Concrete

Red · 11/100 Data confidence 80/100

Missing critical evidence: incident. The score is capped until coverage improves.

Executive summary

Concrete is a multi-chain DeFi yield vault and liquidity metalayer protocol operating on Ethereum, Arbitrum, Berachain, and Stable with $976M TVL, scoring 29/100 (red band).

  • Security: Eight audits listed (Halborn, Zellic, Cantina, Code4rena) dated December 2025–May 2026, but all audit reports are unverified as of 2026-08-29; findings, fix status, and deployed-code coverage cannot be confirmed. Bug bounty active on Cantina with $250k max reward, but payout results are not verifiable.
  • Governance & custody: Governance structure (DAO vs. company), contract ownership, multisig signers, timelock delays, and custody model are all not verifiable as of 2026-08-29. Role separation exists (Vault Admin, Strategy Manager, ZeroShadow pause authority) but full admin surface and user exit guarantees are unverified.
  • Counterparty & oracle risk: Protocol routes capital into whitelisted external DeFi protocols and CEXs, inheriting their loss/liquidation risk; specific protocol list and concentration are not verifiable. Oracle dependency exists (OraclePlug contract) but vendor, fallback design, and manipulation hardening are not verifiable as of 2026-08-30.
  • Top risks: Smart contract exploit across vaults and underlying venues; strategy/integration risk from multiple external protocols; liquidation and leverage risk if collateral depegs; liquidity/redemption risk under stress; execution/market risk from slippage and oracle errors. Protocol states losses can be partial or total and yield is not guaranteed.
  • Team & reputation: Team has tradfi/crypto backgrounds (Point72, Morgan Stanley, Galaxy Digital) and funding from Polychain Capital, VanEck, Portal Ventures; however, founder identities and legal entity are only partially public. No fraud, rug-pull, or sanctions allegations found, but comprehensive verification is not possible.
  • Stress scenarios: Collateral depeg, counterparty insolvency, and negative yield impacts are not verifiable as of 2026-08-29 due to lack of on-chain exposure data and vault-specific loss distribution.
  • Unverified: Native token existence, tokenomics, contract addresses, chain-specific deployment status, reserve/treasury custody, key management (HSM/MPC/multisig), and all audit report contents are not verifiable as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 20 5.0 0 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 50 12.5 0 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 60 9.0 0 onchain, 15 two-source, 6 one-source of 30 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 20 2.0 timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Concrete is a multi-chain DeFi “liquidity metalayer” and yield vault protocol providing automated, risk-managed strategy vaults, a native money market, and liquidation protection for leveraged positions. ### Identification

  • Name: Concrete (often branded as *Concrete Protocol* or *Concrete Liquidity MetaLayer*)
  • Website / App: app.concrete.xyz (primary dApp URL, also referenced by Berachain governance and data aggregators).
  • Docs: docs.concrete.xyz, describing borrowing/liquidation protection and automated yield strategies.
  • Category:
  • DeFi yield / strategy vaults and capital allocator.
  • Lending / money market + liquidation protection (fixed-term credit lines).
  • Launch date: Not verifiable as of 2026-08-29 (aggregators list TVL but do not clearly state mainnet launch date).
  • Chains:
  • Ethereum – largest share of TVL (~90%+).
  • Arbitrum – smaller share of TVL (~1–2%).
  • Berachain – active vault integrations (e.g., USDC/USDT/USDe/sUSDe, WETH, LBTC/WBTC) via Berachain forums and Lombard vaults.
  • Other chains (e.g., BSC, “Other, ArbitrumCorn”) mentioned as deployment targets in a 2024 audit contest repo, but specific production status is not verifiable as of 2026-08-29.
  • User-supplied “Stable” chain label: not verifiable as of 2026-08-29.
  • Native token: No clearly documented governance or utility token is visible in the retrieved sources; not verifiable as of 2026-08-29. ### Core contracts & verification Because direct on-chain tooling is unavailable this turn, main contract addresses and explorer verification status are not verifiable as of 2026-08-29. Data aggregators (DefiLlama, MrDeFi) list Concrete TVL per chain but do not expose canonical contract lists; Berachain governance posts reference Concrete vaults but provide no addresses. ### Fork lineage / upstream relationships
  • The protocol is described as a bespoke “liquidity metalayer” and vault + credit facility stack, not explicitly as a fork of a named upstream (e.g., Aave, Maker, Gearbox).
  • A 2024 security contest repository for Concrete indicates custom logic around:
  • liquidation protection for leveraged positions,
  • capital efficiency improvements,
  • yield opportunities for liquidity providers, across multiple chains. This suggests original architecture rather than a simple fork, but exact upstream inspirations are not verifiable as of 2026-08-29.
  • Audits: The Code4rena contest repo shows Concrete underwent a competitive audit/wardens review in November 2024. Full formal audit reports (from specific firms) are not verifiable as of 2026-08-29.
  • Malicious modifications / fork exploits: No evidence in retrieved sources of malicious contract changes or exploits in Concrete or known forks. As there is no confirmed fork lineage, malicious-modification history in similar forks is not verifiable as of 2026-08-29. ### Contradiction callout
  • TVL figures: MrDeFi reports ~US$759m TVL on Ethereum and smaller amounts on Arbitrum/Berachain, while DefiLlama reports materially lower aggregate TVL (~US$12.95m on Arbitrum and different totals). These analytics platforms rely on different methodologies and are aggregator interpretations, not on-chain verified data.
Evidence (15)

