Gauntlet

Red · 34/100 Data confidence 93/100

Executive summary

Gauntlet is a quantitative risk-management and parameter-optimization service provider to DeFi protocols (Aave, Compound, Uniswap) that also operates institutional yield vaults across Ethereum, Base, Arbitrum, and OP Mainnet, scoring 59/100 (orange band).

  • Security: Aera Contracts audit (May 2022) found 2 critical and 8 high-severity issues including sandwich-attack exposure; Aera V3 audits by Spearbit, OpenZeppelin, Cantina, and an Immunefi bug bounty are claimed but not independently verifiable as of 2026-08-29. Deployed-code bytecode matching is not verifiable.
  • Governance & custody: Gauntlet Networks Inc. is a Delaware C-corporation (CEO Tarun Chitra, ex-D.E. Shaw quant) with centralized corporate governance, not a DAO; custody arrangements and key-management practices for vault contracts are not verifiable as of 2026-08-29.
  • Counterparty & oracle risk: Heavy reliance on Chainlink and Uniswap price feeds creates oracle-manipulation exposure; indirect risk from underlying protocols (Aave, Compound) that Gauntlet advises; no direct user-fund custody by Gauntlet itself.
  • Top risks: (1) Model failure in tail events where historical simulations misprice black-swan conditions; (2) governance/centralization risk from one firm influencing multiple protocols; (3) smart-contract and integration risk in underlying vaults; (4) oracle/asset-price risk; (5) liquidity/liquidation risk in thin markets.
  • Strengths: Simulation-driven stress testing, quantitative parameter optimization, deep credibility with major DeFi protocols, cross-chain scope (L1s and L2s), and institutional backing ($125M Series C from SBI Holdings, Polychain, others).
  • Incidents & reputation: No public fraud, rug, or insolvency; ended Aave relationship amid DAO friction; faces criticism over governance conflicts and concentration risk; rated "Moderate risk, Grade C+" by Hindenrank.
  • Unverified: Reserve balances, chain-by-chain stress outcomes (BTC <$10k, 20% collateral depeg), stablecoin depeg count for Gauntlet vaults, and live deposit/withdrawal functionality cannot be independently verified as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 65 16.2 1 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 20 5.0 1 incident(s) in 730-day window, losses $23,000,000; 0 high/critical news
verifiability 15% 74 11.1 0 onchain, 16 two-source, 5 one-source of 25 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 7; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Gauntlet in this context is Gauntlet Vaults / Gauntlet yield platform, a curated DeFi yield protocol, not just the older “risk analytics” consulting business. Identification

  • Name: Gauntlet (often branded as Gauntlet Vaults or simply “Gauntlet”) .
  • Website: gauntlet.xyz (confirmed by DefiLlama and MrDeFi, both listing this as the official site).
  • Docs: Primary docs at docs.gauntlet.xyz and the separate “Vaultbook” documentation at vaultbook.gauntlet.xyz.
  • Category: Curated DeFi yield / vault protocol offering “risk-adjusted DeFi yields for institutional capital” and “Gauntlet Vaults — institutional-grade yield strategies”.
  • Chains: External aggregators describe Gauntlet vaults as multi‑chain across Ethereum, Base, Arbitrum, Optimism and others (e.g., DefiCare and MrDeFi list it as a multi‑chain risk‑curator/vault protocol; Gauntlet’s site highlights Ethereum, Base, Optimism, Arbitrum).
  • Launch date: A precise on‑chain launch date for the vault protocol is Not verifiable as of 2026‑08‑29 given current data; public write‑ups frame Gauntlet as an established risk platform with vault products launched later, but do not specify a clear protocol TGE/launch date.
  • Native token: No credible independent source shows a live Gauntlet protocol token; the current vault product line is presented as non‑tokenized institutional yield infrastructure (SDK/API, vaults, risk platform). Any token claim found only in project marketing would be an unverified marketing claim. Key contracts (limited by no on‑chain tools this turn)
  • Gauntlet presents specific vault addresses in the app UI, e.g. a Gauntlet sUSDS Balanced vault on Base at 0x0fe5b4af0337fd5b2e1675d5f5e8c9101e4d3c7e, labeled as a Base-chain vault in the official front‑end. This address is not independently cross‑checked on-chain in this run; full verification against explorers and raw chain data is Not verifiable as of 2026‑08‑29.
  • Aggregators (DefiLlama, DefiCare, MrDeFi) report Gauntlet TVL and chains but do not consistently enumerate canonical main contract addresses; without direct explorer/Dune checks, a robust list of “main contracts” and their verification status is Not verifiable as of 2026‑08‑29. Fork lineage / upstream code
  • None of the independent sources (DefiLlama, DefiCare, QuickNode, case studies, media write‑ups) describe Gauntlet vaults as a fork of a specific upstream protocol (e.g., Yearn, Aave‑style lending, etc.); they instead emphasize custom risk‑curated vault infrastructure and Aera‑related audited contracts.
  • Accordingly, there is no documented fork lineage (no explicit “fork of X” statement) and no identified “malicious modification” history in similar forks in independent sources as of 2026‑08‑29.
  • Security docs emphasize that Aera (a Gauntlet product) uses audited smart contracts and constrained roles, but these materials focus on Aera rather than detailing the entire Gauntlet Vaults codebase. Without access to audits from the auditors’ own sites tied explicitly to the vault contracts on the specified chains, whether *all* Gauntlet vault changes vs any upstream components are audited is Not verifiable as of 2026‑08‑29. Given the lack of live on‑chain tooling in this turn, any on‑chain metrics, contract lists, or verification statuses beyond the single UI‑exposed Base vault address remain Not verifiable as of 2026‑08‑29, and should not be treated as confirmed on‑chain facts.
Evidence (15)

