Upshift

Green · 71/100

Executive summary

Upshift is an institutional DeFi vault and yield-aggregation protocol offering ERC-4626 tokenized vaults across 30+ chains, including Ethereum, Hyperliquid L1, and Monad; it scores 59/100 (orange band) with high data confidence (85/100) and a -10 penalty for unresolved incident remediation.

  • Security: Four auditors (ChainSecurity, Hacken, OtterSec, Sigma Prime) conducted 10+ audits; ChainSecurity found 3 high-severity issues (2 corrected, 1 risk-accepted) and 6 medium issues (all corrected) in the Core Vault; Hacken December 2025 report shows 4 medium and 2 low findings with 3 mitigated and 6 accepted; deployment-to-audit bytecode match is not verifiable as of September 2026.
  • Incidents: Two unresolved incidents: (1) February 2026 Velar/Mezo oracle manipulation drained ~$401k from the tBTC vault, affecting 61 depositors; a community recovery token (REKT) was launched but full reimbursement is not verified. (2) March 2026 Resolv key compromise caused USR depeg, impairing earnAUSD (~0.63% exposure, ~$315k), upUSDC (~6%, ~$700k), and coreUSDC (~1.92%); Gamma stated it would cover earnAUSD users, but upUSDC/coreUSDC settlement and final loss amounts remain unverified; status: remediation in progress.
  • Governance & custody: Operationally company- and multisig-controlled (4-of-6 proxy admin split across issuer, curator, and Upshift); no DAO token or binding on-chain governance identified; proxy upgrades have no timelock, while selected parameter changes use a claimed 24-hour timelock; vault assets are non-custodial and segregated, with MPC custody (Fireblocks/Fordefi) for operational keys and policy-engine restrictions on fund movement.
  • Top risks: Smart-contract/configuration failure (high-impact unknown vulnerabilities remain; deployment-specific audit coverage not verifiable); counterparty/protocol dependency (exposure to Aave, Uniswap, Ethena, Kelp, Lombard, and others varies by vault; current allocation percentages not verifiable); bridge/cross-chain risk (LayerZero, Stargate, CCIP dependencies; chain halt or bridge failure could strand assets); oracle/NAV risk (whitelisted feeds and max-change constraints reduce but do not eliminate stale-price or manipulation risk); withdrawal liquidity (vaults may gate or pause redemptions; exact per-vault buffer and lock-up terms not verifiable).
  • Strengths: Institutional-grade positioning with named partners (Kraken Institutional, Securitize); broad cross-chain and multi-strategy coverage (lending, LP, staking, basis, RWA, CeFi); ERC-4626 composability and non-custodial vault architecture; documented policy engine with whitelisted chains/protocols/tokens/functions and maker-checker transaction flow; MPC key management and role-separated controls (owner, operator, curator).
  • Unverified: Legal entity ambiguity (Privacy Policy names Fractal Network Ltd., BVI, but website footer shows August One SA, Geneva); no independent confirmation of $10M Series A led by Dragonfly; no public bug bounty program identified; current TVL composition, chain-by-chain exposure, vault-specific allocation percentages, and live collateralization not verifiable as of September 2026; homepage claims "500M+ total deposits" vs. DeFiLlama ~$401M TVL (scope/date mismatch); no protocol-owned treasury or reserve disclosure; no native governance token identified.
  • Recommended exposure: Limit to <5% of portfolio and treat as high-beta institutional DeFi infrastructure; favor vaults with transparent, overcollateralized DeFi strategies (e.g., Aave lending) over opaque CeFi or cross-chain basis plays; require vault-specific audit coverage, current allocation breakdown, and withdrawal-liquidity terms before allocation; monitor NAV daily and set stop-loss at -10% vault drawdown; avoid vaults with >20% exposure to any single counterparty or bridge; institutional allocators should verify custodian integration, KYC/KYB process, and legal/tax treatment with Upshift directly.
  • Open questions: (1) Obtain current vault-by-vault allocation ledger for Ethereum, Hyperliquid L1, and Monad, including protocol, token, leverage, and bridge exposure. (2) Verify deployment-to-audit bytecode match for all in-scope vaults and confirm remediation status for risk-accepted findings. (3) Clarify legal entity (Fractal Network Ltd. vs. August One SA), governing law, liability caps, and insolvency treatment. (4) Confirm final loss amounts and user reimbursement status for Velar/Mezo and Resolv incidents. (5) Request proof of $10M Series A, bug bounty program (if any), and protocol-owned treasury composition. (6) Verify exact timelock coverage (parameter changes vs. proxy upgrades), multisig signer identities, and emergency-function scope. (7) Obtain withdrawal-liquidity buffer size, gate/lock-up terms, and historical redemption processing time for target vaults.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 9 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 80 16.0 full audit within 365 days (latest 2025-09-24); auditor not in top-20 -20
Incidents 20% 100 20.0 3 open incident(s), $401,000 at risk (2 with unknown loss) = 0.1% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 2 0.4 TVL $419,991,826 = 2% of reference ($17,538,184,136)
Data confidence 85 7/7 critical categories; 12/44 verified facts; 43/44 fresh (180d)

Identification

protocol identification

two sources

Upshift is an institutional DeFi vault / yield protocol and “on‑chain capital allocator”, offering ERC‑4626‑style tokenized vaults and multi‑strategy yield products for fintechs, asset managers and retail depositors. Identification

  • Name: Upshift / Upshift Finance.
  • Category: DeFi vault / yield aggregator using ERC‑4626 tokenized vaults and multi‑asset vaults; institutional lending and curated DeFi/CeFi strategies.
  • Main websites:
  • Corporate/infrastructure: upshift.finance (institutional vault infra).
  • Consumer protocol: upshiftfinance.org (institutional DeFi yield protocol).
  • Separate “app” front‑end referenced by aggregators (app.upshift.finance) — treated as secondary.
  • Docs: docs.upshift.finance (architecture, risk framework, curator docs, API).
  • Launch date: Not explicitly stated; third‑party analysis cites TVL and activity “as of latest data” in 2025, with architecture already described as mature. Exact launch block/time is Not verifiable as of 2026‑09‑04. Chains (focus: Ethereum, Hyperliquid L1, Monad)
  • Docs list support for: Ethereum, Monad, HyperEVM, Arbitrum, Avalanche, Base, BNB, Citrea, Flare, Solana, Stellar and others, “30+ chains”.
  • Upshift Finance front‑end lists deployments across Ethereum, Arbitrum, Base, Avalanche, Sonic, Flare, HyperEVM, Monad, Sui.
  • An external analysis states TVL “across multiple blockchains like Ethereum, Hyperliquid L1, and Avalanche”. Given tool constraints and the absence of direct Hyperliquid L1 explorer references in the retrieved data, on‑chain verification of specific Upshift contracts on Hyperliquid L1 and Monad is Not verifiable as of 2026‑09‑04. Native token
  • No clear evidence of a protocol‑level governance or utility token; vaults are described as ERC‑4626 “receipt tokens” representing deposits, not a global native token.
  • Therefore, existence and details of any native protocol token are Not verifiable as of 2026‑09‑04. Main contract addresses & explorer verification
  • Public docs and SDK references describe TokenizedAccount ERC‑4626 vaults and multiAssetVault proxies as the two core contract families.
  • Specific contract addresses (on Ethereum, Hyperliquid L1, Monad) and their explorer verification status are Not verifiable as of 2026‑09‑04 under current constraints. Fork lineage / upstream relationships
  • Upshift is repeatedly described as built “on top of August prime services / August infrastructure”, using ERC‑4626 and, for Stellar, OpenZeppelin’s stellar‑tokens library.
  • This indicates architectural dependence (vaults integrated with August), but no source explicitly states it is a direct fork of a particular protocol (e.g., Yearn, Aave) or a hard fork of August itself.
  • No evidence of:
  • A declared upstream fork lineage.
  • Audited change logs specifically versus an upstream fork.
  • Documented malicious‑modification incidents in related forks. Accordingly, Upshift’s precise fork status and any audited diffs vs an upstream protocol are Not verifiable as of 2026‑09‑04.
Evidence (15)

