Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.

Yellow Card

Payment Rails, On/Off-Ramps & CBDCsmedium·risk 0.4300·TVL ·blast $0·active
Static profile (Identity / Contract / Dependency / Governance / Reputation)

Identity

Sector
Payment Rails, On/Off-Ramps & CBDCs
Subsector tags
consumer_app, infra_toolingDemo
Chain deployments
Website
https://www.yellow-card.xyzDemo
Launch date
Immutable
noDemo
Permissionless
noDemo

Contract

Primary address
Proxy pattern
n/a
Upgrade authority
n/a
Multisig threshold
Compiler
0.8.20
Uses assembly
noDemo
Bug bounty
noneDemo
Contract addresses
0x338a52d8dd7ebbd30d834f515d2926dd01a7fc39, 0x00a1f455145dfdf5b72ee4d55a5c549f74616574, 0x34b5b9a991b7a1d80b3d59e53fbf0d823c0a1be5Demo
Audits tier
3

Dependency

Oracle providers
Bridge dependencies
Stablecoin dependencies
LST / LRT deps
Demo
DEX liquidity venues
uniswap_v4, aerodrome, uniswap_v3Demo
CEX listings
Demo
Custodian
Demo
KMS provider
aws_kmsDemo
RPC provider
alchemyDemo
Frontend host
cloudflare_pagesDemo
npm lockfile sha
sha256:2bcd6123bf01a0a9b3a6bb690682f10a49fa0ec47e421777c754372fc04daca3Demo

Governance

Governance type
token_votingDemo
Governance token
0x0820293281edffe5a3bd827beb2dd289aaf8a69bDemo
Treasury size
$0Demo
Team size
27Demo
Jurisdiction
CHDemo
Incorporated entity
Yellow Card DAO LLCDemo
Anonymous team
yesDemo
Security disclosure
yesDemo
IR SLA (hours)
4Demo

Reputation

GitHub
https://github.com/yellow-card/yellow-cardDemo
Commit velocity (30d)
11Demo
Contributors
25Demo
Twitter
@yellow-cardDemo
Discord
https://discord.gg/15lwnwdDemo
Last incident
Demo
KYT screening
cleanDemo

Threat History

0 recorded incidents
No recorded incidents for this entity. Threat history will populate as the Incident Ledger ingests live aggregator data (Phase 2a).

Peer Incidents · Method B

9 root-cause predicate matches

Vulnerable to: rug pull hard

Matches the rug pull hard predicate

22 historical peer events
  • SushiSwapDemo
    $25.6M
  • AlliumDemo
    $110.6K
  • HTX (Huobi)Demo
    $23M
  • Aptos FoundationDemo
    $1.2M
  • EtherscanDemo
    $633.1K
  • + 17 more

Vulnerable to: phishing drainer

Matches the phishing drainer predicate

18 historical peer events
  • GoldfinchDemo
    $1M
  • BitgetDemo
    $739.9K
  • OrcaDemo
    $180.8K
  • Ether.fiDemo
    $443.4K
  • Alchemy PayDemo
    $334.2K
  • + 13 more

Vulnerable to: flash loan governance

Matches the flash loan governance predicate

18 historical peer events
  • ThirdwebDemo
    $33.2M
  • LayerZero Labs (physical verification context only)Demo
    $40.2M
  • First Digital USDDemo
    $12.1M
  • Protocol-Native Treasury Agents (DAO-embedded)Demo
    $13.8M
  • F2PoolDemo
    $3.5M
  • + 13 more

Vulnerable to: rug pull soft

Matches the rug pull soft predicate

14 historical peer events
  • Euler FinanceDemo
    $3.2M
  • KlimaDAODemo
    $100.8K
  • Governed protocol (monetary policy–driven)Demo
    $174K
  • R3 (Ethereum interop only)Demo
    $79.1K
  • ViaBTCDemo
    $805.5K
  • + 9 more

Vulnerable to: frontend dns hijack

Matches the frontend dns hijack predicate

12 historical peer events
  • Bridge.xyz / StripeDemo
    $10.4M
  • UK FCA Digital SandboxDemo
    $3.6M
  • Three SigmaDemo
    $2.7M
  • CryptoQuantDemo
    $517.3K
  • Celsius (defunct)Demo
    $22M
  • + 7 more

