Our documentation has been updated with details on Phase 2, how coverage works, claims payouts, and more.
For the complete documentation index, see llms.txt. This page is also available as Markdown.

Risk Consortium

The Risk Consortium is the independent body that validates covered incidents. Without it, payouts would depend on either automated rules (too rigid for the realities of exploit classification) or a single administrator (too centralized to trust). The consortium sits between those extremes: independent domain experts applying published coverage criteria to on-chain evidence.

Confirmed members

The consortium launches with five confirmed members:

  • Hypernative

  • Cyfrin

  • Credora

  • GFX Labs

  • Native

What you'll find here

Why the consortium exists

Exploit classification is judgment-heavy:

  • Was a governance outcome a malicious exploit or a legitimate vote?

  • Was a liquidation cascade a mechanism failure or market behavior within design parameters?

  • Did an oracle deviation reflect manipulation or ordinary cross-exchange drift?

These are not questions a smart contract can answer on its own. They require technical review of on-chain evidence by people who understand the underlying protocols.

What the consortium is not

The consortium is not a backer or risk-pricing authority, a program operator or fund custodian, a designer of coverage criteria or pricing, or a marketing arm of Firelight. Its authority is limited to applying existing coverage criteria to reported incidents and voting on whether those incidents qualify. It does not set premiums, modify terms, hold collateral, or execute fund transfers.

How decisions flow

Because Firelight uses auto-inclusion, the consortium does not wait for program operators to file claims. Once an incident is detected and reported:

  1. An independent security partner delivers an exploit report on-chain.

  2. The protocol auto-includes every active, in-scope Cover Token exposed to the incident.

  3. Consortium members validate the incident against the published coverage criteria and declare any conflicts.

  4. Members vote Approve or Deny. A 3-of-5 quorum is required.

  5. If the quorum and approval threshold are met, the decision is signaled on-chain and triggers the payout waterfall.

Where the consortium appears in the rest of the docs

Last updated