maturity

two sources

Concrete’s docs present a real product portal rather than a mere landing page: they describe ERC-4626 vaults, a user journey, and step-by-step deposit/withdraw flows, including both instant and epoch-based withdrawals. The docs also describe the dApp as wallet-connected and state that users interact through the vault, which is consistent with live application functionality rather than static marketing copy. I did not find web evidence in the retrieved sources of broken links, fake TVL/holder metrics, or obvious template-site signs; those checks are not verifiable as of 2026-08-29. The same applies to whether deposits/withdrawals are currently live on all listed chains (Arbitrum, Berachain, Ethereum, Stable) rather than only documented in theory; that is not verifiable as of 2026-08-29. An open API is not clearly evidenced for the Concrete protocol in the retrieved material. The only API result was for a different product named Concrete CMS, so it does not verify an open API for this protocol; therefore, open API status is not verifiable as of 2026-08-29.

Evidence (4)

Security

audit

unverified

Earn v2 - Whitelisting Hook. The Concrete docs list this audit as dated December 18, 2025. The public results surfaced here do not include the underlying report, so the auditor/date/scope are identifiable, but the critical/high/medium findings, fix status, and whether it covers deployed code are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2025-12-18
Scope
Earn v2 - Whitelisting Hook
Evidence (1)

audit

unverified

AssetCX. The Concrete docs list this audit as dated January 09, 2026. The surfaced sources do not expose the report contents, so findings and bytecode-match/deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-01-09
Scope
AssetCX
Evidence (1)

audit

unverified

Looping Strategy Swapper Contract. The Concrete docs list this audit as dated February 13, 2026. The report itself was not surfaced, so the severity breakdown, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-02-13
Scope
Looping Strategy Swapper Contract
Evidence (1)

audit

unverified

Earn V2 Core. The Concrete docs list this audit as dated February 20, 2026, and Halborn’s report page describes a security audit of Concrete’s smart contract ecosystem. The report page for a different Concrete audit also shows how Halborn reports scope, assessed commit IDs, and finding status, but the specific Earn V2 Core report text was not surfaced in the search results, so the exact critical/high/medium breakdown, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-02-20
Scope
Earn V2 Core
Evidence (2)

audit

unverified

Earn V2 - Improvements & priority withdrawal mechanism. The Concrete docs list this audit as dated March 2, 2026. The audit report content was not surfaced in the results, so findings/fix status and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-03-02
Scope
Earn V2 - Improvements & priority withdrawal mechanism
Evidence (1)

audit

unverified

Earn V2 - Position Management Helper. The Concrete docs list this audit as dated April 17, 2026. The report details were not surfaced, so findings, fix status, and deployed-code coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-04-17
Scope
Earn V2 - Position Management Helper
Evidence (1)

audit

unverified

Earn v2 - Hurdle Rate. The Concrete docs list this audit as dated April 22, 2026. The underlying report was not available in the search results, so the requested severity and fix details are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-04-22
Scope
Earn v2 - Hurdle Rate
Evidence (1)

audit

unverified

Earn v2 v1.4 & AssetCx 1.2. The Concrete docs list this audit as dated May 19, 2026. The audit report was not surfaced, so critical/high/medium findings, remediation status, and bytecode-match coverage are not verifiable as of 2026-08-29.

Auditor
Halborn
Report Date
2026-05-19
Scope
Earn v2 1.4 & AssetCx 1.2
Evidence (1)

bug bounty

one source

For Concrete (Concrete Finance), I found an active bug bounty program on Cantina with a start date of 5 Nov 2025. The published parameters are: maximum reward $250,000, with severity caps of $250,000 for Critical and $100,000 for High; findings also require a $20 deposit to participate. Additional payout constraints include a cap of 10% of direct funds at risk at the time of reporting, and final reward amounts are at Blueprint Finance’s sole discretion based on report quality, completeness, severity, and exploitability. On results: the bounty page itself does not publish completed payout totals, and I could not verify any public outcome statistics from the provided sources. So the results are Not verifiable as of 2026-08-29.

