DeFiPunk'd

StakeWise

2 deployments · $1.6B aggregate TVL · Liquid Staking

Deployments

Each deployment is rated independently. Pick one to see its rating, risk analysis, and stage.

TVL $931.2M
Type Liquid Staking
Chains Ethereum, xDai
View on DeFiLlama ↗
Control criteria
Upgradeability Mixed Bug bounty immunefi.com Governance forum Docs docs.stakewise.io
About

StakeWise V3 is a decentralized liquid staking protocol for Ethereum and Gnosis Chain that allows users to stake ETH or GNO and receive osETH or osGNO, over-collateralized liquid staking tokens, in return. The protocol introduces a marketplace of modular staking Vaults, where any node operator can deploy a Vault with customizable parameters (fee, MEV strategy, DVT setup), and any user can stake into their preferred Vault. osETH is backed by more than 1 ETH per token held in a Vault, providing embedded slashing protection and DeFi composability. The protocol uses a mix of upgradeable contracts (governed via dual governance for keeping up with Ethereum PoS spec changes) and immutable contracts prioritizing security and self-custody.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 62 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    Open source + 9 audits

    Protocol publishes a GitHub repository and has at least one audit on record. This is a coarse Phase-0 signal only: auditor reputation, scope, and post-audit review coverage are not yet weighted.

    Run your own prompt Submit run ↗
  2. Autonomy tentative
    Validator set reduces autonomy

    Liquid staking and restaking protocols hand solvency to an external validator set with slashing dynamics they do not control. At Phase 0 this is a category-level heuristic; a real Autonomy assessment (oracles, fallbacks, governance-mutable dependencies) arrives with onchain review.

    Run your own prompt Submit run ↗
3 dimensions not yet assessed (Control, Ability to exit, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

StakeWise V3 has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 62addresses
  • 0verified source
  • 0proxies

Control fetched 2026-09-03.

