail-risk stress event, not a base case. Independent market commentary consistently frames $10,000 BTC as requiring a synchronized macro shock—global liquidity contraction, broad risk-asset deleveraging, ETF outflows, and a confidence shock—rather than a routine drawdown. Because Dune/on-chain verification is unavailable in this run, the protocol-specific impact is Not verifiable as of 2026-09-04.

I cannot confirm Steakhouse Financial’s Ethereum exposures, collateral composition, or liquidation thresholds from raw on-chain data here. Operationally, the main risks to an Ethereum yield protocol in a BTC-$10k shock would be:

  • Risk-asset contagion: correlated selloffs can hit ETH and other collateral simultaneously, reducing vault equity and governance/token valuations.
  • Liquidity stress: wider spreads and thinner DEX/CEX liquidity can increase slippage on rebalancing, hedging, or emergency unwinds.
  • Collateral haircuts / deleveraging: if the protocol uses BTC-linked or correlated collateral anywhere in its stack, sharp mark-to-market losses could trigger margin pressure or liquidation cascades.
  • Confidence shock: even without direct BTC exposure, users may redeem from yield products during market panic, stressing withdrawals and strategy rebalancing. The key open question for Steakhouse Financial is whether any Ethereum strategies have direct or indirect BTC correlation through wrapped BTC, lending markets, LP positions, or counterparty exposure. That cannot be verified from the available sources. If you want, I can next produce a protocol-risk memo template for Steakhouse Financial with sections for: exposure map, liquidation pathways, withdrawal risk, and stress-test assumptions.
Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

For Steakhouse Financial on Ethereum, a 20% depeg stress for the largest collateral is Not verifiable as of 2026-09-04 with the provided web results. The search results include general stress-test methodology and unrelated DeFi examples, but they do not provide protocol-specific collateral composition, exposure sizing, or a quantified 20% depeg impact for Steakhouse Financial. The closest relevant evidence is that depeg stress analysis is typically expressed by revaluing the collateral basket under a shock scenario and comparing stressed collateral value to debt or margin requirements, but no source here maps that framework to Steakhouse Financial’s Ethereum positions.

The DeFi-specific result about Aave shows how concentrated depeg risk can be in looping markets, yet it is for Aave, not Steakhouse Financial, so it cannot be used as a substitute. If you want, I can still help structure the exact analysis you need, but the missing inputs are the protocol’s Ethereum collateral breakdown, the largest collateral token, and the debt or liabilities tied to that collateral. Without those, any numeric loss estimate would be speculative.

Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Steakhouse Financial is primarily a fixed-rate / structured lending and vault manager for DeFi, closely tied to MakerDAO and other collateralized lending markets. On-chain granular data is Not verifiable as of 2026-09-04. Below is a generic institutional stress map for “top counterparty insolvent” across Steakhouse-like activities on Ethereum. ### 1.

Counterparty type: Borrower in a structured credit / RWA facility

  • Loss path • Borrower defaults → collateral liquidated via protocol-defined auction or AMM routes; shortfall emerges if collateral value < debt. • Any junior / first-loss tranche absorbs initial loss; then senior lenders.
  • Who absorbs itEquity / junior tranche LPs of the facility. • If still undercollateralized, senior lenders (Steakhouse-managed vault depositors / linked protocols such as Maker, depending on structuring).
  • Compensation • Junior investors are *not* compensated; the loss is their contractual risk. • No automatic insurance unless an explicit on-chain cover or off-chain policy is wired into the structure (unverified marketing claim if only stated in docs).
  • Smart-contract impact path • Trigger: missed payment / covenant breach → facility controller marks position in default. • Liquidation functions called on collateral vaults; debt accounting updates; LP token value of junior tranche drops; senior tranche claims reduced proportionally. • Potential knock-on: increased utilization / bad-debt flags in connected protocols (e.g., Maker vault RWA exposure). ### 2. Counterparty type: DeFi protocol used as yield source (e.g., lending / AMM where Steakhouse deploys)
  • Loss path • External protocol suffers insolvency (oracle failure, hack, bad debt). • Steakhouse-managed vault tokens representing that exposure depeg / go to impaired value.
  • Who absorbs itVault depositors / tranche holders exposed to that strategy, according to waterfall. • Any explicit buffer / reserve in the strategy absorbs first, then user capital.
  • Compensation • Only if external protocol has a functioning insurance / backstop fund or DAO bailout; this is uncertain and case-specific (Not verifiable as of 2026-09-04).
  • Smart-contract impact path • Price or accounting oracle for strategy tokens marks down NAV. • Rebalancing / withdrawal functions may revert or incur slippage. • Strategy vaults show loss; withdrawals settle at impaired value. ### 3. Counterparty type: Off-chain servicer / SPV in RWA structures
  • Loss path • SPV insolvency → cashflows to the on-chain facility stop, recoveries handled in court.
  • Who absorbs it • On-chain investors (junior first, then senior), per legal docs; DAO-level exposures if Maker or others are senior lenders.
  • Smart-contract impact • Contracts usually enter prolonged “non-paying” state; no direct on-chain resolution. • Accounting oracles may mark positions to recovery value; losses crystalize at vault level; governance may later decide write-offs / haircuts.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

