Lulo

Orange · 41/100 Data confidence 90/100

Executive summary

Lulo is a Solana-based non-custodial yield aggregator and lending protocol that routes stablecoin deposits across third-party venues such as Morpho, Kamino, Maple, and Pendle, scoring 59/100 (orange band).

  • Security: Five independent audits (Certora, Halborn, OtterSec, Offside Labs, Sec3) identified and remediated critical vulnerabilities including oracle update failures, referral fee exploits, and withdrawal manipulation; no bug bounty program verified.
  • Governance & custody: Founder/company-controlled with no verified on-chain DAO or governance token; non-custodial model where users retain wallet control while smart contracts execute allocations. Specific admin keys, multisig setup, and upgrade authorities are not verifiable.
  • Top risks: (1) Third-party protocol failures in integrated venues can cascade to users despite coverage; (2) stablecoin depeg and Solana network outages explicitly excluded from protection; (3) smart-contract risk in Lulo's own allocation and coverage logic; (4) centralized operational control with no decentralized governance; (5) oracle and bad-debt risk in underlying protocols.
  • Strengths: Diversified multi-protocol routing with transparent on-chain allocations; built-in smart-contract-enforced protection for covered protocol failures in Protected tier; flexible risk tiers (Protected, Boost, Custom); backed by Circle Ventures and Solana Ventures.
  • Incidents: Audit-identified critical issues were remediated pre-launch; no live exploits, hacks, or fraud reported.
  • Unverified: No native governance token confirmed; treasury reserves, exact program IDs, admin multisig composition, and on-chain balances not independently verifiable as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 80 20.0 2 audit(s); no fresh audit; no qualifying bug bounty
incidents 25% 35 8.8 1 incident(s) in 730-day window, losses $0; 0 high/critical news
verifiability 15% 70 10.5 0 onchain, 13 two-source, 9 one-source of 25 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL unavailable; neutral context, not a safety signal
governance 10% 40 4.0 verified governance +20; timelock in governance +15; legal enforcement/sanction -30
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Lulo is a Solana-based DeFi lending/borrowing protocol with a focus on leveraged points farming. On-chain verification via Dune is not available in this run; all on-chain items are “Not verifiable as of 2026-08-29.” 1. Protocol identification

  • Name: Lulo
  • Website: lulo.fi
  • Docs: docs.lulo.fi (linked from main site and UI)
  • Category: Non-custodial lending/borrowing & leverage protocol on Solana, targeting points/airdrop farming.
  • Launch date: Public Solana mainnet launch is not clearly dated in independent sources; most coverage and docs activity appear in 2025. Not verifiable as of 2026-08-29 from independent time-stamped sources.
  • Chains: Solana only as per UI, docs, and third‑party analytics (e.g., DefiLlama lists Lulo only on Solana).
  • Native token: Several listings (DeFiLlama, aggregators) show a LULO token on Solana, but detailed tokenomics and confirmation of it as a *governance/utility* token come primarily from Lulo’s own docs → unverified marketing claim. 2. Main contract / program identification (Solana) Independent Solana explorers and aggregators reference a Lulo lending program but do not consistently expose a canonical “main program ID” with sufficient metadata, and without Dune or manual explorer navigation via tools this cannot be pinned down.
  • Canonical/primary program IDs, reserve accounts, or configuration addresses for Lulo on Solana: Not verifiable as of 2026-08-29.
  • Consequently, explorer verification status (upgraded / immutable / authority) is also Not verifiable as of 2026-08-29. 3. Fork lineage and code provenance
  • Several independent descriptions characterize Lulo as inspired by Solend / marginfi-style Solana lending markets, but none provide a clear, audited statement that Lulo is a direct code fork of a specific upstream repo with a diff.
  • GitHub and docs indicate custom logic for leveraged points/airdrop farming, rather than a 1:1 fork of an existing protocol; this is again primarily from Lulo’s own materials → unverified marketing claim.
  • No independent audit report explicitly documenting “fork from X with changes Y” was located on major auditors’ sites or GitHub. Not verifiable as of 2026-08-29.
  • No documented malicious-modification incidents in Lulo itself or in direct Lulo-branded forks were found in exploit reports, news, or audit advisories. Absence of evidence is not evidence of safety. Given the lack of Dune and limited independent forensic writeups, any precise contract-, diff-, or fork-level claims remain Not verifiable as of 2026-08-29.
Evidence (5)

maturity

unverified

Lulo appears to be a real, functional product rather than a pure landing page: its site exposes a developer-facing REST API, separate docs, and an integration guide describing deposit and withdrawal transaction generation, balance/rate queries, and API-key access. The docs also describe live user actions such as Protected deposits, Boost deposits, withdrawals, and reward claims in the app. I did not find verifiable evidence of broken links, fake metrics, or template-site signs in the retrieved material, but that absence is not proof of cleanliness; it is better stated as Not verifiable as of 2026-08-29. The same applies to checking whether the app’s deposit/withdraw flows are live end-to-end from raw on-chain behavior, because that cannot be verified here. On API maturity, Lulo clearly offers an open developer API: the docs and site explicitly say it provides RESTful endpoints for generating deposit and withdrawal transactions, fetching balances, and accessing rate data, with API-key authentication. That is a strong signal of a productized integration layer, not just marketing copy.

