Stop locking $150 to borrow $100. Arbora gives every wallet an onchain credit score — collateral down to 75% — lending in Paxos USDG on Arbitrum.


Live at arbora-protocol.vercel.app
Aave, Compound, MakerDAO — every major DeFi lender applies the same blunt rule: post 150%+ collateral or don't borrow. A wallet that has never missed a repayment across two years of active DeFi usage is treated identically to a wallet created this morning. This is not a protocol design failure — it is an information gap. Protocols overcollateralize because they cannot distinguish creditworthy borrowers from non-creditworthy ones. The capital cost is concrete: borrowing $10,000 USDG requires $15,000 in ETH, and the $5,000 excess earns nothing locked in a contract that cannot tell good borrowers from bad. Traditional finance solved this decades ago with credit scoring — FICO models default probability from historical behavior using logistic regression with fully interpretable coefficients. DeFi has no equivalent underwriting infrastructure. Arbitrum doesn't just need faster settlement; it needs underwriting. Arbora builds it.
Arbora is a two-source composite credit scoring system deployed on Arbitrum Sepolia (chain ID 421614), with Paxos USDG (Global Dollar, 6 decimals) as the lending/debt asset and native ETH as collateral. The composite score drives a continuous piecewise-linear collateral curve from 150% down to 75% — replacing fixed overcollateralization with risk-priced terms. The same bytecode runs unchanged on Robinhood Chain (Arbitrum Orbit L2, mainnet chain ID 4663), where USDG natively lives.
SIGNAL 1 — ONCHAIN BEHAVIORAL SCORECARD
A FICO/VantageScore-methodology logistic regression trained on 115,687 real onchain DeFi borrowers (15,889 liquidated, 13.7%) labeled from empirical liquidation events across Aave v3 and Radiant, spanning Arbitrum, Ethereum, Optimism, Polygon and Base on Allium's institutional SQL warehouse.
• 11 interpretable features across three categories — lending behavior (protocol activity days, repayment consistency, repayment count, distinct assets borrowed), financial profile (portfolio value, stablecoin allocation, 90-day accumulation trend), and cross-chain breadth (tx volume, DEX activity, chains used, bridge experience)
• FICO scorecard method: each feature binned into 3–5 risk tiers, lowest-risk bin as dropped reference category → 24 one-hot columns → L2-regularized logistic regression (balanced weights, 5-fold stratified CV) → P(not liquidated) scaled to 0–100
• Four training iterations to remove economically contradictory coefficient signs (round 2 hit AUC 0.845 but had 25 sign flags; final model: AUC 0.8182, 0 serious sign flags, frozen)
• Performance: AUC-ROC 0.8182 · Precision 0.9508 · Recall 0.7208 · F1 0.8200 · median score 71 (non-liquidated) vs 29 (liquidated)
• Dominant coefficient: borrowing activity 15+ days → −1.23
• Every contribution explainable in one sentence — regulatory-grade transparency no black-box model can match
SIGNAL 2 — OFFCHAIN CREDIT ATTESTATION (ZKREDIT)
Traditional FICO scores attested onchain without exposing personal data (simulated; production swaps the admin writer for a Brevis/Primus ZK verifier with zero data-model change). Each attestation carries a deterministic identityHash: rebind to a new wallet and the full onchain credit history follows the person, not the key — sybil resistance where a fresh wallet inherits the old record.
COMPOSITE MATH (asymmetric by design)
• No attestation (thin-file): composite = onchainScore × 0.50 — caps thin-file wallets so one borrow/repay can't unlock institutional terms
• With attestation: baseline = offchain × 0.70, boost = onchain × 0.40, composite = min(100, baseline + boost)
• FICO 300–850 linearly maps to 0–100; all multipliers are admin-settable uint8s capped at 100
• Why two signals: they measure structurally different risk domains (FICO sees bills/utilization/income; onchain sees health-factor management/volatility survival/protocol behavior). Concrete example: onchain score 80 goes from 130% collateral (no FICO) → 95% (FICO 650) → 75% (FICO 850). The attestation unlocks sub-100% terms.
