Factor encyclopedia
184 evidence factors across 13 categories. Click any factor for methodology, measurement, and which protocols carry it.
Category
Severity
ID★FactorCategoryCarried
RD-F-001★Audit scope mismatchCode & audits0 of 0RD-F-002Audit recencyCode & audits0 of 0RD-F-003Resolved-without-proof findingsCode & audits0 of 0RD-F-004Audit countCode & audits0 of 0RD-F-005Audit firm tierCode & audits0 of 0RD-F-006Audit-to-deploy gapCode & audits0 of 0RD-F-007Bug bounty presence & max payoutCode & audits0 of 0RD-F-008Ignored bounty disclosureCode & audits0 of 0RD-F-009Formal verification coverageCode & audits0 of 0RD-F-010Static-analyzer high-severity countCode & audits0 of 0RD-F-011SELFDESTRUCT reachable from non-admin pathCode & audits0 of 0RD-F-012delegatecall with user-controlled targetCode & audits0 of 0RD-F-013Arbitrary call with user-controlled targetCode & audits0 of 0RD-F-014Reentrancy guard on external-calling functionsCode & audits0 of 0RD-F-015ERC-777/1155/721 hook without reentrancy guardCode & audits0 of 0RD-F-016Divide-before-multiply patternCode & audits0 of 0RD-F-017Mixed-decimals math without explicit scalingCode & audits0 of 0RD-F-018Signed/unsigned arithmetic confusionCode & audits0 of 0RD-F-019ecrecover zero-address return uncheckedCode & audits0 of 0RD-F-020EIP-712 domain separator missing chainIdCode & audits0 of 0RD-F-021UUPS _authorizeUpgrade correctly permissionedCode & audits0 of 0RD-F-022★Public initialize() without initializer modifierCode & audits0 of 0RD-F-023Constructor calls _disableInitializers()Code & audits0 of 0RD-F-024Code complexity vs audit coverageCode & audits0 of 0RD-F-025Admin key custody typeGovernance & admin0 of 0RD-F-026Upgrade multisig signer configuration (M/N)Governance & admin0 of 0RD-F-027★Single admin EOAGovernance & admin0 of 0RD-F-028★Low-threshold multisig vs TVLGovernance & admin0 of 0RD-F-029Multisig signers co-hostedGovernance & admin0 of 0RD-F-030Hot-wallet signer flagGovernance & admin0 of 0RD-F-031Signer rotation recencyGovernance & admin0 of 0RD-F-032Timelock duration on upgradesGovernance & admin0 of 0RD-F-033Timelock on sensitive actionsGovernance & admin0 of 0RD-F-034Guardian/pause-keeper distinct from upgraderGovernance & admin0 of 0RD-F-035Role separation: upgrade ≠ fee ≠ oracleGovernance & admin0 of 0RD-F-036★Flash-loanable voting weightGovernance & admin0 of 0RD-F-037Quorum achievable via single-entity flash loanGovernance & admin0 of 0RD-F-038Proposal execution delay < 24hGovernance & admin0 of 0RD-F-039★delegatecall/call in proposal execution without allowlistGovernance & admin0 of 0RD-F-040Emergency-veto multisig presentGovernance & admin0 of 0RD-F-041★Rescue/emergencyWithdraw without timelockGovernance & admin0 of 0RD-F-042★Admin has mint() with unlimited maxGovernance & admin0 of 0RD-F-043★Admin = deployer EOA after 7 daysGovernance & admin0 of 0RD-F-044Admin wallet interacts with flagged addressesGovernance & admin0 of 0RD-F-045Constructor args match governance proposalGovernance & admin0 of 0RD-F-046★Contract unverified on Etherscan/SourcifyGovernance & admin0 of 0RD-F-047Governance token concentration (Gini)Governance & admin0 of 0RD-F-048Oracle providers usedOracle & external dependencies0 of 0RD-F-049Oracle role per assetOracle & external dependencies0 of 0RD-F-050Dependency graph (protocols depended upon)Oracle & external