Evidence (8)

Security

audit

one source

Manual security audit of Lulo Rust smart contracts within the Solana ecosystem; report states it found critical vulnerabilities including oracle update failures, referral fee exploits, and withdrawal manipulation, and that these issues were subsequently addressed.

Auditor
Certora
Report Date
2025-01-23
Scope
Lulo Rust smart contracts on Solana runtime.
Evidence (2)

audit

one source

Initial Solana smart contract audit of Lulo Rust programs; reviewed versions at commit 781a0d3d7640207c324253bc15292abb690ea22d and excluded 3 instructions per team direction.

Auditor
Sec3
Report Date
2024-05-02
Scope
Lulo Solana smart contracts; 8 issues/questions reported: 2 Medium, 2 Low, 4 Info.
Evidence (1)

bug bounty

one source

I could not verify an active bug bounty program for Lulo from the available sources. The only Lulo-linked source I found was the project’s rewards documentation, which describes user rewards/airdrops, not a security bug bounty program. Because I could not confirm a program page on Immunefi, HackerOne, GitHub, or the protocol’s own security/docs pages in the provided results, the start date, scope/parameters, and results are Not verifiable as of 2026-08-29. If you want, I can do a narrower follow-up check focused on Lulo’s official security channels, GitHub, and bug-bounty platforms to confirm whether a program exists under a different naming convention or partner platform.

Evidence (2)

counterparty risks

two sources

Lulo’s core dependency is its routing into third-party DeFi protocols, so counterparty risk is mainly *composability risk* rather than reliance on a single venue. Its documented integrations include Kamino, Morpho, Maple, Pendle, Jupiter, and Neutrl, and earlier reviews also note prior routing through Drift, Marginfi, and Save; a failure at any integrated protocol can affect depositor funds. Lulo’s own docs say Protected deposits are designed to cover losses from smart contract exploits, oracle failures, and bad debt in integrated protocols, but not broader system risks such as Solana outages or stablecoin depegs. The main oracle/manipulation risk is therefore upstream: if an integrated lending venue uses faulty or manipulated price feeds, Lulo’s coverage is intended to absorb that protocol-level loss, but only within the stated protection scope. Certora’s audit report for Lulo specifically flagged issues including oracle update failures, showing that oracle handling has been an identified security concern in Lulo’s codebase, though the audit result is not the same as an observed exploit. On custody / bridge / CEX exposure, Lulo’s model appears to avoid direct custodial dependence on CEXs or bridges in the normal deposit flow; the user-facing risk is instead the solvency and security of the destination protocols on Solana and Ethereum. Because the protocol’s docs also state that it allocates across both Solana and Ethereum, any cross-chain exposure would be through the integrated venues themselves rather than through a separately disclosed bridge dependency. The clearest failure scenarios are: (1) exploit or bad debt at one integrated protocol, (2) oracle manipulation or feed malfunction at an integrated venue, (3) Solana network outage preventing execution, and (4) stablecoin depeg events outside the coverage perimeter. Anything beyond that, including exact exposure splits by protocol or chain, is Not verifiable as of 2026-08-30 from the available evidence.

Evidence (4)

crypto custody

one source

Lulo’s custody model is non-custodial: the protocol says it does not ever take custody, possession, or control of user digital assets, and users keep their assets in their own non-custodial wallet. Lulo also says it cannot recover or transfer assets if a user loses access to their wallet or private keys. The practical custody flow is that users connect a wallet, deposit supported stablecoins, and Lulo’s smart contracts route those funds into third-party DeFi protocols rather than holding them on Lulo’s balance sheet. For its Protected product, Lulo says the deposit allocation is spread across integrated protocols and that coverage is enforced at the smart-contract level, with no manual claims process; Boost deposits underwrite that protection and can carry first-loss risk. In short, the user keeps custody of the wallet, while Lulo’s contracts execute allocations and protection logic on-chain.

Evidence (4)

incident

two sources

Certora’s audit found critical issues in Lulo’s Rust programs—specifically oracle update failures, referral fee logic, and withdrawal mechanics—but the sources provided do not show that these became a live incident, nor do they quantify any loss, affected users, reimbursement, or incident response.

Date
2025-01-23
Cause
smart_contract_exploit
Loss Usd
None
Evidence (2)

key management

one source

Lulo’s key management is organized around developer API keys rather than user-managed wallet keys. Its API documentation says all API requests require a valid API key, which can be created and managed through the developer dashboard, and the docs point developers to the dashboard for authentication and key management. For end users, Lulo’s web/app flow emphasizes social login, two-factor authentication, and passkeys instead of seed phrases or direct wallet setup, indicating that account access is abstracted away from raw private-key handling at the user interface layer. From the available sources, the only clearly documented key-related control is the API-key access model for integrations; details such as private-key custody, HSM use, multisig governance, or admin key rotation are Not verifiable as of 2026-08-29.

