Frax

Orange · 40/100 Data confidence 95/100

Executive summary

Frax is a multi-product DeFi ecosystem spanning stablecoins (FRAX, frxUSD), ETH staking (frxETH/sfrxETH), lending (Fraxlend), and an L2 (Fraxtal), governed by FXS token holders, with a score of 40/100 (orange band).

  • Security & audits: Extensive audit program since 2020 covering core contracts and new products by Trail of Bits, CertiK, ChainSecurity, and others; active bug bounty paying lesser of 10% of exploit value or $10m in protocol tokens; zero verified on-chain loss incidents to date.
  • Governance & custody: Transitioning from core-team multisig control to veFXS on-chain governance, but a Frax "comptroller" multisig retains ultimate admin power over the timelock and can override governance; frxUSD reserves are managed off-chain by Frax Inc. with delegated custodians; multisig controls over $1B in assets.
  • Top risks: (1) Stablecoin peg risk under collateral stress (FRAX depegged in March 2023 USDC crisis); (2) smart-contract complexity across multi-product suite; (3) dependency/contagion from external DeFi integrations (Curve, Convex, Chainlink oracles, USDC/USDT); (4) transparency gaps and a stealth-patched frxETH vulnerability; (5) regulatory exposure as a US-based stablecoin issuer with RWA backing.
  • Centralization: Instant-upgradeable contracts on most chains with no forced exit window; 3/5 or 3/6 multisigs control cross-chain deployments and frxUSD lockboxes; limited public visibility into off-chain reserve composition and chain-by-chain TVL splits.
  • Strengths: Multi-asset product breadth; capital-efficient AMO design deploying collateral actively; adaptive fractional-reserve model; DeFi-native liquidity via Fraxswap; multi-chain extensibility across eight networks.
  • Team & maturity: Fully doxxed team (Sam Kazemian, Travis Moore, Jason Huan) with prior Everipedia track record; functional app and API endpoints; no verified fraud or sanctions; launched December 2020.
  • Unverified: Chain-by-chain TVL, exact reserve composition, collateral stress-test outcomes, current signer rosters, geo-restrictions, and live transaction success rates are not verifiable as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 100 25.0 5 audit(s); fresh audit bonus; active bug bounty bonus
incidents 25% 0 0.0 2 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 87 13.1 0 onchain, 24 two-source, 6 one-source of 31 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 8; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Frax (often Frax Finance) is a multi-chain DeFi ecosystem centered on stablecoins and a native L2, Fraxtal, with its governance base in the FXS/FRAX asset pair. It is not a fork of a single upstream protocol but an original design that pioneered the fractional‑algorithmic stablecoin model. Identification

  • Name: Frax / Frax Finance
  • Category: Stablecoin & multi‑product DeFi protocol (FRAX, frxETH, FPI, Fraxlend, Fraxswap, Fraxtal L2).
  • Website: Listed via aggregators ("Website" link on Frax Finance profile). Any details from there are *unverified marketing claims* per your framework.
  • Docs: Frax Finance documentation and Fraxtal docs describe token set and cross‑chain design.
  • Launch date: FRAX stablecoin launched on Ethereum mainnet in December 2020 (testnet mid‑Nov 2020; mainnet Dec 20–21, 2020).
  • Chains: Multi‑chain: Ethereum plus Arbitrum, Avalanche, BSC, Fantom, Polygon, OP Mainnet and Fraxtal; other sources also list Dogechain, Moonbeam.
  • Native / key tokens:
  • FRAX – original dollar‑pegged stablecoin.
  • Frax Share (FXS) – governance/seigniorage token for the ecosystem.
  • frxETH – ETH‑pegged staking derivative, used as gas on Fraxtal at launch.
  • Frax (Fraxtal native gas) – later evolution: Frax is the *native gas/commodity asset* of Fraxtal; FXS on Ethereum can be upgraded 1:1 to Frax on Fraxtal. Main contracts & verification
  • Specific contract addresses per chain (FRAX, FXS, OFT bridges, Fraxlend, Fraxswap) are documented in the Frax LayerZero OFT GitHub repo and cross‑chain overview, and are typically verified on explorers (Etherscan and equivalents).
  • Precise, chain‑by‑chain address lists and their verification status are Not verifiable as of 2026-08-29 under your constraint set (no direct explorer/Dune checks this turn). Fork lineage and modifications
  • FRAX is described as the first fractional‑algorithmic stablecoin, inspired by academic work but not presented as a fork of MakerDAO, Ampleforth, or other stablecoins.
  • Fraxlend and Fraxswap are described as internal subprotocols; sources do not label them straight forks of existing money markets/AMMs.
  • No credible sources show a history of malicious modifications in Frax forks or widely used forked variants.
  • Multiple audits are referenced in ecosystem materials, but specific audit reports and coverage of each change set are Not verifiable as of 2026-08-29 given tool limits.
Evidence (10)

maturity

two sources

Frax appears to have a real, functional product portal rather than a pure marketing landing page: its docs point users to the Pro Website at app.frax.finance, and the docs also expose Swagger/API endpoints for Frax Finance and FraxNet, including no-auth GET endpoints for deposit address lookup, deposit processing, redemption processing, relay status, and active jobs. The presence of dedicated API docs and an orchestration API is a strong maturity signal, and the docs indicate live deposit/redemption workflows rather than static documentation only. I could not independently verify live transaction success, broken links, or template/recycled UI signs from a live browser session in this run, so those details are Not verifiable as of 2026-08-29. Likewise, whether every listed chain surface is fully functional in the app across Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon is Not verifiable as of 2026-08-29. Open API: yes. Frax documents public Swagger/OpenAPI-style documentation for both v1 and v2 APIs, and the FraxNet docs explicitly state no authentication is required for its GET endpoints.

Evidence (3)

Security

audit

one source

Initial Frax stablecoin protocol (core contracts on Ethereum; indirectly relevant to other chains where the same core logic is deployed). Audit report November 2020.