dependencies0 of 0RD-F-051Fallback behavior on oracle failureOracle & external dependencies0 of 0RD-F-052Breakage analysis per dependencyOracle & external dependencies0 of 0RD-F-053★Oracle source = spot DEX pool (no TWAP)Oracle & external dependencies0 of 0RD-F-054TWAP window durationOracle & external dependencies0 of 0RD-F-055Oracle pool depth (USD)Oracle & external dependencies0 of 0RD-F-056Single-pool oracle (no medianization)Oracle & external dependencies0 of 0RD-F-057Circuit breaker on price deviationOracle & external dependencies0 of 0RD-F-058Max-deviation threshold (bps)Oracle & external dependencies0 of 0RD-F-059Oracle staleness check presentOracle & external dependencies0 of 0RD-F-060Chainlink aggregator min/max bound misconfigOracle & external dependencies0 of 0RD-F-061LP token balanceOf used for pricingOracle & external dependencies0 of 0RD-F-062External keeper/relayer not redundantOracle & external dependencies0 of 0RD-F-063TVL (current + 30d trend)Economic risk0 of 0RD-F-064TVL concentration (top-10 wallet share)Economic risk0 of 0RD-F-065Liquidity depth per major assetEconomic risk0 of 0RD-F-066Utilization rate (lending protocols)Economic risk0 of 0RD-F-067Historical bad-debt eventsEconomic risk0 of 0RD-F-068Collateralization under stressEconomic risk0 of 0RD-F-069Algorithmic / under-collateralized stablecoinEconomic risk0 of 0RD-F-070★Empty cToken-style market (zero supply/borrow)Economic risk0 of 0RD-F-071Seed-deposit requirement for new market listingEconomic risk0 of 0RD-F-072Market-listing governance thresholdEconomic risk0 of 0RD-F-073Oracle-manipulation-proof borrow capEconomic risk0 of 0RD-F-074ERC-4626 virtual-share offset (OZ ≥4.9)Economic risk0 of 0RD-F-075First-depositor / share-inflation guardEconomic risk0 of 0RD-F-076Protocol age (days)Operational history0 of 0RD-F-077Prior exploit countOperational history0 of 0RD-F-078Chronic-exploit flag (≥3 incidents)Operational history0 of 0RD-F-079Same-root-cause repeat exploitOperational history0 of 0RD-F-080Days since last exploitOperational history0 of 0RD-F-081Post-exploit response scoreOperational history0 of 0RD-F-082Post-mortem published within 30 daysOperational history0 of 0RD-F-083Auditor re-engaged after last exploitOperational history0 of 0RD-F-084TVL stability (CoV over 90d)Operational history0 of 0RD-F-085Incident response time (minutes)Operational history0 of 0RD-F-086Pause activations (trailing 12 months)Operational history0 of 0RD-F-087Pause > 7 consecutive daysOperational history0 of 0RD-F-088Re-deployed to new addresses in last yearOperational history0 of 0RD-F-089Insurance coverage activeOperational history0 of 0RD-F-090Mixer withdrawal → protocol interactionReal-time signals0 of 0RD-F-091Partial-drain test transactionsReal-time signals0 of 0RD-F-092Unusual mempool pattern from deployer walletReal-time signals0 of 0RD-F-093Abnormal gas-price willingness from attacker walletReal-time signals0 of 0RD-F-094New contract with similar bytecode to exploit templateReal-time signals0 of 0RD-F-095Known-exploit function-selector replayReal-time signals0 of 0RD-F-096New ERC-20 approval to unverified contract from whaleReal-time signals0 of 0RD-F-097Sybil surge of identical-pattern transactionsReal-time signals0 of 0RD-F-098TVL anomaly — % drop in <1hReal-time signals0 of 0RD-F-099Oracle price deviation >X% from secondaryReal-time