Evidence (4)

smart-contract

one source

Lulo is a Solana protocol, so contracts are programs (no EVM proxies) and admin logic is implemented through program authorities and upgrade keys rather than proxy admin contracts. On‑chain verification via Dune is Not verifiable as of 2026‑08‑29. ### 1. Core contracts & deployment Public documentation and explorers show Lulo as a Solana lending protocol, but concrete program IDs for core logic (markets, risk engine, liquidation, oracle adapters) are not consistently documented across independent sources. Because of this, the exact list of:

  • Program addresses
  • Whether they are upgradable via the Solana BPF upgradeable loader
  • Current upgrade authority is Not verifiable as of 2026‑08‑29 without direct on‑chain tools. ### 2. Admin / owner / emergency roles Typical Solana DeFi patterns (inference, not protocol‑specific):
  • One or more upgrade authorities control redeployments of programs (equivalent to upgrade admin in EVM).
  • Each market/program usually has a config authority that can change parameters (LTVs, caps, fees, oracles).
  • Emergency powers often include pause/disable new borrowing, adjust collateral factors, and close markets; these are implemented as instruction handlers gated by a “governance” or “admin” PDA. For Lulo specifically, concrete role addresses, whether governed by a multisig vs EOAs, and any renounce/transfer events are Not verifiable as of 2026‑08‑29. ### 3. Upgradeability, pause & exits Absent hard data, risk assessment must assume:
  • Programs are upgradable unless explicitly redeployed under immutable loader and documented otherwise.
  • Admins can, in principle, change logic to affect:
  • interest/fee parameters
  • oracle sources
  • liquidation rules
  • pause of new actions (deposits/borrows)
  • Whether users can always withdraw when paused (common in well‑designed Solana protocols) is Not verifiable as of 2026‑08‑29. ### 4. Worst‑case with compromised keys If upgrade or config authorities are compromised on Solana:
  • Attacker can deploy malicious program code that steals deposits or blocks withdrawals.
  • Attacker can modify risk and oracle settings to force liquidations or misprice assets.
  • Attacker can change fee parameters to confiscatory levels. Given the lack of visible timelock or on‑chain governance guarantees, institutional assessment should treat Lulo as having full admin / upgrade key risk until proven otherwise: rug/freeze risk is non‑zero and cannot be quantitatively bounded from available data. Architecture diagram:
  • Users → client → Lulo front‑endSolana programs (markets, risk, oracles)upgrade & config authorities (multisig or EOAs, unknown). Granular mapping of each contract, role, and timelock delay remains Not verifiable as of 2026‑08‑29.
Evidence (2)

Live security feed

No verified protocol news in the last 12 months.

Team & Reputation

founders

two sources

Lulo appears to be a real, venture-backed, U.S.-based DeFi business on Solana with a fully public founding team, not an anonymous web-only project. ### Founders & team

  • Founders: Multiple independent sources identify Daniel Garay and Jesse Brauner as Lulo’s co-founders.
  • TechCrunch lists Lulo as a DeFi lending infrastructure / order book for loans, founded by Garay and Brauner.
  • Caplight profiles Lulo’s founding team as Daniel Garay (CEO & Co‑Founder) and Jesse Brauner (Co‑Founder & CTO).
  • Both maintain public LinkedIn profiles stating their Lulo roles; Garay as CEO & Co‑Founder since 2022, based in Miami; Brauner as Co‑Founder & CTO since 2022.
  • Public vs. anon: The core founders are clearly public, doxxed individuals with work history, locations and photos on LinkedIn and third‑party data platforms.
  • Team size: Third‑party company data (AIFI Map, Caplight, PitchBook) describe Lulo as having roughly 1–10 employees and being an early‑stage private company. ### Prior projects, track record, hacks
  • Public profiles for Garay and Brauner indicate prior experience in tech/finance roles, but no widely reported prior DeFi protocol hacks or blow‑ups are associated with their names.
  • No credible sources report security incidents or hacks involving Lulo as of the latest indexed data. Not verifiable as of 2026‑08‑29. ### Legal entity, office, onshore/offshore
  • Multiple data providers list Lulo as a U.S. company:
  • Caplight and PitchBook: Headquartered in San Francisco, California, founded in 2022, operating in crypto/Web3 / other financial services.
  • LinkedIn company page lists locations in Miami, FL (HQ) and Cheyenne, Wyoming, suggesting U.S. corporate registration and operations.
  • These point to Lulo being onshore U.S.‑based, with operations in California, Florida, and possibly Wyoming; however, the exact legal entity name and filing details are Not verifiable as of 2026‑08‑29. ### Funding & institutional backing
  • PitchBook reports Lulo raised about $350k via an accelerator/incubator round with investors including Alliance DAO, Castle Island Ventures, Circle Ventures, GoldenTree Asset Management, ParaFi Capital, and others.
  • AIFI Map similarly reports $350k from Circle Ventures, Alliance, Castle Island, GoldenTree, Gami Capital, reinforcing that institutional funds have diligenced and backed the team. ### Reality check: business vs. web front
  • Presence across PitchBook, Caplight, TechCrunch, Solana ecosystem media, LinkedIn company + employees, and investor listings strongly indicates a real operating business, not just a front website.
  • The protocol’s own marketing claims about product design and risk controls should be treated as unverified marketing claims unless confirmed by independent technical review. Not verifiable as of 2026‑08‑29.
Evidence (15)

general reputation

two sources

Lulo currently has a moderately positive reputation as a Solana-based yield/lending aggregator with multiple independent audits and notable venture backing; no public fraud, rug, insolvency, or regulatory actions are reported as of 2026‑08‑29. Founders / team / investors

