DeFiPunk'd

Centrifuge

2 deployments · $1.4B aggregate TVL · RWA

Deployments

Each deployment is rated independently. Pick one to see its rating, risk analysis, and stage.

TVL $1.4B
Type RWA
Chains Ethereum, Avalanche, Plume Mainnet, Pharos, Monad +5
View on DeFiLlama ↗
Control criteria
Upgradeability Immutable Bug bounty cantina.xyz Governance forum forum.centrifuge.io Docs docs.centrifuge.io
About

Centrifuge is a real-world asset (RWA) tokenization platform that enables asset managers to tokenize institutional-grade assets such as private credit, treasury funds, and structured vehicles into ERC-4626/ERC-7540 compliant vault tokens. Investors deposit into pools and receive liquid vault shares representing claims on the underlying assets, with real-time onchain NAV and reporting. The protocol operates on a hub-and-spoke architecture deployed across 9 EVM chains, with a Root contract enforcing a 48-hour timelock on all configuration changes and a Guardian multisig able to pause in emergencies.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 15 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 19 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
4 dimensions not yet assessed (Control, Ability to exit, Autonomy, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Autonomy unknown Unverified
    No Phase-0 autonomy signal

    Neither the category heuristic nor the forkedFrom signal fires for this protocol. A real autonomy graph (oracles, bridges, fallbacks, governance-mutable dependencies) arrives with Phase-2 onchain discovery.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  4. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Centrifuge Protocol has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 45addresses
  • 21verified source
  • 6proxies
  • 0of 2 owners are Safes

TVL adapter pinned at 683d369. Sourcecode fetched 2026-05-06. Control fetched 2026-05-07.

arbitrumPoolManager0x9180…9e29TVL
arbitrumSpoke0xd30d…fa2bTVL
arbitrumSpoke0xec35…25abTVL
arbitrumFiatTokenProxy0xaf88…5831TVLproxy0xc7a5…ebc9
Arbitrumguardian0xa36c…a433discoverymultisig
Arbitrumroot (48hr timelock)0x7ed4…368fdiscoverytimelock
Avalancheguardian0xb664…4185discoverymultisig
Avalancheroot (48hr timelock)0x7ed4…368fdiscoverytimelock
avaxSpoke0xd30d…fa2bTVL
avaxSpoke0xec35…25abTVL
avaxFiatTokenProxy0xb97e…8a6eTVLproxy
basePoolManager0x7f19…6994TVL
baseSpoke0xd30d…fa2bTVL
baseSpoke0xec35…25abTVL
baseFiatTokenProxy0x8335…2913TVLproxy
Baseguardian0x8b83…0d9bdiscoverymultisig
Baseroot (48hr timelock)0x7ed4…368fdiscoverytimelock
bscSpoke0xd30d…fa2bTVL
bscSpoke0xec35…25abTVL
bscBEP20UpgradeableProxy0x8ac7…580dTVLproxy
bscBEP20USDT0x55d3…7955TVL
BSCguardian0x5706…e445discoverymultisig
BSCroot (48hr timelock)0x7ed4…368fdiscoverytimelock
ethereumPoolManager0x9180…9e29TVL
ethereumSpoke0xd30d…fa2bTVL
ethereumSpoke0xec35…25abTVL
ethereumFiatTokenProxy0xa0b8…eb48TVLproxy0xfcb1…ae3a
Ethereumguardian0xd9d3…e7fddiscoverymultisig
Ethereumroot (48hr timelock)0x7ed4…368fdiscoverytimelock
HyperEVMroot (48hr timelock)0xdc94…235ediscoverytimelock
hyperliquid0x9fdb…3463TVL
hyperliquidTOKEN_FACTORY_V3_10xec35…25abTVL
hyperliquidUSDC0xb883…630fTVL
hyperliquidUSDT00xb8ce…5ebbTVL
monadTOKEN_FACTORY_V3_10xec35…25abTVL
monadUSDC0x7547…b603TVL
Monadroot (48hr timelock)0xdc94…235ediscoverytimelock
optimismSpoke0xec35…25abTVL
optimismFiatTokenProxy0x0b2c…ff85TVLproxy
Optimismroot (48hr timelock)0xdc94…235ediscoverytimelock
Plumeguardian0x2d44…5767discoverymultisig
Plumeroot (48hr timelock)0x7ed4…368fdiscoverytimelock
plume_mainnetTOKEN_FACTORY_V30xd30d…fa2bTVL
plume_mainnetTOKEN_FACTORY_V3_10xec35…25abTVL
plume_mainnetUSDC0x2223…a7afTVL

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@centrifuge
GitHub
centrifuge
Governance forum
https://forum.centrifuge.io

Security

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Audits
5 audits
Security contact
security@centrifuge.io

Technical

[:] Source: DEFI@home quorum
Voting token
CFG Ethereum: 0xcF5D2Aac8D1B29d8DF86d0dDCC52d63a4C95A52B
Upgradeability
Immutable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-06-01 11:27 UTC