Vulnerable to: supply chain npm

Matches the supply chain npm predicate

10 historical peer events
  • Beefy FinanceDemo
    $176.2K
  • PowerledgerDemo
    $7.4M
  • UnichainDemo
    $8.8M
  • MEXCDemo
    $1M
  • Mango MarketsDemo
    $915.6K
  • + 5 more

Vulnerable to: kms misconfiguration

Matches the kms misconfiguration predicate

9 historical peer events
  • Stably, Inc. (issuance via regulated partners depending on program)Demo
    $505K
  • MatrixdockDemo
    $4.3M
  • EulerDemo
    $3.6M
  • NosanaDemo
    $1.7M
  • Tron FoundationDemo
    $1.3M
  • + 4 more

Vulnerable to: dvn collapse

Matches the dvn collapse predicate

8 historical peer events
  • Blast, Blockdaemon Wallet +2Demo
    $93.6M
  • Fordefi, XSGDDemo
    $17M
  • Element Finance, QuantozDemo
    $1.1M
  • Mercado Bitcoin, SwellDemo
    $15.3M
  • Internet Computer (DFINITY), Mantle +1Demo
    $10.3M
  • + 3 more

Vulnerable to: governance proposal malicious

Matches the governance proposal malicious predicate

5 historical peer events
  • Stripe CryptoDemo
    $1.5M
  • Notional V3Demo
    $507.1K
  • Hong Kong Monetary Authority — Ethereum pilotsDemo
    $18.9M
  • FalconXDemo
    $4.8M
  • AvailDemo
    $30.8M

Dependency Twins · Method A + B + C ensemble

Top 10 of 25 precomputed
#1

Aptos Foundation

L1 & L2 Network Operators · medium
Ensemble
0.445
A · Jaccard0.03
B · Overlap3
C · Cosine0.66
Matches on
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = rug_pull_hard, rug_pull_soft
#2

Quantoz

Payment Rails, On/Off-Ramps & CBDCs · medium
Ensemble
0.422
A · Jaccard0.14
B · Overlap1
C · Cosine1.00
Matches on
  • kms_provider = aws_kms
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = dvn_collapse
#3

Mango Markets

Smart-Contract DEXs, AMMs & Aggregators · low
Ensemble
0.404
A · Jaccard0.14
B · Overlap1
C · Cosine0.94
Matches on
  • kms_provider = aws_kms
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = supply_chain_npm
#4

Unichain

Rollups, Data Availability & ZK Infra · high
Ensemble
0.394
A · Jaccard0.05
B · Overlap2
C · Cosine0.73
Matches on
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app
  • method_b_root_causes = frontend_dns_hijack, supply_chain_npm
#5

Bank of England wholesale CBDC pilots

Payment Rails, On/Off-Ramps & CBDCs · medium
Ensemble
0.393
A · Jaccard0.13
B · Overlap1
C · Cosine0.92
Matches on
  • kms_provider = aws_kms
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = kms_misconfiguration
#6

Ripio

Payment Rails, On/Off-Ramps & CBDCs · medium
Ensemble
0.393
A · Jaccard0.13
B · Overlap1
C · Cosine0.92
Matches on
  • kms_provider = aws_kms
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = rug_pull_soft
#7

Project mBridge

Payment Rails, On/Off-Ramps & CBDCs · medium
Ensemble
0.367
A · Jaccard0.07
B · Overlap2
C · Cosine0.62
Matches on
  • kms_provider = aws_kms
  • subsector_tags = infra_tooling
  • method_b_root_causes = rug_pull_hard, rug_pull_soft
#8

Karak

Liquid Staking & Restaking · medium
Ensemble
0.366
A · Jaccard0.05
B · Overlap2
C · Cosine0.63
Matches on
  • frontend_host = cloudflare_pages
  • subsector_tags = infra_tooling
  • method_b_root_causes = flash_loan_governance, rug_pull_hard
#9

HTX (Huobi)

Centralized Exchanges & Brokerages · critical
Ensemble
0.361
A · Jaccard0.07
B · Overlap2
C · Cosine0.60
Matches on
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = frontend_dns_hijack, rug_pull_hard
#10

CyberConnect

Identity, NFTs, Gaming & Consumer Apps · low
Ensemble
0.358
A · Jaccard0.08
B · Overlap1
C · Cosine0.85
Matches on
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling
  • method_b_root_causes = phishing_drainer