defirisk.co
rubric v1.7.0

Storage-layout collision risk across upgrades

Convex Finance's assessment for RD-F-142 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Not applicable. All core Convex contracts are non-proxy, non-upgradeable. No storage layout exists across upgrade versions for core contracts. The vlCVX v1 to v2 transition was a fresh redeployment (not an upgrade to the same proxy), so no storage collision risk applies.

Sources #

  • GitHub
    Convex Booster.sol -- GitHub sourceBooster.sol, VoterProxy.sol -- no proxy pattern, no initialize(), no storage layout across versionsretrieved 2026-05-16
  • Internal
    Protocol profile -- deployment table.research/protocols/convex-finance/00-profile.md §3 -- all contracts proxy:falseretrieved 2026-05-16

Methodology #

Determine whether the OZ upgrades-plugin or manual review flags a storage-layout collision risk between implementation versions.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol convex-finance factor RD-F-142 score not_applicable collected_at 2026-05-16 02:41:28