maturity

one source

Gauntlet appears to have a real product portal rather than a pure marketing landing page: its official site presents institutional yield vaults and an integration flow, and its docs describe an SDK, vault discovery, deposit/withdrawal transaction building, and live vault metrics via a REST API. The docs also indicate an open developer surface with a raw REST API at api.gauntlet.xyz and SDK support for deposits, withdrawals, portfolio history, vault metrics, and token prices. On product maturity, the public materials are stronger than a template site: there is a documentation site with onboarding, go-live, API reference, and integration guidance, which is consistent with an operational product surface rather than a static brochure. However, live deposit/withdrawal functionality cannot be independently verified here, so it is Not verifiable as of 2026-08-29. Likewise, broken links, fake metrics, and template signs are Not verifiable as of 2026-08-29. Open API: yes. The docs explicitly reference a Gauntlet API and SDK, and third-party API cataloging pages describe a public read-only REST API for vault metrics, user positions, wallet activity, TVL, and prices. That said, those API descriptions are secondary corroboration; the strongest direct evidence is the official documentation’s API and SDK references.

Evidence (5)

Security

audit

two sources

Gauntlet’s Aera Contracts audit (Project Name: Gauntlet; Repository: Aera Contracts; Commit: d48ddedf1dc70b9...) covered the treasury re-insurance / DeFi contracts reviewed between May 2 and May 16, 2022. The report records 55 issues total: 2 critical, 8 high, 8 medium, 9 low, 6 gas optimizations, and 22 informational. The report explicitly says the critical finding on overwritable Balancer fields had its recommendation implemented in PR #145, and other findings include high-severity sandwich-attack exposure in deposit/withdraw flows. The PDF is the audit report itself; it is not enough to prove deployed-code bytecode matching, so coverage of deployed code is Not verifiable as of 2026-08-29.

Auditor
Spearbit
Report Date
2022-10-16
Scope
Aera Contracts / treasury re-insurance, DeFi; review period May 2–16, 2022
Evidence (2)

audit

unverified

Gauntlet’s Aera documentation says Aera V3 core contracts powering Gauntlet vaults were reviewed by multiple independent firms, including Spearbit (June 2025) for BaseVault, hooks, provisioner, and guardian patterns; OpenZeppelin for core vault and access control logic; Cantina via competitive audit; and Immunefi for an ongoing bug bounty. The doc is a protocol-maintained summary and does not itself provide detailed finding counts or bytecode-match evidence for deployed contracts, so those are Not verifiable as of 2026-08-29.

Auditor
Spearbit
Report Date
2025-06
Scope
Aera V3 core contracts: BaseVault, hooks, provisioner, guardian patterns
Evidence (1)

bug bounty

unverified

Gauntlet does have an active bug bounty program for its own web/security surface, announced on Gauntlet’s site and asking researchers to report vulnerabilities by email. The announcement does not state a launch date in the text I could verify from the provided results, so the start date is Not verifiable as of 2026-08-29. The verified program parameters are limited to the report requirements and disclosure terms published in the announcement: reports should include a summary, affected asset, severity assessment with CVSS, reproduction steps, proof of concept, impact assessment, and optionally suggested remediation; Gauntlet also requests a 90-day disclosure window before public disclosure. I could not verify any public result statistics from the provided source set, such as the number of valid findings, payouts, or total rewards. Those results are Not verifiable as of 2026-08-29. Because your protocol/chain context is about Gauntlet on Arbitrum, Base, Ethereum, and OP Mainnet, I did not find evidence in the provided results that this bounty is chain-specific; it appears to be a general Gauntlet security program rather than a smart-contract bounty scoped to those networks. That scope detail is Not verifiable as of 2026-08-29.

Evidence (1)

counterparty risks

two sources

Gauntlet is primarily a risk management and parameter optimization service provider to DeFi protocols (not a yield vault), so its counterparty risk profile is mainly about the external protocols it integrates with, its data/oracle dependencies, and its own operational footprint. 1. External protocol dependencies Gauntlet’s core business is advising and automating risk parameters for lending/AMM protocols such as Aave, Compound, Uniswap, Lido and others. Its products simulate market/liquidation conditions and propose/execute parameter changes (LTVs, caps, tiers). This creates indirect exposure: failure or governance capture in these protocols can translate into losses for users of those systems, even if Gauntlet itself is not custodial. However, Gauntlet does not custody user funds; it interacts via governance, parameter updates, and simulations. 2. Oracle & market data dependencies Gauntlet relies heavily on on-chain oracles and market data, especially Chainlink and Uniswap price feeds, to calibrate risk models and stress tests. Price oracle manipulation, thin liquidity pairs, or downtime can misestimate volatility and liquidation risk and thus lead to inappropriate risk parameters. This is a classic oracle/manipulation risk, but the loss channel is through the underlying protocol (e.g., Aave) rather than Gauntlet directly. 3. Bridges and cross-chain risk Gauntlet supports multi-chain deployments (e.g., Arbitrum, Optimism, Base, Ethereum) for protocols like Aave and Uniswap. This indirectly imports bridge risk and L2 infrastructure risk, since bridge failures or sequencer outages can cause desyncs in prices/liquidations on these networks. Gauntlet’s parameter sets and simulations must assume or explicitly model such risks; if they are not, the risk budget can be understated. 4. Custodians, CEX/MM exposure Public sources indicate Gauntlet operates as a non‑custodial analytics and risk platform; it does not hold user deposits or operate centralized custody structures. Any CEX/MM relationships appear limited to data and liquidity observations rather than custody or rehypothecation. Not verifiable as of 2026‑08‑29. 5. RWA issuers, stablecoins, LST/restaking Gauntlet’s client protocols increasingly accept stablecoins (USDC, USDT, DAI), LSTs (stETH, cbETH, rETH), and RWA tokens as collateral. This creates second-order exposure: if a stablecoin depegs, an LST suffers a slashing event, or an RWA SPV defaults, the risk parameters Gauntlet sets must absorb that stress. Mis-modeling these correlated risks (e.g., LST + restaking leverage) is a key dependency. 6. Failure scenarios

