Dolomite

Red · 5/100 Data confidence 91/100

Executive summary

Dolomite is a margin lending/borrowing protocol and DEX deployed on Arbitrum, Ethereum, and Berachain, scoring 5/100 (red band) due to severe governance centralization, unverified custody controls, and material incident history.

  • Security: Multiple audits of core contracts and modules are claimed (Guardian found 2 Critical, 4 High, 13 Medium findings in GMX V2 module, all reportedly remediated), but audit scope and remediation verification remain unverified as of 2026-08-29. Bug bounty program exists via email (security@dolomite.io) with OWASP-based rewards, but no public payout data, scope, or results are verifiable; CertiK lists "No" for both CertiK and 3rd-party bounties.
  • Incidents: March 2024 legacy Ethereum contract exploit drained ~$1.8M from 187 users; Dolomite recovered 90% and covered the rest from treasury. August 2026 address-poisoning theft of ~$165k in BLOCK/DOLO tokens is reported but not verifiable as a protocol-level incident.
  • Governance & custody: Protocol is semi-centralized with team-controlled multisigs and admin roles; no verified timelock details, signer lists, or renounced ownership. veDOLO token-weighted governance exists, but execution is by Leavitt Innovations LLC. A claimed 5/9 multisig and 48-hour timelock are unverified. Non-custodial user model, but protocol contracts hold deposited assets.
  • Top risks: (1) Smart-contract complexity in virtual-liquidity and margin system increases bug surface; (2) liquidation/bad-debt risk in volatile markets; (3) oracle dependence (Chainlink + DEX TWAPs) creates mispricing and manipulation exposure; (4) counterparty risk from GMX, GLP, Camelot LP integrations—collateral collapse or oracle failure can trigger cascading liquidations; (5) governance/regulatory uncertainty and fragmented cross-chain liquidity.
  • Strengths: Capital efficiency via virtual liquidity allowing multi-role deposits; preservation of native asset utility and rewards; broad asset support (thousands of assets claimed); isolated margin accounts to contain position risk; modular core/module architecture for extensibility.
  • Founders & legal: Co-founders Corey Caplan (CEO) and Adam Knuckey (COO) are public and US-linked; corporate structure spans Delaware (Leavitt Innovations Inc.), Marshall Islands DAO, BVI (Dolomite Ltd.), and Cayman Foundation. Terms restrict US Persons and sanctioned jurisdictions; KYC requirement is not verifiable.
  • Tokenomics: No live native DOLO token is verifiable on-chain as of 2026-08-30; all tokenomics claims are prospective/unverified marketing. Protocol yield is organic from borrower interest (lenders receive ~90%), not emissions-driven.
  • Unverified: Exact multisig signers, timelock parameters, treasury addresses/balances, on-chain contract addresses for all chains, bug-bounty results, current token deployment, and chain-specific TVL/exposure are not verifiable as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 20 5.0 0 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 15 3.8 1 incident(s) in 730-day window, losses $165,000; 0 high/critical news
verifiability 15% 64 9.6 0 onchain, 16 two-source, 4 one-source of 28 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Dolomite is a DeFi money market + margin trading + DEX protocol originally launched on Ethereum, now primarily associated with Arbitrum and later expanded multi‑chain. ### Identification

  • Name: Dolomite
  • Website / App: dolomite.io and app.dolomite.io (interface referenced in docs).
  • Docs: Hosted at docs.dolomite.io, covering protocol overview and user guides.
  • Category: Lending + margin trading + spot DEX (money market protocol with leveraged trading).
  • Launch dates: Ethereum deployment around 2019; Arbitrum deployment in 2022.
  • Chains (per off‑chain sources):
  • Arbitrum One (main chain and focus).
  • Ethereum L1.
  • Berachain, Polygon zkEVM, Botanix, Mantle, X Layer mentioned as supported/expansion chains. On‑chain verification of those deployments: Not verifiable as of 2026‑08‑29.
  • Native token: DOLO, described as an ERC‑20 governance/utility token. On‑chain token contract address and supply: Not verifiable as of 2026‑08‑29. ### Main contracts (high‑level)
  • Multiple sources describe a core system called “Dolomite Margin”, a suite of Solidity smart contracts on Arbitrum for lending, borrowing, margin, and spot trading.
  • Yield/analytics platforms list numerous “Dolomite [asset] Lending” markets on Arbitrum (e.g., WETH, DAI, USDC.e, LINK, WBTC, ARB, magicGLP, wstETH, tBTC, USDe, uniBTC, eUSD, ETH+, etc.), implying each asset market corresponds to a lending contract or configuration. Exact contract addresses, explorer verification status (verified source code / proxy patterns), and any Berachain / Ethereum deployment details: Not verifiable as of 2026‑08‑29. ### Fork lineage and modifications
  • Multiple independent educational sources state Dolomite’s original upstream is dYdX Solo Margin, i.e., Dolomite began as a fork of dYdX’s Solo Margin protocol.
  • Dolomite is described as extending this base with:
  • broader token support (hundreds to 1,000+ assets across chains),
  • integrated spot DEX and lending in one account‑based margin system,
  • “virtual liquidity” architecture for capital efficiency.
  • Audit status of Dolomite’s changes vs. dYdX:
  • No independent audit report from a recognized auditor was identified in the retrieved data; therefore audit coverage of the forked and modified contracts is Not verifiable as of 2026‑08‑29.
  • History of malicious modifications in similar forks (i.e., other dYdX Solo Margin forks): Not verifiable as of 2026‑08‑29 with the currently available information. All on‑chain facts (addresses, TVL, verification badges) are missing for this run and must be treated as unverified; any protocol or marketing descriptions sourced from Dolomite’s own site or Medium are unverified marketing claims unless corroborated by independent analytics or media.
Evidence (15)