  • Lulo is described as a Solana-native DeFi savings / yield aggregator (formerly FlexLend), launched in early 2024 and founded in 2022.
  • An independent investigation notes backing from Circle Ventures and Solana Ventures, indicating institutional-level investor confidence.
  • Several ecosystem reviews (Solana Compass, CryptoSkills, SOL Skills, IvyOracle, MEXC News) cover Lulo neutrally or positively, suggesting it is regarded as a legitimate Solana DeFi project rather than a fringe fork. Audits / security reputation
  • Lulo states its smart contracts have been independently audited five times, naming Certora, Halborn, OtterSec, Offside Labs, and Sec3, with public reports.
  • Protocol documentation shows at least one classic audit report (May 2024) available.
  • A third‑party rubric-based review (Crypto Almanac Daily) records 2 audits with linked reports and flags audit documentation as “Met”, reinforcing that external audit reports are accessible and verifiable.
  • Lulo markets “Protected deposits” with integrated coverage; this is a design feature, not a guarantee of safety, but signals a risk-focused positioning. Sentiment and usage
  • Ecosystem and review articles describe Lulo as a “next‑generation yield aggregator” that simplifies stablecoin yields, generally in positive/neutral terms.
  • Coverage highlights non‑custodial design and real‑time compounding yields, often comparing favorably to bank savings rates, reflecting retail‑friendly sentiment.
  • One independent investigation notes growth to $53–86m+ TVL and $100m+ cumulative deposits (range across sources), portraying Lulo as a mid‑tier but growing Solana DeFi protocol. Criticisms, risk framing, and unresolved concerns
  • The main criticism in independent analysis is composability risk: Lulo routes funds into multiple underlying protocols (Kamino, Drift, MarginFi, Morpho, Maple, Pendle, etc.), so failures at those venues can impact Lulo users.
  • Reviews emphasize that “Protected” coverage is still constrained by smart contract logic and underlying protocol events, not traditional insurance. This is a structural risk, not a specific incident.
  • No credible sources report fraud, rugpulls, insolvency events, sanctions, or enforcement actions related to Lulo as of 2026‑08‑29. Not verifiable as of 2026‑08‑29 for detailed founder identity checks, full cap table, or internal risk controls. Reputation summary for institutional risk
  • Positives: multi‑audit coverage by recognized firms; backing from Circle Ventures/Solana Ventures; non‑custodial architecture; generally favorable ecosystem sentiment.
  • Structural concerns: dependence on multiple third‑party protocols; marketing-heavy yield messaging; limited publicly verifiable detail on governance, operational controls, and regulatory posture. Not verifiable as of 2026‑08‑29 whether formal regulatory licenses or jurisdictional registrations exist.
Evidence (15)

Economy

model

two sources

Lulo is a Solana-based lending/yield aggregator that routes primarily stablecoin deposits into multiple underlying DeFi protocols, with an embedded coverage layer that creates two main risk tranches (Protected vs Boosted). ### Strategy & Assets

  • Core strategy: Allocate deposits across integrated Solana and some Ethereum protocols (Kamino, Drift, MarginFi, Jupiter; plus Morpho, Maple, Pendle, Neutrl).
  • Assets in: Mainly stablecoins (USDC, USDT, USDS, PYUSD) plus SOL, LSTs (bSOL, JitoSOL, mSOL) and selected tokens (BONK, JUP, ORCA, COPE, CASH).
  • Assets out: Users hold Lulo positions that represent diversified exposure to underlying lending/yield venues, not a separate governance token. ### Yield Source & Risk Profile
  • Organic vs subsidized: Yield is primarily organic lending/borrowing yield from integrated protocols; no material ongoing emissions program is described.
  • Market-neutral vs directional:
  • Stablecoin strategies are largely market-neutral, earning borrow/lending/APR and points-type incentives.
  • SOL/LST and token strategies add directional price risk of the underlying assets.
  • Leverage/looping/external exposure: Lulo does not itself create leverage; it routes deposits into third-party protocols that may use leverage (e.g., Drift, Kamino vaults), so users have composability-layer exposure to those venues. ### Tranches, Coverage & Mechanics
  • Protected deposits: Lower yield, principal coverage against specified failures (exploits, oracle issues, bad debt) at covered protocols via an on-chain coverage pool.
  • Boosted deposits: Higher yield; depositors effectively underwrite Protected users, earning extra yield in exchange for taking first-loss risk.
  • Custom deposits: Users select exact protocols and risk mix.
  • Lock-ups & withdrawals: Public sources describe Lulo as a savings/yield product with flexible deposits; no hard lock-ups are mentioned, withdrawals depend on underlying venue liquidity. ### Fees, Limits & Revenue
  • Protocol fees: Detailed fee schedule is not publicly broken out; Lulo likely earns a spread or performance/management fee on routed yield, but this is an unverified marketing claim when sourced only from Lulo docs.
  • Minimum deposits: Around $100 for stablecoins and 1 SOL for native deposits. ### Collateral, TVL & APY
  • Collateral: User deposits in the assets above; no separate collateral token.
  • TVL level & trend:
  • DefiLlama lists Lulo as a lending aggregator on Solana with tens of millions in TVL; exact figure and trend are Not verifiable as of 2026-08-30 without on-chain queries.
  • Independent reviews cite $53–86M TVL and >$100M cumulative deposits, but these are aggregator/media estimates, not on-chain verified.
  • APY history/volatility: APYs track underlying protocol yields; sources indicate stable but protocol-dependent rates, with Protected lower and Boosted higher, but no full historical time series is available: Not verifiable as of 2026-08-30.
Evidence (11)

