defirisk.co
rubric v1.7.0

Factor encyclopedia

184 evidence factors across 13 categories. Click any factor for methodology, measurement, and which protocols carry it.

184 factors13 categories20 critical rubric v1.7.0
Category
Severity
IDFactorCategoryCarried
RD-F-001Audit scope mismatchCode & audits0 of 0RD-F-002Audit recencyCode & audits0 of 0RD-F-003Resolved-without-proof findingsCode & audits0 of 0RD-F-004Audit countCode & audits0 of 0RD-F-005Audit firm tierCode & audits0 of 0RD-F-006Audit-to-deploy gapCode & audits0 of 0RD-F-007Bug bounty presence & max payoutCode & audits0 of 0RD-F-008Ignored bounty disclosureCode & audits0 of 0RD-F-009Formal verification coverageCode & audits0 of 0RD-F-010Static-analyzer high-severity countCode & audits0 of 0RD-F-011SELFDESTRUCT reachable from non-admin pathCode & audits0 of 0RD-F-012delegatecall with user-controlled targetCode & audits0 of 0RD-F-013Arbitrary call with user-controlled targetCode & audits0 of 0RD-F-014Reentrancy guard on external-calling functionsCode & audits0 of 0RD-F-015ERC-777/1155/721 hook without reentrancy guardCode & audits0 of 0RD-F-016Divide-before-multiply patternCode & audits0 of 0RD-F-017Mixed-decimals math without explicit scalingCode & audits0 of 0RD-F-018Signed/unsigned arithmetic confusionCode & audits0 of 0RD-F-019ecrecover zero-address return uncheckedCode & audits0 of 0RD-F-020EIP-712 domain separator missing chainIdCode & audits0 of 0RD-F-021UUPS _authorizeUpgrade correctly permissionedCode & audits0 of 0RD-F-022Public initialize() without initializer modifierCode & audits0 of 0RD-F-023Constructor calls _disableInitializers()Code & audits0 of 0RD-F-024Code complexity vs audit coverageCode & audits0 of 0RD-F-025Admin key custody typeGovernance & admin0 of 0RD-F-026Upgrade multisig signer configuration (M/N)Governance & admin0 of 0RD-F-027Single admin EOAGovernance & admin0 of 0RD-F-028Low-threshold multisig vs TVLGovernance & admin0 of 0RD-F-029Multisig signers co-hostedGovernance & admin0 of 0RD-F-030Hot-wallet signer flagGovernance & admin0 of 0RD-F-031Signer rotation recencyGovernance & admin0 of 0RD-F-032Timelock duration on upgradesGovernance & admin0 of 0RD-F-033Timelock on sensitive actionsGovernance & admin0 of 0RD-F-034Guardian/pause-keeper distinct from upgraderGovernance & admin0 of 0RD-F-035Role separation: upgrade ≠ fee ≠ oracleGovernance & admin0 of 0RD-F-036Flash-loanable voting weightGovernance & admin0 of 0RD-F-037Quorum achievable via single-entity flash loanGovernance & admin0 of 0RD-F-038Proposal execution delay < 24hGovernance & admin0 of 0RD-F-039delegatecall/call in proposal execution without allowlistGovernance & admin0 of 0RD-F-040Emergency-veto multisig presentGovernance & admin0 of 0RD-F-041Rescue/emergencyWithdraw without timelockGovernance & admin0 of 0RD-F-042Admin has mint() with unlimited maxGovernance & admin0 of 0RD-F-043Admin = deployer EOA after 7 daysGovernance & admin0 of 0RD-F-044Admin wallet interacts with flagged addressesGovernance & admin0 of 0RD-F-045Constructor args match governance proposalGovernance & admin0 of 0RD-F-046Contract unverified on Etherscan/SourcifyGovernance & admin0 of 0RD-F-047Governance token concentration (Gini)Governance & admin0 of 0RD-F-048Oracle providers usedOracle & external dependencies0 of 0RD-F-049Oracle role per assetOracle & external dependencies0 of 0RD-F-050Dependency