C

Chaos Labs

Chaos Labs builds automated risk management infrastructure for on chain lending and derivatives markets. Its Edge Risk Oracles compute and push parameter changes in real time, adjusting interest rates, loan to value ratios and liquidation thresholds in response to volatility and liquidity conditions, securing more than 2.1 billion dollars across 88 markets on an oracle network the firm states has processed over 70 billion dollars in transactions.

The design is deliberately bounded: automated adjustments may only move within limits approved in advance through protocol governance, and the system includes a kill switch able to pause a market and block new deposits and loans during a disruption such as a stablecoin depeg. The firm reports cutting the time to change a risk parameter from roughly 96 hours of multi team governance and multisignature coordination to under a minute.

It is building the complete risk architecture for Horizon, an institutional platform developed with Aave Labs for tokenised money market funds and United States Treasuries, work that has to accommodate daily and weekly net asset value cycles, overnight and weekend market closures and custodial coordination on liquidations. Chaos AI is a multi agent research system built on Langchain and trained on four years of public and proprietary data, and Chaos Vaults extends the firm into curated yield for institutions. Founded in 2021 in New York by chief executive Omer Goldberg and Julian Lindinger, it has raised 75 million dollars from investors including Galaxy, Haun Ventures and PayPal Ventures.

Last VerifiedAugust 19, 2026
Compare Chaos Labs with other vendors
Founded
2021
Headquarters
New York, New York, United States
Website
chaoslabs.xyz
Categories
crypto-and-digital-assets, capital-markets-ai
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

Risk models, oracles and agent systems are the whole company and there is nothing underneath them. The Edge Risk Oracles exist to compute parameter changes that no person could produce at the required cadence, across what the chief executive describes as thousands of parameters spread over roughly a hundred money markets, each needing to move with volatile conditions. Chaos AI is a multi agent research system built on Langchain and trained on four years of public and proprietary data.

There is no data feed business, no consulting practice and no earlier product that would survive the removal of the modelling layer; what would remain is the governance process the firm was built to replace.

Autonomy and Oversight Model
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a person checks it are all published: modes, thresholds, sampling or audit controls, and the route a case takes to human review.
Vendor Published

The most complete control design encountered in this pocket, and the only one that includes a described failsafe. Automated parameter changes are constrained to move only within bounds approved in advance through protocol governance, so the action space is bounded by a party other than the vendor and the bound is set before the automation runs.

Beyond that sits an explicit kill switch and circuit breaker able to pause a market and block new deposits and loans during a disruption, and the firm illustrates it against a specific historical event, the March 2023 stablecoin depeg, rather than describing it abstractly. That combination, a pre approved bounded action space plus a named stop mechanism, is what the rest of this pocket is missing, and it is published rather than asserted. What is still absent is any statement of who can trigger the stop, how quickly, and what happens if the oracle itself is the component that fails.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

Method is described in operational detail and the models behind it are not. The published work sets out how the risk architecture functions, including which parameters are automated, what conditions drive an adjustment, and how the design accommodates constraints that do not exist in crypto native markets, such as daily or weekly net asset value cycles, overnight and weekend closures, and liquidations requiring custodial coordination.

Individual asset risk reviews are published combining quantitative and qualitative analysis. That gives an institution a real account of the reasoning. It does not give it validation material: no back test of parameter recommendations against realised outcomes, no calibration evidence, no accuracy measure, no description of the simulation or model architecture beyond an orchestration framework name, and no artificial intelligence management system certification.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Named deployments, hard aggregates and one genuinely quantified operational result. The firm reports reducing the time to change a risk parameter from roughly 96 hours, which previously required four teams to write contracts, raise a governance proposal, secure funding, deploy and sign multisignatures, to under a minute. That is a measurable before and after rather than a claim of value.

Around it: more than 2.1 billion dollars secured across 88 markets, an oracle network stated to have processed over 70 billion dollars in transactions, and more than 300 million dollars secured at a single named lending deployment. Third party executives are quoted by name, including the founder of the counterparty behind its largest reference deployment. Investors carry weight, with 75 million dollars raised across two rounds from Galaxy, Haun Ventures and PayPal Ventures.

One caveat is recorded rather than resolved: independent research published in April 2026 states that the flagship protocol engagement ended during 2026, while the firm's own material dated March and April 2026 describes it as that protocol's primary risk provider. Both may be true at different points in the year and neither source settles it.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

A dual position of a shape not previously recorded in this index, and the firm publicises rather than conceals it. It sets the risk parameters governing lending markets, including the leverage limits and liquidation thresholds those markets enforce, and it is simultaneously building autonomous agents that take positions in those same markets, illustrated by its own chief executive with an agent independently executing a nineteen step sequence to open a six times levered position on the largest protocol it advises.

So the party writing the rules of a market is also building the participant that trades inside it. Nothing describes any separation between the risk advisory work and the agent development, whether parameter changes are visible to the agent systems ahead of publication, or how a conflict between protecting a protocol and the performance of an agent operating on it would be resolved. Separately, nothing states whether the proprietary knowledge base underlying the research product incorporates data obtained through risk management engagements.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No privacy policy detail, data processing agreement, subprocessor list or retention schedule was located. Direct personal data exposure is limited, since the risk oracle products operate on market and protocol data rather than on identified individuals.