reserves

two sources

Lulo’s treasury/reserves are not fully verifiable from the provided web results, and I cannot confirm any on-chain treasury wallet balances or a treasury policy from raw chain data because Dune is unavailable in this run. The only reserve-related item I could verify is that Lulo has a reserve-backed product structure for JupUSD: SolanaCompass reports the reserve allocation as 90% USDtb and 10% USDC, with custody handled by Anchorage Digital’s Porto and the reserves described as verifiable on-chain. For Lulo’s broader protocol treasury, reserve size, wallet addresses, custody setup, control keys, composition, and attestations, the available sources do not provide enough independently verifiable detail, so those items are Not verifiable as of 2026-08-29. What the web does show is that Lulo is a Solana yield aggregator with user deposits routed into external lending venues such as Kamino, Drift, Save, and MarginFi; this describes deposit deployment rather than a protocol-owned treasury. DefiLlama reports Lulo TVL on Solana at $78.31m, but that is user TVL, not a protocol reserve balance.

  • Reserve size: Not verifiable as of 2026-08-29.
  • Addresses: Not verifiable as of 2026-08-29.
  • Composition: Only the JupUSD reserve split is published externally: 90% USDtb / 10% USDC.
  • Custody: Anchorage Digital Porto for JupUSD reserves.
  • On-chain balances via Dune: Not verifiable as of 2026-08-29.
  • Control / multisig / signers: Not verifiable as of 2026-08-29.
  • Reserve policy: Not verifiable for Lulo’s general treasury; JupUSD has a published reserve-allocation policy.
  • Attestations: JupUSD reserves are described as verifiable on-chain, but no independent attestation report was found in the provided results.
Evidence (3)

tokenomics

two sources

Lulo currently does not appear to have a live, tradable native token on Solana. All tokenomics items below are therefore “Not verifiable as of 2026-08-29” unless explicitly stated otherwise. ### 1. Existence of a native token

  • Lulo’s site and docs describe it as a Solana yield and liquidity routing protocol but do not present any token page, ticker, or contract address on Solana.
  • Major aggregators (CoinGecko, CoinMarketCap, DefiLlama) have no listing for a “Lulo” protocol token on Solana as of the current date.
  • No Solana explorer records could be reliably matched to an official “Lulo” SPL token via the project’s own docs or reputable listings. Conclusion: As of the latest available information, Lulo operates without a confirmed native token. Any future token plans mentioned in community channels would be treated as unverified marketing claims. ### 2. Token basics (name/ticker, address, supply, market cap)
  • Native token name/ticker: Not verifiable as of 2026-08-29.
  • Contract address (Solana SPL): Not verifiable as of 2026-08-29.
  • Total vs. circulating supply: Not verifiable as of 2026-08-29.
  • Market cap and FDV: No listing on major data sites; Not verifiable as of 2026-08-29. ### 3. Token utility, governance, and value accrual
  • No governance token or fee/revenue-share tokenomics are described in public docs tied to a concrete token contract.
  • Revenue share, buybacks, burns, staking rewards, and fee-switch mechanics cannot be evaluated without a token; Not verifiable as of 2026-08-29. ### 4. Emissions and unlocks
  • Emissions schedule, unlock schedule, and on-chain verification of unlocks: Not verifiable as of 2026-08-29. ### 5. Allocations and insider concentration
  • Team/investor/treasury/community allocations: Not verifiable as of 2026-08-29.
  • Top-holder concentration and insider wallets (team, investors, multisig) for a native token: Not verifiable as of 2026-08-29. ### 6. Control functions
  • Mint, blacklist, and fee-switch functions for a Lulo token contract and who controls them: Not verifiable as of 2026-08-29. ### 7. DEX liquidity and listings
  • No credible DEX pools (e.g., Orca, Raydium, Phoenix) could be linked to an official Lulo token via the project’s own docs or recognized aggregators.
  • DEX liquidity depth and main listings: Not verifiable as of 2026-08-29. From a risk perspective, treat Lulo currently as a non-token protocol on Solana, with no on-chain tokenomics to analyze yet. Any private or future-token references should be flagged as *unverified marketing claims* until a canonical SPL token and supporting data are published and independently confirmable.
Evidence (4)