maturity

two sources

Upshift appears to be a real, live product rather than a mere landing page: the app site shows an active vault marketplace with a visible deposited amount on the front page, and the docs describe a functioning REST API for vault data and user points. The docs and app also describe live deposit/redemption flows, including instant redeem and requested redeem paths, which indicates operational product functionality rather than static marketing. However, no on-chain verification was available in this run, so live deposits/withdrawals, chain-by-chain exposure across Ethereum/Hyperliquid L1/Monad, and any claimed TVL split are Not verifiable as of 2026-09-04.

On maturity signals, the documentation set is fairly developed: there are dedicated docs pages for API reference, code/app examples, vault architecture, FAQs, and curator guidance, plus markdown-accessible pages and examples. The presence of a public API endpoint and unauthenticated endpoints is a strong product-maturity indicator. The app also appears to expose vault-level details such as vault address and withdrawal fee.

That said, no web evidence here conclusively proves the absence of broken links, template reuse, or fake metrics; those checks are Not verifiable as of 2026-09-04. Open API: yes. The docs explicitly state that Upshift API v1 is public, RESTful, JSON-based, and currently available without authentication for public endpoints.

The described endpoints include health, user points, tokenized vault listings, vault details, and APY calculation.

Evidence (4)

Security

bug bounty

two sources

Not verifiable as of 2026-09-04. The web results did not surface a source-confirmed Upshift bug bounty program with a reliable start date, scope/parameters, payout tiers, or disclosed results. The only potentially relevant findings were an Immunefi marketplace page listing many programs and an Upshift app page, but neither provided a confirmed Upshift bounty listing or program terms.

Any claim that Upshift has an active bug bounty would be unverified marketing claim unless corroborated by a dedicated bounty page, platform listing, or disclosure record.

Evidence (2)

counterparty risks

unverified

Assessment: medium/high dependency risk; vault-specific exposure is decisive. Upshift is infrastructure rather than a single strategy. Curators can allocate to lending, LP, staking/restaking, basis, RWA, CeFi and cross-chain strategies; therefore dependency risk varies by vault and chain. A complete current position ledger for Ethereum, Hyperliquid L1 and Monad is Not verifiable as of September 6, 2026 because on-chain verification is unavailable and public sources do not disclose aggregate exposure by vault, protocol, token, or chain. External protocols / tokens. Public materials identify or exemplify exposure to Aave, Uniswap, Ethena, Kelp, Lombard and Treehouse; partner-pool documentation lists products involving agETH, upLBTC and upsUSDe.

These create protocol, smart-contract, liquidity, oracle, issuer and depeg dependencies. Current allocation percentages are Not verifiable as of September 6, 2026. Oracles / NAV. Upshift describes whitelisted price feeds, NAV calculation, API-based CeFi mark-to-market, and a max-percentage-change constraint intended to limit oracle latency/manipulation. This reduces—but does not eliminate—wrong-price, stale-price, API outage, thin-liquidity and NAV-reporting risk. Bridges / chains. Cross-chain strategies may use LayerZero/Stargate and Chainlink CCIP.

Failure scenarios include bridge messaging failure, validator/oracle compromise, delayed settlement, chain halt/reorg, or inability to repatriate assets. Chain-level exposure split is Not verifiable as of September 6, 2026. Custody / venues. The architecture uses August subaccounts and/or Fordefi MPC; curators receive execution permissions but are described as unable to send funds to arbitrary external addresses. This leaves dependency on August, Fordefi, multisig governance, policy enforcement, withdrawal queues, and any connected prime-broker, CEX, market-maker, OTC or Deribit position.

Counterparty insolvency and API/settlement risk remain material. RWA / stablecoins / LSTs. Upshift markets RWA and tokenized-money-market strategies, but issuer/SPV, reserve, redemption and legal-claim exposures are vault-specific and Not verifiable as of September 6, 2026. Failure scenarios: external protocol exploit; stablecoin/LST/restaking depeg; bridge or chain outage; oracle/NAV error; custodian/prime-broker insolvency; or liquidity mismatch causing delayed or haircut redemptions. Contradiction / data gap: marketing materials cite broad supported-chain/protocol coverage and aggregate platform figures, but no independently verified exposure ledger was found. On-chain figures therefore cannot be substituted. dependency_failure_active: unknown; no independently verified active failure identified. max_exposure_pct: unknown.

Evidence (6)

crypto custody

one source

Upshift is organized as non-custodial vault infrastructure: users keep ownership of the deposited assets, and the vault issues a receipt/share token that sits in the user’s wallet or with their qualified custodian. Upshift says neither it nor the curator can move depositor funds to an external wallet, and for institutional setups it can route assets into segregated custody/subaccounts while the custodian holds the receipt token. Withdrawal status is not verifiable as of 2026-09-06.

Segregated assets: true.

Segregated assets
Yes
Evidence (3)

incident

unverified

On February 19, 2026, Mezo reported that the Velar BTC/MUSD perpetual-swap pool on Mezo had been drained. The attack activity ran mainly from January 26 to February 4 and used oracle-price manipulation / low-activity market conditions; it was not described as a smart-contract bug. Approximately $401,000 was drained from the pool, with estimated attacker profit of about $250,000.

The affected Upshift product was the Mezo tBTC vault: initially 87 depositors were reported affected, later narrowed to 61 with active balances. Upshift/Gamma requested and executed a pause of deposits and withdrawals, while Mezo removed Velar from its ecosystem listings. A community recovery mechanism, REKT, was launched on March 24, 2026, with tokens distributed pro rata to the 61 affected depositors; this is recovery coordination, not reimbursement.

Full recovery is not evidenced. Status: remediation_in_progress.