Evidence (2)

counterparty risks

two sources

Concrete’s externally visible dependency stack is only partially verifiable from web sources, so several counterparty questions remain Not verifiable as of 2026-08-30. The strongest confirmed items are that Concrete uses external auditors (Halborn, Zellic), independent monitoring/accounting partners (Hypernative, TRES), and a strategy/curation layer that interacts only with approved protocols under on-chain caps; the protocol also explicitly says curators do not control custody. Concrete’s own materials further reference an OraclePlug contract in the codebase, indicating oracle dependence, but the specific oracle provider, fallback design, and manipulation hardening are Not verifiable as of 2026-08-30 from the available sources. The main counterparty-risk buckets are therefore:

  • External protocols / composability: strategy vaults route capital into whitelisted DeFi protocols, so loss/lockup/liquidation risk inherits from those venues; exact protocol list and concentration by chain are Not verifiable as of 2026-08-30.
  • Oracle / manipulation risk: an oracle layer exists in the codebase, so price-feed failure or manipulation can affect swaps/valuations; the concrete oracle vendor and mitigation controls are Not verifiable as of 2026-08-30.
  • Operational counterparties: Halborn/Zellic, Hypernative, and TRES are meaningful off-chain dependencies for assurance, monitoring, and reconciliation.
  • Bridge / chain exposure: Concrete is discussed across Arbitrum, Berachain, Ethereum, and Stable, but the cross-chain transport/bridge model and any canonical bridge or messaging dependency are Not verifiable as of 2026-08-30.
  • Custody / CEX / MM exposure: no reliable evidence was found that Concrete relies on custodians, CEX market makers, or treasury managers; Not verifiable as of 2026-08-30.
  • RWA issuer / SPV exposure: no verified evidence of RWA-SPV dependency was found; Not verifiable as of 2026-08-30.
  • Stablecoin / LST / restaking exposure: one independent source notes restaking/LST structures can amplify liquidation risk if an LRT depegs, but Concrete-specific exposure to LSTs or restaking is Not verifiable as of 2026-08-30. A practical failure scenario is: oracle malfunction or manipulation → incorrect pricing/allocation → bad strategy execution or unsafe withdrawals; separate failure of an external protocol used by a vault can also impair redemption or NAV. Because chain-by-chain exposure and asset mix were not verifiable here, the precise magnitude of each counterparty risk remains unknown.
Evidence (7)

crypto custody

two sources

Concrete’s custody model is not verifiable as of 2026-08-29 from the provided sources. The available results explain crypto custody in general: custody usually means a party holds or controls private keys, with common models including self-custody, third-party custody, and shared-control / multisig arrangements, often combined with hot, warm, or cold storage tiers. They also note that institutional custody commonly uses regulated custodians, segregated assets, and role-based approvals. However, none of the provided sources establish how Concrete specifically organizes custody across Arbitrum, Berachain, Ethereum, or Stable, so any protocol-specific claim would be unverified marketing claim.

Evidence (6)

key management

two sources

Not verifiable as of 2026-08-29. The available search results do not identify Concrete’s specific key-management design (for example, whether it uses an HSM, multisig, MPC, role-based access, rotation policy, or chain-specific admin keys), and the results provided are only generic cryptographic key-management guidance rather than protocol-specific documentation. From the supplied evidence, the only defensible statement is that *key management* generally covers key generation, distribution, storage, rotation, revocation, and destruction, with access controls and secure storage as standard best practices. For Concrete on Arbitrum, Berachain, Ethereum, and Stable, the protocol-specific organization of key management is therefore Not verifiable as of 2026-08-29 from the current sources. If you want, I can next help you build a source checklist to verify the protocol’s admin keys, upgrade keys, custody model, and any chain-specific governance or signer setup once protocol-specific materials are available.

Evidence (3)