Stress scenarios

stress scenario - bitcoin price falls below $10000

one source

A Bitcoin drop below $10,000 would *not* directly trigger a documented Lulo-specific loss mechanism, because Lulo’s published coverage is limited to losses inside its integrated protocols, not external market price crashes or stablecoin depegs. Lulo says Protected deposits are covered for smart contract exploits, oracle failures, and bad debt in integrated protocols, while protection explicitly does *not* extend to stablecoin depegging, Solana/Ethereum network outages, regulatory action, or Lulo’s own contract vulnerabilities. For this stress scenario, the main transmission channel would be *indirect*: a BTC crash could drive broader crypto stress, which may increase the chance of bad debt, exploit-driven losses, or liquidity stress in the lending venues Lulo routes capital to. However, the available sources do not provide a quantified scenario analysis showing how Lulo’s Protected or Boost tiers would perform specifically if BTC fell below $10,000. So the risk view is:

  • Direct BTC price risk to Lulo principal: Not covered by the published protection terms.
  • Indirect protocol risk via stress in integrated venues: Possible, but not quantitatively verifiable from the available sources.
  • Stablecoin depeg risk in a severe crypto drawdown: Explicitly not covered. Lulo’s own materials describe the product as diversified exposure across protocols like Morpho, Kamino, Maple, and Pendle, with automatic coverage for specified covered events, but that is a general product description rather than a BTC-tail stress test.
Evidence (3)

stress scenario - largest collateral depegs 20%,

two sources

Lulo’s own documentation says its coverage does not extend to stablecoin depegging events; therefore, under a 20% depeg of the largest collateral, losses would not be auto-compensated by Lulo’s protection mechanism. In practical terms, the stressed asset would be exposed to the depeg directly, while Lulo’s “Protected” feature only targets losses from covered integrated-protocol failures such as exploits, oracle failures, or bad debt. Because the question asks for a collateral-depeg stress scenario, the key finding is that the impact depends on which deposited asset depegs and how much of user balances are held in that asset, but the platform itself explicitly excludes this risk from coverage. Lulo is a Solana yield aggregator that routes deposits across third-party lending venues, so depeg losses would propagate through the underlying stablecoin exposure rather than through a compensable protocol-failure event. The exact dollar loss from a 20% depeg is Not verifiable as of 2026-08-29 from the provided sources, because no on-chain position breakdown or live collateral composition was available in the search results.

Evidence (3)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

Lulo is a Solana-based yield protocol focused on tokenized RWAs and yield products; detailed on-chain exposure by counterparty is Not verifiable as of 2026-08-30. Below is a generic institutional stress-path for “top counterparty insolvent” applied to Lulo’s stated model (RWA / yield strategies on Solana), not on-chain verified and subject to protocol-specific design. ### 1. Expected loss path

  • Trigger: Top RWA issuer / borrower / off-chain yield provider defaults or is insolvent.
  • Asset impact:
  • Tokenized RWA or vault token backing Lulo positions becomes impaired (NAV markdown, write-off, or frozen redemption).
  • On-chain, this appears as sharp price drop or oracle failure for the affected asset used in Lulo pools or strategies.
  • Protocol-level impact:
  • Lending pools: collateral values collapse; some positions become undercollateralized and cannot be fully liquidated.
  • Structured products/vaults: share price falls; accrued yield disappears; redemptions may halt pending off-chain resolution. ### 2. Who absorbs losses
  • First loss: Lulo users directly exposed to the insolvent counterparty’s instrument (depositors in that pool/vault, holders of the impacted token).
  • Second layer: junior / subordinated tranches, if Lulo uses tranching or overcollateralization structures.
  • Protocol/Treasury:
  • If Lulo advertises insurance, safety modules, or treasury backstops, these may be tapped to partially compensate users (unverified marketing claim).
  • If no explicit backstop, protocol absorbs only reputational/fee-revenue loss; economic loss stays with users. ### 3. Compensation
  • On-chain: Automatic only if there is a coded insurance or reserve module funded in advance.
  • Off-chain: Any real-world legal claim (e.g., against issuer, custodian, arranger) is processed via courts or arbitration; proceeds, if any, may later be bridged on-chain to compensate affected token holders. ### 4. Impact path through smart contracts
  • Oracles: Price/oracle updates reflect impairment → collateral value falls → liquidation logic triggers for affected positions.
  • Liquidations: Bots attempt to liquidate, but auctions/AMM trades may realize large haircuts; bad debt remains if collateral < debt.
  • Bad debt handling:
  • Some protocols socialize shortfalls across lenders in that pool via reduced claim per share.
  • If Lulo has per-pool accounting, contagion is contained to the affected pool; other pools are spared.
  • Systemic spillover: If Lulo’s tokens are widely used as collateral on Solana (e.g., other money markets, leverage protocols), their price collapse propagates risk across the ecosystem. Because Dune MCP is unavailable and no independent on-chain mapping of Lulo’s counterparty tree is accessible, exact counterparties, exposures, and backstops are Not verifiable as of 2026-08-30.
Evidence (2)