signals0 of 0RD-F-100Flash loan >$10M targeting protocol tokensReal-time signals0 of 0RD-F-101Large governance proposal queuedReal-time signals0 of 0RD-F-102Admin/upgrade transaction in mempoolReal-time signals0 of 0RD-F-103Bridge signer-set change proposed/executedReal-time signals0 of 0RD-F-104Stablecoin depeg >2% on shared-LP venueReal-time signals0 of 0RD-F-105DNS/CDN/frontend hash driftReal-time signals0 of 0RD-F-106Cross-chain bridge unverified mint patternReal-time signals0 of 0RD-F-107Admin EOA signing from new geography/deviceReal-time signals0 of 0RD-F-108GitHub force-push to sensitive branchReal-time signals0 of 0RD-F-109Social-media impersonation scam spikeReal-time signals0 of 0RD-F-110Unusual pending/executed proposal ratioReal-time signals0 of 0RD-F-111Team doxx statusDev identity & insider risk0 of 0RD-F-112Team public accountability surfaceDev identity & insider risk0 of 0RD-F-113Team other-protocol involvement historyDev identity & insider risk0 of 0RD-F-114Deployer address prior on-chain historyDev identity & insider risk0 of 0RD-F-115Prior rug/exit-scam affiliationDev identity & insider risk0 of 0RD-F-116Contributor tenure at admin-permissioned PRDev identity & insider risk0 of 0RD-F-117ENS/NameStone identity bound to deployerDev identity & insider risk0 of 0RD-F-118Handle reuse across failed/rugged projectsDev identity & insider risk0 of 0RD-F-119Commit timezone consistent with stated geographyDev identity & insider risk0 of 0RD-F-120Video-off/voice-consistency flagDev identity & insider risk0 of 0RD-F-121Contributor OSINT depth scoreDev identity & insider risk0 of 0RD-F-122Contributor paid to DPRK-cluster walletDev identity & insider risk0 of 0RD-F-123★Sudden admin-rescue/ACL change without discussionDev identity & insider risk0 of 0RD-F-124★Deployer wallet mixer-funded within 30 daysDev identity & insider risk0 of 0RD-F-125★Deployer linked within 3 hops to DPRK/LazarusDev identity & insider risk0 of 0RD-F-126Is-a-fork-ofFork / dependency lineage0 of 0RD-F-127Upstream patch not mergedFork / dependency lineage0 of 0RD-F-128Upstream vulnerability disclosure (last 90d)Fork / dependency lineage0 of 0RD-F-129Code divergence from upstream (%)Fork / dependency lineage0 of 0RD-F-130Fork depth (generations from original audit)Fork / dependency lineage0 of 0RD-F-131Fork retains upstream audit coverageFork / dependency lineage0 of 0RD-F-132Fork has different economic parameters than upstreamFork / dependency lineage0 of 0RD-F-133Dependency manifest uses unpinned versionsFork / dependency lineage0 of 0RD-F-134Dependency had malicious-release incident (last 90d)Fork / dependency lineage0 of 0RD-F-135Shared-library version with known-vuln statusFork / dependency lineage0 of 0RD-F-136Deployed bytecode matches signed release tagPost-deploy hygiene & change mgmt0 of 0RD-F-137Upgrade frequency (per 90 days)Post-deploy hygiene & change mgmt0 of 0RD-F-138Hot-patch deploys without timelock (last 30 days)Post-deploy hygiene & change mgmt0 of 0RD-F-139★Post-audit code changes without re-auditPost-deploy hygiene & change mgmt0 of 0RD-F-140Fix-merged-but-not-deployed gapPost-deploy hygiene & change mgmt0 of 0RD-F-141Test-mode parameters in deployPost-deploy hygiene & change mgmt0 of 0RD-F-142Storage-layout collision risk across upgradesPost-deploy hygiene & change mgmt0 of 0RD-F-143★Reinitializable