smart-contract

one source

Concrete’s public documentation confirms role separation and delegated pause authority: governance roles are split into Vault Manager, Strategy Manager, and Hook Manager, held by the Vault Admin, while ZeroShadow can pause vaults per mandate. Concrete also publishes an audit page with a specific withdrawal pause item dated January 7, 2025, which indicates pause-related controls exist, but the full admin surface, proxy topology, and renunciation status are not verifiable from the gathered sources alone. I could not verify the protocol’s contract addresses, proxy/admin implementation, timelock delay, or whether users can always exit without admin intervention, so those items are Not verifiable as of 2026-08-29. | Area | Finding | |---|---| | Contract addresses / chain mapping | Not verifiable as of 2026-08-29 | | Verification status | Not verifiable as of 2026-08-29 | | Upgradeability / proxy architecture | Not verifiable as of 2026-08-29 | | Proxy admin type | Not verifiable as of 2026-08-29 | | Owner / emergency roles | Vault Admin, ZeroShadow pause authority are documented | | Pause / withdrawal controls | Withdrawal pause is referenced in audits; exact mechanics not verifiable | | Upgrade / fee / oracle / strategy functions | Vault Manager / Strategy Manager / Hook Manager are documented, but function-level permissions are not fully verifiable | | Renounced roles | Not verifiable as of 2026-08-29 | | Timelock delay | Not verifiable as of 2026-08-29 | | User exit without admin | Not verifiable as of 2026-08-29 | | Worst case if keys compromised | A compromised Vault Admin or pause authority could likely pause or redirect high-impact governance actions; exact blast radius is Not verifiable as of 2026-08-29 | Architecture map: Users → Vaults → Vault Admin (Vault Manager / Strategy Manager / Hook Manager) → ZeroShadow pause authority; underlying proxy/admin/timelock layer not verifiable from current sources. Diagram: Users → Vaults → Vault Admin → {Vault Manager, Strategy Manager, Hook Manager} ↘ ZeroShadow (pause) Because Dune/on-chain verification is unavailable in this run, any claim about proxy admin type, upgrade control, or timelock is unverified and should be treated as a gap rather than an assumption.

Evidence (2)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Concrete appears to be built by a globally distributed, institution-facing team with tradfi and crypto backgrounds, but individual founders are only partially identifiable and the legal/office footprint is not fully transparent. Founders & team identity

  • A Mirror article by “Blueprint Finance” (Concrete’s parent) describes Concrete as its flagship product and states the team has worked at Point72, Morgan Stanley, Galaxy Digital, Caxton, Tala, Polkadot, Eco and more, indicating strong tradfi/crypto pedigrees but without naming specific founders.
  • Berachain governance proposals for Concrete vault rewards list a contact nadim@blueprintfinance.com, implying at least one public-facing lead (likely business/devrel) but not giving a full founder roster.
  • Concrete’s own blog and ecosystem pages reference roles like Chief Growth Officer (Luke Hajduckiwicz), confirming at least some non-anonymous executives. Public vs. anonymous; credibility signals
  • The combination of:
  • Named executives (e.g., Chief Growth Officer),
  • Corporate-facing branding via Blueprint Finance,
  • Use of real names/emails in Berachain governance, suggests a semi-public team: not fully anon, but without a clearly published “founders” page.
  • Concrete/Blueprint highlight prior employment at major institutions (Point72, Morgan Stanley, Galaxy Digital, Caxton), which is a credibility positive if accurate, but this remains an unverified marketing claim absent external HR or regulatory records. Funding, investors & business reality check
  • Concrete (via Blueprint) disclosed $7.5m seed funding led by Hashed and Tribe Capital in late 2024, plus a later $9.5m round led by Polychain Capital with participation from VanEck, Auros, Selini, Gate Ventures and others, signaling strong institutional investor backing.
  • Multiple analytics platforms (DefiLlama, AprScope, MrDeFi) show $800m–$900m+ TVL across Ethereum, “Stable”, Berachain, Arbitrum, and smaller chains, consistent with Concrete being a large, active yield infrastructure protocol rather than a thin web front. Prior projects, outcomes, hacks
  • No credible reports of major hacks or catastrophic losses tied to Concrete or Blueprint were found in current analytics or media coverage. Not verifiable as of 2026-08-29.
  • No clear documentation of founders’ prior on-chain projects (by name/address) is available; team history is described only at a high level. Jurisdiction, office, onshore/offshore
  • No reliable information on registered legal entity, jurisdiction, or physical office locations could be confirmed from governance, analytics, or independent media. Not verifiable as of 2026-08-29.
  • Communications frame the team as “globally distributed”, suggesting a remote-first structure without an obvious single headquarters. Reality check
  • Evidence supports a real, revenue-seeking business with substantial TVL and institutional investors, but:
  • Exact founder identities,
  • legal entity/jurisdiction,
  • and physical office presence remain insufficiently disclosed to perform full institutional KYC-level diligence.
  • Any risk memo should flag founder identity and corporate registration as open items for direct confirmation with the team or investors.
Evidence (8)