Auditor
CertiK
Report Date
2020-11-13
Scope
FRAX two‑token stablecoin protocol smart contracts (core monetary system). Covers system solvency logic, attack vectors, best‑practice compliance, contract logic vs. spec.[1][9][13]
Evidence (1)

audit

one source

BAMM smart contracts (liquidity and risk‑management module).

Auditor
ChainSecurity
Report Date
2025-09-12
Scope
BAMM solvency, arithmetic correctness, oracle‑manipulation resistance, rounding, DoS patterns.[3]
Evidence (1)

audit

one source

Frax maintains a long audit program over many components (Fraxlend, Fraxferry, veFPIS, FrxGov, FXB, sFRAX, frxETH redemption queue and oracles, Fraxchain/Fraxtal, frxETH V2, VestedFXS, Flox, FraxtalERC4626MintRedeemer, Curve AMO for frxETH V2, BAMM, Fraxtal North Star, frxUSD stack, Frax0 Mesh, etc.).

Auditor
Multiple (Trail of Bits, CertiK, Frax Security Cartel, Zellic, ChainSecurity, Certora)
Report Date
2020-11-01
Scope
Programmatic, recurring audits across core protocol, L2 (Fraxtal), governance, bridge, RWAs and newer stablecoin primitives. Specific individual reports from 2022–2025 listed in Frax / Fraxtal docs with auditors and modules.[2]
Evidence (3)

audit

one source

Frax Finance security review (May 2022).

Auditor
Trail of Bits
Report Date
2022-05-01
Scope
Multiple Frax Finance contracts including Fraxswap/FPI, lending components, deployers, controller pools.[4]
Evidence (1)

bug bounty

two sources

Frax appears to have an active bug bounty program. The strongest source is Frax’s own security documentation, which states the bounty is paid at the lower of 10% of the total possible exploit or $10 million in token value, with payment in FRAX+FXS on the older docs page and frxUSD+FRAX on the newer Fraxtal docs page; the newer page also says both tokens are immediately liquid and that payout can take up to 5 days because of timelock + mitigation. On when it started, the only explicit date in the provided results comes from an external security listing that says “Bounty Live Since 26/05/2019.” That is not as authoritative as Frax’s own docs, but it is the only sourced start date available in the results. For results, I could not verify any public tally of paid rewards, disclosed incidents, or aggregate submissions from the provided sources. The external listing shows Funds Reserved: $0 and zero payouts by severity, but that appears to be a directory snapshot rather than an authoritative program ledger, so it should be treated cautiously. CertiK’s project page also says “No CertiK Bug Bounty,” which likely means Frax does not use CertiK’s hosted bounty program, not that Frax has no bounty at all. Bottom line: Frax has an active bounty with a capped reward formula of 10% of exploit value or $10m, paid in protocol tokens; the program appears to have been live since 26 May 2019; and I could not verify public outcome statistics from the provided sources.

Evidence (4)

counterparty risks

two sources

Frax has material dependency and counterparty risk across oracles (Chainlink), external DeFi integrations (Curve, Uniswap, Convex, EigenLayer/LSTs), centralized stablecoins (USDC/USDT), bridges, and its own RWA-backed products. On-chain verification is not possible in this run: Not verifiable as of 2026-08-29. 1. Oracles & price manipulation risk

  • Frax uses Chainlink oracles for pricing FRAX, FXS and collateral assets across chains.
  • Oracle failure (stale/incorrect prices or L2 sequencer issues) can cause bad liquidations, wrong collateralization accounting, and mispriced AMO actions.
  • FRAX liquidity heavily sits in AMM pools (Curve, Uniswap), so large trades could move spot prices, but oracle-dependence mitigates direct pool manipulation; oracle failure is the larger risk. 2. External DeFi & protocol dependencies
  • Major FRAX liquidity and yield routes rely on Curve, Convex, Uniswap, Balancer, and Lending protocols (e.g., Aave, Fraxlend).
  • Frax’s Algorithmic Market Operations (AMOs) actively deploy collateral into external protocols; smart contract failure, governance attacks, or economic exploits in these venues directly impact backing and peg stability.
  • Frax Ether products (frxETH/sfrxETH) are indirectly exposed to Ethereum validator risk and EigenLayer/restaking integrations (shared security and slashing risks). 3. Stablecoin, LST & RWA exposure
  • Historically, FRAX has been partially backed by USDC and other stablecoins, introducing Circle/issuer, banking, and sanctions risk; depeg or freeze of USDC/USDT can impair backing.
  • Frax’s move toward fully collateralized/real-world asset-backed models (e.g., Frax Bonds, potential RWA collateral via SPVs) adds issuer, legal-enforcement, and custody risks; details per SPV/issuer are complex and jurisdiction-dependent.
  • LST exposure (through frxETH collateral and integrations) ties Frax to Lido/other LST providers’ slashing, governance and oracle mechanisms. 4. Bridges & multichain risk (Arbitrum, Avalanche, BSC, Fantom, Fraxtal, OP, Polygon)
  • Cross-chain FRAX and FXS commonly rely on canonical bridges or third-party bridges (e.g., LayerZero, chain-native bridges).
  • Bridge compromise can lead to unbacked synthetic FRAX on a destination chain or stranded collateral, forcing emergency measures or partial wipe-outs. 5. CEX, MM & concentration risk
  • Significant FRAX/FXS liquidity and price discovery depend on CEX listings and market makers; delistings or MM withdrawal can trigger volatility and peg stress. 6. Key failure scenarios
  • Major stablecoin/RWA issuer freeze or depeg;
  • Chainlink or bridge failure;
  • Exploit in Curve/Convex/frax-native AMOs;
  • LST/restaking slashing event on frxETH backing; all of which can produce FRAX peg deviation, undercollateralization, forced contraction, or governance-driven restructuring.
Evidence (6)

crypto custody

two sources

Frax’s crypto custody is organized in two distinct ways. For the core DeFi protocol, custody is mostly non-custodial on-chain: FRAX V3 uses smart contracts, AMOs, and governance actions to manage collateral and peg operations, while holding FRAX itself does not give a claim on any specific redeemable instrument or token. For the newer frxUSD system, custody is explicitly off-chain and delegated: the Frax DAO has delegated issuer-level compliance and collateral management to Frax Inc, which manages regulated custodians and reserve composition, while approved “enshrined custodians” hold cash-equivalent reserves and mint/burn frxUSD against those reserves.