implementation (no _disableInitializers)Post-deploy hygiene & change mgmt0 of 0RD-F-144CREATE2 factory permits same-address redeployPost-deploy hygiene & change mgmt0 of 0RD-F-145Deployed bytecode reproducibilityPost-deploy hygiene & change mgmt0 of 0RD-F-146New contract deploys in last 30 daysPost-deploy hygiene & change mgmt0 of 0RD-F-147Protocol has bridge surfaceCross-chain & bridge0 of 0RD-F-148Bridge validator count (M)Cross-chain & bridge0 of 0RD-F-149Bridge validator threshold (k-of-M)Cross-chain & bridge0 of 0RD-F-150Bridge validator co-hostingCross-chain & bridge0 of 0RD-F-151★Bridge ecrecover checks result ≠ address(0)Cross-chain & bridge0 of 0RD-F-152Bridge binds message to srcChainIdCross-chain & bridge0 of 0RD-F-153Bridge tracks nonce-consumed mappingCross-chain & bridge0 of 0RD-F-154★Default bytes32(0) acceptable as valid rootCross-chain & bridge0 of 0RD-F-155Bridge validator-set rotation recencyCross-chain & bridge0 of 0RD-F-156Bridge uses same key custody for >30% validatorsCross-chain & bridge0 of 0RD-F-157Bridge TVL per validator ratioCross-chain & bridge0 of 0RD-F-158Known-threat-actor cluster has touched protocolThreat intelligence & recon0 of 0RD-F-159Attacker wallet pre-strike probe (low-gas failing txs)Threat intelligence & recon0 of 0RD-F-160GitHub malicious-dependency incident touching protocol depsThreat intelligence & recon0 of 0RD-F-161Protocol-impersonator domain registered (typosquat)Threat intelligence & recon0 of 0RD-F-162Known-exploit-template selector deployed by any addressThreat intelligence & recon0 of 0RD-F-163Avg attacker reconnaissance time for peer-class protocolsThreat intelligence & recon0 of 0RD-F-164Leaked credential on paste/sentry siteThreat intelligence & recon0 of 0RD-F-165Protocol social channel has scam-coordinator flagThreat intelligence & recon0 of 0RD-F-166Deprecated contracts still holding valueOperational history0 of 0RD-F-167Deprecated contract paused but pause reversible by live adminGovernance & admin0 of 0RD-F-168Stale-approval exposure on deprecated routerPost-deploy hygiene & change mgmt0 of 0RD-F-170Solc version used (known-bug versions flagged)Tooling / compiler / AI0 of 0RD-F-171Bytecode similarity to audited upstream with behavior deviationTooling / compiler / AI0 of 0RD-F-172Repo shows AI-tool co-authorship in critical filesTooling / compiler / AI0 of 0RD-F-173Team self-disclosure of AI-generated SolidityTooling / compiler / AI0 of 0RD-F-174Dependency tree uses EOL Solidity versionTooling / compiler / AI0 of 0RD-F-175Disclosure channel existsResponse & disclosure hygiene0 of 0RD-F-176Disclosure SLA publicResponse & disclosure hygiene0 of 0RD-F-177Prior known-ignored disclosureResponse & disclosure hygiene0 of 0RD-F-178CVE/GHSA advisory issued against protocolResponse & disclosure hygiene0 of 0RD-F-179LayerZero OFT DVN config (count, threshold, diversity)Cross-chain & bridge0 of 0RD-F-180★Immutable oracle addressOracle & external dependencies0 of 0RD-F-181Permissionless-pool lending oracleOracle & external dependencies0 of 0RD-F-182Security-Council threshold reduction (RT)Real-time signals0 of 0RD-F-183Bug bounty scope gap on highest-TVL contractsCode & audits0 of 0RD-F-184Real-capital social-engineering personaDev identity & insider risk0 of 0RD-F-185Bridge rate-limiter / chain-pause as positive mitigantPost-deploy hygiene & change mgmt0 of 0