general reputation

two sources

Concrete appears to have a generally positive reputation in DeFi data sources: DefiLlama lists it as a multi-chain yield protocol with two reported audits and recent venture funding rounds, including investors such as Polychain Capital, YZi Labs, VanEck, Portal Ventures, and others. AprScope also describes the protocol as operating across Ethereum, Stable, Berachain, and Arbitrum and says it has completed 2 audits. On founders and team reputation, the available sources did not provide independently verified founder identities or detailed team background, so that is Not verifiable as of 2026-08-29. Investor reputation is stronger than team reputation here because the funding information is listed by an established analytics platform, but it is still an aggregator claim rather than primary-source confirmation. I did not find credible independent reports of fraud, rug-pull allegations, insolvency events, or sanctions specific to Concrete. No legal or regulatory actions against Concrete were surfaced in the retrieved results, and no sanctions hit was identified. The main unresolved concerns are standard DeFi ones: smart-contract risk, cross-chain complexity, and reliance on third-party audits rather than on-chain verification in this run. One source explicitly notes that a comprehensive risk assessment would require review of the underlying audit reports and findings, which were not available in the retrieved material. In short: Concrete currently looks like a funded, audited-yet-still-normal-risk DeFi protocol with no surfaced public scandal, but founder-level diligence, audit-depth review, and sanctions screening remain Not verifiable as of 2026-08-29.

Evidence (4)

Economy

TVL: $975.9M

model

two sources

Concrete is a multi-chain, vault-based yield and credit protocol built by Blueprint Finance, with institutional focus and both DeFi and CEX strategy exposure. ### Strategy & Assets

  • In-going assets: Primarily stablecoins (USDC, USDT, thUSD, sUSDe), blue-chip crypto (WETH, BTC wrappers, ARB) deposited into vaults.
  • Out-going exposures: Lending markets (e.g., Aave/Compound—per aggregator descriptions), on-chain basis/arbitrage trades, and CEX strategies routed by Concrete’s “liquidity metalayer.”
  • Several vaults (e.g., DeFi USDT vault) employ *delta-neutral arbitrage* strategies, implying minimal directional token price exposure. ### Yield Sources & Nature
  • Yield is mainly organic from lending interest, funding/basis spreads, and arbitrage; Concrete emphasizes “transparent, sustainable performance” and institutional-grade modeling.
  • There is also subsidized yield where Concrete seeks external reward programs (e.g., Berachain RFRV requests for Concrete vaults).
  • Strategies are largely market-neutral (arbitrage, hedged positions) but some vaults are implicitly directional when using collateralized leverage in money markets. ### Leverage, Restaking, External Exposure
  • Concrete operates as an on-chain capital allocator across DeFi platforms and CEXs, using borrowing and rehypothecation-like flows in its own money market and credit facilities.
  • Vaults can be leveraged via borrowing against collateral in integrated markets; liquidation protection credit structures reduce forced unwinds but do not remove leverage risk.
  • No evidence of restaking; external exposure comes mainly from DeFi lending, DEXs, and CEX integrations. ### Lock-ups, Withdrawals, Fees
  • Public docs and aggregators describe vault deposits/withdrawals, but specific lock-up periods, withdrawal queues, and fee schedules (performance/management/exit) are Not verifiable as of 2026-08-30. ### Protocol Revenue
  • Revenue arises from vault fees (performance/management) and potentially spreads on credit facilities, but detailed splits and P&L are Not verifiable as of 2026-08-30. ### Collateral & Risk Profile
  • Collateral: stablecoins, blue-chip L1 assets, and RWA-linked tokens like thBILL/thUSD used in structured products.
  • Concrete offers liquidation protection by inserting an on-chain credit layer over existing lending markets, reducing liquidation events at the cost of complexity and counterparty/contract risk. ### TVL & APY
  • DefiLlama / AprScope report ~$850–965M TVL across 4 chains, with Arbitrum around $13M, and multiple active vaults (e.g., THUSD-USDC-ARB pool).
  • Detailed TVL by product/chain over time, APY history, and volatility are Not verifiable as of 2026-08-30 due to lack of direct on-chain analytics access in this run. ### Chain Split
  • Concrete is Ethereum-based but runs vaults on Ethereum, Arbitrum, Berachain, and a “Stable” chain, plus CEX strategies.
  • Precise TVL percentage per chain is Not verifiable as of 2026-08-30.
Evidence (15)

reserves

two sources

Not verifiable as of 2026-08-29. The web results do not provide a protocol-controlled treasury map, reserve addresses, custody structure, reserve policy, or on-chain balance evidence for Concrete on Arbitrum, Berachain, Ethereum, or Stable. The only concrete (non-authoritative) data found is aggregator TVL by chain, which is not the same as treasury/reserves: DefiLlama shows $642.85m Ethereum, $70.53m Stable, $41.97m Berachain, and $12.95m Arbitrum (plus $1,088 Katana) for total TVL, while AprScope reports similar chain splits and a higher total TVL; these are protocol TVL estimates, not reserve attestations. The protocol docs describe ERC-4626 vaults and strategies, but do not specify reserve custody, governance control, or an audited treasury policy in the retrieved material.