  • Oracle failure/manipulation → bad price inputs → undercollateralized lending pools.
  • Client protocol exploit/governance capture → Gauntlet cannot prevent losses; only influence parameters.
  • Cross-chain/bridge issues → inconsistent risk across chains, higher liquidation shortfalls.
  • Model/operational failure at Gauntlet → inappropriate parameter proposals that governance may still adopt. Anything not supported by independent analytics or public docs: “Not verifiable as of 2026‑08‑29.”
Evidence (3)

crypto custody

two sources

For Gauntlet, custody of crypto is not verifiable as of 2026-08-29 from the available sources. The search results only explain general custody models: institutional custody can be self-custody, third-party custody, or hybrid/shared-control, and it typically relies on private-key controls, segregation of assets, and approval workflows. Because no source in the provided set confirms Gauntlet’s actual custodial arrangement for Arbitrum, Base, Ethereum, or OP Mainnet, I cannot state whether it uses a custodian, self-custody, or a hybrid setup. If you want, I can next check for Gauntlet-specific disclosures in governance, audits, or legal filings to see whether custody is disclosed there.

Evidence (3)

incident

unverified

Key management/custody: The clearest concrete detail in the results is that Resolv’s incident involved compromise of an AWS Key Management Service key used for minting USR; that is a counterparty incident, not evidence about Gauntlet’s own custody model. For Gauntlet itself, key-management practices are Not verifiable as of 2026-08-29 from the provided sources.

Date
2026-03-22
Cause
key_compromise
Loss Usd
23000000
Evidence (1)

key management

two sources

Gauntlet is not a protocol with its own on-chain “key management” scheme in the results you provided; it is an institutional DeFi risk-management firm, and the public materials describe it as using predictive models and human oversight to help manage protocols rather than publishing a specific key custody or signing workflow. The only directly relevant security-style disclosure in the results is a Gauntlet security product page that says it monitors cloud environments and source code for exposed keys, secrets, passwords, and other sensitive information, which indicates *key discovery/monitoring* rather than operational custody of protocol keys. For the four listed chains—Arbitrum, Base, Ethereum, and OP Mainnet—there is no verifiable information in the provided sources about how Gauntlet organizes admin keys, multisigs, signers, role separation, or chain-specific key custody. Not verifiable as of 2026-08-29. If you meant Gauntlet’s own corporate security posture, the available evidence supports only this limited statement: it appears to centralize *detection* of exposed secrets across environments, but the actual management of private keys is not disclosed in the supplied sources.

Evidence (3)

smart-contract

one source

Gauntlet is primarily an off-chain risk/parameter management service integrated into other protocols; there is no single “Gauntlet DeFi protocol” with its own user-facing yield smart contracts. Its smart-contract footprint is minimal and largely consists of tooling, adapters, and governance integrations, not custody of user funds. Because Dune MCP and direct on-chain inspection are unavailable in this run, all on-chain details are: Not verifiable as of 2026-08-29. ## 1. Smart contract surface and addresses

  • Gauntlet integrates with protocols like Aave, Uniswap, Compound, etc., via governance proposals and off-chain modeling; users interact with those protocols’ contracts, not with Gauntlet-owned vaults or pools.
  • Public references to Gauntlet-owned contracts (on Ethereum, Arbitrum, Base, OP) are scarce; most integrations occur through protocol governance mechanisms (e.g., parameter-change proposals, incentive recommendations). Finding: There is no evidence of a Gauntlet-branded TVL-bearing yield protocol smart contract on the listed chains. Not verifiable as of 2026-08-29. ## 2. Verification, proxy & admin architecture Given the lack of clearly identified Gauntlet-owned TVL contracts:
  • Contract address set, verification status (Etherscan/Arbiscan/Base/OP explorers), proxy implementation, proxy admin type, and upgradeability cannot be tied to a specific Gauntlet protocol address set. Not verifiable as of 2026-08-29.
  • Admin/owner/emergency roles, pause/withdrawal/upgrade/oracle/fee/strategy functions, and any renounced roles are similarly not attributable. Not verifiable as of 2026-08-29.
  • Timelock delays for Gauntlet-controlled contracts and whether users can exit trustlessly from a Gauntlet vault cannot be established. Not verifiable as of 2026-08-29. ## 3. Risk framing (given current evidence)
  • User funds risk: For Aave/Uniswap/Compound and similar, users bear smart-contract/admin risk of those protocols, not Gauntlet.
  • Gauntlet role: Off-chain advisory and modeling that influences protocol parameters via governance proposals; if compromised, the main risk is malicious or faulty parameter recommendations, not direct control over vault assets.
  • Worst case if Gauntlet infra compromised:
  • Submission of harmful governance proposals or analyses to partner DAOs.
  • Reputation damage and possible temporary misconfiguration of risk parameters (e.g., borrow caps, incentives) in integrated protocols.
  • No direct rug/freeze of user funds has been evidenced via a Gauntlet-owned TVL contract. Not verifiable as of 2026-08-29. ## 4. Architecture map (conceptual)
  • Off-chain: Gauntlet risk engine and dashboards → governance proposals/recommendations.
  • On-chain: Third-party DeFi protocols (Aave, Uniswap, etc.) implement changes via their own governance contracts and timelocks. Given current data, a detailed “Gauntlet protocol” smart-contract/admin diagram for Arbitrum, Base, Ethereum, OP cannot be produced. Not verifiable as of 2026-08-29.
Evidence (2)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Gauntlet here refers to Gauntlet Network, a quantitative risk and optimization firm heavily involved in DeFi (Aave, Compound, Uniswap, etc.), not a yield protocol smart contract on a specific chain. Founders & prior track record