maturity

two sources

Dolomite appears to be a live product, not just a landing page: its site advertises a usable app with deposit/borrow flows, and the docs include concrete transaction paths for depositing and withdrawing via a router contract. The documentation also describes on-chain user actions, which is consistent with an operational DeFi app rather than a static marketing site. For maturity signals, the presence of developer docs, deposit/withdraw guides, and integration docs suggests a reasonably developed UX and API surface, but a full reliability audit of links, broken pages, or template reuse is not verifiable as of 2026-08-29 from the available sources. The protocol’s own materials claim it operates on Arbitrum, Ethereum, and Berachain among other chains, but without on-chain verification here, chain-by-chain live usage and exact TVL/exposure are not verifiable as of 2026-08-29. An open API is at least partially supported by the docs: the developer guide says querying data and transaction submission go through an RPC URL, and the docs reference specific contract interfaces and methods for deposits and withdrawals. That is more like an open developer interface than a closed consumer-only portal, although a public REST API was not explicitly confirmed in the sources. Bottom line: Dolomite looks like a real, functioning DeFi protocol with active app flows and developer-facing docs, but deeper claims about live chain usage, exact supported-network activity, and UI quality issues are not verifiable as of 2026-08-29 from the available evidence.

Evidence (6)

Security

audit

unverified

Most recent audit of the Dolomite Margin Core smart contracts; Dolomite says it covers the most recent suite of updates to the core contracts.

Auditor
Cyfrin
Report Date
2025-04-24
Scope
Dolomite Margin Core smart contracts / most recent suite of updates
Evidence (2)

audit

unverified

Assessment of the GMX V2 module; Guardian states the review found 2 Critical, 4 High, 13 Medium, and 15 Low findings, all confirmed and promptly remediated, with a follow-up review of the remediations.

Auditor
Guardian Audits
Report Date
2024-01-11
Scope
Dolomite GMX V2 module / module integration review
Evidence (2)

bug bounty

one source

Dolomite appears to have an active, open bug bounty program. Its security page says the program rewards responsible disclosures under the OWASP risk framework and offers recognition and monetary rewards. The docs page instructs reporters to email vulnerabilities to security@dolomite.io. When it started: I could not verify a public launch date from the provided sources. The materials available here describe the program as open/active, but do not state a start date. Not verifiable as of 2026-08-29. Parameters: The public sources provided do not include a payout table, scope boundaries by chain, severity thresholds, or explicit maximum reward amounts. The only parameter explicitly stated is that rewards are based on the OWASP risk framework and may include monetary compensation plus recognition. Results: I could not verify any public totals for submitted reports, paid rewards, or disclosed fixes from the provided sources. Not verifiable as of 2026-08-29. One important cross-check: CertiK Skynet currently lists Dolomite with “CertiK Bounty: No” and “3rd Party Bounty: No,” which suggests Dolomite’s program is not hosted on CertiK and may be an in-house disclosure process rather than a third-party platform program.

Evidence (3)

counterparty risks

two sources

Dolomite is a margin lending/borrowing protocol and DEX; its risk profile is heavily driven by external protocols it integrates for collateral, liquidity, and pricing. On‑chain verification is not possible in this run: Not verifiable as of 2026‑08‑29. 1. External protocols & collateral dependencies

  • Dolomite on Arbitrum supports collateral such as GMX, GLP, GRAIL, Camelot LP tokens, and various ERC‑20s; GMX/GLP and Camelot are explicitly referenced as key integrations.
  • Counterparty risk: insolvency or critical bug in GMX, Camelot, or other collateral protocols can cause collateral value to collapse or become non‑redeemable, forcing liquidations and bad debt.
  • On Berachain, Dolomite is expected to integrate Berachain native assets and LPs; details remain early-stage and are marketing roadmaps. Unverified marketing claim. 2. Oracle & price‑manipulation risk
  • Dolomite indicates use of Chainlink price feeds for major assets and custom feeds or DEX TWAPs for long‑tail/LP tokens.
  • Chainlink dependency: oracle failure, delayed updates, or compromised feeds can misprice collateral and trigger under/over‑liquidation.
  • DEX‑based oracles (Camelot/GMX) are vulnerable to short‑term price manipulation via concentrated swaps if liquidity is thin, especially for LP and governance tokens. 3. Bridges & chain risk
  • Arbitrum and Berachain are rollups/L2s secured by Ethereum; L2 sequencer/bridge outages or censorship could freeze Dolomite positions or withdrawals.
  • Any non‑native bridged assets (e.g., bridged stablecoins or governance tokens) introduce bridge‑contract and custodian risk; specific bridge sets per asset are Not verifiable as of 2026‑08‑29. 4. Stablecoin, LST, and restaking exposure
  • Dolomite lists major stablecoins (USDC, USDT, DAI) and LSTs such as wstETH as collateral/borrowable assets on Arbitrum.
  • Stablecoin risk: issuer insolvency, regulatory action, or depeg (USDC/USDT) and protocol failure (DAI’s collateral) can force mass liquidations and protocol insolvency if bad debt exceeds reserves.
  • LST risk: staking slashing, LST depeg from ETH, or liquidity crises on secondary markets.
  • Restaking exposure: any use of EigenLayer‑style restaked LSTs would add smart‑contract and AVS slashing risk; current usage is Not verifiable as of 2026‑08‑29. 5. CEX/MM, custodians, and RWA exposure
  • No direct centralized custodians or RWA issuers are clearly documented; Dolomite appears primarily crypto‑native. Not verifiable as of 2026‑08‑29 for any off‑chain custody or RWA SPVs. Key failure scenarios
  • Major oracle failure, GMX/GLP or stablecoin/LST depeg, or L2/bridge outage could cause:
  • Inaccurate liquidations and systemic bad debt.
  • Locked collateral on compromised L2/bridge.
  • Liquidity spirals if LP tokens lose value or become untradeable.
Evidence (5)

