Caroline Ellison at Manifund: Accountability Without an Audit Trail

PowerPomp
Price Analysis

Caroline Ellison, the former CEO of Alameda Research, has joined Manifund, a nonprofit donation platform operating inside the effective-altruism and AI-safety funding space. The reported timeline is specific: a July trial period, an August transition to full-time, a September 12 start date. Her two-year sentence began in November 2024, with early release projected for January 2026. Those are the facts.

Everything else in circulation is narrative. And narrative is the failure mode this industry keeps paying for.

No independent financial audit of Manifund's donation flows has been published. No wallet addresses have been disclosed. There is no public description of who authorizes disbursements, how signing authority is separated from grant decisions, or what prevents a single compromised keyholder from rerouting funds. For a platform that now employs a person convicted of fraud in connection with the largest collapse in crypto's short history, that gap is not a governance footnote. It is the entire risk. Proof is required, not promise — and here there is no proof to examine.

Caroline Ellison at Manifund: Accountability Without an Audit Trail

Context: a collapse that never closed its books

The FTX and Alameda failure is not a story that ended with a verdict. It is an open balance sheet. Alameda Research functioned as the market-making arm of an exchange that commingled customer deposits with proprietary trading capital. When the mismatch surfaced in November 2022, roughly $8 billion in customer obligations vaporized, and the resulting bankruptcy became the reference case for counterparty risk in crypto.

Ellison pleaded guilty to seven counts, cooperated with prosecutors, and testified against Sam Bankman-Fried. Her cooperation was material; the government's case leaned on it. She was sentenced to two years and began serving in November 2024. That record matters, and I will return to it.

Manifund is a different kind of entity. It is a donation platform, not a protocol. It sits in the effective-altruism funding ecosystem — a network of foundations, grantmakers, and individual donors directing capital toward AI-safety research, biosecurity, and long-termist causes. It is small, it is young, and it has no obligation to publish anything a crypto auditor would recognize as a disclosure package.

That last sentence is the whole article.

The reason this deserves a risk review rather than a shrug is structural. The EA and AI-safety funding network distributed well over a billion dollars in recent years, much of it from a single source that no longer exists. The ecosystem inherited a set of relationships, expectations, and reputational dependencies from the FTX collapse without ever building the governance layer that would have survived it. Manifund is a live test of whether that layer exists.

Core: the disclosure standard nobody applied

I have audited smart contracts where the code ran 14,000 lines of Solidity and the whitepaper quietly omitted the fee model. That was 2018, on the 0x Protocol v2 review. I found three integer-overflow vulnerabilities in the exchange logic and a fee structure that could not survive its own economics. The team halted development for two weeks to patch. The lesson was never that bugs exist. The lesson was that a project's stated architecture and its operational architecture are two different documents, and only one of them is real.

Manifund is now the operational document. Nobody has read it.

Consider what a comparable disclosure package would have to contain. For any custody-bearing platform, an auditor asks four questions before anything else:

| Control Domain | Standard Requirement | Manifund Public Disclosure | |---|---|---| | Key custody | Named multisig, threshold, keyholder identities | Not disclosed | | Disbursement authority | Segregation of grant approval from payment execution | Not disclosed | | Conflict of interest | Register of insider relationships and grant decisions | Not disclosed | | Financial reporting | Audited statements, inflow/outflow reconciliation | Not disclosed |

Caroline Ellison at Manifund: Accountability Without an Audit Trail

This is not me inventing a standard. It is the baseline any DeFi treasury worth $10 million would be asked to meet — and often fails. Manifund is not asked, because it is legally a nonprofit and culturally an EA project, and both labels carry an implicit trust premium that no code has ever earned.

Systemic risk hides in the complexity of the code — and it hides even better in the simplicity of a good reputation.