Date
2026-02-19
Cause
Oracle manipulation
Loss
$401K
Attacker proceeds
$250K
Status
remediation in progress
Reimbursed
No
Event id
upshift-velar-mezo-2026-02-19
Evidence (3)

incident

two sources

On March 22, 2026, the external Resolv/USR infrastructure compromise caused USR to depeg and impaired Resolv-related collateral markets used by Upshift vaults. The root cause was a compromised Resolv privileged signing key that enabled approximately 80 million unbacked USR to be minted; the attacker extracted approximately $24.5–25 million. Upshift-affected products were earnAUSD, upUSDC and coreUSDC: earnAUSD had approximately 0.63% RLP exposure (~$315,000 of ~$50 million vault TVL); upUSDC had approximately 6% RLP exposure (~$700,000 of ~$11.7 million TVL); coreUSDC had approximately 1.92% RLP exposure through upUSDC.

Upshift paused earnAUSD deposits/withdrawals, temporarily removed the Pendle pool, managed upUSDC health factors and paused upUSDC/coreUSDC withdrawals while settling accounting with counterparties. Gamma Research stated it would fully cover all affected earnAUSD users, with deposits and withdrawals expected to reopen. No quantified realised loss for Upshift users or the protocol was publicly disclosed; therefore loss_usd is not verifiable as of September 5, 2026.

The attacker proceeds relate to Resolv, not Upshift. Gamma’s stated earnAUSD reimbursement indicates that affected earnAUSD users were to be made whole, but no evidence was found confirming a full reimbursement or final settlement for upUSDC/coreUSDC. No later public confirmation of complete remediation was found; current status is remediation_in_progress.

Fixes included exposure reduction, withdrawal controls, removal of the Pendle allocation, active liquidation/health-factor management and counterparty accounting reconciliation. Sources do not establish a permanent code fix to Upshift vault contracts.

Date
2026-03-22
Cause
Depeg / collateral
Attacker proceeds
$24.5M
Status
remediation in progress
Reimbursed
No
Evidence (4)

incident

two sources

On March 22, 2026, a Resolv infrastructure compromise allowed approximately 80 million unbacked USR to be minted and about $24.5–25 million to be extracted, causing USR/RLP depeg-related losses across connected markets. Upshift exposure was reported in earnAUSD (~0.63% RLP exposure, approximately $315,000), upUSDC (~6% RLP exposure, approximately $700,000), and coreUSDC (~1.92% RLP exposure through upUSDC). Upshift paused affected vault activity, removed the Pendle pool, managed health factors and pursued liquidation/accounting with counterparties.

Gamma stated it would fully cover earnAUSD users; upUSDC and coreUSDC remained subject to accounting and recovery arrangements. Upshift-specific realised loss and recovery amount are not publicly quantified. Resolv opened staged recovery, but this does not establish that all Upshift users were reimbursed.

Status: remediation_in_progress.

Date
2026-03-22
Cause
Key compromise
Attacker proceeds
$24.5M
Status
remediation in progress
Reimbursed
No
Event id
upshift-resolv-2026-03-22
Evidence (5)

key management

two sources

Upshift’s key management is organized as a layered, role-separated system rather than a single operator wallet. The docs describe an MPC custody layer for operational keys, where Fireblocks and Fordefi split signing authority across shares so no single device holds a complete key. In addition, vault operations use smart-contract wallets / subaccounts with specific permissions, and curators can deploy capital only inside whitelisted contracts; they cannot withdraw funds directly to an external address.

At the governance level, a Vault Owner multisig—shared by Upshift, a partner protocol, and the strategist—controls critical vault parameters and emergency functions, while a Vault Operator handles withdrawals, NAV updates, and liquidity movement between the vault and strategist subaccounts. The Subaccount Manager (Curator/Strategist) manages strategy execution within the approved policy boundaries. Upshift also says its policy engine enforces permissions at the chain, protocol, token, and function levels before transactions execute, and that transactions are simulated and approved in a maker-checker flow before signing.

In practice, that means key management is paired with policy controls: even a valid signer cannot move funds outside the allowed routes. For the Hyperliquid/Monad context specifically, I did not find chain-specific evidence that the key-management model differs from the general Upshift architecture. Not verifiable as of 2026-09-04.

Evidence (5)

smart-contract

two sources

Assessment (as of September 6, 2026). Dune MCP was unavailable; therefore no raw on-chain verification of current owners/signers, proxy-admin events, role enumeration, timelock delay, implementation slots, or Hyperliquid L1/Monad deployments was performed. Not verifiable as of September 6, 2026 for those items and for cross-chain exposure. Documented Ethereum addresses (not current-state verified): upUSDC lending-pool proxy 0x80E1048eDE66ec4c364b4F22C8768fc657FF6A42; implementation 0x43D41393124Dfca45567Ef005F5C79311C57c65b; scheduled proxy admin 0x7820209a65a43b6ce2217692fc09fd52D3df21FD; vault owner 0x17ab7568Cd5386DF6C8E4552438E32794D057cC1; vault operator 0x416e26e331Fc0b77386e9dDB5Ed9AdE73F1241F4; proxy-admin owner 0x4107557d726933f0BcA591A4218Afc92978457F7. Architecture / controls: ERC-4626 vault → policy engine → segregated strategy subaccount/whitelisted venues → redemption queue/buffer. Documentation claims owner/operator-controlled pause, owner-controlled mandate/fees/depositor list, and a 4-of-6 proxy-admin multisig; proxy upgrades reportedly have no timelock, while selected parameter changes use a claimed 24-hour/configurable timelock. Depositor → ERC-4626 proxy → policy engine → segregated subaccount → whitelisted strategies ↘ buffer / redemption queue Owner/operator: pause, parameters, fees, emergency functions; proxy-admin multisig: code upgrade Exit and failure risk: Users may redeem through the buffer/queue, but withdrawals can be paused or delayed and strategy unwind is required if liquidity is deployed. A compromised upgrade quorum could replace logic and potentially bypass stated restrictions.

Emergency authority is especially material because documentation describes movement of vault-held assets to an owner-specified address; this is not equivalent to permissionless repayment to depositors. > Contradiction: Upshift’s framework says emergency functions “move all strategy funds back into the vault,” while its newer operational description says emergency withdrawal moves vault-held assets to an owner-specified address and cannot reach deployed subaccount funds. Resolve against verified deployed bytecode/events; Not verifiable as of September 6, 2026. The supplied OtterSec audit reports zero critical/high findings, but it covers the Sui ember-vaults codebase, not verified Ethereum/Hyperliquid/Monad deployments; deployment applicability is therefore Not verifiable as of September 6, 2026.

Upgradeable
Yes
Evidence (5)

audit

two sources

Auditor: ChainSecurity. Report: “August – Core Vault – ChainSecurity.” Publication date: January 2025 (reported date; PDF metadata is not independently verifiable). Scope: upgradeable ERC-4626 Core Vault with delayed withdrawals, accounting, fees, shares, functional correctness and standard compliance.

Link: published PDF. Covers deployed code: Not verifiable as of 2026-09-05; no bytecode/address-to-commit match was found.