Evidence (3)

incident

one source

Since launch, I found no verified on-chain loss incident for Frax in the retrieved sources; Frax’s own governance states it had “0 critical vulnerabilities where the protocol or any user has lost funds to a vulnerability/bug,” and a later independent assessment also says there has not been a substantial security incident causing user-fund loss.

Date
2022-06-08
Cause
other
Loss Usd
None
Evidence (2)

incident

two sources

Key-management / custody is materially centralized: an independent risk assessment says the Frax core-team multisig controls over $1B of assets and, if compromised, would give an attacker control of the protocol and those assets; another governance post notes that, historically, a core-team 3/6 Safe multisig had admin control over Frax contracts and assets.

Date
2022-09-27
Cause
key_compromise
Loss Usd
None
Evidence (2)

incident

two sources

For frxUSD specifically, governance/delegated-operating responsibility was shifted to Frax Inc. under FIP-432, with responsibility for custodian oversight, reserve composition, audits, and attestations; that is a governance/operational custody concentration rather than a disclosed incident.

Date
2025-12-15
Cause
other
Loss Usd
None
Evidence (2)

incident

two sources

Frax maintains a public bug bounty program covering contracts deployed by FRAX-Deployer, including smart-contract exploits where user funds or protocol-controlled funds/collateral are at risk; the bounty is the lesser of 10% of the exploit value or $10m, paid in FRAX+FXS or frxUSD+FRAX depending on the source, with a no-questions-asked disclosure path and a stated turnaround of up to 5 days.

Date
2026-06-02
Cause
other
Loss Usd
None
Evidence (4)

key management

unverified

Frax’s key management appears to be organized around multisig-controlled admin operations, with hardware-wallet-based signer custody and hardware security keys for codebase access. Frax states that all multisig signers use hardware wallets, all pushes to the codebase require authenticated hardware security keys, and sensitive environments are segmented with tightly controlled permissions to reduce single points of failure. For protocol administration, the available evidence indicates that Frax uses Gnosis Safe / multisig governance controls rather than a single EOA. A Frax governance overview describes a dual Governor model that controls Safes, with FraxGovernorOmega acting as an additional Safe owner that must approve certain Safe transactions and FraxGovernorAlpha providing broader control through a timelock/controller setup. LlamaRisk also reports that frxUSD and its lockboxes are managed by a 3/5 multisig on each supported chain, and that an Ethereum frxUSD owner address is a Frax-controlled multisig with 3-of-5 quorum. Operationally, this means key management is distributed across multiple signers, with different signing layers for code access and on-chain admin rights, and with protocol actions constrained by multisig/quorum plus governance modules rather than a single key holder. What is not verifiable as of 2026-08-29 from the provided sources is the full, current signer roster, whether signer sets differ by chain, and whether every listed chain uses the same threshold and custody model; the sources only confirm the multisig/hardware-wallet approach and at least some 3-of-5 deployments.

Evidence (3)

smart-contract

two sources

Frax uses a heavily upgradeable, multisig‑admin architecture across chains, with significant centralization and instant‑upgrade risk; users generally can withdraw/liquidate positions but cannot prevent or escape an adverse upgrade in real time. Key contract/admin structure

  • Core governance is implemented via FraxGovernorAlpha/Omega plus a TimelockController that is set as a module on underlying Gnosis Safes controlling protocol assets.
  • veFXS holders govern Alpha; Omega lets the Frax team submit proposals corresponding to Gnosis Safe transactions that succeed unless vetoed (optimistic governance).
  • Blockworks Research notes the timelock is 2 days by default but adjustable, and the timelock admin is the Frax comptroller multisig, giving it full control over the governance contract and timelock. Upgradeability & proxy admin
  • Cross‑chain OFT (omnichain fungible token) contracts for FRAX/sFRAX are upgradeable transparent proxies, with admin = chain‑specific multisig (Ethereum, Fraxtal, etc.).
  • L2BEAT’s Fraxtal assessment: Fraxtal contracts are instantly upgradable, administered via a ProxyAdmin ultimately controlled by “Fraxtal Multisig 1”, and there is no forced exit window for users in case of an unwanted upgrade.
  • frxUSD and related tokens are described as upgradeable (proxy pattern) with upgrades and critical parameters gated by timelocked, multisig‑controlled governance. Admin/owner/emergency powers
  • Governance timelock/Safes have full control over Gnosis Safes, including parameter changes and execution of arbitrary transactions on protocol contracts.
  • Code‑423n4 audit findings highlight centralization risk in frxETH: admins can set addresses that can mint arbitrary frxETH, set validators, change critical state and withdraw funds from frxETHMinter, recommending timelocked DAO/multisig controls.
  • LayerZero OFT docs explicitly state the OFTs are owned by chain‑respective multisigs as admins. Timelock & user exit
  • Governance timelock delay: ~2 days but admin‑adjustable, so not a hard safety guarantee.
  • On Fraxtal, contracts are instantly upgradable; users do not have an enforced exit window to leave before upgrades take effect.
  • For normal positions (e.g., stablecoins in vaults), users can usually withdraw or redeem if contracts behave honestly, but cannot block or front‑run a malicious upgrade. Not verifiable as of 2026‑08‑30 for each specific vault across all chains. Worst case if keys compromised / rug‑freeze risk
  • Compromise of the Frax core multisigs/ProxyAdmin/Timelock admin could allow:
  • Upgrading token/vault logic to steal collateral, change mint/burn rules, or block withdrawals.
  • Changing oracle/strategy/fee parameters to drain value or mis‑price assets.
  • L2BEAT explicitly flags that Fraxtal’s instant‑upgrade pattern implies high governance/admin risk with no guaranteed exit window. Architecture map (text)
  • User → upgradeable proxy (token/vault/OFT) → implementation contract → governed by Gnosis Safe + TimelockController → controlled by veFXS governance, but timelock is itself administered by the Frax comptroller multisig; chain‑specific multisigs/ProxyAdmin own cross‑chain/OFT contracts. Many concrete addresses and role renunciation statuses are Not verifiable as of 2026‑08‑30 without direct on‑chain inspection; available docs show a consistent pattern of multisig‑admin, upgradeable proxies, and adjustable timelocks.
Evidence (15)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Frax (Frax Finance / Frax protocol) is a well‑known, fully public‑team DeFi project founded by Sam Kazemian with co‑founders Travis Moore and Jason Huan. Founders & key team