SMART CONTRACTS — LIVE ON ARBITRUM SEPOLIA (deployed 2026-09-25)
• OffchainAttestationRegistry — 0x812a283c68F76E169B1DbdBe23434Bc47f11a897 — EIP-712 attestations, identity-hash sybil resistance, historical-score carryover on rebind
• CreditOracle — 0x93Fb575277eb28f5C0b3987aC233534cF8d11E8A — onchain scores + composite math computed on-read
• LendingPool — 0xf3b1381013f6475b659b9468163ff233534cF8d11E8A... (see README for full) — USDG debt, ETH collateral, deposit/borrow/repay/liquidate
• USDG (Paxos Global Dollar) — 0xFFC95faa3d63Cde504a05B567C600B78C0b41892 (6 decimals, usdgScale handling)
• AdminPriceOracle — 0xad4b47A38167FBA59CD2b4F63Bdb29090b4EAB22 — pluggable IPriceOracle (Chainlink adapter in production), 7-day max price age (capped 30d)
Collateral curve breakpoints: score 0–20 → 150% · 50 → 120% · 70 → 100% · 85 → 85% · 100 → 75% (owner-re-tunable via setCollateralCurve; ratio locked at origination). Liquidation: Aave-style partial with 5% bonus (capped 20%); health factor = collateralUSD/requiredUSD, < 100% liquidatable. Safety: ReentrancyGuard, SafeERC20, Pausable (pause never blocks withdraw/repay), custom errors, NatSpec throughout.
TESTING: 122 Foundry tests, 6 suites, 0 failures (incl. fuzzing on curve interpolation and score arithmetic). forge lint clean. Gas: borrow ≈186k · deposit ≈114k · liquidate ≈96k · LendingPool runtime ≈9.5 kB (24 kB limit).
POST /score · POST /score/stream (SSE) · GET /health
• Pay-per-score gate (x402-style): uncached queries cost 0.01 USDG — API replies 402 Payment Required → client sends USDG transfer → backend verifies the tx onchain (payer, treasury, amount ≥ 10000 atomic) → scores → tx marked one-time/replay-guarded. Cache is checked first, so demo wallets stay free; /health is never gated.
• Three-tier data sourcing, never silently degraded: Tier 0 live Allium SQL (~90s, two concurrent queries: Arbitrum lending + multichain/crosschain) → Tier 1 cached (real captured features) → Tier 2 deterministic synthetic (SHA-256 of address). Every response carries data_source: live/cached/synthetic.
• Onchain push: EIP-1559 tx → CreditOracle.setOnchainScore → reads back composite score + collateral ratio; unconfigured setups skip gracefully with explanatory nulls.
• Thin-file handling (before push): no activity → 0/no push · no lending history → ×0.6 · <2 active lending days → ×0.8 · full history → 1.0×
• SSE progress events mirror real backend stages (arbitrum → crosschain → model → push → result), driving a live 5-chain network map in the UI.
4-step credit-application flow (wallet lookup → live data collection → scoring → onchain publication); composite gauge, factor table, Experian-style full credit report (tier ratings, benchmarks vs top wallets, improvement tips); attestation simulator re-rendering live from chain reads; full lending desk (LP deposit/withdraw, borrower borrow/repay, liquidator health watch); network-enforced Arbitrum Sepolia with one-click chain switching; EIP-1559 tx helper preventing stale-gas failures.
WORKED EXAMPLE (demo wallet): onchain score 44 + FICO-780 attestation → composite 77 → 93% collateral → borrow → repay → health factor 1.32x → 1.38x.
WHY IT FITS THE TRACK: everything deploys and runs on Arbitrum today · Paxos USDG is the pool asset, debt unit, AND revenue unit (pay-per-score) · fully zero-config demo mode · live at arbora-protocol.vercel.app with full docs (overview, setup guide, architecture, whitepaper, development log).
THE THESIS: the trillion-dollar lending market won't move to DeFi until DeFi can underwrite with the same rigor the real world does. Composable next: any EVM protocol can query CreditOracle — Arbora becomes credit-scoring infrastructure, with onchain hard inquiries mirroring FICO.