Auditor
ChainSecurity
Report date
2025-01
Scope
August Core Vault; upgradeable ERC-4626 vault and delayed withdrawals.
Findings
0 critical; 3 high (2 code-corrected, 1 risk accepted); 6 medium (all code-corrected); 8 low (2 corrected, 1 specification changed, 1 risk accepted, 4 acknowledged).
Fix status
High/medium findings were addressed as above; one high and some low findings remained risk-accepted, acknowledged, or specification-dependent.
Evidence (2)

audit

one source

OtterSec, “Upshift Solana ERC4626 Security Assessment.” This is outside the requested Ethereum, Hyperliquid L1 and Monad scope.

Auditor
OtterSec
Report date
2025-09-01
Scope
Solana ERC-4626 program, repository defiborg/solana-erc4626, commit 592be1c; assessment conducted August 20–29, 2025.
Findings
0 critical; 1 high; 1 medium; 3 low; 2 informational. Findings included donation/share inflation, withdrawal-fee truncation, AUM-update constraints, transfer-fee handling and vault-state sizing.
Fix status
The report marks the findings resolved and cites PR#3, PR#4 and PR#5, except the transfer-fee issue, which was acknowledged.
Report url
https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXmCdFTPUHEQ60lKvKop0%2Fuploads%2FfcdBVLOhOIQtc9217chS%2FUpshift_solana_erc_audit_final%20%281%29.pdf?alt=media&token=d46bafce-83dc-4240-97d9-44ebdb4e1411
Report id
doc:33842d079fe8af60
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

OtterSec, “Ember Protocol Security Assessment.” This is outside the requested chains and covers Sui, not Ethereum, Hyperliquid L1 or Monad.

Auditor
OtterSec
Report date
2025-09-09
Scope
ember-vaults program commissioned by Bluewater Labs and Upshift; repository fireflyprotocol/ember-vaults, commit 93a46fb; Sui single-asset vault system.
Findings
0 critical; 0 high; 6 medium; 1 low; 6 informational. Issues included treasury-cap initialization, zero-share withdrawals, blacklist-related fund loss, withdrawal-processing DoS, fee accrual and rounding.
Fix status
All listed vulnerability findings are marked resolved in the report; deployment match is Not verifiable as of 2026-09-06.
Report url
https://hproof-static.s3.us-east-1.amazonaws.com/other/ember_upshift_vaults_audit_final%20%281%29.pdf
Report id
doc:64cae7847dd7d2f0
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

ChainSecurity, “August – Core Vault – ChainSecurity.”

Auditor
ChainSecurity
Report date
2025-01-21
Scope
Upgradeable ERC-4626 Core Vault with delayed withdrawals; accounting, fees, shares, functional correctness and standard compliance. Final reviewed commit e3d4f8e.
Findings
0 critical; 3 high; 6 medium; 8 low. High: 2 code-corrected, 1 risk accepted. Medium: all 6 code-corrected. Low: 2 code-corrected, 1 specification changed, 1 risk accepted, 4 acknowledged.
Fix status
High and medium findings were addressed as stated. One high and several low findings remained risk-accepted, acknowledged or specification-dependent.
Report url
https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYgYVkG0Tyix95GGW1LP8%2Fuploads%2FG3TvU8QBjkTOvhlMX7ae%2FChainSecurity_August_Core_Vault_audit.pdf?alt=media&token=8bef54f8-c89a-4d58-85d9-5dce2a3f0f28
Report id
doc:9c6eb368d331e745
Covers deployed code
No
Unresolved critical
0
Unresolved high
1
Evidence (1)

audit

one source

Corrected report record: Hacken, “Smart Contract Code Review and Security Analysis Report for Upshift Finance.”

Auditor
Hacken
Report date
2025-12-18
Scope
Upgradeable ERC-4626 Upshift Vault contracts for any EVM-compatible chain; repository fractal-protocol/august-contracts-v2, commit 6fbcaf5.
Findings
0 critical; 0 high; 4 medium; 2 low; 3 informational. Total 9 findings: 3 mitigated and 6 accepted.
Fix status
Three findings were mitigated; six were accepted. The report does not support the previously recorded claim that findings were resolved through PR#3–PR#5.
Report url
https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXmCdFTPUHEQ60lKvKop0%2Fuploads%2F8UO5oxZS7bEcnyNpIbfS%2F25.12.18%20-%20Hacken%20Audit.pdf?alt=media&token=1786bf45-7de2-486b-baef-c40f1250f970
Report id
doc:9db79b450010d963
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected report record: Hacken, “Smart Contract Code Review and Security Analysis Report for Upshift Finance – AllocationWhitelist.”

Auditor
Hacken
Report date
2026-01-30
Scope
TimelockedVault, OraclizedMultiAssetVault and SendersAllocationWhitelist; repository branch allocation-whitelist; initial commit 4a08f62 and final commit 78792e4; any EVM-compatible chain.
Findings
0 critical; 0 high; 0 medium; 0 low; 3 informational findings: floating pragma accepted; unused code fixed; missing zero-address check for contract owner fixed.
Fix status
Two informational findings were fixed and one was accepted.
Report url
https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXmCdFTPUHEQ60lKvKop0%2Fuploads%2FIqnlimIRQFwlYr81fncl%2F26.01.30%20-%20Hacken%20Audit%20-%20AllocationWhitelist.pdf?alt=media&token=cd5e1ce5-a20e-4abf-91ad-74deeb064911
Report id
doc:d1de277e0b4a1c30
Covers deployed code
No
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Security review of Upshift Finance smart contracts on any EVM-compatible chain (Solidity); the later report explicitly states the source code is planned to be compatible with any EVM chain supporting Paris or higher, with the deployment version selected per target network.

Auditor
Hacken
Report date
2025-09-24
Scope
Upshift Finance smart contract code review; final report for the 24/09/2025 engagement.
Evidence (2)

audit

one source

Auditor: OtterSec. Report: “Ember Protocol Audit” / “ember-vaults.” Publication date: August 2025 (assessment ran August 6–15, 2025). Scope: Ember vault program commissioned by Bluewater Labs and Upshift; report references commit 93a46fb. Covers deployed code: Not verifiable as of 2026-09-05; no deployed-address/bytecode match was established.

Auditor
OtterSec
Report date
2025-08-15
Scope
ember-vaults program; commit 93a46fb.
Findings
13 findings; report highlights blacklisted-user withdrawal loss, zero-rounding/accounting issues, and fee-calculation/cooldown behavior.
Fix status
Not verifiable as of 2026-09-05 from the located report excerpt.
Evidence (1)

audit

one source

Sigma Prime, “Fractal Network Report.”