Evidence (3)

tokenomics

one source

Not verifiable as of 2026-08-29. The available web evidence indicates Concrete is a multi-chain yield protocol on Ethereum, Arbitrum, Berachain, and Stable, but it does not show a confirmed native token, ticker, or contract address. A third-party article from March 2025 explicitly said Concrete had not launched a token yet, and the more recent web results reviewed here still only show vault/product pages and protocol documentation, not a token listing or tokenomics page. Because no on-chain verification was available in this run, total vs. circulating supply, market cap/FDV, emissions, unlocks, allocations, holder concentration, insider wallets, mint/blacklist/fee-switch controls, and whether any announced unlocks happened on-chain are all Not verifiable as of 2026-08-29. The same applies to revenue share, buybacks, burns, staking rewards, and DEX liquidity depth/main listings. If Concrete now has a token, its existence and mechanics would need confirmation from a non-protocol source or on-chain data before treating any tokenomics claim as reliable.

Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would be a severe tail-risk stress event for Concrete, not a base-case assumption. In that regime, the main risk channels are collateral devaluation, liquidation cascades, redemption/run pressure if BTC is part of any backing asset set, and LP imbalance in any BTC-correlated pools; however, Concrete-specific exposures and contract-level risk are Not verifiable as of 2026-08-29 from the available sources. Because the available results are market commentary about Bitcoin rather than protocol disclosures or on-chain data, they support only the macro stress assumption, not Concrete’s actual loss distribution or solvency buffer. The cited analyses describe sub-$10,000 BTC as an extreme scenario associated with synchronized liquidity shocks, institutional deleveraging, and confidence breakdowns. For Concrete on Arbitrum, Berachain, Ethereum, and Stable, the prudent stress-test framing is:

  • If BTC is a reserve/reference asset: mark-to-market losses could force a sharp contraction in treasury or backing value.
  • If BTC is used as collateral: higher liquidation frequency and weaker bid depth can amplify losses.
  • If users supply BTC-correlated assets: pool imbalance and impermanent loss can rise quickly.
  • If the protocol depends on market confidence: withdrawals and TVL compression can accelerate once BTC breaks major psychological levels. A protocol-specific answer would require verified details on Concrete’s asset mix, leverage, liquidation rules, and chain-by-chain TVL/exposure; those are Not verifiable as of 2026-08-29 from the provided sources. Given the source set, the only defensible conclusion is that a sub-$10,000 BTC shock would be high-impact and likely stress liquidity and user confidence, but the magnitude for Concrete cannot be quantified here.
Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-08-29. The provided search results do not include protocol-specific, chain-specific on-chain exposure data for Concrete on Arbitrum, Berachain, Ethereum, or Stable, so a 20% depeg stress estimate for the largest collateral cannot be computed reliably. The only relevant materials returned are generic stress-test methodology references and unrelated DeFi examples, not verified Concrete positions or collateral concentrations. If you need this assessed, the required inputs are: the largest collateral asset by chain, its current protocol exposure, liquidation thresholds, and the borrow/debt distribution for each market; without those, any numeric stress result would be speculative.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Concrete’s documented stress path is not a classic pooled-loss model; the protocol says recovery in insolvency/default is limited to assets and collateral attributable to the affected vault or strategy, and claims priority generally goes to protocol lenders/liquidators first, then amounts owed to Concrete, then users through vault shares. The result is that a top counterparty insolvency is expected to hit the specific vault/strategy first, with losses absorbed by the collateral and lending structure tied to that vault, not by unrelated vaults.

