TL;DR
edgeX is an orderbook perpetuals DEX running StarkEx as a validium, incubated by Amber Group with a strategic investment from Circle Ventures. In the normal case custody is genuinely non-custodial: USDT sits in an Ethereum L1 escrow contract, matching happens off-chain, and STARK proofs settle state back to L1. The operating record supports that framing. Live on mainnet since 3 August 2024, so 24 months, with no custody or protocol exploit on record and 100 percent normal uptime over the past 30 days.
The admin surface got worse since the July report, not better. L2BEAT now lists two CRITICAL risks where it previously listed one, under a red banner reading "Critical contracts can be upgraded by an EOA which could result in the loss of all funds." The old flag stands: contracts holding user funds can be upgraded with no delay, and the exit window is None. The new one dates to the 6 July 2026 log entry, when a StarkPerpetual facet was upgraded to an unverified contract and the diamond was marked not finalized. The important detail, which is worse than it first reads, is that the unverified contract is not a peripheral facet. L2BEAT lists 0xfAaE2946e846133af314d1Df13684c89fA7d83DD as the USDT escrow itself and marks it unverified, and Etherscan independently returns "Contract source code not verified" for the deployed implementation as of this pull.
Deposits are leaving. TVL is $71.25M, down 52 percent over 90 days and 77 percent from the November 2025 peak. The verdict stays caution, on a weaker footing than last month.
Checklist
Audits & contracts. The published set is real, fully corroborated, and better than typical for this category. edgeX's own repo carries eight reports, and the README table names each engagement explicitly: RigSec and SlowMist on V1, Halborn and Spearbit on V2, SlowMist on the bridge and CCTP extension, Binenet on core vaults and CCTP integrations, SlowMist on EdgeToken and on EdgeDistributor. No firm in that list is invented, and the repo was last pushed on 3 August 2026, so the disclosure habit is alive. What pulls this off green is the upgrade that put an unverified implementation into the StarkPerpetual diamond. L2BEAT scores it as its own CRITICAL, worded "Funds can be stolen if the source code of unverified contracts contains malicious code." A strong audit list does not cover bytecode that was never published, and here the unpublished bytecode is in the contract holding the collateral.
Admin control. The weakest dimension, and the one that sets the verdict. Concretely, and all of this is verbatim from L2BEAT's permissions data: StarkPerpetual (eth:0xfAaE2946e846133af314d1Df13684c89fA7d83DD) has a Safe with a 3-of-5 threshold as admin that "can upgrade with no delay" and is "permitted to appoint and remove the Operator"; the FinalizableGpsFactAdapter (eth:0x4abBc1826389aC0FEaA49E70c30a041b665e8562) is owned by a single EOA that can likewise upgrade with no delay while the adapter is unfinalized. The exit window is recorded as None, which follows directly from instant upgradability. The shared SHARP verifier proxy is better governed, sitting behind a 2-of-4 multisig with an 8 day delay, but that is StarkWare infrastructure rather than edgeX's own escrow. Separately, the EdgeXDepositor wrapper (eth:0xC0a1a1e4AF873E9A37a0caC37F3aB81152432Cc5) has three EOA signers, any two of whom can "withdraw any funds from this deposit wrapper contract." That wrapper routes arbitrary-token deposits through a 1inch swap into USDT, and L2BEAT notes its fast-withdrawal feature "seems deprecated in practice," so it is a smaller surface than the headline TVL. It is still an unaccountable 2-of-3 over whatever passes through it.
Oracle. Verified this run rather than carried. edgeX's documentation states that the Oracle Price is sourced from the independent provider Stork and is used to calculate margin requirements and liquidation prices, with the oracle price rather than the last trade triggering forced liquidation. That is the correct design, and it is what blunts thin-book liquidation games. The reason this is not green is empirical, not architectural. In the early hours of 2 June 2026 the venue's own token fell roughly 71 to 77 percent depending on the reference high, from about $1.12 to $1.26 down to about $0.31 to $0.32, and the event drove more than $140M in forced liquidations across Binance, OKX, Bybit and edgeX inside an hour. edgeX's post-mortem blamed a coordinated market attack and denied any breach or contract vulnerability. Whether the pricing path faithfully tracked a genuinely manipulated spot market or amplified it has never been settled publicly.