Auditor
Sigma Prime
Report date
2024-08
Scope
Fractal Network smart contracts associated with the Upshift/Fractal vault implementation; exact contract list and commit not independently verified.
Findings
0 critical; 1 high; 3 medium; 2 low; 7 informational, based on secondary reporting.
Fix status
Secondary reporting states the high, medium and low findings were fixed. Authoritative report link and deployment match: Not verifiable as of 2026-09-06.
Covers deployed code
No
Unresolved critical
0
Evidence (1)

audit

two sources

Upshift documentation says the protocol has 10 audits by 6 independent firms as of August 2026, but the search results did not expose the individual auditor names, dates, or full scopes for the other reports.

Auditor
Unspecified on the retrieved page; Upshift docs claim 10 audits by 6 independent firms as of August 2026
Report date
2026-08-26
Scope
Protocol-wide audited code claim in documentation; no report-level scope was exposed in the search results.
Findings
Not verifiable as of 2026-09-03.
Fix status
Not verifiable as of 2026-09-03.
Evidence (2)

audit

one source

Hyperliquid Docs state that the Hyperliquid bridge contract has been audited by Zellic; this is the only retrieved non-Upshift source naming Zellic, but the snippet did not expose whether the report covers Upshift-specific deployed code.

Auditor
Zellic
Report date
2026-08-07
Scope
Hyperliquid bridge contract audit referenced in Hyperliquid docs, not explicitly tied in the snippet to Upshift vault deployments.
Findings
Not verifiable as of 2026-09-03.
Fix status
Not verifiable as of 2026-09-03.
Evidence (1)

Team & Reputation

founders

two sources

Upshift is a publicly founded, non-anonymous institutional DeFi yield protocol, built on top of the August prime brokerage infrastructure, with co-founders who have prior institutional crypto track records. ### Founders & team

  • Co-founders: Most sources identify Aya Kantorovich and Alexandre (Alex) Elkrief as Upshift co-founders.
  • Backgrounds:
  • Aya: previously on the *founding team* at FalconX (institutional crypto brokerage) and worked at Pantera Capital.
  • Alex: former portfolio manager at LedgerPrime, a quantitative crypto fund that reportedly managed around $400M.
  • Role split vs August: Upshift is tightly linked to August, an on-chain prime brokerage; multiple sources say Upshift is being developed by the same team behind August and led by Aya and Alex. One review notes that as of April 2025, Upshift and August teams were in the process of formally separating, with Elkrief focusing on Upshift’s product-led growth.
  • Public vs anon: Both founders are fully doxxed, with active LinkedIn and media presence, podcast appearances and conference talks. This is not an anonymous team. ### Prior projects, outcomes, hacks
  • FalconX, Pantera and LedgerPrime are established institutional players; none of the retrieved sources associate Aya or Alex with prior protocol hacks or catastrophic failures.
  • August is described as processing $7B monthly volume and supporting Upshift’s vault infrastructure; no public records of major security incidents for August or Upshift were surfaced in the retrieved data.
  • Not verifiable as of 2026-09-04: a systematic, on-chain incident history; also no direct primary evidence on all past risk events. ### Corporate reality: office, jurisdiction, business substance
  • Upshift positions itself as an “operating system for institutional onchain asset management” and a “DeFi yield protocol built on top of August prime services infrastructure”, with KYC-enabled integration and cross-margining between CeFi and DeFi.
  • Multiple posts mention NYC events with Aya, suggesting at least part of the go-to-market presence is in the United States. Exact legal entities, registration jurisdiction, and office addresses are Not verifiable as of 2026-09-04.
  • The breadth of chains, institutional LP distribution via August, and ongoing LinkedIn/media activity indicate a real operating business, not a static web-front-only project. ### Reality check / credibility
  • Pros:
  • Doxxed founders with prior institutional crypto roles.
  • Clear linkage to a functioning prime brokerage (August) and visible TVL across many chains via independent analytics.
  • Ongoing public communication (LinkedIn, podcasts, blogs, airdrop reviews).
  • Open questions / risks:
  • Detailed corporate structure (onshore vs offshore, regulatory licenses) Not verifiable as of 2026-09-04.
  • No direct access here to audits, bug bounty programs, or formal regulatory filings; these remain unconfirmed.
  • Heavy dependency on August’s infrastructure creates correlated operational and counterparty risk that should be diligence separately.
Evidence (12)

general reputation

two sources

Upshift currently has a strong institutional-leaning reputation with multiple independent audits and a visible investor/partner base; no credible reports of fraud, rug pull, sanctions, or insolvency have surfaced. Not verifiable as of 2026-09-04: any on-chain confirmation of these claims. Founders & investors

  • Upshift describes itself as an *institutional-grade onchain yield/vault platform* used by wallets, exchanges and neobanks.
  • Upshift reports a $10M Series A led by Dragonfly in March 2025. As this is disclosed via Upshift’s own channels, this is an unverified marketing claim pending independent VC or press confirmation.
  • Curators are described as KYC’d institutions with verifiable track records, but individual founders and curator identities are not detailed in retrieved materials. This is therefore only a marketing claim. Auditors & security posture
  • Upshift’s contracts are said to have undergone 10 smart contract audits by 6 independent firms as of August 2026.
  • Named auditors include ChainSecurity, Zellic, Sigma Prime, Hacken, with Upshift noting “four independent audit firms over two years”.
  • At least one audit report (Hacken, Dec 18, 2025) is available as a full PDF, indicating a formal code review and security analysis.
  • Upshift explicitly states it carries no internal smart contract insurance policy, instead referring clients to external underwriters. Institutional partnerships & third‑party views
  • Securitize Fund Services (a regulated digital asset fund administrator) announced a partnership to provide independent performance reporting, investor‑level allocation transparency, and audit/tax‑ready data for Upshift vaults. This is a strong reputational signal for institutional compliance and reporting standards.
  • A Binance Square post offers a favorable “in‑depth analysis” and concludes Upshift is an attractive investment, noting that earlier fraud allegations were investigated and “debunked”. This is commentary rather than a primary source, but indicates positive market sentiment. Criticisms, incidents, and sentiment
  • Retrieved sources emphasize risk controls, policy engine, audits, and institutional processes; none report exploits, insolvency events, rug pulls, or sanctions involving Upshift. Not verifiable as of 2026-09-04: completeness of this picture across all jurisdictions.
  • Upshift’s own blog repeatedly stresses multi-layer security, audit depth, and independent verification, which should be treated as unverified marketing claims until cross-checked. Regulatory / legal
  • No references found to regulatory enforcement actions, lawsuits, or sanctions specifically targeting Upshift. Not verifiable as of 2026-09-04: full global legal status. Key unresolved concerns for an institutional allocator
  • On-chain verification gaps: TVL, chain-level exposures (Ethereum, Hyperliquid L1, Monad), and allowlists are Not verifiable as of 2026-09-04.
  • Founder and governance transparency: Limited public detail on founders, multisig composition, and key management; should be probed directly.
  • Audit scope & recency: While audit count and firms are positive, each report’s coverage and remediation status must be independently reviewed before allocation.
Evidence (14)

Economy

TVL: $420.0M

model

one source

As of September 6, 2026, Upshift is an ERC-4626 vault/institutional asset-allocation platform, not a single homogeneous strategy. V1 vaults accept one asset; V2 vaults can accept multiple assets and redeem into a reference asset. Depositors receive vault shares/receipt tokens.