crypto custody

one source

Dolomite’s custody model is non-custodial / self-custodial: the protocol states it never assumes custody of users’ funds or private keys, and users interact through their own Web3 wallets while smart contracts enforce deposits, withdrawals, lending, trading, and liquidation rules. In practice, assets supplied to Dolomite are locked in protocol smart contracts and reflected as internal balances, but the user’s wallet remains the authority that can approve movements of those assets. Dolomite also says its architecture separates an immutable core layer from an upgradable module layer, which is intended to isolate risk and allow feature upgrades without changing the underlying security model. For risk organization, positions are described as isolated, so liquidations are meant to affect only the specific borrow position involved rather than all of a user’s balances. Governance and administrative stewardship are handled separately from user custody: veDOLO holders govern protocol changes, while the DAO is described as a legal entity with related foundation/entity structure for stewardship and development.

Evidence (7)

incident

unverified

Mar 20, 2024 legacy Ethereum smart-contract vulnerability: an old Dolomite/Loopring Trade Delegate contract with stale approvals was exploited, affecting 187 victims and draining about 1.8M USD in USDC/DAI/WETH. Dolomite says it disabled the vulnerable contract within about an hour, recovered 90% of the stolen assets by Mar 24, and used treasury funds to make users whole for the remaining 10% by Mar 26. The affected system was the old product deployed in 2019 and spun down in 2020; the incident did not concern the current Arbitrum/Berachain-era protocol core. Bug bounty status for this specific event is not verifiable as of 2026-08-29. Key management/custody root cause was stale user approvals on an old mainnet contract, not a disclosed private-key compromise. Key-person risk is not verifiable as of 2026-08-29.

Date
2024-03-20
Cause
smart_contract_exploit
Loss Usd
1800000
Evidence (3)

incident

unverified

An August 15, 2026 address-poisoning theft of about 165,000 USD in BLOCK and DOLO tokens was reported in third-party commentary, but the source does not establish whether this was a protocol-level incident, and it is not verifiable as a Dolomite protocol incident as of 2026-08-29.

Date
2026-08-15
Cause
other
Loss Usd
165000
Evidence (1)

key management

one source

Dolomite’s key management appears to be organized as a governance-controlled, multi-role system rather than a single custodial key owner. The clearest documented path is: community discussion in Discord, a temp check, then a quarterly on-chain vote (BeraVote) by veDOLO holders, followed by execution by Leavitt Innovations, LLC, the operating company that manages the protocol. The docs also state that veDOLO balance determines permissions: 1M+ veDOLO can create proposals, 10k+ can comment, and 1k+ can upvote/react, which means access is organized by token-based governance roles. For the protocol’s administrative/security controls, the available public material does not provide a verified signer list, threshold, or chain-specific key custody model for Arbitrum, Berachain, or Ethereum. A third-party article claims a 5/9 multisig and a 48-hour timelock, but this is not independently confirmed in the provided sources, so it should be treated as unverified. The Dolomite docs confirm a modular architecture with an immutable core and mutable module layer, which implies that some operational authority is separated between fixed logic and upgradeable components, but they do not specify the exact key-management implementation. So, the verified picture is: token-weighted governance for protocol decisions, execution by the operating company, and modular upgradeability, while the exact administrative key custody setup remains Not verifiable as of 2026-08-29 from the available sources.

Evidence (3)

smart-contract

two sources

Key point: Dolomite is a cross‑margin lending/DEX protocol whose core smart contracts are deployed on Arbitrum, then extended to Ethereum and Berachain; it is explicitly described as non‑custodial, but detailed admin/proxy configuration is Not verifiable as of 2026‑08‑29 due to lack of on‑chain tooling this turn. ### Contract architecture & chains