Liquidity & exit. Regular withdrawals work and the escape path is real: users can force a withdrawal through L1, and after 7 days of censorship or downtime they can exit trustlessly by submitting a Merkle proof of funds. The catch is what that proof is built from. This is a validium, so as L2BEAT puts it, "proof construction relies fully on data that is NOT published onchain," held by a Data Availability Committee with a 2-of-6 threshold whose members are not publicly known and who carry no slashable economic security, with no fraud detection. L2BEAT judges that this committee does not meet basic security standards. The escape hatch is therefore only as good as a small anonymous committee's willingness to serve data. On 13 July 2026 edgeX added a DAC member and raised the required signatures from 1 to 2, which is a genuine improvement but off an extremely low base, since a single signature sufficed until then. Forced position closes also require the user to find a counterparty. The eLP vault adds a redemption lockup of up to 2 days on top.
Yield: real vs emission. Traders get no deposit yield here; returns come from directional and carry trading plus the points and airdrop program, which is pure incentive. The eLP vault is the one place with a yield number, and its income is genuinely real: passive market-making profit, liquidation fees, and a share of platform trading fees. That is better provenance than emissions. It is also loss-bearing, because eLP depositors take the other side of trader flow, and it is negative right now at -2.84 percent over 7 days and -3.51 percent over 30 days against a 9.67 percent inception figure and +62.20 percent cumulative since launch 477 days ago. Real yield and safe yield are different claims, and only the first one applies.
Holder concentration. EDGE circulates 350M of a 1B supply, which the project's own tokenomics page reports as 30.34 percent net circulating after 4.67 percent was repurchased and burned from accumulated revenue. The remaining 65 percent is locked, and every bucket has a disclosed schedule: Team and Investors behind a 24 month cliff plus 24 months linear, Future Reserve behind 18 plus 24, Foundation and Ecosystem and Community each behind 12 plus 24. The concern is not that the Future Reserve is unscheduled, because it is scheduled, but that at 30 percent it is the single largest allocation, larger than team and investors combined, with no stated purpose. Layered on that is the unresolved dispute over who holds the float that is already liquid. ZachXBT alleged that insiders control nearly the whole supply and asked edgeX to disclose its market-maker agreements and counterparties; edgeX investigated itself and denied wrongdoing. The June mechanics fit the allegation's shape, with 174 distinct addresses executing coordinated sell orders on PancakeSwap within a single minute. This is token-price risk rather than deposit risk, but the governance signal is bad and no on-chain top-holder breakdown was verified this run.
Track record. The venue went live on mainnet on 3 August 2024 per L2BEAT's own milestone, corroborated by DeFiLlama's first TVL point of $2.56M on 7 August 2024. That is 24 months, not the 21 stated in the previous report, which used a later and incorrect October 2024 start. In that time there has been no protocol-level or custody exploit, L2BEAT records no incidents, and the last 30 days show no operational anomalies. Against that: the June token crash, a compensation program whose second half does not land until April 2027, a 200,000 USDC bounty for information, and an unverified implementation currently live in the fund path. Credit where it is due, the compensation was not just announced. The first tranche was distributed by 8 June, capped at 100,000 USDC per account across both tranches, with 50 percent paid in USDC within seven business days of the account audit. The other 50 percent is payable in EDGE in the first week of April 2027 at a 7 day average price, funded from the Ecosystem and Community allocation that only begins vesting on 31 March 2027. That leaves affected users holding roughly ten months of price exposure to the asset that harmed them.
Worst case
Someone who controls the 3-of-5 Safe, or the EOA on the unfinalized fact adapter, pushes an upgrade that redirects the L1 escrow. There is no delay and no exit window, so no user can front-run it; the 7 day escape hatch defends against censorship and downtime, not against logic that changes in one block. The unverified implementation makes this materially worse rather than theoretically worse, because the contract an observer would need to read to notice a hostile change is the escrow itself, and its source is not published. A second, quieter path runs through data availability. If the 2-of-6 anonymous committee withholds or falsely attests to unavailable batches, the Merkle proof the escape hatch depends on cannot be constructed, and the guaranteed exit stops being guaranteed exactly when it is needed. For eLP depositors the ordinary bad case needs no villain at all: the vault is the counterparty to trader flow, its 7 and 30 day returns are already negative, and a violent move against the book is a straightforward drawdown on principal.
Bottom line
Caution, unchanged in label but not in reasoning. The architecture is legitimately non-custodial, the audit disclosure is above average and fully verifiable, the operating record is clean across two years, and the team paid real money after an event it denied causing. That is not an avoid. But a fund-holding contract that can be replaced instantly, by a small multisig, whose current implementation nobody outside the team can read, is a live fund-loss vector rather than a theoretical one, and worst-flaw-wins puts the ceiling here. Deposits voting with their feet, down 52 percent in 90 days and 77 percent off the peak, is consistent with the market reaching the same conclusion.