  • Sam Kazemian – Iranian‑American software programmer and founder of Frax Finance. He previously co‑founded Everipedia (now IQ.wiki) in 2014 with Travis Moore and others. Frax docs state the FRAX token launched on 20 Dec 2020, founded by Sam Kazemian, Travis Moore, and Jason Huan.
  • Travis Moore – Co‑founder and CTO of Frax Finance and also co‑founder/CTO of Everipedia. Background as a software engineer and entrepreneur.
  • Jason Huan – Co‑founder providing technical expertise.
  • Other visible contributors include Nader Ghazvini (governance/core team member; also listed as co‑founder of Fraxtal network) and various engineers. All of these individuals are doxxed with public biographies, LinkedIn profiles, and prior media coverage; this is not an anonymous team. Prior projects / outcomes / hacks
  • The main prior project is Everipedia / IQ.wiki, an on‑chain knowledge base that has operated since 2014 and remains active under new leadership, with Sam and Travis now advisors.
  • No credible records of major protocol‑level hacks tied to founders’ prior projects were found in the reviewed sources. *Absence of evidence is not proof of no incidents; on‑chain verification is Not verifiable as of 2026‑08‑29.* Corporate presence, office, jurisdiction
  • Third‑party company data platforms list Frax’s headquarters in Las Vegas, Nevada, United States. This indicates a US‑linked entity and suggests an onshore (US) corporate presence, although exact legal entity structure is not detailed in the sources.
  • Separate “Frax” companies in India, Belgium, Mexico, and Kansas identified in search results are clearly unrelated industrial/engineering businesses (different sectors, locations, founders) and should not be confused with Frax Finance. Credibility & ‘real business’ vs web‑front
  • The founding team has an 8+ year public track record in crypto (Everipedia, Frax) with named individuals and ongoing media coverage.
  • External profiles show multiple employees and roles (engineering, governance, BD), consistent with an operating organization rather than a thin shell.
  • Nevertheless, without direct access to corporate filings or on‑chain ownership analytics, the full legal/operational structure is Not verifiable as of 2026‑08‑29. Overall, Frax appears to be a publicly led, US‑linked DeFi protocol with a doxxed founding team and prior shipped products, not an anonymous or purely web‑front operation, though some legal/structural details remain unverified under the current data set.
Evidence (15)

general reputation

two sources

Frax currently has a mixed but generally serious security and reputational profile: no public evidence of fraud, rug pull, or sanctions action, but ongoing concerns around centralization of control, complex design, and past unremediated issues. Founders / team / investors

  • Frax was founded by Sam Kazemian, a long‑standing crypto entrepreneur who is publicly visible and active in media and policy discussions, including commenting on banking de‑risking of crypto businesses.
  • There are no credible public reports of fraud charges or regulatory enforcement actions against Kazemian or the core team as of 29 Aug 2026. Not verifiable as of 2026‑08‑29. Security posture & auditors
  • Frax has an unusually extensive audit history with multiple firms: CertiK (base protocol, 2020), Trail of Bits (FPI/Fraxlend/Fraxferry/FXB/sFRAX/oracles, Fraxchain/Fraxtal, frxETH, governance, etc., 2022–2024), ChainSecurity (BAMM, solvency/oracle‑resistance focus), EtherAuthority (FRAX token, frxETH, 2024 – rated “Secured” with only low/very low issues), plus Cyberscope and Callisto on specific contracts.
  • A community governance post highlights Frax’s “strong commitment to protocol security through audits, transparent smart contract infrastructure, and continuous development,” reflecting internal and community perception. This is a *sentiment* statement, not independent verification. Key criticisms and risk concerns
  • A DeFiSafety review notes Frax “has been audited once, before launch” and that 3 major findings were not corrected in that early phase, raising concerns about historical risk governance. (This appears in tension with the later extensive audit program.)
  • The Code4rena frxETH contest explicitly flags severe centralization risk: admins can mint unlimited frxETH, set validators, change critical state, and withdraw funds; the report states there are “numerous methods that the admin could apply to rug pull the protocol” and that without redesign “it is not possible to avoid the admin being able to rug pull.” It recommends timelocked DAO/multisig controls. These are structural governance risks, not allegations that a rug has occurred.
  • Frax’s design spans stablecoins, LSTs, lending, AMM, and now its own L2/Fraxtal, increasing complexity risk and surface area; independent frameworks often score such systems lower on simplicity and transparency. Not verifiable as of 2026‑08‑29. Legal / regulatory / sanctions
  • No evidence in retrieved data of OFAC sanctions, asset freezes, or direct regulatory enforcement targeting Frax, FRAX, or core team. Not verifiable as of 2026‑08‑29.
  • Some broader stablecoin‑regulation debates mention Frax alongside other issuers, but without specific enforcement outcomes. Not verifiable as of 2026‑08‑29. Unresolved concerns for an institutional LP
  • Admin key / governance centralization around frxETH and possibly other components (ability to mint, reconfigure, or move collateral) remains a primary structural risk.
  • Legacy unremediated findings in early audits vs. later “secured” ratings create a fragmented picture; each product line (FRAX, Fraxlend, Fraxswap, frxETH, sFRAX, Fraxtal) requires independent review of the relevant audit to confirm fixes.
  • Full on‑chain verification of actual admin controls, timelocks, and multisig composition across Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP, Polygon is Not verifiable as of 2026‑08‑29 without direct on‑chain analysis.
Evidence (13)