stress scenario - committed fraud by the DAO or owners

two sources

For the stress scenario “committed fraud by the DAO or owners”, I found no verifiable evidence that Lulo’s DAO or owners committed fraud. The available materials instead describe Lulo as a Solana yield aggregator and discuss security audits and a separate exploit affecting a *LULA token* on BSC, which is not the same thing as proven DAO/owner fraud at Lulo. The audit report does document technical vulnerabilities in Lulo-related smart-contract logic, which indicates security risk, but a vulnerability is not evidence of intentional fraud by the DAO or owners. What can be said with confidence is limited to: Lulo has had security review findings, and an external investigation page claims it is backed by audits and investors, but that page is not proof of fraud or innocence. The search results do not provide court filings, regulator actions, governance votes, or credible investigative reporting establishing intentional misappropriation, insider theft, or other fraudulent conduct by the DAO/owners. Verdict for this stress case: Not verifiable as of 2026-08-29.

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

In a stress scenario where Lulo’s primary yield source is negative over the last 30 days, the protocol’s user-facing return would likely compress sharply, and a negative gross source yield would be *more severe* for the higher-risk / boosted tier than for protected deposits. Lulo is described as a yield router on Solana that routes stablecoin deposits into underlying lending markets, and its returns depend on those external borrowing/lending rates rather than on native yield generation. The main risk implication is straightforward: if the dominant underlying venue or basket of venues produces negative 30d yield after fees, bad debt, incentive decay, or adverse market conditions, Lulo’s net APY can fall below zero unless offset by other sources in the routing set. Because Lulo’s model aggregates third-party lending protocols, the stress event is not isolated to Lulo’s UI layer; it transmits through to depositor returns at the source level. Public descriptions also indicate that Lulo offers protected and boost styles of exposure, where protected users accept lower yield in exchange for smarter routing and protocol-level coverage, while boost users take first-loss risk for higher yield. Under a negative-yield shock, protected balances would still face lower realized earnings, but boost balances would be the first layer exposed to losses if the underlying protection or reserve mechanics are insufficient. What I can verify from the web is limited: independent pages confirm Lulo’s Solana yield-routing design and its protected/boosted structure, but I cannot verify on-chain 30d source performance here. Not verifiable as of 2026-08-29: the exact primary yield source, its 30d return, and whether it is negative at the protocol level.

Evidence (7)

Governance & Legal

governance

two sources

Lulo appears to be founder/company-controlled, with only symbolic DAO-style elements so far; detailed on-chain governance, voting concentration, and multisig specifics are largely Not verifiable as of 2026-08-29. ### 1. Who controls development, contracts, frontend, funds

  • Lulo is a Solana-based lending/borrowing protocol focused on undercollateralized and yield-backed loans.
  • Publicly available materials and listings (e.g., Solana ecosystem, Medium/announcement-style posts) consistently describe Lulo as a team-driven early-stage protocol, not a mature on-chain DAO with formal governance contracts.
  • There is no independently documented governance contract, admin timelock, or DAO controller for the core program on Solana in major analytics/explorer overviews.
  • On-chain admin structure for the Solana program is Not verifiable as of 2026-08-29.
  • Control of frontend and infra is described as operated by the Lulo team/company, with no evidence of decentralized hosting or community-controlled frontends. ### 2. Governance / DAO structure
  • No credible independent source (audits, governance forums, DeFi analytics) documents a live Lulo DAO, proposal process, or on-chain voting module.
  • Governance is therefore best characterized as off-chain, team-led product decision-making, with users having at most informal input via community channels (Discord/Twitter etc.).
  • Any references on the official site to “community” or “future governance tokens” are unverified marketing claims unless backed elsewhere. ### 3. Voting concentration & top holders
  • Lulo does not have a widely listed governance token with established DeFi analytics coverage; no DeFiLlama/Token Terminal governance metrics are available.
  • Token holder distribution, voting power, and concentration via Dune or equivalent on-chain analytics are Not verifiable as of 2026-08-29. ### 4. Timelock, multisig, signers, powers
  • No independent audit reports or explorer writeups detailing:
  • Admin multisig address, signer identities, or threshold.
  • Timelock parameters or upgrade delay.
  • Explicit scopes (ability to pause, change parameters, or upgrade programs).
  • All of the above are Not verifiable as of 2026-08-29 from third-party sources. ### 5. Legal entity, jurisdiction, ToS
  • There is no clear public record (company registries, legal filings, ToS hosted outside lulo.fi) tying Lulo to a specific incorporated entity, jurisdiction, registration number, or directors.
  • Any such claims appearing only on lulo.fi are unverified marketing claims.
Evidence (3)

legal & regulatory

unverified

Lulo appears to be a Solana-based yield / restaking protocol with an app at lulo.fi; however, its legal, regulatory and corporate information is extremely sparse and largely Not verifiable as of 2026‑08‑30 beyond marketing materials. 1. Entity / jurisdiction & legal structure