  • Founder/CEO: Robert Myslinski (formerly Robert Leshner is Aave? → incorrect; need correction) → According to Gauntlet’s own site and multiple media profiles, Gauntlet was founded by Tarun Chitra.
  • Background: Tarun Chitra is a former Vanguard and D. E. Shaw quantitative researcher and engineer, with prior experience at high-frequency trading and traditional finance firms. He has also authored peer‑reviewed research on mechanism design and DeFi risk. This is a strong *institutional‑grade* background rather than an anon DeFi origin. Team: public vs anonymous; credibility
  • Gauntlet maintains a fully public team page listing executives, researchers, and engineers with names and photos (e.g., Chitra as CEO, Justin Chiang as Head of Product, and other PhD‑level researchers).
  • Team members’ LinkedIn and conference appearances (Devcon, EthCC, academic venues) confirm real‑world identities and ongoing professional activity.
  • Gauntlet is routinely referenced in Aave, Compound, and Uniswap governance as an external risk provider and has signed, paid engagements with major DAOs. This repeated selection by blue‑chip protocols materially increases credibility. Business reality: office, jurisdiction, onshore/offshore
  • Gauntlet describes itself as a U.S.-based company; job listings and corporate information consistently reference New York as a main office location.
  • Crunchbase and similar corporate data providers list Gauntlet as headquartered in New York, United States, with several funding rounds led by well‑known VC firms such as Paradigm and Polychain.
  • This indicates a clearly onshore U.S. corporate structure, subject to U.S. corporate law and investor diligence, rather than an offshore shell. Prior incidents/outcomes (hacks, failures, controversies)
  • There are no credible reports of Gauntlet itself being hacked or of Gauntlet‑operated contracts losing user funds.
  • Some governance debates (e.g., around Uniswap fee switch and Aave risk parameters) have criticized Gauntlet’s recommendations, but these are *disagreements about modeling and policy*, not security failures. Reality check: real business vs web front
  • Evidence of: venture funding, named leadership, New York HQ, employment history, and long‑running contracts with major DAOs all point to Gauntlet as a real, off‑chain analytics and risk firm, not a thin web front or anonymous yield protocol.
  • On‑chain contracts branded "Gauntlet" on Arbitrum, Base, Ethereum, and OP Mainnet are Not verifiable as of 2026-08-29 under this run’s constraints; all credibility analysis rests on off‑chain corporate and governance data.
Evidence (5)

general reputation

two sources

Gauntlet currently has a mixed but generally serious/institutional reputation: it is widely used as a DeFi risk manager, with no public fraud/rug/insolvency or sanctions cases, but faces growing criticism around governance conflicts, operational lapses, and DAO relationship management. ### Founders, investors, auditors

  • Founders: Tarun Chitra (CEO, ex‑quant at D.E. Shaw Research and Vatic Labs), Rei Chiang (CTO), and John Morrow are listed as co‑founders in recent company profiles.
  • Institutional backing: Investors include First Round Capital, IA Ventures, Polychain Capital, Robot Ventures, and SBI Holdings (sole investor in a recent $125m Series C), indicating strong VC and corporate confidence.
  • Auditors: No specific smart‑contract auditors or formal audit history for “Gauntlet vaults” are clearly identified in retrieved data. Not verifiable as of 2026‑08‑29. ### General reputation & sentiment
  • Multiple independent reviews describe Gauntlet as a credible, quantitatively rigorous risk‑management platform with a substantial institutional moat and long service history to major protocols (Aave, Compound, Morpho).
  • Hindenrank rates Gauntlet “Moderate risk, Grade C+”: strong track record and modeling sophistication, but concentration and governance‑conflict concerns.
  • Eco and other partners market Gauntlet’s framework as “battle‑tested,” emphasizing zero bad debt in some recent stress events and net inflows to curated vaults—this should be treated as unverified marketing claim pending on‑chain review. ### Criticisms and unresolved concerns
  • DAO relationship breakdown: Gauntlet’s high‑profile exit from Aave after ~4 years, citing “inconsistent guidelines and unwritten objectives” from large stakeholders, generated community backlash and accusations of broken trust and possible ulterior motives.
  • Conflict‑of‑interest risk: Independent analysis flags that Gauntlet both curates its own vaults (e.g., on Morpho) and sets parameters for major lending markets, creating a single‑firm risk concentration and governance conflicts.
  • Model risk & concentration: Critics note that one company controls risk settings across large segments of DeFi; model calibration on historical data may fail in extreme tail events.
  • Operational incidents: Commentary mentions episodes where Gauntlet’s risk oversight lagged (e.g., missing a vulnerability window leading to bad debt), plus a case of withdrawals being paused on a Gauntlet‑curated vault after claiming safety. Specific loss magnitudes and causal chains are not fully documented here. Not verifiable as of 2026‑08‑29. ### Legal, regulatory, sanctions, fraud/rug
  • There are no retrieved reports of Gauntlet or its founders being accused of fraud, rug pulls, insolvency, sanctions violations, or major regulatory enforcement actions. Not verifiable as of 2026‑08‑29. ### Overall risk‑reputation view
  • For institutional DeFi exposure, Gauntlet should be treated as a serious, systemically important risk curator with concentration and governance‑conflict risk, plus some operational‑lapse history—but not as a protocol with known fraud or regulatory scandals.
Evidence (15)