one source

For the specific stress scenario “committed fraud by the DAO or owners”, I found no verifiable evidence that Steakhouse Financial’s DAO or owners committed fraud. The available sources instead describe a domain/DNS phishing incident affecting the website, while stating that vaults, smart contracts, and depositor funds were not affected. Because the user asked for a fraud-by-insiders scenario and the web evidence does not substantiate that premise, the correct assessment is Not verifiable as of 2026-09-04.

What *is* verifiable is that Steakhouse reported a March 30 domain-control compromise where an attacker changed DNS records to serve a malicious frontend, but Steakhouse said this was not a vault or contract compromise and that existing user funds were never at risk. An independent report likewise said deposits and contracts were unaffected and that the incident primarily created phishing risk for users interacting with the compromised website. So, for risk modeling, treat insider fraud by DAO/owners as unconfirmed, and treat frontend/domain compromise as the observed stress case instead.

Evidence (2)

stress scenario - primary yield source negative 30d,

two sources

Steakhouse Financial’s documentation says its vaults are yield-curated, but the provided web results do not verify which specific Ethereum vault is the primary yield source or whether its 30-day yield is negative. Because on-chain checks are unavailable in this run, the 30-day yield stress outcome is Not verifiable as of 2026-09-04. What can be said from the available sources is that Steakhouse describes its service as deploying stablecoins into risk-curated DeFi vaults, and its risk-management page is the relevant place to inspect stress assumptions and source attribution.

The search results also indicate Steakhouse’s vaults are primarily lending-based, with yield coming from borrower interest, but that is only a high-level description and not a verified 30-day performance figure. For a stress scenario, the conservative interpretation is:

  • if the primary yield source turns negative over 30 days, vault net APY can compress sharply or go below zero;
  • management response would typically depend on whether the vault has diversified yield legs, floating-rate lending income, or fee offsets; and
  • without chain data, the size of any loss, redeemability impact, or chain-specific exposure cannot be quantified. The only direct protocol-specific quantitative claim in the results is a marketing statement that Steakhouse vaults processed $108.5 million in liquidations on February 5, 2026, while maintaining full redeemability across nearly $1.7 billion in deposits. That is useful context, but it does not establish current 30-day yield resilience or negative-yield behavior.
Evidence (3)

Governance & Legal

governance

one source

Assessment (as of September 13, 2026): Governance is company-controlled with a depositor veto layer, not a fully autonomous DAO. Carniceria Tropical Inc., a Panama corporation and wholly owned subsidiary of Steakhouse Financial Ltd., states that it exclusively develops/operates the vault smart contracts, interfaces, and related services. The underlying Morpho protocol is not controlled by Steakhouse. Control map: Steakhouse’s Owner multisig controls ownership transfers, curator assignment, fee recipients, and delegation of downstream powers.

Curators can configure allocators, funding modules, whitelisted tokens/oracles, slippage, and submit timelocked changes; allocators can execute reallocations, swaps, borrowing, and repayments. The Owner multisig is documented as requiring 5 signers, but the total signer set, identities, and independence are Not verifiable as of September 13, 2026. Proposal process / DAO reality: Critical actions are queued through the vault timelock. Aragon Guardian DAOs representing vault share/depositor holders can veto queued actions and trigger shutdown/recovery.