  • Publicly available sources do not clearly identify a registered legal entity, jurisdiction of incorporation, or company number linked to Lulo.
  • No independent filings (company registries, regulator databases) are easily traceable to “Lulo” in connection with the lulo.fi domain or Solana protocol.
  • Therefore, the operating entity, jurisdiction, and legal structure (DAO vs company) are Not verifiable as of 2026‑08‑30. 2. Terms of Service / user restrictions
  • The main site and app pages indexed by search do not prominently display a detailed Terms of Service, User Agreement, or explicit risk / eligibility disclosures beyond standard marketing copy.
  • No clear country‑based restrictions (e.g., US persons, sanctioned jurisdictions) are visible in public materials.
  • Result: ToS, user eligibility and geographic restrictions are Not verifiable as of 2026‑08‑30. 3. KYC / AML & compliance posture
  • Lulo presents itself as a non‑custodial DeFi app; there is no public indication that it performs KYC/AML onboarding or uses regulated VASP infrastructure.
  • No references to travel rule compliance, KYT monitoring providers, or AML policy documents are found.
  • This suggests no visible KYC/AML framework, but this cannot be fully confirmed without internal documentation; thus details are Not verifiable as of 2026‑08‑30. 4. Regulatory classification & licensing
  • No evidence in public records that Lulo or its operators hold securities, derivatives, broker‑dealer, or asset‑management licenses in major jurisdictions.
  • No formal classification (e.g., staking service, investment product, collective investment scheme) from any regulator is found. 5. Warnings, enforcement, court cases, sanctions
  • Searches do not surface regulatory warnings, enforcement actions, sanctions listings, or court cases explicitly naming Lulo or lulo.fi.
  • Absence of hits is *not* proof of regulatory comfort; it only means no public action is traceable as of 2026‑08‑30. 6. Data protection & privacy
  • No standalone privacy policy or data‑protection statement (GDPR, CCPA) is clearly indexed.
  • Therefore, how user data (web analytics, wallets, IPs) is processed is Not verifiable as of 2026‑08‑30. Risk takeaway for an institutional user
  • You are interacting with a largely opaque legal structure with no verifiable compliance, ToS or privacy framework, and no visible licensing.
  • For institutional use, this implies elevated counterparty, regulatory and operational risk, particularly regarding classification of yields/staking, consumer protection, and recourse in case of disputes or losses.
Evidence (1)

Stability

stability

two sources

Not verifiable as of 2026-08-29 from the available web results. The only protocol-specific source says Lulo’s coverage does not extend to stablecoin depegging events, but it does not identify which stablecoin(s) Lulo used, nor provide an incident history, count, or last depeg magnitude. Available third-party results only show generic stablecoin depeg histories and a Lulo marketing/article mention that Lulo offers yield on USDC; that is insufficient to confirm whether Lulo’s specific stablecoin ever depegged, how many times, or by what percentage. If you want, I can next verify the exact stablecoin(s) Lulo supports and then check whether those assets have documented depegs.

Evidence (3)

Risks & Strengths

risks

one source

Lulo’s top 5 risks are: (1) composability / third-party protocol risk, because Lulo routes deposits into external venues such as Morpho, Kamino, Maple, Pendle, Jupiter, and Neutrl, so a failure in any integrated protocol can affect users; (2) smart-contract risk at Lulo itself, since the product depends on its own allocation and coverage contracts, and the site explicitly says coverage is enforced by smart contract rather than by a manual process; (3) oracle and bad-debt risk, which Lulo itself names as covered failure modes for integrated protocols and which can still create losses or trigger coverage events; (4) systemic / chain-level risk, because Lulo states its coverage does not extend to Solana network outages or stablecoin depegging events; and (5) governance / operational centralization risk, since the available materials show no token-based decentralized governance and the protocol’s risk analyses flag centralized team control and dependency on ongoing protocol operations. One important nuance: Lulo’s “Protected” product is designed to absorb certain losses from covered integrated-protocol failures, but that does not eliminate all risk; it mainly shifts the residual exposure toward Lulo’s own coverage mechanism, uncovered systemic events, and operational dependence on the team.

Evidence (5)

strengths

unverified

Lulo’s top strengths are: 1) systematic yield allocation across leading stablecoin venues based on TVL and rates, which reduces manual venue-picking; 2) built-in protection for its Protected product, with smart-contract-level coverage designed to handle a total loss in a covered protocol; 3) transparent, on-chain verifiability, since positions, allocations, and coverage mechanics are documented as independently checkable; 4) diversified multi-protocol access to venues such as Morpho, Kamino, Maple, Pendle, Jupiter, and Neutrl, reducing single-venue dependence; and 5) flexible risk tiers and controls, including Protected, Boost, and Custom Deposits for different yield/risk preferences. Additional practical strengths noted in the documentation are that funds are deployed directly into underlying protocols rather than being held in a large intermediary pool, and that allocation can shift as rates change, which supports active optimization of risk-adjusted yield. One important caveat: the public materials are the protocol’s own docs, so these are best treated as unverified marketing claims unless independently cross-checked. Not verifiable as of 2026-08-29.

Evidence (4)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 13 two independent sources, 9 one source, 3 unverified.
  • Oldest fact verification date: 2026-08-29.