defirisk.co
rubric v1.7.0

Post-exploit response score

A operational history factor in the v1.7.0 rubric. Measured per protocol on a e cadence.

Methodology how we score#

What this measures
This factor is a curator-assigned score from 1 to 5 evaluating the protocol's response to its most recent incident across four dimensions: user compensation (restitution offered and delivered), transparency (public communication timeliness and completeness), root-cause depth (post-mortem technical precision), and operational recovery (time to restore normal function). A score of 5 represents exemplary response on all four dimensions; a score of 1 represents silence or denial.

Why it matters
Post-exploit response quality is a leading indicator of whether a future incident will be handled well. Protocols that respond poorly -- by going silent, providing vague post-mortems, or failing to compensate affected users -- demonstrate governance and operational cultures that increase systemic risk. In contrast, protocols that publish detailed post-mortems within thirty days, offer structured compensation, and commission re-audits signal that security is treated as a continuous process rather than a one-time checkbox. The dataset shows consistent correlation between poor response scores and subsequent second exploits.

Green / Yellow / Red
Green: score of 4 or 5, indicating timely public communication, full root-cause disclosure, meaningful compensation effort, and rapid operational recovery. Yellow: score of 2 or 3, indicating partial disclosure, delayed communication, or incomplete compensation. Red: score of 1, indicating silence, denial, or team abandonment following the incident.

Common gray cases
For protocols with multiple incidents, this score applies to the most recent incident only. If the most recent incident is ongoing (fewer than thirty days elapsed) and no post-mortem has been published, the field is marked gray pending curator assessment.

Notable historical examples
No cross-hacked incidents currently linked in database for this factor.

Measurement what to look for#

Curator-score (1–5) the most recent incident response on: compensation completeness, transparency of disclosure, root-cause analysis depth, and operational recovery speed.

Data & output #

Data source
Protocol post-mortem document + governance forum announcements + news coverage
Output format
Green / Yellow / Red
Evidence artifact
Post-mortem URL + curator score sheet (1–5 per sub-dimension) + curator sign-off
Confidence signal
green = score ≥4; yellow = score 2–3; red = score 1 or no response; gray = no prior exploits (N/A)

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks 4 historical incidents#

relatedBalancer V2 (Composable Stable Pools): `_upscale()` rounding-down compounded across 65+ micro-swaps2025-11-03 · $128M · `_upscale()` rounding-down compounded across 65+ micro-swaps · Auto-linked by C.4 triage 2026-05-07
relatedGMX V1: Cross-Contract Reentrancy via Order-Keeper Callback2025-07-09 · Cross-Contract Reentrancy via Order-Keeper Callback · Auto-linked by C.4 triage 2026-05-07
relatedEuler Finance: Donation Function Bypassing Health Check (Logic Bug in EIP-14 upgrade)2023-03-13 · $197M · Donation Function Bypassing Health Check (Logic Bug in EIP-14 upgrade) · Auto-linked by C.4 triage 2026-05-07
relatedCurve Finance (curve.fi frontend): DNS nameserver compromise → malicious frontend injection → approval harvesting2022-08-09 · $575K · DNS nameserver compromise → malicious frontend injection → approval harvesting · Auto-linked by C.4 triage 2026-05-07
rubric_version v1.7.0factor RD-F-081category 5carried 0critical no