Prime vaults document a 7-day / 168-hour delay; High Yield vaults document 3 days / 72 hours. Thus, the DAO has a meaningful veto role but does not generally originate or control upgrades, parameters, or operator appointments; classify DAO governance as false. Risk finding: A 5-of-N Owner multisig can delegate operational authority without a token-holder governance vote. Because downstream roles can allocate, borrow, and change supported assets/modules, admin_can_drain = true in the broad risk sense, although timelocks and Guardian vetoes can delay or block many actions.

A universal emergency bypass is Not verifiable as of September 13, 2026; Box documentation notes deployment-specific timelock initialization and shutdown/winddown powers. Company details: Operator: Carniceria Tropical Inc., Panama; reported RUC/registry folio: 155756471-2-2024 / 155756471, not independently confirmed from the official registry. Parent: Steakhouse Financial Ltd., Cayman Islands, registration CO-399520. Directors of the operator and applicable Terms-of-Service governing directors are Not verifiable as of September 13, 2026. Dune checks: Voting concentration, top holders, signer count/identities, and contract-role balances: Not verifiable as of September 13, 2026 (Dune unavailable).

Timelock
Yes
Multisig threshold
5
Admin can drain
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Steakhouse Financial appears to be a DeFi-focused advisory / structuring firm rather than an on-chain yield protocol with a distinct token; it is closely associated with the team behind Angle Protocol and the “Steakhouse” stablecoin/treasury advisory brand. Its activities are largely off-chain advisory and governance participation, with some on-chain involvement via protocol-controlled positions and multisigs. Entity & jurisdiction Open-source and media references identify *Steakhouse Financial* as a research/advisory entity working with Angle, Liquity, and MakerDAO, but do not provide a clear, confirmed corporate registration record (e.g., LLC, SAS, Ltd) or domicile. As of 2026-09-04 this is Not verifiable as of [2026-09-04] from independent corporate registries via web search. Legal structure & ToS / user restrictions Steakhouse operates mainly through governance forums, research posts, and GitHub/Notion-style documentation rather than a consumer-facing app with explicit Terms of Service.

No standalone Steakhouse-branded front-end with published ToS, geographic restrictions, or retail user onboarding could be located. Not verifiable as of [2026-09-04] whether there is any hidden or private ToS applicable to institutional counterparties. KYC / AML & user classification There is no evidence that Steakhouse Financial runs a custodial exchange, fiat on/off-ramp, or retail wallet; rather, it provides structuring and risk/treasury advisory to DAOs (e.g., Maker, Angle). In that role, KYC/AML obligations would typically sit with counterparties (centralized exchanges, custodians, OTC desks) rather than the research entity itself. No explicit KYC/AML program or policy statement is published. Not verifiable as of [2026-09-04]. Regulatory warnings, enforcement, court cases, sanctions Searches across:

  • Regulatory databases (e.g., SEC, ESMA summaries, major national regulators)
  • Sanctions lists (e.g., OFAC SDN summaries, EU consolidated lists)
  • Court case reporting and legal news found no entries naming “Steakhouse Financial” or its key individuals as subjects of enforcement actions, formal warnings, or sanctions. Accordingly, as of 2026-09-04:
  • active_enforcement: false (no regulator action identified against Steakhouse Financial itself).
  • sanctioned: false (entity not found on major sanctions lists; compliance blocking of third-party sanctioned addresses on protocols it advises is out of scope). Data protection / privacy risk Given the absence of a retail-facing app, Steakhouse’s direct data-protection surface for end users appears limited; most risk exposure is indirect, via governance influence on protocols (e.g., collateral strategies, treasury allocations) rather than custody of user data or funds. Any actual data-processing practices remain Not verifiable as of [2026-09-04]. Key institutional takeaway From a DeFi risk perspective, Steakhouse Financial should be treated primarily as an advisory/governance actor. Legal and regulatory risk is therefore largely *indirect*—channelled through the protocols and entities it advises—rather than through a distinct, regulated financial institution entity of its own, which remains unconfirmed.
Sanctioned
No
Entity
Steakhouse Financial (advisory / research entity; precise corporate registration Not verifiable as of [2026-09-04])
Evidence (2)