Economy

TVL: $119.0M

model

two sources

Frax is best described as a multi-product, collateral-backed DeFi ecosystem rather than a single yield strategy. Its core economic model spans frxETH/sfrxETH (ETH staking), Fraxlend (permissionless lending), Fraxswap (AMM with TWAMM), and Fraxtal (an L2 that uses frxETH as gas), with each product generating yield from different sources. The dominant yield source for the ETH leg is organic staking yield and MEV accrued by validators and distributed to sfrxETH holders; that yield is not primarily subsidized, though the system description does not rule out incentives elsewhere. The model is mostly market-neutral for the staker on the ETH product: users deposit ETH, receive frxETH, and can stake into sfrxETH to earn validator rewards while staying exposed to ETH price risk, not directional protocol leverage. Fraxswap is used internally for rebalancing collateral, mints/redemptions, and protocol-owned liquidity, which suggests treasury/collateral management rather than directional speculation. Fraxlend adds external credit exposure because returns depend on borrower interest and collateral quality, so risk is driven by lending-market utilization and liquidation performance. On-chain verification is Not verifiable as of 2026-08-29 because Dune access is unavailable in this run, so protocol revenue, collateral composition, lock-ups, withdrawal mechanics, fee gates, and chain-by-chain TVL splits cannot be independently confirmed from raw chain data here. DefiLlama reports Frax Finance TVL of about $284.43m across Ethereum, Fraxtal, Arbitrum, BSC, Avalanche, Polygon, OP Mainnet, and Fantom; Ethereum dominates, with Fraxtal a distant second. DefiLlama separately lists Frax at about $47.81m on Ethereum only, which indicates a definition mismatch between the narrower Frax protocol view and the broader Frax Finance umbrella. For APY, the relevant characteristic is sustainability through real yield on frxETH/sfrxETH, but the exact APY history and volatility are Not verifiable as of 2026-08-29 in this run. The most defensible read from the available sources is that Frax’s yield is primarily organic on the staking side, while lending/AMM products add heterogeneous, utilization-driven revenue streams rather than a single subsidized incentive farm.

Evidence (5)

reserves

two sources

Frax’s treasury/reserve picture is materially different by product era. For the legacy FRAX model, Frax described a Protocol Reserve Treasury used for governance-token holdings and stabilization; that older reserve pool was managed to support yield and peg stability. For the current frxUSD era, Frax states that Frax Inc. is responsible for managing custodians, reserve composition, audits, and attestations, with reserves backed by permitted cash-equivalent assets, including tokenized U.S. Treasury products and stablecoin reserve paths. The best available public sources do not provide a complete, on-chain verified treasury size or a complete custody map for all chains in this run. Not verifiable as of 2026-08-29. The same applies to chain-by-chain reserve balances across Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon. Not verifiable as of 2026-08-29. What is verifiable from the gathered sources is the control model: Frax says reserve oversight sits with Frax Inc., and community/governance material indicates the protocol treasury has historically been used as a reserve backstop and yield engine. Public third-party commentary also indicates a meaningful share of backing is held off-chain in custodial/RWA structures rather than solely in smart contracts, but that part is dependent on attestations and issuer reporting rather than direct chain inspection. No current on-chain balance breakdown, custody-address inventory, or Dune-style as-of snapshot is available in this run. Not verifiable as of 2026-08-29.

Evidence (6)

tokenomics

two sources

Frax has multiple core tokens; the native governance / value token is Frax Share (FXS), plus FRAX stablecoin and newer Frax v3 assets. ### Core tokens