Yield sources include lending, LPing, staking, tokenized yield positions, protocol incentives/points, and—where a curator’s mandate permits—basis, market-making, derivatives or CeFi strategies. The platform architecture supports cross-chain bridging and valuation of options and CeFi perpetual positions, but the exact strategy, collateral, leverage, looping, restaking and directional/market-neutral exposure are product-specific. Exact exposure for Ethereum, Hyperliquid L1 and Monad is Not verifiable as of 2026-09-06.

Organic versus subsidized yield cannot be quantified: Upshift documents explicitly include both underlying-protocol yield and incentives/points. organic_yield_pct is therefore null. APY sustainability and historical volatility are Not verifiable as of 2026-09-06; DeFiLlama currently reports 7 tracked pools with average APY 8.37%, but this is an aggregator snapshot, not a full history. Withdrawals are ERC-4626 redemptions, subject to configurable withdrawal, instant-redemption and management fees; vaults may maintain a liquidity buffer, impose a withdrawal period, or pause deposits/withdrawals.

Exact fees, lock-ups, gates, per-vault limits and withdrawal timing are Not verifiable as of 2026-09-06. DeFiLlama snapshot: total TVL $401.74m, up 46.3% over 30 days; Ethereum $274.10m (68.2%), Monad $23.35m (5.8%), Hyperliquid L1 $5.04m (1.3%). The remaining TVL is on other chains.

Fees were $2.02m over 30 days and reported protocol revenue $158,157; revenue consists of management and performance fees under DeFiLlama’s methodology. Dune comparison and on-chain verification are Not verifiable as of 2026-09-06. Contradiction / scope finding: prior notes describing Upshift mainly as perp-funding/restaking are narrower than current documentation, which describes a broad multi-strategy vault platform; product-level confirmation is unavailable.

Evidence (5)

reserves

two sources

As of September 6, 2026: Not verifiable as of 2026-09-06. No public, independently verified reserve/treasury schedule, treasury wallet map, custody statement, reserve policy, liabilities schedule, or reserve attestation was located for Upshift across Ethereum, Hyperliquid L1, or Monad. Dune on-chain verification was unavailable in this run; therefore on-chain balances and addresses are Not verifiable as of 2026-09-06. What is documented: Upshift describes depositor capital as held in vault contracts and segregated subaccounts, with transfers restricted to whitelisted strategy contracts. It documents a configurable withdrawal-liquidity buffer, 24-hour timelocks, and a multisig emergency function.

These are vault risk controls, not evidence of a protocol-owned reserve. Institutional custody models include August subaccounts and Fordefi MPC; the custody arrangement is vault-/client-specific, not a disclosed Upshift treasury custody structure. Composition and size: No protocol treasury composition or liquid-reserve amount was disclosed. DeFiLlama reports approximately $401.28m TVL, including about $273.88m Ethereum, $5.07m Hyperliquid L1, and $23.35m Monad; this is deposited vault TVL, not treasury reserves or liquid reserves. > Contradiction / classification finding: Upshift’s homepage claims “500M+” total deposits, while DeFiLlama reports approximately $401.28m TVL.

The figures may use different scopes or measurement dates, but neither establishes treasury size; the discrepancy is unresolved. Attestations: The Securitize partnership concerns independent performance, allocation, and reconciliation reporting; it is not evidence of a public reserve attestation. Publicly identified audits concern smart-contract security, not solvency or treasury reserves.

Evidence (5)

tokenomics

one source

Conclusion — no native protocol token identified. As of September 4, 2026, Upshift’s investable on-chain assets are vault receipt/share tokens (e.g., upUSDC, hgETH, svUSDC), not a fungible governance or value-accrual token. Upshift documents a points program, but not a token-generation event, token ticker, or governance token.

  • Native token / contract: None identified across Ethereum, Hyperliquid L1/HyperEVM, or Monad. Contract addresses found are vault/share-token contracts, not an Upshift native token.
  • Supply, market cap, FDV: N/A. Not verifiable as of September 4, 2026 for a native token because none is documented or identified.
  • Utility/governance: No native-token utility, voting rights, revenue share, buyback, burn, staking-reward, or fee-discount mechanism identified. Points and vault receipt tokens should not be treated as tokenomics.
  • Emissions/unlocks/allocations: No native-token emissions, vesting, team/investor/treasury/community allocation, or announced unlock schedule identified. Whether unlocks occurred on-chain: Not verifiable as of September 4, 2026.
  • Mint/blacklist/fee switch/control: Not applicable to a nonexistent native token. Vault contracts are upgradeable proxies and expose administrative controls; permissions are vault-specific rather than evidence of token-level controls.
  • Holder concentration/insiders: N/A for a native token. Receipt-token holder concentration is product-specific; Not verifiable as of September 4, 2026 without a reproducible on-chain dataset.
  • DEX liquidity/listings: No native-token DEX pool or exchange listing identified. Vault receipt tokens may appear in integrations, but are not native-token liquidity. Not verifiable as of September 4, 2026 for comprehensive liquidity depth. Risk finding: Any “UP,” “UPSHIFT,” or similarly named token claiming affiliation should be treated as unaffiliated unless contract ownership and chain identity are independently established.
Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A BTC move below $10,000 is a severe macro stress event, but for Upshift the key question is whether its vaults hold BTC-linked, leveraged, or highly correlated positions. The public sources provided do not let me verify Upshift’s exact exposure by chain or strategy, so the protocol-specific impact is Not verifiable as of 2026-09-04. What is verifiable is that Upshift says its vault framework includes a withdrawal liquidity buffer, NAV volatility protection that caps share-to-asset ratio changes within an update cycle, and emergency functions that can pause deposits/withdrawals and move strategy funds back to the vault.

Those controls would generally help reduce immediate redemption and valuation shocks during a market crash, but they do not prove immunity from losses if a vault’s underlying strategy is exposed to BTC or BTC-linked collateral. On the user-facing side, Upshift describes itself as institutional onchain asset management and a DeFi vault platform, but the sources here do not identify which live vaults are on Ethereum, Hyperliquid L1, or Monad, nor their allocation mix. Because of that, I cannot quantify TVL at risk, chain-by-chain exposure, or liquidation sensitivity. Stress-case interpretation:

  • If a vault is unlevered and non-BTC-correlated, a BTC crash below $10,000 should mainly affect sentiment and flows, not principal mechanics.
  • If a vault holds BTC, BTC-perps, BTC-collateralized credit, or correlated alt risk, losses could be severe, and the emergency pause/buffer controls may only slow withdrawals rather than prevent NAV drawdown.
  • If a vault relies on external liquidity or delta-hedged perp funding, extreme dislocations can still produce realized losses despite protection features. For a defensible risk answer, the missing inputs are the current vault roster, per-chain deployment, and each strategy’s assets, leverage, and hedge profile. Those are Not verifiable as of 2026-09-04 from the provided sources.
Evidence (4)

stress scenario - largest collateral depegs 20%,

one source

Not verifiable as of 2026-09-04. The available sources do not provide on-chain, protocol-wide collateral composition by chain or a liquidation model for a 20% depeg stress, so the maximum loss to Upshift under this scenario cannot be quantified reliably. The closest relevant evidence is that Upshift vaults can have strategy-specific exposures, including a Core USDC vault that had exposure to apxUSD and realized an 8% drawdown when that underlying depegged, but that is a single-vault incident rather than a protocol-wide stress test.