  • Expected loss path: if the borrowed/underlying leg loses value or depegs, the position can be liquidated; if liquidation proceeds are insufficient, the remaining shortfall becomes bad debt inside that vault/strategy.
  • Who absorbs it: first the secured lenders/liquidators claim the collateral proceeds, then Concrete’s contractual fees/amounts owed, and only after that do vault users receive any residual value through their shares.
  • Compensation: Concrete’s stated mitigation is its three-tranche protection system, which injects credit before liquidation and can keep a borrower from being liquidated; if all three tranches are used, Concrete forecloses the position and returns residual assets to the borrower while preventing lender bad debt accrual.
  • Impact path through smart contracts: the protection contract/top-up logic adds collateral as the position approaches threshold; if market stress continues, the liquidation/foreclosure logic closes the position, realizes collateral, and distributes proceeds by contract priority. For chain-specific exposure, the available source confirms Concrete has deployments on Ethereum, Stable, Berachain, and Arbitrum, but a chain-by-chain loss split is Not verifiable as of 2026-08-29 from the available evidence.
Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For committed fraud by the DAO or owners, I found no verifiable evidence that Concrete’s DAO, founders, or owners have been accused of or proven to have committed fraud. As of 2026-08-29, this is Not verifiable as of 2026-08-29 from the available non-onchain sources. What I *can* say is that the legal and risk literature on DAOs shows a relevant failure mode: if founders or governance participants misuse control, courts may treat DAO actors as potentially liable, especially where tokenholders or controllers are alleged to function like a partnership or where a private key/administrative control is used to move funds improperly. Those sources are about DAO liability in general, not Concrete specifically. I also did not find a Concrete-specific fraud case, regulator action, audit finding, or credible media report in the provided results. Because the protocol website is not a primary source for this question and on-chain verification is unavailable in this run, I cannot substantiate a fraud stress scenario beyond the generic DAO-risk framework. For a conservative institutional risk view, the correct treatment is: no confirmed fraud event found, but governance/key-control fraud remains a plausible tail risk for any DAO-style protocol until independently disproven by audits, governance records, and on-chain review.

Evidence (3)

stress scenario - primary yield source negative 30d,

one source

Concrete docs state that yields are not guaranteed and that strategy losses reduce share price, so a negative 30d primary yield source means the protocol is in a stress state where the core earning leg has recently lost money rather than generated income. For Concrete’s multi-chain setup, I could not verify on-chain which chain or vault is driving the negative 30d primary yield because Dune/on-chain checks are unavailable in this run; the chain-level exposure is Not verifiable as of 2026-08-29. The most relevant independent warning in the available results is Hindenrank’s assessment that Concrete uses multi-strategy vaults across Aave, Curve, Morpho, and EigenLayer, and that correlated drawdowns can cause losses even when diversification appears broad. In practical risk terms, this scenario usually implies one of three things: the underlying strategy APR has turned negative, incentive emissions have faded, or losses/fees have overwhelmed gross yield; however, which of these is happening for Concrete is Not verifiable as of 2026-08-29 from the available web results alone.

Evidence (2)

Governance & Legal

governance

one source

Concrete appears to be an early-stage / concept-phase DeFi project, and most of the governance details requested are not verifiable from independent sources as of 2026-08-29. 1. Existence and scope of the protocol

  • Web search returns references to generic "concrete" terms, construction, and unrelated projects; there is no clearly identifiable DeFi protocol named Concrete with the given slug operating on Arbitrum, Berachain, Ethereum, Stable that can be matched to contracts or a coherent ecosystem.
  • Without confirmed contract addresses or documentation tied to those chains, all on-chain aspects (ownership, timelocks, multisigs, voting concentration) are Not verifiable as of 2026-08-29. 2. Governance structure (DAO vs company)
  • No independent governance documentation (forum, docs, snapshot spaces, GitHub governance repos, or legal entity disclosures) can be reliably associated with this Concrete protocol.
  • Therefore, whether governance is DAO-based, company-controlled, or purely symbolic is Not verifiable as of 2026-08-29. 3. Control over dev, contracts, frontend, and funds
  • Usual checks would be: owner/admin roles in core contracts, multisig addresses and signers, and DNS/hosting for frontends. These all require known contract or domain references.
  • Because no such references can be confidently linked to this Concrete protocol, who controls development, upgrade rights, frontends, or treasury/funds is Not verifiable as of 2026-08-29. 4. Timelocks, multisig design, voting concentration
  • Standard institutional review would examine:
  • Timelock delays on administrative functions.
  • Multisig threshold (e.g., 2-of-3, 4-of-7), signer independence, and powers.
  • Token distribution, top holders, and Snapshot/Dune voting concentration.
  • In absence of confirmed token contract(s) or governance contract(s), none of these items can be measured or confirmed; all are Not verifiable as of 2026-08-29. 5. Legal entity, jurisdiction, ToS
  • No trustworthy references to a Concrete protocol-operated legal entity (company name, jurisdiction, registration number, directors) or binding Terms of Service are found.
  • Any such information would be speculative; thus legal control and regulatory posture are Not verifiable as of 2026-08-29. From an institutional risk perspective, the inability to even confirm the protocol’s operational existence and governance footprint is itself a critical finding: Concrete cannot be assessed as an operational DeFi protocol on the named chains based on available independent data as of 2026-08-29.
Evidence (2)

legal & regulatory

one source

Concrete appears to be a newer / smaller protocol with limited independent coverage; most legal/regulatory aspects are therefore not verifiable as of 2026‑08‑30 from high‑quality sources. ### 1. Entity, jurisdiction, legal structure