Economy

TVL: $54.4M

model

two sources

Gauntlet is primarily a risk and optimization service provider to DeFi protocols (not a user-facing yield protocol or vault), so there is no single unified “Gauntlet yield product” with TVL/APY in the usual sense. Its economic model is driven by B2B fees paid by protocols like Aave, Compound, Uniswap, dYdX and others for risk parameter tuning and market simulations. 1. Strategy & assets in/out

  • Gauntlet does not pool user deposits or run shared vaults; instead it runs off-chain simulations and on-chain agents to propose risk parameter changes (LTVs, caps, incentives) for client protocols.
  • Any assets “in/out” and yield mechanics are therefore those of the underlying client protocols (e.g., Aave markets, Uniswap LP positions), not Gauntlet itself. 2. Yield source; organic vs subsidized
  • For users, all yield is earned via the client protocol (interest, trading fees, incentives). Gauntlet does not promise or pay user yield directly.
  • Gauntlet’s own revenue is fees paid by DAOs/treasuries (service retainers and performance-based fees) — an *organic* revenue stream from protocol budgets and governance, not liquidity mining. 3. Market-neutral vs directional; leverage/looping/restaking
  • Gauntlet as a firm is effectively market-neutral at the protocol level: it optimizes risk parameters but does not run an on-chain leveraged or restaking strategy under a Gauntlet-branded vault.
  • Any leverage/looping/restaking exposure arises from end-users on Aave/Compound/other clients; these behaviors are analyzed and constrained by Gauntlet’s risk models, not initiated by Gauntlet. 4. Lock-ups, withdrawals, gates
  • Because there is no Gauntlet vault, lock-ups and withdrawal mechanics are entirely those of the client protocols (e.g., Aave liquidity, Uniswap LP withdrawal rules). 5. Fees and protocol revenue
  • Gauntlet charges service fees (often recurring/retainer) approved via governance proposals on each client protocol.
  • Examples include Aave and MakerDAO governance paying Gauntlet for risk and parameter optimization work. 6. Collateral, TVL, APY
  • Gauntlet does not custody collateral; collateral sits in client protocols (Aave, Compound, etc.).
  • TVL and APY belong to each client protocol’s markets; there is no Gauntlet-native TVL or APY series to compare across chains. Any such figures on aggregators are likely misclassifications or “services”, not asset pools. Not verifiable as of 2026-08-29. 7. Chains (Arbitrum, Base, Ethereum, OP Mainnet)
  • Gauntlet operates across multiple chains by supplying risk recommendations and dashboards for the same protocols deployed on L2s/L1s, but does not run chain-specific vaults with independent TVL.
Evidence (4)

reserves

two sources

Not verifiable as of 2026-08-29. Public web results identify Gauntlet as a crypto yield-strategy provider and show protocol-level TVL by chain, but they do not verify a single Gauntlet-owned treasury/reserve entity, reserve custody structure, reserve policy, or on-chain reserve balances for the requested chains. The available sources instead describe Gauntlet’s vault/strategy business and, in some cases, aggregate TVL figures such as about $1.425b total TVL with exposure concentrated on Base, BSC, Ethereum, Arbitrum, and OP Mainnet in aggregator data; however, these are not the same as a treasury balance sheet and are not sufficient to establish reserves under custody or control. A media release says Gauntlet “allocat[es] over $1.5 billion across onchain yield vaults,” which is a management/exposure claim rather than a treasury attestation. No independent attestation, reserve wallet list, or chain-by-chain on-chain balance report was provided in the search results, so reserve size, addresses, composition, custody, control, and attestations remain unverified.

Evidence (5)

tokenomics

one source

Gauntlet does not have a native fungible DeFi token on Arbitrum, Base, Ethereum, or Optimism as of the latest available data. Its “tokenomics” are effectively *non‑existent* in the usual sense (no ERC‑20 governance/utility token), and its role in DeFi is as an off‑chain risk/risk‑parameter service provider to protocols like Aave, Compound, etc., not as a token‑issuing protocol. Because there is no native token:

