Skip to content
Wall 04 Certify

Asset Ratings

Structure, graded before it costs you anything. Every cross-chain asset rests on structural choices: how many independent parties must agree before new units appear, whether minting is capped, who can upgrade the contracts and how fast, and whether backing can be checked on chain. All readable in advance.

Wall04 of 05Watches5 surfacesBuilt for4 groupsLosses answered5Refuses a transactionThrough Live Detection

How it works.

Every cross-chain asset rests on a few decisions somebody made once. How many organisations must agree before new units appear. Whether there is any ceiling on minting. Who can change the contracts, and how fast. Whether the backing is checkable on chain or only asserted. All of it is readable today, and Asset Ratings publishes the answer as a grade from F0, do not integrate, to F4, exemplary. The grade is a floor, not an average: certain structural failures cap it however well everything else scores. You inherit a small contract, set the floor you will accept, and add one line to the function that onboards collateral.

  • Public methodology
  • A floor, not an average
  • Watched for drift
  • Enforced at onboarding

What it actually looks at.

Five surfaces, named. Anything outside this list is not covered by this wall; the perimeter page says which one covers it.

How many separate organisations must agree before new units appear, which is not the same as how many keys exist
Whether minting is capped at all, and who can lift the cap
Who can change the contracts, and how quickly a change can take effect
Whether the backing can be verified on chain by anyone, or only claimed in a document
Drift: the day something you depend on falls below the level you accepted it at, rather than the day of your next review

Who it is for.

Who accepts collateral

Anyone who has to decide what may be posted, and at what factor.

  • Lending and money markets
  • Perpetual and margin venues
  • Curated and managed vault operators
  • Stablecoin issuers accepting reserves

Who signs off

Anyone who has to justify that decision afterwards.

  • DAO risk committees
  • Collateral working groups
  • Underwriters and insurers
  • Treasury and investment committees

Who issues the asset

Anyone who would rather be graded on the record than argued about on a forum.

  • Bridges and message layers
  • Wrapped and bridged asset issuers
  • Liquid staking and restaking protocols
  • RWA issuers

Who integrates

Anyone carrying an asset somebody else built.

  • Exchanges and custodians
  • Index and structured-product issuers
  • Treasury desks
  • Wallets listing assets

Five losses this wall answers.

Public, dated and sourced. Open a row for what happened and for what would have caught or refused it.

$$81.5MM Orbit Chain December 2023 moved once seven of ten signers turned out not to be ten parties
What happened

The bridge required seven of ten multisig signers. The attacker obtained seven, and the bridge behaved exactly as configured. Most of what left was stablecoins, alongside 231 WBTC and 9,500 ETH, on New Year's Eve.

What answers it

A threshold is only worth the number of genuinely separate organisations that have to agree to satisfy it. Counting keys and counting parties are different measurements, and a threshold no independent set can actually satisfy caps the floor outright.

Halborn on the Orbit Bridge hack
~$~$126MM Multichain July 2023 left a bridge whose multi-party signing ran on one person's cloud account
What happened

The protocol's multi-party computation nodes ran under the chief executive's personal cloud account. When he was detained in May, along with his devices and recovery phrases, nobody else could reach the servers. Unauthorised withdrawals began in July and the project ceased operations.

What answers it

How many separate organisations must agree, and whether backing can be checked on chain at all, are structural questions the methodology asks before grading. Both are read from the deployment rather than from a disclosure. A design marketed as multi-party but operated by one person does not reach a floor you would accept.

Chainalysis on the Multichain exploit
$$5MM Ankr December 2022 of real value drained after 20 trillion tokens were minted from a contract with no cap
What happened

A former team member planted a malicious package that captured a deployer key on the next legitimate update. The token contract had no mint ceiling, so the key minted 20 trillion units and sold them into liquidity pools. The token fell 99.5 per cent in hours.

What answers it

Whether minting is capped, and who can upgrade the contracts and how fast, are readable properties of a deployment rather than facts you learn afterwards. An unbounded mint reachable by one key is a fatal criterion: it caps the rating outright, and a floor enforced in your own onboarding function refuses the asset.

Ankr's own report on the aBNBc exploit
~$~$100MM Harmony Horizon Bridge June 2022 moved across fourteen transactions on two of five keys
What happened

The bridge was, in effect, a two-of-five multisig: if any two of five addresses instructed it to move funds, it moved them. Two of those keys were obtained. No contract misbehaved and no signature was invalid. Afterwards the threshold was raised to four of five.

What answers it

The important part is the date. That threshold was public, on chain and readable by anyone before the loss rather than after it. A minority of keyholders being able to move everything is a structural fact about how the asset was built, and it can be graded in advance and enforced by a gate in your own contract.

Halborn on the Harmony Horizon Bridge hack
$$624MM Ronin Bridge March 2022 withdrawn on a five-of-nine threshold one organisation could satisfy alone
What happened

The bridge required five of nine validators. Sky Mavis operated four, and an allowlist granted five months earlier, letting it also sign for the Axie DAO's validator, was never revoked. One organisation's access therefore reached the threshold on its own.

What answers it

Nine keys, five signatures, one party. The measurement that matters is how many separate organisations those keys really represent, and a delegation that collapses a threshold is configuration drift the methodology re-measures on a schedule rather than reading once.

Halborn on the Ronin bridge hack

What it builds on.

Shared substrate, not features of this wall. Every layer below is already paid for by the first wall in your scope.

Asset Ratings This wall
public verification-stack configuration, read live from every chain an asset spans
L2Beat frameworks, cited and complemented
EAS attestations and Ops Monitor configuration watchers

How it is operated.

How this wall is run Stated before anything is provisioned

Floors are floors, not averages. Certain structural failures cap a rating outright however well everything else scores. The methodology is public, run against real historical losses and against healthy assets that must not be flagged, with both misses and false flags published. Ratings expire, drift is watched, and issuers who disagree have a real appeals route.

What turns on when it is in scope.

Individually, or bundled with the walls beside it.

In scope

Graded floors and the working

The full published methodology, the derivation behind every score, and drift monitoring across everything you depend on rather than only what you issue

In scope

A gate, not a memo

The integrator floor API read at point of use, and a base contract you inherit so an asset below your floor cannot be onboarded as collateral

It gives Exposure Map the weights that make contagion realistic, because a structurally fragile asset propagates differently from a robust one. It gives Live Detection a reason to hold a tighter threshold where the structure is weaker. And it gives the whole perimeter the vocabulary risk committees already use.

Fuga Labs is read-and-attest, never custody-and-execute.
The cardinal ruleEnforced in code across every wall, Asset Ratings included

Put Asset Ratings on your perimeter.

A scoping call maps this wall against what you run and says where it reaches and where it stops. Nothing is provisioned until that is agreed in writing.