Credit · Fixed Income · SPECTRA
Spectra (formerly APWine) is a permissionless interest-rate derivatives protocol: any yield-bearing asset can be split into principal and yield tokens to trade fixed and variable rates.
Permissionless yield tokenization (ex-APWine).
SPECTRA price
$0.0031
+11.1% 24h
Latest data · 15 min delay
Typed risks scored by severity, likelihood and impact, with the incident record behind them.
38
severity-weighted points across 13 typed risks · 2 critical
assessed Jul 2026Market
13· 4 risks · 1 critical
Technological
19· 7 risks
Counterparty
4· 1 risk · 1 critical
Governance
2· 1 risk
Regulatory
No rowsNo Regulatory risk rows in the dataset: a recorded finding (no fetchable regulatory exposure source), not missing data.
Every score is recomputed at render time from the typed risks below; nothing is hand-assigned. Each risk contributes its severity weight (critical 4 · high 3 · medium 2 · low 1) to its category; the headline number is the sum across all categories. Bars scale to this entity's highest category score. Scores are not comparable across tags because a permissionless-market protocol concentrates technological risk while an institutional-credit protocol concentrates counterparty and regulatory risk, and a single league table would misrepresent both.
Market 4 × → 13
Technological 7 × → 19
Counterparty 1 × → 4
Governance 1 × → 2
Spectra is a small, permissionless protocol whose core contracts have held up well and whose risk sits almost entirely at the edges. Three independent audit engagements, Code4rena, Pashov and Sherlock, produced no high severity findings, and the one exploit it suffered in July 2024 hit a peripheral router contract and four wallets rather than the protocol itself, costing around 168 ETH and being contained within six hours. The structural exposures are different in kind. Anyone can list any ERC-4626 token as a market with no vetting, and Spectra's own documentation says it has no control over what users contribute, so the protocol's real credit quality is whatever its underlyings happen to be. That became concrete on 22 March 2026 when Resolv, a major source of Spectra collateral, was exploited for 80 million USR of unbacked mint and saw USR trade below three cents. On top of that, TVL has fallen to about 28 million USD spread thinly across twelve chains, with more than 85% sitting on Hemi and Flare rather than Ethereum. Spectra should be judged one market at a time, because the protocol offers no protection at all against a bad underlying. Report compiled 26 July 2026. Every value above is drawn from a page fetched during the research session and linked inline. Where a figure could not be confirmed from a fetched source it is marked n.a.
Market4
Technological7
Counterparty1
Governance1
2 documented incidents · 23 Jul 2024 to 22 Mar 2026 · how the protocol behaved under stress, with sources.
23 Jul 2024
At approximately 3:00 PM UTC on Ethereum mainnet an attacker exploited a command in Spectra's router utility contract that allowed users to enter and exit pools with a token of their choice, sweeping funds after users approved the transaction. A Discord user made false claims about YT contract problems to prompt withdrawals. Four wallets were impacted and core protocol contracts were unaffected.
DetailsAt approximately 3:00 PM UTC on Ethereum mainnet an attacker exploited a command in Spectra's router utility contract that allowed users to enter and exit pools with a token of their choice, sweeping funds after users approved the transaction. A Discord user made false claims about YT contract problems to prompt withdrawals. Four wallets were impacted and core protocol contracts were unaffected.
Outcome: Spectra disabled the app, terminated the router contracts, paused Principal Token contracts to block exchanges at the Curve pool level, then unpaused at about 9 PM UTC and reinstated the app on 24 July. Authorities, exchanges and security teams were contacted, and Spectra sent the attacker an onchain offer to close the case if 90% of funds were returned. Attacker address 0x53635bf7b92b9512f6de0eb7450b26d5d1ad9a4c.
Source22 Mar 2026
Resolv, a major source of ERC-4626 collateral tokenised on Spectra, was exploited. A compromised SERVICE_ROLE private key held in AWS KMS combined with a completeSwap function that performed no onchain check on the ratio between deposited funds and minted tokens allowed 80 million USR to be minted from roughly 300 thousand USDC, a 266 to 1 ratio.
DetailsResolv, a major source of ERC-4626 collateral tokenised on Spectra, was exploited. A compromised SERVICE_ROLE private key held in AWS KMS combined with a completeSwap function that performed no onchain check on the ratio between deposited funds and minted tokens allowed 80 million USR to be minted from roughly 300 thousand USDC, a 266 to 1 ratio.
Outcome: USR fell below 0.025 USD at its lowest point. The attacker extracted about 11,400 ETH worth roughly 24 million USD and still held about 36 million USR worth an estimated 2 million USD. Downstream damage was amplified by a donation attack on Morpho vaults using a hardcoded 1 USD oracle for USR and wstUSR. Spectra is not named among the affected protocols in the OAK Research analysis, so direct Spectra losses are n.a.
SourceEvent-type chips are categorised by event type against the risk taxonomy (a documented presentation mapping, not a dataset assessment). Amounts are the dataset's published figures; missing values were never published.