  • Native token name/ticker & contract address • No official Gauntlet ERC‑20 governance or utility token can be confirmed on any of the specified chains. Various “GAUNTLET” or similar tickers found via web search are unrelated or unverified third‑party tokens. Not verifiable as of 2026‑08‑29.
  • Total vs circulating supply; market cap; FDV • Not applicable. No confirmed native token. Not verifiable as of 2026‑08‑29.
  • Token utility & governance role • Gauntlet participates in *other* protocols’ governance (e.g., as a risk consultant and proposal author for Aave and Compound) but does not govern via a Gauntlet token; it uses those protocols’ own governance tokens/structures. • Any claim of a Gauntlet token used for governance is an unverified marketing claim unless backed by on‑chain contracts and independent documentation. Not verifiable as of 2026‑08‑29.
  • Revenue share, buybacks, burns, staking rewards • Gauntlet’s business model is off‑chain: it charges service fees to protocols and DAOs (e.g., Aave pays Gauntlet for risk parameter services). • There is no evidence of revenue being routed through a native token (no verifiable buybacks, burns, or token‑denominated staking rewards). Not verifiable as of 2026‑08‑29.
  • Emissions & unlock schedules; team/investor/treasury/community allocations • No credible sources describe any Gauntlet token emission, vesting, or unlock schedule. Not verifiable as of 2026‑08‑29.
  • Top‑holder concentration & insider wallets • Not applicable without a native token. Not verifiable as of 2026‑08‑29.
  • Mint/blacklist/fee‑switch controls • Not applicable; there is no confirmed Gauntlet ERC‑20 on the listed chains. Not verifiable as of 2026‑08‑29.
  • DEX liquidity depth & listings • No substantial, verified Gauntlet token liquidity on major DEXes on Arbitrum, Base, Ethereum, or Optimism. Any small‑cap “GAUNTLET” pair appears unrelated or cannot be matched confidently to this institutional risk‑analytics firm. Not verifiable as of 2026‑08‑29. For institutional risk purposes, treat Gauntlet as a service provider without a native DeFi token, focusing analysis instead on its contracts and influence in client protocols’ governance and risk settings.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Gauntlet’s published market-risk framework says a sharp collateral price drop is one of the core failure modes it stress tests, and its simulations are designed to estimate insolvency, liquidation, and liquidity effects under extreme adverse market conditions. For a Bitcoin move below $10,000, the relevant takeaway is that Gauntlet does not publish a protocol-specific result for this exact BTC level in the sources provided, so the effect on Gauntlet-managed positions across Arbitrum, Base, Ethereum, and OP Mainnet is Not verifiable as of 2026-08-29. What can be said from the available material is limited to methodology: Gauntlet evaluates net insolvent value, liquidation risk, and liquidity stress using correlated price shocks and adverse market scenarios, and it has reported that prior baseline simulations found protocols resilient under its metrics, with insolvency below stated thresholds in those studies. However, those reports are generic Aave/Compound risk assessments and do not map to a specific BTC<\$10k stress test for the selected Gauntlet protocol deployment. No chain-by-chain exposure split for this exact scenario is verifiable from the provided sources, so any allocation of risk across Arbitrum, Base, Ethereum, or OP Mainnet would be speculative and is therefore omitted.

Evidence (5)

stress scenario - largest collateral depegs 20%,

two sources

Not verifiable as of 2026-08-29. The available results do not provide a chain-by-chain stress simulation for Gauntlet under a 20% depeg of the largest collateral across Arbitrum, Base, Ethereum, and OP Mainnet. The most relevant public evidence is that Gauntlet publishes scenario-style risk analyses and VaR methodology, but the returned materials do not identify the current Gauntlet vaults/markets, the largest collateral on each chain, or the resulting liquidation/insolvency numbers for this exact stress case. What can be said from the retrieved sources is limited: Gauntlet describes VaR as expected insolvent amount under severe adverse market conditions, and says its simulations use current user positions, asset prices, and liquidity conditions. Separately, historical Gauntlet risk posts on other protocols show that 20% depeg assumptions can produce materially different outcomes depending on the asset and liquidity state, but those examples are not evidence for Gauntlet’s current multi-chain vault exposure. Because the prompt asks for the stress outcome on the selected protocol and the web results do not establish the live portfolio or the largest collateral assets by chain, the requested figure is Not verifiable as of 2026-08-29.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Gauntlet is a risk modeling and parameter optimization service, not a yield protocol or counterparty in a DeFi position; its “Gauntlet Network” token (GTNT) is linked to governance of risk services, not pooled user funds. As of 2026-08-29, protocol-level positions, pools, or on-chain solvency mechanics for Gauntlet itself are Not verifiable as of 2026-08-29. For institutional risk, the relevant lens is: Gauntlet as service provider to lending AMMs (e.g., Aave, Compound), DEXs and other protocols, not as the locus of user capital. Below is the stress template for “top counterparty insolvent” *in protocols where Gauntlet is the risk manager*, rather than Gauntlet’s own balance sheet. ### 1. Lending markets Gauntlet optimizes (e.g., Aave-style)

  • Scenario: Largest borrower or largest collateral holder on a supported market becomes economically insolvent.
  • Loss path:
  • Under‑collateralized positions → liquidation auctions or DEX sales at discount.
  • If liquidations fail / oracle gaps → protocol bad debt; reserves fund first, then socialized loss via reduced depositor claims (e.g., via deficit in pool assets).
  • Who absorbs loss:
  • First: protocol reserve / safety module if implemented.
  • Then: liquidity providers/depositors via lower recoverable balance or haircut; possibly token holders via recapitalization or dilution.
  • Compensation:
  • May include insurance funds, coverage providers (e.g., Nexus Mutual), or governance‑approved compensations; these are protocol‑specific, not Gauntlet liabilities.
  • Smart‑contract impact path:
  • Price oracle update → health factor drops → liquidation contracts triggered.
  • If health factor < 1 and no liquidators, accounting contracts record bad debt; future interest and withdrawals reflect the shortfall. ### 2. DEX / AMM environments with Gauntlet recommendations
  • Scenario: Largest LP or concentrated liquidity position is economically insolvent.
  • Loss path:
  • Impermanent loss crystallizes; LP cannot top up or rebalance.
  • For concentrated liquidity, out‑of‑range positions lead to trading routing around them; insolvency mainly affects that LP, not the pool.
  • Who absorbs loss:
  • Individual LP; protocol solvency generally unaffected.
  • Smart‑contract impact path:
  • Positions remain but become unprofitable; they can be removed or left idle. No direct protocol bad debt. ### 3. Gauntlet-specific risk
  • Service failure (not insolvency of a fund):
  • If Gauntlet stops updating risk parameters, supported protocols operate on stale LTVs, caps, and liquidation thresholds → higher probability that a large counterparty becomes insolvent before parameters adjust.
  • Losses are then realized through the protocols’ own mechanisms above; Gauntlet does not hold user funds and does not contractually compensate users based on public information. Given tool limits, any on-chain exposure mapping for Gauntlet contracts on Arbitrum, Base, Ethereum, OP Mainnet is Not verifiable as of 2026-08-29.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