Here is the technical point the coverage has missed entirely. Ellison's value to an AI-safety grantmaker is not administrative. It is judgment: the capacity to evaluate quantitative models, stress-test risk claims, and decide which research gets funded. That is a decision-making function inside a capital-allocation pipeline. In any regulated fund, someone with her conviction record would face a restricted-activity order, a supervisory requirement, and a documented pre-approval chain for transactions above a threshold. In the EA grantmaking ecosystem, none of that machinery exists. There is no regulator, no self-regulatory organization, no disclosure regime, no threshold.

There is only the question of whether donors care. Structurally, they cannot — because they do not have the information required to care.

The recovery math is worth stating plainly, because it is the clearest evidence that this ecosystem does not reconcile its own numbers. The FTX estate has reported recoveries exceeding 100% of petition-date customer claims in several classes. That figure is real and it is misleading. Claims were valued in November 2022 dollars, during the deepest drawdown of the cycle, and distributions arrive years later in appreciated assets. A nominal 119% recovery, discounted for time and priced against the market value of the assets being returned, is a materially lower real return. No donor dashboard reports it that way. No grantmaker publishes the reconciliation. The most celebrated outcome in the aftermath of the collapse is a nominal figure that has never been audited against a real one.

Now ask what Manifund publishes about the money it routes. The answer is nothing comparable. A platform executing donations at scale with no disclosed custody model, no named signers, and no reconciliation is not a low-risk counterparty because it is small. It is a low-visibility counterparty because it is small, and visibility is the only variable that matters.

Let me be precise about what Ellison is and is not. She is not accused of any new misconduct. She served as a cooperating witness, which is the single most valuable action a defendant can take in a fraud case of that scale. Her testimony was corroborated and the court credited it. Under the standard I apply to code, she passed the audit that mattered: she produced evidence, not excuses.

But a clean legal outcome and a clean control environment are different audit opinions. The first is settled. The second is unexamined.

The counterintuitive angle: the bulls have a point

The instinct on a desk like mine is to file this under reputational arbitrage — a convicted fraud executive buying back legitimacy through charity, using a nonprofit's halo to launder a resume. That reading is cheap and it is partly wrong.

The strongest version of the bull case is this. The EA and AI-safety funding ecosystem is chronically short of people who can evaluate financial risk at scale. Most grantmakers in that world are researchers and philosophers, not market practitioners. Ellison's skill set — market microstructure, model risk, quantitative evaluation under adversarial conditions — is genuinely scarce there. If the objective is reducing catastrophic risk, hiring the best available quantitative evaluator is not a concession to reputation. It is a rational allocation of talent.

That argument would hold if the hiring process were auditable. It is not. There is no published role definition, no disclosed decision-maker, no conflict-of-interest review, no independent approval. The bull case rests entirely on the quality of a process that has released no evidence of its quality. That is the circularity: a process cannot validate itself by pointing at its own outcome.

And the bulls underrate a second point. The EA ecosystem's defining vulnerability is not a lack of talent. It is a lack of adversarial review. The culture is optimized for consensus — everyone is aligned on the mission, so nobody runs the red team. The FTX collapse already demonstrated what happens when that culture meets a leader who is trusted rather than audited. Absorbing a figure from that collapse without adding the audit function that was missing does not repair the pattern. It reproduces it at smaller scale.

Where this goes

Manifund owes no public disclosure. That is the point, and it is also the risk. If the platform publishes an audited control report — key custody, disbursement authority, conflict register, annual financials — the concern evaporates and the hire becomes defensible on the merits. The talent argument is legitimate. The scarcity is real. The job itself is not the problem.

If it does not publish, then the only thing distinguishing this arrangement from the arrangements that failed in 2022 is that the amounts are smaller and the donors are more polite. There is no regulator watching a nonprofit move research grants, and there will not be one. Accountability here is voluntary or it is fictional.

The question is not whether Caroline Ellison deserves a second career. She served her sentence and earned her cooperation credit. The question is whether the ecosystem that hired her can produce one document that proves, rather than promises, that the money moves the way it says it moves. If it cannot, then Manifund has not hired a risk evaluator. It has hired a risk.