  • FXS (Frax Share) – governance / value-accrual.
  • Main contract (Ethereum): 0x3432b6A60D23Ca0dfCA7761B7ab56459D9C964D0.
  • FRAX – USD-pegged stablecoin (Ethereum): 0x853d955aCEf822Db058eb8505911ED77F175b99e. ### Supply, market cap, FDV Not verifiable as of 2026-08-30 (on-chain check via Dune unavailable; aggregator figures conflict and change frequently). ### Token utility & governance
  • FXS: used for protocol governance, including monetary policy, collateral configuration, and expansion into Frax v3 / Fraxtal L2.
  • Value capture: historically via AMO profits, protocol fees, and buybacks, and in v3 via yield on protocol-controlled collateral and rollup revenues.
  • FRAX: used as stable medium of exchange, DeFi collateral, and base asset in Frax ecosystem (lending, staking, Fraxtal gas incentives). ### Revenue share, buybacks, burns, staking
  • Earlier Frax versions directed revenue to FXS holders via veFXS staking, gauge weight voting, and buybacks; current v3 design continues fee and yield routing to governance token holders, but exact splits per product vary and are described only in docs/medium posts (unverified marketing claims).
  • Staking: veFXS lock/stake model for boosted rewards and governance influence on Ethereum; mirrors or variants exist on other chains via bridges/wrappers. ### Emissions & unlocks
  • FXS launched with a fixed max supply and multi-year emissions schedule including liquidity mining, community incentives, and team/investor allocations.
  • Whether specific cliffs / unlocks executed on-chain on each date is Not verifiable as of 2026-08-30. ### Allocations & concentration
  • Launch documents describe allocations to community/LP incentives, team, investors, and treasury (numbers differ between sources; no single canonical off-chain source).
  • Top-holder / insider concentration by address across chains is Not verifiable as of 2026-08-30. ### Control functions
  • Core FRAX/FXS contracts include minting and monetary-policy functions controlled by governance (Frax DAO / multisig); no credible source shows end-user blacklist or arbitrary seizure functions in the main stablecoin contract, but this is Not verifiable as of 2026-08-30 at bytecode level. ### DEX liquidity & listings (multi-chain)
  • Ethereum: FRAX and FXS have deep liquidity on Curve, Uniswap, and other major DEXs; both also listed on centralized exchanges.
  • Arbitrum, Optimism, Polygon, BSC, Avalanche, Fantom, Fraxtal: FRAX and bridged/wrapped FXS pairs exist on leading local DEXs (Uniswap v3 forks, Curve deployments, native DEXs), but exact pool depth and chain-by-chain TVL are Not verifiable as of 2026-08-30.
Evidence (5)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Under a BTC < $10,000 stress scenario, the directly relevant risk for Frax is not Bitcoin exposure itself, but any knock-on effect on market confidence, collateral values, and governance-token liquidity across Frax’s multi-product system. Frax’s core design is that FRAX adjusts its collateral ratio when FRAX trades below $1, and it becomes more collateralized as depeg pressure rises. For a BTC crash, the most plausible stress path is a broader DeFi risk-off event: if crypto markets sell off sharply, FXS price pressure could make any partially algorithmic components less effective, because Frax’s architecture historically used FXS as part of the mint/redemption balance and risk assessments explicitly note bank-run risk from native-token dependence. In that case, the protocol’s own mechanism would tend to respond by raising collateralization if FRAX weakens, shifting the system toward more conservative backing. What is not verifiable as of 2026-08-29 from the available sources is Frax’s exact chain-by-chain TVL exposure, reserve composition, or how much of its current liabilities sit on Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon. Because on-chain verification is unavailable in this run, those figures should not be inferred. Practically, the stress result is:

  • Primary vulnerability: FRAX/FXS confidence loop and liquidity under market-wide panic
  • Primary defense: dynamic collateral-ratio adjustment toward higher backing when FRAX trades below peg
  • Unknown in this run: exact current solvency margin, protocol-owned liquidity, and chain-level exposure split The most important conclusion is that a BTC collapse below $10,000 would likely be a systemic DeFi stressor for Frax, but the available evidence does not show a BTC-specific insolvency trigger; the protocol’s documented design instead suggests a move toward higher collateralization under stress.
Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

Frax is not fully stress-testable from the provided sources for a “largest collateral depeg 20%” scenario across Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon. The available material confirms that Frax has used a dynamic collateral ratio in v1 and that v3 targets full exogenous collateralization, but it does not provide chain-by-chain collateral inventories or a verified stress-loss output for a 20% collateral depeg, so the impact is Not verifiable as of 2026-08-29. The most relevant risk implication from the sources is that Frax’s earlier design was explicitly exposed to recollateralization/decollateralization dynamics, and independent analysis warned that a bank-run or collateral impairment could force FRAX redemptions, pressure FXS, and worsen the peg via reflexive selling. However, those sources do not quantify losses for a 20% depeg of the largest collateral asset, nor do they identify which chain holds the largest collateral share at this date. For an institutional estimate, the missing inputs are:

  • the current on-chain collateral composition by chain,
  • the largest collateral asset and its dollar weight,
  • whether the asset is exogenous collateral or endogenous/supporting inventory,
  • and the protocol’s current redemption/AMO response capacity by chain. Because those inputs are not verifiable from the provided sources, the correct risk statement is: a 20% depeg in the largest collateral asset would likely reduce the effective backing of FRAX and could amplify redemption stress, but the dollar loss and solvency effect are Not verifiable as of 2026-08-29.
Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Frax’s main counterparty-insolvency exposure on the listed chains is not a single credit counterparty, but bridge/OFT infrastructure, lockboxes, multisigs, and lending/AMM counterparties. The dominant loss path is: a counterparty or custodian fails → assets backing a wrapped/OFT representation or a lending position become inaccessible or undercollateralized → the affected token market reprices → the loss is absorbed first by the specific pool, vault, or collateral silo, then by downstream holders of the impacted wrapped asset or LP token. Frax docs say the cross-chain OFTs and lockboxes are audited and managed by a 3/6 multisig on each respective chain, which means governance/operators can potentially pause, upgrade, or remediate, but users bear residual smart-contract and custody risk if the multisig or bridge stack is compromised. Per chain: the web sources confirm Frax has active deployments on Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon; Frax also publishes chain-specific contract addresses for many of these networks, including Ethereum, Arbitrum, Avalanche, BSC, Fantom, Fraxtal, and Polygon. However, the exact chain-by-chain TVL/exposure mix and the precise loss waterfall are not verifiable as of 2026-08-29 without on-chain queries. Expected loss path: if the insolvent counterparty is a bridge or lockbox operator, the immediate loss is a backing deficit in the wrapped asset or OFT; if the insolvent counterparty is a lending borrower/market participant, the loss is a bad-debt shortfall inside the relevant lending market or vault. In both cases, the compensation mechanism is typically limited and contract-specific: liquidation proceeds, overcollateralization buffers, protocol-owned liquidity, or treasury/governance intervention; there is no evidence in the retrieved sources of an explicit full-loss guarantee. Impact through smart contracts: funds flow through the relevant chain’s token contract, bridge/lockbox, and any associated AMM/lending contracts; once solvency breaks, redemptions or swaps can fail, pricing can decouple, and downstream integrated protocols absorb the mark-to-market loss. Trail of Bits’ Frax review shows the protocol has had material security findings historically, reinforcing that contract-level failures can propagate beyond the first affected component. Callout: The sources retrieved do not provide a verified, quantitative insolvency waterfall for each chain or a chain-specific loss allocation schedule. Not verifiable as of 2026-08-29.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For a fraud-by-DAO-or-owners stress scenario, Frax shows meaningful governance and custody centralization risk, but I found no verified public evidence that the DAO or owners committed fraud. The strongest support in the available sources is that Frax relies on centralized or enshrined custodians for frxUSD reserves, and external analysts have flagged limited visibility into off-chain assets and centralized dependencies. What is verifiable is that Frax has had security findings and governance controversies, not a confirmed fraud finding. Code4rena identified multiple vulnerabilities in Frax Ether Liquid Staking, including a note that the admin could “rug pull” the protocol without a timelock, which is a centralization-risk signal rather than proof of fraud. LlamaRisk also highlighted “centralized dependencies” and “general lapses in funds management oversight.” A separate media post alleged a DAO proposal could be used to misappropriate user assets, but this is an allegation and not a verified adjudication. Community commentary on Frax’s governance/depeg history similarly reflects concern about founder or institutional influence, but not a confirmed fraud event. On balance, the appropriate stress-test answer is: yes, this is a plausible severe risk vector for Frax because of centralized controls and off-chain reserve dependence, but it is not verifiable as a historical fraud event based on the available sources.