  • I could not locate a clearly identified legal entity, corporate registration, or jurisdiction (e.g., Cayman foundation, Delaware LLC) tied to “Concrete” across Arbitrum, Ethereum, Berachain or a “Stable” chain.
  • This includes searches for “Concrete DeFi”, “Concrete protocol Arbitrum/Ethereum/Berachain”, and combinations with “foundation”, “labs”, “Ltd”, “LLC”, or “DAO”.
  • No independently verifiable Terms of Service or legal/Privacy Policy pages could be confirmed that are clearly linked to this specific protocol (matching contracts/chains). Implication for risk: From an institutional standpoint, treat Concrete as effectively anonymous / unregistered until a verifiable entity and jurisdiction are found. That increases counterparty and enforcement risk. ### 2. KYC / AML, user restrictions
  • I did not find reliable documentation indicating whether Concrete enforces KYC/AML, geo‑blocking (e.g., US persons), or sanctions screening.
  • No integration with well‑known compliance providers (e.g., Chainalysis/KYB vendors) is independently documented. Risk view: Assume no KYC/AML, typical of permissionless DeFi, implying higher regulatory sensitivity (especially for US/EU‑regulated institutions). ### 3. Regulatory classification, warnings, enforcement
  • No credible references from regulators (SEC, CFTC, FCA, ESMA, MAS, etc.) mentioning “Concrete” as a supervised entity, target of enforcement, or subject of an investor warning.
  • No entries found linking Concrete to sanctions lists (OFAC, EU, UN) or designated persons.
  • No public court cases or litigation involving Concrete, its team, or foundation were identified. Risk view: Absence of enforcement does not imply low risk; it mainly reflects Concrete’s low profile or youth. Regulatory treatment of yield‑generating DeFi remains unsettled, and institutional users bear residual legal risk. ### 4. Data protection / privacy
  • Without a verifiable website ToS/Privacy Policy, obligations under GDPR/CCPA or other data‑protection regimes are Not verifiable as of 2026‑08‑30. ### 5. Overall legal‑regulatory risk assessment (institutional lens)
  • Key gaps: Unknown legal entity, unclear jurisdiction, missing ToS/Privacy Policy, no visible compliance framework, no documented classification (fund, note, derivatives, etc.), and no formal disclosures.
  • For an institutional risk framework, Concrete currently falls into a high legal/regulatory uncertainty bucket: usable only with strict size limits, enhanced approvals, and an assumption of no enforceable investor protections beyond on‑chain mechanics.
Evidence (3)

Stability

stability

two sources

Not verifiable as of 2026-08-29 for the specific Concrete protocol stablecoin(s) on Arbitrum, Berachain, Ethereum, and Stable, because the provided sources cover *general* stablecoin depeg history, not Concrete’s selected stablecoin or its market history. The only supported answer is that stablecoin depegs have happened in the broader market multiple times, but I cannot attribute any count, last occurrence, or depeg percentage to Concrete without a verified token identity and price history. If you want, I can next help identify Concrete’s exact stablecoin ticker/contract and then assess whether it ever depegged using chain-specific evidence.

Evidence (4)

Risks & Strengths

risks

two sources

Concrete’s main risks are: smart contract/exploit risk across the vault and any underlying DeFi venues, strategy/integration risk from deploying into multiple external protocols, liquidity and redemption risk if large withdrawals or stressed markets force asset sales at poor prices, leverage/liquidation risk where collateral declines or depegs can trigger losses, and execution/market risk from slippage, oracle errors, or front-running during rebalancing. Concrete’s own disclosures say vault assets are not government-insured, yield is not guaranteed, losses can be partial or total, and underlying protocol failures or oracle issues can impair recovery.

Evidence (4)

strengths

unverified

Concrete’s top strengths are: automated yield deployment, yield-bearing vault shares, liquidation protection / borrowing automation, modular security architecture, and institutional risk controls with audits and monitoring. Its docs describe a “one deposit, fully deployed” model where capital is allocated across strategies behind the scenes, while users hold ERC-20 vault shares that accrue value through exchange-rate growth. The protocol also emphasizes protection policies and pre-emptive monitoring to reduce liquidation risk in borrowing workflows. Concrete’s security model separates governance and operational roles, keeps assets in custody via multisig/MPC wallets, constrains accounting updates on-chain, and uses independent monitoring plus pause authority; the docs also say the codebase has been audited by Halborn, Cantina, Zellic, and Code4rena. A secondary strength is its modular architecture, which is designed so components can be updated or replaced without disrupting the whole system. Finally, Concrete is positioned as multi-chain and cross-environment compatible, with references to EVM and Solana Virtual Machine integration in the ecosystem overview.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 1 of 24 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 6 one source, 9 unverified.
  • Oldest fact verification date: 2026-08-29.