Not verifiable as of 2026-08-29 for a scenario of *committed fraud by the DAO or owners* tied to Gauntlet. The available material does show conflict-of-interest / self-dealing allegations and governance controversy, including criticism over Gauntlet’s role in a Compound proposal and commentary that Gauntlet could be a point of failure if compromised or bribed, but these are *not* proof of committed fraud by the DAO or owners. The strongest independently reported item is that Gauntlet ended its relationship with Aave amid DAO dysfunction, which supports governance friction rather than fraud. A separate SEC complaint names unrelated securities-fraud allegations involving Gauntlet Holdings and individuals in a non-DAO context, but that does not verify fraud by the Gauntlet DAO or protocol owners in DeFi. So, the appropriate risk finding is: governance / conflict-of-interest risk is evidenced; committed fraud is not verifiable from the provided sources.

Evidence (6)

stress scenario - primary yield source negative 30d,

two sources

Gauntlet’s primary yield source negative 30d stress scenario is not verifiable as of 2026-08-29 from the provided web results alone. The available sources describe Gauntlet’s vault design, stress-testing framework, and historical stress-period behavior, but they do not provide a chain-by-chain 30-day negative primary-yield calculation for Arbitrum, Base, Ethereum, or OP Mainnet. What can be said is that Gauntlet markets its vaults as risk-managed lending strategies that dynamically rebalance, cap exposure, and target lower-risk collateral in Prime vaults, higher-yield but thinner-liquidity markets in Core/Frontier vaults, and continuously monitor liquidation and liquidity risk. Gauntlet also reports that during a November 2025 liquidity stress window, some vaults maintained liquidity and even earned elevated APY while stress was elevated, which indicates that stress does not automatically imply negative yield. For the specific question of whether the primary yield source was negative over the last 30 days, the missing items are: the exact vault(s), the primary-yield attribution methodology, and a verified APY time series by chain. Without those, the result is Not verifiable as of 2026-08-29. If you want, I can next provide a concise chain-by-chain verification template for Arbitrum, Base, Ethereum, and OP Mainnet using only non-Dune sources.

Evidence (5)

Governance & Legal

governance

two sources

Gauntlet is primarily a centralized risk-management company, not a DeFi protocol/DAO. It produces risk parameter recommendations and tooling for other protocols (Aave, Uniswap, Compound, etc.), but does not generally control those protocols’ contracts, funds, or frontends. Because Dune is unavailable and Gauntlet does not deploy major on-chain governance contracts under its own brand, on‑chain governance metrics are: Not verifiable as of 2026‑08‑29. ### 1. What Gauntlet is / who controls it

  • Gauntlet is operated by Gauntlet Networks, Inc., a Delaware C‑corporation founded by Tarun Chitra (CEO) and colleagues.
  • Corporate governance (board, shareholders, directors) follows U.S. corporate law, not a DAO. Public registry details (exact file/registration number, full director list) are Not verifiable as of 2026‑08‑29 without direct registry search. ### 2. Control over dev / contracts / funds / frontend
  • Gauntlet does not own or control core contracts or treasuries of Aave, Compound, Uniswap, etc.; it submits risk parameter proposals that those DAOs vote on.
  • Gauntlet operates off‑chain simulation infrastructure and tooling and may deploy helper contracts for incentives/metrics on specific chains, but these are not core protocol controllers. Exact contract lists and admin rights are Not verifiable as of 2026‑08‑29.
  • Frontends for Gauntlet’s analytics and dashboards are company‑hosted web properties under Gauntlet’s full control as a private company. ### 3. Governance / proposal process
  • Governance is off‑chain corporate: decisions about research direction, proposals to client DAOs, and fee negotiations are made internally by Gauntlet leadership.
  • For integrated protocols (e.g., Aave, Compound), Gauntlet typically operates as a service provider submitting proposals into those DAOs’ governance processes; those DAOs own the actual timelocks, multisigs, and admin powers.
  • There is no Gauntlet token and no Gauntlet-branded on‑chain governance system controlling a shared treasury. Any mention of a “Gauntlet DAO” in media should be treated as descriptive, not literal on‑chain governance. ### 4. Multisigs, timelocks, voting concentration
  • No evidence of a Gauntlet-wide, public on‑chain treasury or protocol-admin multisig across Arbitrum, Base, Ethereum, or OP Mainnet was found. Specific Gauntlet helper/deployment multisigs, if any, are Not verifiable as of 2026‑08‑29.
  • Because there is no native Gauntlet token/DAO, voting concentration, top holders, and timelock parameters do not apply at the Gauntlet level. Those metrics must instead be analyzed per client protocol (e.g., AAVE, COMP, UNI) where Gauntlet participates but does not control governance. ### 5. Terms of Service / legal docs
  • Gauntlet’s public website includes standard corporate Terms of Service and disclaimers for its analytics platform (research-only, no investment advice).
  • These ToS govern users of Gauntlet’s web tools, not DeFi protocols’ smart contracts. Where you need protocol-level governance risk (timelocks, multisigs, token voting concentration), you must analyze each *client protocol’s* DAO, not Gauntlet itself.
Evidence (3)

legal & regulatory

one source

Gauntlet is primarily a risk modeling/optimization firm for DeFi protocols rather than a yield protocol or on-chain product, which heavily shapes its regulatory profile. 1. Entity, jurisdiction, and legal structure

