Core protocol contracts
Deposit/borrow/repay, stake/unstake/slash, swap/liquidity, open/close/liquidate — invariants enforced on every state transition, not assumed.
Development · DeFi
DeFi protocols built to survive stress, not just testnet. Lending, staking, yield, DEXs, perpetuals — audited and capital-efficient, engineered for the day the market turns adversarial.
Corum8 builds production DeFi protocols — lending markets, liquid-staking systems, yield aggregators, DEXs and perpetuals venues. Work spans smart-contract engineering, oracle design, risk parameter modeling, liquidity bootstrapping, independent audit coordination, and the post-launch operations that keep capital-efficient protocols solvent through market stress.
What's included
Deposit/borrow/repay, stake/unstake/slash, swap/liquidity, open/close/liquidate — invariants enforced on every state transition, not assumed.
Chainlink, Pyth and API3 integration with deviation guards, heartbeat checks and protocol-level halts on stale or deviated data.
Explicit priority ordering, partial-liquidation support and fail-safe auto-deleveraging — the most security-critical piece of any over-collateralized protocol.
LTV caps, liquidation thresholds and interest-rate curves set through timelocked, risk-committee-reviewed governance, not ad-hoc dev keys.
LP incentive programs with explicit emission schedules, coordinated with market-makers for concentrated liquidity on key pairs.
Per-market health dashboards, keeper networks and an explicit runbook for protocol halts — production DeFi isn't deploy-and-walk-away.
We book and manage the calendar with two independent tier-one firms, and add formal verification on liquidation, oracle and core accounting logic for material TVL.
Immunefi bounty programs launched at mainnet, backed by static analysis, fuzzing and simulation tooling through the build.
Is this you?
You don't need all of them. One is usually enough to justify the call.
You've identified a specific market inefficiency that permissionless composition solves better than a centralized product.
Your user base is crypto-native and the UX friction of DeFi is genuinely acceptable to them.
Your economic model depends on collateral that can also earn yield elsewhere — composability is core, not decorative.
Censorship resistance or non-sovereign settlement is a real requirement, not available from a centralized counterparty.
You're building in a category where clarity around permissionless finance is a genuine competitive advantage.
Your team has the post-launch capacity for monitoring, parameter adjustment and incident response — not just the launch.
Sectors
The hard problems differ, the engineering discipline doesn't.
Aave-style pools, Morpho-style peer-to-peer, isolated-asset markets.
Validator pools, restaking and liquid-restaking token systems.
Concentrated-liquidity curves, stable swaps and order-book hybrids.
Peer-to-pool and on-chain order-book venues with real risk engines.
Auto-rebalancing vaults that don't leak value to MEV.
Over-collateralized dollar instruments and delta-neutral yield tokens.
Whitelisted market entry with permissionless tokens underneath.
Intent-based rebalancing and settlement across multiple chains.
Process
Threat model, liquidation math, oracle-failure scenarios and parameter sensitivity — written before a line of Solidity.
Core contracts, oracle integration, liquidation engine and governance tooling, engineered against the threat model.
Two independent third-party audits minimum, formal verification on critical components, bug bounty live at mainnet.
Monitoring, keeper infrastructure and an incident runbook for the 3am moment an oracle deviates.
Case studies
A cross-chain yield aggregator and a liquid-staking protocol, each engineered around a distinct failure mode.
A cross-chain yield aggregator needed to rebalance capital across six chains without leaking value to MEV. A custom intent-based rebalancing layer with batched netting across vaults delivered measurably better net yield than the aggregators it competed with.
A liquid-staking protocol for Ethereum validators differentiated on validator-set diversification — randomized delegation across 40+ operators, none above 3% of stake — plus a protocol-owned insurance module. The protocol survived its first slashing event, a validator misconfiguration, with zero customer-facing impact.
Why Corum8
Through the earliest yield protocols, the 2022 cascade, and into a market where institutions finally participate.
Engineering discipline built from watching real protocols break, not from theorizing about what might.
Contracts, oracle integration, keeper infrastructure, governance and monitoring under one roof and one security lead.
No mainnet deployment without at least two independent third-party audits, plus formal verification on critical components.
