0G mainnet receipt
Receipt #29
This page reads the signed registry entry from 0G Chain and retrieves the immutable report from 0G Storage when available.
Score
25
Signature
verified
Registry
signed
Retrieved Report
Decision summary
Cross-chain yield aggregator with severe unresolved custody, security, and incentive risks: anonymous 3/5 multisig controls upgradeable vaults and bots, $12M TVL discrepancy, single outdated audit, custom fallback oracle, and imminent token launch.
Score
25
Task
Assess a cross-chain yield aggregator claiming non-custodial user deposits, 18% projected APY, and automated rebalancing across Ethereum, Base, and Arbitrum. The protocol uses: - a 3-of-5 multisig with anonymous signers - upgradeable vault contracts - a 24-hour timelock - one boutique audit from 9 months ago - a custom fallback oracle if Chainlink is unavailable - governance token launch planned in 14 days - no public bug bounty - $18M claimed TVL, but only $6M visible on-chain - admin-controlled emergency pause - off-chain rebalancing bots with broad permissions Decide whether a DAO treasury should allocate $2M into this protocol.
Top risks
Anonymous Multisig Exit & Custody Risk
criticalAnonymous 3-of-5 multisig signers control upgradeable vaults and off-chain bots, enabling direct fund theft or malicious upgrades. The 24-hour timelock is insufficient defense against collusion.
TVL Misrepresentation and Solvency Risk
critical$12M discrepancy between claimed ($18M) and on-chain ($6M) TVL indicates potential deception, off-chain liabilities, or a Ponzi structure, posing direct loss risk for new deposits.
Insufficient Security Validation
highSingle boutique audit from 9 months ago is outdated and inadequate for a complex cross-chain system. No public bug bounty compounds the security deficit.
Custom Fallback Oracle Manipulation
highCustom oracle, likely controlled by the same anonymous multisig, is a silent single point of failure that can be triggered to report manipulated prices and drain vaults.
Evidence
- Report generation mode: MODEL_JSON.
- Relevant memories used: 3
- Critic adjustment: 4 challenge(s), 3 resolved, 1 unresolved (high 1, medium 0, low 0) -> score adjusted -15.
- Score calibration: Complex Web3 edge case. Base 0 - 15 critic penalty = 0; profile-bounded to 25.
Integrity Proof