Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.

Supra

Oracles & Off-Chain Data Networkscritical·risk 0.6615·TVL $8.8M·blast $8.8M·active
Static profile (Identity / Contract / Dependency / Governance / Reputation)

Identity

Sector
Oracles & Off-Chain Data Networks
Subsector tags
consumer_app, infra_tooling, general_defiDemo
Chain deployments
Supra
Website
https://www.supra.xyzDemo
Launch date
May 12, 2025
Immutable
noDemo
Permissionless
yesDemo

Contract

Primary address
Proxy pattern
UNKNOWN
Upgrade authority
UNKNOWN
Multisig threshold
Compiler
0.8.20
Uses assembly
noDemo
Bug bounty
noneDemo
Contract addresses
0x66bcac7d6d84fc5032e7822863596fd81cb34083, 0x21a9553b571289dfe77d9f43aa85a7001892b76b, 0x70083bfee8a1b587a0ff575b0ac01bd9d28c8dd2Demo
Audits tier
0

Dependency

Oracle providers
Bridge dependencies
Stablecoin dependencies
LST / LRT deps
Demo
DEX liquidity venues
balancerDemo
CEX listings
binanceDemo
Custodian
Demo
KMS provider
aws_kmsDemo
RPC provider
self_hostedDemo
Frontend host
aws_s3Demo
npm lockfile sha
sha256:444494e7c59a07033fa99b88b593a2c9a5f693b0a7e8814b914bf05a0395c642Demo

Governance

Governance type
multisig_councilDemo
Governance token
Demo
Treasury size
$268.1KDemo
Team size
21Demo
Jurisdiction
PTDemo
Incorporated entity
Supra DAO LLCDemo
Anonymous team
noDemo
Security disclosure
noDemo
IR SLA (hours)
Demo

Reputation

GitHub
https://github.com/supra/supraDemo
Commit velocity (30d)
8Demo
Contributors
32Demo
Twitter
@supraDemo
Discord
https://discord.gg/xjfx1vDemo
Last incident
Jan 30, 2022Demo
KYT screening
cleanDemo

Threat History

1 recorded incident
oracle manipulationprotocolunknownDemo
$54.6M

On 2022-01-30, Supra suffered a oracle manipulation incident resulting in approximately $54,643,182 in losses. The exploit targeted the protocol layer. A flash loan was used to amplify the attack. Attribution: unknown. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0040DEMO:AADAPT.TA0007

Peer Incidents · Method B

7 root-cause predicate matches

Vulnerable to: reentrancy

Matches the reentrancy predicate

28 historical peer events
  • SommelierDemo
    $30.7M
  • Kyber NetworkDemo
    $2.1M
  • DeribitDemo
    $936K
  • Zora NetworkDemo
    $4.7M
  • Stader LabsDemo
    $16.1M
  • + 23 more

Vulnerable to: ice phishing approval

Matches the ice phishing approval predicate

16 historical peer events
  • deBridgeDemo
    $7.5M
  • EulerDemo
    $87.9K
  • Bend DAODemo
    $968.9K
  • Maple FinanceDemo
    $1.4M
  • BlurDemo
    $6.5M
  • + 11 more

Vulnerable to: rounding precision

Matches the rounding precision predicate

10 historical peer events
  • Frax EtherDemo
    $51.2K
  • BNY Mellon DigitalDemo
    $750K
  • RedStoneDemo
    $63.2K
  • Bend DAODemo
    $57.9K
  • Starknet BridgeDemo
    $784.1K
  • + 5 more

Vulnerable to: supply chain npm

Matches the supply chain npm predicate

10 historical peer events
  • Beefy FinanceDemo
    $176.2K
  • PowerledgerDemo
    $7.4M
  • UnichainDemo
    $8.8M
  • MEXCDemo
    $1M
  • Mango MarketsDemo
    $915.6K
  • + 5 more

Vulnerable to: kms misconfiguration

Matches the kms misconfiguration predicate

9 historical peer events
  • Stably, Inc. (issuance via regulated partners depending on program)Demo
    $505K
  • MatrixdockDemo
    $4.3M
  • EulerDemo
    $3.6M
  • NosanaDemo
    $1.7M
  • Tron FoundationDemo
    $1.3M
  • + 4 more