  • The v2 protocol is centered around a suite of Solidity smart contracts deployed first on Arbitrum as the main settlement layer.
  • The core engine is DolomiteMargin, which stores balances, interest, and market configuration; deposits/withdrawals use a DepositWithdrawalRouter that calls depositWei / withdrawWei.
  • Dolomite Finance states current deployments on Ethereum, Arbitrum, Berachain, Mantle, Botanix.
  • Yield integrations list multiple Arbitrum lending markets (WETH, DAI, USDC, LINK, WBTC, USDT, ARB, mGLP, MIM, rETH, etc.), implying a multi‑market money‑market architecture. On‑chain verification, proxy layout and exact addresses for Arbitrum/Ethereum/Berachain contracts are Not verifiable as of 2026‑08‑29. This includes:
  • Whether DolomiteMargin and routers are behind upgradeable proxies.
  • Proxy admin contract type (EOA vs. contract‑based, timelocked, multisig).
  • Decoded admin events (ownership transfers, upgrades, pauses). ### Admin / owner / emergency powers Public docs describe Dolomite as *non‑custodial*, with users retaining control of funds and using overcollateralized loans and margin trading. However, specific admin capabilities are Not verifiable as of 2026‑08‑29, including:
  • Existence and scope of pause/unpause functions.
  • Who can change risk parameters (collateral factors, caps, interest curves).
  • Who can upgrade implementations, change oracles, or list/delist markets.
  • Whether any roles have been renounced or restricted by timelock. ### User exit / worst‑case key compromise
  • The protocol claims never to assume custody of user funds and relies on AMM pools and on‑chain margin settlement. This suggests users interact directly with smart contracts and, in normal conditions, should be able to repay/withdraw via DolomiteMargin/routers without off‑chain intervention.
  • Without verified ABI/event analysis, it is Not verifiable as of 2026‑08‑29 whether:
  • Admins can globally pause withdrawals or selectively freeze markets.
  • Admins can seize collateral or block specific accounts.
  • Upgrade powers could introduce malicious logic (rug risk) or break exit paths. In a worst‑case scenario where privileged keys are compromised, standard DeFi patterns would imply risks of:
  • Malicious upgrades to lending/DEX logic contracts.
  • Oracle manipulation, fee hikes, or parameter changes causing forced liquidations.
  • Potential global pause of markets or disabled withdrawals if such controls exist. Because contract addresses, verification status, role configuration, and timelock delays cannot be inspected directly this turn, detailed smart‑contract/admin risk for Dolomite on Arbitrum, Ethereum, Berachain is Not verifiable as of 2026‑08‑29 and should be treated as an open risk pending on‑chain analysis.
Evidence (8)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Dolomite is a publicly led DeFi protocol with identifiable founders, US-linked corporate setup, and venture backing; several details of its legal structure and office presence remain partially documented and therefore uncertain. Founders & key team

  • Co‑founders: Corey Caplan and Adam Knuckey are consistently cited as Dolomite’s co‑founders.
  • Roles: Caplan is described as CEO/President and product/architecture lead; Knuckey as COO, focusing on operations and growth.
  • Additional team: Public appearances name “Bobo” (Head of BD & Growth) and “Brandon” (operations) as part of the core team.
  • Status: Founders and senior staff are fully public, not anonymous, with interviews, AMAs, and social profiles under real names. Prior experience & affiliations
  • Caplan and Knuckey have been active in crypto since at least 2017–2018, initially building a DEX on Loopring and trading actively.
  • Dolomite was originally launched around 2018 as a non‑custodial exchange and later evolved into a margin / money‑market protocol on Arbitrum.
  • Caplan is also cited as a technical advisor/CTO‑type role at World Liberty Financial, a politically associated DeFi project.
  • Bitget and other research notes state experience in DeFi architecture, protocol governance, Layer‑1 infra, lending, and asset management, but these are largely self‑reported or second‑hand summaries. Corporate entity, location, and onshore/offshore signal
  • StartupIntros describes Dolomite.io as based in Dover, Delaware, founded in 2018 by Caplan and Knuckey, suggesting a U.S. corporate registration (likely Delaware C‑corp or LLC). This is an analytics description and not a primary registry extract.
  • Multiple sources say Dolomite was “developed by Leavitt Innovations,” implying a corporate parent or dev company; the precise jurisdiction and structure of Leavitt Innovations are not independently documented in retrieved material.
  • Venture backers include Draper Goren Holm, NGC Ventures, Coinbase Ventures, 6th Man Ventures, Polygon/Sandeep Nailwal, Solana Ventures, Optic Capital and others, indicating standard VC due‑diligence and a real business rather than a purely anonymous web front. Reality checks & risk‑relevant observations
  • Public vs anon: Clear, persistent founder identities across interviews, AMAs, X posts, and venture materials; high transparency relative to typical DeFi money markets.
  • Track record: No credible records of major protocol hacks or founder‑linked exploits surfaced in the gathered data; however, absence of evidence is not proof of absence.
  • Regulatory / corporate verification: Direct on‑chain or registry confirmation of the Delaware entity, Leavitt Innovations structure, and any physical office is Not verifiable as of 2026‑08‑29.
  • Credibility: Presence of reputable VCs, Chainlink BUILD participation, and long operating history since early DEX days moderately increase perceived institutional credibility, but this remains a risk assessment, not a legal endorsement.
Evidence (15)

general reputation

two sources

Overall, Dolomite currently has a positive but not unanimous risk reputation, with multiple third‑party audits, no reported hacks or insolvency events, and no visible fraud/rug or sanctions allegations, but with differing views on its risk profile and scale. Safety / risk ratings & sentiment