Market-maker partnerships, crypto-native PR and community building for the governance phase, built alongside the protocol.
The communication and technical runbook for the first time something novel goes wrong is written before launch, not during.
What drives scope
The decisions that swing cost and risk by an order of magnitude happen before the first line of Solidity.
A yield aggregator is lighter than a lending market; a lending market is lighter than a perpetuals venue — each layer compounds the audit surface.
A single-asset, single-oracle protocol is simple; a multi-asset market with heterogeneous oracle sources multiplies the blast radius of a mispriced feed.
Ethereum mainnet for security and TVL, L2s for cost, Solana for throughput — each has a different MEV environment and operational cadence.
Fully on-chain governance with timelocks is a product in itself; admin-multisig is lighter to ship but carries reputational cost.
Two audits from top firms is baseline; formal verification on liquidation, oracle and accounting logic adds real cost and real safety.
A protocol launching with signed market-makers and a treasury-backed LP program is a different product from one figuring out liquidity after launch.
FAQ
DeFi development is the engineering of permissionless financial primitives — lending, borrowing, trading, staking, yield and derivatives — as composable on-chain protocols where the protocol itself is the counterparty. Real builds include core contracts, oracle integration, liquidation engines, parameter governance, liquidity bootstrapping and the monitoring plus incident response that keeps protocols solvent after launch.
Cost is driven mostly by protocol category, oracle dependence, chain choice, governance design, security-review depth and launch liquidity strategy — the client UI is a small slice of the total. A yield aggregator is lighter than a lending market, which is lighter than a perpetuals venue or a cross-chain restaking protocol.
For most protocols, two independent third-party audits plus a strong bug bounty is the appropriate bar; for the most security-critical components — liquidation logic, oracle handling, core accounting — formal verification is increasingly standard. The real question is whether your security posture matches the TVL the protocol will hold, not whether audits alone are theoretically sufficient.
Ethereum mainnet for security, tooling and TVL; Arbitrum, Optimism or Base for cheaper EVM-compatible execution; Solana for throughput-sensitive products; Cosmos app-chains or custom rollups when sovereign infrastructure genuinely helps. The choice depends on where your users already hold assets and how much MEV and bridge-risk complexity you can operationally absorb.
Core smart contracts, oracle integration with failover, a liquidation engine, risk-parameter governance, keeper infrastructure, monitoring and alerts, and client-facing surfaces including a web dApp and subgraph. Two independent third-party audits and formal verification on critical components are standard; the liquidity itself and token-distribution design sit outside the engineering scope.
Every oracle interaction carries explicit deviation checks, heartbeat monitoring and circuit breakers — never just a raw call to a price feed. Chainlink is the default, Pyth covers low-latency assets, API3 covers first-party data, with custom on-chain TWAP as a fallback. Protocols halt rather than transact when oracles deviate beyond threshold — oracle failure is the single most common DeFi exploit vector.
Yes — Rust on Solana, Move on Aptos and Sui, Solidity on EVM, CosmWasm on Cosmos. The financial mechanics translate across chains; the tooling, MEV environment and operational cadence differ. The right choice depends on target audience and product category, not team familiarity.
Liquidation logic gets tested against adversarial keeper behavior and simulated gas spikes, not just happy-path testnet conditions. Gas spikes during volatile markets can make liquidations unprofitable for keepers, leaving bad debt on the books — priority ordering, partial liquidations and fail-safe auto-deleveraging are designed in from the start, not patched in after a bad day.
Protocols holding material stablecoin exposure need oracle caps, depeg detection and automatic halts built in — treating any stablecoin as a hard peg is how protocols end up insolvent when the peg breaks. USDC, USDT and DAI have all depegged under specific market conditions; the design has to assume it happens again.
On-chain earns its place wherever trustlessness, composability or verifiable settlement are the point. Lending, AMMs, staking and anything where users need to verify the rules themselves belong there. Parts of a product that are purely operational — dashboards, notifications, analytics — usually sit off-chain where they are cheaper and faster to iterate. Most strong protocols are a mix, and getting that split right early is one of the higher-leverage decisions in the build. We map it with you before any contract is written.