Ethereumadmin (CuratorsRegistry — DAO-approved allocation strategies)0xa23f…933cdiscoverygovernance
Ethereumadmin (NodesManager — delegates vault validator operations to registered node operators)0x5674…3592discoveryvault
Ethereumadmin (VaultsRegistry — canonical list of valid Vaults and approved implementations)0x3a00…c20ediscovery
Ethereumfactory (BlocklistErc20VaultFactory)0x39c6…a368discoveryfactory
Ethereumfactory (BlocklistVaultFactory)0x608d…f3b5discoveryfactory
Ethereumfactory (Erc20MetaVaultFactory)0x4e3d…90d0discoveryfactory
Ethereumfactory (Erc20VaultFactory)0x9779…0488discoveryfactory
Ethereumfactory (MetaVaultFactory — deploys MetaVaults that delegate to sub-vaults)0x76d9…8f14discoveryfactory
Ethereumfactory (PrivErc20MetaVaultFactory)0xe14f…9141discoveryfactory
Ethereumfactory (PrivErc20VaultFactory)0x1831…fdc9discoveryfactory
Ethereumfactory (PrivMetaVaultFactory)0x1e86…be66discoveryfactory
Ethereumfactory (PrivVaultFactory)0x4c95…f8fddiscoveryfactory
Ethereumfactory (RewardSplitterFactory)0xd12d…4775discoveryfactory
Ethereumfactory (SubVaultsRegistryFactory — deploys per-MetaVault registry)0x3cc1…17eediscoveryfactory
Ethereumfactory (VaultFactory — deploys standard ETH Vaults)0x7a8c…22dddiscoveryfactory
Ethereumoracle (Keeper — verifies oracle sigs, stores rewards Merkle root, approves validator registrations)0x6b58…87b5discoveryoracle
Ethereumoracle (PriceFeed — reports osToken exchange rate to external protocols like Aave)0x8023…e471discoveryoracle
Ethereumother (BalancedCurator — DAO-approved allocation strategy for MetaVaults)0xe013…4d90discoverygovernance
Ethereumother (ConsolidationsChecker — verifies oracle sigs for validator consolidations)0x033e…810fdiscoveryoracle
Ethereumother (DepositDataRegistry — stores deposit data root pre-approving validator keys)0x75ab…223ediscovery
Ethereumother (LegacyPoolEscrow — StakeWise V2 escrow for migration)0x2296…f079discovery
Ethereumother (MerkleDistributor — distributes extra token rewards to vault stakers)0xa9dc…8d34discoverytoken
Ethereumother (OsTokenConfig — per-vault LTV, liquidation threshold and bonus)0x287d…eb59discoveryvault
Ethereumother (OsTokenFlashLoans — uncollateralised same-tx osToken loans, capped 100k)0xebe1…f5d2discovery
Ethereumother (OsTokenRedeemer — osToken redemption queue for ETH)0xc43a…1fd0discovery
Ethereumother (OsTokenVaultController — tracks total osToken supply and sets exchange rate)0x2a26…0306discovery
Ethereumother (OsTokenVaultEscrow — holds osToken positions during vault exit)0x09e8…3605discoveryvault
Ethereumother (SharedMevEscrow — smoothing pool for participating vaults)0x4831…ff86discovery
Ethereumother (ValidatorsChecker — read-only helper for validator registration eligibility)0x508e…9906discovery
Ethereumtoken (LegacyRewardToken — StakeWise V2 reward token retained for migration)0x20bc…86c5discoverytoken
Ethereumtoken (osETH liquid staking token)0xf1c9…0e38discoverytoken
Ethereumvault (CommunityVault — partner-deployed vault)0x1546…ef4ddiscoveryvault
Ethereumvault (FoxVault — partner-deployed vault)0x4fef…47dfdiscoveryvault
Ethereumvault (GenesisVault — V2 migration vault)0xac0f…2885discoveryvault
xDaiadmin (CuratorsRegistry on Gnosis Chain)0xa23f…933cdiscovery
xDaiadmin (VaultsRegistry on Gnosis Chain)0x7d01…67cbdiscovery
xDaifactory (BlocklistErc20VaultFactory on Gnosis Chain)0x39c6…a368discoveryfactory
xDaifactory (BlocklistVaultFactory on Gnosis Chain)0x608d…f3b5discoveryfactory
xDaifactory (Erc20VaultFactory on Gnosis Chain)0x9779…0488discoveryfactory
xDaifactory (MetaVaultFactory on Gnosis Chain)0x75e6…5f1bdiscoveryfactory
xDaifactory (PrivErc20VaultFactory on Gnosis Chain)0x1831…fdc9discoveryfactory
xDaifactory (PrivVaultFactory on Gnosis Chain)0x4c95…f8fddiscoveryfactory
xDaifactory (RewardSplitterFactory on Gnosis Chain)0xd12d…4775discoveryfactory
xDaifactory (SubVaultsRegistryFactory on Gnosis Chain)0x37bf…891fdiscoveryfactory
xDaifactory (VaultFactory on Gnosis Chain)0x7a8c…22dddiscoveryfactory
xDaioracle (Keeper on Gnosis Chain)0xcac0…26aadiscoveryoracle
xDaioracle (PriceFeed on Gnosis Chain)0x9b1b…d272discoveryoracle
xDaiother (BalancedCurator on Gnosis Chain)0x5dd9…ab9ediscovery
xDaiother (ConsolidationsChecker on Gnosis Chain)0x033e…810fdiscovery
xDaiother (DepositDataRegistry on Gnosis Chain)0x58e1…9e16discovery
xDaiother (LegacyPoolEscrow on Gnosis Chain)0xfc9b…0394discovery
xDaiother (MerkleDistributor on Gnosis Chain)0xfbce…3710discovery
xDaiother (OsTokenConfig on Gnosis Chain)0xd667…c3ecdiscovery
xDaiother (OsTokenFlashLoans on Gnosis Chain)0xe841…bb11discovery
xDaiother (OsTokenRedeemer on Gnosis Chain)0xb790…86c4discovery
xDaiother (OsTokenVaultController on Gnosis Chain)0x60b2…179adiscovery
xDaiother (OsTokenVaultEscrow on Gnosis Chain)0x28f3…9e71discovery
xDaiother (SharedMevEscrow on Gnosis Chain)0x30db…488adiscovery
xDaiother (ValidatorsChecker on Gnosis Chain)0x8035…de86discovery
xDaitoken (LegacyRewardToken on Gnosis Chain)0x6ac7…31d4discoverytoken
xDaitoken (OsToken / osGNO on Gnosis Chain)0xf490…d1a0discoverytoken
xDaivault (GenesisVault on Gnosis Chain)0x4b44…0a7adiscoveryvault

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum
Twitter
@stakewise_io

Security

[:] Source: DEFI@home quorum
Audits
7 audits
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Voting token
osETH Ethereum: 0xf1C9acDc66974dFB6dEcB12aA385b9cD01190E38
Upgradeability
Mixed (some immutable, some upgradeable)

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-09-07 11:30 UTC