Vulnerable to: dvn collapse

Matches the dvn collapse predicate

8 historical peer events
  • Blast, Blockdaemon Wallet +2Demo
    $93.6M
  • Fordefi, XSGDDemo
    $17M
  • Element Finance, QuantozDemo
    $1.1M
  • Mercado Bitcoin, SwellDemo
    $15.3M
  • Internet Computer (DFINITY), Mantle +1Demo
    $10.3M
  • + 3 more

Vulnerable to: prompt injection agent

Matches the prompt injection agent predicate

4 historical peer events
  • LodestarDemo
    $3.2M
  • Ether.fi CashDemo
    $4.6M
  • HTX (Huobi)Demo
    $3.7M
  • SwellDemo
    $403K

Dependency Twins · Method A + B + C ensemble

Top 10 of 25 precomputed
#1

Euler

Lending, Money Markets & CDPs · low
Ensemble
0.456
A · Jaccard0.13
B · Overlap2
C · Cosine0.86
Matches on
  • kms_provider = aws_kms
  • frontend_host = aws_s3
  • subsector_tags = general_defi, infra_tooling
  • method_b_root_causes = kms_misconfiguration, ice_phishing_approval
#2

Lift Dollar (USDL)

Stablecoin Issuers & Synthetic Dollars · high
Ensemble
0.424
A · Jaccard0.07
B · Overlap2
C · Cosine0.81
Matches on
  • frontend_host = aws_s3
  • subsector_tags = general_defi, consumer_app
  • method_b_root_causes = reentrancy, rounding_precision
#3

Deribit

Centralized Exchanges & Brokerages · critical
Ensemble
0.417
A · Jaccard0.10
B · Overlap2
C · Cosine0.76
Matches on
  • kms_provider = aws_kms
  • subsector_tags = general_defi, consumer_app, infra_tooling
  • method_b_root_causes = reentrancy, rounding_precision
#4

Notional Finance

Lending, Money Markets & CDPs · high
Ensemble
0.409
A · Jaccard0.09
B · Overlap2
C · Cosine0.74
Matches on
  • kms_provider = aws_kms
  • subsector_tags = general_defi, infra_tooling
  • method_b_root_causes = reentrancy, ice_phishing_approval
#5

GCash

Payment Rails, On/Off-Ramps & CBDCs · medium
Ensemble
0.408
A · Jaccard0.14
B · Overlap1
C · Cosine0.95
Matches on
  • kms_provider = aws_kms
  • frontend_host = aws_s3
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • method_b_root_causes = kms_misconfiguration
#6

Keep3r Network

AI Agents & Autonomous On-Chain Systems · medium
Ensemble
0.398
A · Jaccard0.14
B · Overlap1
C · Cosine0.92
Matches on
  • kms_provider = aws_kms
  • frontend_host = aws_s3
  • subsector_tags = general_defi, infra_tooling, consumer_app
  • method_b_root_causes = ice_phishing_approval
#7

Blur

Identity, NFTs, Gaming & Consumer Apps · high
Ensemble
0.395
A · Jaccard0.04
B · Overlap2
C · Cosine0.74
Matches on
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • method_b_root_causes = reentrancy, ice_phishing_approval
#8

Taurus Group

Institutional Custody & Prime Services · medium
Ensemble
0.386
A · Jaccard0.13
B · Overlap1
C · Cosine0.89
Matches on
  • kms_provider = aws_kms
  • frontend_host = aws_s3
  • subsector_tags = infra_tooling, consumer_app
  • method_b_root_causes = dvn_collapse
#9

Radiant Capital

Lending, Money Markets & CDPs · medium
Ensemble
0.385
A · Jaccard0.04
B · Overlap2
C · Cosine0.71
Matches on
  • subsector_tags = consumer_app, infra_tooling, general_defi
  • method_b_root_causes = reentrancy, ice_phishing_approval
#10

Sanctum

Liquid Staking & Restaking · critical
Ensemble
0.385
A · Jaccard0.03
B · Overlap2
C · Cosine0.72
Matches on
  • subsector_tags = general_defi, consumer_app
  • method_b_root_causes = reentrancy