TL;DR — the decision rule

A corpus of ~40 stablecoin depegs and DeFi/CeFi blowups, classified by root cause and mapped to our rubric. The honest finding: you cannot rank “most common cause” from this data (it is thematically sampled and visibility-biased), but the consequence pattern is clear and actionable.

The largest single blow-up is reflexive token economics (Terra) — but that is one outlier. The largest robust permanent-loss cluster is opaque off-chain counterparty insolvency / re-hypothecation / attestation failure (Celsius, Voyager, Genesis, BlockFi, Babel, Orthogonal — multiple independent billion-dollar events). Bridges and smart-contract exploits dominate the headlines but are heavily recovered (high gross, lower permanent loss). Treat off-chain solvency & attestation dependencies as the top under-priced risk in any eval — it is both the most reliable permanent-loss signal and our framework’s biggest blind spot. Never size off a “most common by count” claim.

Scope & caveat (read first — every eval citing this inherits it)

This is a thematically-sampled, visibility-biased corpus — five category lists, curated. So:

Taxonomy (root-cause categories)

What the corpus supports (ranked honestly)

Framework coverage map

Plain rubric section names; coverage is for catching the failure pre-incident.

CategoryRubric section / lensCoverage
A — Reflexive / emissionsMechanism design (Hard-no: reflexive collateral / emissions yield)Well — for the rule. Conditional on the analyst not being captured by the yield narrative.
G — Bank-run / liquidityOracle & liquidity (stress-haircut), Backing & redemptionWell. The stress-liquidity haircut is purpose-built for this.
B — Oracle manipulationOracle & liquidity + contagion “audit every price feed”Partial. The dimension text is scoped to our exit feed; internal liquidation-oracle manipulation is covered only by re-reading it via the contagion lens. Tighten the wording.
C — Smart-contract bugSmart-contract surfacePartial, structural. Audits don’t catch novel bugs in audited, mature code; only time-in-production + scope-of-deployed-version helps.
D — Key / gov (config)Governance & counterparty, Key-compromise thresholdWell on config (thresholds, timelocks, signer look-through).
D — Key / gov (OPSEC)Blind spot. No treatment of signer-device / supply-chain malware / blind-signing (Radiant, Multichain).
E — Off-chain solvency / re-hypBacking & redemption, Governance & counterpartyBlind → now partially closed (see rubric change below). We checked attestation form but had no balance-sheet / re-hyp / counterparty-concentration test.
F — Bridge / cross-chainConcentration line onlyBlind vs dollars. Bridges (Ronin, Wormhole, Nomad, Harmony, Multichain, BNB, Poly) are treated as a concentration surface, not as first-class entities to run key-compromise on; bridge code bugs fall in C’s gap.
(meta)Narrative / classification capture. Every “Well” assumes the analyst correctly labels the mechanism; the modal historical failure was mislabeling a risky thing as safe in real time (Anchor’s “real yield”, audited-Euler, “decentralized” Ronin). No pre-mortem step.
  1. Off-chain counterparty solvency & re-hypothecation Hard-noapplied in this change to the Governance & counterparty section, with the playbook principle “trace every off-chain leg to an audited balance sheet, or treat it as a discretionary promise.” Highest leverage: it maps to the most robust permanent-loss cluster (E) and generalizes to every RWA / CeFi-backed / delta-neutral product. Would have flagged Celsius, the Maple defaults, msUSD.
  2. Bridge sub-checklist (proposal) — evaluate the bridge under an asset as a first-class entity (security model: light-client vs multisig vs MPC vs optimistic; signer composition + jurisdiction; upgrade/init safety; audit-of-deployed-version).
  3. Signer-OPSEC clause (proposal) — in the key-compromise section: blind-signing, developer-device compromise, payload substitution.
  4. Oracle-feed wording fix (proposal) — extend the Oracle & liquidity dimension to explicitly cover the protocol’s internal liquidation/valuation feed, not only our exit pricing.
  5. Pre-mortem step (proposal) — one line forcing “name the narrative that would make us wrong,” to counter classification capture.

Methodology

Data sources & how to reproduce

Compiled via the failure-mode-research workflow (7 agents: 5 parallel category researchers → synthesis that read rubric.md + eval-playbook.md and mapped causes to dimensions → an adversarial critique that pressure-tested sampling bias and framework overclaims), run 2026-06-21 (run id wf_4c410b6f). Sources are third-party postmortems and reporting (Rekt.news, Chainalysis, CoinDesk, Fortune, regulator filings — CFTC/Fed, audit firms). Loss figures are as reported, not on-chain-verified this session; disputed figures are marked. The corpus is curated, not a census — see the Scope & caveat above.

Appendix — selected incidents (sourced)

IncidentDateReported loss (qualified)Root causeCategorySection that catches itSource
Terra UST/LUNA2022-05~$45–50B mktcap (as reported; broader contagion contested)Reflexive algo peg, zero exogenous collateralAMechanism design (Hard-no)Chainalysis
Iron Finance2021-06~$2B TITAN mktcap (as reported, not realized redemptions)TWAP-lag partial-collateral redemptionAMechanism designFed note
USDR (TangibleDAO)2023-10depeg to ~$0.53; ~$45M mktcapLiquid liabilities, illiquid RWA backing; buffer exhaustedGOracle & liquidity; Backing & redemptionDL News
Main Street msUSD2026-06~71% in 24h; ~$30.5M mktcapSingle off-chain PoR verifier (Accountable) exitedEGovernance & counterparty (new)crypto.news
USDC / Circle (SVB)2023-03recovered; nadir ~$0.87; $3.3B at SVBReserve concentration at a single bankE / GBacking & redemptionCoinDesk
bZx2020-02~$0.95MSingle-source DEX spot oracleBOracle & liquidityRekt
Cream Finance2021-10~$130MManipulable pricePerShare oracle, no TWAPBOracle & liquidityImmunefi
Mango Markets2022-10$117M ($67M returned)Thin perp oracle, no circuit breakerBOracle & liquidityCFTC
Euler Finance2023-03~$197M (largely recovered)donateToReserves missing health checkCSmart-contract surface (partial)Chainalysis
Beanstalk2022-04$182M ($77M net)Flash-loan governance, no timelockDGovernance & counterpartyImmunefi
Radiant Capital2024-10~$50MDPRK supply-chain malware, blind-signingD (OPSEC)Blind spotRadiant post-mortem
Maple / Orthogonal2022-12$36M; pool depositors ~80% lossBorrower misrepresented solvency to off-chain underwriterEGovernance & counterparty (new)CoinDesk
Celsius Network2022-06~$1.2B deficit; $4.7B owedCeFi re-hyp / maturity mismatch, concealed insolvencyEGovernance & counterparty (new)Fortune
Genesis Global2023-01$2.3B to 3AC; ~$1.1B hole papered with IOUIntragroup loan concealed insolvencyEGovernance & counterparty (new)CoinDesk
Goldfinch / Stratos2023-10~$7M on $20M poolNo on-chain covenant on RWA loan sub-allocationEGovernance & counterparty (new)CoinDesk
Tether (USDT)2016–21no depositor loss; CFTC $41M fineReserve attestation misrepresentationEBacking & redemptionCFTC

Bridges (Ronin, Wormhole, Nomad, Harmony, Multichain, BNB Bridge, Poly Network) are in the full workflow corpus (run wf_4c410b6f); omitted from this table pending a dedicated bridge sub-study, since they are the framework’s other major blind spot and warrant their own checklist (recommendation #2).