For us this is a data relationship, not a money one. The $10k portfolio does not sit here; edgeX is a funding-rate reference in our scanner and a row in the vault registry, and the slug is in HIDDEN_RISK_SLUGS, so this report is reachable at /risk/edgex but is not listed on the public /risk board. One operational note survives checking, and one does not. The registry is fine: our latest perp_vault_snapshots row for the edgeX vault, written 2026-08-12 12:00 UTC, carries $16,648,718.55 and -3.51 percent 30d, matching the venue API exactly, so no re-sync is needed. The watchlist entry is the one worth a look: it labels edgeX as Arbitrum alone, whereas DeFiLlama splits the tracked deposits into $56.21M on Ethereum and $15.04M on Arbitrum, and every governance contract sits on Ethereum. The label is incomplete rather than wrong. If capital ever were routed here, the instant-upgrade path is the reason to keep the size small and the duration short.
Data appendix
- TVL: $71.25M. The shape matters twice. First, the DeFiLlama parent resolves entirely to the
edgex-bridgechild at $71,254,931, whileedgex-perps,edgex-spotandedgex-v2return no value at all. On a StarkEx validium the escrow is where trader collateral actually sits, so this is deposited collateral rather than open interest or book depth. Second, the chain split is Ethereum $56,209,406 (78.9%), Arbitrum $15,043,515 (21.1%), edgeX L1 $2,009, BSC $0. Source: api.llama.fi/protocol/edgex, /tvl/edgex-bridge. - Deposit-size disagreement: three independent measures do not reconcile. DeFiLlama $71.25M, L2BEAT value secured $47,499,860 in USDT, and the main L1 escrow's live on-chain USDT balance 38,040,366.50 USDT via Etherscan. Treat the headline as an upper bound on collateral actually escrowed at the StarkPerpetual contract. Cause of the spread: refresh.
- TVL trend: 7d $78.28M (-9.0%), 30d $95.37M on 2026-07-13 (-25.3%), 90d $150.06M on 2026-05-14 (-52.5%). ATH $306,603,608 on 2025-11-12, so -76.8% from peak. Monthly 2026 trail: Apr $229.26M, May $154.94M, Jun $147.18M, Jul $94.51M, Aug $78.47M. First data point $2,564,936 on 2024-08-07. Source: DeFiLlama.
- Chain / tech: StarkEx validium, off-chain matching, STARK proofs settled to Ethereum L1. Data availability external via DAC, not on chain. Collateral counted in value secured is USDT. Source: L2BEAT.
- Custody: Non-custodial. Deposit to L1 escrow; force withdrawal via L1; escape hatch after 7d of censorship or downtime, exercised by submitting a Merkle proof of funds. Forced position closes require the user to source a counterparty. Source: L2BEAT, StarkEx docs.
- Admin / governance: StarkPerpetual (eth:0xfAaE2946e846133af314d1Df13684c89fA7d83DD) admin is a Safe with 3/5 threshold that can upgrade with no delay and appoints or removes the Operator. FinalizableGpsFactAdapter (eth:0x4abBc1826389aC0FEaA49E70c30a041b665e8562) owner is an EOA that can upgrade with no delay while unfinalized. SHARP Multisig is 2/4 with an 8d delay on the verifier call proxy. EdgeXDepositor (eth:0xC0a1a1e4AF873E9A37a0caC37F3aB81152432Cc5) has 3 EOA signers, any 2 of whom can withdraw any funds held in the wrapper; its fast-withdrawal path "seems deprecated in practice." Exit window: None. Red banner: "Critical contracts can be upgraded by an EOA which could result in the loss of all funds." Two CRITICAL risks: no delay on code upgrades, and unverified contract source. Signer identities and DAC member identities: refresh. Total count of StarkPerpetual implementation upgrades and average interval: refresh (not present in page source). Source: L2BEAT.
- Unverified contract, independently confirmed: L2BEAT lists eth:0xfAaE2946e846133af314d1Df13684c89fA7d83DD as an unverified contract and as the USDT escrow. Etherscan
getsourcecodefor the deployed implementation eth:0x80961E33198fa91C43De1Bc1d07516148099D58D returns "Contract source code not verified" as of 2026-08-12. Source: L2BEAT, Etherscan. - Change log since last report: L2BEAT's tracked changelog holds 9 entries since discovery began 2026-10-14, three of them after the last report. 2026-07-06, "Upgraded PerpetualTokensAndRamping facet of Stark diamond to an unverified contract. The diamond changed to not finalized, so probably there will be further upgrades" (underlying on-chain upgrade tx dated 2026-07-05). 2026-07-08, global configuration hash updated. 2026-07-13, "Added a DAC member and increased DAC min signatures required to 2" (signaturesRequired 1 to 2). Nothing recorded after 2026-07-13. Source: L2BEAT.
