Risk Consortium
The Risk Consortium is the independent body that validates covered incidents. Without it, payouts would depend on either automated rules (too rigid for the realities of exploit classification) or a single administrator (too centralized to trust). The consortium sits between those extremes: independent domain experts applying published coverage criteria to on-chain evidence.
Confirmed members
The consortium launches with five confirmed members:
Hypernative
Cyfrin
Credora
GFX Labs
Native
What you'll find here
Role of the Consortium defines the consortium's scope, responsibilities, and limits.
How Claims Are Assessed details the validation and voting procedure under the auto-inclusion model.
Becoming a Member describes eligibility and the terms of participation.
Why the consortium exists
Exploit classification is judgment-heavy:
Was a governance outcome a malicious exploit or a legitimate vote?
Was a liquidation cascade a mechanism failure or market behavior within design parameters?
Did an oracle deviation reflect manipulation or ordinary cross-exchange drift?
These are not questions a smart contract can answer on its own. They require technical review of on-chain evidence by people who understand the underlying protocols.
What the consortium is not
The consortium is not a backer or risk-pricing authority, a program operator or fund custodian, a designer of coverage criteria or pricing, or a marketing arm of Firelight. Its authority is limited to applying existing coverage criteria to reported incidents and voting on whether those incidents qualify. It does not set premiums, modify terms, hold collateral, or execute fund transfers.
How decisions flow
Because Firelight uses auto-inclusion, the consortium does not wait for program operators to file claims. Once an incident is detected and reported:
An independent security partner delivers an exploit report on-chain.
The protocol auto-includes every active, in-scope Cover Token exposed to the incident.
Consortium members validate the incident against the published coverage criteria and declare any conflicts.
Members vote Approve or Deny. A 3-of-5 quorum is required.
If the quorum and approval threshold are met, the decision is signaled on-chain and triggers the payout waterfall.
Where the consortium appears in the rest of the docs
Claims Process shows the consortium's role from the program operator's perspective.
On-Chain Components documents the contracts the consortium interacts with.
Last updated