graph (protocols depended upon)Oracle & external dependencies0 of 0RD-F-051Fallback behavior on oracle failureOracle & external dependencies0 of 0RD-F-052Breakage analysis per dependencyOracle & external dependencies0 of 0RD-F-053Oracle source = spot DEX pool (no TWAP)Oracle & external dependencies0 of 0RD-F-054TWAP window durationOracle & external dependencies0 of 0RD-F-055Oracle pool depth (USD)Oracle & external dependencies0 of 0RD-F-056Single-pool oracle (no medianization)Oracle & external dependencies0 of 0RD-F-057Circuit breaker on price deviationOracle & external dependencies0 of 0RD-F-058Max-deviation threshold (bps)Oracle & external dependencies0 of 0RD-F-059Oracle staleness check presentOracle & external dependencies0 of 0RD-F-060Chainlink aggregator min/max bound misconfigOracle & external dependencies0 of 0RD-F-061LP token balanceOf used for pricingOracle & external dependencies0 of 0RD-F-062External keeper/relayer not redundantOracle & external dependencies0 of 0RD-F-063TVL (current + 30d trend)Economic risk0 of 0RD-F-064TVL concentration (top-10 wallet share)Economic risk0 of 0RD-F-065Liquidity depth per major assetEconomic risk0 of 0RD-F-066Utilization rate (lending protocols)Economic risk0 of 0RD-F-067Historical bad-debt eventsEconomic risk0 of 0RD-F-068Collateralization under stressEconomic risk0 of 0RD-F-069Algorithmic / under-collateralized stablecoinEconomic risk0 of 0RD-F-070Empty cToken-style market (zero supply/borrow)Economic risk0 of 0RD-F-071Seed-deposit requirement for new market listingEconomic risk0 of 0RD-F-072Market-listing governance thresholdEconomic risk0 of 0RD-F-073Oracle-manipulation-proof borrow capEconomic risk0 of 0RD-F-074ERC-4626 virtual-share offset (OZ ≥4.9)Economic risk0 of 0RD-F-075First-depositor / share-inflation guardEconomic risk0 of 0RD-F-076Protocol age (days)Operational history0 of 0RD-F-077Prior exploit countOperational history0 of 0RD-F-078Chronic-exploit flag (≥3 incidents)Operational history0 of 0RD-F-079Same-root-cause repeat exploitOperational history0 of 0RD-F-080Days since last exploitOperational history0 of 0RD-F-081Post-exploit response scoreOperational history0 of 0RD-F-082Post-mortem published within 30 daysOperational history0 of 0RD-F-083Auditor re-engaged after last exploitOperational history0 of 0RD-F-084TVL stability (CoV over 90d)Operational history0 of 0RD-F-085Incident response time (minutes)Operational history0 of 0RD-F-086Pause activations (trailing 12 months)Operational history0 of 0RD-F-087Pause > 7 consecutive daysOperational history0 of 0RD-F-088Re-deployed to new addresses in last yearOperational history0 of 0RD-F-089Insurance coverage activeOperational history0 of 0RD-F-090Mixer withdrawal → protocol interactionReal-time signals0 of 0RD-F-091Partial-drain test transactionsReal-time signals0 of 0RD-F-092Unusual mempool pattern from deployer walletReal-time signals0 of 0RD-F-093Abnormal gas-price willingness from attacker walletReal-time signals0 of 0RD-F-094New contract with similar bytecode to exploit templateReal-time signals0 of 0RD-F-095Known-exploit function-selector replayReal-time signals0 of 0RD-F-096New ERC-20 approval to unverified contract from whaleReal-time signals0 of 0RD-F-097Sybil surge of identical-pattern transactionsReal-time signals0 of 0RD-F-098TVL anomaly — % drop in <1hReal-time signals0 of 0RD-F-099Oracle price