Upshift also states that vaults process claimable redemptions daily and may offer instant redemption subject to liquidity, which implies that impact from a collateral depeg would depend on each vault’s liquidity buffer, unwind speed, and whether the depegged asset is used as collateral in the first place. The protocol’s own materials and third-party pages confirm multi-chain operation, but none of the provided sources quantify ETH, Hyperliquid L1, or Monad exposure for the selected product set.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Scope / identification. Dune was unavailable, so no on-chain exposure ranking, contract-state check, or query/execution IDs can be supplied. Not verifiable as of September 5, 2026. The largest publicly displayed relevant exposures are: Ethereum—Sentora USD, approximately $40.6M; Monad—earnAUSD, approximately $22.2M; Hyperliquid L1—approximately $5.1M protocol TVL, but the underlying vault/counterparty split is not disclosed. These are analytics/UI figures, not on-chain verified balances. Stress case: top underlying counterparty becomes insolvent

  • Ethereum / Sentora-type credit or strategy exposure: borrower default, venue failure, or frozen redemption creates a shortfall in the external position. For overcollateralized DeFi lending, collateral is liquidated/auctioned; for institutional/CeFi credit, recovery becomes an off-chain claim. Expected loss = principal shortfall plus liquidation slippage and any trapped yield. The vault’s shareholders absorb the loss pro rata; no Upshift principal guarantee or insurance backstop was verified.
  • Monad / earnAUSD: the vault allocates across lending and DEX venues including Curvance, Euler, Neverland, Morpho and Uniswap. A single venue failure causes impairment or illiquidity in that allocation; liquidation or withdrawal from unaffected venues may recover part of the loss. Because current allocation weights are not publicly verifiable here, the top venue and loss percentage are Not verifiable as of September 5, 2026.
  • Hyperliquid L1: if the failure is a trading/perps counterparty, losses flow through the strategy’s marked-to-market P&L, liquidation engine, or custody/subaccount balance. If positions cannot be closed, the vault suffers realized loss or delayed redemption. The exact Upshift strategy and counterparty are Not verifiable as of September 5, 2026. Smart-contract impact path. Strategy/subaccount assets become impaired → curator/operator disables the affected strategy or invokes emergency withdrawal → vault totalAssets/external-asset reporting is reduced → ERC-4626 share price/NAV falls, subject to max-change controls → deposits may pause and withdrawals may queue or use the liquidity buffer. Redemption requires sufficient reference-asset liquidity; otherwise users remain exposed to the impaired NAV. Compensation. Recoveries are limited to collateral liquidation, venue redemption, or legal recovery from the borrower. No verified automatic make-whole mechanism exists; absent a separate indemnity, remaining losses stay with depositors/shareholders—not Upshift infrastructure or the curator.
Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

Not verifiable as of 2026-09-04. I found no reliable, protocol-specific evidence that Upshift’s DAO or owners committed fraud, and the strongest result set is dominated by a third-party social post that explicitly says the fraud allegations were debunked and lacked official FCA evidence; however, that is not independent proof of innocence, only a claim about the allegation set. The only clearly authoritative fraud precedent in the search results is the unrelated 2016 SEC report on *The DAO*, which found an attacker exploited code to divert about one-third of assets; it does not establish wrongdoing by Upshift’s DAO or owners.

Because I cannot confirm Upshift-specific allegations with independent sources, on-chain verification is unavailable in this run and the stress scenario should be treated as an unverified risk hypothesis, not a substantiated incident.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

Upshift’s primary yield source is not fully verifiable from the provided web results, because the available sources describe general strategy categories and some example vault APYs, but do not expose a chain-by-chain, vault-by-vault yield decomposition for Ethereum, Hyperliquid L1, and Monad as of the current snapshot. The only directly relevant negative-yield stress mechanism explicitly documented is that basis/funding-rate strategies can turn from carry into cost when funding stays negative, so a 30-day negative primary yield scenario is credible for that strategy class. For a stress scenario, the key risk is that headline APY can compress quickly or become negative if the vault’s main engine depends on funding, lending spread, or incentive yield that decays or reverses.

Upshift also states that yield can come from real yield, protocol rewards, and yield tokenization, which means the stress impact depends on whether the vault is mostly organic yield or subsidized/incentive-driven yield. The current web evidence does show that Upshift operates on multiple chains, including Ethereum, Hyperliquid L1, and Monad, but it does not provide verifiable TVL or exposure shares by chain for this request, so chain-level stress allocation is Not verifiable as of 2026-09-04. Likewise, the exact vaults affected by a negative 30-day primary yield shock are Not verifiable as of 2026-09-04 from the supplied sources.

Practical stress readout: if the primary engine is funding/carry, expect the first-order effect to be lower or negative realized yield; if the strategy relies on lending spread, the main downside is spread compression; if it relies on incentives, the main downside is reward decay.

Evidence (6)

Governance & Legal

governance

one source

As of September 13, 2026, Upshift appears company-, vault-owner-, curator-, and multisig-controlled—not token/DAO-governed. The frontend identifies Upshift as powered by August; the operating entity disclosed on the site is August One SA, Geneva, Switzerland (UID CHE-327.498.232; register CH-660.7.328.025-2). The registry reports Laurent Elkrief as the sole registered director/signatory.

No binding token-governance system, public governor, proposal forum, quorum, or token-vote execution process was identified: Not verifiable as of September 13, 2026. Therefore DAO governance is false; any DAO branding appears symbolic. Control surface: the vault owner sets protocol/token/function whitelists, depositor permissions, fees, and pause controls; curators allocate capital within the whitelist; Upshift/August operates contracts, policy enforcement, NAV/accounting, fee and redemption logic, and the frontend.

Parameter changes generally use a configurable 24-hour timelock. Proxy upgrades have no timelock and require a 4-of-6 multisig, described as two signers each from the asset issuer, curator, and Upshift. Individual signer identities, wallet addresses across all supported chains, key-management independence, and whether the organizations are operationally independent are Not verifiable as of September 13, 2026.

Voting concentration and top holders via Dune: Not verifiable as of September 13, 2026 (Dune unavailable; no verified governance token/control-token distribution established). CONTRADICTION / DRAIN RISK: Upshift marketing states neither Upshift nor the curator can move depositor funds to an external wallet, while its interface documents emergencyWithdraw(token, destination) as an admin sweep and its risk framework says emergency functions can move strategy funds back to the vault. The exact destination restrictions and implementation per vault/chain are Not verifiable as of September 13, 2026.

