Our documentation has been updated with details on Phase 2, how coverage works, claims payouts, and more.
For the complete documentation index, see llms.txt. This page is also available as Markdown.

Becoming a Member

The Risk Consortium is made up of independent technical experts. The MVP launches with five confirmed members (Hypernative, Cyfrin, Credora, GFX Labs, and Native). This page covers who the consortium looks for and the terms of participation. It does not publish compensation specifics.

Who the consortium looks for

The consortium draws from organizations with deep technical expertise in DeFi security and risk. Typical backgrounds include:

Background
What they bring

DeFi risk managers

Protocol-level risk analysis, parameter setting, credit and liquidity assessment

Security auditors

Smart contract review, exploit pattern recognition, remediation experience

On-chain forensics specialists

Transaction tracing, attacker identification, evidence assembly

Monitoring and infrastructure providers

Real-time detection, oracle and bridge expertise

No single member needs to cover all of these. The consortium is designed to aggregate complementary expertise across its members.

Independence requirement

Independence is the gating criterion. Candidates must operate at arm's length from Firelight's commercial teams and from the protocols they assess. That includes no direct employment relationship with Firelight entities, disclosure of advisory roles or investments in covered protocols, and a commitment to declare conflicts and abstain when they arise. Candidates whose independence cannot be maintained are not eligible, regardless of technical strength.

Selection process

The Foundation engages members through a structured process: introduction or nomination, a capability review against the expertise the consortium wants to cover, an independence check, and a participation agreement on approval. The consortium starts at its confirmed size of five and may expand as coverage volume and protocol complexity grow.

Terms of participation

A participation agreement covers scope of duties, the mandatory voting responsibilities and optional activities described in Role of the Consortium, response-time commitments, the conflicts policy, confidentiality around non-public exploit information, term and termination, and the basis for compensation.

What the consortium expects

Effective participation requires availability (incidents arrive on the protocol's schedule, not the member's), technical rigor (members are the last line of defense before payout), discretion (exploit information can be time-sensitive), and professional conduct (votes and rationales are on the record).

Exiting the consortium

Members can leave by giving notice under their participation agreement. The Foundation can also remove members who repeatedly miss response windows, develop unresolvable conflicts, or breach the confidentiality or conflicts policies.

Last updated