- Data availability committee: 2-of-6 threshold, members not publicly known, no slashable economic security, no fraud detection. L2BEAT: the committee does not meet basic security standards. Threshold was 1-of-5 until 2026-07-13. Source: L2BEAT.
- Liveness: "100% normal uptime" and "No ongoing anomalies detected" for the window 2026 Jul 13 to Aug 12. Average proof submission and state update intervals: refresh (client-rendered, not verifiable from page source this run). Source: L2BEAT.
- Oracle: Stork decentralized oracle supplies the Oracle Price used for margin requirements and liquidation prices; oracle price rather than last trade triggers forced liquidation. Verified this run. Source: edgeX docs, Decentralized Oracle Pricing.
- Audits: Eight reports in github.com/edgex-Tech/audit-reports, repo last pushed 2026-08-03, each engagement named in the repo README table: RigSec (V1), SlowMist (V1), Halborn (V2), Spearbit (V2), SlowMist (bridge and CCTP extension), Binenet (core vaults and CCTP integrations), SlowMist (EdgeToken), SlowMist (EdgeDistributor). Individual report dates, scope and open findings: refresh (file list and README verified, report contents not read). StarkEx core audit by PeckShield: refresh (carried from a prior run, not verified this run). Source: GitHub API and repo README.
- eLP vault: totalLocked $16,648,718.55; apy1 3.80%, apy7 -2.84%, apy30 -3.51%, inception apy 9.67%, cumulative return 62.20%, total earnings $11,427,045.63, age 477 days, quota 500,000,000. Depositors are counterparty to trader flow with selective hedging; income from market-making PnL, liquidation fees and a share of trading fees; redemption lockup up to 2 days. Source: pro.edgex.exchange /api/v1/public/vault/vaultPerformance?vaultId=1. Cross-check: our own
perp_vault_snapshotsrow at 2026-08-12 12:00 UTC carries the identical $16,648,718.55 and -3.51% 30d, so the registry is in sync. - Token / holders: EDGE $0.3593, market cap $126,068,290, FDV $360,195,115, 350M of 1B circulating, ATH $1.54 on 2026-05-22, -76.7% from ATH, -7.4% over 30d, contract eth:0xb0076de78dc50581770bba1d211ddc0ad4f2a241 (CoinGecko, 2026-08-12). Tokenomics page: 4.67% repurchased and burned from accumulated revenue, 30.34% net circulating, 65% locked as Future Reserve 30%, Team and Investors 25%, Foundation 5%, Ecosystem and Community 5%; the circulating 35% is Airdrop 30% and Liquidity 5%. Vesting cliffs post-TGE plus 24 months linear in every case: Team and Investors 24 months, Future Reserve 18 months, Foundation 12 months, Ecosystem and Community 12 months. On-chain top-holder breakdown: refresh.
- June incident, corrected: 2 June 2026, eligible window 04:50 to 06:00 UTC+8, so late 1 June UTC, which is why both dates appear in reporting. The decline ran roughly one hour, not one minute; the one-minute figure refers to 174 distinct addresses executing coordinated sells on PancakeSwap, whose initial DEX impact was a 23% drop. Drop of roughly 71 to 77% depending on reference high, from about $1.12 to $1.26 down to about $0.31 to $0.32, recovering toward $0.60. More than $140M in forced liquidations across Binance, OKX, Bybit and edgeX within the hour. The frequently quoted 68.2% figure is the long-to-short ratio before the crash, not the share of longs liquidated. Compensation: cap 100,000 USDC per account across both tranches, 50% USDC within seven business days of account audit with the first tranche distributed by 8 June, 50% in EDGE in the first week of April 2027 at a 7 day average price, funded from the Ecosystem and Community allocation that begins vesting 31 March 2027. Described as a goodwill payment program. A 200,000 USDC bounty was offered in tiers of 100,000, 60,000 and 40,000. Sources: edgeX incident report via KuCoin, crypto.news, cryptotimes.io.
- Recent news scan (since 2026-07-01): No exploit, no withdrawal halt and no custody incident found, and L2BEAT records no incidents. Contract changes as logged above. A buyback program is corroborated on the project's own tokenomics page by the 4.67% cumulative burn described as "repurchased by accumulative revenue." Secondary reports that July deposits surged past $100M, a roughly 1,000% increase driven by the Open Season campaign, do not reconcile with the net TVL series falling from $95.37M to $71.25M over the same window; treat as unverified or as gross inflow. Sources: L2BEAT, DeFiLlama, secondary press. Maintained monthly. Methodology: DeFi Research Instruction v2.