Evidence (7)

stress scenario - primary yield source negative 30d,

two sources

Under a stress scenario where Frax’s primary yield source is negative over 30 days, the main risk is that the staking vault’s current APY could fall toward zero or become negative if the protocol cannot offset losses with its alternate yield sleeves. Frax’s own documentation says yield for sfrxUSD is allocated across carry-trade, AMO, and IORB/T-bill venues, and that the vault shifts to the best available source in current market conditions. The broader Frax design also states that when IORB declines, AMO strategies rebalance toward on-chain decentralized assets and overcollateralized loans, which implies the protocol is intended to switch sources rather than depend on a single venue. For sFRAX specifically, independent risk research says the yield has historically been sourced from a mix of RWAs and AMO activity, and that the live allocation can be dominated by on-chain sources when those are more attractive. That means a 30-day negative primary source does not automatically imply immediate insolvency, but it does create yield compression risk and may force the protocol to either pass through lower returns to users or consume reserves/alternate earnings if available. For fraxETH, the staking model is structurally different: validator rewards are the yield source, with 90% routed to sfrxETH holders, 8% to protocol fee, and 2% to insurance. If validator yield were negative over 30 days, that would be an exceptional stress event; the documentation supports reward distribution but does not show a mechanism guaranteeing positive returns in that scenario. Bottom line: the stressed outcome is lower or potentially negative user yield, not a confirmed balance-sheet failure. However, the exact loss absorption capacity, reserve buffers, and current yield mix are Not verifiable as of 2026-08-29 from the provided sources.

Evidence (5)

Governance & Legal

governance

two sources

Frax is transitioning from core-team multisig control to a veFXS-based on‑chain governance (frxGov), but many critical powers remain effectively company/multisig-controlled today. Who controls what

  • Smart contracts / funds: Frax uses a hub‑and‑spoke model of Gnosis Safes (treasuries, AMO safes, product safes) where the FraxGovernorAlpha TimelockController is configured as a Safe module with *full control* over each Safe. However, analysis notes that the admin of this timelock is a Frax “comptroller” core‑team multisig, which can override governance and thus retains ultimate power over protocol contracts and funds.
  • Frontend / app: Not explicitly documented in retrieved sources; typical pattern is company/team operation. Not verifiable as of 2026‑08‑30. Governance mechanics & proposal process
  • Governance token: FXS; veFXS (time‑locked FXS up to 4 years) provides voting power across the Frax ecosystem.
  • Eligibility: Only veFXS holders can call propose() in FraxGovernorAlpha. Smart contracts/DAOs must be whitelisted to stake for veFXS and otherwise only EOAs can lock.
  • Voting: Snapshot‑based process (FIP‑1), where:
  • Voting uses weighted voting of veFXS and certain boosted FXS balances.
  • Quorum: 5% of circulating FXS for normal proposals; 10% for meta‑governance/emissions.
  • Majority threshold: simple majority (50%+1). DAO vs symbolic control
  • Frax documents state the “final state” is veFXS governance having full control of major Safes. Independent risk assessments (e.g., LlamaRisk, Prisma) report that on‑chain governance is “largely unused” and a team‑controlled multisig executes operations and veFXS decisions, with some products’ timelocks wired but not yet practically used.
  • This indicates the DAO is partially implemented: governance exists but execution is still significantly dependent on the core team multisig. Timelock & multisig details
  • Governor timelock: Standard 2‑day delay, adjustable; during the delay, a veFXS majority can veto malicious transactions.
  • Admin: Timelock’s admin is the Frax comptroller multisig, so the team can change timelock parameters or bypass via admin power.
  • Multisig example: For sfrxETH operations, PrismaRisk cites a 3‑of‑5 team multisig controlling protocol operations and upgrades, with Frax governance timelock currently “not in use.” Broader signer identities/independence are not disclosed in retrieved sources. Company / legal entity
  • External profiles describe Frax as a project founded by Sam Kazemian and co‑founders in 2019. Frax’s own FAQ notes Sam and Travis now act as advisors and the company is led by Ted Forselius, Navin Vethanayagam, and Cesar Rodriguez.
  • Formal legal entity name, jurisdiction, registration number, directors’ registry entries, and ToS linking governance to a specific company are not verifiable as of 2026‑08‑30. Chain distribution
  • Governance and veFXS are anchored on Ethereum mainnet, with a Fraxtal veFXS counter aggregating Ethereum + Fraxtal balances. Governance power on other chains (Arbitrum, Avalanche, BSC, Fantom, OP, Polygon) appears indirectly controlled via the same Safe/Timelock architecture, but detailed per‑chain TVL and control breakdown are not verifiable as of 2026‑08‑30.
Evidence (15)

legal & regulatory

two sources

Frax is a US-based stablecoin and DeFi protocol ecosystem (FRAX, frxETH, lending, staking) operated by Frax Finance / Frax Labs, with core entities and contributors largely in the United States. Its products are broadly accessible across major EVM chains, with no chain‑specific legal segmentation visible from public sources. Entity / jurisdiction & legal structure