  • DeFi Sentinel assigns Dolomite an AA rating with a safety score of 80/100, describing it as “very low risk” across smart contract, economic, governance, sustainability, and reputation dimensions.
  • Hindenrank gives Dolomite a B‑ grade with a 33/100 risk score, placing it in the middle tier of lending protocols by safety; in their framework, lower scores indicate lower risk, and Dolomite ranks #34 of 95 lending protocols.
  • Exponential.fi classifies Dolomite’s overall risk as “Average” and notes decent protocol code quality, with TVL in the mid‑hundreds of millions and lending ranking around #12.
  • RFP.wiki shows a reputational snapshot score of 3.3/5 with moderate confidence, highlighting its multi‑chain deployment controls. Track record / incidents
  • A third‑party AMA recap reports > $900M cumulative trading volume and > $1B TVL historically, claiming a “spotless track record spanning over two years” and “less than $50 of bad debt across all networks and markets” with no security incidents. As this comes via an AMA and not an independent audit, it should be treated as a partially marketing‑influenced claim.
  • No sources in the current dataset report hacks, insolvency, user fund loss, or operational crises. Not verifiable as of 2026‑08‑29 whether smaller incidents or edge‑case losses have occurred. Audits, security, and external review
  • Dolomite’s smart contracts have been audited by OpenZeppelin, Bramah Systems, SECBIT Labs, Cyfrin, Zokyo, and Guardian Audits, according to both the protocol’s security page and independent profiles. Claims of “100% test and branch coverage” stem from the protocol documentation and are therefore unverified marketing claims.
  • Multiple investment/rating notes on Binance’s content hub describe Dolomite as a recommended candidate for on‑chain leverage, emphasizing perceived strong architecture and security baseline. These are opinionated analyses, not formal audits. Founders, investors, legal/regulatory
  • Public profiles focus on the protocol rather than named founders or investors; no credible sources in this set discuss founder background checks or VC cap tables. Not verifiable as of 2026‑08‑29.
  • No evidence of fraud, rug‑pull, sanctions listings, or regulatory enforcement actions against Dolomite or its core team appears in the reviewed materials. Key unresolved concerns
  • Scale and complexity (multi‑chain, long‑tail assets, margin) mean systemic and oracle risk remain material even with good audits; Hindenrank notes non‑trivial mechanism novelty and interaction severity.
  • Limited public information on founders’ identities, governance processes, and formal regulatory posture is a due‑diligence gap for institutional allocators. Not verifiable as of 2026‑08‑29.
  • Some metrics (TVL, “spotless track record”) rely on protocol/partner communications and ratings sites rather than raw on‑chain verification, and should be treated cautiously as unverified marketing claims where not independently corroborated.
Evidence (15)

Economy

TVL: $652.0M

model

two sources

Dolomite is a lending/margin protocol with multi-asset, cross-chain deployment; the web results indicate activity on Arbitrum, Berachain, and Ethereum. Its economic model is primarily organic yield from borrower interest and trading/margin activity, with lenders receiving a portion of borrower-paid interest (the whitepaper snippet says lenders currently receive 90% of what borrowers pay), so it is not a pure emissions farm. The protocol also supports external asset exposure via listed collateral/markets that include stablecoins, ETH/BTC wrappers, LP-like or ecosystem tokens, and other long-tail assets, making returns partly dependent on the underlying asset mix rather than just protocol subsidies. The available web evidence suggests the product is not strictly market-neutral: users can post collateral, borrow, and run leveraged or looping-style positions through the lending/margin design, which introduces directional and liquidation risk. The protocol marketing also highlights high APY variability by asset and chain; third-party trackers show current APYs ranging from near 0% on some pools to double digits on others, implying yield is highly asset-specific and volatile. That volatility makes sustainability dependent on borrower demand, spreads, and asset utilization rather than fixed subsidy flows. On fees and revenue, one third-party analysis snippet reports roughly $12.66M in 30-day fees and about $221k in 30-day revenue excluding incentives, implying a large fee-to-revenue gap and suggesting incentives may still materially affect economics. However, because this comes from an aggregator and not on-chain verification, it should be treated as unverified marketing/analytics data, not a confirmed protocol accounting statement. For TVL, the sources conflict materially. DeFiLlama’s Dolomite page snippet shows only very small per-chain figures in one result snapshot, while another tracker shows about $109.6M TVL with most exposure on Arbitrum and Berachain. A different source claims much higher chain-level TVL, especially on Ethereum, but that is inconsistent with the other snapshots and cannot be reconciled here. Because on-chain checking is unavailable in this run, the correct finding is that TVL by chain and by product is not verifiable as of 2026-08-29 from the available evidence, and the public figures are contradictory. Withdrawal mechanics, lock-ups, precise fees, gates, and protocol-owned revenue split beyond the lender share are Not verifiable as of 2026-08-29.

Evidence (7)

reserves

unverified

Dolomite does not appear to publish a standalone, auditable on-chain treasury/reserve disclosure for Arbitrum, Berachain, or Ethereum in the materials available here; the protocol docs only show governance-controlled emissions/allocation rules and a treasury multisig for chain-level distribution, but not reserve wallet addresses, reserve composition, or current balances. The clearest documented reserve-like allocation is the token distribution: 10.6511% to the Foundation, 3.0000% to Service Providers, and 2.0000% protocol-owned liquidity seeded on Kodiak and Uniswap, while governance notes say the treasury multisig signers and Dolomite core contributors are responsible for treasury deployment on the listed chains. However, the actual treasury size, custody addresses, and on-chain balances are not verifiable as of 2026-08-29 from the sources provided, because no Dune-backed or explorer-backed reserve wallet inventory is available in this run.

Evidence (3)

tokenomics

two sources

Dolomite currently does not have a live native token on Arbitrum, Berachain or Ethereum. All tokenomics-related items are therefore prospective or “unverified marketing claims”. Not verifiable as of 2026-08-30. ### 1. Existence of a native token