Accordingly, admin_can_drain is conservatively true: a multisig-controlled emergency path can move assets without a DAO vote, even if intended for recovery rather than theft.

Timelock
Yes
Timelock delay hours
24
Multisig threshold
4
Multisig owners
6
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Assessment (as of September 4, 2026): Upshift identifies Fractal Network Ltd. as the service operator in its Privacy Policy. A LEI record identifies that company as a BVI company limited by shares, incorporated October 11, 2021, with registered address in Road Town, British Virgin Islands. However, the current Upshift website footer names August One SA, Geneva, Switzerland, creating a material legal-entity/contracting-party ambiguity.

ToS and restrictions: The public access page states that users in restricted jurisdictions—including sanctioned locations and jurisdictions where the service is legally ineligible—are blocked. The full Terms of Use could not be machine-verified from the available page. Not verifiable as of September 4, 2026 for governing law, forum, liability caps, arbitration, insolvency treatment, or precise prohibited-country list. KYC/AML: The Privacy Policy says Upshift may verify identity against public/third-party databases, investigate illicit activity, and share information with regulators or law enforcement.

It does not establish that Fractal Network Ltd. is a regulated AML-obligated institution or that retail users undergo universal KYC. Institutional KYC/KYB is described in Upshift/August materials, but this is an unverified marketing claim, not an independently verified compliance program. Classification: Fractal Network Ltd. filed a U.S.

SEC Form D for a $16.16 million Rule 506(b) equity offering, identifying itself as “Other Technology,” not as a registered investment company. This confirms a securities-law financing by the entity; it does not determine whether Upshift vault interests, receipt tokens, yield products, or management activities are securities, investment-company interests, advisory services, money transmission, or regulated crypto-asset services. Not verifiable as of September 4, 2026 whether required licenses/registrations exist. Warnings, enforcement, litigation, sanctions: Not verifiable as of September 4, 2026 for regulator warnings/enforcement, court cases, or sanctions against Upshift, Fractal Network Ltd., or August One SA from the reviewed public sources.

No evidence located that protocol-level screening controls imply the entity itself is sanctioned. Data protection: The policy claims GDPR and California privacy rights, collects wallet/transaction, IP, browser and identity-related data, retains information for at least five years, and acknowledges blockchain data cannot be erased. Legal structure vs. actual risk: The principal risk is not merely offshore incorporation; it is uncertainty over the contracting entity, cross-border regulatory perimeter, custody/control of vault assets, curator discretion, and whether product distribution through fintechs creates regulated advisory, collective-investment, or securities exposure.

Active enforcement
No
Sanctioned
No
Entity
Fractal Network Ltd. (brand: Upshift); website also names August One SA
Jurisdiction
British Virgin Islands; Geneva, Switzerland shown as principal/operating address
Evidence (5)

legal registries

two sources

GLEIF LEI registry unavailable at scan time. OFAC SDN screening of 'Fractal Network Ltd', 'website also names August One SA', 'Upshift': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Fractal Network Ltd
  • website also names August One SA
  • Upshift
Entity
Fractal Network Ltd.
LEI
254900PEGQ2WQ7O0YM49
Jurisdiction
VG
Entity status
ACTIVE
Sanctioned
No
Evidence (3)

Stability

stability

one source

Upshift does not appear to issue its own stablecoin. The available evidence describes Upshift as vault and yield infrastructure that accepts or routes existing stablecoins such as USDC, BOLD, and AUSD, not as a protocol minting a native dollar token. A reported August 2026 incident involved two Upshift USD vaults losing value due to indirect exposure to apxUSD, but that was a vault NAV drawdown, not a verified depeg of an Upshift-issued stablecoin.

Depeg_count, max_depeg_pct, and last_depeg_date are not verifiable as of 2026-09-06 because no Upshift-issued stablecoin depeg is confirmed in the available sources.

Own stablecoin
No
Evidence (5)

Risks & Strengths

risks

one source

Upshift’s principal risks arise from layered vault smart contracts, curator-controlled strategy execution, external DeFi/bridge dependencies, and redemption liquidity. The platform documents meaningful controls, but chain-level exposure, current TVL composition, privileged roles, and live collateralization are Not verifiable as of September 5, 2026 because on-chain verification was unavailable; therefore residual risks remain conservatively elevated.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract and configuration failureVault, adapter, accounting, whitelist, or upgrade defects could misprice shares, block withdrawals, or cause loss of deposited assets. Audits reduce but do not eliminate this risk.HighMediumAudits, whitelisted integrations, NAV-change limits, timelocks, pause functions, and multisig emergency controls are documented.High-impact unknown vulnerabilities and configuration mistakes remain; deployment-specific audit coverage is Not verifiable as of September 5, 2026.
Curator and operator dependencyStrategists control allocation, execution, and in some custody models NAV proposals; poor decisions, compromised credentials, or operational failure can impair performance or solvency.HighMediumRole-based permissions, MPC/shared-workspace controls, whitelisted protocols/tokens, and non-custodial restrictions are documented.High residual governance and key-person risk; actual role holders, limits, and monitoring are Not verifiable as of September 5, 2026.
Underlying protocol and bridge contagionVaults can depend on lending, LP, staking, derivatives, stablecoins, price feeds, and cross-chain bridges; an external exploit, depeg, oracle error, or bridge outage can transmit losses.HighMediumProtocol/token whitelisting, bridge-module restrictions, reserve buffers, and NAV controls are described.High, because composability and third-party failure remain outside Upshift’s direct control.
Redemption and liquidity mismatchRedemptions may be queued to a later epoch, while strategy assets may be illiquid or require unwinding at a loss; reserve buffers may be insufficient during stress.HighMediumConfigurable withdrawal liquidity buffers, reserve targets, withdrawal periods, and redemption-request mechanics are documented.Medium-High; live buffer coverage, withdrawal queues, and asset liquidity are Not verifiable as of September 5, 2026.
Centralization and limited loss protectionEmergency pauses, whitelists, fee settings, and strategy permissions rely on administrators, curators, infrastructure providers, or multisigs; the protocol reports no insurance policy.MediumMediumTimelocks, multisig emergency functions, permissioned policies, and documented transparency controls are in place.Medium-High: governance actions can still restrict withdrawals or alter risk, and uninsured losses may be borne by users.
Evidence (4)

strengths

two sources

Upshift’s top five strengths are: institutional-grade positioning, broad cross-chain strategy coverage, non-custodial vault architecture, ERC-4626 composability, and Vault-as-a-Service (VaaS) / product modularity. The strongest directly supported signals are that Upshift describes itself as an “operating system for institutional onchain asset management,” supports “30+ chains and 70+ protocols,” uses ERC-4626 tokenized vaults, and offers a vault infrastructure layer for fintechs and asset managers.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 23 one source, 2 unverified.
  • Oldest fact verification date: 2026-08-29.