defirisk.co
rubric v1.7.0

Fork depth (generations from original audit)

A fork / dependency lineage factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor records the number of fork hops between the assessed protocol and an originally-audited base protocol. A direct fork of Compound Finance has a fork depth of 1. A fork of a Compound fork has a fork depth of 2. Each additional hop potentially dilutes the audit coverage assurance and introduces new parameter divergences at each layer. The data source is a curator-maintained lineage map cross-referenced with bytecode similarity analysis.

Why it matters
Fork-of-fork deployments compound the audit coverage risk at each layer. A third-generation fork (depth 3) may carry bugs introduced at the second-generation level that were never audited, combined with parameter changes introduced at the third level that diverge from both the first and second generation audits. The BSC DeFi ecosystem during 2021-2022 was dominated by second- and third-generation forks where an already-dangerous pattern (unaudited BSC fork of an audited Ethereum protocol) was further forked without any additional review. AutoShark was a fork of PancakeBunny which was itself a yield aggregator inspired by Yearn -- two hops from the original audited design, with vulnerabilities introduced at each layer.

Green / Yellow / Red
Green: fork depth of 0 (original code) or 1 (direct fork with independent audit of the fork itself). Yellow: fork depth of 2, where the protocol can demonstrate that the intermediate fork's changes were reviewed. Red: fork depth of 3 or more, or fork depth of 2 without any audit of the intermediate changes.

Common gray cases
Fork depth is gray when the lineage cannot be reliably traced due to undisclosed or multiple overlapping upstream sources.

Notable historical examples
No hacks are currently linked in the database for this specific factor as a standalone causal driver. The factor is a structural modifier on the overall Cat 8 lineage assessment.

Measurement what to look for#

Count the number of fork hops from an originally audited protocol (0 = direct fork of an audited protocol, N = N-th generation).

Data & output #

Data source
Curator lineage map built from F126 results + GitHub repo histories
Output format
Green / Yellow / Red
Evidence artifact
Fork chain list (protocol names + commit SHAs) + depth integer
Confidence signal
green = depth 0–1 (direct fork of audited protocol); yellow = depth 2; red = depth ≥3 (audit coverage very diluted); gray = fork lineage not determinable

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-130category 8carried 0critical no