deviation >X% from secondaryReal-time signals0 of 0RD-F-100Flash loan >$10M targeting protocol tokensReal-time signals0 of 0RD-F-101Large governance proposal queuedReal-time signals0 of 0RD-F-102Admin/upgrade transaction in mempoolReal-time signals0 of 0RD-F-103Bridge signer-set change proposed/executedReal-time signals0 of 0RD-F-104Stablecoin depeg >2% on shared-LP venueReal-time signals0 of 0RD-F-105DNS/CDN/frontend hash driftReal-time signals0 of 0RD-F-106Cross-chain bridge unverified mint patternReal-time signals0 of 0RD-F-107Admin EOA signing from new geography/deviceReal-time signals0 of 0RD-F-108GitHub force-push to sensitive branchReal-time signals0 of 0RD-F-109Social-media impersonation scam spikeReal-time signals0 of 0RD-F-110Unusual pending/executed proposal ratioReal-time signals0 of 0RD-F-111Team doxx statusDev identity & insider risk0 of 0RD-F-112Team public accountability surfaceDev identity & insider risk0 of 0RD-F-113Team other-protocol involvement historyDev identity & insider risk0 of 0RD-F-114Deployer address prior on-chain historyDev identity & insider risk0 of 0RD-F-115Prior rug/exit-scam affiliationDev identity & insider risk0 of 0RD-F-116Contributor tenure at admin-permissioned PRDev identity & insider risk0 of 0RD-F-117ENS/NameStone identity bound to deployerDev identity & insider risk0 of 0RD-F-118Handle reuse across failed/rugged projectsDev identity & insider risk0 of 0RD-F-119Commit timezone consistent with stated geographyDev identity & insider risk0 of 0RD-F-120Video-off/voice-consistency flagDev identity & insider risk0 of 0RD-F-121Contributor OSINT depth scoreDev identity & insider risk0 of 0RD-F-122Contributor paid to DPRK-cluster walletDev identity & insider risk0 of 0RD-F-123Sudden admin-rescue/ACL change without discussionDev identity & insider risk0 of 0RD-F-124Deployer wallet mixer-funded within 30 daysDev identity & insider risk0 of 0RD-F-125Deployer linked within 3 hops to DPRK/LazarusDev identity & insider risk0 of 0RD-F-126Is-a-fork-ofFork / dependency lineage0 of 0RD-F-127Upstream patch not mergedFork / dependency lineage0 of 0RD-F-128Upstream vulnerability disclosure (last 90d)Fork / dependency lineage0 of 0RD-F-129Code divergence from upstream (%)Fork / dependency lineage0 of 0RD-F-130Fork depth (generations from original audit)Fork / dependency lineage0 of 0RD-F-131Fork retains upstream audit coverageFork / dependency lineage0 of 0RD-F-132Fork has different economic parameters than upstreamFork / dependency lineage0 of 0RD-F-133Dependency manifest uses unpinned versionsFork / dependency lineage0 of 0RD-F-134Dependency had malicious-release incident (last 90d)Fork / dependency lineage0 of 0RD-F-135Shared-library version with known-vuln statusFork / dependency lineage0 of 0RD-F-136Deployed bytecode matches signed release tagPost-deploy hygiene & change mgmt0 of 0RD-F-137Upgrade frequency (per 90 days)Post-deploy hygiene & change mgmt0 of 0RD-F-138Hot-patch deploys without timelock (last 30 days)Post-deploy hygiene & change mgmt0 of 0RD-F-139Post-audit code changes without re-auditPost-deploy hygiene & change mgmt0 of 0RD-F-140Fix-merged-but-not-deployed gapPost-deploy hygiene & change mgmt0 of 0RD-F-141Test-mode parameters in deployPost-deploy hygiene & change mgmt0 of 0RD-F-142Storage-layout collision risk across upgradesPost-deploy hygiene & change mgmt0 of 0RD-F-143Reinitializable