  • Dolomite’s official docs and various listings reference a prospective DOLO token, but no deployed token contract matching an official announcement can be reliably confirmed across Arbitrum, Ethereum or Berachain.
  • No widely traded Dolomite-native token with clear association to the protocol, audited address, and substantial market cap is visible on major analytics platforms. Conclusion: From available data, Dolomite is operating as a protocol without a launched native governance/utility token. Any DOLO tokenomics you may find are unverified marketing claims and Not verifiable as of 2026-08-30. ### 2. Tokenomics items requested (current status) Because there is no verifiably deployed native token:
  • Token name/ticker & contract address: Prospective name appears as *Dolomite / DOLO* in some materials, but no authoritative, on-chain-confirmed contract address can be tied to the protocol. Not verifiable as of 2026-08-30.
  • Total vs circulating supply; market cap; FDV: No reliable data on-chain or via independent analytics. Not verifiable as of 2026-08-30.
  • Token utility & governance role; revenue share, buybacks, burns, staking rewards: All such features are only described hypothetically in scattered references; none can be confirmed against an existing token contract or governance framework. Unverified marketing claims.
  • Emissions schedule & unlock schedule; whether unlocks occurred on-chain: No emissions or unlocks can be tracked because there is no confirmed token contract. Not verifiable as of 2026-08-30.
  • Allocations (team/investors/treasury/community): Any allocation charts circulating are not backed by on-chain distributions or independent filings. Unverified marketing claims.
  • Top-holder concentration & insider wallets: Cannot be analyzed without a confirmed token contract. Not verifiable as of 2026-08-30.
  • Mint/blacklist/fee-switch functions & controllers: No verified token contract → cannot inspect control functions, admin roles, or upgradeability. Not verifiable as of 2026-08-30.
  • DEX liquidity depth & main listings: No deep, liquid markets for a Dolomite-native token on major DEX/aggregators can be confirmed. Not verifiable as of 2026-08-30. ### 3. Risk analyst takeaway For institutional risk purposes, treat Dolomite as a tokenless protocol at this time, with no on-chain-verified governance, revenue-sharing, or emissions mechanics tied to a native asset. Any investment thesis based on future DOLO tokenomics is speculative and should be classified as unverified marketing claims; not verifiable as of 2026-08-30.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Under a BTC < $10,000 stress, Dolomite’s risk is indirect and position-specific, not a protocol-wide automatic failure. Dolomite liquidates accounts when collateralization falls below the required threshold, so the main effect would be forced liquidations on accounts whose collateral is BTC or highly BTC-correlated assets, while accounts over-collateralized with stablecoins or less-correlated assets should be less affected. For this specific scenario, the key question is whether BTC-priced collateral can still cover borrowed debt after the crash. Dolomite’s documented model says liquidation is triggered when an account falls below the minimum collateralization threshold, which means a severe BTC drawdown can rapidly push leveraged borrowers into liquidation risk. That risk is amplified if market liquidity is thin, because liquidations may occur at worse prices and could leave residual bad debt if collateral cannot be sold fast enough; however, that outcome is Not verifiable as of 2026-08-29 from the available sources. On the chain-specific exposure question, the provided results do not verify Dolomite’s actual BTC collateral usage, user leverage, or TVL distribution across Arbitrum, Berachain, and Ethereum. Therefore, the protocol-wide exposure by chain is Not verifiable as of 2026-08-29. The only confirmed cross-checkable point is that Dolomite’s liquidation design is built around multi-asset collateral and account health rather than single-asset liquidation, which can reduce some over-liquidation risk but does not eliminate correlation risk in a BTC crash. The most relevant operational risk in this scenario is a cascade: BTC price collapse -> account health deterioration -> liquidations -> possible price slippage -> potentially stressed liquidator participation. Any claim that Dolomite would face protocol insolvency, bad debt, or a token collapse from this scenario alone is Not verifiable as of 2026-08-29 on the evidence provided.

Evidence (2)

stress scenario - largest collateral depegs 20%,

two sources

Dolomite’s published risk model uses a 115% minimum collateralization / 86.9565% max LTV and liquidates positions when health factor falls below 1. Under a 20% depeg of the largest collateral asset, the impact depends on that asset’s starting cushion: if a position was initially at the maximum allowed leverage, a 20% collateral price drop would push it to roughly 92.3% of borrowed value relative to collateral value, which is below the 115% safety requirement and therefore liquidatable. For the protocol-level stress question, the key risk is not just liquidation, but whether the largest collateral is sufficiently liquid to absorb the unwind without bad debt. Dolomite’s own docs describe isolated borrow positions and liquidation mechanics, but the supplied sources do not provide on-chain exposure, the identity of the largest collateral by chain, or liquidation depth across Arbitrum, Berachain, and Ethereum, so the protocol-wide loss estimate is Not verifiable as of 2026-08-29. The available web sources also contain high-risk anecdotes around WLFI collateral concentration and possible liquidity strain, but those are media/analysis claims and do not establish a reproducible protocol-wide stress loss number.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Dolomite is a margin lending / borrowing protocol where users deposit collateral, borrow assets, and some strategies use integrated protocol positions (e.g., GLP/GMX-style integrations on Arbitrum). Precise on-chain positions and top counterparties are Not verifiable as of 2026-08-29. Below is a generic stress-path analysis for “top borrower / largest margin account becomes insolvent” on Dolomite, per chain. --- 1) Arbitrum – largest margin account default Trigger path