legal registries

two sources

Legal entity per GLEIF: Steakhouse Financial Ltd (LEI 254900E5M86PI4TIPQ04; jurisdiction KY; registration ACTIVE). OFAC SDN screening of 'Steakhouse Financial': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Steakhouse Financial
Entity
Steakhouse Financial Ltd
LEI
254900E5M86PI4TIPQ04
Jurisdiction
KY
Entity status
ACTIVE
Sanctioned
No
Evidence (4)

Stability

stability

unverified

Steakhouse Financial does not appear to issue its own stablecoin; it operates noncustodial yield vaults and its documented products are denominated in third-party stablecoins such as USDC. A depeg event for the stablecoin used by Steakhouse is not verifiable as of 2026-09-06, so depeg_count, last_depeg_date, and max_depeg_pct remain unknown. The protocol’s observed stablecoin exposure is centered on USDC, with some products also supporting USDT, PYUSD, USDG, EURC, and EURCV.

Own stablecoin
No
Stablecoin ids
  • USDC
Evidence (2)

Risks & Strengths

risks

one source

Steakhouse Financial’s main risks arise from its modular vault architecture, dependence on Morpho/Aave and external oracles, privileged governance, and liquidity constraints during market stress. The December 2025 ChainSecurity review corrected all three high-severity findings but left two medium-severity findings risk-accepted; on-chain TVL, exposure, and current contract-state checks are Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract and integration failureBox, adapters, funding modules, Morpho, Aave, or token interactions could misaccount, lock, or lose depositor assets. The audit scope excluded third-party protocols and oracle implementation.HighMediumExternal ChainSecurity audit; modular whitelists; slippage limits; timelocks; shutdown and permissionless winddown.Medium
Privileged governance compromiseOwner, curator, guardian, allocator, feeder, and skim roles can change strategy, pricing, liquidity, or asset routing. A compromised role could cause loss or denial of service.HighMediumRole separation, delayed critical actions, Aragon guardian veto, whitelists, and shutdown controls.Medium
Oracle and valuation manipulationIncorrect prices can misprice shares, enable bad allocations, distort liquidations, or create arbitrage. Oracle failure can also temporarily DOS the vault.HighMediumMetaOracle primary/backup feeds, deviation checks, timelocked switching, and oracle-based slippage protection.Medium
Underlying credit and market stressCollateral depegs, borrower defaults, bad debt, liquidation shortfalls, or volatile high-yield collateral can impair NAV, especially in Turbo/High Yield products.HighMediumCollateral risk framework, LLTV limits, asset/platform/market ratings, market monitoring, and automated/manual killswitches.Medium
Liquidity and withdrawal mismatchMorpho markets commonly target 90% utilization, leaving roughly 10% immediate liquidity; congestion, utilization spikes, term assets, or mass withdrawals may delay or impair exits.HighMediumLiquidity sleeves, automated reallocation, idle-market deployment, withdrawal monitoring, and winddown procedures.Medium
Evidence (5)

strengths

two sources

Steakhouse Financial’s top strengths are: institutional-grade noncustodial vault infrastructure, strong risk curation, blue-chip collateral and liquid-market focus, multi-chain / multi-product reach, and auditability with onchain transparency. Its materials describe it as a DeFi protocol for funds, treasuries, fintechs, and asset managers that deploys capital into risk-curated yield vaults, mainly on Morpho and related lending markets. The protocol emphasizes that users keep custody while Steakhouse selects acceptable collateral and markets, sets exposure and loan-to-value limits, and applies a consistent risk framework rather than simply chasing the highest APY.

Its product pages also highlight Prime and other risk-rated strategies, custom mandates, and programmatic access, which support different treasury and fund requirements. Steakhouse further claims it is live on Ethereum and other chains, with unified credit strategies and non-custodial vaults across multiple networks. Finally, the protocol states that its vault contracts are publicly auditable and that Spearbit has audited the vault contracts, supporting security and transparency.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 18 two independent sources, 18 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-29.