implementation (no _disableInitializers)Post-deploy hygiene & change mgmt0 of 0RD-F-144CREATE2 factory permits same-address redeployPost-deploy hygiene & change mgmt0 of 0RD-F-145Deployed bytecode reproducibilityPost-deploy hygiene & change mgmt0 of 0RD-F-146New contract deploys in last 30 daysPost-deploy hygiene & change mgmt0 of 0RD-F-147Protocol has bridge surfaceCross-chain & bridge0 of 0RD-F-148Bridge validator count (M)Cross-chain & bridge0 of 0RD-F-149Bridge validator threshold (k-of-M)Cross-chain & bridge0 of 0RD-F-150Bridge validator co-hostingCross-chain & bridge0 of 0RD-F-151Bridge ecrecover checks result ≠ address(0)Cross-chain & bridge0 of 0RD-F-152Bridge binds message to srcChainIdCross-chain & bridge0 of 0RD-F-153Bridge tracks nonce-consumed mappingCross-chain & bridge0 of 0RD-F-154Default bytes32(0) acceptable as valid rootCross-chain & bridge0 of 0RD-F-155Bridge validator-set rotation recencyCross-chain & bridge0 of 0RD-F-156Bridge uses same key custody for >30% validatorsCross-chain & bridge0 of 0RD-F-157Bridge TVL per validator ratioCross-chain & bridge0 of 0RD-F-158Known-threat-actor cluster has touched protocolThreat intelligence & recon0 of 0RD-F-159Attacker wallet pre-strike probe (low-gas failing txs)Threat intelligence & recon0 of 0RD-F-160GitHub malicious-dependency incident touching protocol depsThreat intelligence & recon0 of 0RD-F-161Protocol-impersonator domain registered (typosquat)Threat intelligence & recon0 of 0RD-F-162Known-exploit-template selector deployed by any addressThreat intelligence & recon0 of 0RD-F-163Avg attacker reconnaissance time for peer-class protocolsThreat intelligence & recon0 of 0RD-F-164Leaked credential on paste/sentry siteThreat intelligence & recon0 of 0RD-F-165Protocol social channel has scam-coordinator flagThreat intelligence & recon0 of 0RD-F-166Deprecated contracts still holding valueOperational history0 of 0RD-F-167Deprecated contract paused but pause reversible by live adminGovernance & admin0 of 0RD-F-168Stale-approval exposure on deprecated routerPost-deploy hygiene & change mgmt0 of 0RD-F-170Solc version used (known-bug versions flagged)Tooling / compiler / AI0 of 0RD-F-171Bytecode similarity to audited upstream with behavior deviationTooling / compiler / AI0 of 0RD-F-172Repo shows AI-tool co-authorship in critical filesTooling / compiler / AI0 of 0RD-F-173Team self-disclosure of AI-generated SolidityTooling / compiler / AI0 of 0RD-F-174Dependency tree uses EOL Solidity versionTooling / compiler / AI0 of 0RD-F-175Disclosure channel existsResponse & disclosure hygiene0 of 0RD-F-176Disclosure SLA publicResponse & disclosure hygiene0 of 0RD-F-177Prior known-ignored disclosureResponse & disclosure hygiene0 of 0RD-F-178CVE/GHSA advisory issued against protocolResponse & disclosure hygiene0 of 0RD-F-179LayerZero OFT DVN config (count, threshold, diversity)Cross-chain & bridge0 of 0RD-F-180Immutable oracle addressOracle & external dependencies0 of 0RD-F-181Permissionless-pool lending oracleOracle & external dependencies0 of 0RD-F-182Security-Council threshold reduction (RT)Real-time signals0 of 0RD-F-183Bug bounty scope gap on highest-TVL contractsCode & audits0 of 0RD-F-184Real-capital social-engineering personaDev identity & insider risk0 of 0RD-F-185Bridge rate-limiter / chain-pause as positive mitigantPost-deploy hygiene & change mgmt0 of 0