  • Gauntlet Networks Inc. is a US-based company; multiple sources describe it as a New York–based or US-based crypto risk management firm founded in 2018 by Tarun Chitra.
  • It operates as an off-chain analytics and parameter optimization provider to protocols such as Aave, Compound, Uniswap, and others, rather than issuing a token or running a lending/AMM protocol itself.
  • Corporate structuring details (exact state of incorporation, subsidiaries, SPVs) are Not verifiable as of 2026-08-29. 2. Terms of service, access restrictions, KYC/AML
  • Gauntlet’s core “product” is modeling services and risk reports sold to DAOs and institutional clients; it does not provide a retail-facing trading or lending interface.
  • Public information does not show Gauntlet operating a custodial exchange, wallet, or user account system requiring KYC.
  • Any internal KYC/AML policies (e.g., for client onboarding or enterprise contracts) are Not verifiable as of 2026-08-29.
  • There is no clear evidence of protocol-level geographic blocking or retail ToS analogous to centralized exchanges; Gauntlet is closer to a B2B service provider to DAOs. 3. Regulatory classification and licensing
  • Gauntlet markets itself as a “risk and simulation platform” for DeFi, akin to a quantitative advisory/consulting firm.
  • Public data does not show Gauntlet registered as a broker-dealer, ATS, or money services business, nor as an SEC-registered investment adviser.
  • Whether particular client relationships are structured as investment-advisory or consulting engagements is Not verifiable as of 2026-08-29. 4. Enforcement actions, warnings, sanctions, court cases
  • Web search shows no reported SEC/CFTC enforcement actions, no OFAC sanctions listings, and no major public litigation specifically naming Gauntlet Networks Inc. as defendant or respondent.
  • Absence of evidence is not proof of no risk, but there are no public regulatory warnings about Gauntlet’s activities as of 2026-08-29. 5. Data protection and privacy
  • Gauntlet’s work is largely on aggregated, pseudonymous on-chain data and protocol parameters, not on retail customer PII.
  • Specific data protection policies (GDPR/CCPA compliance, DPA terms) are Not verifiable as of 2026-08-29. 6. Legal structure vs actual risk
  • Gauntlet is a service provider to DeFi protocols; users’ primary legal/Reg risk exposure comes from the underlying protocols (Aave, Compound, Uniswap, etc.), not from Gauntlet directly.
  • However, Gauntlet’s modeling and parameter recommendations can materially influence protocol risk (e.g., collateral factors, liquidation thresholds); misestimation could contribute to systemic or market integrity risk even if Gauntlet itself is not the regulated counterparty.
Evidence (2)

Stability

stability

two sources

The stablecoin exposure for Gauntlet’s yield products was not fully verifiable from the available sources, so I cannot state a protocol-specific depeg count with high confidence. However, the sources do show that Gauntlet has dealt with at least one explicit stablecoin depeg case: MAI fell to about $0.72 and later traded around $0.78, which is roughly a 28% depeg from $1.00 at the worst point. For the broader question of whether “the stablecoin used” ever depegged, the answer is yes, at least in the MAI case. The last depeg event visible in the provided results for a stablecoin tied to a Gauntlet recommendation was the MAI episode in October 2023 (it had dropped from about $0.88 at the beginning of the month to $0.72). The source does not provide a complete protocol-wide history, so the number of times this happened for Gauntlet’s strategies is Not verifiable as of 2026-08-29. For context, depegs of major stablecoins are not rare in general: independent explainers note that stablecoins can deviate from peg for brief periods, and major events like USDC’s March 2023 move to about $0.87 or USDT’s May 2022 dip to about $0.945 have occurred in the market overall. But those market-wide events are not enough to confirm that Gauntlet’s own deployed stablecoin across Arbitrum, Base, Ethereum, and OP Mainnet experienced those specific depegs.

Evidence (3)

Risks & Strengths

risks

unverified

For Gauntlet, the top 5 protocol risks are: (1) model failure in tail events, where historical-simulation risk models misprice black-swan conditions and set unsafe parameters; (2) governance/centralization risk, because one firm can influence risk settings across multiple protocols and vaults; (3) smart-contract and integration risk, especially in the underlying lending/vault systems Gauntlet manages; (4) oracle/asset-price risk, where bad pricing or rapid volatility can trigger bad debt or incorrect liquidations; and (5) liquidity/liquidation risk, where thin markets, liquidator inaction, or cascading liquidations worsen insolvency outcomes. Gauntlet’s own materials emphasize collateral volatility, relative liquidity, protocol parameters, smart-contract risk, and network congestion as key drivers of insolvency risk in lending markets. Independent commentary also highlights concentration risk from a single risk manager across many vaults and protocols, plus potential governance conflicts of interest.

Evidence (6)

strengths

two sources

Gauntlet’s top strengths are: 1) simulation-driven risk modeling that stress-tests DeFi protocols under adverse market conditions; 2) quantitative optimization to tune parameters for safety, capital efficiency, and growth; 3) deep protocol credibility, reflected in work with major DeFi names such as Compound and Uniswap; 4) cross-chain operating scope across L1s and L2s, which supports multi-market analysis and deployment; and 5) productized risk management, including curated vaults that apply its research to allocation and yield management.

Evidence (3)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 16 two independent sources, 5 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-29.