  • Frax originated as the Frax stablecoin (initially partially algorithmic, now fully collateralized).
  • The project appears to be organized around Frax Finance / Frax Labs, with founders (e.g., Sam Kazemian) U.S.-based.
  • No clearly articulated corporate group structure (e.g., Cayman foundation + U.S. devco) is publicly documented across independent sources; this is Not verifiable as of 2026‑08‑29. Terms of Service / user restrictions
  • Front-end apps (e.g., app.frax.finance) include typical DeFi disclaimers about use at own risk and not offering regulated financial services.
  • Geo‑restriction or exclusion of specific jurisdictions (e.g., U.S. persons, sanctioned countries) is Not verifiable as of 2026‑08‑29 from independent non‑protocol sources. KYC / AML
  • Core Frax on-chain products on Ethereum, Arbitrum, Avalanche, BSC, Fantom, Fraxtal, OP Mainnet, Polygon are permissionless smart contracts; no KYC is applied at protocol level.
  • Some centralized exchanges listing FRAX or FXS apply KYC/AML at the exchange level, not at the protocol level. Regulatory classification & public commentary
  • FRAX is generally treated by market observers as a crypto‑asset stablecoin, not as bank money; it is not recognized as legal tender.
  • No clear, authoritative regulatory classification (e.g., security vs. commodity vs. payment token) has been issued specifically for FRAX or FXS by major regulators; this is Not verifiable as of 2026‑08‑29. Warnings, enforcement, court cases, sanctions
  • No public record of direct enforcement actions or formal warnings targeting Frax Finance, FRAX, or FXS by the SEC, CFTC, FinCEN, OFAC, or EU regulators was identified in independent searches; therefore any such actions are Not verifiable as of 2026‑08‑29.
  • No court cases or sanctions lists specifically naming Frax or FRAX were identified; again Not verifiable as of 2026‑08‑29. Data protection / privacy
  • Like typical DeFi protocols, Frax front ends may collect web analytics data; comprehensive independent analysis of their privacy practices is Not verifiable as of 2026‑08‑29. Risk note (legal vs actual)
  • The absence of explicit regulatory actions does not imply regulatory comfort. As a non‑KYC, multi‑chain stablecoin and DeFi protocol operated by U.S.-linked founders, Frax remains exposed to evolving U.S. and global stablecoin, securities, and DeFi regulatory regimes.
Evidence (4)

Stability

stability

two sources

Yes — FRAX has depegged in the past. The clearest documented episode in the gathered sources is the March 2023 USDC banking crisis, when FRAX was among the depegged stablecoins referenced in coverage of the event. A separate source says FRAX has generally stayed close to peg and cites only one deviation greater than 0.5% on 2025-06-26 for frxUSD, but that is a different token variant and does not by itself establish a historical FRAX depeg count. How many times: not verifiable as of 2026-08-29 from the gathered sources. There is no reliable, chain-verified tally here, and one source explicitly notes that definitions of a depeg vary, which changes the event count materially. Last time: the last clearly evidenced depeg-related event in the gathered sources is March 2023. The exact last timestamp for FRAX itself is not verifiable as of 2026-08-29. % of depeg: not verifiable as of 2026-08-29. The sources gathered do not provide a confirmed FRAX price floor or a precise percentage move for the last FRAX depeg event.

Evidence (3)

Risks & Strengths

risks

two sources

For Frax, the top 5 protocol risks are: (1) stablecoin design / peg risk if collateral or market conditions stress FRAX or related assets; (2) smart-contract and product-complexity risk from a broad suite spanning stablecoin, staking, lending, and L2 components; (3) dependency / contagion risk from reliance on external venues, liquidity, and counterparties; (4) transparency and governance risk if critical fixes or design changes are not fully disclosed; and (5) regulatory / legal risk given the protocol’s large, multi-product DeFi footprint and exposure to stablecoin-style oversight concerns. The strongest source-backed themes are the following. Hindenrank identifies Frax’s historical fractional-algorithmic design as vulnerable to a Terra-like death spiral under severe stress, and also flags ecosystem-wide smart-contract risk because multiple products can compound one another. LlamaRisk’s sFRAX assessment adds that Frax depends on traditional-finance rails through its RWA partner, creating counterparty and legal exposure, while also noting crisis-time FRAX depeg risk. Hindenrank further highlights a stealth-patched frxETH vulnerability, which points to disclosure and operational-trust risk. Because on-chain verification is unavailable in this run, the exact chain-by-chain exposure split across Arbitrum, Avalanche, BSC, Ethereum, Fantom, Fraxtal, OP Mainnet, and Polygon is Not verifiable as of 2026-08-29.

Evidence (3)

strengths

two sources

Frax’s top strengths are: 1) multi-asset product breadth — it now spans several core assets and subprotocols, including frxUSD, FPI, frxETH, Fraxswap, and AMO/protocol-owned-liquidity infrastructure; 2) on-chain capital efficiency — its AMO design lets the protocol actively deploy collateral and liquidity to generate revenue rather than leaving assets idle; 3) flexible, adaptive monetary design — the protocol was built around fractional-reserve and algorithmic mechanisms, with a variable backing approach that can adjust to conditions; 4) DeFi-native utility — Fraxswap and protocol-owned liquidity are integrated directly into the system for mint/redemption, rebalancing, and liquidity management; 5) multi-chain extensibility — the protocol design is explicitly intended to operate across multiple networks while keeping FRAX and FXS fungible.

Evidence (2)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 24 two independent sources, 6 one source, 1 unverified.
  • Oldest fact verification date: 2026-08-29.