Who accepts collateral
Anyone who has to decide what may be posted, and at what factor.
- Lending and money markets
- Perpetual and margin venues
- Curated and managed vault operators
- Stablecoin issuers accepting reserves
Structure, graded before it costs you anything. Every cross-chain asset rests on structural choices: how many independent parties must agree before new units appear, whether minting is capped, who can upgrade the contracts and how fast, and whether backing can be checked on chain. All readable in advance.
Every cross-chain asset rests on a few decisions somebody made once. How many organisations must agree before new units appear. Whether there is any ceiling on minting. Who can change the contracts, and how fast. Whether the backing is checkable on chain or only asserted. All of it is readable today, and Asset Ratings publishes the answer as a grade from F0, do not integrate, to F4, exemplary. The grade is a floor, not an average: certain structural failures cap it however well everything else scores. You inherit a small contract, set the floor you will accept, and add one line to the function that onboards collateral.
Five surfaces, named. Anything outside this list is not covered by this wall; the perimeter page says which one covers it.
Anyone who has to decide what may be posted, and at what factor.
Anyone who has to justify that decision afterwards.
Anyone who would rather be graded on the record than argued about on a forum.
Anyone carrying an asset somebody else built.
Public, dated and sourced. Open a row for what happened and for what would have caught or refused it.
The bridge required seven of ten multisig signers. The attacker obtained seven, and the bridge behaved exactly as configured. Most of what left was stablecoins, alongside 231 WBTC and 9,500 ETH, on New Year's Eve.
A threshold is only worth the number of genuinely separate organisations that have to agree to satisfy it. Counting keys and counting parties are different measurements, and a threshold no independent set can actually satisfy caps the floor outright.
Halborn on the Orbit Bridge hackThe protocol's multi-party computation nodes ran under the chief executive's personal cloud account. When he was detained in May, along with his devices and recovery phrases, nobody else could reach the servers. Unauthorised withdrawals began in July and the project ceased operations.
How many separate organisations must agree, and whether backing can be checked on chain at all, are structural questions the methodology asks before grading. Both are read from the deployment rather than from a disclosure. A design marketed as multi-party but operated by one person does not reach a floor you would accept.
Chainalysis on the Multichain exploitA former team member planted a malicious package that captured a deployer key on the next legitimate update. The token contract had no mint ceiling, so the key minted 20 trillion units and sold them into liquidity pools. The token fell 99.5 per cent in hours.
Whether minting is capped, and who can upgrade the contracts and how fast, are readable properties of a deployment rather than facts you learn afterwards. An unbounded mint reachable by one key is a fatal criterion: it caps the rating outright, and a floor enforced in your own onboarding function refuses the asset.
Ankr's own report on the aBNBc exploitThe bridge was, in effect, a two-of-five multisig: if any two of five addresses instructed it to move funds, it moved them. Two of those keys were obtained. No contract misbehaved and no signature was invalid. Afterwards the threshold was raised to four of five.
The important part is the date. That threshold was public, on chain and readable by anyone before the loss rather than after it. A minority of keyholders being able to move everything is a structural fact about how the asset was built, and it can be graded in advance and enforced by a gate in your own contract.
Halborn on the Harmony Horizon Bridge hackThe bridge required five of nine validators. Sky Mavis operated four, and an allowlist granted five months earlier, letting it also sign for the Axie DAO's validator, was never revoked. One organisation's access therefore reached the threshold on its own.
Nine keys, five signatures, one party. The measurement that matters is how many separate organisations those keys really represent, and a delegation that collapses a threshold is configuration drift the methodology re-measures on a schedule rather than reading once.
Halborn on the Ronin bridge hackShared substrate, not features of this wall. Every layer below is already paid for by the first wall in your scope.
Floors are floors, not averages. Certain structural failures cap a rating outright however well everything else scores. The methodology is public, run against real historical losses and against healthy assets that must not be flagged, with both misses and false flags published. Ratings expire, drift is watched, and issuers who disagree have a real appeals route.
Individually, or bundled with the walls beside it.
The full published methodology, the derivation behind every score, and drift monitoring across everything you depend on rather than only what you issue
The integrator floor API read at point of use, and a base contract you inherit so an asset below your floor cannot be onboarded as collateral
It gives Exposure Map the weights that make contagion realistic, because a structurally fragile asset propagates differently from a robust one. It gives Live Detection a reason to hold a tighter threshold where the structure is weaker. And it gives the whole perimeter the vocabulary risk committees already use.
Fuga Labs is read-and-attest, never custody-and-execute.
A scoping call maps this wall against what you run and says where it reaches and where it stops. Nothing is provisioned until that is agreed in writing.