  • Large account borrows stablecoins vs. volatile collateral (or LP / strategy token).
  • Market shock: collateral price drops sharply; account’s health factor < 1.
  • Liquidators either:
  • Cannot or do not liquidate fast enough (oracle delay, extreme volatility, gas / liquidity issues), or
  • Liquidation discount is insufficient to clear the bad debt. Loss realization and absorption
  • The shortfall is the gap between borrower debt and liquidation proceeds from collateral.
  • In Dolomite’s model, this shortfall is borne pro‑rata by liquidity suppliers in the affected asset pools: depositors’ claims are haircut relative to what they supplied.
  • If there is any insurance / backstop fund or protocol treasury buffer configured for that market, it is tapped before depositor losses; if none or exhausted, LPs absorb the loss. Smart-contract impact path
  • Underwater position flagged via health factor / account liquidity view.
  • liquidate function transfers collateral from borrower to liquidator and repays part of the debt.
  • When collateral is exhausted and some borrow remains, the protocol’s accounting marks that portion as bad debt, reducing pool assets while liabilities to depositors remain higher.
  • Future borrowers may face higher interest rates as utilization spikes; withdrawals can become constrained if on-chain liquidity is low. Compensation
  • Unless a separate insurance / safety module exists and is funded, there is typically no automatic compensation to depositors; they bear the economic loss. --- 2) Ethereum / Berachain As of now, Dolomite activity appears concentrated on Arbitrum; presence and scale on Ethereum / Berachain are Not verifiable as of 2026-08-29. If/when live, the same mechanism applies per chain:
  • Each chain’s pools are ring‑fenced; an insolvency on Arbitrum does not directly drain Ethereum/Berachain pools.
  • Losses from a top counterparty default remain local to that chain’s lenders in the affected asset markets.
Evidence (1)

stress scenario - committed fraud by the DAO or owners

two sources

For a fraud-by-DAO-or-owners stress scenario, I found no verifiable evidence that Dolomite’s DAO or owners have committed fraud. The strongest available material instead points to a separate 2024 legacy smart-contract vulnerability on an old Ethereum product, which Dolomite says they disabled quickly and partially covered from treasury funds; that is an incident response, not proof of fraud. Dolomite’s own risk documentation also discusses liquidations and a fee-rake safety buffer, which is operational risk management rather than misconduct. A key caveat is that the web results do not provide an independent, source-confirmed finding of fraud, misappropriation, or owner-controlled drain for Dolomite across Arbitrum, Berachain, or Ethereum. The only directly relevant legal/DAO-liability material in the results concerns other protocols (for example, bZx/“The DAO”), not Dolomite. Assessment:

  • Fraud by DAO/owners: Not verifiable as of 2026-08-29.
  • Closest confirmed adverse event: legacy contract vulnerability/exploit on an old Ethereum system, with user losses and treasury reimbursement actions.
  • Current stress implication: if a future governance or custody abuse occurred, the loss severity would depend on treasury controls, multisig authority, and cross-chain exposure; however, those specifics are Not verifiable as of 2026-08-29 from the provided results. If you want, I can next map Dolomite’s publicly documented governance and custody structure by chain and assess which control points would matter most in a fraud scenario.
Evidence (5)

stress scenario - primary yield source negative 30d,

unverified

Dolomite’s documentation frames liquidation risk around the account’s collateralization falling below the 115% minimum, but it does not provide a verified on-chain view of whether the protocol’s primary yield source has been negative over the last 30 days. In this run, that specific stress test is Not verifiable as of 2026-08-29 from the available non-on-chain sources. What can be said from the retrieved material is limited:

  • Dolomite describes itself as a capital-efficiency protocol where users can combine lending yield and swap-fee yield, and its risk docs emphasize liquidation mechanics and the 115% minimum collateralization threshold.
  • The retrieved third-party commentary suggests some Dolomite strategies are exposed to yield reversal risk, meaning borrow costs can exceed strategy yield and create negative carry.
  • However, those pages are strategy-specific commentary and marketing/news content, not a protocol-level verification of the aggregate primary yield source becoming negative for 30 days. For an institutional risk memo, the defensible conclusion is: negative 30-day primary yield is not verifiable from the current web results. Any stronger statement would require direct on-chain data or a validated analytics source covering the exact yield source and chain-by-chain exposure on Arbitrum, Berachain, and Ethereum.
Evidence (6)

Governance & Legal

governance

two sources

Dolomite’s governance is semi‑centralized and company‑controlled, with protocol parameters and major upgrades ultimately gated by core team–controlled multisigs and smart‑contract roles. On‑chain verification is not possible in this run: Not verifiable as of 2026‑08‑29. ### Governance structure & control

  • Dolomite describes itself as a hybrid DEX / margin protocol on Arbitrum with plans for Berachain and Ethereum, but does not present a mature, fully on‑chain DAO for protocol control; most references are to “community” and “partner” governance rather than a formal DAO constitution.
  • There is no clear public documentation that protocol ownership (admin roles on core contracts) has been fully renounced; audits and listings (e.g., DefiLlama, DeFiSafety) treat Dolomite as a protocol with active admin powers retained by the team. ### Contracts, upgrades, timelocks
  • Core lending/margin/DEX contracts are upgradable or parameterized via privileged roles, typically multisig or EOA controlled by the Dolomite team; specific timelock details (delay, scope) cannot be reliably confirmed from secondary sources alone. Not verifiable as of 2026‑08‑29.
  • No independent confirmation of timelock contract addresses, their delay settings, or whether all critical functions are behind a timelock. Not verifiable as of 2026‑08‑29. ### Multisigs & signers
  • Dolomite uses multisig wallets (likely Gnosis Safe on Arbitrum) for treasury and protocol control, but public information on:
  • signer identities and independence,
  • threshold (e.g., 2‑of‑3, 3‑of‑5), and
  • which contracts each multisig controls is fragmentary and mainly from Dolomite’s own communications and dashboards.
  • Because this information is not corroborated by independent explorers plus Dune: Not verifiable as of 2026‑08‑29. ### DAO, voting, proposal process
  • There is no widely‑documented, token‑based Dolomite DAO with formal proposal/voting mechanics comparable to major DeFi protocols (e.g., GovernorBravo, Snapshot spaces). Governance appears symbolic / advisory, with key decisions remaining with the core team and partners.
  • Voting concentration, top holders, and governance participation via Dune cannot be assessed here: Not verifiable as of 2026‑08‑29. ### Legal entity & ToS
  • Public profiles and listings indicate Dolomite is operated by a company‑style entity (US‑based team), but precise legal entity name, jurisdiction, registration number, directors, and Terms of Service are only available via Dolomite’s own site and app and thus count as unverified marketing claims. Overall, Dolomite should be treated as founder‑ and company‑controlled, with limited, mostly informal community governance and incomplete transparency on admin roles, timelocks, and multisig structure.
Evidence (4)