The research assistant is the part that raises the question, because it is offered as an interface users query and it is trained on a proprietary knowledge base, and nothing states whether user queries are retained, whether they inform subsequent training, or how an institution's research activity is separated from data serving other users.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No certification, attestation, security page or trust centre was located in the material reviewed. The absence is recorded as unlocated rather than proven, on the same basis applied elsewhere in this index, since a dedicated compliance page can carry an entire posture without being linked from product or research pages.

What can be said is that a firm whose outputs directly move liquidation thresholds across 88 markets, and which describes its own oracles as securing billions, publishes nothing about how the infrastructure producing those outputs is itself secured, audited or access controlled.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The firm holds no financial licence or registration, which is the correct posture for an infrastructure supplier and carries no penalty. Its institutional work is structured accordingly: on the platform it is building for tokenised money market funds and Treasuries it supplies the risk architecture while another party holds the customer relationship and any regulatory obligation. No sandbox participation, regulator engagement or supervised test was located. Nothing states a position under the European artificial intelligence regime despite operating automated decision systems that determine credit terms.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing, differential outcome analysis or model governance disclosure was located, and two specific exposures sit unexamined. The risk oracles set loan to value ratios and liquidation thresholds, which is a direct determination of which borrowers are liquidated and when, and nothing addresses whether those adjustments fall unevenly across position sizes, collateral types or venues.

Separately, the research assistant is presented as delivering informational parity with the most sophisticated traders while being trained on proprietary data unavailable elsewhere, so a product framed as democratising access is built on an information advantage whose distribution is set entirely by who is granted access.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No liability position, error rate, remediation commitment or appeal route is published, against a product whose normal operation causes irreversible financial events. An automated tightening of a liquidation threshold liquidates positions, and the borrower affected has no relationship with the firm, no notice that a model rather than a governance vote moved the parameter, and no route to have the decision reviewed.

The published material is asymmetric on exactly this point: it describes in specific terms a past crisis in which the circuit breaker would have protected users, and says nothing about what happens or who answers when an automated adjustment is wrong.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Partial disclosure at an unusual layer and none at the layer that matters. The research assistant is stated to use Langchain for multi agent orchestration, which is more framework disclosure than most vendors in this index provide, and it stops there. No model provider, family, version or hosting arrangement is named for that system or for the models driving the risk oracles, and nothing states whether an external provider processes the proprietary data the assistant is trained on. For a product whose outputs change lending parameters automatically, the question of whose model computes the adjustment is unanswered.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

The integration sits inside the execution path rather than beside it, which is as deep as this category goes. Risk oracles are wired into both the governance and the execution layers of the protocols that use them, so an oracle output becomes a live parameter change rather than a recommendation someone actions.

One deployment uses the firm's price oracles as its exclusive feed provider, another integrates proof of reserves at network level for real time verification of bridged asset backing, and the firm is building the risk framework for a derivatives appchain from the ground up. Coverage spans 88 markets across multiple networks, and the Horizon work requires integration with custodial processes and net asset value schedules that sit entirely outside the chain.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting regions, residency commitments or tenancy model are published for the off chain infrastructure. The oracle network publishes outputs on chain across multiple named networks, which makes the delivered result inspectable by construction, and says nothing about where the computation producing it runs. An institution using the risk architecture inside a jurisdiction with localisation requirements would find nothing addressing where the models, the data pipeline or the research system are hosted.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, tier structure or billing basis is published for any product line. The honest qualification is the same one that applies to peers whose work is commissioned through protocol governance: those engagements carry publicly visible budgets in governance proposals, so the economics of at least part of the business are discoverable by someone who knows where to look.

That makes the position undocumented rather than concealed, and it still leaves an institutional buyer of the risk architecture or the research product with no published basis for what it would cost or how it would be charged.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Substantial scale inside one buyer type, with the institutional expansion announced and only partly evidenced. Named deployments are numerous and specific: Aave, GMX, Renzo, Benqi across lending markets securing more than 300 million dollars on Avalanche, Avalanche itself for proof of reserves, the derivatives appchain Ethereal, and Tydro as the first whitelabel deployment to use the firm's price oracles exclusively.

Aggregate figures are stated consistently at more than 2.1 billion dollars secured across 88 markets. Every one of those counterparties is a protocol or a network rather than a financial institution. The institutional side rests on Horizon, built with Aave Labs for tokenised money market funds and Treasuries, and on a curated vault product positioned for institutions, and no institutional customer is yet named for either.

Alternatives to Chaos Labs

The closest documented capability profiles to Chaos Labs in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Security Certifications and Trust Center where Chaos Labs does not

A lighter documented profile than Chaos Labs

Documents Security Certifications and Trust Center where Chaos Labs does not

Documents Security Certifications and Trust Center where Chaos Labs does not

Documents Regulatory Status and Licensure and Model Supply Chain Disclosure where Chaos Labs does not

Documents GLBA and Data Privacy Posture and Regulatory Status and Licensure, among others where Chaos Labs does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746