legal & regulatory

two sources

Dolomite’s legal structure appears to be multi-entity and jurisdictionally split: its whitepaper says the company behind Dolomite is Leavitt Innovations, Inc., a Delaware corporation, while the governance docs describe the DAO as a legal entity in the Marshall Islands, with Dolomite Ltd. (BVI) as token issuer and the Dolomite Foundation (Cayman Islands) as steward. Its Terms of Service state disputes are governed by British Virgin Islands law and list the Dolomite Foundation at a Cayman Islands address. The main user restrictions are explicit: users must not be U.S. Persons (with limited carve-outs for Non-OTC access), must not be in restricted territories, must not be subject to sanctions, must not transact with restricted or sanctioned persons, and must not use VPNs or anonymization tools to bypass restrictions. The terms also indicate the service may be unavailable where prohibited by law. On KYC/AML, the public terms and token distribution materials show strong sanctions and AML language, but I did not find a direct public statement that Dolomite requires full user KYC for protocol use. Based on the available sources, KYC requirement is not verifiable as of 2026-08-29. Regulatory classification is also partly stated by the project and therefore should be treated cautiously: governance docs refer to a DAO legal entity, but there is no authoritative public regulator determination in the materials reviewed. I found no public court case, enforcement action, or sanctions designation specifically against Dolomite in the gathered sources; not verifiable as of 2026-08-29. Data protection obligations are not clearly described in the protocol materials reviewed, beyond general references to legal compliance and privacy restrictions; not verifiable as of 2026-08-29. Risk view: the legal structure appears intentionally decentralized and multi-jurisdictional, but the ToS and token documents impose centralized access restrictions and sanctions compliance language. That creates a gap between the protocol’s DeFi posture and the real-world legal controls around its interface, entities, and token distribution.

Evidence (4)

Stability

stability

two sources

I can’t verify a Dolomite stablecoin depeg history from the provided results. The search results only show general stablecoin depeg examples and Dolomite’s DOLO token price history, not the actual stablecoin used by Dolomite across Arbitrum, Berachain, and Ethereum. Because the stablecoin itself is not identified or tied to confirmed on-chain data here, the number of depegs, the last depeg date, and the depeg percentage are Not verifiable as of 2026-08-29. If you mean a specific stablecoin used inside Dolomite markets or collateral, I’d need that token symbol or contract address to answer precisely.

Evidence (3)

Risks & Strengths

risks

two sources

Top 5 risks for Dolomite, based on available public sources, are: 1) Smart-contract / mechanism complexity risk: Dolomite uses a more complex virtual-liquidity and margin system than standard lending markets, which increases the chance that bugs or edge cases affect collateral, borrowing, or liquidation behavior. 2) Liquidation and bad-debt risk: the protocol explicitly relies on collateral thresholds and liquidation fees to manage insolvency; in volatile markets, failed or delayed liquidations can still create bad debt. 3) Oracle and pricing risk: several sources flag oracle dependence as a major exposure, since incorrect or delayed pricing can trigger wrong liquidations or allow unhealthy positions to persist. 4) Liquidity fragmentation / execution risk across chains: Dolomite is deployed on Arbitrum, Berachain, and Ethereum, and multiple sources note that fragmented liquidity or chain-specific market stress can impair liquidations, withdrawals, and capital mobility. 5) Governance / regulatory / token-model risk: public analyses flag regulatory uncertainty, the influence of external partnerships, and limited current fee capture or reliance on future growth as material risks for the protocol and its token economics. Notable protocol-specific detail: Dolomite’s own docs state that liquidations occur when an account falls below the minimum collateralization threshold, and that as of March 2026 non-isolation liquidations pay a fee rake that builds a safety buffer.

Evidence (8)

strengths

two sources

Dolomite’s top strengths are its capital efficiency, asset utility preservation, broad asset support, risk isolation, and modular extensibility. It combines lending, borrowing, margin trading, and spot trading in one protocol while aiming to let deposited assets keep their native rewards and utility, rather than becoming idle collateral. It also emphasizes support for thousands of assets, which broadens what users can deploy as collateral or in yield strategies. 1. Capital efficiency / virtual liquidity: Dolomite’s virtual liquidity system is described as allowing a single deposit to serve multiple roles at once—collateral, lending, trading, and fee generation—reducing capital lockup. 2. Preservation of asset utility: The protocol is designed so assets can retain external rewards or rights while being used inside Dolomite, which is a major differentiator for yield-bearing or governance tokens. 3. Broad asset compatibility: Dolomite says it was built to support a diverse set of assets and is capable of listing thousands of assets in a central pooling architecture, expanding usability beyond standard ERC-20 collateral. 4. Risk containment: Dolomite uses isolated margin accounts, which are intended to prevent losses in one position from cascading across the whole system. 5. Modular architecture: Its core/module design is presented as a strength because it can add new features and asset types without changing the immutable core, improving upgrade flexibility while preserving security.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 16 two independent sources, 4 one source, 8 unverified.
  • Oldest fact verification date: 2026-08-29.